DEEP DIVE DATAEvery app on Zimbabwe's banking and mobile money market was checked against the same five-point scale.
The score isn't just a permissions count. It weighs what an app declares in its manifest against what's actually granted and used to track you — camera, contacts, location and phone access carry more weight than notifications, and anything flagged under "data used to track you" (identifiers, device IDs, contact info shared onward) pushes a score up regardless of category.
A 1/5 means a clean, minimal footprint. A 5/5 means broad access across sensitive categories, active tracking signals, or both.
| High risk (4–5/5) | 2 apps |
| Moderate (2–3/5) | 14 apps |
| Minimal (1/5) | 7 apps |
Most of Zimbabwe's banking apps land in the middle: they declare sensitive permissions for KYC and fraud checks, but at scan time very few had those permissions actively granted.
| Camera | 17 of 23 apps |
| Location | 17 of 23 apps |
| Contacts | 16 of 23 apps |
| Notifications | 10 of 23 apps |
| Photos and Videos | 8 of 23 apps |
| Phone | 7 of 23 apps |
| Microphone | 3 of 23 apps |
Camera and location are declared by nearly three-quarters of the apps we checked — mostly justified as KYC document capture, QR payments, or fraud/compliance geofencing.
| Version | 8.0.2 |
| Data linked to you | 7 items |
| Data used to track you | Contact Info, Device/SIM identifiers |
Camera, contacts, location, nearby devices, notifications, phone and photos — the widest permission footprint of any app we checked. Some of it supports core wallet functions like KYC and Bluetooth-based device pairing, but the scope is broad enough that it's the only app in the set flagged for active tracking via device and SIM identifiers.
| Version | 5.3.3 |
| Data linked to you | 9 items |
| Data used to track you | Contact Info, Device/SIM identifiers |
Location, contacts, camera, microphone, photos, phone identifiers, music/audio, notifications and diagnostics & usage data. The permission scope exceeds what standard banking operations typically require, and — like InnBucks — it's flagged for identifiers used to track you across apps.
| CBZ Touch | 3/5 |
| CABS Mobile Banking | 3/5 |
| FBCBank | 3/5 |
| EcoCash | 3/5 |
| Ecobank | 3/5 |
| NBS Bank | 3/5 |
| FBC Mobile | 2/5 |
| FirstCapital | 2/5 |
| Standard/Stanbic Bank | 2/5 |
| Nedbank | 2/5 |
| OMARI Mobile | 2/5 |
| OneMoney Mobile | 2/5 |
| POSB Mobile Banking | 2/5 |
| Unayo | 2/5 |
Fourteen of the 23 apps land here. The 3/5 cluster (CBZ, CABS, FBCBank, EcoCash, Ecobank, NBS) all declare the same core set — camera, contacts, location, photos — for KYC and payee/fraud checks, with no permissions actively granted at scan time.
Seven apps score 1/5, with no data linked to identity and no tracking signals observed.
Of 23 apps, only InnBucks and NMB Connect are flagged with "data used to track you" — both citing contact info and device/SIM identifiers. Every other app in the dataset shows no active tracking behaviour, even where the declared permission list is long.
Camera, Contacts, Location and Photos/Videos show up together across most of the moderate-risk banking apps — almost always justified the same way: KYC or ID capture, payee/beneficiary management, fraud or compliance geofencing, and document uploads. It's a template permission set for regulated banking apps in this market, not app-specific overreach.
The typical app in this dataset declares more access than it's currently using. That's not necessarily reassuring — a declared permission can be activated by a future update without a fresh privacy notice — but at scan time, the real outliers are InnBucks and NMB Connect, where both the permission scope and the active tracking signals stand apart from the rest of the market.
If you use InnBucks or NMB Connect, that's the pair worth checking your own device permissions on first.
Deep Dive Data tracks how Zimbabwe's apps handle your data.