How to choose a safe and trusted personal finance product
Eight practical checks you can run before connecting a bank — most take a couple of minutes, and one can be done on a government website in about thirty seconds.
ACCC public register
Confirm the provider is listed as an accredited data recipient or CDR representative.
How data is collected
Prefer a CDR consent flow over screen scraping or unexplained statement uploads.
Read-only access
Budgeting apps should view balances and transactions — not move money.
Clear, revocable consent
Know what is collected, why, for how long, and how to cancel in-product — not only via support.
Export and deletion
You should be able to leave with your data, and ask for it to be deleted.
Controls you can see
2FA, proper password hashing, and failed-login protection should be available.
Visible revenue model
If you cannot see how the company is paid, you cannot reason about what funds security.
Ongoing maintenance
Look for policies, scanning, and a way to report vulnerabilities — not launch-day claims alone.
There is a new personal finance app almost every week. Some are built by teams who have spent years thinking about how to protect financial data. Some are built over a weekend by someone who has not thought about it at all. From the outside, on an app store listing, the two look almost identical — same clean screenshots, same promise to sort your spending out, same five-star reviews.
The difference only shows up later, in where your data went and who was accountable for it.
And plenty of these apps never go near Open Banking at all. They ask you to upload a statement, import a CSV, or type your account details straight into a form. It feels lower-risk, because no bank connection is involved. It usually is not — you have still handed over your transaction history, your account numbers and your spending patterns, to a company you now know nothing about, with no regulator anywhere in the arrangement and no way to find out how any of it is stored.
This matters more than it used to. The Office of the Australian Information Commissioner recorded 1,205 data breach notifications in the 2025 calendar year — an 8% increase on 2024 — and finance was the second most affected sector, with 157 notifications, behind only health.
So the question worth asking before you connect anything to your bank is not “is this app any good?” It is “can I verify that this app is safe?”
Here are the checks that answer that — most of them take a couple of minutes, and one of them can be done on a government website in about thirty seconds.
1. Check whether it appears on the ACCC's public register
This is the strongest check available to you, because it is the only one you can confirm independently rather than take on faith.
In Australia, sharing bank data through Open Banking is governed by the Consumer Data Right (CDR). Businesses can only receive your banking data if they are either an accredited data recipient — which means going through the ACCC's accreditation process — or a CDR representative, operating under a written agreement with an accredited business that stays accountable to the regulator for how the data is handled.
Either way, they appear on a public register. The ACCC maintains it, and anyone can search it: cdr.gov.au/find-a-provider.
Type in the name of the app you are considering. If it is there, you can see the entity name, the ABN, the role it holds, and — if it is a representative — the accredited business standing behind it. If it is not there and it is asking for your bank data anyway, that tells you something too.
How Wealthra sits on that register: Wealthra Pty Ltd (ABN 82 693 425 393) is a registered CDR representative of Basiq Pty Ltd, an accredited data recipient under the Consumer Data Right. Basiq collects the banking data on our behalf and remains accountable to the regulators for how it is handled — which means our security controls and data-handling practices were assessed by a business with its own accreditation at stake, not just signed off internally. You do not have to take our word for any of that. It is on the register linked above.
One piece of language to watch while you are there: an app that says “we are CDR accredited” when the register lists it as a representative is describing itself inaccurately. It is a small thing, but how carefully a company describes its own regulatory position is a reasonable proxy for how carefully it does everything else.
For more on how the framework works, see Understanding Open Banking in Australia and our Open Banking feature page.
2. Check how it gets your data — and what that tells you
There are three ways an app can get your transactions, and they are not equivalent.
Open Banking (CDR) uses a consent flow run by your bank. You log in on your bank's own page, choose what to share, and the app never sees your credentials. The business receiving the data has to be on the register from section 1, which means someone outside the company has looked at how it handles that data.
Screen scraping works differently: you hand the app your internet banking username and password, and it logs in as you to read the screens. That practice has been the subject of a Treasury review into its policy and regulatory implications, and most banks' terms of use have historically discouraged sharing your login details with third parties. If an app asks for your banking password, that is the moment to stop and think about what you are handing over.
Manual import is the one people worry about least and probably know least about. You export a statement or a CSV from your bank and upload it, or type your account details into a form. There is no bank connection, so it feels like the cautious option.
But look at what you actually gave away: months of transactions, account numbers, salary, rent, every merchant you have paid. And because no Open Banking connection was involved, none of the CDR obligations apply. The company is not on any register. Nobody outside it has assessed how that file is stored, who inside the business can open it, whether it is encrypted, how long it is kept, or what happens to it if the company is sold or shuts down.
That is the real problem — not that these apps are necessarily insecure, but that there is no way for you to find out either way. You are being asked to assess a company's security posture from its marketing page. Nobody can do that.
