Editorial illustration of a bank customer reviewing and revoking third-party app access on a smartphone.
AI-generated editorial illustration; it does not depict an actual interface or documentary scene.

Key takeaways

  • Phased in the Chase Mobile app
  • Apps connected to Chase accounts and associated sharing
  • Permissions, access duration, eligible linked accounts and unlinking

Chase has begun a phased rollout of a Data Security Center inside its mobile app, giving customers one place to review third-party connections, change permissions, shorten access duration or unlink an app. The launch centralises controls that were previously spread across the bank’s account-linking experience.

The Chase Data Security Center shows which apps are connected, what information is being shared and which eligible accounts are linked. Chase says customers can also review connected-app activity and read plain-language guidance. Reuters and MT Newswires independently confirmed the rollout and its core controls.

Why a single control surface matters

Open banking gives consumers useful ways to move account data into budgeting, payments, tax and accounting tools. The risk is that consent becomes invisible after setup. A customer may remember linking an app but forget how much data it can access, which accounts are included or when that permission expires.

A central dashboard makes the ongoing relationship easier to inspect. It does not guarantee that every external app handles data safely, and Chase cannot control a third party’s privacy practices. But it can reduce the effort required to see and revoke a connection at the bank boundary.

This is the same basic control problem that appears across financial integrations. Lapaas Voice previously covered how the Lumin–MX integration replaced credential sharing with an open-banking connection. Moving away from shared passwords is important; giving customers a durable way to manage the resulting tokens is the next step.

What the Chase Data Security Center can and cannot do

Chase says customers can adjust how long an app has access, choose eligible accounts and unlink connections where available. Its support page also explains that some connections use substitute account numbers and that customers should review the terms and privacy policies of any app they authorize.

The centre does not independently certify an app, erase data the app already received or replace the app’s own deletion process. Revoking access should stop new data flows at the bank connection, but users may still need to contact the third party about retained records. That distinction should be clear in any security workflow.

Regulators are increasingly focusing on material harm in bank–fintech relationships. Our analysis of proposed bank-fintech risk guidance showed why accountability cannot end at the API boundary. A customer-facing control centre helps, but banks still need monitoring, incident response and clear responsibility across providers.

What customers should check

Customers should review connections they no longer use, narrow access to the minimum accounts required and pay attention to unusually long authorization periods. They should confirm whether revocation affects payments already scheduled and whether the external app keeps copies of historical data.

Businesses building on financial data should expect customers to demand the same clarity. The broader industry is connecting bank systems to more digital-asset and AI services; Oracle’s Digital Assets Data Nexus is one example of that expanding integration layer. Every new connection creates a need for visible consent and reliable offboarding.

The launch is a practical improvement, not proof that data-sharing risk has been solved. Its value will depend on how completely it lists connections, how quickly revocations take effect and whether customers can understand the consequences before they tap.

Chase Centralises Connected-App Data ControlsA three-step diagram moving from Connect to Review to Revoke.ConnectReviewRevoke
A practical view of the event’s mechanism and consequence.

Facts at a glance

Disclosure date September 25, 2026
Rollout Phased in the Chase Mobile app
Core view Apps connected to Chase accounts and associated sharing
Controls Permissions, access duration, eligible linked accounts and unlinking
Scope limit Chase has not published adoption or effectiveness data

Frequently asked questions

Where is the Chase Data Security Center?

Chase says it is rolling out inside the Chase Mobile app.

Can customers remove a connected app?

Yes, the centre includes unlinking where applicable, along with permission and duration controls.

Does unlinking delete data held by the app?

Not necessarily. Customers may need to contact the third party about data already received.

Reporting date: 2026-09-25. Source links and claim notes are recorded in the accompanying source ledger.

Get the day’s top stories in your inbox

One concise email. No spam, unsubscribe anytime.