Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The policy describes Plaid Portal (available at my.plaid.com) as a centralized dashboard for US users to view financial account connections made through Plaid, review the types of data shared with each app, terminate specific app connections, and request deletion of associated data. Access requires phone number and email verification.
This analysis describes what Plaid's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision identifies a specific operational mechanism through which US users can view, manage, and terminate data connections and request data deletion, which is directly relevant to the practical exercise of data rights disclosed elsewhere in the policy. The availability of this tool is limited to US-based users as stated in the policy.
End consumers may see their financial data accessed by a broader range of people under developer accounts, but Plaid now requires developers to formally designate and manage these 'Authorized Users' and take responsibility for their conduct. The introduction of session replay and activity monitoring means developer interactions with your financial data may be recorded for audit or security purposes. The policy does not specify what data is covered by monitoring or how long recordings are retained, which creates operational uncertainty for developers handling sensitive consumer financial information.
View change record →Plaid's updated terms establish a new direct relationship with you through the Plaid Account and introduce a monitoring service that operates through a web app. The terms now authorize Plaid to share financial information needed for third-party apps to initiate payments to or from you, which is a broader statement of data-sharing scope than the previous language. This means Plaid's role shifts from primarily facilitating connections to third-party apps toward directly providing account services, including monitoring. The effective date is April 14, 2026, though the change was detected on April 19, 2026. Review your Plaid Account settings to understand what data Plaid holds and how the monitoring service works.
View change record →The updated terms clarify that Plaid may request and collect phone numbers, email addresses, and other contact information when you connect financial accounts or verify your identity through a Plaid-connected application. The terms no longer describe a separate Plaid Monitoring Service or Plaid Web-App. The Plaid Account is now framed primarily as a tool to accelerate onboarding and use of third-party applications rather than as a standalone service for monitoring and alerts. The updated language authorizes Plaid to store identity verification data within your Plaid Account if you choose to do so.
View change record →Under these terms, US users can access Plaid Portal at my.plaid.com to view all financial app connections made through Plaid, review what data categories are shared with each app, terminate specific connections, and request deletion of associated data stored in Plaid's systems. The portal requires phone number and email verification to access.
Cross-platform context
See how other platforms handle Plaid Portal User Control Mechanism and similar clauses.
Compare across platforms →Monitoring
Plaid has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.
"Plaid developed the Plaid Portal to provide you with a convenient, centralized way to view and manage the connections you've made using Plaid. If you're located in the U.S., you can sign up for Plaid Portal by visiting my.plaid.com, verifying your phone number and email address, and creating a password. Once you've signed up for Plaid Portal, you'll be directed to a dashboard that can show you financial accounts you've connected to your chosen apps using Plaid, and the types of data shared with those apps. Additionally, the Plaid Portal provides you with controls to terminate the connection between apps and your financial accounts and delete associated data stored in Plaid's systems.Excerpt from Plaid's End User Privacy Policy [SPA-QUARANTINE: needs human capture]
1. REGULATORY LANDSCAPE: This provision is operationally relevant to CCPA's requirement that businesses provide at least two methods for consumers to submit data rights requests, and to GDPR's requirement that data subject rights be exercisable through accessible mechanisms. The portal's functionality as a data control interface may also be evaluated against CFPB open banking rulemaking requirements regarding consumer-facing data access and revocation tools. 2. GOVERNANCE EXPOSURE: Low. The Plaid Portal is a voluntary consumer-facing tool that supports compliance with data rights obligations by providing a documented, accessible mechanism for connection management and deletion requests. The limitation of the portal to US users (as stated in the policy) means EEA and UK users must exercise rights through other mechanisms described in the policy. 3. JURISDICTION FLAGS: The policy states that Plaid Portal is available to US-located users only; EEA and UK users must submit data rights requests via the online form or email, which may create a procedural distinction in the accessibility of data management tools. Compliance teams should confirm that EEA and UK user-facing mechanisms are equivalently accessible and documented. 4. CONTRACT AND VENDOR IMPLICATIONS: Organizations deploying Plaid should inform their end users of the availability of Plaid Portal as a mechanism for managing data connections, as the portal may be the most direct path for users to revoke developer access to their financial data. Developer agreements with Plaid should specify how connection terminations initiated through Plaid Portal affect the developer's access and downstream data handling obligations. 5. COMPLIANCE CONSIDERATIONS: The portal's functionality to terminate connections and request deletion should be tested to confirm that it triggers Plaid's automated deletion workflows as described in the retention and deletion section of the policy. Compliance teams should document the portal as part of their consumer data rights fulfillment infrastructure for CCPA and other applicable state privacy law compliance.
Regulatory citations, enforcement risk, and due diligence action items.
Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.
This provision identifies a specific operational mechanism through which US users can view, manage, and terminate data connections and request data deletion, which is directly relevant to the practical exercise of data rights disclosed elsewhere in the policy. The availability of this tool is limited to US-based users as stated in the policy.
Under these terms, US users can access Plaid Portal at my.plaid.com to view all financial app connections made through Plaid, review what data categories are shared with each app, terminate specific connections, and request deletion of associated data stored in Plaid's systems. The portal requires phone number and email verification to access.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Plaid.