This is what regulation actually buys you. It does not make a product perfect. It makes it checkable — it converts a question you cannot possibly answer into one you can answer on a government website in thirty seconds.
Wealthra uses the CDR consent flow. You authenticate with your bank, not with us. We never see, store, or transmit your banking password. You can also add accounts manually if you would rather not connect a bank at all, or if you hold something the CDR does not cover — but the accounts you do connect come through the regulated path, and the obligations that come with it apply to us either way.

Before you connect, Wealthra spells out the deal: automatic sync, read-only access, encryption, CDR protection, and the right to revoke — then sends you to your bank to authorise.
3. Check whether the access is read-only
Reading your transactions and being able to move your money are two very different levels of access. An app that only needs to show you where your money went does not need the ability to send any of it anywhere.
Ask — or check the app's own documentation — whether the connection is read-only, and whether payment initiation is technically possible at all.
Wealthra's bank connections are read-only by design. We can see balances and transaction history. We cannot initiate a payment or move money, on any account, ever. That is not a setting we have switched off; it is not a capability the connection has. See also Security.
4. Check the consent: what, how long, and how you cancel
Good consent is specific and reversible. Vague consent is a warning sign. Before you tick anything, look for four things:
- What data is being collected, named plainly, rather than “your financial information”
- What it will be used for — and whether that includes sharing it with anyone else
- How long the consent lasts
- How to withdraw it, and how quickly that takes effect
Under the CDR, consent is not permanent. It must be an active opt-in — no pre-ticked boxes — and it expires after a maximum of 12 months unless you renew it.
That last point is where products diverge in practice. CDR rules require consent to be withdrawable — but not every finance app makes revocation easy inside the product. Some bury it, push you to a support ticket, or only support disconnecting through a third-party portal you may never find again. If you cannot see a clear in-app path to revoke a bank connection and its consent, treat that as a red flag.
In Wealthra, every bank connection and every consent can be revoked at any time from your account settings — per institution, without affecting your other connections. Revocation takes effect immediately: collection stops, and the deletion workflow begins for data held under that consent. That is not a promise you have to email support to redeem. It is a control you can use yourself, whenever you want.
Each bank you connect has its own consent, with its own expiry, visible in your account. When a consent lapses or you withdraw it, we stop collecting from that institution. Other products may not give you the same self-serve path — which is exactly why you should check before you connect.

The regulated consent screen names the data, the purposes, the expiry, and that you can revoke anytime — before Wealthra receives anything from your bank.
5. Check what happens to your data when you leave
The end of the relationship is where a lot of apps quietly fall short. Two questions cover it:
Can you take your data with you? Look for a genuine export, not a screenshot function.
Can you make them delete it? And is that a real deletion process, or a support email that goes nowhere?
Wealthra provides full data export and deletion. When a bank consent expires or you revoke it, collection stops and the deletion workflow begins. Some records — consent history and audit logs — are retained where the CDR rules and Australian record-keeping requirements say they must be, and that is spelled out in our CDR policy rather than buried.
6. Check the security you control
The controls a product gives you are the easiest to assess, because you can see them in the settings before you commit to anything.
- Two-factor authentication. Is it available on your account, and does it support an authenticator app rather than SMS alone?
- Password handling. Does a password reset email you a link — or does it email you your existing password? The second means it is stored in a readable form, which is a serious problem.
- Failed login handling. Does repeated guessing get throttled or locked out?
In Wealthra: two-factor authentication is available to every user through any standard authenticator app — Google Authenticator, Authy, Microsoft Authenticator — with backup codes for recovery. Passwords are stored using PBKDF2-SHA256 hashing, which means they are never held in a readable form and cannot be emailed back to you. Repeated failed logins are rate-limited and locked out. Administrative access inside Wealthra is held to a separate and higher standard, with mandatory multi-factor sign-in.
7. Check how the product makes money
This one feels rude to ask and is one of the more revealing questions you can put to a finance app.
Security is not free. Accreditation, encryption, penetration testing, vulnerability scanning, breach response planning, the engineers who maintain all of it — that is a permanent, expensive line in a company's budget, and it produces nothing a customer can see on a screenshot. It has to be paid for out of something.
So it is worth knowing what that something is. A published subscription price is a plain answer: you pay, and the money funds the product. Where there is no price, there is still a revenue model — it is just not visible to you. It might be venture funding, and the security question becomes what happens at the end of the runway. It might be referral commissions on the products the app suggests to you, which shapes what it suggests. It might be your data.
None of that makes every free app unsafe, and it does not make every paid app well built. Paying is not proof of anything on its own. The point is narrower: when you cannot see how a company makes money, you also cannot reason about what it is spending on protecting you. It is the same problem as section 2 — not evidence of a bad answer, just no way to get an answer.
