Data Policy

Moneylizer, operated by Megagraphs Technologies Private Limited ("Moneylizer", "we", "us", "our")
Primary website: https://moneylizer.com
Additional covered domain: https://megagraphs.com
Effective Date: 19 July 2026
Last Updated: 19 July 2026


1. Purpose and Scope

This Data Policy is the operational companion to our Privacy Policy. The Privacy Policy explains what we collect and why; this document explains how your data is handled in practice — where each category of data lives, how it is encrypted, who can access it, how long it is retained, and exactly what happens when it is deleted or exported.

This policy applies to all data processed through Moneylizer (including the m360 module and future modules) on both covered domains. If this document and the Privacy Policy ever conflict, the Privacy Policy prevails.

2. Data Inventory and Classification

#Data categorySourceSensitivityStorageEncryption at rest
1Account identity (name, email, profile picture)Google OAuthPersonalPrimary database (AWS India)AWS KMS
2OAuth tokens (Google sign-in; Gmail integration if enabled)Google OAuthSensitive credentialEncrypted token storeAWS KMS
3Statement files (PDF/XLSX)User upload / Gmail integrationSensitive financialObject storage (AWS India)AWS KMS
4Statement passwords (original, per source)Supplied by userSensitive credentialDedicated encrypted keyringAWS KMS, keyring-isolated
5Master password materialGenerated/derived per accountSensitive credentialDedicated encrypted keyringAWS KMS, keyring-isolated
6Extracted transactions (date, amount, currency, counterparty, reference, source statement)Parsed from statementsSensitive financialNoSQL database (AWS India)AWS KMS
7Categories and system labelsGenerated by platformDerivedNoSQL databaseAWS KMS
8Community and location labelsUser contributionsCommunity (description-level only)NoSQL databaseAWS KMS
9Personal notes (private, per transaction)UserPersonal-privateNoSQL databaseAWS KMS
10Technical/session data (device, IP, session IDs)AutomaticPersonalLogs / session storeAWS KMS
11Product analytics eventsAutomaticAggregated/anonymized where possibleAnalytics storeAWS KMS

Classification rules. Categories 2, 4, and 5 are treated as sensitive credentials: they are never logged, never included in analytics, never displayed back in full, and are accessible only to the processing services that need them. Categories 3, 6, and 9 are sensitive financial/private data: excluded from analytics and from community features. Category 8 is the only category shared across users, and it contains vendor/description-level information only — never amounts, dates, account details, or notes.

3. Statement Lifecycle

  1. Ingestion. You upload a statement, or (if enabled) our Gmail integration downloads a qualifying attachment — sender on the pre-defined allowlist and carrying a PDF/XLSX attachment. No other emails are accessed; email bodies are not retained beyond associating the attachment with its source.
  2. Unlocking. If the file is password-protected, the password you supply is used to unlock it. The password is written only to the encrypted keyring, never to logs or the database.
  3. Re-keying. The original password is removed from the stored copy and replaced with your account's master password. All your stored documents share this single master password.
  4. Extraction. Transactions are parsed from the unlocked file and written to the transactions store (category 6 above). The re-keyed original file is retained so you can always access the source document.
  5. Keyring retention. The original password is retained, encrypted, in the keyring so future statements from the same source unlock automatically. You may delete any stored password at any time from account settings; deletion from the keyring is immediate.

4. Encryption Standards

  • In transit: All connections use TLS. Plain-HTTP access is not served.
  • At rest: All stores listed in Section 2 are encrypted using AWS KMS-managed keys.
  • Keyring isolation: Statement passwords and master password material live in a dedicated keyring, encrypted separately from application data, with access restricted to the unlocking service.
  • Exports: Every export file is protected with your master password before it leaves our infrastructure.

