Frequently Asked Questions
Moneylizer — m360 Operated by Megagraphs Technologies Private Limited
Last updated: August 12, 2026
Getting started
1. What is Moneylizer?
Moneylizer is a personal finance platform that brings all your bank and credit card statements into one place, extracts every transaction from them, and helps you understand where your money actually goes. Instead of logging into six different bank portals and squinting at six different PDF layouts, you upload your statements once and get a single, searchable, categorized view of your financial life. We are built around a simple commitment: your financial data is yours, we do not monetize it, and we do not show advertisements.
2. What is m360, and will there be other modules?
Moneylizer is organized into modules, and m360 is the first one. It handles financial statement ingestion, transaction extraction, categorization, labelling, and the net worth vs. liability dashboard. It is the module you interact with today. We have additional modules planned that will extend the platform in other directions, and unless we tell you otherwise at the point of collection, they will be governed by the same Privacy Policy. If a new module ever introduces a genuinely new type of data processing, we will update the policy and, where the law requires it, ask for your fresh consent before switching it on.
3. What does it cost?
m360 is free while in early access. What we can commit to permanently is the revenue model we will not use: we do not sell your data, we do not rent or license it, we do not show ads, and we do not act as a lead-generation channel for lenders, brokers, or credit bureaus. Whatever we charge, we charge you directly and transparently, so that our incentives and yours point in the same direction.
4. Which banks and card issuers are supported?
We support statements from several leading Indian banks (see the current list of Supported FIs). Support is per statement format rather than per bank, so a bank may be fully supported for its savings account statement and still be in progress for its credit card statement. If your bank is not on the list, you can still upload the file. In many cases it will parse correctly anyway, and if it does not, tell us and we will add the format. Coverage grows steadily, and requests from users are the main thing that decides what we build next.
5. Do I need to sign up with Google, or can I use email?
Today, sign-in is through Google OAuth. We chose this deliberately: it means you never create another password, and it means we never receive or store your Google account password. We plan to add other providers such as Apple or Microsoft in future, and if we do, we will update the Privacy Policy to reflect it. Note that signing in with Google is entirely separate from the optional Gmail integration described below. Signing in via Google gives us your name, email address, and profile picture, and nothing more.
6. What can I actually do on day one, with one statement uploaded?
Quite a lot. A single (supported) statement gives you every transaction in it, extracted and categorized, with the ability to search, filter, relabel, and annotate. You can see how that month broke down by category. The platform gets substantially more useful as you add more accounts and more months, because that is when trends, category comparisons, and net worth movement become meaningful, but you do not have to upload your entire financial history before you see value.
Statements and uploads
7. What file formats can I upload?
We accept PDF and Excel (XLSX) statements: the two formats Indian banks and card issuers actually send. Both password-protected and unprotected files are fine. We work from the statement as issued by your bank, which means you do not need to convert, re-save, or clean up anything before uploading. Scanned or photographed statements are a different matter: because they are images rather than structured documents, they may not parse reliably. If your bank only issues scans, get in touch and we will tell you where we stand on that format.
8. My statement is password-protected, what do I do?
Just supply the password when you upload. Indian banks almost universally protect statement PDFs, typically with some combination of your date of birth, name, account number, or PAN. You input the password to unlock statements on our platform, we use it to unlock the file and extract the transactions. Because these passwords are sensitive credentials in their own right, we store them encrypted in a dedicated keyring with restricted access so that future statements from the same source unlock automatically and you do not have to keep re-entering them. You can delete any stored password at any time.
9. What is the master password, and why do you re-key my PDFs?
Every bank uses a different password rule, which makes your own archive of statements almost unusable. You cannot open your own documents without remembering which rule applied to which file, wasting time each time you want to see your statements. So once we have unlocked and extracted a statement, we remove the original password from the stored copy and apply a single master password, unique to your account, to all your stored financial documents. From then on, one password opens everything of yours that we hold. The same master password protects the file you get when you export your data, which means your exported archive is encrypted the moment it leaves us.
10. What happens if I lose my master password?
We cannot recover it. That is a consequence of the way it is designed rather than an oversight; a master password we could recover would be a master password we could read. What we can do is help you reset it through an authenticated session, so that your stored documents are re-keyed to a new master password of your choosing. What we cannot do is decrypt an already-exported file for you after the fact. Treat your master password the way you would treat the password to a password manager: store it somewhere you trust and will not lose.
