How open banking will work in Vault, and what it does not do today.
Version 1.0 · Effective 8 September 2026 · Last updated 8 September 2026
Read this first. Bank feeds through the Consumer Data Right are built into Vault but are not switched on. The arrangement with an accredited data recipient is not in place, so:
no Consumer Data Right data is being collected, held or used by Vault today. If you try to connect a bank feed in the app, it will tell you the same thing. This page describes how it will work when it is available, so you can decide in advance whether you want it.
The Consumer Data Right (CDR) is Australian law that lets you direct your bank to share your own banking data with a business you choose. It is the framework behind “open banking” in Australia. It is regulated by the Australian Competition and Consumer Commission and the Office of the Australian Information Commissioner, and it is built around consent: your bank shares nothing unless you tell it to, and you can tell it to stop at any time.
Its practical benefit for you is that a bank feed does not need your banking password. You authorise the share on your bank’s own website, and Vault never sees your login.
Vault is not accredited under the Consumer Data Right, and we do not claim to be. If you see us described anywhere as holding accreditation, that description is wrong and we would like to know where you saw it.
Accreditation is granted by the ACCC to entities that meet requirements for security, insurance, dispute resolution and fitness. We do not hold it. The pathway we intend to use is the CDR representative model, in which an accredited business collects data on our behalf and remains responsible for what we do with it.
Our intended CDR principal is Fiskil, which holds unrestricted accreditation as a data recipient. That arrangement is not signed. Until it is, none of the rest of this page is operative.
Under the CDR Rules, a business that is not itself accredited can provide CDR services through a written CDR representative arrangement with an accredited principal. In that arrangement:
Under the CDR Rules, consent must be voluntary, express, informed and specific, and it is time-limited. In practice, when you connect a bank feed:
Account details (name, type, masked number, balance, institution) and transactions (date, amount, description, status) for the accounts you select.
The route matters, so here it is exactly:
Your data is not sold, brokered, used for advertising or used to train AI models. Our server-side hosting is in Australia.
One feature to be aware of: the optional AI QuickView sends summary totals for a financial year to an AI provider you configure, and those totals are calculated over bank-fed transactions among others. It is off unless you enable it with your own API key, and the app asks you to confirm before the first send. See the Privacy Policy.
You can withdraw at any time, from any of three places, and any one of them is enough:
Withdrawal stops future data sharing immediately. It does not need a reason and there is no penalty.
Transactions already delivered stay in your ledger. This is deliberate: they are your financial records and may be tax substantiation, and silently deleting five years of history because you disconnected a feed would be the wrong default. You can delete them yourself at any time, in the app, individually or in bulk.
Under the CDR Rules, when consent is withdrawn or expires and the data is no longer needed, it must be deleted or de-identified. Because Vault does not retain CDR data server-side, there is very little on our side to delete — the enrolment record and the feed timestamps, which go when you remove the connection or delete your account.
The copy that matters is the one on your own device, and you control it directly. Vault does not de-identify your data for research or any other purpose, and does not disclose de-identified data to anyone.
To have your account and all server-side data deleted, email [email protected] — see the Privacy Policy for that process and our 30-day commitment.
Start with us: [email protected]. We acknowledge within 7 days and answer substantively within 30.
Once the CDR arrangement is live, a complaint about CDR data can also go to the accredited principal, whose internal dispute resolution process and external scheme membership will be published here alongside its CDR policy. From there, the external paths are:
General information about your rights is at cdr.gov.au.
Bank feeds are a convenience, not a requirement. Today, without any of the above:
Every one of these puts the same data in the same ledger, and the tax engine does not care which one it came from.