Connecting your bank: how it works and what happens to your data
Many finance apps offer to connect your bank account. Transactions then arrive automatically instead of you typing them in. That raises fair questions: who sees my credentials? Can anyone transfer money? How long does the permission last? Here are the answers, in general and for Ausgabentracker in particular.
How the connection works technically
Since the second EU payment services directive (PSD2), banks have to provide an interface to licensed third parties. An account information service may use it to fetch balances and transactions with your explicit consent. These services need a licence and are supervised.
- You choose your bankIn the app you start the connection and choose your bank.
- Redirect to the bankYou sign in on your bank’s page or in its app, as with online banking, usually with approval in the banking app.
- Give consentThe bank asks which accounts are shared and for which period.
- Back to the appFrom now on the service can read transactions and balances of the shared accounts.
What the service may and may not do
- May: read balance and transactions of the shared accounts, i.e. booking date, amount, payee or payer and reference.
- May not: transfer money, change standing orders or see your credentials. That would need a different service and your separate approval of each payment.
- Limited: the permission expires after the period set by the bank, usually after 90 to 180 days. Then you confirm it again at the bank.
What to look out for with any finance app
- Licensed service: fetching should run through a licensed account information service, not through an app that wants to store your PIN.
- Read the privacy policy: who gets the transactions? Are they analysed or used for advertising?
- Disconnecting possible: there should always be a way to end the connection and delete the data.
- Never type your PIN into a third-party page: signing in belongs on your bank’s page or in its app.
How it is in Ausgabentracker
Ausgabentracker fetches transactions via Enable Banking, an account information service from Finland licensed under PSD2. You use your own app at Enable Banking for this; the details are in the settings under Bank connection.
- Read-only: neither Ausgabentracker nor Enable Banking receives your online banking credentials in readable form.
- Fetching: when connecting, as far back as you set and the bank allows, then automatically at most twice a day.
- You decide: fetched transactions are only booked as an expense or income after you confirm them. The app learns categories per payee from your decisions.
- AI only on request: category suggestions by AI are off until you explicitly turn them on.
- Disconnect: ends the session and deletes transactions not booked yet; booked entries stay.
- No advertising, no sharing: the data is stored on this installation’s server. Everything else is in the privacy policy.
The bank connection is included from the Plus plan. Everything else works without it: you then enter expenses yourself or import them via CSV.
- Transactions and balances automatically, read-only
- Import with learned categories per payee
- Balance history from the fetched balances

Frequently asked questions
Is this safer than screen scraping? Yes. With screen scraping you give an app your PIN and the app signs in with it itself. With PSD2 interfaces you sign in directly at the bank, and the service only gets limited, read-only access.
What happens when the permission expires? No new transactions arrive. Entries already fetched and booked stay. You renew the permission by signing in at the bank again and consenting.
Can I share just one account? With most banks you choose during consent which accounts are shared. Everything else stays invisible to the service.
What if my bank is missing? Then the CSV import helps. It works with the transaction export of almost any bank.
