Bank connections · 6 min read
How to Revoke an App’s Access to Your Bank Account

To revoke an app’s access to your bank account, you usually need to cut the connection in up to three places: inside the app itself (delete the linked account or your whole account), inside your bank’s online security settings (look for “linked apps,” “connected apps,” or “security and access”), and — if the app connects through Plaid — at my.plaid.com, Plaid’s consumer portal, where you can see and disconnect every app using your credentials. Deleting the app from your phone does none of this; the data connection lives on servers, not on your home screen.
Why doesn’t deleting the app revoke access?
The app on your phone is just a window. The actual connection — the token that lets a service pull your balances and transactions — lives between the app’s servers and your bank (often with an aggregator like Plaid in the middle). Uninstalling the app removes the window but leaves the plumbing intact. The company can keep syncing your data on a schedule, and many do, because that’s how they keep your dashboard current for when you come back. If you want the syncing to stop, you have to tell one of the parties holding the token to destroy it.
That’s also why revoking access is worth doing deliberately when you stop using a finance app. There’s no harm in a dormant read-only connection in most cases — as Can Plaid Move My Money? explains, these connections generally can’t initiate transfers — but there’s also no reason to leave a company you’ve abandoned with a live feed of your spending.
Step 1: Revoke access inside the app
Start with the app itself, because this is the only place you can also request deletion of the data it has already collected. The pattern is nearly universal:
- Open the app’s settings and find the linked-accounts or connections screen.
- Remove or unlink each bank connection. This typically tells the app’s servers to invalidate the access token.
- Look for a “delete my account” or “delete my data” option. Under state privacy laws like California’s, many companies must honor deletion requests; good apps make it a button rather than an email.
- If there’s no in-app deletion, email support and explicitly request account closure and data deletion, and keep the reply.
Be precise about the difference between unlinking a bank and deleting your account. Unlinking stops future syncing; the app may still retain the history it already pulled. If you want that gone too, you need the deletion step.
Step 2: Check your bank’s connected-apps settings
Many banks — especially larger ones like Chase, Bank of America, Wells Fargo, and Capital One — now offer a security dashboard where you can see which third-party services have access to your accounts and shut them off from the bank’s side. This exists because these banks have moved to OAuth-style connections, where you log in on the bank’s own page and the bank issues a token it can later revoke. Plaid vs. Screen Scraping covers why this design is safer, but the practical upside is exactly this switch.
Log in to your bank’s website (these settings are often easier to find on the web than in the mobile app) and look under Security, Privacy, or Profile for language like “Linked apps and websites,” “Account access,” or “Manage connected apps.” Toggle off anything you don’t recognize or no longer use. Revoking from the bank’s side is the most decisive cut: the app’s token simply stops working, no matter what the app does.
One caveat: smaller banks and credit unions may not have this dashboard yet. If yours doesn’t, the app-side and Plaid-side steps carry more weight — and in the worst case, changing your online banking password will break credential-based connections, though it will also break connections you wanted to keep.
Step 3: Use the Plaid portal if the app connects through Plaid
A large share of US finance apps link banks through Plaid — Which Apps Use Plaid? explains how to tell. Plaid runs a consumer portal at my.plaid.com where you can verify your identity, see a list of the apps you’ve connected through Plaid, and disconnect them. You can also ask Plaid to delete the data it holds from those connections.
This is the step most people don’t know exists, and it’s useful precisely because it doesn’t depend on the app cooperating. If a company has gone quiet, shut down, or buried its unlink button, the portal lets you sever the connection at the aggregator level. It only covers Plaid-based connections, though — apps using other aggregators (MX, Finicity, Yodlee) or direct bank integrations won’t appear there.
A worked example: unwinding three old apps
Say you audit your accounts and find three stale connections: a budgeting app you tried for a month in 2023, a rent-reporting service from an old apartment, and a crypto app you abandoned. Here’s how the cleanup might actually go:
- The budgeting app still has a working login. You unlink your two banks in its settings, then use its delete-account flow. Five minutes, fully clean.
- The rent-reporting service has no delete button. You email support requesting deletion, then log in to your bank’s connected-apps page and revoke its access there so it stops syncing while the request is processed.
- The crypto app’s company shut down last year. You can’t log in at all. You check my.plaid.com, find the connection listed, and disconnect it there — then confirm at your bank that no active token remains.
Total time: maybe twenty minutes, and the result is that only apps you actively use can see your transactions. That’s the state you want to maintain going forward.
How do you know it actually worked?
Revocation is quiet — there’s rarely a confirmation email from your bank. Three checks give you confidence. First, if you revoked from the bank side, the app’s dashboard should show a broken or disconnected state the next time it tries to sync (the same state described in What to Do When Your Bank Connection Breaks, just intentional this time). Second, your bank’s connected-apps list should no longer show the service. Third, in the Plaid portal, the app should be gone from your connections list.
One thing revocation does not do: claw back data the app already stored. That’s why the deletion request in step one matters, and why it’s worth vetting an app’s deletion policy before you link anything — Is It Safe to Link Your Bank Account to an App? walks through what to look for. An app that offers instant in-app data deletion is telling you something about how it thinks about your data. Seven Financial, for what it’s worth, is built that way: read-only access, and a delete that takes effect immediately rather than after a support ticket.
Make this a yearly habit, not a crisis response
Most people only think about revoking access after something spooks them — a breach headline, a weird charge, an app acquired by a company they don’t trust. A better pattern is a short annual audit: open your bank’s connected-apps page and the Plaid portal, and prune anything you haven’t used in six months. Connections you keep should earn their place. A read-only aggregator you check weekly is doing real work for you; a free trial from two years ago is pure downside surface with zero benefit.
And if you’re deciding which connections deserve to survive the audit, the security review in Is Plaid Safe? is a reasonable baseline for what a trustworthy connection looks like: tokenized access, no stored passwords at the app level, and a clear way out — which is exactly what you just exercised.
Frequently asked questions
Does changing my bank password revoke app access?
For older, credential-based connections, yes — the app's stored login stops working and syncing breaks. But OAuth-based connections use tokens that survive a password change, so you still need to revoke those through the bank's connected-apps page or the app itself.
Can an app still see my old transactions after I disconnect?
It can keep whatever data it downloaded while connected, unless you separately request deletion. Disconnecting stops future access; a deletion request (in-app or via support) addresses the history it already holds.
What if the app's company has shut down entirely?
Go around it. Revoke access from your bank's linked-apps settings if available, and check my.plaid.com to disconnect any Plaid-based link. A defunct company's servers may stop syncing anyway, but it costs nothing to cut the token formally.
Will revoking an app's access affect my credit score?
No. Read-only data connections are not credit accounts and aren't reported to credit bureaus. The exception is a service you signed up for specifically to report data to bureaus, like rent reporting — canceling that stops the reporting, but the revocation itself isn't a negative mark.