Try an experiment: open last month's bank statement — assume it's yours, here in Portugal — and read it as if it belonged to a stranger. In ten minutes you know where that person lives and works, what time they leave home, where they buy food, which gym they pay for (and since when), whether they have children, pets, credit. You know whether they donated to a church or a cause, what they bought at the pharmacy, when a relationship began — and, from the dinners for two that disappear, when it ended. A bank statement is the most honest diary there is, written with no wish to impress anyone.
Science confirms that this portrait doesn't need a name. In 2015, an MIT team led by Yves-Alexandre de Montjoye analysed three months of credit card records from 1.1 million people, in a study published in the journal Science. The conclusion: four spatio-temporal points — four purchases, with date and location — are enough to uniquely reidentify 90% of people in a dataset with no names. And knowing the price of a transaction increases the reidentification risk by, on average, a further 22% [1]. Removing the name from a statement doesn't make it anonymous; it just makes it an easy puzzle.
An industry that knows more about you than your family does
And this portrait has had a market for a long time. In 2014, the Federal Trade Commission (FTC), the US trade regulator, studied nine data brokers — companies that buy, cross-reference and resell information about consumers, typically without consumers knowing it. The findings are striking in scale: data brokers hold billions of data elements on virtually every US consumer; one of the brokers studied alone held information on more than 1.4 billion consumer transactions and 700 billion data elements, and another added more than 3 billion new data points a month [2]. More important than the volume is what they do with it: they combine this data to infer what you never declared — ethnicity, income, religion, political leanings, age and health conditions [2].
Edith Ramirez, then chair of the FTC, put it this way: "The extent of consumer profiling today means that data brokers often know as much – or even more – about us than our family and friends, including our online and in-store purchases, our political and religious affiliations, our income and socioeconomic status, and more" [2].
"Out of control" — literally
Time hasn't tempered the appetite; it has industrialised it. In January 2020, Norway's Consumer Council (Forbrukerrådet) published the "Out of Control" report, with a technical test that has become a reference point: ten popular apps transmitted personal data to at least 135 distinct third-party companies involved in advertising and behavioural profiling [3][4]. Every time the app was opened, it silently fed a chain of entities the user never saw or consciously authorised.
Finn Myrstad, Forbrukerrådet's director of digital policy, was direct: "These practices are out of control and in breach of European data protection legislation. The extent of tracking makes it impossible for us to make informed choices about how our personal data is collected, shared and used" [3].
And your bank statement? Financial data enters the game
For years, transaction data lived relatively protected inside banks in Portugal. European open banking (PSD2) opened it up — in a regulated way, with authentication at the bank and revocable consent — and the FIDA framework, currently under negotiation in Brussels, is preparing to extend this to savings, insurance and pensions. The direction is good: the data starts answering to you, not to the institution. But the European Data Protection Supervisor (EDPS) warned, when assessing these proposals, where we can't go. In the words of Wojciech Wiewiórowski: "Increased sharing of financial data should open new opportunities for individuals, not close doors. Without clear boundaries, one could see higher prices for important financial services or the exclusion of customers with an unfavourable risk profile" [5].
This is where financial management apps come in — as a category. To serve you, an app like this has to read your transactions: that's the raw material behind the visibility it gives back to you. So the right question is never "does this app access my data?" — it's "who else accesses it, for what purposes, and how does this company make money?". The GDPR provides the legal test, in the principle of data minimisation: data must be "adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed" (Article 5(1)(c)) [6]. An app that collects more than it needs, or uses your data for purposes that aren't yours, fails the test from the outset.
Follow the business model
There's a heuristic worth more than any privacy policy: every service lives off something. If you pay a subscription, you're the customer, and the company's incentive is to serve you. If you pay nothing and the company lives off advertising or "data partnerships", you're the raw material — and, as we've seen, a bank statement is one of the most valuable raw materials there is. This isn't an accusation against any particular app; it's accounting. The business model is the real privacy policy of any service — the rest is legal drafting.
How AtivaMoney handles your bank statements
AtivaMoney was built to answer this question well — because we handle exactly the category of data this article is about:
- You pay with money, not with data. Our business model is the subscription. We don't sell data, we don't share your profile for marketing, and we don't do behavioural advertising.
- Minimisation, for real. We collect what the app needs to function — visibility, categorisation, balance projection — and nothing for "future monetisation". Having legal access to more doesn't mean we're obliged to use it.
- The AI learns only from you. Automatic categorisation trains on your own patterns, to serve you — it doesn't feed global profiles or audience segments.
- European jurisdiction. Your data lives on sovereign EU infrastructure — we've explained why jurisdiction matters as much as the law does.
- An exit door that's always open. You export your data (CSV/PDF) and request deletion whenever you want — and, coming up on the roadmap for this August 2026, is the option to store your data in your own cloud.
Five questions before you connect your bank to any app
- How does this company make money? If the answer isn't visible on a pricing page, assume the answer is you.
- Does the privacy policy name who it shares data with? Look for "partners", "affiliates" and "personalised advertising" — vagueness here is information.
- Where does the data live, and under what jurisdiction? EU/EEA by default; transfers outside it should be identified and justified.
- Is the connection to your bank regulated and revocable? Open banking (PSD2) means authenticating at your bank, never handing over your credentials — and cutting off access whenever you want.
- Can you export and delete everything yourself? Articles 17 and 20 of the GDPR give you that right; if leaving means writing to support, that's the warning sign.
Your bank statement tells your life with a fidelity no photo album has — and it will keep telling it. The only variable is the audience. Don't wait for your data to circulate before you react. Get ahead of it: choose today who reads your story.
References
- Y.-A. de Montjoye, L. Radaelli, V. K. Singh, A. Pentland — Unique in the shopping mall: On the reidentifiability of credit card metadata, Science 347(6221), pp. 536–539, 30 de janeiro de 2015
- Federal Trade Commission — Data Brokers: A Call for Transparency and Accountability (comunicado e relatório, declarações de Edith Ramirez), 27 de maio de 2014
- Forbrukerrådet (Conselho de Consumidores da Noruega) — New study: The advertising industry is systematically breaking the law (relatório "Out of Control", declarações de Finn Myrstad), 14 de janeiro de 2020
- mnemonic — Out of Control: advertisers receive large amounts of personal data from popular mobile apps (relatório técnico do estudo do Forbrukerrådet), janeiro de 2020
- European Data Protection Supervisor — Financial and payment services: use of personal data should remain proportionate and fair (Opinions 38/2023 e 39/2023, declarações de Wojciech Wiewiórowski), 23 de agosto de 2023
- Regulamento (UE) 2016/679 (RGPD), artigo 5.º, n.º 1, alínea c) — texto oficial em português, EUR-Lex
This article was translated from the Portuguese original.