Plaid, Stripe, and the financial data brokers nobody talks about.
Short answer
When you connect your bank account to Mint, Robinhood, Venmo, Cash App, or any crypto on-ramp, you almost certainly route the connection through Plaid. Plaid sees twenty-four months of your transactions, your balances, and the metadata of every payment. The data brokers everyone worries about pale next to the one almost every fintech app already uses.
How Plaid actually works
Plaid is a financial data aggregator. When a fintech app needs to read or write to your bank account, it does not connect directly. The app embeds Plaid’s Link widget, you enter your bank credentials into the widget, and Plaid uses those credentials to log into your bank as you. Plaid then reads the data the app needs and returns it. For some banks, Plaid uses an API connection that does not require your password; for many, it still does.
The model has worked because banks did not provide their own connectivity for years and Plaid filled the gap. Plaid now handles connectivity for the majority of consumer fintech in the United States: Venmo, Cash App, Robinhood, Coinbase, SoFi, Chime, Mint (before its shutdown), Acorns, Stash, and most of the rest. The same architecture, with different vendor names, runs in Europe (Tink, owned by Visa) and the UK (TrueLayer).
What Plaid sees and stores
Plaid’s documented data scope, when you authorize a typical fintech connection, includes the following.
Account balances at every connected institution, refreshed continuously. Transaction history, by default twenty-four months of past transactions and ongoing transactions thereafter. Account and routing numbers in plain form. Account holder name, address, phone, email as the bank has them on file. The category and merchant of each transaction (Plaid runs a categorization layer that infers Chipotle, Amazon, Spotify from the raw transaction descriptors).
Where Plaid uses screen-scraping (some banks still require it), Plaid also temporarily holds your bank login credentials. The 2022 FTC settlement required Plaid to stop the most aggressive forms of credential retention, but the architecture for credential-based access still exists for institutions that have not migrated to the API model. The framework around credential exposure is the same one we covered in what law enforcement can actually access from your accounts: third-party storage of credentials creates third-party exposure, regardless of contractual terms.
Where the data goes
Plaid’s terms allow data sharing in three categories. The first is the app you authorized: when you connected Cash App to your bank, Cash App receives the data scope you authorized. That is the user-visible part.
The second is Plaid’s own product use. Plaid uses aggregated transaction data to build categorization models, fraud-prevention products, and analytics services that are sold to third parties. The 2022 FTC settlement narrowed but did not eliminate this. Plaid’s current Privacy Policy still permits use of your data for product improvement and for unspecified affiliate purposes.
The third is the secondary fintech ecosystem. When a credit-scoring company, a fraud-prevention vendor, or a mortgage lender needs to verify income or assets, they often request the data through Plaid. The user has separately authorized this through whatever app prompted the verification. The user rarely understands that the same Plaid account is now feeding data to multiple downstream parties.
How to audit and revoke
Plaid runs a dashboard at my.plaid.com. Most users have never visited it. Most users have never logged in to it, because Plaid does not announce its existence at the time of the bank connection. The dashboard exists and it works.
Sign in at my.plaid.com using the email Plaid has on file (typically the same email you used to sign up for the fintech app that prompted the first connection). Plaid will send a verification code. Once in, you see every active connection: which app, which bank, which permissions. You can revoke any connection. Revoking through Plaid is more authoritative than revoking through the fintech app, because the fintech app may not actually purge the connection on its end.
Revoke connections you no longer use. For active connections, audit the permissions: many connections were authorized for a one-time verification (income verification for a loan application) but remain active afterwards, continuing to fetch transaction data you never asked them to fetch. This pattern of commercially monetized data flow that the user never explicitly authorized has a direct parallel on the telecom side, documented in our piece on how phone carriers sell real-time location data despite repeated FCC fines.
The same dashboard has a Data Disconnect option that closes the underlying Plaid record. After disconnect, Plaid retains its records of past activity for a period defined in their privacy policy, but the live data feed stops. The retention pattern is the same one we documented across the wider data broker ecosystem in why data brokers archive your profile rather than delete it: the visible feed stops, the underlying record does not.
Alternatives when an app requires bank linking
Three options, in increasing order of friction.
Use a separate account for fintech connections. A second checking account at the same bank, used only for the apps that require Plaid, limits the scope of data those apps see. The second account holds only the funds being moved through the apps. Your primary account stays unconnected. The trade-off is the operational overhead of maintaining two accounts.
Use manual ACH input where the app supports it. Many apps will accept routing and account numbers entered manually, without Plaid. The flow takes a few extra steps. Test transactions delay activation by a couple of days. The data exposure is dramatically smaller because the app never gets continuous read access to the account.
Choose apps that explicitly do not use Plaid. The list is shorter than it was five years ago, but it exists. Some banks (Capital One, Chase, certain Wells Fargo accounts) now offer their own native data-sharing API that does not route through Plaid. The principle is the same one we cover in operational identity separation between your fintech accounts and your primary banking: the email tied to your fintech should not be the email tied to anything else, and the account tied to your fintech should not be the account that holds your savings.
Frequently asked questions
Is Plaid covered by GDPR or CCPA?
Yes for CCPA, with limits for GDPR. CCPA gives California residents the right to access and delete data Plaid holds. GDPR rights apply to EU residents whose data Plaid processes (typically through Tink, Plaid’s European acquisition). The request flow is documented at plaid.com/legal. Expect a thirty-day response and partial fulfillment: deletion requests preserve some metadata for fraud-prevention purposes that the regulations explicitly carve out.
Does Plaid sell my data?
Plaid says no. The current privacy policy permits sharing for stated purposes (provision of the app you authorized, product improvement, fraud prevention, affiliate purposes), but does not include direct sale to third-party data brokers. The 2022 FTC settlement narrowed several categories that previously permitted broader use. The framing matters less than the practical result: data flows through Plaid to multiple downstream parties under contractual terms that look like sharing, regardless of the legal label.
If I disconnect through Plaid, will my fintech app break?
Sometimes. Apps that depend on continuous read access (Mint-style budget aggregators, automatic investment platforms) break immediately because they cannot fetch new data. Apps that use Plaid only for one-time verification (initial signup, occasional balance check) are unaffected by past disconnections. When in doubt, disconnect and let the app prompt you to reconnect if it needs to.
What about Yodlee, MX, Finicity, and other Plaid competitors?
Same architecture, different operator. Yodlee (owned by Envestnet) and Finicity (owned by Mastercard) have similar data flows and similar dashboards. MX is a smaller competitor with similar terms. The audit process is similar: find the dashboard, audit connections, revoke what you do not use. The exposure is structurally the same regardless of which aggregator the fintech app picked.
There’s no perfect setup. Anyone selling you perfect is selling fear. The goal is simple: make yourself a harder target than the person next to you.
