How PFM Apps Use Your Bank Data in the UAE (Consent Explained)
-
Personal finance management (PFM) apps in the UAE access your bank data through the CBUAE Open Finance framework, never through your banking password.
-
Consent is explicit and specific: you approve a defined list of data, for a defined period, capped at 12 months before renewal.
-
A data-sharing consent is read-only: the app can see balances and transactions but cannot move money, change your account or apply for products.
-
You authenticate inside your own bank's app or the Al Tareq consent app, so the PFM app never handles your credentials.
-
You can revoke consent at any time from the app, your bank, or the Al Tareq consent app, and the provider must delete data it has no legal duty to keep.
-
Regulation prohibits providers from selling your data or re-sharing it with anyone else.
PFM (personal finance management) apps in the UAE connect to your bank through the Central Bank's Open Finance framework: you grant an explicit, read-only, time-limited consent, authenticated inside your own bank's app, and the PFM app receives structured data such as balances and transactions. It never sees your banking password and it cannot move your money under a data-sharing consent. Here is exactly what happens, step by step, and how to stay in control.
Disclosure: Himma, the publisher of this site, is itself a PFM app. This guide describes how the regulated framework applies to any licensed provider, including us.
What is a PFM app and why does it need bank data?
A PFM app aggregates your financial accounts into one view and builds features on top: spending categorisation, budgets, safe-to-spend numbers, savings targets, bill detection, net worth tracking. To do any of that accurately, it needs to read your transactions and balances rather than rely on you typing them in.
Before Open Finance, the only routes were manual uploads or screen scraping, where an app logs into your online banking with your password. Screen scraping breaks bank terms and creates real risk, because whoever holds your password can usually also transact. The UAE's Open Finance Regulation (Circular No. 3 of 2025) replaced that model with licensed, consent-based API access, described in full in what is Open Finance in the UAE.
How does the consent flow actually work?
Under the Al Tareq framework, connecting a bank account follows a standardised journey:
-
The app requests access. Inside the PFM app you choose your bank and see precisely what is being requested: which data categories (for example account details, balances, transactions, standing orders) and for how long.
-
You are handed to your bank to authenticate. The flow redirects you to your own bank's app or the Al Tareq consent app. You log in there with your usual credentials and multi-factor authentication. The PFM app is not part of this step and never sees what you type.
-
You approve a specific consent. Your bank shows you the exact scope and duration. Consent can last up to a maximum of 12 months before it must be renewed; you can set or accept shorter.
-
You are returned to the app, which now receives the approved data through the central Nebras infrastructure, over encrypted connections, as structured data rather than screenshots or scraped pages.
Every consent is recorded centrally, which is why you can later see and manage all of them in one place.
What can a PFM app see, and what can it never do?
The distinction that matters is between data sharing (read-only) and service initiation (payments), which are separate consents under the regulation.
| With your data-sharing consent, the app CAN | Under that same consent, the app CANNOT |
|---|---|
| See account names, numbers and balances | Move, transfer or withdraw money |
| Read transaction history for consented accounts | Change beneficiaries, limits or account settings |
| See standing orders and direct debits | Apply for loans, cards or products in your name |
| Read consented insurance or FX data as those phases go live | See your banking password or PIN (it never has them) |
| Refresh this data periodically during the consent term | Share or sell your data onwards (prohibited by regulation) |
Payment initiation exists in the framework, but it is a separate service initiation consent, approved per payment or per defined mandate, each authenticated with your bank. An app cannot quietly upgrade a read-only consent into payment powers.
A worked example of what read-only looks like in practice. You connect a salary account holding AED 12,300 and a credit card with AED 7,800 outstanding. The PFM app can now tell you that your card interest next month will cost roughly AED 230 at a typical 2.9% monthly rate if you only pay the minimum, and that your dining spend hit AED 1,950 last month against a budget of AED 1,200. What it cannot do is pay the card, move the salary, or open a savings account for you. Acting on the insight stays entirely with you, for instance by adjusting your plan with the UAE budget calculator or applying the method in how to budget on a UAE salary.
How do you revoke consent, and what happens to your data?
