Acceptable Use Policy
Effective August 25, 2026
Published by NAS Innovation LLC, which operates Bao Budget.
Version: 1.1 Applies to: everyone who uses Bao Budget — the web app at https://app.baobudget.com, the iOS and Android apps, and the Bao Budget API.
This policy forms part of the Bao Budget Terms of Service. A violation of this policy is a violation of the Terms of Service.
1. Scope of This Policy
1.1 Bao Budget includes surfaces on which your activity is visible to, or affects, other people:
- Share cards — the public habit-share images and pages you may generate and post.
- Leaderboards — where you appear under a display handle you choose, alongside other people.
- Transaction notes — text you attach to your own records.
- Merchant enrichment contributions — corrections and labels you submit that help improve merchant names for everyone.
1.2 This policy sets out what is not permitted on those surfaces and in the product generally. Every restriction in it is one we will enforce.
1.3 You are responsible for everything done through your account.
2. Unlawful Use
2.1 You may not use Bao Budget for any unlawful purpose, or to assist any other person in violating the law.
2.2 You may not use it to launder money, evade sanctions, commit or facilitate fraud, or conceal the proceeds of crime.
2.3 You may not upload, submit, or share content that is unlawful, or that you do not have the right to share.
3. Other People's Financial Data
3.1 You may not connect, upload, enter, or share another person's financial data unless you are authorized to do so. A joint account you hold is yours to connect. Another person's account is not.
3.2 You may not use anyone else's bank credentials, and you may not ask anyone to provide you with theirs. We never see or store bank login credentials, and neither should you.
3.3 You may not share another person's financial information on a share card, a leaderboard, in a display handle, or anywhere else in the product. Your own figures are yours to publish. Another person's are not.
4. Misrepresentation and Impersonation
4.1 You may not impersonate another person, another company, or Bao Budget itself.
4.2 You may not choose a display handle, avatar, or share-card content that suggests you are someone you are not, or that you are affiliated with or endorsed by an organization when you are not.
4.3 You may not create an account using another person's identity, or permit another person to use your account to evade a suspension.
4.4 You may not state or imply that Bao Budget is a bank, that it holds or moves your money, or that anything in it is insured by the FDIC or any government agency. None of those statements is true.
5. Conduct on Shared and Public Surfaces
5.1 On any surface other people can see — share cards, leaderboards, display handles, avatars — you may not post content that is:
(a) harassing, threatening, or intended to intimidate;
(b) hateful toward people on the basis of race, ethnicity, national origin, religion, sex, gender identity, sexual orientation, disability, or age;
(c) sexually explicit; or
(d) an attack on a specific person.
5.2 You may not use shared surfaces to spam, to advertise, to recruit, or to promote a scheme.
5.3 You may not submit merchant enrichment contributions that are deliberately inaccurate, defamatory, obscene, or used to inject a message.
5.4 We may remove content from any shared or public surface without notice.
6. Scraping and Automated Access
6.1 You may not scrape Bao Budget. You may not use crawlers, spiders, scripts, headless browsers, or any other automated means to extract data from the web app or the mobile apps.
6.2 Automated access is permitted only through the Bao Budget API, using your own API key, within the rate limits we publish or apply. If you require programmatic access, use the API.
6.3 You may not circumvent, disable, or interfere with rate limits, authentication, paywall gating, or any other technical control.
6.4 You may not use Bao Budget to build a dataset about other users, or to compile information about people who have not agreed to it.
6.5 You may not share or resell your API key, and you may not permit anyone else to use your account's access.
7. Reverse Engineering
7.1 You may not decompile, disassemble, reverse engineer, or attempt to derive the source code of the Bao Budget apps or service, except to the extent that restriction is prohibited by law or permitted by the licence terms of an open-source component we include.
7.2 You may not copy, mirror, or create a derivative version of the service.
(For the full software licence terms — install and use rights, restrictions, and reservation of rights — see Terms of Service §15. There is no separate Bao Budget End User License Agreement; on iOS, Apple's standard Licensed Application EULA also applies.)
8. Security Testing and Vulnerability Research
8.1 You may not conduct security testing against Bao Budget without authorization. That includes penetration testing, vulnerability scanning, fuzzing, credential stuffing, denial-of-service testing, and social engineering of our staff or our vendors.
