Automatic expense tracking has to get its data from somewhere, and in India there are only a handful of places it can come from. Each asks for something different, and the differences are not cosmetic — one of them hands a third party the credentials that move your money. Worth knowing which is which before installing anything.
No expense tracker needs your net-banking password. Anything asking for it is either scraping your bank’s website on your behalf, or it is not what it says it is. The legitimate capture routes are SMS inbox access (Android only, broad permission), notification reading (Android only, fragile), email alerts (works on both platforms, but the mechanism matters), and Account Aggregator consent (RBI-regulated, read-only, heavier to set up). Only some of them can be revoked without depending on the app’s own interface.
| Mechanism | What you hand over | Works on iOS | Revocable independently |
|---|---|---|---|
| SMS inbox | Your entire inbox, including every OTP | No | Yes, in Android settings |
| Notification reading | Every notification on the device | No | Yes, in Android settings |
| Email, via a scoped API | Read-only access to matching messages | Yes | Yes, from your Google Account |
| Email, via forwarding | Your bank mail, routed to an address the app owns | Yes | Only by undoing the forwarding rule |
| Account Aggregator | Consent to share account data, RBI-regulated | Yes | Yes, at the AA |
| Net-banking credentials | The keys to your account | Yes | Only by changing your password |
The last row is the one to refuse outright. Handing over net-banking credentials gives a third party everything needed to transact, not merely to read, and no amount of stated good intent changes what the credential can do. Your bank’s own terms almost certainly make sharing it your liability rather than theirs.
Plenty of apps advertise “no bank login required” truthfully and still ask for a great deal. SMS inbox permission on Android is the clearest case: it is not a bank credential, but Android cannot scope it to your bank’s texts. The permission is the whole inbox, every OTP included, and Google restricts which apps may even request it — an app needs to be your default SMS handler or hold an approved declaration. The full argument is on expense tracking without SMS permission.
Email deserves the same scrutiny, and here the mechanism matters more than the word. Being asked to create a filter that forwards your bank alerts to an address the app controls means your financial mail now arrives on someone else’s mail server. There is no scope, no consent screen and no revocation page — only a forwarding rule you have to remember to delete. That is a materially different arrangement from a scoped API grant, even though both end with “we read your email”.
Can you revoke access without the app’s cooperation? A Google API grant is withdrawn from your own Google Account permissions page. An Account Aggregator consent is withdrawn at the AA. A forwarding rule and a stored password are withdrawn only by you remembering they exist. If revocation runs through the vendor’s interface, you are trusting the interface.
India’s Account Aggregator framework is RBI-regulated infrastructure for consented, read-only financial data sharing. You approve a specific purpose, a specific data set and a specific duration, and you can revoke it. It is genuinely the most rigorous of the routes here and the right answer for plenty of use cases.
Its cost is friction and immediacy. Consent flows are long, institutional participation is uneven, and data arrives in periodic pulls rather than the moment a transaction happens. For a spending tracker, where the value is largely in seeing a charge appear as it lands, that lag matters. A trade-off rather than a verdict.
Read-only access to matching messages in your Gmail, granted through Google’s own consent screen at the narrowest workable scope. No net-banking password. No SMS permission. No forwarding rule pointing at a mailbox we own — your mail stays in your mailbox, and the Gmail API notifies us when something matching arrives. Revoke it from your Google Account permissions page without opening our app.
That route also means an outside party reviews the security of what holds your data: Google classifies mailbox read access as a restricted scope and requires an independent third-party security assessment before an app may use it. The detail is on the security page.
Yes, and none of the legitimate ones need it. Automatic capture can come from bank SMS on Android, from notifications, from email transaction alerts through a scoped API, or from an RBI-regulated Account Aggregator consent. Any app requesting net-banking credentials is asking for the ability to transact, not just to read.
It is a weaker arrangement than a scoped API grant. Forwarding routes your financial mail to a server the app controls, with no consent scope, no permissions page, and no revocation route other than deleting the rule yourself. It also usually means the app never went through the API review that scoped access requires.
It is RBI-regulated infrastructure for consented, read-only sharing of financial data, where you approve a specific purpose, data set and duration and can revoke it. It is the most rigorous option available. The trade-offs are a longer consent flow, uneven institutional coverage, and data arriving in periodic pulls rather than instantly.
A Google API grant or an Account Aggregator consent, because both are revoked from a page you control rather than from inside the app. SMS and notification permissions are also revocable in Android settings. A forwarding rule and a shared password are hardest, because nothing reminds you they are still active.
Usually because the capture layer they built needs it. An app whose parsing engine reads bank SMS has to request the whole inbox, since Android cannot grant access to a single sender. That is an architectural consequence rather than a choice about your privacy, but it is still a cost you carry.
TLDR Money reads transaction alerts in your Gmail through Google’s own consent screen. Never your texts, never your OTPs, never your bank login — and you can cut it off from your Google Account without opening the app.
Join the waitlistNo spam, ever.
Facts on this page verified 5 August 2026. Anything about another company changes without notice; if something here is out of date, tell us at [email protected] and it gets corrected.
This is an explanation, not advice about your money. TLDR Money is not a registered investment adviser and earns no commission on any product mentioned. Where another company is described, the description reflects publicly available information on the date above and may since have changed.