← Back to list

Financial Exposure: What Your Neobank Really Knows About You

Introduction: The Clean UI Has a Dirty Secret

Ojilere kingsley · 2026-05-01 00:52 · 0 claps · 7.7 min read
#neobanks #revolut #arcium #stealf
Open on Medium ↗
Wiki topics: FIN · Fintech & Banking ECO · Economy · General

Financial Exposure: What Your Neobank Really Knows About You

Introduction: The Clean UI Has a Dirty Secret

There is a version of modern banking that feels almost too good to be true. No hidden fees, instant transfers, beautiful design, spending analytics right in your pocket. Revolut built an empire on this promise and now counts over 50 million users globally.

But while you are splitting dinner bills and tracking your subscriptions, something else is happening on the other side of that clean interface. Revolut is building a detailed, continuously updated portrait of your financial life. Not just your balance. Your habits, your schedule, your relationships, your vulnerabilities. And they are not keeping it to themselves.

This article digs into what Revolut actually collects, who they share it with, what their privacy policy says in plain language, and why the answer to all of this is not just a better privacy policy but a fundamentally different architecture for money.

Section 1: What Revolut Actually Collects

1.1 The Obvious Layer

Most users accept that a financial app needs basic information. Name, address, date of birth, government ID for KYC. That part surprises nobody.

But Revolut’s data collection does not stop at identity verification.

Their privacy policy documents collection across several categories that most users scroll past without reading:

Transaction data including merchant names, amounts, timestamps, categories, frequencies, and locations

Device data including your IP address, device identifiers, operating system, browser type, and mobile network information

Behavioural data tracking how you navigate the app, which features you use, how long you spend on certain screens, and what you tap

Location data when location permissions are granted, and inferred location even when they are not, through IP and merchant data

Communication data from any in-app support chats, feedback submissions, or interactions with Revolut’s customer service

Biometric data including facial recognition scans submitted during identity verification

Third-party data pulled from credit bureaus, fraud prevention agencies, and external data brokers to fill in gaps about who you are

1.2 The Less Obvious Layer

Here is where it gets more interesting and more unsettling.

Revolut uses transaction data to build what they internally categorise as spending profiles. Every merchant you pay tells them something. A pharmacy purchase reveals potential health concerns. Recurring transfers to the same individual reveal relationships. Late-night food delivery orders paint a lifestyle picture. Paycheck timing reveals your employer and employment status. Subscription patterns reveal your income bracket.

None of this is explicitly stated as a risk in their marketing. All of it is buried in their data processing documentation.

They also collect what they call “inferred data,” meaning conclusions drawn from your raw data rather than data you directly provided. You never told Revolut you were going through a difficult financial period. But if your spending patterns shift, your savings drop, and you start using their credit features, their systems can infer it anyway.

Section 2: Who Gets This Data

2.1 Inside the Revolut Group

Revolut operates as a group of companies across different jurisdictions. Your data is shared internally across Revolut entities for purposes including fraud detection, product development, and regulatory compliance. This means data collected under one entity’s licence can flow to another with fewer questions asked.

2.2 Third-Party Sharing: The Full Picture

Revolut’s privacy policy lists the following categories of third parties who may receive your data:

Payment processors and card networks like Visa and Mastercard, who have their own extensive data collection and sharing practices layered on top of Revolut’s

Credit reference agencies including Experian, Equifax, and TransUnion, who receive data about your creditworthiness and repayment behaviour

Fraud prevention agencies operating shared databases that flag accounts across multiple institutions

Marketing and analytics partners who receive behavioural and demographic data for advertising purposes

Identity verification providers who handle your biometric data and government documents

Cloud infrastructure providers including AWS and Google Cloud, meaning your financial data sits on servers owned by companies with their own data use terms

Regulators and law enforcement in any jurisdiction Revolut operates in, upon request and sometimes without your notification

2.3 The Advertising Connection

This is the part that most users genuinely do not expect from a bank.

Revolut’s privacy policy includes provisions for sharing data with advertising partners for targeted marketing. Your transaction data can feed into advertising profiles. If you purchase gym memberships, health supplements, and fitness equipment, that behavioural cluster becomes an advertising segment. Brands pay to reach people in that segment. Your financial behaviour becomes inventory.

Traditional banks are constrained by decades of regulation and cultural expectations around financial data. Neobanks, operating under fintech licences and with looser cultural norms around data, have moved faster and further into this territory.

Section 3: What the Privacy Policy Actually Says

3.1 The Legal Basis for Processing

Revolut processes your data under several legal bases under GDPR and equivalent frameworks:

Contractual necessity for data needed to provide the service

Legal obligation for regulatory and compliance data

Legitimate interests for fraud prevention, product improvement, and marketing analytics

The “legitimate interests” category is the widest and most contested. It allows Revolut to process your data for purposes that benefit them, as long as those interests are not overridden by your rights. In practice, this is the legal vehicle that enables most of the data use that users would find surprising.

3.2 Your Rights on Paper vs. Reality

The policy grants users rights to access, correct, delete, and restrict processing of their data. In practice, exercising these rights is friction-heavy. Data deletion requests often cannot be fully honoured due to regulatory retention requirements. Opting out of marketing data sharing does not opt you out of fraud data sharing, credit bureau reporting, or regulatory disclosures.

The rights exist. But they exist inside a framework designed to minimise their practical impact.

