Security and privacy at Penge
Your bank data is some of the most sensitive data you have, so we treat it that way. Penge connects to your bank through Open Banking, the connection is read-only, and you stay in control of your data the whole way. Here is exactly how it works.
How Penge connects to your bank
Penge fetches your balances and transactions through Open Banking, built on the EU directive PSD2, which also applies across the EEA. Banks are required to offer secure interfaces, and only licensed, supervised companies are allowed to connect. Penge fetches bank data through GoCardless, a licensed account information service provider. It is not a shortcut around the bank, but a solution the bank itself is part of.
You log in with your bank, not in the app
When you connect an account, you are sent to your bank's own login, for example with BankID in Norway and Sweden or MitID in Denmark. Penge never sees your password or BankID, and no bank credentials are ever entered into the app.
Read-only access, so no one can move your money
The connection can read your balances and transactions, and nothing more. It cannot move money, make payments or pay bills. Whatever happens, your money stays where it is.
Credentials are never stored, and your data is encrypted
Penge never stores your bank login. Your financial data is encrypted in transit and at rest, and it is used only to show you your own overview inside the app.
Where your data is stored
Your bank data is stored in data centres in London, encrypted in transit and at rest. The UK is covered by the EU adequacy decision, so the data has the same protection as inside the EEA. A few services we use for error tracking, app usage statistics and push notifications process data in the United States, but they never receive your transactions or balances. The two AI features in the app are the only places transaction data can leave Europe, and you control both: PDF statements are only sent when you upload a file yourself, and category suggestions are off by default. If you turn them on, every digit is stripped from the text first, so account numbers are never sent, and your balances are never sent at all. The full list of processors is in our Privacy Policy.
You decide, and you can revoke access anytime
Access is time-limited, usually 90 days, and has to be renewed. You can revoke it at any time, both in the app and directly with your bank, and you choose which accounts Penge can see in the first place.
Your data stays yours
You are in control of your own data. You can disconnect a bank whenever you want, and you can delete your data or your entire account directly in the app's settings.
Frequently asked questions
- Can Penge move my money?
- No. Open Banking only gives read access to balances and transactions. No app can move money or pay bills through this connection.
- Does Penge see my password?
- No. You log in with your bank yourself, for example with BankID, and the app never sees your password or BankID.
- How do I revoke access?
- You can disconnect an account in the app at any time, or revoke consent directly with your bank. Access also expires automatically after a period.