FinanceGadget
Methodology

How an app gets tested

This page exists so you can judge whether a review is worth anything. If a process is not written down, it is not a process.

The rules

  1. No review without installation. Every app in a review has been installed on a real device, signed into with a real account, and used. No review is written from marketing pages alone.
  2. Screenshots are original. Images come from the tested device, with the app version visible where possible. No press kits, no stock photography standing in for a real screen.
  3. "Unknown" gets published. If a permission scope, data residency or incident history cannot be established, the record says unknown. An honest gap is worth more than a confident guess.
  4. Numbers are dated. Fees, spreads and rates carry the date they were checked. Anything undated is a bug, so report it.
  5. Payment buys nothing. No provider can influence a verdict, a ranking, or inclusion. Commercial relationships are disclosed on the page where they exist.

What gets checked

Access and permissions

Which permissions the app requests at install and at runtime, and which of those it genuinely needs for the feature set it advertises. Requested-versus- necessary is usually the most revealing line in the whole record.

Authentication and credential handling

How the app connects to a bank: a proper redirect-based consent flow where the bank collects the password, or screen-scraping that requires handing over credentials directly. Whether multi-factor authentication is supported, which second factors, and whether it can be enforced. Where refresh tokens live and what revoking access actually does.

Data flow and third parties

Which analytics and advertising SDKs are present, what the privacy policy permits the provider to share, and whether transaction-level data is used for anything beyond delivering the service.

Provider and accountability

The legal entity behind the app, its regulator and licence reference where one exists, the governing jurisdiction, and where data is stored. An app operated by an unregulated entity is not automatically bad — but you should know.

Real cost

Subscription price, and for anything involving currency conversion, the spread against the mid-market rate at the time of testing. "Zero fee" transfers are frequently not free; the margin has simply moved into the exchange rate.

What gets checked: AI tools

AI developer tools and chatbots get a different set of questions, because the risk is different. You are not connecting a bank account — you are sending source code, documents or client data to a third party under whatever terms you clicked through.

Retention and training

How long inputs are kept, whether they are used to train models by default, whether an opt-out exists, and what that opt-out actually covers. The answer frequently differs between the consumer tier and the business tier, and the difference is the part worth publishing.

Sub-processors and residency

Whether the provider names its sub-processors, whether a data processing agreement is available, and whether EU data residency is offered — and if it is, whether it covers inference or only storage.

Reading the terms, not the marketing

Every claim in an AI tool record cites the clause it came from and the date the terms were read. Providers revise these quietly. A dated citation is what makes the record worth anything a year later.

What these are not: benchmark rankings. This site does not score models on reasoning, coding or knowledge, and does not publish "best model for medicine" or "best model for law" comparisons. Those require eval infrastructure this site does not have, and in the case of medical and legal advice, expertise the author does not claim.

Verdicts

Each record ends with one of four verdicts. They describe security and privacy posture only. None of them is a recommendation to use or avoid a financial product.

VerdictMeaning
No material concerns Nothing found that a reasonable person would want flagged.
Proceed with caution Specific issues worth understanding before connecting an account.
Material concern A finding serious enough to name in the summary.
Insufficient information Key facts could not be established. Stated plainly, not glossed.

What this testing is not

This is a review process, not a penetration test or a security audit in the formal sense. No app is attacked, no account other than the author's own is accessed, and no attempt is made to breach any system. Findings are based on observable behaviour, published documentation and public records.

Assessments describe software, not financial merit. Nothing here is financial advice.

Review cadence

Apps change. Each record shows the version tested and the date. Records are revisited when a provider ships a significant change to authentication, pricing or data handling — not on a fixed marketing schedule.