11. Can I upload statements from years ago? Is there a limit on history?
Yes, and older statements are genuinely worth uploading; historical data is what makes trends, year-on-year comparisons, and net worth movement meaningful. At present we do not have any limit on how many statements a user can upload. The practical constraint is usually your bank rather than us: most Indian banks only let you download statements going back a limited number of years through internet banking, though many will issue older ones on request. Upload them in any order; we sort transactions by date, not by when you uploaded them. Currently, we also support fetching the statements from certain email providers like Gmail and Outlook.
12. What if my bank's statement format isn't parsed correctly?
Tell us. Statement layouts change without warning — banks redesign them, add columns, shift date formats — and when that happens the parser needs updating. Report it through the in-app option or write to us, and we will look at the format and fix it. In the meantime, do not assume a partially parsed statement is silently corrupting your data: you can remove the statement and its transactions from your account and re-upload once the format is supported. Format reports from users are one of the most useful things we receive, so please do send them.
13. Can I delete a statement I uploaded by mistake? Does that remove its transactions?
Yes, and yes. Deleting a statement removes the stored file along with the transactions that were extracted from it, so you do not end up with orphaned entries polluting your totals. This is the right move if you upload the wrong file, upload the same statement twice, or upload a statement for an account you did not mean to include. Deleting a statement does not touch your account, your other statements, or the community labels that other users have contributed — those exist at the transaction-description level and belong to everyone. Our system puts a check on ingesting financial statements of others into your account; many users receive their parents financial statements in their Inbox, we skip that once we could read them and start labelling them differently in your Inbox.
14. Do you support joint accounts, multiple accounts, or multiple people in one household?
Multiple accounts, yes — that is the entire point of the platform. Upload statements from as many banks, cards, and accounts as you like, and they consolidate into one view. Joint accounts work too, in the sense that a joint account statement is just a statement; it will be attributed to whoever's account uploaded it. What we do not currently offer is a shared household view where two people pool their data into one dashboard while keeping separate logins. We follow one simple rule: without consent; do not process! If you need a joint view, both parties must consent with a strict timeline of expiry of the consent.
Gmail/Outlook integration
15. What exactly does Moneylizer read from my Gmail/Outlook?
Only emails that satisfy two conditions at once: the sender is on a pre-defined allowlist of known statement-issuing senders — banks, brokers, and card issuers — and the email carries a file attachment (PDF/XLS statement) OR has transaction confirmation like credit card payment. An email with an attachment from anyone not on the allowlist does not qualify. Everything else in your inbox is never accessed, read, scanned, indexed, or stored. From qualifying emails we download only the attachment itself; we do not keep the email body beyond what is needed to associate the attachment with where it came from.
16. Why do you need Gmail/Outlook access at all — can I skip it?
You can absolutely skip it and opt for either manual upload for email forwarding option. The Gmail/Outlook integration exists purely for convenience: most banks email your statement to you every month, so letting us fetch those attachments automatically saves you the monthly ritual of downloading a file and re-uploading it. If you would rather not grant the permission, upload manually and the platform works identically in every other respect. Nothing is gated behind Gmail access. You can also enable it now and revoke it later, or the reverse, without losing any data you have already ingested.
17. Which senders are on the allowlist, and can I add my own?
The allowlist consists of the official statement-sending addresses of the banks, card issuers, and brokers we support — the specific no-reply and statements addresses those institutions actually send from. The allowlist is deliberately narrow (you can see the list under Settings) rather than pattern-based, because a loose rule like "anything from a domain containing bank" would widen access far beyond what the feature needs. If your institution sends statements from an address we do not yet recognise, tell us and we will review it.
18. How do I revoke Gmail/Outlook access?
Two ways, and both work immediately. You can turn the integration off from within Moneylizer, or you can revoke it directly from your Account's security settings, under the list of third-party apps with account access. Revoking through Google/Outlook is the belt-and-braces option, since it cuts the token off at the source regardless of what any application does. Revoking access stops all future fetching; statements already ingested stay in your account unless you delete them separately.
19. Do you store my emails?
No. We download qualifying attachments and retain enough context to know which email a given statement arrived in, so that you can see where a statement came from. We do not store your inbox, your email bodies, your contacts, or your mail metadata generally. Our use of information received from Google/Outlook APIs adheres to the Google/Outlook API Services User Data Policy, including its Limited Use requirements. We do not use Gmail/Outlook data for advertising, we do not transfer or sell it, and humans do not read it except with your explicit consent for a specific “support” message. Once the support ticket is resolved, we delete the associated data too.
