Back to Blog
Guides

Open banking consent: What you're agreeing to beyond the fine print

Most users skim open banking permission screens, but the consent you grant is far broader than it appears. Here's what you're actually agreeing to share and why it matters.

SubDupes Team
2026-10-02
5 min read
Open banking consent: What you're agreeing to beyond the fine print
TL;DR When you connect a financial app through open banking, the permission screen you breeze past often grants far broader data access than the headline suggests — covering years of transaction history, account metadata, and ongoing refresh rights. Most users consent to sharing far more than they realize, and understanding exactly what you're authorizing is the first step to protecting your financial privacy.

You've seen the screen. A clean, reassuring interface appears between you and the app you're trying to connect. It says something like "We'll access your account to find your transactions." You tap Allow in under three seconds, and you're in. But what you just agreed to — buried in the technical scope of that consent — is almost certainly much broader than those two dozen words implied. Open banking consent is designed to look simple, but the permissions it grants are anything but. If you're using financial apps to track spending, detect waste, or manage subscriptions, understanding what you're actually authorizing matters enormously. A subscription tracking tool that doesn't require bank login can help you get the same insights without the hidden data exposure that open banking connections often carry.


What Open Banking Actually Is — And Why It Exists

Open banking is a regulatory and technology framework that allows third-party financial applications to access your bank account data — with your consent — through standardized application programming interfaces (APIs). In the UK and EU, it's governed by the Payment Services Directive 2 (PSD2). In the US, it's been evolving under CFPB rulemaking, particularly the Personal Financial Data Rights rule finalized in late 2024. The intent is genuinely positive: give consumers the power to share their financial data with apps of their choosing, breaking banks' monopoly on that information.

The practical result is that budgeting apps, subscription trackers, lending platforms, wealth managers, and dozens of other fintech tools can pull your transaction history directly from your bank. No manual CSV exports, no hunting through statements. It's seamless — and that seamlessness is precisely what makes the consent problem so acute. When something feels effortless, our brains don't engage critical scrutiny the same way they would if the process felt weighty or complex.

Open banking was designed for consumer empowerment. But the way consent flows have been implemented in practice has created a significant gap between what users think they're agreeing to and what they're actually authorizing. This gap is not theoretical — it has real implications for your privacy, your financial data security, and the longevity of third-party access to your most sensitive personal information.


The Permission Screen Is a Summary, Not a Contract

Here's the core issue: the permission screen you see is a user experience design artifact, not a comprehensive legal disclosure. It is engineered to reduce friction and maximize conversion rates for the app asking for access. The actual scope of what's being authorized lives in the OAuth token parameters, the terms of service of the intermediary data aggregator (often a company like Plaid, TrueLayer, MX, Finicity, or Yapily), and the privacy policy of the app itself.

When you click "Connect with Plaid" or tap through an open banking OAuth flow, you may be authorizing access to:

Transaction history going back 12–24 months — or in some cases further. The screen might say "recent transactions," but the API call frequently pulls everything available in the bank's data export. That's potentially thousands of transactions revealing where you shop, what you eat, your medical spending, your political donations, your subscription habits, and much more.

Account balances across all linked accounts — not just the checking account you were thinking about. Many aggregators pull from every account visible under your credentials: savings, investment accounts linked to the same online banking portal, credit cards, and even loan accounts.

Account metadata including account numbers (in masked form), routing numbers, institution names, account types, and ownership information. This is enough data to facilitate ACH transfers and, in the wrong hands, targeted fraud.

Ongoing data refresh rights — perhaps the least understood element. Many open banking connections don't expire when you close the app or even when you think you've disconnected. Token-based access can persist for 90 days, 180 days, or longer, with silent background refreshes happening without any visible prompt to you.

PRO TIP: Check Your Active Connections, Not Just Your Apps
Deleting a financial app from your phone does NOT necessarily revoke its data access. You need to actively revoke the OAuth token either through your bank's connected apps dashboard or through the aggregator's own revocation portal. If your bank doesn't show you these connections clearly, check Plaid's data portal at my.plaid.com to see every institution and app that has ever connected through their service.

The Data Aggregator Layer Most Users Don't Know Exists

One of the most significant blind spots in open banking consent is the intermediary data aggregator. When you connect an app to your bank, you often don't realize there's a middleman. The app you're using — let's say a subscription tracker or budgeting tool — contracts with an aggregator like Plaid, TrueLayer, or Finicity. The aggregator is the entity that actually holds the OAuth connection to your bank and stores the pulled data on their servers.

