securitybudgeting appspersonal finance

What Happens to Your Data When You Connect Your Bank to an App: A Comprehensive Guide

When you link your bank to an app, tokenization and aggregators like Plaid handle the data exchange. Here's exactly what happens, and how to control access.

By Wizpend Team3 min read
What Happens to Your Data When You Connect Your Bank to an App: A Comprehensive Guide

When you connect your bank account to an app, your data is accessed via tokenization, reducing security risks compared to credential sharing. Aggregators may access your data, but you can control and revoke this access at any time.

In today’s digital landscape, the question “what happens to your data when you connect your bank to an app” is more relevant than ever. This is not just a technical question; it’s a question of trust. As more people rely on financial apps to manage their money, understanding the data journey, from input to potential third-party viewing, matters. This guide walks through that process: token-based access, credential sharing, and the privacy controls you actually have.

The initial step: data entry and credentials

When you link your bank account to a financial app, the first step is entering your login credentials. Traditionally, that meant sharing sensitive information directly with the app, a method known as credential sharing. That practice is becoming outdated because of its security vulnerabilities.

Modern apps instead prefer tokenization, a safer method where your bank issues a “token” to the app that represents your access rights without exposing your actual credentials.

The role of data aggregators: the middleman explained

Once your credentials are entered, the app typically works with a data aggregator, a crucial intermediary in the exchange. Companies like Plaid and Finicity operate in this space, bridging your bank and the app. These aggregators request access from your bank using OAuth 2.0, a protocol that lets you authorise an app to access your information securely, without sharing your password.

Aggregator Function Security protocol used
Plaid Connects apps and financial institutions OAuth 2.0
Finicity Provides financial data solutions OAuth 2.0
MX Aggregates financial data OAuth 2.0

As financial apps become more integral to everyday life, understanding the complexities of data flow and security mechanisms is essential for consumers. Modern practices like tokenization and secure protocols such as OAuth 2.0 are vital for safeguarding personal information. Even so, users must remain vigilant about who can access their data and take proactive steps to manage app permissions.

– Data Privacy Expert

Tokenization vs. credential sharing: a security evolution

Tokenization changes how data is accessed by replacing sensitive information with unique identifiers that carry the essential access information without exposing the underlying credentials. This significantly reduces the risk of a breach compared to credential sharing, where your actual account credentials are what gets exchanged. With tokenization, even if the data is intercepted, it can’t be used maliciously without the corresponding token. Credential sharing, by contrast, leaves your data vulnerable to interception and unauthorised use.

Who can access your data?

Once your data is shared with an app, three parties are typically involved: the app itself, the data aggregator, and potentially third-party advertisers or partners. The app and aggregator need certain fields to function (transaction details, account balances), but they shouldn’t need unnecessary personal information, like your full account number, unless there’s a clear reason. Read the privacy policy to see exactly what’s collected and who might see it.

Party Potential data access
App Transaction history, account balance
Aggregator All data necessary for app functionality
Advertisers Limited to anonymous data (if consented)

Revoking access: regaining control over your data

Revoking access is an often-overlooked step in the bank-linking process. You can regain control by going to your bank’s security settings or using the app’s own privacy controls to disconnect and stop the data flow. This matters if an app no longer suits your needs, or if you have concerns about how your data is handled. Many banks now offer a “linked apps” dashboard where you can see every connected service and revoke access in a couple of clicks.

If you’d rather sidestep this process altogether, a manual-entry app like Wizpend never requests bank access in the first place; there’s no token or credential to revoke because none was ever shared.

Frequently asked questions

Is it safer to use tokenization or credential sharing?

Tokenization is safer. It gives an app a revocable token that represents your access rights instead of your actual bank credentials, so even if the token is intercepted, it can't be used the way a stolen password could. Credential sharing exposes your real login details to a third party.

Can third-party advertisers see my banking data?

Advertisers generally shouldn't see your raw banking data. If an app shares data with advertisers at all, it's typically limited to anonymised or aggregated data, and usually only with your consent. Check the app's privacy policy to see exactly what, if anything, is shared and with whom.

How can I revoke access to my bank account from an app?

Most banks have a 'linked apps' or 'connected services' dashboard in their security settings where you can see every app with access and revoke it directly. Many apps also let you disconnect a linked account from within their own privacy or account settings.

What is the role of data aggregators like Plaid?

Aggregators like Plaid, Finicity, and MX act as the middleman between your bank and the app you're using. They request access via a secure protocol (typically OAuth 2.0), retrieve the data the app needs, and pass it along, so the app itself doesn't have to build a direct connection to every bank.

Does an app require my full account number to function?

Usually not. Most budgeting and finance apps only need transaction history and account balances to work. If an app requests more than that, like your full account number when it's not needed, treat it as a red flag worth investigating.

Related articles