What is an Account Aggregator?

An Account Aggregator, or AA, is a type of company licensed by the Reserve Bank of India as a non-banking financial company for one specific job: carrying your financial information from one regulated institution to another, with your consent. It is not a bank, it does not lend, and it is not meant to analyse your data for its own use.

The framework exists because people kept sharing bank statements as PDFs and screenshots, which are easy to edit and easy to leak. With an AA, the data moves digitally, in a standard format, and each transfer is tied to a consent you gave.

Who are the three parties?

Party Plain meaning Example
Financial information provider (FIP) The institution that holds your data Your bank, insurer, mutual fund registrar
Account Aggregator The licensed carrier that passes the data on An RBI-licensed AA
Financial information user (FIU) The institution that asked for your data A lender, a wealth platform

You are the fourth party, and the only one who can say yes. The FIP releases data only against a valid consent, and the FIU receives only what the consent describes. According to Sahamati, the industry alliance for the AA ecosystem, the data moves in encrypted form and the aggregator is designed to carry it without reading it.

What does an AA consent actually say?

Every consent is a structured record, often called a consent artefact. The RBI's directions for NBFC-AAs require it to be standardised and to carry specific elements. In plain words, a consent screen should tell you:

Field What to look for
Who is asking The name of the lender or platform (the FIU)
Purpose Why they want it, for example loan underwriting or wealth management
Data types Deposits, mutual funds, insurance, GST data and so on
Date range The period of history requested
Fetch frequency One time, or repeated fetches
Consent validity The date the consent expires

If any of these is vague, that is a reason to stop and read, not to tap approve.

How does one consent look? A worked example

Say Aarav applies for a personal loan on 10 October 2026. The lender, as the FIU, sends a request through an AA.

  • Purpose: loan assessment
  • Data: savings account statements
  • Date range: 1 April 2026 to 30 September 2026
  • Frequency: one time
  • Consent validity: until 10 January 2027

Months of history requested: April, May, June, July, August and September, which is 6 months.

Consent window: 10 October 2026 to 10 January 2027 is 3 months.

Now suppose the same screen had asked for repeated fetches with validity until 10 October 2027. The consent window would be 12 months, four times longer, and the lender would be able to pull fresh data repeatedly. Neither version is right or wrong in itself. The point is that the numbers on the screen tell you how much, for how long and how often.

Aarav's check before approving: does a 6-month history and a 3-month window match what a loan assessment needs? If the lender wants more, he can ask why.

Is it safe?

Safety depends on which part of the chain you mean.

  • In transit. The framework specifies encrypted transfer between the data provider, the AA and the user of the data. Sahamati describes the AA as a conduit that is not meant to store or read your financial data.
  • At the institution that receives it. After the data reaches the FIU, it is covered by that institution's own privacy policy and by Indian data protection law. This is the part worth reading, because the AA no longer controls it.
  • Around the consent. The biggest practical risks are approving too much, approving in a rush, and phishing messages that imitate an AA or a lender. Only approve requests you started, inside the official app or website.

No system is risk free. The framework reduces the need to share screenshots and PDFs, and it puts consent and revocation in your hands. It does not remove the need to read what you are approving.

How do I see and revoke a consent?

Each AA has its own app or web portal, and you log in with your mobile number and a one-time password. In most of them you can:

  1. Open the list of consents, usually grouped as active, paused, expired and revoked.
  2. Open a consent to see the requester, purpose, data types, date range and expiry.
  3. Choose revoke, and confirm.

According to the framework, you can withdraw a consent at any time and the FIP will not release further data under it. Where the consent was for repeated fetches, revoking stops later fetches.

What revoking does not do is reach into the FIU's systems and delete what it has already received. If you want that data removed, ask the FIU directly under its privacy policy, and use its grievance contact if needed. The Digital Personal Data Protection Act, 2023 gives people rights over their personal data, and its rules are being brought into force in stages, so check the current position when you make the request.

What do people miss?

  • Consent for a long period. A one-year repeated consent keeps running after the loan decision.
  • Approving from a link in a message. Open the lender's own app instead.
  • Forgetting old consents. An expired or unused consent is harmless, but an active one for a service you no longer use should be revoked.
  • Confusing the AA with the lender. Revoking at the AA stops future fetches. The lender keeps its own copy under its policy.
  • Sharing more data types than needed. A purpose that needs savings statements may not need insurance or mutual fund data.

Where does Kubear stand?

Kubear does not use Account Aggregator. It does not log in to your bank and does not read SMS. That is a design choice, not a judgement on the AA framework. If you ever see an AA consent screen, it has nothing to do with Kubear.

What to check for your own situation

  • Who is the FIU, and did I start this request?
  • Is the purpose specific, and does the data requested match it?
  • What is the date range, the frequency and the expiry?
  • Where will I revoke it, and have I noted the date to review it?
  • What does the receiving institution's privacy policy say about retention and deletion?

How this looks in Kubear

Kubear is a web app where chat is the home. It does not connect to banks or read SMS. You type a record or upload a statement, a CAS, a policy or a receipt, review the draft, and confirm. The upload is discarded after it is read, and your reviewed records stay yours, with the working one tap away. The privacy policy explains each point.

This is general education, not personal financial, tax or insurance advice.