Money Clarity

    Expense tracker without bank login: what each route hands over

    Every automatic expense tracker gets your transactions from one of four places: your net-banking login, a consent through the RBI's Account Aggregator framework, the alerts your bank already sends you, or statements you upload. The four differ much less in what they see than in what they can do. A tracker reading your alerts and a tracker holding your net-banking password can show you the same 120 debits. Only one of them holds a key that opens the account.

    So 'no bank login' is the right instinct and the wrong test. It rules out the worst route and says nothing about what the app takes instead. Your inbox holds more about you than your bank account does, and an Android app allowed to read SMS can technically read the OTPs that arrive beside your alerts. The useful question is not 'is it secure?', which every app answers yes, but 'what did I hand over, and what can the app do with it?'

    This page turns that into a ledger you can apply to any app, using one illustrative household with two bank accounts and two credit cards.

    Last reviewed 2026-09-25

    Seeing is not the same as doing

    The technique

    The permission ledger: four columns, not one

    Security claims describe servers you cannot see. The ledger asks four checkable things: what the route sees, what it can do, whom you must trust, and how you revoke. Most people judge only the first column, which is where the routes are most alike.

    All four routes can produce a list of amounts, dates and counterparties. The login and the Account Aggregator route see a little more, such as ledger lines that never trigger an alert; alerts see a little less; statements see everything, late. On seeing alone, the routes are close to interchangeable.

    The second column separates them. A net-banking password is not a read permission. It is the credential you use to add payees and move money, and the bank cannot tell the tracker's session from yours. The other three routes hand over something that cannot move a rupee: a consent that carries data only, a permission to read messages already sent to you, or a file. Columns three and four decide the rest: where your data ends up, and whether you can end the arrangement yourself, today.

    • Apply the ledger to the route, not the brand. Two trackers on the same route share the same ceiling on what they can do and differ only in the last two columns
    • The household: 4 accounts, about 120 debits and ₹50,000 of spending a month. The counts below scale with accounts, not transactions, so swap in your own number of accounts

    Route 1: your net-banking username and password

    The technique

    Screen scraping: the app logs in as you

    The tracker stores your credentials, signs in to net banking on a schedule and reads the pages as you would. The bank sees an ordinary login, and nothing in the design limits that session to reading.

    Sees: whatever your net-banking screens show, usually the full ledger. For the household that is 4 logins and 8 secrets, a username and password each, held on someone else's systems.

    Can do: in principle, anything you can do once logged in. Most banks put an OTP in front of adding a payee or making a transfer, so the password alone rarely moves money. A stored password plus a way to receive your OTP does, and scrapers often need you to relay an OTP, training you in the exact habit fraud depends on.

    Must trust: the app's storage of 8 live credentials, its staff and any future owner. A breach there leaks your bank login, not just your history.

    Revoke: only by changing the password, which breaks the tracker until you type the new one into the same app. Change each password quarterly and that is 16 re-links a year, each repeating the original risk. So people change passwords less often, and the tracker penalises the habit that protects the account.

    Banks tell customers never to share these credentials, and the reason shows up in a dispute. RBI's rules on unauthorised electronic transactions put the loss on the customer where the customer's negligence caused it, and sharing credentials is the textbook case.

    • This route existed because nothing better did. Now it is the one route of the four with a clear reason to refuse it

    Route 2: consent through an Account Aggregator

    The technique

    Data moves on a consent, not a credential

    A licensed aggregator carries your data from the bank to a regulated recipient only against a consent you approve, naming the purpose, data, period and frequency. It passes the data along encrypted and is not meant to read it.

    Sees: the accounts you approve, for the date range the consent names, straight from the bank's records, so a year of history can arrive on day one, including lines no alert ever mentioned.

    Can do: read. The framework carries information, not payment instructions; no consent turns into the ability to move money.

    Must trust: the recipient. The framework governs the sharing, not what the recipient does afterwards, so read the purpose and duration on the consent screen: a one-time pull and a 12-month recurring feed are very different grants.

    Revoke: in the aggregator's app, yourself, at any time. For the household, one consent can cover all 4 accounts if every institution is live; split by institution, it is up to 4 approvals, each renewed once a year on a 12-month consent. The limit is coverage: not every institution or account type is live yet. The consent flow itself is explained on the Account Aggregator page.

