When you connect your bank account to an app, your data is accessed via tokenization, reducing security risks compared to credential sharing. Aggregators may access your data, but you can control and revoke this access at any time.
In today’s digital landscape, the question “what happens to your data when you connect your bank to an app” is more relevant than ever. This is not just a technical question; it’s a question of trust. As more people rely on financial apps to manage their money, understanding the data journey, from input to potential third-party viewing, matters. This guide walks through that process: token-based access, credential sharing, and the privacy controls you actually have.
The initial step: data entry and credentials
When you link your bank account to a financial app, the first step is entering your login credentials. Traditionally, that meant sharing sensitive information directly with the app, a method known as credential sharing. That practice is becoming outdated because of its security vulnerabilities.
Modern apps instead prefer tokenization, a safer method where your bank issues a “token” to the app that represents your access rights without exposing your actual credentials.
The role of data aggregators: the middleman explained
Once your credentials are entered, the app typically works with a data aggregator, a crucial intermediary in the exchange. Companies like Plaid and Finicity operate in this space, bridging your bank and the app. These aggregators request access from your bank using OAuth 2.0, a protocol that lets you authorise an app to access your information securely, without sharing your password.
| Aggregator | Function | Security protocol used |
|---|---|---|
| Plaid | Connects apps and financial institutions | OAuth 2.0 |
| Finicity | Provides financial data solutions | OAuth 2.0 |
| MX | Aggregates financial data | OAuth 2.0 |
As financial apps become more integral to everyday life, understanding the complexities of data flow and security mechanisms is essential for consumers. Modern practices like tokenization and secure protocols such as OAuth 2.0 are vital for safeguarding personal information. Even so, users must remain vigilant about who can access their data and take proactive steps to manage app permissions.
– Data Privacy Expert
Tokenization vs. credential sharing: a security evolution
Tokenization changes how data is accessed by replacing sensitive information with unique identifiers that carry the essential access information without exposing the underlying credentials. This significantly reduces the risk of a breach compared to credential sharing, where your actual account credentials are what gets exchanged. With tokenization, even if the data is intercepted, it can’t be used maliciously without the corresponding token. Credential sharing, by contrast, leaves your data vulnerable to interception and unauthorised use.
Who can access your data?
Once your data is shared with an app, three parties are typically involved: the app itself, the data aggregator, and potentially third-party advertisers or partners. The app and aggregator need certain fields to function (transaction details, account balances), but they shouldn’t need unnecessary personal information, like your full account number, unless there’s a clear reason. Read the privacy policy to see exactly what’s collected and who might see it.
| Party | Potential data access |
|---|---|
| App | Transaction history, account balance |
| Aggregator | All data necessary for app functionality |
| Advertisers | Limited to anonymous data (if consented) |
Revoking access: regaining control over your data
Revoking access is an often-overlooked step in the bank-linking process. You can regain control by going to your bank’s security settings or using the app’s own privacy controls to disconnect and stop the data flow. This matters if an app no longer suits your needs, or if you have concerns about how your data is handled. Many banks now offer a “linked apps” dashboard where you can see every connected service and revoke access in a couple of clicks.
If you’d rather sidestep this process altogether, a manual-entry app like Wizpend never requests bank access in the first place; there’s no token or credential to revoke because none was ever shared.