Privacy and security
20. Do you sell my data?
No. We do not sell, rent, license, or otherwise monetize your personal data or your financial data in any form, and we do not share your transactions with marketers, data brokers, lenders, credit bureaus, or any other third party for commercial purposes. This is not a "not currently" — it is THE business model. A personal finance platform that sells its users' spending data is not really working for its users, and we would rather charge you honestly than pretend the service is free while selling what you upload. In fact, Moneylizer is a service guided by the state-of-the-art research in PETs (Privacy Enhancing Technologies) domain; borrowing heavily from the latest research findings and testing the limits of privacy-preserving computation. So, feel assured, our aim is not to monetize you but to design something that guarantees that it cannot be done.
21. Do you show ads?
No. Moneylizer displays no advertisements, and we do not use your data to target ads anywhere else. There is a particular flavour of dishonesty in an app that knows every restaurant you eat at and every SIP you hold, and then sells that knowledge to whoever wants to sell you something. We are not building that. Ironically, the Internet (in collective sense) knows about you more than you know yourself; and almost all of it is related to your financial status. Moneylizer is a system that helps you know what THEY know about you; so you too can start making better decisions. We repeat: no ads, no user monetization.
22. Do you use AI or LLMs on my financial data?
No. Moneylizer currently uses no large language models, and we do not use your financial data to train any machine learning model. Categorization is rule-based and community-driven, not model-driven. We do not intend to change this in the foreseeable future, and if it ever does change, we will update our Privacy Policy and obtain fresh consent before using your data for any such purpose — not bury it in a policy update and treat your continued use as agreement.
23. Where is my data stored?
All of it is hosted on Amazon Web Services in the India region. Your personal data does not leave India in the ordinary course of operations. Everything is encrypted in transit using TLS and encrypted at rest using AWS KMS-managed keys: statement files, transaction records, and the password keyring alike. The keyring holding your PDF passwords sits in its own encrypted store with separately restricted access, because credentials warrant a higher bar than the documents they open.
24. Who at Moneylizer can see my transactions?
Access to production data is restricted to authorized engineering personnel, governed by role-based access control, audit logging, and the principle of least privilege — meaning access is granted for a specific operational reason, not held standing by default, and it leaves a record. In practice, the situations where a human would look at your data are debugging a parsing failure you have reported, investigating abuse or a security incident, or complying with a lawful request, which we will intimate to affected users. We are also working towards an architecture that reduces this exposure further; see the next question.
25. Do you ever ask for my net-banking password?
Never. We do not collect or store net-banking credentials, we do not have any mechanism to log into your bank, and we cannot initiate a transaction on your behalf. The only password we ask for is the one that opens a statement PDF you are uploading, and that is a document password, not an account credential, which grants the ability to read a file you already possess, and nothing more. If anything claiming to be Moneylizer ever asks for your net-banking login, it is not us; please report it to us immediately.
26. What is "privacy-first architecture" and what does it mean in practice today?
It is a specific engineering goal: an architecture in which no single internal process is capable of identifying an individual user by combining the data available to it. Splitting identity, documents, and transactions such that no one component holds enough to reconstruct a person. We want to be precise about status — this is a commitment we are building towards, not something we claim to have finished. Today your data is protected by the encryption, isolation, and access controls described above. As we ship pieces of the deeper architecture, we will describe them here rather than quietly implying we had them all along.
27. What happens if there's a data breach?
No system is perfectly secure, and we would rather say so than promise otherwise. If we become aware of a personal data breach affecting you, we will notify you and the Data Protection Board of India in accordance with the DPDP Act and the rules under it. Our disclosure will tell you what was affected, what we know about how it happened, and what you should do — on the timeline the law prescribes, not when it becomes convenient for us.
28. Are you an RBI-regulated entity or an account aggregator?
No. Moneylizer is not a bank, an NBFC, an account aggregator, or any other RBI-regulated financial entity, and we do not hold funds, execute transactions, or provide investment advice. We are a document and data tool: you give us statements you already have, and we make them legible, meaningful, understandable, and actionable. Our primary regulatory framework is the Digital Personal Data Protection Act, 2023, which governs how we handle your personal data. If we ever pursue a regulated capability, that would be a material change and we would say so clearly.
Categorization and labels
29. How does auto-categorization work?
Every transaction carries a description string from your bank, and categorization works off that description. There are three sources for any given category assignment. System categories come from our own rules, covering the descriptions that are unambiguous across all users. User-proposed categories come from the community: someone proposes a category for a description, others vote, and accepted proposals apply broadly. Self-categorized entries are your own corrections. Each transaction shows which of these it came from, so you always know whether a label is ours, the community's, or yours.
