What Happens When You Connect Your Bank Account
Account aggregators let you securely link your bank account to MyFam360. Here's exactly how the process works and what data you're sharing.
When you decide to connect your bank account to MyFam360, you might naturally worry: “Am I giving MyFam360 access to my bank login? Can they see everything? What if they get hacked?”
These are reasonable concerns. This post explains exactly what happens, how the Account Aggregator framework protects you, and why this approach is safer than alternatives.
The Scenario You Should Avoid
Imagine a finance app asks: “Enter your bank username and password so we can pull your transactions.”
This is a red flag. Here’s why:
- You’re sharing your bank credentials with a third party — if MyFam360 is compromised, your login is compromised
- MyFam360 becomes liable for your bank account security — if credentials are leaked, you and the bank might both pursue legal action against them
- It violates your bank’s terms of service — you’re not supposed to share your login with anyone
- It’s not verifiable — there’s no audit trail proving you consented to this specific access
Better finance apps don’t ask for this. Better apps use an Account Aggregator (AA).
What an Account Aggregator Is (And Why You Should Care)
An Account Aggregator is an RBI-regulated financial service that acts as a secure intermediary between you and your bank.
The Flow (Simplified)
You → Account Aggregator ← Your Bank
↓
MyFam360
What you do:
- Initiate bank connection in MyFam360
- MyFam360 redirects you to the AA’s secure portal
- You authenticate with your bank (username/password)
- You approve MyFam360’s request to access your transactions
- The AA retrieves your transaction history
- The AA shares sanitized transaction data with MyFam360
- MyFam360 imports your transactions
Key point: Your bank credentials never leave your bank. You never share them with MyFam360.
Why This Matters: Three Scenarios
Scenario 1: MyFam360 Gets Hacked
Without AA (risky):
- Hackers find MyFam360’s database with stored bank credentials
- They use your credentials to access your bank account
- They can withdraw money, open loans, change account settings
With AA (safe):
- Hackers find MyFam360’s database
- They see only transaction history that was already synced
- They cannot access your bank account because they don’t have your credentials
- Your bank remains secure because only the AA has your login
Scenario 2: An Employee Goes Rogue
Without AA (risky):
- A disgruntled MyFam360 employee with database access steals your credentials
- They can directly access your bank account
With AA (safe):
- An employee can see only transaction data they’ve already accessed
- They cannot steal credentials because MyFam360 never stores them
- All AA access is logged and auditable — if someone tries to retrieve your data improperly, it’s detected
Scenario 3: Data Breach Recovery
Without AA (difficult):
- Your bank credentials were compromised
- You must change your bank password immediately
- You must assume your account is potentially at risk
- You may need to cancel cards, monitor accounts, file fraud reports
With AA (simpler):
- Transaction history in MyFam360 is exposed
- But your bank account itself is safe (credentials were never shared)
- You simply revoke MyFam360’s access through the AA
- No action needed on your bank account
How the Account Aggregator Works (Technical)
When you connect your bank account, here’s what actually happens:
Step 1: You Initiate Connection
You click “Connect Bank Account” in MyFam360 Settings. MyFam360 redirects you to the AA’s secure portal with a consent request:
Consent Request:
- Purpose: Retrieve your bank transactions for personal finance tracking
- Scope: Read-only access to transaction history (no write access)
- Duration: 12 months (renewable)
- Data types: Transaction date, amount, merchant, transaction type
Step 2: AA-to-Bank Authentication
You log in with your actual bank credentials — directly to your bank’s secure portal (facilitated by the AA). Your credentials stay with your bank. The AA never sees them.
Step 3: Bank Verifies Consent
Your bank asks: “Do you authorize [AA name] to share your transactions with [MyFam360] for [personal finance tracking]?” You approve.
Step 4: AA Retrieves Data
The AA connects to your bank using standard banking APIs (OAuth-like flows) and retrieves:
Transactions:
- 2026-04-15: Debit ₹5,200 | Swiggy | Food & Dining
- 2026-04-14: Debit ₹1,500 | ICICI Bank | Transfer
- 2026-04-13: Credit ₹75,000 | Salary | Employer Transfer
Notice: No personal identifiers, no account number, no PAN. Just transaction data.
Step 5: AA Shares With MyFam360
The AA encrypts and sends this transaction data to MyFam360. MyFam360 receives it over TLS (encrypted in transit) and decrypts it (encrypted at rest).
Step 6: MyFam360 Imports
MyFam360 imports these transactions into your account:
Expense: Swiggy, ₹5,200, Food & Dining, 2026-04-15
Transfer: ICICI Bank, ₹1,500, Transfers, 2026-04-14
Income: Salary, ₹75,000, Salary, 2026-04-13
You can now see all your bank transactions in MyFam360, searchable and categorizable.
