I love Monzo, but one thing that does concern me greatly are banking apps (or any apps that touch highly sensitive pieces of information) that include third party components or make any communication to third parties.
In the case of Monzo: https://reports.exodus-privacy.eu.org/en/reports/88809/
+ Facebook Analytics
+ Facebook Login
+ Google Ads
+ Google CrashLytics
+ Google DoubleClick
+ Google Firebase Analytics
And according to NetGuard locally:
ws-eu.pusher.com
graph.facebook.com
e.crashlytics.com
app.adjust.com
graph.accountkit.com
Of those, aside from generally "Why?" I'm most concerned by crashlytics.com . Is this like Sentry? Does it send a stack on a crash? If I'm paying someone and entered my PIN and it crashes, did my PIN go to a third party?I saw an app recently that gave me the option in the settings to opt out of crashlytics - more of that please!
I'd be much happier seeing nothing third party in apps that deal with sensitive information.
And I'd be happy to memorise a 2nd less important software PIN for app transaction authorisation that wasn't the same as the ATM and hardware PIN.