Maintainer-led ยท best-effort support

Choose the support route that matches the problem.

Start with the current documentation. When you need to report something, share the smallest reproducible example and replace financial or personal details with fabricated values.

Use public forms for setup, bugs, and feedback; use private email for security reports; request written permission for commercial use; remove private data before sending.
Send the smallest useful example. Replace real financial and personal details with fake values.

Support routes

Put the question where it can be handled safely.

Reproducible product bug

Use the structured bug form for behavior that differs from the current release documentation.

Open a sanitized bug report

Installation or update problem

Include the deployment path, version, host architecture, exact command, and the smallest useful sanitized output.

Ask for setup help

Workflow feedback

Explain what you were trying to accomplish, where the workflow became difficult, and what a useful outcome would look like.

Share product feedback

Suspected vulnerability

Do not open a public issue. Read the security policy and email a private report without real financial records, credentials, or other people's data.

Read private reporting instructions

Commercial permission

The noncommercial license does not grant commercial use. Request separate written permission before using the software for a commercial purpose.

Review commercial licensing

Before posting

Keep public diagnostics useful and harmless.

Include

  • Current app version and exact image tag.
  • Host OS, CPU architecture, container runtime, and browser where relevant.
  • Documented deployment path and sanitized configuration names.
  • Exact steps, expected behavior, observed behavior, and a minimal log excerpt.
  • Fabricated examples that reproduce the same problem.

Never include publicly

  • Passwords, cookies, Rails credentials, private keys, or database URLs.
  • Complete environment files, database dumps, or infrastructure snapshots.
  • Bank exports, real transaction descriptions, balances, email addresses, or account names.
  • A security proof of concept that could put active installations at risk.

Scope

What best-effort support can and cannot cover.

Best fit for support

  • The latest stable FinanceTracking.app release.
  • The documented local and production Compose paths.
  • The published GHCR image and an unmodified source checkout.
  • Reproducible application behavior, documentation gaps, and clear workflow feedback.

Outside the normal boundary

  • Operating a user's server or guaranteeing uptime and recovery.
  • Every reverse proxy, custom fork, or institution-specific CSV variation.
  • Recovering from an untested or incomplete infrastructure backup.
  • Accounting, tax, legal, investment, or personal financial advice.
No service-level agreementFinanceTracking.app is a maintainer-led project. Public and private requests are handled as capacity allows, without guaranteed response or resolution times.

Not sure whether the issue belongs to the app or the host?

The trust center maps application behavior, external requests, infrastructure responsibilities, and the production baseline.