Privacy Policy
Last updated: 1 July 2026 · Version 2026-07-01
This notice explains, in plain language, how MoneyMistri collects and uses personal data. It is written to meet India's Digital Personal Data Protection Act, 2023 (the “DPDP Act”). For the data you upload about your own vendors and customers, you are the data fiduciary and MoneyMistri acts as your processor — we handle it only to run the service for you.
What we collect
- Account details — your name and email from Google sign-in, your mobile number, and the business details you add (company name, GSTIN, Tally configuration).
- Documents you upload — invoice, bill, and bank-statement files (PDFs, images, spreadsheets) and the structured data extracted from them, which can include third parties' names, addresses, GSTINs, PANs, and bank details.
- Usage records — actions inside the app (uploads, reviews, exports, sync events) kept as an audit trail of changes to your books.
- Contact submissions — what you send via the contact form so we can respond.
Why we use it
- To run the service — read your bills, extract and validate fields, and prepare Tally-compatible vouchers.
- To keep your books — store the structured accounting data you review, export, and sync.
- To reach you — account, billing, and support messages, and to notify you in the unlikely event of a data breach.
- To keep things secure and accountable — an audit trail of changes and abuse prevention.
We only process your data for these purposes, on the consent you give at sign-up. We do not process it for anything you have not been told about here.
How your documents are processed
When you upload a bill, its content is sent to Google Gemini (via the OpenRouter gateway) to extract the fields (vendor, GSTIN, amounts, line items). This is automated processing for the single purpose of reading your document. It runs under a data-processing agreement with zero-data-retention routing, so your documents are not stored by, or used to train, the AI model. Extracted data is then validated and stored in your account. This processing may happen on servers outside India; cross-border processing for this purpose is permitted under the DPDP Act.
Where your data lives
Your account and accounting data is stored in India (Supabase Postgres, Mumbai region). Authentication is handled by Supabase Auth with Google sign-in. All traffic is encrypted in transit (HTTPS). We use a small number of established infrastructure providers, each under a data-processing agreement:
- Supabase — database and authentication (Mumbai, India).
- Google (Gemini via OpenRouter) — invoice-field extraction, zero data retention.
- Vercel — serves the web app.
- Cloudflare R2 — stores uploaded files and generated exports.
The desktop connector talks to our servers over HTTPS and to your Tally Prime only on your own computer — MoneyMistri never reaches into your Tally on its own.
How long we keep things
We keep your uploaded bills and the accounting data built from them for as long as your account is open, so your books stay complete and you can meet your own record-keeping duties (GST law generally requires businesses to keep records for several years). Audit logs are kept for one year. When you delete your account, we permanently erase your personal data after a short grace window — see your rights below. We may retain the minimum records we are legally required to keep (for example, our own invoicing records).
Your rights under the DPDP Act
- Access — get a copy of the personal data we hold about you. You can download your data from your account settings.
- Correction — fix data that is wrong or out of date, from your account or by asking us.
- Erasure — delete your account and data from your account settings (a short grace window lets you undo it before the erase is final).
- Withdraw consent — withdraw your consent at any time; it is as easy to withdraw as it was to give. Withdrawing stops further processing.
- Grievance redressal — raise any concern with our Grievance Officer (below) and get a response within 90 days.
- Nominate — nominate someone to exercise your rights if you are unable to (contact us to arrange this).
To exercise any right, use your account settings where available, or write to our Grievance Officer. We respond to rights requests within the timelines the DPDP Act requires.
Grievance Officer
Our Grievance Officer handles privacy questions, rights requests, and complaints:
Himanshu Bhatnagar, Grievance Officer, MoneyMistri
Email: support@moneymistri.com
We acknowledge and respond within 90 days.
If you are not satisfied with our response, you may complain to the Data Protection Board of India.
What we never do
- We never sell your data.
- We never share your documents or financials with advertisers or data brokers.
- We never let AI providers store or train on your documents.
- We never use your data for anything other than the purposes above.
Cookies
We use cookies only to keep you signed in and to remember your onboarding state. There are no advertising or cross-site tracking cookies.
Changes to this policy
If we make a material change, we will update the version above and ask you to review and agree again the next time you sign in. The version you consented to is recorded against your account.