Data Policy
Moneylizer, operated by Megagraphs Technologies Private Limited ("Moneylizer", "we", "us", "our")
Primary website: https://moneylizer.com
Additional covered domain: https://megagraphs.com
Effective Date: 19 July 2026
Last Updated: 19 July 2026
1. Purpose and Scope
This Data Policy is the operational companion to our Privacy Policy. The Privacy Policy explains what we collect and why; this document explains how your data is handled in practice — where each category of data lives, how it is encrypted, who can access it, how long it is retained, and exactly what happens when it is deleted or exported.
This policy applies to all data processed through Moneylizer (including the m360 module and future modules) on both covered domains. If this document and the Privacy Policy ever conflict, the Privacy Policy prevails.
2. Data Inventory and Classification
| # | Data category | Source | Sensitivity | Storage | Encryption at rest |
|---|---|---|---|---|---|
| 1 | Account identity (name, email, profile picture) | Google OAuth | Personal | Primary database (AWS India) | AWS KMS |
| 2 | OAuth tokens (Google sign-in; Gmail integration if enabled) | Google OAuth | Sensitive credential | Encrypted token store | AWS KMS |
| 3 | Statement files (PDF/XLSX) | User upload / Gmail integration | Sensitive financial | Object storage (AWS India) | AWS KMS |
| 4 | Statement passwords (original, per source) | Supplied by user | Sensitive credential | Dedicated encrypted keyring | AWS KMS, keyring-isolated |
| 5 | Master password material | Generated/derived per account | Sensitive credential | Dedicated encrypted keyring | AWS KMS, keyring-isolated |
| 6 | Extracted transactions (date, amount, currency, counterparty, reference, source statement) | Parsed from statements | Sensitive financial | NoSQL database (AWS India) | AWS KMS |
| 7 | Categories and system labels | Generated by platform | Derived | NoSQL database | AWS KMS |
| 8 | Community and location labels | User contributions | Community (description-level only) | NoSQL database | AWS KMS |
| 9 | Personal notes (private, per transaction) | User | Personal-private | NoSQL database | AWS KMS |
| 10 | Technical/session data (device, IP, session IDs) | Automatic | Personal | Logs / session store | AWS KMS |
| 11 | Product analytics events | Automatic | Aggregated/anonymized where possible | Analytics store | AWS KMS |
Classification rules. Categories 2, 4, and 5 are treated as sensitive credentials: they are never logged, never included in analytics, never displayed back in full, and are accessible only to the processing services that need them. Categories 3, 6, and 9 are sensitive financial/private data: excluded from analytics and from community features. Category 8 is the only category shared across users, and it contains vendor/description-level information only — never amounts, dates, account details, or notes.
3. Statement Lifecycle
- Ingestion. You upload a statement, or (if enabled) our Gmail integration downloads a qualifying attachment — sender on the pre-defined allowlist and carrying a PDF/XLSX attachment. No other emails are accessed; email bodies are not retained beyond associating the attachment with its source.
- Unlocking. If the file is password-protected, the password you supply is used to unlock it. The password is written only to the encrypted keyring, never to logs or the database.
- Re-keying. The original password is removed from the stored copy and replaced with your account's master password. All your stored documents share this single master password.
- Extraction. Transactions are parsed from the unlocked file and written to the transactions store (category 6 above). The re-keyed original file is retained so you can always access the source document.
- Keyring retention. The original password is retained, encrypted, in the keyring so future statements from the same source unlock automatically. You may delete any stored password at any time from account settings; deletion from the keyring is immediate.
4. Encryption Standards
- In transit: All connections use TLS. Plain-HTTP access is not served.
- At rest: All stores listed in Section 2 are encrypted using AWS KMS-managed keys.
- Keyring isolation: Statement passwords and master password material live in a dedicated keyring, encrypted separately from application data, with access restricted to the unlocking service.
- Exports: Every export file is protected with your master password before it leaves our infrastructure.
5. Access Control
- Production data access is limited to authorized engineering personnel under role-based access control and the principle of least privilege.
- All production access is audit-logged.
