Plaid

Plaid is a financial-data aggregator founded in 2013, headquartered in San Francisco. Provides API access to bank-account data for fintech apps (Venmo, Robinhood, Coinbase, Chime, dozens more). Around 12,000 financial institutions integrated by 2026. The user signs into their bank through a Plaid-hosted screen, Plaid retains credentials and produces an API feed of transactions, balances, and account history that the requesting fintech consumes.

What it means in practice

The structural privacy story has two faces. Operationally, Plaid is what makes modern fintech work: connecting Venmo to your checking account, Robinhood to your funding source, the entire ecosystem of personal-finance and investment apps depend on the Plaid (or Yodlee, the older competitor) link. Privately, Plaid sits between every fintech app and your bank, with visibility into transactions across services. The 2022 FTC settlement ($58 million) addressed Plaid’s practice of retaining bank credentials longer than disclosed and using transaction data for purposes beyond the connecting fintech’s requested service. The Open Banking framework that Europe has adopted (PSD2 then PSR) constrains the data-aggregator role through regulatory oversight; the US equivalent (CFPB Open Banking rule, finalized 2024) is in implementation.

Who uses it, and against whom

Used by: most major US fintech apps (Venmo, Cash App, Robinhood, Coinbase, Chime, Wealthfront, M1, dozens more), bank-aggregator services that consolidate balances across accounts, lenders running income-verification through Plaid Income, and an emerging category of financial services using Plaid for fraud detection and identity verification. The data flow: the user authenticates to their bank through Plaid’s hosted screen, Plaid retains the credentials in encrypted form, Plaid pulls transaction data on the fintech’s schedule, the fintech consumes the data through Plaid’s API. The structural concern: Plaid sees more about your financial life than any single fintech does, and the data retention has been the subject of FTC enforcement.

What you can change today

Three actions. First, audit which apps you have connected through Plaid: log into Plaid Portal at my.plaid.com (Plaid added user-facing controls in 2023 under FTC pressure), see which institutions you have authorized and which fintechs are receiving the data feeds, revoke connections you no longer use. Second, prefer official bank apps over Plaid-mediated fintech where the bank app provides the same functionality; the data flow is one-hop rather than two-hop. Third, for new fintech signups, evaluate whether the Plaid connection is necessary or whether the app supports a manual transaction-import option; the manual path is friction but reduces the persistent data-share.

Related articles