How forwarding works
You set up a forwarding rule in your own email client — the same feature your email provider already offers. Every bank alert you forward lands at a private MoneyMochi address created just for you.
Mail sent to an address that doesn't exist in our system is rejected at the mail server level, before anything is stored. Mail that reaches your address but doesn't verify as coming from a recognised bank — DBS/POSB, OCBC, UOB, Citibank, StanChart, HSBC, Trust, Maybank, or AMEX — is never turned into a transaction. Instead, it's kept for 90 days like all raw email, shown to you as an ignored count in the app, then permanently purged.
How we check it's really your bank
Every bank alert carries a digital signature — called DKIM — added by the bank that sent it. It works like a wax seal: if the email is altered after the bank signs it, the seal breaks.
We check that this signature survives your forwarding rule. When it does, we know the alert genuinely came from your bank, not a look-alike scam address, even after passing through your inbox. Alerts where the signature doesn't check out are still processed, but flagged and shown to you at a lower trust level — never silently trusted.
What we store, and for how long
| We collect | What happens to it |
|---|---|
| Merchant, amount, date, category | Kept indefinitely, as your transaction history — until you delete your account. |
| Card issuer + last 4 digits | That's all we ever store about a card. Our database has no column that could even hold a full card number. |
| The original forwarded email | Kept 90 days so a transaction can be re-checked or re-parsed, then permanently deleted. |
| Your online banking login | Never collected. Never stored. We don't have a field for it. |
Your rights under Singapore's PDPA
MoneyMochi is built with Singapore's Personal Data Protection Act in mind, and our primary data store lives in Singapore. You can export everything as a CSV, or delete your account, at any time from Settings.
Account deletion is confirmed by typing your email address, then held for 7 days — an emailed undo window — before it's permanently carried out.
For the full picture of what we collect, why, and who we share it with, see our privacy policy.
The pledge
We will never ask for your online banking username or password — in the app, by email, or over the phone. If anyone claiming to be MoneyMochi ever does, it isn't us.