TL;DR
- Trust comes first: In financial apps, every in-app element is judged for credibility before relevance. A nudge that feels merely annoying in shopping can feel disqualifying when money is involved.
- Regulatory context: Covers RBI’s 2026 dark pattern and mis-selling rules and SEBI’s proposed Common Advertisement Code, with a focus on what they mean for in-app promotions.
- Activation gap: Explores the gap between KYC completion and the first transaction, and the in-app patterns that help users move forward.
- Helpful vs. pushy: Examines which in-app formats feel supportive and which can undermine trust in a financial context.
- Explaining complexity: Shows how to communicate risk and complex financial products without overwhelming users with compliance disclaimers.
- Cross-selling: Covers how to introduce a second financial product without damaging the confidence established through the first purchase.
- Personalisation & consent: Explains what DPDP means for personalisation, data usage, and consent design.
- Real-world implementation: Shares patterns from a regulated wealth management implementation, along with the transferable principle behind each.
- Sourcing: Regulatory claims are attributed to current 2025–2026 rulemaking, while case study claims are attributed to their sources and the regulatory status of referenced companies is clearly stated.
A scratch card in a food delivery app reads as a fun bonus. The same scratch card in an investment app reads as a question: why is a platform holding my money trying to gamify my behaviour? This is not a matter of taste or brand tone. It is a structural feature of how people evaluate anything asking for their money. Every in-app element in a financial app is first processed as a credibility signal, and only afterward, if it survives that first check, as a relevant or useful piece of content. Most in-app design guidance is written for categories where this ordering does not apply, which is why so much of it produces the wrong instinct the moment it is applied to fintech or BFSI.
The Trust Constraint
The evaluation ordering is the whole story. In a shopping or media app, a user asks "is this relevant to me" first, and "can I trust this platform" is a background question that only surfaces if something goes wrong. In a financial app, the order inverts. A user asks "can this institution be trusted with my money" continuously, on every screen, and "is this specific piece of content relevant" is downstream of that trust question, not independent of it.

This inversion means a technically well-targeted, perfectly timed in-app nudge can still fail if its format or tone reads as commercially aggressive, because the failure is not about relevance. It is about what the element's mere presence signals about the institution's priorities. A nudge, correctly defined, must be easy to avoid: a dismissible tooltip is a nudge, while a full-screen interstitial that cannot be skipped without an acknowledgment tap is not, and the ease of avoidance is not a design weakness but the mechanism itself, because when users know they can ignore a prompt, the ones who do not ignore it are demonstrating genuine intent. In a financial context specifically, this principle carries extra weight: an element the user cannot easily dismiss does not just fail to convert. It actively damages the trust relationship the entire platform depends on, because it signals that the institution's commercial interest has been placed above the user's autonomy over their own money.
Regulatory Boundaries
The regulatory environment for financial promotion in India tightened substantially through 2025 and 2026, and the changes speak directly to in-app design specifically, not just traditional advertising.

The RBI's Commercial Banks Responsible Business Conduct Second Amendment Directions, coming into force January 1, 2027, extend beyond branch sales practices to explicitly address digital journeys, user interfaces, direct selling agents, and third-party payment aggregators, introducing detailed requirements around customer consent, suitability assessment, and prevention of mis-selling. A related draft framework specifically addresses dark patterns, mis-selling, and compulsory bundling, proposed to take effect from July 1 and April 1, 2026, and explicitly cautions against practices including high-pressure sales competitions and targeting customers for loans around festive seasons or month-ends. The same framework specifically notes that merely sending a link or an in-app notification is insufficient for certain disclosure obligations, which are considered products of higher risk requiring more deliberate presentation.
On the securities side, SEBI's proposed Common Advertisement Code, under consultation as of June 2026, requires that advertisements be true, fair, accurate, complete, and unambiguous, must not be designed to be misunderstood or to disguise the significance of any statement, and must not exploit a lack of experience or knowledge on the part of investors, with extensive technical or legal terminology specifically flagged as a practice to avoid. For short-format messaging specifically, including pop-ups and push notifications, where character limits prevent a full disclaimer, the proposed rule allows a hyperlink to the official disclosure page to satisfy the requirement, which is directly relevant to how a bottom sheet or in-app card should be structured.
