Learn
Ten things to check before you trust a finance app with your data
By the My AI Fin App team · Updated October 3, 2026 · 6 min read
You cannot audit an app's code, but you can learn a lot in fifteen minutes from what it tells you and what it lets you do. This checklist works for any budgeting or finance app, including ours.
How it connects and signs you in
These three are about the front door. An app that gets them wrong is unlikely to have got the harder things right.
- 1. It never asks for your bank password itself. The bank sign-in should happen on your bank's site or on a known connection service's screen, not in a form the app built.
- 2. It offers two-factor authentication, ideally with an authenticator app or passkeys and not only text messages.
- 3. It tells you when something changes: an email on a sign-in from a new device, and a list of active sessions you can end.
What it does with your data
Be wary of security pages that are all adjectives. Be equally wary of badges and certifications you cannot verify. An honest page says what is in place and where the limits are.
- 4. It says how it makes money. If the app is free and has no paid plan, your data or your attention is probably the product. Look for a plain statement about selling data and showing ads.
- 5. It names what it collects and who it shares it with. A privacy policy that lists actual service providers is a better sign than one full of 'trusted partners'.
- 6. It describes its security in specifics. 'Bank-level security' means nothing. Encryption in transit and at rest, how access tokens are stored, and how access between customers is separated mean something.
What control you keep
The way out tells you how an app thinks about your data. If leaving requires an email to support and a waiting period, the company is treating your data as theirs.
- 7. You can export your data in a format you can open, such as CSV, without asking support.
- 8. You can delete your account yourself, and the app says what deletion removes.
- 9. Disconnecting a bank really disconnects it: the app says the connection is removed at the connection service, not only hidden in the app.
Who is behind it
Also check the basics: that you installed the app from the official store listing linked from the company's own website, and that the website address matches the name on that listing. Copycat apps rely on people skipping this step.
- 10. There is a real way to reach someone, a named company, and a place to report security problems. A published security contact or bug bounty shows the company expects scrutiny and has a plan for it.
Red flags that should end the evaluation
- A sign-in form for your bank that is part of the app's own page.
- Requests for access the app's purpose does not need, such as the ability to move money in a tool that only shows charts.
- No way to delete your account.
- Pressure to connect a bank before you can see anything at all.
- Vague or missing answers about how the company earns revenue.
Run the checklist on us
My AI Fin App publishes its answers on its security page: bank sign-in happens on Plaid's screen, two-factor authentication is enforced by the database once it is on, new-device sign-ins trigger an email, revenue is subscriptions with no ads and no data selling, and export and account deletion are buttons in settings.
The same page also says what the app does not have. It is a small product and has not had a SOC 2 audit, and it says so instead of implying otherwise. We would rather you decide with the full picture.