In my case, it's different.
Open the app the first time, accept the license, it contacts the server (anonymously, as it doesn't have any user data at this point) and establishes a random TOTP seed and a hex ID (which is an unchanging hex string visible in the UI along with the generated codes). There is no need to log in, and the app does not even have a login form. The bank has a database table that maps the hex ID to the corresponding TOTP seed. From that point on, the app never uses the network.
When you open the app the next time, it functions as a regular TOTP generator that keeps the seed in some protected area that cannot be backed up even if you have root (ignoring the license concerns) - except that you can't use the generated codes anywhere.
This also means that reinstalling the application, or installing it on a second phone, will result in a new ID and a new TOTP seed, so the two phones will have different hex IDs and different seeds, and thus will not agree on the codes generated.
To make the application useful, you need to physically go to the bank and present the running app together with your passport. They will inspect your phone for signs of rooting, dangerous settings or unwanted apps, associate the hex ID displayed by their app with your account (so that the generated TOTP codes start working on their online banking website), and disable the previous one (so you can't use two phones).