30. A transaction was categorized wrongly — how do I fix it?
Recategorize it directly. Self-categorization is available for transactions that appear only once in your history — the case where there is no community consensus to override. Your correction then applies automatically to every matching description within your own account, including future ones, so you fix it once rather than every month. If a description already carries a community-accepted category that you disagree with, the route is the voting mechanism described below rather than a private override, since that category is shared across users.
31. If I recategorize something, does it change for other users?
Sometimes, and this is worth understanding. A self-categorization is scoped either as personal — applying only within your account — or rippled, where it also propagates to other users who have transactions with the same description. Rippling happens silently, without your identity attached: what travels is the mapping from a description to a category, not anything about you. This is what makes the system get better for everyone as it is used. Nothing about the transaction itself — amount, date, your account, your notes — is ever shared.
32. What's the difference between a category, a community label, and a location label?
A category is the functional classification of a transaction: Food, Travel, SIP, Shopping, Education. A community label is a single lowercase word that names who the merchant actually is, so an unintelligible bank description becomes recognisable. Labels are one-word long: dashes are allowed for compound names, but it is one word, which keeps the shared vocabulary consistent rather than sprawling. A location label places the merchant, either hierarchically or via a Google Maps place ID. All three attach at the transaction-description group level rather than to your individual transaction, which is exactly why one person's work benefits everyone.
33. What are personal notes, and can anyone else see them?
A personal note is a private annotation of up to 160 characters that you attach to a transaction, for example; "Ravi's birthday gift", "reimbursable, submitted 12th". They are private to your account, full stop. They are never shared with other users, never surfaced in the community label system, never used to generate categories, and never included in analytics. The 160-character limit is deliberate: notes are meant to be a memory aid, not a second place your financial life accumulates.
34. Who approves community labels, and how long does it take?
Other users do, by voting. There is no editorial board and no Moneylizer employee approving submissions. A proposed label becomes established once enough other users have accepted it, which is why the system rewards proposers only after a label has cleared the ten-user threshold described below. How long that takes depends entirely on how common the merchant is; a widely used vendor might be labelled within days, an obscure local one might sit unlabelled for a long time. Both outcomes are fine; the system is designed to be patient.
35. Can I see who proposed a label?
No. Labels are attributed to the community, not to individuals, and proposers are not identified to voters. This is intentional in both directions: it keeps voting focused on whether a label is correct rather than on who wrote it, and it means contributing does not expose anything about you to other users. Relatedly, if you downvote a label, that label is suppressed for you specifically, and the transaction reopens for new proposals, so a label you reject does not keep reappearing in your view.
Tokens and community
36. What are tokens and what are they for?
Tokens are how we recognise the work of labelling. Turning POS 4176*XXXX BLR IN into something a human can read takes a person who happens to know what that merchant is, and that person is doing something useful for every other user who will ever see the same description. Tokens are the record of that contribution. They are held in an append-only ledger — entries are added, never rewritten — with a running balance materialized from it, so that your contribution history is auditable rather than a number that can quietly change.
37. How do I earn tokens?
By proposing a label that the community accepts. Specifically, a reward is issued when your proposed label has been accepted by at least ten other users — a threshold high enough that a label has to be genuinely right, not merely plausible, before it counts. Rewards are keyed to the label itself and issued idempotently, meaning a given accepted label pays out exactly once no matter how the acceptance count is recalculated. There is no reward for volume: proposing a hundred labels nobody accepts earns nothing.
38. Why can't I vote on my own label proposal?
Because a system where you can vote for yourself is a system that measures enthusiasm rather than accuracy. Proposers are given no voting controls on their own proposals, and there are hard guards in the reward logic to prevent self-voting from contributing to the acceptance count. The ten-user threshold is meant to represent ten independent people agreeing with you, and it only means that if you are not one of them.
39. Do tokens have monetary value?
No, not in terms of legal currency. Tokens are a recognition mechanism within Moneylizer. They are not a cryptocurrency, not a security, not redeemable for cash, and not transferable between users. If we ever attach benefits to them, we will describe exactly what those benefits are before doing so.
Dashboard and net worth
40. How is my net worth calculated?
Net worth is assets minus liabilities at a point in time. The dashboard's main visualization is a waterfall: your assets stack up, your liabilities pull back down, and what remains is your net worth — so you can see not just the number but what produced it. Underneath, this requires a different kind of data than the rest of the platform. Your transactions describe flow — money moving — whereas net worth needs holdings at a moment. So we take periodic snapshots of your positions, and it is those snapshots, not your transaction history, that the net worth figures are built from.
