Learn
Can a budgeting app move your money? Read-only access explained
By the My AI Fin App team · Updated October 3, 2026 · 5 min read
The fear behind most questions about linking a bank is simple: could this app, or someone who breaks into it, take my money? The answer depends on what kind of access was granted, and you can check.
Reading and moving are different permissions
A bank connection is not all or nothing. The app asks the connection service for specific kinds of access, and each one is a separate permission. Reading balances and transactions is one. Reading loan details is another. Starting a payment or a transfer is a different one again, and apps that only track your money have no reason to ask for it.
An app that was only granted read access cannot use its connection to send money anywhere. The capability is not hidden or switched off. It was never issued.
Why a token is safer than a password
Your bank password is a master key. Anyone holding it can do everything you can: pay a bill, add a payee, change your address. That is why handing a password to a third party has always been a bad trade.
A token is a narrow key cut for one purpose. It is a long random string issued to one app, tied to particular accounts and particular permissions. If it leaks, it can only do what it was issued for, it can be cancelled without touching your password, and cancelling it affects nobody else.
- Scope: a token carries only the permissions granted, such as reading transactions.
- Revocable: you or the bank can cancel one token without changing your sign-in.
- Separate: a token cannot be used to sign in to your bank's website as you.
Apps that do need to move money
Some apps legitimately move money: payment apps, automatic savings tools, investment apps that pull deposits from checking. They ask for more, typically your account and routing numbers or permission to start transfers. That is not a red flag in itself, since it is the product. It does mean the stakes are higher, and it is worth holding those apps to a higher standard.
The useful question is whether the access matches the job. A tool whose whole purpose is to show you charts has no need for the ability to initiate payments.
How to tell what an app can do
- Read the consent screen when you connect. It lists the kinds of data the app is asking for.
- Check the app's security page for a plain statement of what it can and cannot do with the connection.
- Look at your bank's connected apps page, if it has one. Many show the permissions granted to each app.
- Notice whether the app ever asks for your account and routing numbers. Tracking alone does not need them.
What read-only does not protect
Read-only access keeps your money where it is. It does not keep your information private if the app is careless. Transaction history, balances and the names of your lenders are sensitive on their own, and a scammer who knows them can write a far more convincing fake message.
So read-only is the floor, not the whole answer. You still want an app that encrypts what it stores, limits who can see it, offers two-factor sign-in and lets you delete everything.
Where My AI Fin App stands
The app is a tracker and planner. Through Plaid it asks for balances, transactions, loan and card details and investment holdings, and it never asks for the ability to move money. There is no feature in the app that pays a bill or makes a transfer, and the same is true of its connector for AI assistants: an assistant can read your numbers and, if you allow it, tidy categories and budgets, but it can never move money or link a bank.