The most consequential proposal for gamification specifically: SEBI's draft Common Advertisement Code proposes prohibiting advertisements that promise guaranteed returns, make exaggerated claims, feature testimonials, or present unfair comparisons, and a separate proposal specifically targets rewards-based customer acquisition, meaning investment apps may need to abandon reward-driven signup incentives entirely under the revised code. This is a direct, structural constraint on any gamification mechanic tied to new-account acquisition specifically in the investment category, and it means the general commerce playbook of scratch cards and spin-the-wheel as signup incentives, which works cleanly in e-commerce, does not transfer to a SEBI-regulated investment product without running into this specific, currently active regulatory scrutiny.
The Activation Problem
Most neobanks lose 60% of users between KYC completion and first transaction, and treating account creation as activation is premature, since a completed account means nothing if the user never funds it. Real activation is transactional: the first meaningful money movement, and the specific product teams that close this gap successfully treat KYC completion as the start of a distinct, high-intensity 72-hour intervention window, not the end of onboarding.

The in-app patterns that close this gap specifically for fintech and BFSI trade on the trust constraint rather than working against it. Groww's KYC copy states plainly why a step is legally required, "we need your Aadhaar to verify your identity, this is required by SEBI for all investment accounts," rather than presenting the requirement without context, which is the general principle: a required regulatory step delivered with an honest explanation of why it exists builds trust through the friction itself, rather than despite it. The empty-account moment immediately after KYC completion is the highest-leverage screen in the entire activation funnel, and it needs a specific prompt connected to the original reason the user signed up, not a generic add-money instruction, because a generic prompt at this exact moment reads as the platform having no memory of what the user actually came for, which is itself a small trust failure at the highest-stakes point in the funnel.
Formats That Work and Formats That Damage Trust
What reads as helpful. A bottom sheet that appears at a moment the user's own behaviour has signalled genuine intent, viewing a fund category twice, reaching a specific step in a form, reads as the platform paying attention. A progress indicator showing where the user stands in a required compliance flow reads as transparency. A confirmation screen that explicitly states what just happened and what it means reads as respect for the user's need to understand their own financial actions.
What reads as pushy. An interstitial that fires on app open, before the user has done anything, reads as the platform's priorities coming before the user's. A countdown timer on an investment product reads as manufactured urgency applied to a decision that should be made deliberately, not under artificial pressure, which is precisely the FOMO-style messaging SEBI's proposed advertisement code explicitly targets. The regulator's stated concern is aggressive behavioural prompts and fear-of-missing-out messaging that lure individuals into transactions without adequate deliberation, which means a design pattern that is merely aggressive marketing in e-commerce is a specific, named regulatory concern in this category.
The general test that separates the two categories: does the format give the user information and time to decide, or does it compress the decision window artificially. A financial decision benefits from the opposite of what compresses a commerce decision. Commerce in-app design optimises for speed because the product is usually low-stakes and reversible. Financial in-app design has to optimise for informed deliberation because the product frequently is not.
Explaining Risk and Complexity In-App
Financial products carry genuine complexity that most users have not been taught to reason about, and the in-app design challenge is delivering that complexity without either a compliance-driven wall of text or an oversimplification that leaves the user under-informed about real risk.
Progressive disclosure, revealing questions or information gradually rather than presenting the full scope in a single dense screen, produces meaningfully higher completion rates, roughly 75% versus 53% for equivalent content delivered as a single form, and for a required regulatory step specifically, this completion gap carries direct compliance consequence, since an incomplete flow blocks the platform from serving the user at all. This is the correct architecture for risk disclosure specifically: a multi-step sequence that introduces one concept at a time, rather than a single screen with every risk factor listed simultaneously, which most users skim without genuinely absorbing.