5. Access Control

  • Production data access is limited to authorized engineering personnel under role-based access control and the principle of least privilege.
  • All production access is audit-logged.
  • No employee accesses Gmail-derived data except in the narrow cases permitted by Google's Limited Use policy (explicit consent for a specific message, security investigation, legal compliance, or aggregated/anonymized internal use), as stated in the Privacy Policy.
  • Privacy-first design (commitment): we are building towards an architecture in which no single internal process can identify an individual user by combining the data it can see. Until fully achieved, the controls above apply.

6. Data Residency

All infrastructure is hosted on Amazon Web Services in the India region. Your personal data does not leave India in the ordinary course of operations. Any future change to this posture would be a material change requiring a Privacy Policy update and, where required, fresh consent.

7. Retention Schedule

Data categoryRetained while account activeOn account deletionNotes
Account identityYesDeleted within 30 days
OAuth tokensYesRevoked and deleted within 30 daysGmail token also revocable any time via Google Account settings or in-app
Statement filesYesDeleted within 30 daysExcept legally mandated retention (Section 9)
Keyring entries (statement + master passwords)Yes; individual entries deletable any timeDeleted within 30 days
Extracted transactionsYesDeleted within 30 daysExcept legally mandated retention
Personal notesYesDeleted within 30 daysNever shared while active
Community/location labels you contributedYesContribution remains, permanently de-linked from your identityLabels are description-level and contain no personal data
Technical/session dataRolling, short-livedDeleted within 30 daysSession logs age out on rotation
Analytics eventsAggregated/anonymizedRetained only in aggregated/anonymized formNo longer personal data
Encrypted backupsRolling windowPurged on standard backup rotationSee Section 8

8. Deletion Workflow

  1. You trigger deletion via the in-app account deletion flow (or by request to the Grievance Officer).
  2. Your account is deactivated immediately; the service stops processing your data except for the deletion itself.
  3. Within 30 days, statements, transactions, labels-to-identity links, notes, keyring entries, and OAuth tokens are deleted from primary stores, and Google tokens are revoked.
  4. Residual copies in encrypted, time-limited backups are purged on the standard backup rotation cycle; backups are never used to restore deleted user data except during a disaster recovery event, after which deletion is re-applied.
  5. Where Indian law (tax, anti-money-laundering, or law-enforcement requirements) mandates retention, only the legally required minimum is retained, for the legally mandated period, and remains protected under Sections 4–5.

9. Legal Holds

If we receive a lawful order requiring preservation of specific data, that data is placed under a legal hold: excluded from the deletion workflow, access-restricted, and released (then deleted per Section 8) when the hold lapses.

10. Data Export and Portability

You can export all your transactions at any time from your account. Exports are generated as a downloadable file protected with your master password, giving you a complete local copy outside Moneylizer. Export does not delete anything; it can be combined with account deletion to take your data with you.

11. Analytics Data Handling

Product analytics exist to find journey bottlenecks and usability problems. Events are aggregated or anonymized wherever possible and never include the contents of statements, transactions, amounts, labels, notes, or any credential. Analytics data is not sold and is not shared with advertisers.

12. Sub-processors

Sub-processorPurposeRegion
Amazon Web Services (AWS)Hosting, storage, encryption (KMS), backupsIndia
Google LLCOAuth sign-in; scoped Gmail integration (optional)Per Google infrastructure; only OAuth/Gmail-scope data

We engage no other processors. Adding one is a material change requiring a Privacy Policy update.

13. Breach Response

If we become aware of a personal data breach affecting you, we will notify you and the Data Protection Board of India in accordance with the DPDP Act, 2023 and rules thereunder, including a description of the breach, the data involved, and the mitigation steps taken.

14. Review of This Policy

This Data Policy is reviewed alongside the Privacy Policy whenever we make a material change — new modules introducing new processing, new sub-processors, changes to retention or residency — and at least annually. Updates are posted with a revised "Last Updated" date; changes materially affecting your rights are notified per the Privacy Policy.

15. Contact

Grievance Officer: Vishwas
Email: support@megagraphs.com
Company: Megagraphs Technologies Private Limited
Address: 105B, Bldg 3, N G Suncity, Thakur Village, Kandivali (East), Mumbai 400101, India