What You’re NOT Sharing
To be crystal clear, connecting your bank account does NOT share:
| Data | Shared? | Why Not? |
|---|---|---|
| Bank password | ❌ No | Only your bank sees it |
| Account number | ❌ No | AA sanitizes before sending to MyFam360 |
| Full bank details | ❌ No | Only transaction-level data shared |
| PAN / Tax ID | ❌ No | Not included in transaction data |
| Credit card details | ❌ No | Only transaction amounts, not payment instrument details |
| Personal identification | ❌ No | Transaction data is anonymized |
| Account balance | ❌ Depends* | *Only if explicitly included in AA data; can be disabled |
The RBI Framework (Regulatory Protection)
Account Aggregators exist because of RBI’s Open Banking Framework. Here’s what that means for you:
You Have Legal Rights
Under the RBI’s Consumer Protection Framework:
- Right to know — You must be informed what data is being shared, with whom, and for how long
- Right to consent — Your explicit approval is legally required; it’s not pre-approved
- Right to revoke — You can stop data sharing at any time
- Right to transparency — The AA must maintain audit logs of all data access
- Right to grievance — If something goes wrong, you have a formal complaint procedure
Regulated Participants
All parties involved are RBI-regulated:
- Your Bank — licensed by RBI, bound by data protection regulations
- Account Aggregator — licensed by RBI, subject to strict security and audit requirements
- Data Recipient (MyFam360) — not directly licensed, but contracted to comply with AA standards
If an AA violates your rights, you can file a complaint with the RBI’s Consumer Grievance Redressal System.
Disconnecting Your Bank Account
You can disconnect at any time. Three methods:
Method 1: MyFam360 Settings (Easiest)
Settings → Bank Account → Disconnect
MyFam360 sends a revocation request to the AA. Within seconds, MyFam360’s access is terminated.
Method 2: AA Customer Portal
Log in to the Account Aggregator’s app/portal → Revoke MyFam360 access.
This also immediately terminates MyFam360’s access.
Method 3: Direct Bank Request
Contact your bank and inform them you’ve revoked MyFam360’s access through your account settings. (This is redundant if you’ve used methods 1 or 2, but you can do it for extra assurance.)
What Happens After Disconnection
- ✅ No new transactions are synced to MyFam360
- ✅ Past transactions remain visible in MyFam360 (they’re now local copies)
- ✅ You can manually add transactions if desired
- ✅ Your bank account remains fully secure
Common Concerns (Addressed)
“What if the AA gets hacked?”
The AA (Setu or others) is a regulated financial service with dedicated security teams and insurance. A breach would be public and highly regulated. Your bank account remains protected because credentials are never shared.
”How do I know the AA won’t sell my data?”
RBI regulations strictly prohibit AAs from selling or misusing data. They can only use it for the purposes you consented to. Violations result in license suspension or revocation. It’s not optional compliance — it’s structurally enforced.
”What about auto-renewals?”
When your AA consent expires (default: 12 months), you’ll receive a notification. You must explicitly re-approve continued access. It doesn’t auto-renew.
”Can MyFam360 access my credit card if it’s linked to the same bank?”
No. The AA can only access accounts you explicitly connect. If you don’t connect your credit card, MyFam360 never sees it.
”Does the AA work with all Indian banks?”
Yes. All major Indian banks (ICICI, HDFC, Axis, SBI, Kotak, Federal, IndusInd, Yes Bank, etc.) are part of the RBI AA network. If you have an account at an Indian bank, your AA can connect it.
The Broader Context: Open Banking in India
Connecting your bank account to MyFam360 via an AA is part of a larger trend called Open Banking.
Open Banking means:
- You own your financial data
- You can choose to share it with apps you trust
- Sharing is secure and auditable
- You can withdraw sharing at any time
This is transformative for personal finance in India. It means:
- Better apps — Finance apps can now work with real transaction data instead of asking you to manually enter every transaction
- Lower friction — Connecting your bank takes 30 seconds instead of weeks of manual data entry
- More competition — With APIs standardized by RBI, new finance apps can launch faster and compete on features, not just bank relationships
- Better recommendations — Apps like MyFam360 can give smarter budgeting suggestions because they see your actual spending patterns
What MyFam360 Does With This Data
Once MyFam360 receives your transaction data via the AA, we:
- Categorize — Automatically tag transactions (Food, Transport, Utilities) using merchant names
- Analyze — Calculate your spending patterns, savings rate, budget adherence
- Report — Show you visual reports and insights about your money
- Secure — Encrypt sensitive fields (amounts, account identifiers) at rest
We do NOT:
- Sell or share your data with advertisers
- Use it to train advertising models
- Share it with marketers or brokers
- Use it to make credit decisions about you
- Retain it longer than necessary
Your financial data exists in MyFam360 to serve your financial goals, not ours.
