8 Total
3 High severity
3 Medium severity
2 Low severity
Get alerted the next time Plaid changes these terms. Follow Plaid →
Summary

This document describes how Plaid collects, uses, and shares your personal and financial data when you connect accounts through apps built on Plaid's platform. Plaid may use your data to build and train AI systems, and it shares your data with the app developer you are using and as that developer directs. Your data is deleted when the developer removes your connection—not when you request it—though certain exceptions allow Plaid to keep it even after that.

Analysis

This document establishes Plaid's data collection, use, sharing, and retention practices for end users of applications built on Plaid's platform. It authorizes Plaid to collect and process biometric facial geometry data for identity verification and to use end user data broadly to develop, train, test, and deploy AI systems, while imposing an absolute prohibition—covering both Plaid and its service providers—on using identity document information, photographs, video images, or derived facial geometry to enhance or develop services. Data deletion is triggered by developer action rather than user action and is subject to unspecified exceptions permitting retention; residents of Illinois or Texas are subject to a specific three-year retention cap on facial geometry data. Developers are bound by obligations including prohibitions on selling or renting end user data, export-sanctions compliance certifications covering affiliated entities, and liability to suspension or termination of access upon any policy violation.

What this means for you

As an end user, your personal and financial data is shared with the developer of the app you are using, and that developer directs further sharing, without this document specifying additional user consent for developer-directed sharing. Plaid may use your data to develop and train AI systems. If you live in Illinois or Texas, your facial geometry data is retained for no longer than three years. Because deletion is triggered by a developer removing your connection—not by a user request—users who want their data removed may need to contact the developer of the app through which they connected their accounts.

Institutional Analysis
Institutional analysis available with Insight

Which mapped governance frameworks each document engages, tied to the specific provisions that engage them.

4 important changes detected

4 versions captured · Last updated: April 2026

What changed Plaid updated its Developer Policy on April 21, 2026, making significant changes to how developers must manage account access and handle end user data. The policy now explicitly requires developers to designate 'Authorized Users' and maintain sole responsibility for their access to accounts and end user data. The updated terms also introduce new monitoring capabilities, clarify enforcement mechanisms, and expand the scope of what constitutes a policy violation.
Why this matters End consumers may see their financial data accessed by a broader range of people under developer accounts, but Plaid now requires developers to formally designate and manage these 'Authorized Users' and take responsibility for their conduct. The introduction of session replay and activity monitoring means developer interactions with your financial data may be recorded for audit or security purposes. The policy does not specify what data is covered by monitoring or how long recordings are retained, which creates operational uncertainty for developers handling sensitive consumer financial information.
View full change record →
What changed Plaid restructured its account terms to clarify the role of the Plaid Account and introduced a new Plaid Monitoring Service. The updated language shifts focus from helping you connect to third-party apps more quickly to emphasizing Plaid's direct provision of streamlined services and account monitoring. The terms now explicitly state that a Plaid Account enables Plaid to share information that third-party apps need to initiate payments to or from you, expanding the stated functional scope of the account beyond connection management.
Why this matters Plaid's updated terms establish a new direct relationship with you through the Plaid Account and introduce a monitoring service that operates through a web app. The terms now authorize Plaid to share financial information needed for third-party apps to initiate payments to or from you, which is a broader statement of data-sharing scope than the previous language. This means Plaid's role shifts from primarily facilitating connections to third-party apps toward directly providing account services, including monitoring. The effective date is April 14, 2026, though the change was detected on April 19, 2026. Review your Plaid Account settings to understand what data Plaid holds and how the monitoring service works.
View full change record →

April 16, 2026 low

Plaid restructured its account terms to emphasize a new direct-to-consumer Plaid Web-App monitoring service alongside its core financial account connection functionality. The updated language clarifies that a Plaid Account now …

View change record →
April 3, 2026 medium

Plaid's privacy policy was substantially revised on April 3, 2026, with 46 sentences added, 76 removed, and 149 modified. The updated terms shift focus from describing a 'Plaid Account' primarily …

View change record →
Featured, High severity
Featured, Medium severity
Featured, Low severity
Monitoring

Plaid has updated this document before. Monitor includes same-day alerts, structured change summaries, and monitoring for up to 20 platforms.

Governance Intelligence

Need provision-level monitoring and regulatory mapping? Insight includes governance timelines, drift analysis, and full provision tracking.

Mapped Governance Frameworks

CCPA/CPRA
California, USA
View official text ↗
Connecticut Data Privacy Act Amendments
US-CT
View official text ↗
CAN-SPAM
United States Federal
View official text ↗
FCRA
United States Federal
View official text ↗
FTC Act Section 5
United States Federal
View official text ↗
GDPR
European Union
View official text ↗
GLBA
United States Federal
View official text ↗
Indiana Consumer Data Protection Act
US-IN
View official text ↗
Kentucky Consumer Data Protection Act
US-KY
View official text ↗
Universal Opt-Out Mechanism Expansion 2026
US
View official text ↗
Archival ProvenanceSource & Archival Record
Last Captured April 21, 2026 06:13 UTC
Capture Method Automated scheduled archival capture
Document ID CA-D-000169
Version ID CA-V-001902
SHA-256 0a8d827572962cc5012319c796e08d8fb49190be40484061ff10c08cf6718f4b
✓ Snapshot stored ✓ Text extracted ✓ Change verified ✓ Hash verified

Governance Monitoring

Monitor governance changes across the platforms you rely on.

Structured alerts for policy changes, governance events, and provision updates across 352+ platforms.

Create free account Compare plans