7 Total
3 High severity
3 Medium severity
1 Low severity
Summary

The Plaid End User Privacy Policy describes how Plaid collects, retains, and uses financial data including bank account information, transaction history, and login credentials when users connect their bank accounts to third-party applications through Plaid's infrastructure. The policy establishes that Plaid retains financial transaction data for use in network analytics and product improvement purposes independently of the original third-party application connection. Users may access and request deletion of their financial data through Plaid's data portal at my.plaid.com.

Technical / Legal Breakdown

This document governs Plaid's collection, use, storage, and sharing of personal and financial data through its data network and API infrastructure, operating under a stated basis of user consent obtained through partner application flows and Plaid's own Link product. The policy states that Plaid collects financial account data (including account numbers, balances, transaction history, and credentials in some flows), identity information, and device/usage data, and the terms authorize sharing this data with financial institution partners, developers building on Plaid's platform, and third-party service providers. Notably, Plaid's data collection model is operationally distinct from many consumer-facing privacy policies in that the end user typically interacts with Plaid through a third-party application rather than directly, creating a layered consent structure where users may not be fully aware of Plaid's role as a data intermediary; the policy asserts broad rights to retain and use transaction data for product improvement and network-level analytics, which the agreement states is done in de-identified or aggregated form, though the scope of re-identification risk under applicable standards warrants evaluation. The policy engages CCPA and CPRA for California residents, GLBA for financial data contexts, and GDPR and UK GDPR for European and UK users respectively, with the FTC and CFPB representing the primary federal enforcement authorities given Plaid's role in financial data intermediation. Compliance teams should note that Plaid entered a 2021 FTC consent order resolving allegations about data collection and use practices, which creates a regulatory baseline against which current policy language should be evaluated, particularly regarding the scope of credential collection and data use for purposes beyond the user's stated transaction.

Institutional Analysis

Institutional analysis available with Professional

Regulatory exposure by statute, material risk assessment, vendor due diligence action items, and enforcement precedent. Available on Professional.

Start Professional free trial

4 important changes detected

4 versions captured · Last updated: April 2026

What changed Plaid updated its Developer Policy on April 21, 2026, making significant changes to how developers must manage account access and handle end user data. The policy now explicitly requires developers to designate 'Authorized Users' and maintain sole responsibility for their access to accounts and end user data. The updated terms also introduce new monitoring capabilities, clarify enforcement mechanisms, and expand the scope of what constitutes a policy violation.
Why this matters End consumers may see their financial data accessed by a broader range of people under developer accounts, but Plaid now requires developers to formally designate and manage these 'Authorized Users' and take responsibility for their conduct. The introduction of session replay and activity monitoring means developer interactions with your financial data may be recorded for audit or security purposes. The policy does not specify what data is covered by monitoring or how long recordings are retained, which creates operational uncertainty for developers handling sensitive consumer financial information.
View full change record →
What changed Plaid restructured its account terms to clarify the role of the Plaid Account and introduced a new Plaid Monitoring Service. The updated language shifts focus from helping you connect to third-party apps more quickly to emphasizing Plaid's direct provision of streamlined services and account monitoring. The terms now explicitly state that a Plaid Account enables Plaid to share information that third-party apps need to initiate payments to or from you, expanding the stated functional scope of the account beyond connection management.
Why this matters Plaid's updated terms establish a new direct relationship with you through the Plaid Account and introduce a monitoring service that operates through a web app. The terms now authorize Plaid to share financial information needed for third-party apps to initiate payments to or from you, which is a broader statement of data-sharing scope than the previous language. This means Plaid's role shifts from primarily facilitating connections to third-party apps toward directly providing account services, including monitoring. The effective date is April 14, 2026, though the change was detected on April 19, 2026. Review your Plaid Account settings to understand what data Plaid holds and how the monitoring service works.
View full change record →

April 16, 2026 low

Plaid restructured its account terms to emphasize a new direct-to-consumer Plaid Web-App monitoring service alongside its core financial account connection functionality. The updated language clarifies that a Plaid Account now …

View change record →
April 3, 2026 medium

Plaid's privacy policy was substantially revised on April 3, 2026, with 46 sentences added, 76 removed, and 149 modified. The updated terms shift focus from describing a 'Plaid Account' primarily …

View change record →
High — 3 provisions
Medium — 3 provisions
Low — 1 provision

Monitoring

Plaid has updated this document before.

Watcher includes same-day alerts, structured change summaries, and monitoring for up to 10 platforms.

Start Watcher free trial Or create a free account →

Professional Governance Intelligence

Need provision-level monitoring and regulatory mapping?

Professional includes governance timelines, compliance memos, audit-ready analysis, and full provision tracking.

Start Professional free trial

Cross-platform context

See how other platforms handle Data Retention and Secondary Use for Network Analytics and similar clauses.

Compare across platforms →

Mapped Governance Frameworks

CCPA/CPRA
California, USA
View official text ↗
Connecticut Data Privacy Act Amendments
US-CT
View official text ↗
CAN-SPAM
United States Federal
View official text ↗
ePrivacy Directive
European Union
View official text ↗
FCRA
United States Federal
View official text ↗
FTC Act Section 5
United States Federal
View official text ↗
GDPR
European Union
View official text ↗
GLBA
United States Federal
View official text ↗
Indiana Consumer Data Protection Act
US-IN
View official text ↗
Kentucky Consumer Data Protection Act
US-KY
View official text ↗
Universal Opt-Out Mechanism Expansion 2026
US
View official text ↗
Archival ProvenanceSource & Archival Record
Last Captured April 21, 2026 06:13 UTC
Capture Method Automated scheduled archival capture
Document ID CA-D-000169
Version ID CA-V-001902
SHA-256 0a8d827572962cc5012319c796e08d8fb49190be40484061ff10c08cf6718f4b
✓ Snapshot stored ✓ Text extracted ✓ Change verified ✓ Hash verified

Governance Monitoring

Monitor governance changes across the platforms you rely on.

Structured alerts for policy changes, governance events, and provision updates across 318+ platforms.

Create free account Compare plans