41. Where do you get asset values like mutual funds, gold, or property from?
The asset taxonomy covers savings balances, fixed deposits, mutual funds, equities, bonds, property, and gold, and it maps onto the same Category and Sub-Category structure that m360 (our transaction categorization engine) already uses for transactions, so assets are not a bolted-on second system. Values that appear in your statements can be picked up from them; values that do not exist in any statement — the market value of a flat, for instance — necessarily come from you. Anything you enter yourself is worth revisiting periodically, since a stale valuation quietly distorts everything downstream of it.
42. Does "liabilities" mean my EMI or my outstanding loan amount?
Your outstanding principal — the amount you still owe — not your monthly EMI. This distinction matters more than it might seem. An EMI is a cash flow; the outstanding balance is a debt. Subtracting your monthly EMI from your assets would produce a number that looks encouraging and means nothing. So a home loan with ₹40 lakh remaining reduces your net worth by ₹40 lakh, regardless of whether the EMI is ₹35,000 or ₹50,000. The EMI shows up where it belongs: in your transactions, as monthly outflow.
43. Why does my net worth history start only from when I joined?
Because net worth requires a snapshot of what you held at a given moment, and we can only take snapshots from the point we start observing. Reconstructing your net worth on a date before you joined would mean inferring what you owned and owed then — from incomplete records, without knowing the market values that applied — and the resulting chart would look authoritative while being largely invented. We would rather show you a short honest history that lengthens every month than a long fictional one. Uploading historical statements does improve the picture, but the trend line genuinely begins where the data does.
44. How often does the dashboard update?
Transaction views update as soon as a statement is processed, so uploading a statement changes your spending picture immediately. Net worth works on a different cadence: because it depends on point-in-time snapshots, the trend is built from a scheduled snapshot taken monthly, which is why the trend line advances in steps rather than continuously. The twelve-month trend, range controls, and sliding-window views on the dashboard all read from that same snapshot series.
Account and data control
45. How do I export my data?
From your account, at any time, without asking us. The export produces a downloadable file containing your transactions, protected with your account's master password. This is a real export, not a gesture: the point is that you hold a complete, usable copy of your own data outside Moneylizer, so that staying with us is a choice rather than a consequence of your data being stuck here. Remember that we cannot decrypt the exported file for you afterwards, so keep the master password safe.
46. How do I delete my account, and what happens to my data?
There is an in-app deletion flow under Settings. When you use it, we delete your statements, transactions, labels, notes, keyring entries, and OAuth tokens within 30 days (upper bound) or earlier depending upon the time required to execute our scripts. We send a summary email to you once the account deletion process is complete. The exception is data we are legally required to retain, for example under tax, anti-money-laundering, or law-enforcement obligations; in that case we retain only the legally required minimum, for the legally mandated period, and nothing beyond it. Community labels you proposed remain, since they belong to the shared vocabulary and carry no identifying link back to you.
47. How long do you keep data after deletion?
Active deletion completes within 30 days. Beyond that, residual copies persist in encrypted, time-limited backups until they age out on the standard backup rotation — this is a consequence of having backups at all, and any provider claiming instant total erasure either has no backups or is being imprecise. Backups are encrypted and are not used to resurrect deleted accounts. Analytics events, which are aggregated or anonymized and never contain your statement or transaction contents, are retained in that aggregated form.
48. Can I withdraw consent for one feature without deleting everything?
Yes. Consent is not all-or-nothing. You can revoke the Gmail/Outlook integration and continue uploading manually. You can delete stored PDF passwords from the keyring and re-enter them per statement instead. You can delete individual statements without touching the rest. Withdrawing consent for core processing — statement ingestion itself — means we can no longer provide that feature, which is unavoidable, but it does not affect the lawfulness of processing already done, and it does not force you to delete your account.
49. How do I raise a privacy complaint?
Write to our Grievance Officer, Vishwas, at support@megagraphs.com, or use the in-app controls in your account settings. Under the DPDP Act you have the right to access a summary of the personal data we hold about you, correct or complete it, erase it subject to legal retention, withdraw consent, and nominate someone to exercise these rights on your behalf in the event of your death or incapacity. We will respond within the timeline the law prescribes. If our response does not satisfy you, you may escalate to the Data Protection Board of India.
For full details of how we handle your data, see our Privacy Policy.