Skip to content

A bank statement is a diary

The question to ask LIBRA is not whether it can take your money: it never touches it, and no aggregator does. The question is what twelve months of your transactions say about you, and who else gets to read them.

What four lines give away

Four transactions taken from this site's demonstration dashboard. They are invented. If they were yours, this is what they would say.

The transactionWhat it says about you
Farmacia Centrale− €19.50That you went to the pharmacy, when, and how often you go back. How regularly you spend on health is health data.
Bonifico da Studio Ferri+ €1,450.00Who pays you, how much and how often. A recurring transfer gives up your employer and your salary.
Trenord− €13.40Which line you travel on and at what time. Repeated over a month, it gives up where you live and where you work.
Osteria del Binario− €62.00Where you go in the evening and how often. A repeated bill for two is a relationship.

None of these lines is sensitive on its own. Twelve months of them together are the most intimate document you own, and that is what an aggregator asks to read.

You give the permission to the bank, not to the app

This is the part almost no site explains, and it changes who holds the handle. These four things are true of any service that connects over the European PSD2 link, not only of the product described here.

  1. You enter your credentials on the bank's own site

    Not in the app doing the connecting. Anyone asking for your bank username and password inside their own form is going around the rules, and should be abandoned on the spot.

  2. The permission is read-only

    The rules separate access to transactions from authorisation to make payments. They are two different consents: an aggregator only ever gets the first.

  3. It expires by itself

    The consent has a lifetime and has to be renewed. If you stop using the service and do nothing at all, the access closes on its own.

  4. You revoke it at the bank

    You do not need the app's permission to take its access away: you revoke it from your bank's own customer area, even if the app is uncooperative or no longer exists.

Three questions for anyone who reads your accounts

LIBRA included. Below is the answer this product would give — but on a real service an answer is not enough: beside it is the evidence you should demand.

  1. Does anyone else see my transactions?

    LIBRA's answer

    No. They are not passed on, pooled or resold to third parties in any form, anonymised or otherwise. The subscription is the only revenue.

    The evidence to demand

    The privacy notice with data processors listed by name. If there is no list, or the list is generic, the answer is worthless.

  2. What is left if I stop?

    LIBRA's answer

    Nothing. Profile closed, data deleted within thirty days, history exported if you ask beforehand.

    The evidence to demand

    A deletion you can start from the app without writing to anyone, and written confirmation once it is done.

  3. Who has looked at my data, and when?

    LIBRA's answer

    An access log you can read: which devices, from where, on what date.

    The evidence to demand

    The log visible to you, not on request. Access that leaves no readable trace cannot be checked.

None of this exists on this site

LIBRA is a demonstration. There is no sign-up, no login, no form that submits anything, no trackers and no bank connected: the pages are generated in advance and served as files, with no database behind them. You can check that right now with your browser's network panel. The answers above describe how the product being described would behave, and nobody has verified them.