Stories-format content, tap-driven and sequential, is particularly well suited to this problem for a specific reason: complex financial concepts including how SIPs compound, what a credit score means, or how insurance premiums are calculated are well suited to a sequential structure where each segment introduces one concept before building to the next, which fintech education specifically has already demonstrated works, with CRED Learn's storytelling-based model explaining credit psychology through short narratives. The format's tap-to-advance mechanic lets the user control their own pace through genuinely difficult material, rather than being scrolled past it or overwhelmed by it in a single dense block.
The line this approach has to respect, given the regulatory context above, is that simplification cannot cross into omission of material risk. A stories sequence explaining SIP compounding cannot imply guaranteed returns. A sequence about a lending product must still surface the disclosures SEBI and RBI require, even when doing so within a format built for brevity. The correct design response is not to skip the disclosure to preserve the format's simplicity. It is to place the disclosure at the point in the sequence where it is contextually load-bearing, and to use the hyperlink-to-full-disclosure pattern the regulator has explicitly endorsed for short-format content, rather than compressing a required warning into a single word that satisfies the letter of the rule without its actual purpose.
Cross-Sell Without Eroding Confidence
The timing, placement, and framing of a second-product offer to an existing customer determines whether it reads as the platform genuinely understanding the customer's financial picture, or as the platform trying to extract more revenue from an existing relationship.

Timing. The correct moment is after the first product has demonstrably delivered value, a completed transaction, a portfolio that has grown, a bill successfully paid on time, not immediately after account opening when the relationship has not yet earned the credibility a second ask requires. A cross-sell offered before the first product has proven itself reads as the platform not actually caring whether the first relationship works, only whether it can be expanded.
Placement. The offer belongs adjacent to the moment of demonstrated value, not interrupting it. A user who has just seen their portfolio grow, viewing that growth on a dashboard screen, is in a receptive state for a related suggestion presented alongside that dashboard. The same offer, delivered as an interstitial the moment the app opens, disconnected from any specific value moment, reads as generic upsell rather than a relevant next step.
Framing. The offer should be framed around the specific financial goal or behaviour the platform has actually observed, not a generic product pitch. "You've been consistently investing for six months, here's how a tax-saving option fits your pattern" is grounded in specific, observed behaviour. "Upgrade to Premium" with no connection to anything the user has actually done reads as a template applied to every user regardless of fit, which is precisely the kind of generic, unsuitable recommendation the RBI's suitability assessment requirements are designed to prevent.
DPDP and Consent
Personalisation in a financial app operates under a stricter compliance bar than in most other categories, because the data involved, transaction history, risk profile, income indicators, is squarely sensitive personal data under DPDP.
India's DPDP Act applies to the processing of personal data of Indian residents regardless of where that processing occurs, and every third-party vendor that touches personal data, including analytics and engagement platforms, must have a signed Data Processing Agreement in place, with the data fiduciary, the app itself, remaining accountable for any misuse or violation regardless of what the vendor's own infrastructure looks like. The Data Protection Board of India began active enforcement in Q1 2026, which makes consent architecture a live compliance question, not a theoretical one, for any fintech app running in-app personalisation today.
What personalisation is permissible without additional explicit consent: using a user's own declared preferences and behaviour within the app they are actively using, to tailor what that same app shows them, is generally within the scope of processing the user reasonably expects as part of using the product. What requires explicit, purpose-specific consent: sharing behavioural or financial data with a third party for a purpose beyond delivering the immediate service, using inferred risk or income signals to make an offer the user has not specifically consented to receiving, and any use of data that extends beyond the specific purpose stated when it was collected.
Designing for auditability means the consent architecture has to produce a record, not just a checkbox the user taps once. Every personalisation decision that draws on sensitive financial data should be traceable back to a specific, timestamped consent event, and the platform should be able to demonstrate, on request, exactly which data informed a specific in-app decision shown to a specific user. This is a meaningfully higher bar than a generic cookie-consent banner, and it needs to be built into the in-app engagement architecture from the start, not retrofitted after a personalisation feature has already shipped.
