Money Clarity

    What is an Account Aggregator, and should you use one?

    An Account Aggregator is an RBI-regulated intermediary that moves your financial data from the institution that holds it to one you want to share it with - only with your explicit consent, only for a stated purpose, only for a stated period, and revocable at any moment. The aggregator itself cannot read what passes through it. It exists because the alternative, which is handing over your net-banking password, is indefensible.

    The problem: the old way of sharing your own data is terrible

    Until this framework existed, letting an app see your bank data meant either giving it your credentials or emailing PDFs around. Both are worse than most people realise.

    • Sharing net-banking credentials gives away full transactional access, not read-only access, and usually voids your bank's protection terms
    • Emailing statement PDFs leaves permanent copies in inboxes and on servers you do not control
    • Neither has an expiry, so access you granted in 2023 is still access today
    • Neither has a revocation mechanism you can operate yourself

    How the framework actually works

    Three parties, and the important structural point is what the aggregator can and cannot see.

    • The Financial Information Provider is who holds your data - your bank, insurer, mutual fund registry
    • The Financial Information User is who wants it - a lender, an advisor, a personal finance app
    • The Account Aggregator is an RBI-licensed NBFC-AA that moves it between them
    • The data is encrypted end to end, so the aggregator transports it without being able to read it - it is a consent pipe, not a database
    • Every request states the purpose, the exact data types, the frequency and the duration, and you approve or refuse that specific request
    • You can revoke consent at any time, and the flow stops

    What it protects, and what it does not

    Honest limits, because the framework is genuinely good and is still not magic.

    • It protects the sharing: no credentials change hands, consent is explicit, scoped and time-bound, and revocation is yours to operate
    • It does not control what the receiving institution does with the data once delivered - their privacy policy governs that, not the framework
    • An AA cannot see or sell your data, but the FIU you shared it with has it
    • Coverage is not universal - not every bank, insurer or account type is live, so a picture built this way can be incomplete
    • Check the AA is on RBI's list of licensed NBFC-AAs before consenting to anything

    What to check before you consent

    The consent screen carries all of this. Reading it takes twenty seconds and is the whole point of the design.

    • The purpose stated - it should match what you are actually trying to do
    • The data types requested - a lender assessing eligibility does not need five years of everything
    • The duration - a one-time pull and a one-year recurring feed are very different consents
    • The frequency - daily pulls for a one-time loan assessment is a mismatch worth refusing
    • Where to revoke, which is inside the AA app, not the app that asked you

    How Unyfy reads your data today

    Stated plainly, because a page about data-sharing safety that is vague about its own method would be worthless.

    • Unyfy currently reads bank and card transaction alerts, and statement PDFs you upload
    • Gmail access is optional and scoped to transaction and statement emails - what is read and stored, and how to revoke in under a minute, is set out at /is-it-safe-to-connect-gmail
    • SMS capture and manual statement upload work without connecting email at all
    • Whichever route you use, ask the five questions on the Gmail page before granting anything to any app, including this one

    Common questions

    What is an Account Aggregator in India?

    An RBI-licensed NBFC-AA that moves your financial data from institutions that hold it to institutions you choose to share it with, under your explicit, purpose-bound, time-limited and revocable consent. The data passes through encrypted, so the aggregator itself cannot read it.

    Is an Account Aggregator safe?

    The sharing mechanism is a substantial improvement — no credentials change hands, consent names the purpose, data types, frequency and duration, and you can revoke it yourself at any time. What it does not control is what the receiving institution does with the data after delivery; that is governed by their privacy policy. Check the aggregator appears on RBI’s list of licensed NBFC-AAs.

    Can an Account Aggregator see or sell my data?

    No. The framework is designed so data passes through encrypted and the aggregator cannot read, store or trade it — it carries consent and data, not access. The institution you shared with does receive the data, which is why the purpose and duration on the consent screen are worth reading.

    If an app asks for your net-banking password, refuse. That is the comparison worth holding on to. Consent that is explicit, scoped, time-limited and revocable by you is a far better arrangement than anything that existed before, and it is worth understanding well enough to read the consent screen rather than tapping through it.

    Written by Danish Mirza, founder of Unyfy. 14 years in Indian lending and collections at Standard Chartered, Barclays, Ola Money and Uni Cards.
    Last reviewed 2026-09-09.

    Our Partners

    Partnered with India's Leading Banks & NBFCs

    We work with the most trusted financial institutions to bring you the best loan offers.

    HDFC Bank logo
    ICICI Bank logo
    Axis Bank
    State Bank of India logo
    IDFC First Bank logo
    Kotak Mahindra logo
    IndusInd Bank logo
    Yes Bank logo
    Bajaj Finserv logo
    Tata Capital logo

    50,000+

    Happy Customers

    ₹500 Cr+

    Loans Disbursed

    4.8/5

    Customer Rating