What read-only access to your bank means, and what an app can't do with it
by Lee Schmidt
Published September 20, 2026
Read-only access means an app can look at your accounts and cannot act on them. It receives balances and transactions through a connection service that holds a session with your bank, and that session returns data only: the app cannot move money, pay a bill, change a setting, or sign in as you, and it never has your password. The line between reading and acting is drawn by the bank and the connection service, not by the app's good intentions, and it is the reason connecting a budgeting app is a different kind of decision from giving someone your login. What remains your responsibility is the account itself, its password and its two-factor settings, because those are what stop anyone from getting the kind of access that can act.
What the app receives
The left column is what a statement contains. The right column is what a teller would need your signature for, and read-only access provides none of it.
How the line is drawn
When you connect, you sign in to the bank inside a window the connection service opens, on the bank's own page where the bank offers one. The bank checks your credentials, asks which accounts to share, and hands the connection service a session for reading those accounts. The app is given the data that session returns, and nothing else: it was never handed the password, and the session it depends on is one the bank scoped to reading and can end at any time. See What Plaid is, and why your bank shows it for the service in the middle.
The session is what makes the access read-only. A session for moving money is a different grant, with a different consent screen, that a budgeting app does not request and a bank would not give it under the name of reading.
Reading versus paying, side by side
The difference between a budgeting app and a payment app is the grant each asks for, and the consent screen is where the two are told apart.
A budgeting app asks for the left column. If a consent screen for a budgeting connection ever describes the right column, stop, because the app is asking for more than reading needs, and that is reason enough to close the window.
What read-only does not protect against
Read-only access protects the money. It does not protect the information: an app that can see your transactions has your transactions, and what it does with them is governed by its privacy policy and by the law, not by the connection's scope. Read the policy for whether the data is sold, and prefer apps that say plainly it is not.
It also does not protect the account from you. The password you typed on the bank's page is still the password; a weak one, a reused one, or one typed into a lookalike page from an email link is the risk, and none of it is changed by an app's access being read-only. See Is it safe to connect your bank to a budgeting app? for the whole picture.
Check it yourself
- Look at the consent screen when connecting. It names the accounts and describes what is shared, and it does not mention payments or transfers.
- Look at the bank's connected-apps page afterward. Most banks list each app with what it can access, and read-only appears as viewing balances and transactions.
- Try to find a payment feature in the app. A budgeting app with read-only access has none, because it cannot.
- Revoke and reconnect if anything looks broader than reading. The bank's page and the connection service's own portal both allow it; see How to see and revoke which apps are connected to your bank.
Common mistakes
- Treating read-only as no risk. The money is protected; the data is the app's to handle, and the account is still yours to secure.
- Giving an app your actual password instead of connecting. That is full access, whatever the app says it does with it.
- Confusing a payment app with a budgeting app. A payment app requests a different grant and can move money; the consent screen says which.
- Assuming the app stores the password because you typed one. It was typed on the bank's page; the app received a session.
- Never checking the connected-apps page. It is where the scope is written down, and where an old connection is ended.
Common questions
Can a budgeting app take money from my account? No. Read-only access returns balances and transactions and provides no way to move money, pay anyone, or change the account. Moving money requires a different grant with its own consent, which a budgeting app does not request.
Does the app have my bank password? No. You sign in on the bank's own page inside the connection window, the bank issues the connection service a session for reading, and the app receives data from that session. The password stays with the bank.
What exactly does the app see? Account names and types, the last digits of the account numbers, balances, and transactions with their dates, amounts, merchant names, and pending status. Some banks also share the account holder's name and address. It is the statement, and nothing the statement does not have.
Can read-only access be used for fraud? It cannot move money. Someone with your transaction data knows what you spend and where, which is private and worth protecting, but the account itself is reached only through your credentials, which the app never had.
How do I turn it off? From the bank's connected-apps page, from the connection service's portal, or from the app's own settings, any of which ends the session. The data already synced stays with the app until you ask the app to delete it.
How Zypper handles this
Zypper's connections run through Plaid, and you sign in on your bank's own screen inside the secure Plaid window, so your bank credentials are never seen or stored by Zypper; Zypper receives read-only financial data, never your login. There is no Zypper password to steal either: sign-in is by an emailed link or a Google account. The connections settings show each institution, the accounts it provides, its status, and when it last updated, and removing a connection there disconnects the institution and stops every account it provides from syncing. See Privacy and security at Zypper, Connecting your bank accounts, and Editing and removing accounts for the details, or get started with Zypper to connect with reading only.