Wealthra is a subscription product, with plans published on our pricing page and paid by the people who use it. There is a free plan, and it is worth being straight about how it is funded: it runs on the same platform, the same controls and the same regulated bank connections as the paid plans, and it is paid for by the subscribers on those plans. We do not sell user data, and we do not take commissions for pointing you at financial products. The revenue model is the one on the pricing page.
8. Check whether security is maintained, not just launched
This is the check almost nobody makes, and it is the one that separates a product built for the long term from one that was secure on launch day and has not been looked at since.
Security is not a feature you ship. It is maintenance. The questions that get at it:
- Does the company publish a privacy policy, a data retention policy, and a data breach response plan — or just the privacy policy the app store required?
- Is there evidence of ongoing testing, rather than a one-off review?
- Is there a way to report a vulnerability?
At Wealthra, every code change runs through automated vulnerability scanning before it can ship, with scheduled scans running weekly on top of that. Dependencies are pinned to exact versions with integrity checks, and updates are reviewed by a person rather than merged automatically — a discipline we tightened after watching supply-chain attacks hit other companies through exactly that gap. Data in transit is encrypted with TLS 1.2 or higher, and sensitive fields like account numbers and BSBs carry their own layer of encryption on top of the encrypted database. We maintain written policies for privacy, retention and deletion, access control, server hardening, monitoring, and incident and breach response.
The short version — eight red flags
Worth pausing on any of these:
- 1
It asks for your internet banking password. The CDR exists so that it does not have to.
- 2
It is not on the CDR register but wants your bank data anyway.
- 3
It only takes uploads or manual entry — and offers nothing about how that data is stored.
- 4
It says "bank-level security" and nothing else. That phrase means nothing on its own.
- 5
The consent is vague, permanent, or pre-ticked — or you cannot revoke a connection in-app.
- 6
There is no clear way to delete your data.
- 7
You cannot work out how it makes money.
- 8
You cannot find out who is behind it — no company name, no ABN, no Australian entity.
Frequently asked questions
Is Open Banking safe?
Open Banking is the regulated alternative to sharing your banking password. You authorise the connection on your bank’s own site, the receiving business must be accredited or operating as a representative of an accredited business, consent is time-limited, and you can withdraw it at any time. What varies is the individual app — which is why the register check is worth doing.
How do I check whether an app is CDR accredited?
Search the ACCC’s provider directory at cdr.gov.au/find-a-provider. It lists accredited data recipients and the representatives operating under them.
What is the difference between an accredited data recipient and a CDR representative?
An accredited data recipient has been accredited by the ACCC directly. A CDR representative operates under a written agreement with an accredited business, which remains accountable to the regulator for how the representative handles your data. Both appear on the public register.
Is it safer to upload a bank statement than to connect my bank?
It feels safer, because no live connection is created. But the data in that statement — account numbers, transaction history, income — is now held by a company that is not on any register and has no CDR obligations attached to it. A regulated Open Banking connection is read-only, time-limited, revocable, and handled by a business the ACCC lists publicly. An uploaded file is none of those things.
Are free personal finance apps less secure than paid ones?
Not automatically, and plenty of paid products are poorly built. The useful question is not free versus paid, it is whether you can see how the company makes money — because security is a permanent cost that has to come from somewhere. Where there is a published price, you know. Where there is not, the money is coming from somewhere else and you are not being told where.
Can a personal finance app take money out of my account?
Not through an Open Banking connection — CDR access is read-only. An app that can move money is doing it through a separate payment arrangement, which you would have authorised separately.
Can I revoke bank connections and consents in Wealthra?
Yes. Every bank connection and every CDR consent in Wealthra can be revoked at any time from your account settings, per institution. Revocation takes effect immediately and starts the deletion workflow for data held under that consent. Other products may not offer the same self-serve path — always check before you connect.
See it for yourself
Every check above is one you can run on Wealthra before you connect a single account. Run them. Then decide.
Important: The information provided is factual and general educational information only. It is not financial, investment, tax or legal advice and must not be relied on as such. Wealthra Pty Ltd does not hold an Australian Financial Services Licence (AFSL) and does not provide financial product advice. This information does not take into account your personal objectives, financial situation or needs. Before making any financial decision, consider whether it is appropriate for your circumstances and seek advice from a licensed financial adviser, accountant or other qualified professional.
Sources: Data breach notifications increase to all-time high in 2025 — OAIC, 6 July 2026 · The Consumer Data Right — ACCC · Find a provider — Consumer Data Right · CDR representative model: privacy obligations of a CDR principal — OAIC · Screen scraping — policy and regulatory implications, Treasury consultation