How connecting a bank account through Fena will work once that's live — written ahead of launch so it's ready for review.
This document describes a feature that isn't live yet. yamma currently connects only to a Google Sheet you pick — see the Privacy Policy. This page will move from "Phase 2" to active, and be linked from the main legal hub and footer, once bank connections via Fena ship.
In short
Fena holds the regulatory permission to access your bank data on your behalf (an Account Information Service Provider); yamma is a downstream recipient of that data under our agreement with Fena.
Open banking in the UK operates under the Payment Services Regulations 2017 (PSRs) and the Open Banking standard overseen by the FCA and the Open Banking Implementation Entity. A regulated Account Information Service Provider (AISP)— Fena — is authorised to request read-only account and transaction data from your bank on your behalf, once you've given consent. yamma integrates with Fena's API to receive that data; yamma itself is not separately FCA-authorised and does not request data from your bank directly. [Insert Fena's FCA Firm Reference Number and confirm the exact regulatory relationship — e.g. whether yamma acts as Fena's agent or tied technical services provider — once the integration agreement is finalised. This section needs sign-off from qualified legal/regulatory advice before this feature launches.]
You choose your bank, log in on your bank's own site or app, and approve exactly what yamma can see — yamma never sees your banking password.
When you connect a bank account, you'll be taken through Fena's consent flow: you select your bank, authenticate directly with your bank (via redirect or your banking app), and approve the specific accounts and data yamma is requesting. Your banking credentials are entered only on your bank's own site or app — never on yamma or Fena.
Read-only account information — balances and transactions. Never payment initiation, and never your credentials.
Open Banking consent lasts 90 days by regulation, and you can revoke it at any time — either in yamma or with your bank directly.
By regulation, Open Banking access consent expires after 90 days; yamma will prompt you to reconfirm before that happens so your data stays up to date. You can revoke access at any time in yamma's Settings, or directly through your bank's own app/site — revoking it there also stops yamma's access immediately.
Everything in our Privacy Policy about storage, security, retention, and your rights applies equally to bank data.
Bank data received via Fena is protected under the same encryption, access-control, and retention practices described in the Privacy Policy, and Fena is added to the list of subprocessors there.
Questions about any of this, or want to exercise one of your data rights? Contact help@yamma.money.