← Back to Home

Privacy Policy

MoneyKeep is operated by Zeta Pegasi Labs Pte. Ltd. (UEN 202636586D), 152 Beach Road #23-02 Gateway East, Singapore 189721.

Effective: July 25, 2026 · Last updated: 30 August 2026

Information We Collect

MoneyKeep collects only the data necessary to provide personal finance tracking services: the email address or WhatsApp number you sign up with, transaction data from the bank statements and spreadsheets you upload, and the budgets, goals and accounts you configure.

If you send a voice note or use the microphone in the web app, we also process a recording of your voice. It is turned into text and then dropped — we never write it to disk and keep no copy. Only the text is saved, as part of your conversation history, and you can delete that history at any time.

Encryption

Encrypting your financial data is something you switch on, and we invite you to when you start. Once you do, your database is encrypted with AES-256-GCM using a key derived from a passphrase only you know — we hold neither the passphrase nor the key, so from that point we cannot read your data, not even our own team.

Until you switch it on, your database is not encrypted. It is protected by the access controls on our servers, but not by cryptography. This page used to say all financial data is encrypted; that was not true of an account that had not switched it on, and we would rather correct it than let it stand.

We do not make encryption compulsory, and the reason matters: the passphrase is yours alone. If we forced it, forgetting it would mean losing your data permanently with nobody able to bring it back — which is the same reason we cannot recover it for you.

How We Use Your Data

We use your data to: analyze spending, provide budget recommendations, and generate personal reports.

We never sell your data, we never rent or trade it, and we never use it for advertising or to train AI models. Running the Service does mean sending some of it to a small number of providers who work on our behalf — they are named individually below, because "we share it with no one" would not have been true.

Who We Share With

We share only what is necessary, with providers acting as processors on our behalf under contractual obligations:

Some of these providers are located outside Singapore, which means a cross-border transfer of data. By using the Service you consent to that transfer to the extent necessary to operate it. We disclose your data to no one else unless required by law or a judicial order.

What is never sent to any of them: your encryption passphrase, the keys to your financial database, and the database file itself — no processor ever receives your complete financial records. What is sent is set out above, processor by processor: the PDF statement to the extraction provider, and the transaction data needed to answer a question to the AI provider.

In the web app the text transcribed from your voice is placed in the message box for you to read, and nothing is sent until you press send. It is a proposal, not a submission: if the transcription is wrong you edit it or delete it, and words you never said never enter your record. Anything you had already typed is kept — the transcript is added to it rather than replacing it.

Statement Files

We never save the statement file you upload. It is held in memory, passed to the extraction provider, and dropped; what we keep is the transaction data extracted from it.

The file itself stays with that provider for 90 days and is then deleted. That 90 days is a setting we choose on our own mailbox there, not a schedule it imposes on us — we say so because a policy that hands a processor the responsibility for a setting its customer controls sends the reader to the wrong party to ask. Its own policy says a deleted document leaves its active systems immediately and its backups within 45 days.

Deleting Your Data

You can delete everything at any time — in the web app under Settings → Delete my account, or by sending DELETE ALL MY DATA to the bot. Both run the same code, because this product has one deletion path and no second one. Your financial database and its salt, your logins, every active session and the account record itself are removed immediately, along with the copies most products forget: if two of your accounts were ever merged, the retired side's database and the snapshot kept to make that merge reversible go too, so no readable duplicate is left anywhere.

Backups are the one exception, and we would rather state it exactly than round it off:

Backups are never opened, searched or edited to remove one account, and nothing is ever restored from them to rebuild an account you deleted; they are only ever used to bring the Service back after a failure. A backup carries exactly the encryption the live file had: if you switched encryption on, the copy is unreadable to us as well; if you did not, the copy is no better protected than the original.

Language

This policy is published in English, and the English text is the one that applies.

Changes to This Policy

Change log
30 August 2026the AI provider named in Who We Share With changed from Together AI to OpenRouter, Inc. What we do with your data did not change; who serves the model did. The model is the same open-weights DeepSeek V4 Pro build, and the commitment that your data is not stored and is not used to train models still stands — it now rests on the Zero Data Retention condition set on our OpenRouter account rather than on section 2.6 of Together's policy, which no longer describes the route your data takes and whose citation has been removed. Speech-to-text moved with the model and is covered by the same condition.

30 August 2026 — several statements were corrected because they did not match what the system does. Encryption: this page said all your financial data is encrypted; encryption is something you switch on, and an account that has not switched it on is not encrypted. It now says so. Backups: "off-site backups age out within 14 days" was true of the daily archives and not of the weekly ones, which nothing deletes; both are now stated, along with the fact that a backup carries only the encryption its source had. Hosting: the host is now named — DigitalOcean, Singapore — instead of "our hosting provider". Processors: Google sign-in, our website's content-delivery provider and the exchange-rate sources were in use and unnamed, and are now named with what each receives. Statement files and what deletion destroys now have sections of their own. None of this changed what we do with your data; it changed what this policy says about it.

24 August 2026 — voice input was added to the web app, and voice notes now reach the same AI provider named in Who We Share With. This adds a new category of personal data leaving the Service: audio recordings of your voice. They are sent to be transcribed and are covered by the same Zero Data Retention terms as your transaction data — not stored, not used for training. We do not keep the audio either: it is held in memory, transcribed, and dropped. Only the resulting text is saved, as part of your conversation history, and you can delete that history at any time.

23 August 2026 — corrected the last line of Who We Share With. It said the contents of your database are never sent to a processor in readable form, which does not square with the line three bullets above it: transaction descriptions and amounts do go to the AI provider, and always have. It now says what is actually withheld — the passphrase, the database keys and the database file — and points at what is sent.

23 August 2026 — added the Who We Share With section naming every processor individually, and corrected the sentence above it. The previous wording said we never share your data with third parties; that had never been accurate, because every statement uploaded for parsing goes to Parseur. What we do with your data has not changed — what this policy says about it has.

Contact Us

For privacy questions: info@zetapegasilabs.com