- No employee accesses Gmail-derived data except in the narrow cases permitted by Google's Limited Use policy (explicit consent for a specific message, security investigation, legal compliance, or aggregated/anonymized internal use), as stated in the Privacy Policy.
- Privacy-first design (commitment): we are building towards an architecture in which no single internal process can identify an individual user by combining the data it can see. Until fully achieved, the controls above apply.
6. Data Residency
All infrastructure is hosted on Amazon Web Services in the India region. Your personal data does not leave India in the ordinary course of operations. Any future change to this posture would be a material change requiring a Privacy Policy update and, where required, fresh consent.
7. Retention Schedule
| Data category | Retained while account active | On account deletion | Notes |
|---|---|---|---|
| Account identity | Yes | Deleted within 30 days | — |
| OAuth tokens | Yes | Revoked and deleted within 30 days | Gmail token also revocable any time via Google Account settings or in-app |
| Statement files | Yes | Deleted within 30 days | Except legally mandated retention (Section 9) |
| Keyring entries (statement + master passwords) | Yes; individual entries deletable any time | Deleted within 30 days | — |
| Extracted transactions | Yes | Deleted within 30 days | Except legally mandated retention |
| Personal notes | Yes | Deleted within 30 days | Never shared while active |
| Community/location labels you contributed | Yes | Contribution remains, permanently de-linked from your identity | Labels are description-level and contain no personal data |
| Technical/session data | Rolling, short-lived | Deleted within 30 days | Session logs age out on rotation |
| Analytics events | Aggregated/anonymized | Retained only in aggregated/anonymized form | No longer personal data |
| Encrypted backups | Rolling window | Purged on standard backup rotation | See Section 8 |
8. Deletion Workflow
- You trigger deletion via the in-app account deletion flow (or by request to the Grievance Officer).
- Your account is deactivated immediately; the service stops processing your data except for the deletion itself.
- Within 30 days, statements, transactions, labels-to-identity links, notes, keyring entries, and OAuth tokens are deleted from primary stores, and Google tokens are revoked.
- Residual copies in encrypted, time-limited backups are purged on the standard backup rotation cycle; backups are never used to restore deleted user data except during a disaster recovery event, after which deletion is re-applied.
- Where Indian law (tax, anti-money-laundering, or law-enforcement requirements) mandates retention, only the legally required minimum is retained, for the legally mandated period, and remains protected under Sections 4–5.
9. Legal Holds
If we receive a lawful order requiring preservation of specific data, that data is placed under a legal hold: excluded from the deletion workflow, access-restricted, and released (then deleted per Section 8) when the hold lapses.
10. Data Export and Portability
You can export all your transactions at any time from your account. Exports are generated as a downloadable file protected with your master password, giving you a complete local copy outside Moneylizer. Export does not delete anything; it can be combined with account deletion to take your data with you.
11. Analytics Data Handling
Product analytics exist to find journey bottlenecks and usability problems. Events are aggregated or anonymized wherever possible and never include the contents of statements, transactions, amounts, labels, notes, or any credential. Analytics data is not sold and is not shared with advertisers.
12. Sub-processors
| Sub-processor | Purpose | Region |
|---|---|---|
| Amazon Web Services (AWS) | Hosting, storage, encryption (KMS), backups | India |
| Google LLC | OAuth sign-in; scoped Gmail integration (optional) | Per Google infrastructure; only OAuth/Gmail-scope data |
We engage no other processors. Adding one is a material change requiring a Privacy Policy update.
13. Breach Response
If we become aware of a personal data breach affecting you, we will notify you and the Data Protection Board of India in accordance with the DPDP Act, 2023 and rules thereunder, including a description of the breach, the data involved, and the mitigation steps taken.
14. Review of This Policy
This Data Policy is reviewed alongside the Privacy Policy whenever we make a material change — new modules introducing new processing, new sub-processors, changes to retention or residency — and at least annually. Updates are posted with a revised "Last Updated" date; changes materially affecting your rights are notified per the Privacy Policy.
15. Contact
Grievance Officer: Vishwas
Email: support@megagraphs.com
Company: Megagraphs Technologies Private Limited
Address: 105B, Bldg 3, N G Suncity, Thakur Village, Kandivali (East), Mumbai 400101, India