Privacy
Portfolio trackers without a bank login
What aggregators technically do, what the privacy policies actually say — and what the CSV model costs in convenience.
Last updated: 22 July 2026 · By The Acutic Research Team
“Connect your portfolio” is the first step in most tracker apps. The convenience is not in dispute. What happens technically, however, is rarely printed on the same screen as the button — it lives in the privacy policy, and there it is usually stated precisely. This article reads those policies, sets out what the CSV model offers instead, and is honest about what that route costs in return. Without alarmism: the bank-login path is a regulated, legal and widely used arrangement. It is simply not without consequences, and the consequences are documented. As of 22 July 2026.
What a bank-login tracker technically does
The legal frame is the Second Payment Services Directive (EU) 2015/2366, PSD2. Article 4(16) defines an account information service as “an online service to provide consolidated information on one or more payment accounts held by the payment service user”. That is exactly what the component sitting between your bank and the app does.
Offering it in Germany requires not an authorisation but a registration: under § 34 ZAG, a firm providing only account information services needs “only written or electronic registration”. BaFin puts the distinction plainly: payment services generally require authorisation — anyone wishing to provide account information services “must register”. That is a lower bar than a banking licence, but not a formality. Article 67(2) PSD2 binds such services to act only on explicit consent, to identify themselves to the bank in every communication session, to access only designated accounts, and not to use data “for purposes other than for performing the account information service explicitly requested”.
The gap nobody mentions
Now the point that is almost always missing from this discussion, and the decisive one for portfolio tracking: PSD2 covers payment accounts only. The European Data Protection Board states it unambiguously in Guidelines 06/2020 (version 2.0, adopted 15 December 2020): banks are “only allowed to provide access to payment account information”, and there is “no legal basis under the PSD2” to provide access to personal data held in other accounts, “such as savings, mortgages or investment accounts”.
For securities accounts, then, no EU-wide regulated right of interface access exists. The proposed Financial Data Access regulation (FiDA) would change that, explicitly covering investments in financial instruments. But FiDA is stalled: per the European Parliament’s procedure file the dossier still awaits Parliament’s first-reading position, and the last formal step on record dates from 18 December 2024. PSD3 and the accompanying Payment Services Regulation are much further along — the ECON committee approved the negotiated text on 5 May 2026, with a plenary vote scheduled for December 2026.
The practical consequence: when a tracker connects to your securities account, it does so not on the strength of a PSD2 entitlement but through commercial arrangements or credential-based access. That is why portfolio connections break so much more often than current-account connections — and why the file route has proved so stubbornly durable for brokerage data.
Who the intermediaries are
Few trackers build the connection themselves. They license it from specialists, and those providers are findable in public registers — the European Banking Authority maintains a central register that held roughly 327,900 records on 22 July 2026. The EBA itself notes that the register “has no legal significance and confers no rights in law”; it documents what national supervisors have reported.
Four examples, each with its register date:
- finAPI GmbH, Munich — registered with BaFin under number 151548 since 22 January 2019 for account information and payment initiation services. SCHUFA divested 75% of its shares to Fabrick S.p.A. (Sella Group, Italy), with completion reported for 18 June 2025.
- Tink AB, Stockholm — registered with Sweden’s Finansinspektionen; a Visa subsidiary since 10 March 2022, operating per Visa “as a standalone subsidiary”.
- Plaid, B.V. — registered not in the US but in the Netherlands, with De Nederlandsche Bank since 17 March 2021.
- QPLIX GmbH, Munich — registered with BaFin under 154608 since 23 March 2021 as an account information service institution.
One detail worth knowing turns up while checking these: registers lag reality. SOFORT GmbH is still listed by BaFin as an active institution, although the German commercial register records its merger into Klarna Bank AB on 27 November 2024 and the company as extinguished. A register entry proves a licence exists — not that the company still exists in that form.
Storage locations differ substantially too, on the providers’ own accounts. Plaid states that data is transferred from the EEA and UK to the United States and stored in US AWS regions, relying on standard contractual clauses. Tink’s sub-processor list names AWS and Google Cloud regions in EMEA. Salt Edge states that personal data of users resident in the EU/EEA “will only be stored in EU”, with staff access from Canada, the United Kingdom and Moldova. These are not judgements — they are three different, self-published answers to the same question.