3.3 Data Retention: Longer Than You Think

Revolut retains transaction data for a minimum of five years after account closure in most jurisdictions, driven by anti-money laundering regulations. Biometric data has its own retention schedule. Marketing data may be retained independently.

Closing your Revolut account does not make your data disappear. It enters a retention holding pattern that you have no visibility into.

Section 4: What This Data Can Reveal and Who Benefits From Knowing

4.1 The Insurance Industry

Insurance underwriters are increasingly interested in behavioural financial data. Your spending patterns can signal health risks, lifestyle risks, and financial stability, all of which influence insurance pricing. While Revolut does not directly sell to insurers, the data broker ecosystem they participate in creates pathways for this information to travel.

4.2 Lenders and Credit Scoring

Open banking frameworks in the UK and EU, which Revolut participates in, allow third-party lenders to access your transaction history with your consent, and sometimes with consent buried in terms you accepted at sign-up. A lender reviewing your Revolut data does not just see your balance. They see your behaviour under financial pressure, your spending discipline, and your income reliability.

4.3 Employers

Background screening companies in certain sectors now offer financial behaviour assessments. While this is more common in finance and security roles, the use of financial data in hiring decisions is expanding. Data that flows through brokers can eventually surface in places you never anticipated.

4.4 The Data Broker Ecosystem

Once data enters the broker ecosystem, its final destination is practically untraceable. Revolut’s privacy policy acknowledges data sharing with third-party partners but cannot meaningfully control what those partners do downstream. A data point about your financial behaviour can be re-sold, re-packaged, and re-purposed across dozens of entities before it influences any decision about you.

Section 5: Why Encrypted, Self-Custodial Finance Changes Everything

5.1 The Structural Problem Is Not Policy, It Is Architecture

Reading Revolut’s privacy policy more carefully does not solve the problem. Revolut could publish the most transparent privacy policy ever written and the fundamental issue would remain. Their business model requires centralised custody of your funds and centralised visibility into your behaviour. The data collection is not an abuse of the system. It is the system.

Self-custodial finance built on encrypted infrastructure addresses this at the architectural level.

5.2 What Encrypted Execution Actually Means

Projects like @Stealf_finance, built on @Arcium encrypted execution environment, do not just add privacy as a feature on top of existing infrastructure. They change the underlying computation model.

In Arcium’s Multiparty Computation architecture, financial operations are computed across distributed nodes in encrypted form. No single node, and no outside party, ever sees the raw inputs. The computation happens. The result is produced. But the data that produced it remains shielded throughout the process.

This is not anonymisation. Anonymisation strips identifiers but leaves patterns intact. This is genuine encrypted execution where the financial activity of transferring, swapping, or earning yields is processed without exposure.

5.3 The Self-Custody Dimension

The second half of the equation is custody. Revolut holds your funds. You access them through their interface, under their terms, subject to their decisions. Accounts can be frozen, access can be restricted, and your funds can become inaccessible during disputes or regulatory investigations.

Self-custodial finance means your private key is yours. No platform can freeze it. No company can decide your access is suspended pending review. The financial relationship exists between you and the protocol, not between you and a corporation that answers to its own incentives.

5.4 The Compliance Question

A common objection is that privacy makes compliance impossible. This is a false binary. Cryptographic tools including zero-knowledge proofs and selective disclosure allow users to prove compliance with specific requirements, such as confirming that a transaction is not linked to a sanctioned entity, without revealing the full content of their financial history to every party in the chain.

Stealf and the broader encrypted finance ecosystem are building toward this model. Compliance that is precise, auditable, and limited in scope, rather than the current model where you surrender your entire financial picture to prove you are not doing something wrong.

Conclusion: Reconsider What’s Sitting on Your Phone

Revolut is not uniquely predatory. Cash App, Venmo, Chime, and N26 operate with similar data architectures and similar incentive structures. The neobank model is built on the premise that your financial data is a product, and that you will trade it for convenience without noticing or caring.

Most people do not notice. This article is an argument for caring.

The question is not whether you trust Revolut’s intentions today. The question is whether you are comfortable with a system where your financial life is an open dataset, shared across a network of parties you will never fully know, persisted for years after you close the app, and capable of influencing decisions about your insurance, your credit, your employment, and what you see on the internet.

Encrypted, self-custodial finance is not a fringe experiment anymore. It is a working alternative built on infrastructure that treats privacy as a structural property rather than a policy promise.

@Stealf_finance and @Arcium are building toward the version of finance where the transaction happens, the outcome is recorded, and nothing else leaks. Not your identity. Not your habits. Not your relationships. Not your vulnerabilities.

That is what financial privacy actually looks like. And it is worth understanding what you are giving up before deciding it does not matter.

SOURCE: Research from Revolut’s published Privacy Policy, Terms of Service, and Open Banking documentation. Third-party data practices referenced from publicly available regulatory filings and fintech industry analyses.


메타데이터
post_id
0c59e6ff9b2f
slug
financial-exposure-what-your-neobank-really-knows-about-you-0c59e6ff9b2f
url
https://medium.com/@ojilerekingsley/financial-exposure-what-your-neobank-really-knows-about-you-0c59e6ff9b2f
canonical_url
https://medium.com/@ojilerekingsley/financial-exposure-what-your-neobank-really-knows-about-you-0c59e6ff9b2f
author_url
https://medium.com/@ojilerekingsley
status
ok
fetched_at
2026-06-24 23:31:39