Mobile App Risk is Business Risk.
Regulators are watching Enterprise mobile apps. Users demand transparency. Get instant visibility into privacy risks, AI data exposure, dangerous permissions and suspicious network connections across your entire enterprise app portfolio.
Search 2,000+ Enterprise Apps. Know Your Risk in Minutes.
Ally: Bank, Auto & Invest
Ally: Bank, Auto & Invest
Refer your friends to Ally and you could both get paid. Terms & conditions apply. Eligible Ally Bank account holders can select the Learn how link in Profile for details.
Making your financial life simple and secure has always been our thing. Easily manage your bank, credit card, invest and auto accounts on the go — all in one app.
Ally Auto
• Make one-time vehicle payments or use Auto Pay to schedule future payments
• Manage multiple vehicles from your Snapshot
• Stay on top of your financial health with free FICO® Score updates
Ally Bank
• Save more with smart savings tools: buckets and boosters
• Our Spending Account is a checking account packed with money management tools
• Get paid up to two days sooner with early direct deposit
• Avoid monthly maintenance fees and hidden fees
• Your deposits are insured by the FDIC up to the maximum allowed by law
Ally Credit Card
• Make secure credit card payments, review credit statements, and check your FICO® Score for free
• Ally Mastercard credit cards available by invitation only
Ally Invest
• With Robo Portfolio, choose one strategy, then select cash enhanced for no advisory fee, or invest more money in the market with a fee-based, market-focused portfolio
• For the more hands-on investor, trade commission free on eligible U.S. stocks and funds with Self-Directed Trading
• With Personal Advice, start with a $100,000 minimum in assets under care and receive ongoing guidance from one dedicated advisor for all your assets — even ones we don’t manage
We’re serious about security
• We never store personal or account information on your phone
• Our security codes provide extra protection when you log in from a computer or device we don’t recognize
• Our online and mobile security guarantee protects you against fraudulent transactions
You should know
• The Ally app is free — your mobile carrier’s message and data rates may apply
• FICO® is a registered trademark of the Fair Isaac Corporation in the United States and other countries
• Deposit products are offered by Ally Bank, Member FDIC
• Savings buckets and boosters are features of the Ally Bank Savings Account. Spending buckets are a feature of the Ally Bank Spending Account
• Early direct deposit, a feature of Ally Bank’s Spending Account, offers eligible direct deposits up to two days sooner
• Earn more than 5x the national average claim is based on the national average APY for this type of account, which is 0.38% APY, based on rates published in the FDIC Monthly National Rates and Rate Caps accurate as of 6/16/2025.
• Securities products and services offered through Ally Invest Securities LLC, member finra.org/#/ / sipc.org. For background on Ally Invest Securities go to brokercheck.finra.org/firm/summary/136131. Advisory services offered through Ally Invest Advisors Inc., a registered investment adviser. Ally Bank, Ally Invest Advisors, and Ally Invest Securities are wholly owned subsidiaries of Ally Financial Inc. ally.com/invest/disclosures/. Securities products are NOT FDIC INSURED, NOT BANK GUARANTEED, and MAY LOSE VALUE
• Ally Invest doesn't charge commissions for stocks and ETFs priced $2 and higher. Stocks priced less than $2 are charged a base commission up to $4.95 plus 1 cent per share on the entire order. See ally.com/invest/commissions-and-fees/ for more information
• Get access to cash at 75,000+ no-fee Allpoint® and MoneyPass® ATMs nationwide with reimbursement of other ATM fees nationwide, up to $10 per statement cycle.
Ally: Bank, Auto & Invest
Package ID
com.ally.MobileBanking
Version
69731
Developer
Ally Financial
Category
Finance
Store Rank
95
App Store Link
View in Google PlayDeveloper Privacy Policy
Privacy PolicyObservations Summary:
Permissions Observations
DETECTEDPermissions defined by Apple and Google as dangerous have been observed.
