At a glance
Banking and UPI apps often ask for contacts, photos, or location access once during setup — for a feature like “pay a contact directly” — and keep that access indefinitely, whether you use the feature or not. You can review and revoke it any time from your phone’s settings without losing UPI or banking functionality itself: regulators have already established that core payment features can’t be held hostage to a permission the payment itself doesn’t need.
Educational resource only. This is a practical guide to reviewing and revoking app permissions on banking and UPI apps in India, in line with the safe-handling ideas behind India’s Digital Personal Data Protection Act, 2023 (DPDP Act); it is not formal legal advice.
Why banking and UPI apps ask for more than they need
A single feature — “pay someone from your contacts” — is often the reason an app asks for permanent access to your entire contact list, photo gallery, or location, well beyond what that one feature needs at the moment you use it. Contacts access lets an app suggest payees by name instead of a UPI ID or number; photo access is often used to let you attach a screenshot or scan a QR code from your gallery; location has historically been used for fraud checks and geotagging risk profiles. None of these are unreasonable features on their own — the problem is when the access is granted once and never revisited, sitting active long after you’ve stopped using the specific feature that needed it.
The rule that backs you up: a permission can’t hold the service hostage
Regulators have already drawn this exact line for UPI apps specifically, and it’s a useful precedent for permissions generally. The National Payments Corporation of India (NPCI) directed UPI apps in 2022 that they cannot deny or disable core payment services just because a user declines or later revokes location-data access — consent for that data has to be genuinely optional, not bundled into the app working at all. It’s the same principle India’s DPDP Act applies more broadly: consent for anything beyond what a purpose strictly needs has to be free and unconditional, not a take-it-or-leave-it demand. Practically, that means revoking contacts, photos, or location access from your UPI or banking app should not stop you sending or receiving payments — if it does, that’s the app over-reaching, not a real technical requirement.
Step-by-step: revoking permissions on Android
- Open Settings → Apps and select the banking or UPI app.
- Tap Permissions.
- Go through each listed permission — Contacts, Photos/Media, Location, Microphone — and set the ones you don’t actively need to Deny or Only while using the app (or Ask every time, on Android versions that offer it).
- Repeat this for every payment, banking, and wallet app on the phone — not just the one you use most, since a rarely-opened app with standing access is easy to forget about entirely.
- Revisit this every few months; an app update can occasionally reset a permission back to its default.
Step-by-step: revoking permissions on iPhone
- Open Settings → Privacy & Security.
- Tap the permission category you want to review — Contacts, Photos, or Location Services.
- Find the banking or UPI app in the list and toggle its access off, or for Photos specifically, switch it to Limited Access to a chosen selection rather than your entire library.
- For Location Services, choose Never or While Using the App rather than Always, unless a specific feature you use genuinely needs background location.
- Test the app’s core payment function afterward to confirm nothing essential broke — it shouldn’t have.
Don’t forget your Account Aggregator consents
If you’ve ever linked your bank data to a lending app, budgeting tool, or credit-score service, that’s a separate consent from your phone’s permission settings — and it needs its own revocation. India’s Account Aggregator framework lets apps pull your bank statements and transaction history with your explicit, purpose-bound consent, tracked through the Account Aggregator you used (apps like OneMoney, CAMS Finserv, or one built into your bank’s own app). To revoke:
- Open the Account Aggregator app or website you originally consented through.
- Log in with your registered mobile number and OTP.
- Go to Consents (sometimes labelled My Consents or Permissions).
- Find the specific consent — it shows who requested the data and what accounts were shared — and tap Revoke, then confirm.
Revoking stops future access; it doesn’t erase data already pulled before you revoked, which is a separate ask you’d direct to whoever received it.
FAQ
Will my banking or UPI app stop working if I revoke its contacts or photo access?
The core function — sending and receiving payments — shouldn’t break. Regulators have specifically ruled that UPI apps can’t hold payment functionality hostage to permissions like location; the same logic applies to contacts and photos in practice.
How often should I review app permissions?
Every few months is a reasonable habit, and definitely after any major app update, since updates occasionally reset permissions or introduce new ones you haven’t reviewed yet.
What’s the difference between a phone permission and an Account Aggregator consent?
A phone permission controls what the app can access on your device (your contacts, camera roll, location). An Account Aggregator consent is a separate, purpose-bound agreement letting an app pull your actual bank data through a regulated intermediary — it needs to be revoked through that intermediary, not your phone’s settings.
Does revoking an Account Aggregator consent delete data already shared?
No — it stops future access only. Data already pulled before you revoked stays with whoever received it, unless you separately ask them to delete it.