Is It Safe to Connect Your Bank to a Credit Card App? (2026)
What Plaid actually does, what read-only access can and cannot see, what we do with the data at OfferBee, and the honest reasons some people should decline.
We make OfferBee, a credit card credit tracker that offers a Plaid connection, so we have an obvious interest in you saying yes. We have tried to write this so it is useful even if you say no, including a section on the apps that need no bank connection at all. Everything about our own handling below is drawn from our code and our published retention policy, checked 2026-09-08.
The short version, before the detail:
- Your bank password does not reach the app. It goes to your bank or to Plaid, and the app receives a token.
- A read-only transactions connection cannot move money. That is a different Plaid product with a different authorization.
- What it can see is real and worth taking seriously: where you shop, what you paid, when. That is the whole privacy question, and "read-only" does not make it small.
- Some people should decline, and there are good apps for them.
What Plaid is, and what happens when you tap Connect
Plaid sits between your bank and the app. Almost every US consumer finance app that reads transactions uses it, because maintaining connections to thousands of institutions is not something a small app can do.
Plaid's own description of the flow is three steps: you verify ownership of the account with your username and password, Plaid retrieves the account information you permitted from your institution, and Plaid shares that data with the app you chose. Data is protected in transit and at rest with AES-256 and TLS.
The part worth understanding is where you type your password. Many large US banks now hand you off to their own login page; you leave the app's sheet, land on your bank's site, authenticate there, and approve the connection on the bank's own screen. At institutions that have not built that handoff, you type your credentials into Plaid's form instead.
You can tell which one you got, and it takes two seconds: look at whether the login screen is your bank's real page or Plaid's. Either way, the app on the other side never receives your password. It receives an access token scoped to what you approved.
"Read-only" is a specific claim, not a reassurance
This phrase gets used loosely, so here is what it means concretely.
Plaid's capabilities are split into products, and an app requests the ones it needs when
it creates the connection. transactions reads history. auth returns account and routing
numbers. The transfer and payment products move money and require their own authorization.
They are separate grants; requesting one does not get you the others.
OfferBee's connection requests exactly one product: transactions. Not auth, not
identity, not any payment product. So there is no mechanism by which the connection we
hold could initiate a payment. This is not "we choose not to", but "the grant does not
include it."
You do not have to take our word for that shape. You can see and revoke every connection you have ever made through Plaid at my.plaid.com, including the data types each app receives. It is worth visiting once whether or not you use us.
What the app can actually see
With a transactions connection, and for the accounts you selected in Link:
| Visible | Not visible |
|---|---|
| Account name, type/subtype, last four digits | Full card or account number |
| Transaction merchant name and raw statement line | Your bank username or password |
| Amount, date, pending status | Your PIN or card security code |
| Plaid's spending category for each transaction | Anything on accounts you did not select |
| Up to two years of history | Any ability to move money |
That left column is the honest cost. A list of merchants, amounts and dates is a detailed picture of your life: where you eat, where you travel, what you subscribe to, which pharmacy you use. No amount of "it's read-only" changes that, and an app that brushes past it is not being straight with you.
The reason a credit tracker wants it is narrow but real: there is no other way to know a credit was used. Your issuer does not publish a "credit consumed" feed. The only signal that your $15 Uber Cash was spent is the transaction itself. Apps that take no bank connection cannot tell you, not because they are worse engineered, but because they deliberately gave up that signal.
What OfferBee does with it
We store transactions for the accounts you connected, match them against the credits you track, and mark a credit used when a charge that satisfies it posts. The same data powers the fee-vs-value verdict at renewal and the spending questions you can ask Bee.
Three things about how it is held.
Merchant text is encrypted at rest. The three fields that carry the privacy payload (the merchant name, the transaction name, and the raw statement line) are encrypted with AES-256-GCM before they are written. Amounts, dates and categories are not: they key the indexes the app queries on, and a low-cardinality category enum does not survive frequency analysis anyway, so encrypting them would cost a query and buy nothing.
What that encryption does not cover, stated plainly. The key lives in the same deployment as the data, because our database platform has no separate key service. It defends against the realistic leaks: someone browsing the data table during routine operations, an export, a log line, a raw storage compromise. It is not a defence against an operator with dashboard access. Better to say that than let "encrypted at rest" imply more than it does.
Merchant names still leave in copies, deliberately. A push notification reading "a $12.50 charge at Blue Bottle looks like your dining credit" carries the merchant name through Apple's and Google's push services, and Bee's answers quote merchants into the assistant transcript. Both were accepted as the price of those features working at all. If that trade is not one you want, those are the surfaces to think about, not the database.
The one place your transactions leave our servers
Some transactions are ambiguous: a refund with no merchant name, a statement line that could be two different credits. Those go to a language model for classification, and that is the only path by which your merchant text reaches a third party. The boundary is deliberately narrow:
- Rows are identified by their position in the request, never by a Plaid transaction id, so the request cannot be joined back to your account by whoever receives it.
