DEEP DIVE DATA
×
PRIVACY HEALTH · ZIMBABWE BANKING APPS

We opened 23 Zimbabwean banking and mobile money apps.Here's what each one asks for.

23
APPS ANALYZED
2
HIGH RISK
2.2/5
AVG RISK SCORE
SWIPE TO READ  ›
HOW WE SCORED THEM

Every app on Zimbabwe's banking and mobile money market was checked against the same five-point scale.

The score isn't just a permissions count. It weighs what an app declares in its manifest against what's actually granted and used to track you — camera, contacts, location and phone access carry more weight than notifications, and anything flagged under "data used to track you" (identifiers, device IDs, contact info shared onward) pushes a score up regardless of category.

A 1/5 means a clean, minimal footprint. A 5/5 means broad access across sensitive categories, active tracking signals, or both.

THE SPLIT
2
of 23 apps rated high risk
High risk (4–5/5)2 apps
Moderate (2–3/5)14 apps
Minimal (1/5)7 apps

Most of Zimbabwe's banking apps land in the middle: they declare sensitive permissions for KYC and fraud checks, but at scan time very few had those permissions actively granted.

WHAT THEY ALL WANT

Camera and location, almost everywhere

Camera17 of 23 apps
Location17 of 23 apps
Contacts16 of 23 apps
Notifications10 of 23 apps
Photos and Videos8 of 23 apps
Phone7 of 23 apps
Microphone3 of 23 apps

Camera and location are declared by nearly three-quarters of the apps we checked — mostly justified as KYC document capture, QR payments, or fraud/compliance geofencing.

HIGHEST RISK · 5/5

InnBucks

7
data points linked to you
Version8.0.2
Data linked to you7 items
Data used to track youContact Info, Device/SIM identifiers

Camera, contacts, location, nearby devices, notifications, phone and photos — the widest permission footprint of any app we checked. Some of it supports core wallet functions like KYC and Bluetooth-based device pairing, but the scope is broad enough that it's the only app in the set flagged for active tracking via device and SIM identifiers.

SECOND HIGHEST · 4/5

NMB Connect

Version5.3.3
Data linked to you9 items
Data used to track youContact Info, Device/SIM identifiers

Location, contacts, camera, microphone, photos, phone identifiers, music/audio, notifications and diagnostics & usage data. The permission scope exceeds what standard banking operations typically require, and — like InnBucks — it's flagged for identifiers used to track you across apps.

MODERATE RISK · 2–3/5

The mainstream banking pack

CBZ Touch3/5
CABS Mobile Banking3/5
FBCBank3/5
EcoCash3/5
Ecobank3/5
NBS Bank3/5
FBC Mobile2/5
FirstCapital2/5
Standard/Stanbic Bank2/5
Nedbank2/5
OMARI Mobile2/5
OneMoney Mobile2/5
POSB Mobile Banking2/5
Unayo2/5

Fourteen of the 23 apps land here. The 3/5 cluster (CBZ, CABS, FBCBank, EcoCash, Ecobank, NBS) all declare the same core set — camera, contacts, location, photos — for KYC and payee/fraud checks, with no permissions actively granted at scan time.

THE IMPORTANT CAVEAT

Declared isn't the same as active

Declared vs granted: across nearly every app in the moderate tier, the assessment notes the same thing — sensitive permissions are declared in the manifest, but none were currently allowed by the user at scan time. A high score here reflects potential access scope for identity verification and fraud monitoring, not confirmed active data collection. EcoCash was the one exception: its assessment notes camera is set to ask each time, rather than sitting dormant.
MINIMAL RISK · 1/5

The cleanest footprints

  • BancabcVisa — only Location declared, nothing granted.
  • Blue247 — Contacts and Location declared, not granted.
  • Steward Bank Square — Notifications actively used for alerts; Contacts declared only.
  • Steward Bank Visa — Contacts and Notifications declared, not granted.
  • A360 — Camera, Microphone, Phone declared, none granted.
  • African Century — only Camera declared, unused.
  • One ZB — Camera and Notifications declared, minimal footprint.

Seven apps score 1/5, with no data linked to identity and no tracking signals observed.

OBSERVATION 01

Active tracking is the exception, not the rule.

Of 23 apps, only InnBucks and NMB Connect are flagged with "data used to track you" — both citing contact info and device/SIM identifiers. Every other app in the dataset shows no active tracking behaviour, even where the declared permission list is long.

OBSERVATION 02

The same four permissions repeat for a reason.

Camera, Contacts, Location and Photos/Videos show up together across most of the moderate-risk banking apps — almost always justified the same way: KYC or ID capture, payee/beneficiary management, fraud or compliance geofencing, and document uploads. It's a template permission set for regulated banking apps in this market, not app-specific overreach.

THE BOTTOM LINE

Most of Zimbabwe's banking apps ask wide, but sit dormant

The typical app in this dataset declares more access than it's currently using. That's not necessarily reassuring — a declared permission can be activated by a future update without a fresh privacy notice — but at scan time, the real outliers are InnBucks and NMB Connect, where both the permission scope and the active tracking signals stand apart from the rest of the market.

Two apps out of 23 account for both flagged tracking cases in this dataset.

If you use InnBucks or NMB Connect, that's the pair worth checking your own device permissions on first.

END OF STORY

Deep Dive Data tracks how Zimbabwe's apps handle your data.

Produced independently by Deep Dive Data from manifest and permission analysis of 23 Zimbabwean banking and mobile money apps, last analyzed 1–2 June 2025. Risk scores (1–5) reflect declared permission scope, active grants at scan time, and any data flagged for cross-app tracking. Findings describe declared app manifests and permissions observed at the time of analysis and may not reflect the current version of any app.