Specter SpecterFreedom, Privacy, Monetary Independence PRESALE LIVE
← Specter
Your Bank & You

What Does Your Bank Know About You?

Try Specter in your browser, or install it as a web app. Money and speech, free from surveillance. Pseudonymous by design: no KYC, self-custodied, can't read your messages. No app store, no gatekeeper. Open specterapp.io

Your bank holds a timestamped, categorised record of nearly everything you buy. Read one line at a time it is accounting. Read twelve months at once and it describes your life in more detail than you could reconstruct from memory.

What is in a single transaction record

Card payments run on messaging standards that carry consistent fields, and the fields are more descriptive than most people expect. A typical authorisation record includes the amount and currency, the exact timestamp, the merchant name and their identifier, the merchant's location, the terminal or channel used, and a merchant category code.

The merchant category code is the field that does the heavy lifting. It is a standardised four digit number classifying the type of business, assigned so networks and issuers can apply rules and reporting by category. It is why your statement can be grouped into travel, groceries, and medical without anyone reading the itemised receipt, and it is why category level inference works without anyone knowing what you actually bought.

What can be inferred, and how reliably

  • Where you live and work. Merchant locations plus timestamps produce a movement pattern. The place you buy coffee at eight on weekday mornings is near where you live or work, and the pattern holds even if you never share an address.
  • Health conditions. Pharmacy visit frequency, specialist clinic co-payments, medical device suppliers, and fertility or mental health services all appear as identifiable merchants. The diagnosis is not in the record. The pattern of spending around it usually is.
  • Politics and religion. Party donations, campaign contributions, place of worship payments, and membership subscriptions are all ordinary transactions.
  • Relationships and dependents. Recurring transfers to the same individuals, joint payments, childcare and school fees, and care home costs map a household without anyone declaring one.
  • Financial distress. Overdraft frequency, payday lender activity, gambling merchants, timing of spending relative to payday, and the ratio of essential to discretionary spend. This category is the most commercially valuable and the most heavily modelled.
  • Life events. A move, a separation, a new baby, a job loss, and a bereavement all produce recognisable signatures in spending, and marketing systems are specifically tuned to detect them because behaviour is most changeable at those moments.

Who else receives it

The record does not stay in one place. Understanding the layers is what makes the practical steps below make sense.

  • Card networks and processors. Every transaction passes through the network and its processors, which see the flow across all of your cards at that network rather than only one bank's view.
  • Affiliates. In the United States, the Gramm-Leach-Bliley Act permits a financial institution to share customer information with companies under the same corporate umbrella. For large banking groups this covers a substantial family of businesses, and the consumer control over it is limited.
  • Data aggregators. Companies such as Plaid, Yodlee, MX, and Finicity connect your bank account to third party apps. Yodlee in particular has faced repeated scrutiny from United States legislators over the resale of transaction data.
  • Credit bureaus. Account level data feeds the bureaus, which are themselves data brokers with their own customers and their own breach history.
  • Government requests. Lawful requests are routine and generally arrive without notice to the customer. Reporting obligations such as currency transaction reports for large cash movements happen automatically, with no request required at all.

Open banking made this easier, in both directions

Regulation now requires banks to share your data with third parties you authorise. PSD2 in the EU, Open Banking in the UK, and the Consumer Financial Protection Bureau's personal financial data rights rule in the US all point the same way.

This is genuinely good for competition and portability. It also means the number of companies holding a complete copy of your transaction history is now a function of how many apps you have ever connected, and most people have never revoked a connection they no longer use. Older screen scraping integrations were worse still, since they required handing over your actual banking credentials.

What you can actually do

  • Audit your connections. Check which third party apps have access to your accounts and revoke the ones you no longer use. Your bank's online settings list them, and Plaid maintains a portal at my.plaid.com showing connections made through it.
  • Read the privacy notice you were mailed and ignored. In the US it contains the specific opt outs available, and some of them only take effect if you actively exercise them.
  • Exercise the opt outs that exist. Sharing with non-affiliated third parties for marketing generally carries an opt out. Sharing within the corporate family is more limited, and knowing which is which prevents wasted effort.
  • Use cash for the categories you consider nobody's business. Medical, political, and religious spending are the three that produce the most sensitive inferences from the smallest number of transactions.
  • Request your data. In the EU and UK, a subject access request compels disclosure of what is held, including inferences and risk scores in many cases.
  • Delete the fintech apps you tried once. Each retains a copy of what it pulled, with its own security posture and its own future owners.

These reduce the number of copies. They do not remove the original, because the file is generated by the act of using an identity linked account.

The structural version

Every step above manages a file that already exists. The alternative is a system where the file is never opened, which requires that no identity is collected at the point of entry.

Specter requires no bank account and no KYC. Transactions settle on a public chain that is auditable by anyone and tied to no name, and Specter Comms is end-to-end encrypted so the platform cannot read message contents. Related reading: pseudonymity and data minimisation.