A side note: The big banks expose mobile apis to their apps. However, I'm pretty sure that those are for private use
It turns out that the bigger bank has dozens of smaller banks using the very same API, and its a trivial matter of switching a URL slug to make my makeshift API work for these other banks.
It was an interesting learning experience, but I did manage to get myself locked out of my own bank account a few times while replicating the login process.
That said, using your account data in that way with third parties is often against the terms of service that a customer has with their bank.
.. And do you do everything you're told? ;)
I think we put far too much weight into magic documents like Privacy Policies and Terms of Service, etc.