    • If you want a bank-linked tracker, this is the version of bank-linked worth accepting: scoped, dated and revocable by you, which is a different category from a password

    Route 3: reading the alerts you already get

    The technique

    Read what the bank has already sent you

    Your bank and card issuer already notify you of each debit by SMS, email or both. A tracker built on those alerts needs nothing from the account, because the information has already left the bank and reached you.

    Sees: the amount, date, last digits of the account or card, often the balance, and a counterparty: a merchant descriptor for cards, an address or registered name for UPI. Whether you paid on GPay, PhonePe or Paytm, the bank executes the debit and sends the alert.

    Can do: nothing to the account. There is no credential here, so nothing can log in, add a payee or approve a payment.

    Must trust: the app's handling of your inbox or SMS, covered two sections down. Revoke: remove email access in your Google account settings and switch off the SMS permission in Android settings, both instant and neither needing the app's cooperation; deleting stored data is a separate step. The Gmail-specific questions are on the page about connecting Gmail.

    Unyfy reads your bank and card transaction emails and, on Android, your bank's transactional SMS, with no manual entry and no bank password or UPI PIN, and drops any debit it has already seen through the other channel. That last step matters: if each of the household's 120 debits arrived both ways, that is 240 alerts a month, 50 percent duplicates, and a ₹50,000 month would read as ₹1,00,000.

    The route is weaker in three places, and Unyfy with it. Cash: it sees the ₹4,000 ATM withdrawal, not what the cash bought, so 8 percent of the household's spending, ₹48,000 a year, is one line with no detail. Alerts without a merchant: if 30 of 120 carry only a reference number, 25 percent of debits are amounts without names. iPhone: iOS does not let apps read SMS, so Unyfy's SMS reading is Android only; on an iPhone the web app at app.unyfy.co.in works from email alerts and statements.

    Route 4, and all four side by side

    The technique

    The statement: complete, late and manual

    A statement is the bank's own record for the period, so nothing is missing. The cost is effort and delay: your data is only as fresh as your last upload.

    Sees: every line for the period, including charges and reversals no alert mentioned. Can do: nothing; a PDF is a file, not a connection. Must trust: whoever holds it, and it carries your name, address and full account number. Revoke: you cannot un-send a file, so revocation means deletion; check that the app discards uploads after reading them. If it asks to store your PDF password, which is usually built from personal details, unlock the file yourself instead.

    The cost is upkeep: 4 accounts at 12 statements a year is 48 uploads, and at three minutes each, 144 minutes a year. Backfilling a year on day one is another 48. Unyfy parses statement PDFs from five supported banks, so for those accounts the alert and statement routes combine.

    One household, one year, four routes
    Net-banking login: secrets held, re-links at quarterly password changes
    8 held, 16 a year
    Account Aggregator: bank secrets held, consents to renew
    0 held, 1 to 4 a year
    Alerts: bank secrets held, permissions granted, upkeep
    0 held, 2 granted, none
    Statements: uploads and time
    48 a year, 144 minutes
    History on day one: login, consent, email alerts, SMS, statements
    12, 12, 24, 6, and 0 to 12 months

    Illustrative. Day-one history depends on your portal, the consent's date range, what your inbox and phone kept, and how many past statements you upload.

    RouteSeesCan doYou must trustRevoke by
    Net-banking loginThe full ledger the portal showsIn principle, act on the accountThe app, holding 8 live secretsChanging the password, which breaks it
    Account AggregatorConsented accounts and datesRead onlyThe regulated recipientRevoking in the aggregator's app
    Alerts (SMS, email)What each alert saysRead onlyThe app, with your inbox or SMSRemoving the permission
    Statement uploadEvery line, one period at a timeNothing: it is a fileWhoever holds the PDFDeletion only
    Household of 2 bank accounts and 2 credit cards; one separate login assumed per account.
    • Alert upkeep does not grow with accounts: a fifth account adds nothing to its 2 permissions, but 12 uploads a year to route 4 and one more password to route 1
    • Day-one history favours routes that pull from the bank; alerts give you only what your inbox and phone kept

    What 'no bank login' does not guarantee

    The technique

    No login is not no access

    An app holding no bank credential can still hold your inbox or every SMS on your phone: one holds your life, the other the OTPs that guard your accounts.

    'No bank login' promises that the app cannot act on your account. Nothing more.

    On Android, SMS permission is not limited to bank senders; the permission that reads a debit alert can read the OTP a minute later. What stops it is design and policy, not impossibility. On email, the read scope decides whether the app sees only the messages it searches for or the whole mailbox.