What the privacy policies actually say
The most instructive reading is the trackers’ own policies. Four examples, quoted, each with the date the document itself carries.
getquin (QUIN Technologies GmbH, Berlin; document dated 12 March 2026) describes the model openly: it uses “a combination of third-party providers and its own APIs to retrieve the transaction history”. Several partners are named — among them Plaid, Flanks, finAPI (described there as a “BaFin-licensed fintech company”) and SnapTrade, of which the policy says it collects and stores the login credentials and that this information is “never stored by us or passed on to us”. The stated legal basis for connected accounts is Art. 6(1)(b) GDPR; for third-country transfers, standard contractual clauses, binding corporate rules, or failing that Art. 49 GDPR. The same policy lists around thirty further recipients, including analytics and marketing services.
Parqet (Parqet Fintech GmbH, Hamburg; the document carries no date) distinguishes three connection modes. For local autosync: “the user’s credentials are processed exclusively locally on the user’s device and are at no point transmitted to Parqet.” For cloud autosync, the service is provided “legally and technically by our partner, QPLIX GmbH” — and, structurally the important sentence, “by using this function the user enters into an independent contractual relationship with QPLIX”. The aggregator here is therefore not a processor but its own controller, with its own separately published policy. On funding, Parqet writes that it “never finances itself through your personal data”, and elsewhere that it uses “fully anonymised and aggregated data” which may also be shared with selected partners, “always without personal reference”. Both sentences belong together.
Finanzguru (dwins GmbH; dated February 2025) is the case where no intermediary appears at all — because the company holds the registration itself: it states it received authorisation to provide account information services from BaFin on 15 May 2019, with a link to the register entry. On storage, data is held “encrypted in a data centre in Germany (Frankfurt)”. Worth noting fairly: the policy names US recipients but at no point names a transfer mechanism — it is silent on the question. That is an observation about the text, not about the company’s legal position.
Portfolio Performance sits at the other end: the desktop application (licensed under the Eclipse Public License 1.0) states that it does “not collect, use, save, or have access to any of your personal data” when used locally, and that portfolio files and settings “are stored exclusively on your device”. The qualification belongs with it: Sentry is used for crash reporting, and an optional account exists for historical price data.
Is this dangerous? No — but it is precisely describable
Two common misconceptions are worth correcting. The first: financial data is not a special category of personal data. Art. 9(1) GDPR gives an exhaustive list — racial and ethnic origin, political opinions, religious beliefs, trade union membership, genetic and biometric data, health data, sex life. Account balances are not on it.
The second misconception is the reassurance drawn from the first. In the same guidelines the EDPB supplies the decisive intermediate step: financial transactions “can reveal sensitive information about an individual data subject, including those related to special categories of personal data” — donations to parties, churches or organisations reveal political or religious beliefs; a deducted annual membership fee reveals trade union membership. Even single transactions, the EDPB writes, can contain special categories. A current account’s transaction stream is therefore a different thing in data-protection terms than a list of ISINs and share counts — a distinction routinely flattened in this debate, although it is the actual point.
And the record on incidents? The best documented case is a US class action: In re Plaid Inc. Privacy Litigation before the Northern District of California (no. 4:20-cv-03056-DMR) ended on 20 July 2022 with final approval of a USD 58 million settlement, roughly USD 31.50 per class member. Plaintiffs alleged the company used banking login credentials to harvest detailed financial data and designed its login screens to resemble those of the individual banks. For a fair account, the court-approved notice itself is decisive: Plaid “denies any wrongdoing and all of the allegations in the lawsuit; no court or other entity has made any findings against Plaid nor any determination that the law has been violated”. The settlement also carried injunctive commitments on data minimisation and screen design — those were limited to three years and have since lapsed.
Europe has a counterpart that is frequently miscited: the Swedish data protection authority IMY fined Klarna on 28 March 2022. That case concerned no data leak but the transparency of privacy information — breaches of Arts. 5, 12, 13 and 14 GDPR. Beyond that, no security incident involving data exposure has been publicly disclosed for the aggregators named here. That is a statement about the state of public disclosure, not proof that nothing ever happened.
Sharing credentials: what the rule actually says
“Screen scraping”, where a service logs in with your credentials as if it were you, is this market’s historical origin. Delegated Regulation (EU) 2018/389 has constrained it since 14 September 2019: Article 30 requires services to identify themselves to the bank; Article 31 lets the bank choose between a dedicated interface and the customer interface; Article 33 permits falling back on the customer interface only as contingency, until the dedicated interface is restored. The co-legislators put their position more bluntly in the draft Payment Services Regulation — recital 61 records that access to payment account data without proper identification, “so-called ‘screen-scraping’”, should “in any circumstances, never be performed”. That wording survived the negotiations and appears in the compromise text of 5 May 2026. It is not binding yet, though: the binding law today is the 2018 regulation.
