Having said that, none of this prevents people from creating fake accounts. On our system I can see people regularly signin in with multiple google accounts, with incrementing digits in the name, trying to abuse the free tier. You'll need to build something yourself for that, depending on your risk surface. For us this involves tracking requests across IP addresses, blocking free access from data centre IPs, blocking bots using AWS WAF, analyzing task patterns to spot people who use multiple residential IPs and a bit more.