This means your financial data flows to at least two companies you may not have fully considered: the app itself and the aggregator it uses. The aggregator has its own terms of service, its own data retention policies, and its own monetization strategies. Plaid, for example, settled a $58 million class action lawsuit in 2022 over allegations that it collected more financial data than users consented to and used it for purposes beyond what was disclosed. That settlement didn't require Plaid to change its core data practices — it just required a payout to affected users.

The permission screen you saw never mentioned Plaid. It showed you a clean interface with your bank's logo. The legal relationship you entered into with a data aggregator was disclosed somewhere in a terms-of-service document that virtually no one reads.

3 sec
Average time users spend reading open banking permission screens
$58M
Plaid class action settlement over alleged unauthorized data collection
24 mo
Typical transaction history window pulled through aggregator APIs
180 days
Common duration of open banking token access before required re-authorization

Regulators have been pushing for what's called granular consent — the idea that users should be able to authorize specific data types for specific purposes rather than granting broad access all at once. The UK's Financial Conduct Authority and the EU's PSD2 framework both include provisions aimed at this. The CFPB's 2024 Personal Financial Data Rights rule explicitly references the need for consumers to have clear, purposeful consent.

In practice, however, most open banking implementations use blanket consent flows. The app asks for everything it might ever need — all transaction types, all accounts, full history, plus ongoing refresh — in a single authorization step. Asking for less would require the app to re-authenticate you every time it needed a new data category, which increases friction and reduces retention. The business incentive almost always wins over the privacy-preserving alternative.

Some newer implementations are improving. Open banking providers in the UK have been piloting more granular consent UIs. But the majority of users interacting with financial apps today are working with consent flows designed years ago, optimized for conversion, not comprehension.

Data Element What Permission Screen Implies What Is Often Actually Granted
Transaction History "Recent transactions" Up to 24 months of all transactions across linked accounts
Account Scope Implied: the account you're thinking of All accounts visible under your online banking credentials
Access Duration Not mentioned Ongoing token with 90–180 day silent refresh cycles
Data Recipients The app you're using The app + its aggregator partner + potentially sub-processors
Balance Information "Your balance" Real-time balance polling across all linked accounts
Identity Data Not mentioned Name, address, email associated with the bank account

The Specific Risk for Subscription Tracking Use Cases

People connect their bank accounts to subscription tracking and expense management tools for an entirely reasonable purpose: they want to see where their money is going, catch forgotten subscriptions, and identify duplicate charges. It's a genuinely useful function. But the data footprint required to deliver that functionality is being collected at a scale and with a persistence that vastly exceeds what's needed for the job.

To identify your Netflix, Spotify, and gym memberships, an app needs to see your recurring transactions — a relatively narrow data set. It does not need to know your pharmacy purchases, your political contributions, your medical billing patterns, or the timing of your rent payments. It does not need to hold 24 months of data when most duplicate subscription detection can be accomplished in 90 days or less. And it certainly doesn't need to silently refresh that access every few months without prompting you.

The problem is that most open banking-based subscription trackers collect everything because the API gives them everything. There is no technical cost to collecting more; there is only upside (better data, more training for ML models, richer user profiles). The user bears all of the privacy risk while the company captures all of the data value.

This asymmetry is why the consent screen's brevity isn't just a UX problem — it's an ethical one. Users would make different decisions if the permission screen read: "We will pull 2 years of transactions from all your accounts, store them on our servers and those of our data aggregator partner, and refresh this access every 90 days automatically, including data about your medical expenses, charitable donations, and spending at adult websites."

PRO TIP: The "Minimum Necessary Data" Test
Before connecting any financial app to your bank, ask yourself: does this task require full account access, or just a specific data type? Subscription detection, renewal alerts, and duplicate charge identification can all be accomplished with email receipt scanning rather than bank API connections — with zero exposure of your transaction history to third-party aggregators.

What "Revoking Access" Actually Does (And Doesn't Do)

Many users assume that when they stop using an app, the connection to their bank goes away too. This is rarely true. OAuth tokens issued through open banking aggregators operate independently of the app's user-facing interface. Deleting the app, canceling your account, or even contacting customer support may not actually revoke the underlying data access token.

Furthermore, even when a token is revoked, data that has already been collected remains on the aggregator's and app's servers subject to their own retention policies. Plaid's privacy policy, for example, has historically retained transaction data for periods extending beyond the end of the user relationship. The CFPB's new rules include some provisions on data deletion rights, but enforcement is gradual and user-initiated deletion requests are still an unfamiliar concept to most people.

