Simkassa

How Simkassa protects your family budget

We do not promise abstract “complete security”. We openly describe the data, access boundaries and technical measures already used by the service.

Telegram verification and family isolation

The server verifies the signature and age of Telegram init data. Every budget request checks family membership, so one family's data should not be available to another.

Encrypted connection

The website and Mini App use HTTPS. PostgreSQL and the internal Django server are not exposed directly to the internet.

Voice messages

The bot downloads a voice message temporarily for recognition. The audio file is deleted immediately after processing, regardless of the result. A transaction is saved only after user confirmation.

Receipt photos

The image is processed in the browser to find a QR code and is not uploaded to the Simkassa server. Only the decoded QR text is sent for format validation and duplicate protection.

Storage and reports

Core data is stored in PostgreSQL on the Simkassa server and backups are retained for up to 14 days. Report suspicious behavior through Complaints and Suggestions in the Mini App.

Open @simkassa_bot