    Four checks for any alert-based tracker, this one included. Read scope: which emails and SMS senders, stated specifically. Raw messages: whether full text is uploaded or only the extracted transactions. Deletion: whether you can erase what it stored from inside the app. Credentials: no tracker ever needs your UPI PIN, whether you pay on GPay, PhonePe or Paytm, because the PIN approves payments and tracking only reads them.

    Then the red flags, which apply to any finance app.

    • It asks for an OTP, for any reason. An OTP authorises an action, and reading data never needs one
    • It asks for your UPI PIN. The PIN approves payments in your own payment app and nothing else has a use for it
    • It asks for a card CVV to verify a card for tracking. The CVV authorises online payments, and a tracker makes none
    • It asks you to install a screen-sharing or remote-access app for support. Whoever sees your screen sees every OTP as it lands

    When a linked route wins, and five checks

    Three situations favour a bank-linked route, meaning the Account Aggregator route and never a shared password. Business or high-volume accounts, with dozens of transactions a day and charges no alert mentions, need the bank's full ledger. Needing a complete history now, for a loan application or tax filing, favours a consent that pulls a year on day one, or 48 statement uploads, over whatever alerts your phone kept. And if alerts go to a number or inbox you no longer use, or you are on an iPhone, the alert route has little to read.

    For everything else, and for any app, five questions settle it. The first two decide most cases.

    • What exactly am I handing over: a password, a consent, a permission to read messages, or a file?
    • Could the app act on my account with it, even in principle? If the answer involves a password or an OTP, stop there
    • What does it store: raw messages and files, or extracted transactions only, and where?
    • How do I revoke it myself, today, without asking the company, and how do I delete what it already holds?
    • Has it ever asked for an OTP, a UPI PIN, a CVV or a screen share? One yes is enough to uninstall it

    Common questions

    Is an expense tracker without bank login safe?

    Safer on one axis: an app with no bank credential cannot act on your account. It is not automatically safe on the others, because it reads your email or SMS instead, and those hold more about you than your bank account. Check what it reads, whether raw messages leave your phone, how you revoke it, and that it never asks for an OTP or UPI PIN.

    Which is safer, an Account Aggregator link or an SMS and email tracker?

    Neither can move money. The aggregator route sees more, including lines no alert mentions, and needs a consent you renew; the alert route needs no renewal but relies on the app handling your inbox or SMS well. Both are a different category from sharing a net-banking password, which is the one to refuse.

    Does an expense tracker need my OTP or UPI PIN?

    No. An OTP authorises an action and a UPI PIN approves a payment; tracking only reads what already happened. An app that asks for either, or for a card CVV or a screen share, wants a capability the job does not require.

    Can an app that reads my SMS see my OTPs?

    On Android, the permission that reads bank alerts can read other messages, OTPs included. What stops it is design and policy: filtering to transactional senders, ignoring OTPs and not uploading raw text. Ask the app to state all three, and switch the permission off if the answer is vague.

    Is there an expense tracker without bank login for iPhone?

    The SMS half of the alert route does not exist on iPhone, because iOS does not let apps read SMS. What remains is email alerts, statement uploads or an Account Aggregator consent. On an iPhone, Unyfy works through its web app from email alerts and statements, so judge those routes with the same five questions.

    Every automatic expense tracker uses one of four routes, and they differ less in what they see than in what they can do. A net-banking password lets an app act as you; a consent, an alert reader and an uploaded statement can only read. For the household, that is 8 live secrets and 16 re-links a year, against 2 permissions and no upkeep, or 48 uploads. 'No bank login' removes the worst route. It does not tell you what the app takes instead, so read the ledger. Informational page, not financial advice. Every figure is illustrative; your bank's terms and each app's privacy policy govern what is shared and kept, not this page.

    Our Partners

    Partnered with India's Leading Banks & NBFCs

    We work with the most trusted financial institutions to bring you the best loan offers.

    HDFC Bank logo
    ICICI Bank logo
    Axis Bank
    State Bank of India logo
    IDFC First Bank logo
    Kotak Mahindra logo
    IndusInd Bank logo
    Yes Bank logo
    Bajaj Finserv logo
    Tata Capital logo

    50,000+

    Happy Customers

    ₹500 Cr+

    Loans Disbursed

    4.8/5

    Customer Rating