Skip to main content
Redbark connects to Australian banks through the Consumer Data Right (CDR), Australia’s regulated Open Banking framework. This page explains what that means in practice for you as a consumer, and how the model works behind the scenes.

Who we are

Redbark is the trading name of SKINT AI Pty Ltd (ACN 685 364 729). We operate as a CDR Representative of Fiskil Pty Ltd, whose Accredited Data Recipient number is ADRBNK000246. Our appointment is listed on the public CDR register at cdr.gov.au/find-a-provider under Fiskil’s entry. The CDR Representative Arrangement is dated 19 February 2026.

The CDR Representative model

The Representative model is defined in CDR Rule 1.10AA. It allows an Accredited Data Recipient (an ADR, like Fiskil) to appoint another business (us) to deliver a CDR-powered product under the ADR’s accreditation. In practice this means:
  • Fiskil runs the hosted consent screen. When you connect a bank, you’re redirected to Fiskil’s consent UI to authenticate with your bank and choose which data to share.
  • Fiskil collects the data from your bank. The bank’s obligation to share data under CDR is to Fiskil, not directly to us.
  • Fiskil discloses the data to us on your behalf. We process it live and deliver it to the destination you configured.
  • Fiskil carries primary liability under Rule 1.16A for our handling of CDR data.
  • We adopt Fiskil’s CDR Policy under Rule 1.10AA(2)(e). You can read it at fiskil.com/legal/cdr-policy.

The accredited data path

The CDR-regulated path is:
Your bank → Fiskil (ADR) → Redbark (CDR Representative) → Your destination
Once data arrives at the destination you configured (Google Sheets, YNAB, Notion, a webhook), it lives in your own account with that provider and falls outside the CDR framework. The ACCC’s Third-party data sharing use cases guidance (updated 27 January 2026) addresses this model directly under Scenario 1(b).

What this is not

  • Not screen scraping. We never see your banking password. You authenticate with your bank directly.
  • Not a data broker. We only use your CDR data to provide the sync service you asked for.
  • Not indefinite access. Every consent expires after a maximum of 12 months.

Further reading