Is it safe to give a money app your bank login?

No, and you do not have to. A cloud service has to store the password and use it while you are not there; software on your own computer can drive a browser you are already signed into.

Mind My Money is the second kind. It runs on your computer and is never told a password.

Anything that shows you where your money goes has to reach your transactions, which live at your bank. Handing over the login, or a standing bank connection, is one way to arrange that, and it is how most money apps work, because they run on somebody else's servers and the access has to be there too.

What a cloud service needs from you

Most money apps run as a web service. For one of those to read your transactions, it needs standing access to your bank: a bank connection through an aggregator, or your login, held on their side so their servers can use it while you are asleep.

That is not a criticism of how any of them is built, because it is what the shape requires. If the work happens on their machines, the access has to be on their machines too. It does mean the answer to "who can reach my accounts" includes a company, its staff, its subprocessors and whatever happens to it later.

What Mind My Money does instead

It runs on your computer and drives a real browser there — its own Chrome window on a separate profile kept just for this, not your everyday browsing. You sign into your bank in that window yourself, and that session stays put on your machine. The commitments, in the words they are made in on how it works:

“We never ask for a banking password. Logins happen in your browser, by you.”
“There is no Mind My Money cloud holding your money data.”
“Reading receipts and screenshots, and transcribing your voice, happen on your computer.”
“Photos, messages and browsing history are each asked for when a payment needs them, and it looks only at the few days around that payment.”
“iPhone sync, if you use it, goes through your own iCloud.”

There is no account of yours on a server of ours holding any of it, because there is no server. That is the structural part: we could not read your bank session if we wanted to, since it never leaves the machine it was created on.

What does leave your computer

Something has to reason about the transactions, and that step goes to a model. Again in the words used on how it works: “The agent step that reasons about your spending does go to a model. Which one, and under whose agreement, is your choice.” Today that is your own subscription, under your own contract with the provider, which is the arrangement you already have if you use one.

So “it all stays on your computer” would be the wrong thing for us to say, and we do not say it. Your transactions are stored on your machine and your logins never leave it; the reasoning step is a network call, the same as any other use of an assistant.

Signing into things is still the hard part

Worth saying plainly, because the industry has been here before. Xero used to log into supplier portals and download documents on its customers' behalf, and it retired that in 2022, saying the connections had become outdated and were “often blocked by banks and online suppliers”. Banks block automation deliberately, and they are not going to stop.

Driving a real browser that reads the page, rather than a script that expects a fixed one, copes with a great deal more of that. It does not make the problem disappear. What it does is fail in the open: when a login needs you, it leaves the tab there and asks, rather than recording a silent blank you find out about months later.

The longer version of this question, including where it is genuinely up to you, is on how it works under “is it safe to let this near your bank?”.

Your logins, on your machine

Have a look at what it actually does.

Runs on your own computer. Pay what you decide, including nothing.

Apple Silicon or Intel · macOS 14+ · vunknown