While that's common in Germany, in Poland giving your login & passto 3rd party means that bank has no responsibility for any loss/fraud/anything if something goes wrong for whatever reason. This is breaching the term with the bank, that your login and password are confidential.
In Poland a oauth like alternative for payments is used, where you end up on your bank website to confirm payment and then you go back to the merchant.
> You agree to: 1) keep your password secure and strictly confidential, providing it only to authorized signers on your account(s); 2) instruct each person to whom you give your password that he or she is not to disclose it to any unauthorized person; and 3) immediately notify us and select a new password if you believe your password may have become known to an unauthorized person. We may suspend or cancel your password even without receiving such notice from you, if we suspect your password is being used in an unauthorized or fraudulent manner
You would freely give out the private key of your credit card (credit card number/expiry date/cvv) to any online merchant, but hesitate on authing your bank account user/pass which you can change anytime you want?
smh.
Maybe different for other banks, but this was the requirement for Chase.
Is privacy.com actually asking for bank logins, or just your bank account number/routing? In either case, it is nothing new or uniquely scary about this service. If you're not comfortable with this, then there really aren't any third-party online banking apps you are going to be comfortable with anyway.