Plaid sees your transaction history and account type, but not your password or Social Security number

When you connect your bank account to an app through Plaid, Plaid receives read-only access to information your bank already holds about you. This includes your account balance, recent transactions, account type (checking, savings, money market), and routing and account numbers. Plaid cannot see your login password, PIN, Social Security number, or any information stored outside your bank's system.

The scope of what Plaid sees depends on what the app you're connecting to actually needs. A budgeting app might request only transaction history and current balance. A loan process might request the same data plus account age and account type. Plaid acts as a middleman—it retrieves what the app asks for, then passes it along. You control which permissions you grant at the moment you connect.

Plaid does not store your bank login credentials. Instead, it uses a find token system: your bank issues a temporary key that lets Plaid read your account without ever handling your password. This is different from the old method, where apps asked you to type your bank password directly into their website—a practice that exposed credentials to unnecessary risk.

Key Takeaways

  • Plaid can see your account balance, transaction history, account type, and account numbers, but not your password or Social Security number.
  • The specific data Plaid retrieves depends on what permissions the app requests and what you approve during the connection process.
  • Plaid uses find token authentication rather than storing your bank password, which reduces the risk of credential theft.
  • You can revoke Plaid's access to your account at any time through your bank's settings or the app's account management page.
  • Different banks and different apps may have different data-sharing policies, so the exact information visible can vary.

How Plaid retrieves your data without storing your password

When you first connect through Plaid, you are redirected to your bank's login page—not Plaid's. You enter your credentials directly into your bank's website, which is encrypted and controlled by your bank. Plaid never sees your password typed on screen.

After you log in, your bank generates a temporary authorization token—a digital key that grants Plaid permission to read specific account information for a set time period. This token is what Plaid stores and uses to pull your data, not your password. The token can be revoked by you or your bank at any time, and it expires automatically after a period of inactivity.

This method is called OAuth or token-based authentication, and it is the same system used when you log into a website using your Google or Facebook account. Your Google password stays with Google; the website gets a token instead. If that website is hacked, your Google password is not compromised.

What data Plaid can access depends on the app's request

Plaid is a data conduit, not a data collector. It retrieves only what the app you are connecting to has asked for. A personal finance app like YNAB or Mint might request your last 90 days of transactions and your current balance. A lending platform might request the same plus your account age and whether the account is in good standing. A payroll app might request only your routing and account numbers.

During the connection process, you will see a permissions screen that lists what the app is requesting. This screen comes from Plaid and shows you exactly what data will be shared. You can review this before you approve the connection. If the request seems excessive—for example, if a straightforward budgeting app is asking for your Social Security number—you can decline and try a different connection method.

Some apps offer multiple connection routes. If Plaid's permissions don't match what you're comfortable sharing, you may be able to connect by uploading a bank statement PDF, entering your account numbers manually, or using your bank's own API connection if the bank offers one.

The difference between what Plaid can see and what it stores

Plaid retrieves your data on demand, usually in real time or near-real time when you open the app. It does not continuously monitor your account or store a permanent copy of your full transaction history. When you check your balance in a budgeting app, Plaid pulls the current balance from your bank at that moment.

However, the app itself—not Plaid—may store transaction data locally on your device or on its own servers. If you use a budgeting app, that app stores the transactions you've categorized and the notes you've added. Plaid is not responsible for how the app handles data after it receives it. You should review the app's privacy policy separately to understand what it keeps and for how long.

Plaid's own data retention policy allows it to keep transaction data for a limited time to improve its service, but it does not sell your transaction history to third parties. Plaid is paid by the apps you connect to, not by selling your data to advertisers or data brokers.

How to see what Plaid has access to and revoke it

You can view and manage Plaid's access through your bank's website or mobile app. Most banks list connected third-party apps under a section called "Connected Apps," "Authorized Apps," or "Third-Party Access." Look for Plaid in that list and select it to see which apps have connected through it.

To revoke Plaid's access, you can disconnect it from your bank's settings. This when ready invalidates the token Plaid holds, and the app will no longer be able to pull your data. You can also revoke access directly from the app itself—most apps have an account settings or "Connections" page where you can disconnect your bank.

If you disconnect Plaid from your bank but forget to disconnect it from the app, the app will show an error the next time it tries to refresh your data. You can then disconnect from the app's side. Either way works; the important step is breaking the connection so the token expires.

What Plaid cannot see, even if you grant permission

Plaid cannot see information that is not stored in your bank's system. This includes your Social Security number (unless your bank displays it in your account settings, which most do not), your credit score, your tax returns, your employment history, or any documents you have not uploaded to your bank's portal.

Plaid also cannot initiate transactions on your behalf. It has read-only access, meaning it can view your account but cannot move money, pay bills, or make purchases. If an app wants to move money from your account, it must use a separate authorization system (usually ACH or wire transfer permissions), and you must grant that permission separately and explicitly.

Plaid cannot see accounts at institutions that do not support Plaid connections. Some banks, credit unions, and investment firms have opted not to integrate with Plaid and instead offer their own connection methods or do not allow third-party access at all.

Why banks and apps use Plaid instead of direct connections

Plaid standardizes the connection process across thousands of financial institutions. Without Plaid, each app would need to build and maintain a separate integration with every bank—a costly and error-prone process. Plaid handles the technical work of connecting to each bank's system, translating different data formats, and keeping those connections working as banks update their systems.

For you, this means one login experience across multiple apps. You do not have to remember which apps you've given access to which banks, or manage separate tokens for each connection. Plaid centralizes this, and you can manage all your connected apps from one place.

Banks use Plaid because it reduces support burden. Instead of fielding questions about third-party app connections, banks can point users to Plaid's documentation. Plaid also handles security updates and compliance requirements, so banks do not have to audit every app that wants to connect.

Frequently Asked Questions

Can Plaid see my credit score or credit history?

No. Plaid can only see information stored in your bank's system—balances, transactions, and account details. Credit scores and credit reports are held by credit bureaus like Equifax, Experian, and TransUnion, not by your bank. If an app needs your credit information, it must connect to a credit bureau separately, not through Plaid.

If I disconnect an app, does Plaid still have my data?

Plaid retains transaction data for a limited period to maintain service quality, but it cannot share that data with the app once you disconnect. The app loses access when ready when you revoke the token. Plaid's own data retention follows its privacy policy, which you can review on Plaid's website.

Is it safer to connect through Plaid or to give an app my bank password directly?

Connecting through Plaid is safer. Your bank password never reaches the app or Plaid—you enter it directly into your bank's website. The app receives only a temporary token, which can be revoked without changing your password. If you give an app your actual bank password, that password is stored on the app's servers and could be exposed if the app is hacked.

Can Plaid see my savings account if I only connected my checking account?

No. Plaid can see only the accounts you explicitly authorized during the connection process. If you connected only your checking account, Plaid cannot access your savings account, money market account, or any other account at that bank unless you go back and add those accounts to the connection.

What happens if Plaid is hacked—can hackers see my bank account?

Plaid stores tokens, not passwords or full account numbers. A breach of Plaid would expose the tokens, which are temporary and can be revoked. Your bank password would not be exposed because Plaid never stores it. However, an attacker with a valid token could potentially access your account data until you revoke the token, which is why Plaid maintains security certifications and undergoes regular audits.