232 APPS TRACKED · 227 CLAUSES ON FILE · 38 WITH NO CLAUSE TO QUOTE

Which finance apps train AI on your data?

Of the 19 finance apps on file, 6 are graded, and every one of them trains on your data by default. The other 13 have a policy that doesn't say either way. The best graded is Monzo (D) and the worst is Commonwealth Bank (F).

19 APPS TRACKED IN THIS CATEGORY · WORST FIRST

Do they train on what you spend, send and borrow?

The banks are read together on the banks page, and the finding there is silence: the incumbents that hold every payee and balance mostly never raise the subject. This note reads the rest of the category: the payment and money apps, and the banks that page doesn’t single out. They divide by what the company’s own words offer. Training with no way out. Training with an objection you have to write in to make. And policies that mention AI and never say whether you’re in the training set.

The banks, read together →

Trains, and names no way out

Robinhood names one thing it trains on, in a list it leaves open: “including but not limited to your inputs and conversations with our chatbots and AI features”. The sentence is hedged twice, “may be used” and “from time to time”, and neither hedge is a control. What follows it, “We provide notice and obtain consent where required under applicable law”, describes the law and doesn’t offer a choice. The opt-outs the policy does walk through govern advertising and profile visibility. Whether trading data trains anything is not stated.

Commonwealth Bank puts the use in an “Artificial Intelligence” row of its purposes table, with your transactions as its own example. It uses your information, “for example your transaction information, to train, develop, and in deployed artificial intelligence models”. The only opt-outs offered are for direct marketing and advertising, and neither reaches the models. Customers in the EEA and the UK can object under the GDPR appendix. Australian customers have nothing equivalent. That’s what an F is: on by default, with no way out.

PayPal’s sentence is unusually direct, and is quoted in full on the banks page. Two things that page doesn’t draw out. The sentence names the models, “train our artificial intelligence (AI) models that power our Services”. And it never says the data is anonymised or aggregated first, as smaller companies on this site do. The one route that could reach it, an objection to legitimate-interest processing, is offered “where applicable by law”, and the notice never says which legal basis the training rests on.

Trains, and the way out is a message

Monzo answers in a section headed Artificial intelligence: it may use your data to “train and analyse the performance of our AI systems”, and only where it is “not possible to anonymise your data”. Its AI suppliers are barred from training on you. But every toggle in the app governs marketing or advertising. The route that reaches training is the statutory objection to processing on legitimate interests “or for research and statistical reasons”, made by contacting Monzo. A switch that is a message is the D.

Revolut lists “develop, train and test our internal models” among what it does with your personal data, on a legitimate-interests basis, and says separately that some credit decisions are made using artificial intelligence without any initial human input. There’s a privacy setting in the app, and it’s easy to mistake for the control. It governs credit reference agency data, not the training list. The route that does reach training is an objection by email, and the same document warns that “we may need to close your account”.

Never says whether you are in the training set

The policy is published as a PDF per country, and the German-account version has a section headed “Use of Artificial Intelligence Systems”. It says those systems “support decision-making, automate individual processing steps, or assist with analysis, classification, or prediction tasks”, and that transaction data is analysed “to improve our products and services”. That’s data going into AI systems, described carefully. No form of train, model or machine learning appears, so whether any of them is trained on you is not stated, and not inferred.

DBS names artificial intelligence as an interface, not as a purpose: personal data may reach the bank “through interfaces powered by artificial intelligence”. On training in any form, the policy is silent. A retail bank’s records are among the most revealing a policy can cover, and this one never says whether they train a model.

Every quotation above is the company’s own words, read from a dated, archived copy of its document. The check date and the archived copy are on each verdict, and every grade here is the one on the company’s own entry. An opt-out from marketing isn’t an opt-out from training. UNCLEAR is a finding about the document, never an accusation about the company. A policy that comes to answer the question is re-read against it. How grades are set · Right of reply