All guides

Why FLOW Never Asks for Your Bank Login, and Why You Should Question Apps That Do

7 min read
Why FLOW Never Asks for Your Bank Login, and Why You Should Question Apps That Do · VESTELON FLOW

Almost every finance app has the same onboarding screen: connect your bank account. It shows a padlock, a row of bank logos, and a promise that everything is secure. VESTELON FLOW does not have that screen at all. You upload one bank statement, the analysis runs in your browser, and no login to your bank ever happens.

That is a deliberate design decision, not a missing feature. To explain it, we need to look at what connecting your bank actually grants, because most people click through that screen in seconds without knowing.

What connecting your bank actually grants

In the EU and UK, that connection usually runs through regulated open banking. A licensed provider, called an AISP (account information service provider), receives read-only access to your account: balance, transaction history and account details. It cannot move your money.

The part most people miss is the duration. This is not a one-time look:

  • In the EU, the European Banking Authority's technical standards under PSD2 allow an access consent to run for up to 180 days before you must re-authenticate with your bank.
  • In the UK, the open banking standard works on a 90-day reconfirmation cycle.
  • Until the consent expires or you revoke it, the provider can read every new transaction: salary, rent, pharmacy, the donation you made, the bar tab.

So the honest description is: months of standing, automatic access to your complete transaction feed, flowing to a third-party server. That can be a fair trade for some tools. It is simply a much bigger trade than one click suggests.

The trade-offs nobody spells out

Open banking is regulated and read-only, and this article will not pretend otherwise. The trade-offs are subtler:

  • Your data changes jurisdiction. Once transactions leave your bank, they are governed by the app's privacy policy, not your bank's. Two documents, very different incentives.
  • There is usually a middleman. Many apps do not connect to your bank themselves. They use an aggregator, one more company between you and your account, one you never chose by name.
  • Consent outlives attention. Revocation dashboards exist, but few people can list every service currently connected to their account without checking.

When access goes wrong: a 58 million dollar lesson

In 2022, a US federal court approved a 58 million dollar class action settlement with Plaid, the aggregator that connected apps like Venmo and Robinhood to users' banks. The lawsuit alleged that Plaid collected more financial data than the apps needed and used login screens that looked like the users' own banks while the credentials went to Plaid. Plaid settled without admitting wrongdoing and agreed to delete certain data and minimize future collection (reported by Courthouse News Service and Bloomberg Law, 2022).

The lesson is not that aggregators are villains. It is structural: standing access plus a middleman position creates the temptation to collect more than the job requires. The only access that can never be over-collected is access that was never granted.

The real red flag: typing your bank password into an app's own screen

Regulated open banking has one visible safety property: you authenticate at your bank, in your bank's own app or page, and the finance app never sees your password.

So here is a simple test. If any app asks you to type your bank login directly into its own form, stop. That is credential sharing, the pre-regulation technique known as screen scraping, and your bank's terms almost certainly state that your login is strictly personal. Check them before you ever do it.

Statement-only tools remove this entire risk class: when there is no login step, there is nothing to phish, mimic, store or leak.

How statement-only analysis works: a model example

The following is a model example, invented to show the mechanics, not real user data. Two neighbours use the same bank and both want to know where their money goes.

  • Marta connects an app via open banking. Through its aggregator, the app can now read her transaction history and every new transaction, until the consent expires or she remembers to revoke it. Processing happens on the provider's servers.
  • Jonas downloads his July statement as a PDF from his bank, the same document he could print, and uploads it for analysis. The analysis sees exactly the 31 days he chose, ending at the moment he picked, and nothing that happens on his account afterwards.

Three boundaries differ: scope (a chosen month versus a running feed), direction (he pushes one file versus the app pulling data), and endpoint (in FLOW's case, the file is parsed in the browser on his own device). Same question, radically different exposure.

Five questions to ask any finance app

You do not need to be technical. Ask these in plain words and watch how directly they get answered:

  • Do I authenticate at my bank, or do I type my password on your screen?
  • How long does your access last, and where exactly do I revoke it?
  • Which companies sit between you and my bank?
  • Where is my transaction data processed and stored?
  • What happens to my data when I stop using you?

An honest product answers each in one sentence. Vague answers are answers too.

Try the no-login version yourself

This model is verifiable rather than trust-based. Upload one statement at app.vestelonflow.com: the analysis runs in your browser, you see your number in about a minute, no account and no bank login needed, and nothing leaves your device without your consent. If you want a deeper side-by-side of the two approaches, we compared them in open banking vs uploading a statement.

FAQ

Is open banking unsafe? No. It is regulated, read-only and authenticated at your bank. The question is not safety but scope: an always-on tool may justify a standing connection, while a report or an analysis needs only one statement. Match the access to the job.

Can an app steal money with open banking access? Account information access is read-only. Initiating a payment requires a separate consent and a separate authentication. The realistic risk is not theft, it is how much data flows out and how it is handled afterwards.

What if my statement contains lines I do not want to share? That is exactly the advantage: you pick the file and the month, and you can open it and read every line before uploading, something you can never do with a live data feed.

Upload one bank statement. FLOW shows exactly where your money leaks today, what it is worth once you redirect it, and the year it could set you free. Not another tracker: a plan you can act on.

Get my free reportFree first report · No card needed · No bank login · Delete anytime · GDPR-first