- The raw statement line is included only when it carries signal, on a credit posting, or where the bank gave no merchant name at all. On an ordinary purchase the merchant name is enough, so the raw line is pure exposure and is left out.
- Routing is pinned to zero-retention providers. If no compliant provider is available, the request fails and those transactions stay unclassified until the next sync. We do not retry without the pin.
You can use it with no bank connection at all
This is the part most comparison articles skip. Adding cards by name and tracking credits by hand works without connecting anything. You can log a credit used, clear a period, backfill a month you forgot, get reminded before a reset.
What you give up is exactly one thing, and it is the thing: the app no longer notices. You have to tell it. That is the same deal every no-bank-connection app in this category offers, and for some people it is the right one.
On price, since it shapes the trade: a 14-day trial with no card required, then $9.99/mo or $80/yr at offerbee.ai ($12.99/mo or $104.99/yr through the App Store; the app shows both and marks the cheaper). After the trial, manual credit tracking on cards already in your wallet stays free; adding a new card needs Pro.
How to disconnect, and what actually happens
In the app, Connected accounts → the bank → Disconnect. That does three things:
- Calls Plaid's
/item/removeto revoke the access token, so no further data can be pulled. - Deletes the stored connection, its accounts, and every transaction we pulled from it, in batches, with the connection staying visible until the last row is gone.
- Unwinds anything that was auto-logged from those transactions, so your credit history does not keep claims backed by data that no longer exists.
Our published policy commits to removing tokens and item identifiers within 7 days in all cases, and account and transaction data within 30 days of disconnection or account closure. Deleting your whole account runs the same Plaid removal plus a cascade across every table that holds your data. Separately, and not dependent on us, you can revoke from Plaid's side at my.plaid.com.
The honest case for declining
We would rather you read this section than skip it.
You are adding a party. Before, your transaction history lived at your bank. Now a copy lives at Plaid and a copy lives with the app, each a company with its own security posture, its own employees, and its own future, including the possibility of being acquired by someone whose priorities differ. Aggregated financial data is a high-value target precisely because it is aggregated. That is a structural risk, not a hypothetical one.
Read Plaid's own policy, not just its safety page. Plaid's End User Privacy Policy describes collecting identifiers, financial data, commercial data, location data and network activity data across its products, and states that while it does not sell personal information, it may share information with third parties for advertising purposes using cookies. That is more surface than "connector" implies.
The rules are still being written. Section 1033 of Dodd-Frank governs your right to your own financial data and who may act on your behalf. The CFPB issued an advance notice of proposed rulemaking in August 2025 reopening several core questions, including the data security and privacy pictures for 1033 compliance. Anyone telling you this area is settled is not reading the docket.
And you may simply not want it. "I don't hand out access to my transaction history for a $200 credit" is a coherent position, not a failure to understand the technology.
If you're declining, these two need no connection
Both were checked on 2026-09-08:
- CardPointers: adds issuer offers across Amex, Chase, Bank of America, Citi, Wells Fargo and US Bank without your logins or purchase history, and does best-card recommendations. $90/yr for CardPointers+; the free tier is limited to one card of each type. It cannot confirm a credit was used, and it does not claim to.
- Pointer AI: cards are added by name, no bank connection of any kind, with the most generous free tier in the category as of today: unlimited cards, a full perks tracker, weekly store searches. iOS only. Same ceiling on credit confirmation.
Both are good products. If your line is "no bank access", they are the answer and nothing on the rest of this page changes that.
Five questions to ask any app before you connect
- Which Plaid products does it request? Transactions only, or also auth or payments? The Link screen tells you what data types are shared.
- What does it do with the data besides the feature you want? Look for third-party sharing and advertising language, not for the word "encrypted."
- Does anything leave for AI processing, and on what terms? Retention by the model provider is the question, not whether AI is used.
- What exactly is deleted on disconnect, and how fast? A named endpoint and a named number, or it is marketing.
- Does the app work at all without connecting? If not, you are betting the whole subscription on one decision.
If an app cannot answer those in writing, that is the answer.
Plaid's practices verified 2026-09-08 against plaid.com/safety, plaid.com/how-we-handle-data and Plaid's End User Privacy Policy; CardPointers and Pointer AI against their live sites the same day. Our own handling reflects OfferBee's code and published Data Retention & Disposal Policy as of that date. Re-checked quarterly; if the date above is stale, verify before relying on it.
SOURCES
- 01Plaid: What is Plaid, and is it safe?
- 02Plaid: How we handle your financial data
- 03Plaid: End User Privacy Policy
- 04Plaid Portal: manage and revoke connections
- 05CFPB: Required Rulemaking on Personal Financial Data Rights (section 1033)
- 06CardPointers: adds offers without logins or purchase history
- 07Pointer AI: cards added by name, no bank connection
- 08OfferBee: Data Retention & Disposal Policy
Stop losing credits you already paid for.
OfferBee reads your card transactions, marks a statement credit used when the charge posts, and reminds you before it resets. 14 days free, no card required.