What We Have Seen Work
Growth teams at Probo, Dezerv, and Lokal run nudge campaigns from the Digia dashboard independently of engineering. A note on scope before drawing patterns from this list: Probo, an opinion trading platform, has been under active Enforcement Directorate investigation since July 2025, with allegations that the platform disguised illegal betting as opinion trading and that ₹284.5 crore in assets were frozen amid concerns including inadequate age verification. Probo is not SEBI-regulated, and its underlying category's legality in India remains contested. Given this, the patterns discussed below draw specifically on Dezerv, a SEBI, APMI, and AMFI-regulated wealth management platform, and on the general engagement principles this article has covered throughout, rather than treating Probo's implementation as a model to emulate.
Dezerv, a wealth consolidation and portfolio review platform. Dezerv brings mutual funds, stocks, NPS, and fixed deposits into a single wealth dashboard, offering a real-time unified view of a user's assets alongside expert-led portfolio review, and the platform is fully licensed by SEBI, APMI, and AMFI, with bank-grade security and ISO 27001 certification. The transferable principle from a wealth consolidation product specifically: the core in-app job is surfacing a genuinely useful insight the user could not easily calculate themselves, an underperforming fund flagged against its benchmark, a diversification gap made visible, rather than a promotional prompt. The product's own positioning centres on identifying "leaks" eating into long-term returns, which is the correct model for in-app content in a wealth management context: the nudge exists to deliver an insight the user genuinely needed, and any commercial action that follows is downstream of that insight having been delivered honestly, not the other way around.
The broader transferable principle across regulated financial products. Timeliness and relevance, not the specific content of a nudge, are the two factors that most determine whether a financial nudge actually works, with the impact dictated by the narrow window when a customer's attention and intent are genuinely aligned. In-app nudges in a comparable financial services trial achieved a 75% open rate, compared to low single digits for traditional email marketing, which confirms the general in-app advantage holds in financial services specifically, provided the nudge itself respects the trust constraint this entire article has been built around.
Topics Not in the Brief That Teams Should Know
The suppression logic for financial apps needs a wider blocklist than commerce. Beyond the standard suppression states, transaction in progress, error state, any in-app promotional or cross-sell content should also be suppressed for a defined period following a customer complaint, a failed KYC attempt, or a support escalation, since a promotional element appearing immediately after any of these moments reads as the platform being tone-deaf to a user's actual, current relationship with the product at exactly the moment trust is most fragile.
Language and literacy considerations carry more weight in financial disclosure than in general vernacular localisation. Risk tolerance concepts including volatility, drawdown, and time horizon are genuinely abstract for a first-time investor regardless of how well a survey or disclosure is framed, which means visual metaphors and regional language support matter more for financial risk communication specifically than for most other in-app content categories, precisely because the underlying concepts being communicated are ones many first-time users have never had to reason about explicitly before, in any language.
Regulatory change velocity itself is an operational constraint worth planning for. Given how much of the RBI and SEBI framework covered in this article is still in draft or consultation stage as of mid-2026, any in-app promotional architecture built today should be designed for rapid reconfiguration, not a fixed compliance posture assumed to hold indefinitely. A platform whose in-app disclosure and promotional content requires an app release to update is structurally unprepared for a regulatory environment that is actively revising its rules on a rolling basis.
Re-KYC and periodic review moments are underused as trust-building surfaces, not just compliance chores. A mandatory re-verification or periodic risk-profile review, required under SEBI's KYC framework, is frequently delivered as a bare compliance interruption. Framed instead as "let's confirm your situation hasn't changed so we can keep giving you the right guidance," the same mandatory step becomes a demonstration of ongoing attentiveness rather than administrative friction, using the same reframe principle documented in Groww's KYC copy.
Key Takeaways
Financial apps evaluate every in-app element for credibility before relevance, which inverts the design priority that governs most other mobile categories and means a technically well-targeted nudge can still fail if its format reads as commercially aggressive.
RBI's 2026 dark pattern and mis-selling rules and SEBI's proposed Common Advertisement Code impose specific, currently active constraints on in-app promotion, including a proposed ban on rewards-based customer acquisition for investment apps specifically, which means the standard commerce gamification playbook does not transfer cleanly into this category.
The KYC-to-first-transaction gap, where most neobanks lose 60% of users, closes through honest, contextual explanation of why regulatory steps exist and specific, remembered prompts at the empty-account moment, not generic add-money instructions.
