Two separate questions
“Is it safe?” mixes two questions with different answers:
- Can the assistant do anything to my money? This depends on what the connection allows: read, write, or both.
- Who ends up with my financial data? This depends on the connector, the bank-connection provider behind it, and the AI company running the chat.
A connection can score well on the first and poorly on the second. Look at both.
Read-only versus write access
In ChatGPT and Claude, a bank connector is an MCP server: a list of tools the assistant can call. Each tool either reads something or does something.
Read access
Read tools return information: balances, transactions, holdings. The worst a read tool can do is show the assistant data you did not need it to see.
Write access
Write tools change something: send a payment, move funds between accounts, place a trade. These carry a different kind of risk, because an assistant can misread your request, act on a stale number, or be steered by injected text. ChatGPT and Claude both ask for confirmation on actions in some cases, but a confirmation dialog is a safeguard, not a boundary.
How to tell which you have
Both apps show the tools a connector exposes when you add it. Read the list. BankBridge exposes 11 read tools (list_accounts, list_transactions, get_recurring_charges, and so on) plus connect_bank, which returns a link you open yourself. The bank connection itself is provisioned without payment or transfer permissions, so the limit is enforced below the AI layer. More detail in read-only, forever.
Where your data goes
When you ask “what did I spend on groceries last month?” with BankBridge connected, this happens:
- The assistant calls a tool. ChatGPT or Claude sends a request like
get_spending_summarywith a date range to BankBridge. - BankBridge fetches live. BankBridge uses your encrypted access token to request the transactions from your bank through its bank-connection provider, totals them, and returns the result. Nothing is written to a database on our side; see why we don't cache your data.
- The result enters your chat. The totals (or transaction list) become part of the conversation. From here, OpenAI or Anthropic handle it under their policies and your account settings: how long chats are kept, whether they can be used for training, and who in your workspace can see them.
The last step is the one people miss. A careful connector cannot control what the AI company does with a conversation. Check your data controls in ChatGPT or Claude, and use a business or enterprise workspace if your employer requires it for financial data.
The risks that remain
- Over-sharing.“Show me all my transactions” pulls far more into the chat than “total my restaurant spending in May.” Ask narrow questions when you can.
- Mixed toolsets. If the same chat has a bank connector and a tool that can send email or post messages, injected text could try to get the assistant to send your data somewhere. Keep finance chats separate from send-capable tools, or review every outgoing action.
- Wrong answers. An assistant can double-count card payments or misread a transfer. Read-only does not mean error-free. See stop double-counting credit card payments.
- Shared devices and accounts. Anyone signed in to your ChatGPT or Claude account can ask the same questions. Use two-factor authentication on the AI account as well as the bank.
Checklist before you connect
- Does the connector list only read tools?
- Is read-only enforced at the bank connection, or only in the prompt?
- Does the connector store your transactions, and for how long?
- Does your bank password go to the connector, or to a bank-run sign-in?
- What are your AI account's retention and training settings?
- Can you revoke access from one place?
For BankBridge: yes; at the connection; no storage; bank-run sign-in; check your settings; yes. For a comparison across connectors, see bank account MCP servers compared.
How to undo it
Remove the connector in ChatGPT (Settings, Connectors) or Claude (Settings, Connectors). In the BankBridge dashboard, disconnect the bank, and rotate your API key if you set one up in a config file (see rotating your API key). Old keys stop working immediately.
If the read-only, no-storage model fits what you want, connect your bank ($5 per month per bank) and follow the setup for ChatGPT or Claude.