Compare · Privacy

Expense trackers that never ask for your bank login

Automatic expense tracking has to get its data from somewhere, and in India there are only a handful of places it can come from. Each asks for something different, and the differences are not cosmetic — one of them hands a third party the credentials that move your money. Worth knowing which is which before installing anything.

The short answer

No expense tracker needs your net-banking password. Anything asking for it is either scraping your bank’s website on your behalf, or it is not what it says it is. The legitimate capture routes are SMS inbox access (Android only, broad permission), notification reading (Android only, fragile), email alerts (works on both platforms, but the mechanism matters), and Account Aggregator consent (RBI-regulated, read-only, heavier to set up). Only some of them can be revoked without depending on the app’s own interface.

The routes, and what each costs you

Capture mechanisms available to an Indian expense tracker, and what each requires. “Revocable independently” means you can cut access off without going through the app.
Mechanism What you hand over Works on iOS Revocable independently
SMS inboxYour entire inbox, including every OTPNoYes, in Android settings
Notification readingEvery notification on the deviceNoYes, in Android settings
Email, via a scoped APIRead-only access to matching messagesYesYes, from your Google Account
Email, via forwardingYour bank mail, routed to an address the app ownsYesOnly by undoing the forwarding rule
Account AggregatorConsent to share account data, RBI-regulatedYesYes, at the AA
Net-banking credentialsThe keys to your accountYesOnly by changing your password

The last row is the one to refuse outright. Handing over net-banking credentials gives a third party everything needed to transact, not merely to read, and no amount of stated good intent changes what the credential can do. Your bank’s own terms almost certainly make sharing it your liability rather than theirs.

Why “no bank login” is not the same as “no access”

Plenty of apps advertise “no bank login required” truthfully and still ask for a great deal. SMS inbox permission on Android is the clearest case: it is not a bank credential, but Android cannot scope it to your bank’s texts. The permission is the whole inbox, every OTP included, and Google restricts which apps may even request it — an app needs to be your default SMS handler or hold an approved declaration. The full argument is on expense tracking without SMS permission.

Email deserves the same scrutiny, and here the mechanism matters more than the word. Being asked to create a filter that forwards your bank alerts to an address the app controls means your financial mail now arrives on someone else’s mail server. There is no scope, no consent screen and no revocation page — only a forwarding rule you have to remember to delete. That is a materially different arrangement from a scoped API grant, even though both end with “we read your email”.

The question that separates them

Can you revoke access without the app’s cooperation? A Google API grant is withdrawn from your own Google Account permissions page. An Account Aggregator consent is withdrawn at the AA. A forwarding rule and a stored password are withdrawn only by you remembering they exist. If revocation runs through the vendor’s interface, you are trusting the interface.

What Account Aggregator actually is

India’s Account Aggregator framework is RBI-regulated infrastructure for consented, read-only financial data sharing. You approve a specific purpose, a specific data set and a specific duration, and you can revoke it. It is genuinely the most rigorous of the routes here and the right answer for plenty of use cases.

Its cost is friction and immediacy. Consent flows are long, institutional participation is uneven, and data arrives in periodic pulls rather than the moment a transaction happens. For a spending tracker, where the value is largely in seeing a charge appear as it lands, that lag matters. A trade-off rather than a verdict.

Where TLDR Money sits

Read-only access to matching messages in your Gmail, granted through Google’s own consent screen at the narrowest workable scope. No net-banking password. No SMS permission. No forwarding rule pointing at a mailbox we own — your mail stays in your mailbox, and the Gmail API notifies us when something matching arrives. Revoke it from your Google Account permissions page without opening our app.

That route also means an outside party reviews the security of what holds your data: Google classifies mailbox read access as a restricted scope and requires an independent third-party security assessment before an app may use it. The detail is on the security page.

Questions worth asking

Can an expense tracker work without my net-banking password?

Yes, and none of the legitimate ones need it. Automatic capture can come from bank SMS on Android, from notifications, from email transaction alerts through a scoped API, or from an RBI-regulated Account Aggregator consent. Any app requesting net-banking credentials is asking for the ability to transact, not just to read.

Is it safe to forward my bank emails to an app’s own address?

It is a weaker arrangement than a scoped API grant. Forwarding routes your financial mail to a server the app controls, with no consent scope, no permissions page, and no revocation route other than deleting the rule yourself. It also usually means the app never went through the API review that scoped access requires.

What is an Account Aggregator and should I use one?

It is RBI-regulated infrastructure for consented, read-only sharing of financial data, where you approve a specific purpose, data set and duration and can revoke it. It is the most rigorous option available. The trade-offs are a longer consent flow, uneven institutional coverage, and data arriving in periodic pulls rather than instantly.

Which capture method is easiest to turn off?

A Google API grant or an Account Aggregator consent, because both are revoked from a page you control rather than from inside the app. SMS and notification permissions are also revocable in Android settings. A forwarding rule and a shared password are hardest, because nothing reminds you they are still active.

Why do some trackers ask for so much access?

Usually because the capture layer they built needs it. An app whose parsing engine reads bank SMS has to request the whole inbox, since Android cannot grant access to a single sender. That is an architectural consequence rather than a choice about your privacy, but it is still a cost you carry.

Related

Tracker vs broker app A broker shows what it custodies. That gap is structural, not a missing feature. Tracking without investing Most net worth tools are investment platforms. What changes when there is nothing to sell you. FIRE vs retirement calculator Same arithmetic, twice the horizon, and EPF locked for the first stretch of it. Expense tracking on an iPhone What is actually possible on iOS, given that no app can read the SMS inbox. All eleven calculators Retirement planner, home loan EMI and prepayment, FIRE, Coast FIRE, net worth, FOIR, rent vs buy, rental yield, SIP vs EMI, inflation, life cycle funds.

Read-only, scoped, and revocable without us

TLDR Money reads transaction alerts in your Gmail through Google’s own consent screen. Never your texts, never your OTPs, never your bank login — and you can cut it off from your Google Account without opening the app.

Join the waitlist

No spam, ever.

Facts on this page verified 5 August 2026. Anything about another company changes without notice; if something here is out of date, tell us at [email protected] and it gets corrected.

This is an explanation, not advice about your money. TLDR Money is not a registered investment adviser and earns no commission on any product mentioned. Where another company is described, the description reflects publicly available information on the date above and may since have changed.