DRAFT — pending founder legal review.This page describes our intended approach in plain language, but hasn't been signed off by a lawyer yet. Don't treat it as final until this banner is gone.

Privacy Policy

Last updated: 26 July 2026

1. Who this policy covers

This policy explains how MoneyMochi ("we", "us") collects, uses, and protects the personal data of anyone who creates a MoneyMochi account ("you"). MoneyMochi is a Singapore-focused product built around Singapore's Personal Data Protection Act (PDPA).

2. What we collect

  • Account information: your name and email address, from Google sign-in or email one-time-code sign-in.
  • Forwarded bank alert emails: the raw email you forward to your MoneyMochi address, kept for 90 days.
  • Transaction data: merchant, amount, date, card issuer and last 4 digits, and category — extracted from the emails above.
  • Household data: who's in your household and their role, if you use MoneyMochi with family.
  • Billing data: handled by Stripe on our behalf — we never see or store your card number.

We never collect your online banking username, password, or any other bank login credential. There is no way to give it to us even if you wanted to.

3. Why we collect it

We collect only what's needed to run MoneyMochi: turning your forwarded bank alerts into a transaction ledger, sharing that ledger with the household you choose to join, billing your subscription, and keeping the service secure and working. We don't use your data for advertising, and we don't sell it.

4. Who we share it with

We use a small number of service providers ("processors") to run MoneyMochi. Each one only receives the data it needs to do its specific job:

MoneyMochi's data processors and their roles
ProcessorWhat they do for us
VercelHosts the MoneyMochi web app.
CloudflareReceives forwarded bank alert emails at your ingest address.
InngestRuns the background jobs that parse alerts into transactions.
StripeHandles subscription billing. Never sees your bank data.
Google (Gemini)Reads forwarded email text to extract transaction details.
NeonHosts our Postgres database, in the Singapore region.
SentryReports application errors so we can fix bugs quickly.

5. How long we keep it

  • The raw forwarded email is kept 90 days, then permanently purged.
  • Extracted transaction data is kept for as long as your account is active, so your history stays complete.
  • If your subscription lapses, your data is never deleted — the app becomes read-only until you resubscribe.
  • If you delete your account, we hold the deletion for 7 days (in case you change your mind), then permanently remove your account, your cards, and your transactions — including your share of a household's data.

6. Your rights and choices

You can access and export your data (CSV) at any time from Settings. You can correct inaccurate transaction details yourself in the app. You can withdraw consent and delete your account at any time, also from Settings. If you'd rather not use email for a request like this, you can reach us using the contact details below.

7. Where your data lives

Our primary database runs in a Singapore data-region. Some processors above (Vercel, Google, Sentry) operate global infrastructure that may process data outside Singapore as part of delivering their service to us; we choose processors that meet industry-standard security and confidentiality commitments.

8. Changes to this policy

If we make a material change to this policy, we'll let you know by email before it takes effect.

9. Contact and our Data Protection Officer

MoneyMochi's founder acts as our Data Protection Officer. You can reach us at privacy@moneymochi.app (placeholder contact — final details pending founder legal review, see banner above) for any question about this policy or your data.