Testing conducted in compliance with our Coordinated Vulnerability Disclosure Policy (document 11) is authorized, and is not a violation of this section. Security testing that falls outside that policy — anything in its out-of-scope list, or testing that breaches its rules of engagement — is unauthorized, and this section 8.1 applies to it in full.
8.2 You may not attempt to access an account, a record, or a system you are not authorized to access. You may not probe for or exploit a vulnerability in order to reach other users' data. This provision has no research carve-out: the Vulnerability Disclosure Policy does not authorize access to another person's account or financial data either.
8.3 If you find a vulnerability, tell us. Report it to security@baobudget.com, and give us a reasonable opportunity to remediate it before disclosing it publicly.
The full process is set out in our Coordinated Vulnerability Disclosure Policy (document 11) — what is in scope, the rules to test within, how to write a useful report, what we commit to in response, and our good-faith safe harbor for researchers who follow it. If you intend to look for vulnerabilities, read that policy first.
8.4 You may not introduce malware, or use Bao Budget to distribute it.
8.5 You may not interfere with the operation of the service — no flooding, no deliberate overloading, no disruption of other users' access.
9. Enforcement
9.1 If you breach this policy, we may — depending on what occurred and how serious it is:
(a) remove or hide the content; (b) reset a display handle or avatar; (c) remove you from leaderboards; (d) revoke an API key; (e) suspend your account; or (f) terminate your account.
9.2 We will usually warn you first, and where we are able to, we will tell you which rule was breached and how to correct it. We may act immediately and without warning where the conduct is unlawful, puts another person's data at risk, threatens the security or availability of the service, or repeats conduct we have already warned you about.
9.3 If we suspend or terminate your account, your subscription is handled under the Subscription & Billing Terms. Subscriptions are non-refundable, and termination for a breach of this policy does not entitle you to a refund of any part of the period you have paid for.
9.4 You may appeal. Email legal@baobudget.com and we will review the decision. Tell us what happened; a person will read it.
9.5 You may delete your account at any time from your account settings, whether or not we have taken action.
10. Repeat Infringers
10.1 We terminate, in appropriate circumstances, the accounts of users who repeatedly infringe the copyright or other intellectual property rights of others.
10.2 The repeat-infringer policy is stated in full in Terms of Service §18 (Copyright and the DMCA), and that section governs. This section is a pointer to it, not a second version of it. Where anything here appears to differ from ToS §18, ToS §18 controls — including how notices are counted, when an account is terminated, and our reservation of the right to terminate sooner in a clear case of deliberate, large-scale infringement.
10.3 Send infringement notices and counter-notices to our DMCA designated agent, whose name and address are published in Terms of Service §18. Notices may also be emailed to legal@baobudget.com.
11. Reporting a Problem
11.1 To report content or conduct that breaches this policy, email legal@baobudget.com with a link to, or a description of, where you saw it.
11.2 To report a security vulnerability, email security@baobudget.com. Before you begin looking for one, read the Coordinated Vulnerability Disclosure Policy (document 11) — it sets out what testing is authorized and carries our safe-harbor commitment (see section 8).
11.3 To report that a child under 13 is using Bao Budget, email privacy@baobudget.com.
12. Amendments to This Policy
12.1 This policy forms part of the Terms of Service, and it is amended under the same standard: Terms of Service §22 governs. For any material change, we will email the address on your account at least 30 days before the change takes effect, stating what is changing. Posting a new version is not, by itself, notice. Changes apply prospectively only.
12.2 If you do not accept a material change, you may reject it and terminate your subscription before it takes effect, at no penalty, on the terms set out in Terms of Service §22 — including the pro-rata refund of the unused portion of the period you have already paid for.
12.3 Non-material changes — correcting a typo, clarifying a sentence, updating a contact address — take effect on their effective date without the 30-day process.
12.4 Continued use of Bao Budget after a material change has taken effect, having received notice of it, means you accept the updated policy. The version number and effective date above are updated with every change.
13. Changelog
| Version | Effective date | Change |
|---|---|---|
| 1.0 | August 25, 2026 | Initial publication. |
| 1.1 | August 25, 2026 | Section 8 updated: security testing conducted under our Coordinated Vulnerability Disclosure Policy (document 11) is authorized, and section 8.3 points to that policy. Section 11.2 updated to match. |