You can withdraw a consent at any time through any of three channels:
-
Inside the PFM app itself (look for connected accounts or consents in settings).
-
Through your bank's app, where active consents are listed.
-
Through the Al Tareq consent app, the central dashboard for everything you have approved.
Revocation takes effect immediately: the data connection stops. The provider must then delete your data unless a specific legal obligation requires retention (for example financial record-keeping rules), and it may not keep using it for anything else. Consents also lapse automatically at the end of their term, at most 12 months, unless you actively renew.
Good hygiene: review your consents every few months, the same way you would review app subscriptions, and revoke anything you no longer use.
How is this different from what apps did before?
| Screen scraping (old model) | Open Finance (current model) | |
|---|---|---|
| Credentials | You give the app your banking password | Never shared; you authenticate at your bank |
| Scope | Whatever the login can see | Only the categories you approved |
| Duration | Until you change your password | Fixed term, maximum 12 months |
| Money movement | Technically possible with your login | Impossible under a read-only consent |
| Oversight | None | CBUAE licensing, liability model, audit trail |
| Revocation | Change your password and hope | One tap, centrally recorded, data deletion required |
If an app operating in the UAE still asks you to type your online banking username and password into its own screens, that is the old model and a serious red flag; the warning signs are catalogued in are money apps safe in the UAE?.
Which banks can PFM apps connect to?
Coverage depends on the Open Finance rollout waves: CBD went fully live in December 2025, ADIB and digital banks such as Wio followed in 2026, and remaining institutions are onboarding through the year. A PFM app can only show accounts from banks that are live on the network with the relevant API capabilities. The Open Finance tracker shows current bank participation, wave status, and whether each bank supports balances, transactions and payment initiation. The consumer-by-consumer impact of this rollout is covered in what Open Finance changes for you in 2026.
FAQ
Can a PFM app take money out of my account?
Not under a data-sharing consent, which is strictly read-only. Payments require a separate service initiation consent, and every payment or mandate is authenticated with your bank. Nothing you approve for data viewing gives an app authority to transact.
Does connecting a PFM app hurt my credit score?
No. Open Finance data sharing is completely separate from the AECB (Al Etihad Credit Bureau) system, and granting or revoking a consent is not reported anywhere. Your AECB score is driven by credit behaviour, as explained in your AECB score decoded; you can check your own file per how to check your AECB credit report.
What happens to my data if I delete the app?
Deleting the app does not by itself revoke consent, the data connection can technically remain active until it expires. Revoke the consent first (in the app, your bank's app, or the Al Tareq consent app), then delete. After revocation the provider must erase data it is not legally required to retain.
Can the app see my banking password?
No, at no point. Authentication happens entirely on your bank's side or in the Al Tareq consent app. A legitimate Open Finance app never asks for your online banking credentials.
Are these apps allowed to sell my data?
No. The Open Finance Regulation explicitly prohibits providers and banks from selling, trading or monetising your customer data, and from re-sharing it with other parties. Data may only be used for the service you consented to.
Related reading:
Sources and References
-
Central Bank of the UAE, Open Finance Regulation (Circular No. 3 of 2025); consent requirements, data-sharing vs service initiation split, prohibition on selling or re-sharing customer data (rulebook.centralbank.ae, centralbank.ae)
-
Commercial Bank of Dubai, AlTareq Open Finance customer pages; standardised consent journey, bank-side authentication, 12-month maximum consent duration, revocation channels and data deletion (cbd.ae)
-
Pinsent Masons legal analysis of the UAE Open Finance framework; explicit informed consent, liability model and licensing of third party providers (pinsentmasons.com)
-
Nebras Open Finance ecosystem documentation; central hub role, consent metrics and live participant status including ADIB and Wio (nebras-open-finance.com)
-
Commercial Bank of Dubai press release, December 2025; first full Open Finance activation with licensed TPPs Pay10 and Lean Technologies (cbd.ae)
This article is for general information and does not constitute financial advice. Consent journeys, app capabilities and bank coverage under Open Finance are still evolving, so always verify a provider's licence and the current consent terms with the CBUAE and your bank before connecting your accounts.
Published on 9 September 2026.