A source-checked field guide. The linked primary sources were reviewed for the explanations in this note. Provider examples are not universal terms. This is a local editorial preview, not individualized advice; publication review remains pending.

Deleting a budgeting or payment app does not prove that its data connection has ended. A practical revocation workflow checks both ends of the connection, saves the authorization record, and distinguishes stopping future collection from deleting data already held.

The legal backdrop is unsettled. The CFPB says the compliance dates for its 2024 Personal Financial Data Rights Rule were stayed by a federal court on October 29, 2025, while the agency was reconsidering parts of the rule (CFPB). The steps below are operational checks, not a claim that Section 1033’s detailed requirements are currently enforceable against every company.

Inventory the connection

Write down the app, financial institution, data aggregator if named, accounts selected, data categories, authorization date, and purpose. Search email for “connected,” “linked account,” “authorization,” or the aggregator’s name. A bank connection that redirects you to the bank’s own domain usually uses a token; an app that asks you to type bank credentials into its own screen may be using a different method.

Before revoking, export any records you are entitled to keep. If the app is still providing bill payment, underwriting, tax preparation, or bookkeeping, understand what will stop working.

Revoke from the app

Use the app’s connected-account or privacy settings to disconnect the specific bank. Capture the confirmation. Then ask separately for deletion of data the app no longer needs, if that is your intent. “Stop collecting,” “disconnect,” “close account,” and “delete my data” may be four different controls.

The 2024 rule text describes a model in which third parties provide a revocation method and stop future collection after revocation, while allowing some continued use or retention when reasonably necessary for the requested service (CFPB §1033.421). Because compliance dates are stayed, treat this as a useful framework to ask about—not a guarantee of current coverage.

Revoke from the bank too

Sign in through the bank’s official app or a URL you typed yourself. Look for “connected apps,” “linked services,” “data sharing,” or “third-party access.” Remove the app and save the bank’s confirmation. CFPB’s rule text separately describes a data-provider revocation method, but current availability is provider-specific (CFPB §1033.331).

Changing the bank password may terminate some credential-based connections, but it is not a clean substitute for revoking a token and may disrupt unrelated services. Do it immediately if credentials were exposed or entered on a suspicious page; otherwise use the documented controls first.

Never approve a fresh connection merely to reach the disconnection screen.

Verify the result

After a reasonable interval, check three things:

  1. the bank no longer lists the app;
  2. the app no longer refreshes balances or transactions;
  3. the aggregator, if it has a consumer portal, no longer shows an active connection.

Keep timestamps and case numbers if one side says access is closed while the other still shows activity. Review the app’s privacy notice for retention needed for fraud, disputes, or legal obligations; revocation may not erase historical transaction copies instantly.

Also check whether the app created a payment authorization in addition to a data connection. Revoking read access does not necessarily cancel an ACH debit, recurring card payment, or bill-pay instruction. Handle that separately through the contract and payment channel; cancel recurring payments explains the distinction.

A hypothetical user disconnecting “Budget Oak” could save the app confirmation at 10:02 a.m., remove it from the bank’s connected-app page at 10:06, then verify the next day that no new transactions appeared. That demonstrates a workflow, not a test of any real provider.

Reduce the next connection’s scope

Link only the accounts needed, prefer bank-hosted authorization, read the requested data categories, and calendar a quarterly review. For a broader provider check, use questions before trusting a fintech app and the lost-phone response plan if the device holding the tokens disappears.

Sources

Evidence & dates

Prepared 19 Sept 2026 · source checks 19 Sept 2026 · website publication pending. Undated means no publication date was established on the reviewed page.

  • 2025-10-29 — Court stayed Personal Financial Data Rights Rule compliance dates
Consumer Financial Protection Bureau · Personal financial data rights

Official notice that compliance dates were stayed and rule reconsideration was announced.

Source publication date: undated; last modified 2026-01-06 · checked 2026-09-19 · full page reviewed · evidence: verified · recheck by 2026-12-19

Read the primary source ↗
Consumer Financial Protection Bureau · 12 CFR § 1033.421 Third party obligations

Rule-text framework for authorization scope, revocation method, notice, and post-revocation collection and retention.

Source publication date: undated · checked 2026-09-19 · full page reviewed · evidence: verified · recheck by 2026-12-19

Read the primary source ↗
Consumer Financial Protection Bureau · 12 CFR § 1033.331 Responding to requests for information

Rule-text framework for data-provider revocation methods and access termination.

Source publication date: undated · checked 2026-09-19 · full page reviewed · evidence: verified · recheck by 2026-12-19

Read the primary source ↗
KEEP THE THREAD GOING12 Questions to Ask Before Trusting a Fintech App With Your Money → (original research draft)Respond to a lost phone that holds payment accounts →Passkeys resist phishing only if recovery does too →Reading path: Before you trust an app with money ↗Return to the library →