The CSV model: the same analysis, one hand-off fewer
The alternative is unspectacular, and robust for exactly that reason: the bank produces a file, you download it, you hand it over. No third party gains access to your account, no credential leaves your control, and the volume of data is precisely what is in the file — not the set of accounts a permission would cover. This is nothing other than the data minimisation principle of Art. 5(1)(c) GDPR applied to daily practice: data must be “limited to what is necessary in relation to the purposes for which they are processed”.
The honest price is convenience. A file is a snapshot, not a synchronisation: if you want the current state, you export again. There are no live prices from the account, no automatic distribution bookings, no push notification on execution. For most analyses this is immaterial — weights, concentration, cost basis and quality metrics do not change by the minute. For day-to-day bookkeeping it is noticeably less comfortable. Weighting that convenience more heavily is a defensible choice; it should simply be a conscious one. How the file is produced at the major German providers is covered in the guides to comdirect, Trade Republic and Scalable Capital.
Eight criteria a policy should answer
Not a ranking and not a verdict — eight questions whose answers should be readable in any privacy policy.
| Criterion | Question to ask |
|---|---|
| Connection model | Does the policy state whether a bank connection exists at all — and whether credentials ever leave your device? |
| Named intermediary | Is the aggregator named? Without a name the chain cannot be checked. |
| Role of the intermediary | Processor, or its own controller? A separate contractual relationship means its policy applies to you as well. |
| Register entry | For payment accounts: is the account-information registration findable in the BaFin or EBA register? |
| Storage location | Where does the data sit? Some providers name EU regions explicitly, some name US locations, others say nothing. |
| Transfer mechanism | Are standard contractual clauses, an adequacy decision, or Art. 49 GDPR named — or nothing at all? |
| Data minimisation | Can the period or the set of accounts be narrowed? EDPB guidelines require exactly that selection before collection. |
| Funding | Does the provider say how it makes money — and does that match the list of analytics and advertising services in the same policy? |
Where Acutic sits, factually
For disclosure, since this text sits on a vendor’s website: Acutic operates without a bank connection. There is no account linking, no aggregator and no credential handling — portfolios are created from a file or entered manually. That is not a virtue but a design decision, carrying precisely the drawbacks set out above: no synchronisation, no automatic reconciliation.
The other half belongs with it, and it is in our own privacy policy: servers are at Hetzner Online GmbH in Germany with no third-country transfer, and AI processing runs through Microsoft Ireland in the West Europe region. Alongside that we use service providers with a US nexus — Cloudflare, Paddle, Resend and, for Google sign-in, Google’s identity service — relying on the EU-US Data Privacy Framework adequacy decision and subsidiarily on standard contractual clauses. “Without a bank connection” therefore means: one hand-off fewer. It does not mean “without service providers”, and any vendor claiming otherwise should be held to the same list.
A word on how durable that framework is. The adequacy decision of 10 July 2023 was challenged before the General Court; the Latombe action (T-553/23) was dismissed on 3 September 2025. An appeal against that judgment has been pending before the Court of Justice since 31 October 2025 (C-703/25 P). Until it is decided, the decision remains in force. Anyone who takes third-country transfers seriously should know that case — in both directions.
How the analysis itself works, which models are involved and what they demonstrably do not do, is set out on the AI transparency page; what the product costs is on the pricing page.
Conclusion
The question is not whether bank-login trackers are safe — they are regulated, registered and generally carefully documented. The question is how many hand-offs an analysis needs when the same analysis could be produced from a file. For a current account with hundreds of bookings a month, the answer is often that automation earns the extra hand-off. For a portfolio with twelve positions and four distributions a year, it is visibly less clear-cut. Both answers are defensible. It is worth knowing which one you are giving — and the eight criteria above make that checkable.
Further reading: comdirect: exporting holdings and transactions as CSV and Scalable Capital: exporting your portfolio as CSV — the file route in practice — plus the self-directed investor’s 2026 stack for how the category sorts out. Create free account.
Acutic provides investment research and educational analysis under MAR Art. 20 / § 85 WpHG. Acutic does not provide investment advice (Anlageberatung per § 1 Abs. 1a S. 2 Nr. 1a KWG / Art. 4(1)(4) MiFID II), portfolio management, or any other licensed investment service. No content in this article constitutes a personal recommendation.