Observed During Analysis
- Allows an app to access approximate location.
- Allows an app to access precise location.
- + 25 more
- Allows applications to access information about networks.
- Allows applications to access information about Wi-Fi networks.
- Allows applications to connect to paired bluetooth devices.
- Allows applications to discover and pair bluetooth devices.
- Required to be able to connect to paired Bluetooth devices.
- Allows an application to initiate a phone call without going through the Dialer user interface for the user to confirm the call.
- Required to be able to access the camera device.
- Allows applications to change network connectivity state.
- Allows access to the list of accounts in the Accounts Service.
- Allows applications to open network sockets.
- Allows an application to modify global audio settings.
- Allows an app to post notifications
- Allows an application to read the user's calendar data.
- Allows an application to read the user's contacts data.
- Allows an application to read from external storage.
- Allows read only access to phone state, including the current cellular network information, the status of any ongoing calls, and a list of any PhoneAccounts registered on the device.
- Allows an application to receive the Intent.ACTION_BOOT_COMPLETED that is broadcast after the system finishes booting.
- Allows an application to record audio.
- Allows an application to change the Z-order of tasks.
- Allows an app to create windows using the type WindowManager.LayoutParams.TYPE_APPLICATION_OVERLAY, shown on top of all other apps.
- Allows an app to use device supported biometric modalities.
- This constant was deprecated in API level 28. Applications should request USE_BIOMETRIC instead
- Allows access to the vibrator.
- Allows using PowerManager WakeLocks to keep processor from sleeping or screen from dimming.
- Allows an application to write to external storage.
- show less
- See Your App’s Risk Profile
Why Permissions Matter
If not managed properly, dangerous permissions can permit malicious access to sensitive data, and device features.
Sensitive Data Collection and Sharing Observations
SENSITIVE INFO FOUNDThis app collects, stores, or shares information that is often designated as sensitive and private.
Observed During Analysis
- Build Fingerprint
- See Your App’s Risk Profile
Why Data Collection and Sharing Matters
If not managed properly private data can expose enterprises, customers, employees and partners to breach and compliance violations.
AI Observations
DETECTEDThis app uses artificial intelligence and may introduce risks including loss of IP, privacy concerns, or other unintended consequences.
Observed During Analysis
- ML Kit
- LiteRT model
- See Your App’s Risk Profile
Why AI Matters
AI features can process sensitive data in unexpected ways, potentially exposing proprietary information or creating liability.
Network Connections Observations
DETECTEDNetwork analysis has detected communication with external servers and data transfer patterns.
Observed During Analysis
Connected Hostname:
- adobe.com
- akamai.com
- + 4 more
- amazon.com
- cloudflare.com
- fastly.com
- google.com
- show less
Server Locations:
- Ashburn, Virginia, US
- Council Bluffs, Iowa, US
- + 5 more
- Dulles, Virginia, US
- Lehi, Utah, US
- Mountain View, California, US
- San Francisco, California, US
- Seattle, Washington, US
- show less
- See Your App’s Risk Profile
Why Network Connections Matter
Uncontrolled communication with external servers by an employee-used app could expose sensitive business data to unauthorized third parties. This unauthorized access can lead to data breaches, regulatory non-compliance, and damage to your business's reputation and financial standing.
Privacy Declarations Observations
NOT DETECTEDThis test did not detect a discrepancy, indicating all required declarations are disclosed.
- See Your App’s Risk Profile
Why Privacy Declarations Matter
Declarations matter because they provide transparency on how apps collect and use sensitive data. iOS requires Privacy Manifest declarations, while Android requires Data Safety disclosures and manifest permissions.
NowSecure provides detailed risk assessments for millions of mobile apps. We Can Help Secure Your App.
All trademarks, logos, and brand names are the property of their respective owners. All company, product, and service names used in this website are for identification purposes only. Use of these names, trademarks, and brands does not imply endorsement.
MARC App Directory