Formats that respect the user's need for deliberation, progressive disclosure, contextual bottom sheets, transparent confirmations, read as helpful. Formats that compress decision time, countdown timers, interstitials on app open, read as pushy and increasingly draw specific regulatory scrutiny under the FOMO and dark pattern provisions now in force or under consultation.
Explaining risk and complexity works best through progressive, sequential formats like stories, which improve completion without sacrificing the material disclosures that SEBI and RBI require, provided the format's brevity is used to sequence information rather than to omit it.
Cross-sell should follow demonstrated value, sit adjacent to the moment that value was shown, and be framed around specific observed behaviour rather than a generic product pitch, since a mistimed or badly framed cross-sell in this category damages the trust the entire platform depends on.
DPDP requires an auditable consent architecture built into the in-app engagement system from the start, with every personalisation decision drawing on sensitive financial data traceable to a specific, timestamped consent event.
Further Reading
From Digia Engage:
- In-App Nudges: What They Are, When to Use Them & 12 Examples — the ease-of-avoidance nudge definition and event-triggered targeting principle this article's trust constraint section builds on
- How Groww Uses In-App Surveys to Build Risk Profiles Without Feeling Like KYC — the full progressive disclosure and plain-language regulatory framing pattern referenced throughout this article
- How Indian Fintech Apps Drive User Activation: 8 In-App Patterns — the KYC-to-first-transaction activation gap covered in fuller depth
- In-App Storytelling: How to Use Stories Format to Drive Engagement — the sequential disclosure format referenced in this article's risk communication section
- Why Indian Product Teams Need Different In-App Tooling Than US SaaS — the DPDP compliance detail this article's consent section builds on
- Scratch Cards in Mobile Apps: Design, Timing, and Conversion Data — the variable reward mechanic principles, relevant to understanding why SEBI's proposed reward-acquisition ban targets this specific pattern
- When NOT to Show a Nudge: Building a Suppression Logic — the suppression framework this article's additional topics extend for financial-specific trust moments
- Digia Engage Nudges — event-triggered, dismissible in-app formats built around the trust constraint this article describes
External Sources:
- RBI Tightens Rules on Financial Product Marketing and Sales — Law.asia (RBI Second Amendment Directions 2026, effective January 2027)
- RBI Issues Draft Directions on Fair Marketing and Sales Practices — Lexology, Fox Mandal & Associates (dark pattern definitions and festive-season targeting caution)
- Introduction: Agency/Referral Activities by Banks and NBFCs — Khaitan & Co (in-app notification insufficiency for higher-risk disclosures)
- SEBI Common Advertisement Code (CAC) 2026: Key Proposals Explained — CorpLawUpdates (short-format disclaimer hyperlink rule; misleading and technical-terminology prohibitions)
- Investment Apps May Have to Abandon Rewards-Based Customer Acquisition Under SEBI's Proposed Ad Code — BusinessToday (the reward-acquisition ban proposal directly relevant to gamification design in this category)
- 'FOMO, Fixed Return': SEBI Proposes Revamped Ad Code for Bond Portals — BusinessToday (FOMO messaging and artificial scarcity as specific regulatory targets)
- How to Apply Nudge Theory in Financial Services — Moneyhub (timeliness and relevance as the two determinants of nudge effectiveness; 75% open rate case data)
- Dezerv: Mutual Funds & Stocks, Google Play — Dezerv (SEBI, APMI, and AMFI regulatory licensing confirmation)
- Probo — Grokipedia — Grokipedia (Enforcement Directorate raid details, asset freeze, and regulatory allegations, cited for factual accuracy and appropriate caution regarding this article's case study scope)
The event-triggered, dismissible in-app formats and consent-auditable personalisation architecture described in this article are native to Digia Engage, deployable without engineering tickets after initial SDK integration and built around the trust-first design constraint this category requires. Book a demo to see how a regulated financial product's in-app engagement can be configured within RBI and SEBI's current promotional boundaries, or read the Groww risk profiling breakdown for the full progressive disclosure pattern this article's risk communication section is built on.