Next Steps: If You Decide to Connect
- Open MyFam360 Settings → Bank Account
- Click “Connect Bank”
- You’ll be redirected to the Account Aggregator (Setu)
- Log in with your bank credentials (on Setu’s secure portal, not MyFam360’s)
- Approve MyFam360’s data request
- Return to MyFam360 — transactions are now syncing
The whole process takes 2–3 minutes.
See Also
- Your Data Rights Under India’s DPDP Act — legal framework and your rights
- How AI Features Work Without Seeing Your Personal Data — privacy-first feature design
- Your Financial Data Is Encrypted at Rest — how we protect synced data
- RBI Account Aggregator Framework — official RBI guidance (external link)
- Privacy Policy (link in app footer) — complete details on data handling
Take control of your family finances — free
MyFam360 lets your whole family track expenses, set budgets, and hit savings goals together. Free to start, no credit card needed.
Free plan available · No credit card required · Cancel anytime
Frequently Asked Questions
What is an Account Aggregator?
An Account Aggregator (AA) is an RBI-regulated financial service that sits between you and your bank. Instead of giving MyFam360 your bank credentials, you give them to the AA. The AA then retrieves your transaction data from your bank and shares it with MyFam360 — securely and with your explicit consent. Think of it as a trusted middleman.
Why does MyFam360 use an Account Aggregator instead of direct bank login?
Direct bank login (entering your username/password into MyFam360) is risky: you'd need to share your bank credentials with a third party, MyFam360 would be liable if they're compromised, and it violates most banks' terms of service. An AA is safer: your credentials never leave your bank, the AA is RBI-regulated, and your consent is auditable. It's the modern standard for open banking in India.
Does connecting my bank account share my personal information?
No. The AA shares only transaction data (amounts, dates, merchant names, transaction types) — never your bank password, PAN, account number, or other personal identifiers. MyFam360 receives a sanitized transaction feed that looks like: 'Debit ₹2,500 to grocery store on Jan 15' without exposing your full account details to MyFam360.
Can I disconnect my bank account at any time?
Yes. You can revoke access through the AA's portal or directly within MyFam360's Settings. Once revoked, the AA stops sharing new transactions with MyFam360 and MyFam360's access to your bank account is immediately terminated. Historical transactions already synced remain in MyFam360 but no new data flows in.
Is the Account Aggregator safe?
Yes. All AAs are RBI-regulated and must comply with strict data security standards, encryption requirements, and audit trails. They're legally required to protect your data and are subject to RBI inspection. Setu (the AA recommended by MyFam360) has 500,000+ active users and is one of India's largest AA operators.
What happens if MyFam360 gets hacked after my bank account is connected?
Even if MyFam360 is compromised, hackers cannot access your bank account. The AA holds the actual connection to your bank. Hackers would only see the transaction history that MyFam360 has already synced (past transactions). They cannot withdraw money, open new accounts, or access your credentials. Your bank account remains protected by the AA's security layer.
Does MyFam360 ever directly connect to my bank?
No. MyFam360 only ever communicates with the Account Aggregator (AA). The AA connects to your bank. This separation is intentional: it means your bank never has to trust MyFam360 with any access, and MyFam360 never has to handle bank credentials.
Can I revoke MyFam360's access to my transaction data later?
Yes. You have three ways to revoke access: (1) Disconnect within MyFam360 Settings → Bank Account, (2) revoke consent through the AA's customer portal, or (3) contact your bank directly (though steps 1–2 are faster). Once revoked, no new transaction data flows to MyFam360, though past transactions remain visible in your MyFam360 account.
Share this article
Related Articles
7 Days of Everything, Unlocked — Why We Built the Auto-Trial
A 7-day Family+ trial activates automatically after onboarding, with no credit card. Here's what unlocks, what changes on expiry, and why we built it.
19 Apr 2026
App GuideExplore MyFam360 Before Entering a Single Rupee
Explore a realistic MyFam360 demo before entering your own financial data. Here's what's inside the Experience Org and why this flow exists.
19 Apr 2026
App GuideHow AI Features Work Without Seeing Your Personal Data
AskAI sends only aggregate spending summaries to AI — never transaction details or personal data. Here's how we protect your privacy.
19 Apr 2026