Four stages, and the one that is actually hard.
The audit answers a narrow question — ₹875 earned against ₹2,230 achievable on the same spend with the same wallet — and the whole difficulty is in being able to defend the second number. Here is every step between your inbox and that figure.
The statement, out of the mail you already have
Every issuer sends a monthly statement to the address you signed up with. That mail is the only complete, bank-authored record of what a card did — every transaction, the reward it paid, the total it billed. Zenidhi reads it there rather than asking you to upload anything or waiting on an account-aggregator handshake.
Statement mail is parsed today for HDFC, SBI, ICICI, Axis, HSBC, IDFC FIRST. Formats differ per issuer and change without notice — a sender address moves, a subject line gets reworded, an amount stops appearing in the body and only survives in a password-protected attachment. Each of those is a parser, and each break is a bug we fix rather than a number you have to correct.
The rulebook, versioned by date
42 cards across 11 issuers, transcribed from the issuers' own terms. Not a rate per card — the whole shape of it: base earn, accelerated categories, merchant exclusions, monthly and cycle caps, per-transaction floors and rounding, and the milestone thresholds that only matter once a year.
Rules are stored against the dates they were in force, because they move. A card that paid 5X on groceries in March and 1X in April has to be replayed both ways, or a March transaction gets judged by an April rule and the answer is confidently wrong. This is the part that cannot be scraped from a comparison site, and it is the reason the audit can be checked.
The replay
Each transaction runs the same path the issuer's own system would: identify the merchant, test it against the exclusion list, resolve its category, apply the rate that category earned on that date, then draw the result down against whatever caps are still open for the cycle.
Doing it in that order matters. A cap that burned on the 12th changes what the 13th was worth, so the engine keeps a running ledger per cap rather than applying a rate to a monthly total. The same replay then runs against every other card in your wallet, which is what produces “what the best card you already hold would have earned” instead of “what card we think you should buy”.
Reconciliation, before you see any of it
Our replay produces a number. So does the bank, and it prints it on the statement. Those two are compared before a report exists — and when they disagree, the disagreement is the output rather than something smoothed away.
On the cycle printed on the homepage the bank paid 772 points and the replay said 756. The 16-point gap is not a rounding error we hid: 560 of the bank's figure was bonus earned in the previous cycle, because that card settles its accelerated earn a month late. Reconciling a total is the easy half. Knowing which month a bonus belongs to is the half that makes the total worth quoting.
What the audit will not do
- We don't recommend a card we can't derive a number for. If the rulebook has a gap for your card, the audit says so instead of estimating around it.
- We aren't paid on any card. There is no affiliate link, no issuer relationship and no referral revenue anywhere in the model, which is the only condition under which “the best card in your wallet” means anything.
- We don't move money, and we can't. The Gmail scope is read-only and there is no payment rail on our side.
- We don't claim a cohort result yet. The figures on this site are one audited wallet over one cycle, labelled as such, because a median across cardholders needs more verified months than we have.
Reading it yourself
Every line in a report cites the rule it came from and the transaction it applies to, so the arithmetic can be followed rather than trusted. If a number looks wrong, that citation is the fastest way to prove it — and a report that can be argued with is the only kind worth publishing.
What connecting Gmail grants · How we handle your data · Request access