True data minimization — where only the data necessary for the task is collected, held for only as long as needed, and then deleted — remains aspirational in most of the open banking ecosystem. It is not the default. Users who care about their financial privacy need to actively manage their connections rather than assuming app deletion equals data deletion.


SubDupes was built with a clear philosophical position: your bank account data is yours, and a subscription tracker doesn't need it. Instead of using open banking APIs and the data aggregator layer that comes with them, SubDupes uses email receipt scanning to identify your subscriptions. Your purchase confirmations, renewal notices, and billing receipts already contain everything needed to build a complete picture of your active subscriptions — no bank connection required.

This approach means SubDupes never asks you to authorize an OAuth connection to your financial institution. There's no Plaid integration pulling 24 months of transactions. There's no background token refreshing silently every 90 days. Your bank account data stays between you and your bank, exactly where it belongs.

For users who want to understand their subscription landscape, SubDupes' duplicate detection identifies cases where you're paying for overlapping services — two cloud storage plans, a streaming service and its redundant competitor, multiple project management tools — purely from receipt and billing email analysis. The renewal alert system flags upcoming charges before they hit so you can make an informed decision about whether to continue. And the SaaS spend visibility dashboard gives you a clear view of total subscription costs without any of the privacy trade-offs that come with bank-connected alternatives.

The question isn't just "does this app work?" — it's "what am I paying in privacy to make it work?" With SubDupes, that cost is near zero. The only data analyzed is the email receipts you've already received and already stored in your inbox. No new data trail is created with banks, aggregators, or third-party financial data brokers.


Steps You Can Take Right Now to Audit Your Open Banking Exposure

If you've connected financial apps in the past and want to understand your current exposure, here's a practical audit process:

1. Check your bank's connected apps dashboard. Most major banks now provide a screen — usually under Settings or Security — showing third-party applications that have authorized access to your account. Revoke anything you no longer actively use.

2. Visit my.plaid.com. Plaid maintains a portal where you can see every institution you've ever connected through their service and which apps hold active connections. You can request data deletion directly from this portal.

3. Review TrueLayer, MX, and Finicity if applicable. If you're in the UK or Europe, TrueLayer is a common aggregator. In the US, MX and Finicity (now Mastercard Open Banking) are widely used. Each has its own user-facing portal or data rights request process.

4. Read the retention policy of apps you trust. For apps you actively want to continue using, locate their privacy policy's data retention section. How long do they keep your transaction history? What happens to your data if you close your account? These answers should inform how much trust you extend.

5. Consider alternatives that don't require bank access. For subscription tracking specifically, email-based tools can deliver equivalent results without the bank connection overhead. This isn't a compromise on functionality — it's an upgrade on privacy.

Does connecting to open banking give apps permanent access to my bank account?
Not technically permanent, but often much longer than users expect. OAuth tokens issued through open banking aggregators typically last 90 to 180 days and can be silently refreshed without prompting you. Deleting the app does not automatically revoke the token. You need to explicitly revoke access through your bank's connected apps dashboard or through the aggregator's user portal to fully terminate access.
What is a data aggregator and why does it matter for my privacy?
A data aggregator is a middleman company — like Plaid, TrueLayer, or MX — that sits between your bank and the financial app you're using. When you authorize an open banking connection, your data flows to the aggregator first, then to the app. This means at least two companies hold your financial data, each with their own retention policies and terms. The permission screen you see usually doesn't clearly disclose the aggregator's role.
Can I track my subscriptions without connecting my bank account?
Yes — and it's the privacy-preserving approach. Email receipt scanning is a proven alternative that analyzes billing confirmations and renewal notices already in your inbox to identify subscriptions, detect duplicates, and flag upcoming renewals. SubDupes uses this method exclusively, meaning no bank connection, no open banking tokens, and no data aggregator involvement is required at any point.
Does revoking open banking access delete my data from the app's servers?
Revoking access stops new data from being pulled, but it does not automatically delete data already collected. Most aggregators and apps retain historical transaction data according to their own retention schedules, which can extend months or years beyond the end of your relationship with the service. To request actual data deletion, you typically need to submit a formal data deletion request under applicable privacy law (GDPR, CCPA, etc.) through the company's privacy request process.

Track Every Subscription Without Handing Over Your Bank Access

SubDupes identifies your subscriptions, catches duplicate charges, and alerts you before renewals hit — all through email receipt analysis. No bank login required. No open banking tokens. No data aggregators watching your transactions. Just clear, private subscription visibility that respects your financial data.

Get Your Free Subscription Waste Report

Related Articles

View all articles →