nint
Privacy & Security·August 10, 2026
You probably know your bank has your account number and transaction history. That's obvious. But do you know that your budgeting app might be tracking how long you stare at your credit card balance? Or that your payment processor has built a behavioral profile predicting your likelihood of switching banks?
Most of us hand over financial data without a second thought. The trade-off feels reasonable: convenience in exchange for some personal information. But "some" is doing a lot of heavy lifting in that sentence.
Here's how to find out what's actually happening with your data—and what to do about it.
The information you consciously provide to finance apps—your name, email, bank credentials—is just the surface layer. Underneath, most apps are collecting:
That last category is the one that surprises people most. Your budgeting app might know things about you that you never told it, because it bought that information from someone else.
Thanks to GDPR (if you're in the EU/UK) and CCPA (if you're in California), you have a legal right to see what companies have collected about you. Even if you're outside these jurisdictions, many companies honor these requests globally because it's easier than maintaining separate systems.
List every finance-related app and service you use. Don't forget:
For each app, look for one of these:
If there's no automated tool, send an email with this template:
Subject: Data Subject Access Request
I am exercising my right of access under GDPR Article 15 / CCPA §1798.110 to request a copy of all personal data you hold about me.
Please include: all data collected directly, all data inferred or derived, all third parties with whom my data has been shared, and the purposes for each category of processing.
Account email: [your email]
Companies have 30 days under GDPR and 45 days under CCPA to respond. Set a calendar reminder. If they miss the deadline, follow up and mention the regulatory deadline explicitly.
This is where it gets interesting.
When the data arrives (usually as a JSON dump or CSV export), expect to see:
The expected stuff: Transaction history, account details, login records. Fine.
The less expected stuff: A detailed log of every time you opened the app. Timestamps for every screen you visited. A record of every notification you received and whether you tapped it.
The concerning stuff: Third-party sharing lists that include advertising partners, analytics companies, and "business partners" you've never heard of. Inferred categories like "high-value customer" or "churn risk" or "impulse spender."
Some apps will also reveal that your transaction data has been anonymized and sold in aggregate—which sounds harmless until you realize that "anonymized" financial data is notoriously easy to re-identify.
When reviewing your data export, watch for:
If you find any of these, you have the right to object to processing (GDPR Article 21) or request deletion (GDPR Article 17 / CCPA §1798.105). You don't have to accept it just because you agreed to a terms-of-service document you didn't read.
Here's an uncomfortable truth about data audits: they only work if the company is honest about what they have. You're relying on the same organization that collected your data without clear disclosure to now fully disclose it. The incentives aren't aligned.
This is the core argument for local-first architecture in personal finance.
With nint, there's almost nothing to audit—because your financial data never leaves your device in the first place. Your transactions, budgets, categories, and spending patterns live on your phone or computer, not on a company's servers. There's no behavioral profile being built. No third-party sharing list. No inferred scores.
If you wanted to do a "data audit" of nint, you'd open the app and look at your own data. That's it. You already have the complete picture because you're the only one who ever had it.
This isn't a philosophical stance—it's an architectural decision. When financial data is processed locally, the entire category of "what does this company know about me?" becomes irrelevant. The answer is: nothing they didn't need to make the software work.
Whether or not you switch to a local-first app, submit those data requests. Knowledge is leverage. Once you see the scale of collection, you can make informed decisions about which trade-offs you're actually willing to accept.
Start with your most-used finance app. Submit the request today. Set the calendar reminder for 30 days. And when the export arrives, read it carefully—especially the parts about third-party sharing and inferred data.
You might be surprised. Or you might be furious. Either way, you'll finally know.
Join 20,000+ users who have secured their financial future with nint's private vault technology.
Related Posts