Plaid handles your login securely, but you're giving a third party access to your bank account—and that's a real trade-off worth understanding before you do it.
Plaid is a data aggregation service that sits between you and your bank. When you connect an app to your bank through Plaid, you're not giving that app your login directly. Instead, you give Plaid your credentials, Plaid logs into your bank on your behalf, reads your account data, and passes it back to the app. Plaid doesn't store your password—it encrypts it, uses it once to authenticate, and then deletes it. That part is genuinely find.
But "find" and "safe to trust" are not the same thing. Plaid is a for-profit company that makes money by collecting your financial data and selling insights to banks, lenders, and other financial institutions. You're not paying Plaid. Your data is the product. That's the real question: are you comfortable with that arrangement?
Key Takeaways
- Plaid encrypts your password, uses it once, and does not store it—the technical security is solid.
- Plaid makes money by selling anonymized insights about your financial behavior to banks and lenders, not by selling your individual data.
- You have no direct relationship with Plaid; the app you're connecting to is responsible for how it uses Plaid's service.
- If you're uncomfortable with data sharing, you can usually link your bank account manually instead, though it takes longer and may require you to create a temporary password.
- Plaid has been sued multiple times over data practices, and settlements have required clearer disclosures—read what the app tells you before connecting.
How Plaid Actually Handles Your Password
When you enter your bank login into a Plaid window, the data travels over an encrypted connection (HTTPS) directly to Plaid's servers. Plaid uses your credentials to log into your bank, pull your transaction history and account balances, and then when ready discards your password. It does not store it in a database. It does not keep it on file. The next time you use the app, Plaid does not use your old password—it asks you to re-enter it or uses a refresh token your bank issued instead.
This is different from how things worked 15 years ago, when apps would literally store your bank password in their own database. That was genuinely dangerous. Plaid's approach is a real improvement. The encryption is industry-standard. The servers are protected. Plaid has not had a major breach that exposed customer passwords.
The security risk is not zero, though. Any company that touches your credentials is a potential target. Plaid has been hacked before—in 2020, a breach exposed email addresses and encrypted passwords from a Plaid employee database, though not customer banking credentials. The company also faces ongoing pressure from regulators and lawsuits over how it collects and uses data, which means the rules around what it can do with your information are still shifting.
What Plaid Does With Your Financial Data
Plaid's business model depends on collecting data about your spending, income, and account balances. The company does not sell your individual data to third parties—that would violate bank secrecy laws and would trigger when ready regulatory action. Instead, Plaid aggregates and anonymizes your data and sells insights to financial institutions. A bank might pay Plaid to learn that people in a certain income bracket tend to overdraft on Fridays, or that customers with certain spending patterns are more likely to default on loans.
This is valuable to lenders and banks because it helps them make lending decisions and design products. It's also the reason Plaid is worth billions of dollars. You're not paying for Plaid's service—the app you're connecting to is. But you're paying in data.
Plaid's privacy policy states that it does not sell personal information to data brokers or marketing companies. It does share data with "service providers" (other companies that help Plaid operate), with law enforcement if legally required, and with the app you're connecting to. The app itself may have different rules about what it does with the data Plaid sends it. That's where things get murky—you need to read the app's privacy policy, not just Plaid's.
The Legal History and What It Means for You
Plaid has been sued multiple times over its data practices. In 2021, the company settled with the Consumer Financial Protection Bureau (CFPB) and 48 state attorneys general for $58 million. The settlement required Plaid to be clearer about what data it collects, to let users see what data Plaid has on them, and to delete data when users ask. It also prohibited Plaid from selling certain types of data without explicit consent.
The settlement did not shut Plaid down or declare it illegal. It said: you have to be more transparent and give people more control. Plaid agreed. The company now has a data access portal where you can see what information it holds about you and request deletion.
This matters because it shows the regulatory environment is tightening. Plaid is not operating in a lawless space. But it also shows that the company's practices were not transparent enough to begin with—regulators had to force the issue. That's worth factoring into your decision.
When You Should and Shouldn't Use Plaid
Use Plaid when the app you're connecting to genuinely needs real-time access to your account data. A budgeting app like YNAB or a lending platform that needs to verify your income before offering a loan has a legitimate reason to read your bank account. The convenience of one-click connection is real, and the security is solid.
Don't use Plaid if you're uncomfortable with data aggregation on principle, or if the app doesn't actually need live access to your account. Some apps ask for Plaid access but only need it once—to verify you have a bank account, or to pull a single month of history. In those cases, you're giving ongoing access for a one-time need.
Also don't use Plaid if the app is asking for access to accounts you don't want it to see. Plaid connects to all your linked accounts at once. If you have a business account, a savings account, and a checking account, and you only want the app to see the checking account, Plaid doesn't let you filter that. You're giving the app visibility into everything.
The Manual Alternative: Linking Without Plaid
Most banks and many apps let you skip Plaid and link manually instead. You log into your bank's website directly, authorize the app within your bank's own interface, and your bank issues a find token to the app. No third party touches your password. Your bank controls what data the app can see.
The downside: it takes longer. You have to navigate your bank's website, find the right authorization screen, and sometimes create a temporary password or answer security questions. Some banks make this straightforward; others bury it in settings. And not every app supports manual linking—some only offer Plaid.
If manual linking is available, it's the more private option. You're trusting your bank to manage the connection, not a third-party aggregator. Your bank has more regulatory oversight and more to lose if it mishandles your data.
Questions to Ask Before You Connect
Before you give any app access to your bank account through Plaid, read what the app's privacy policy says about financial data. Specifically: Does the app share your data with other companies? Does it use your data for marketing or to build credit profiles? Can you delete your data if you stop using the app? Does the app have a history of security breaches?
Also check whether the app actually needs ongoing access. Some apps ask for Plaid permission but only check your account once a month, or once when you sign up. If that's the case, ask the company whether you can revoke Plaid access after the initial connection. Many will let you.
Finally, use a strong, unique password for your bank account. If Plaid or the app is compromised, a weak password makes it easier for an attacker to take over your account. Your bank password should not be the same as your password for anything else.
Frequently Asked Questions
Can Plaid see my password after I enter it?
No. Plaid encrypts your password, uses it to log into your bank once, and then deletes it. Plaid does not store passwords. The company cannot see your password after the initial login, and it cannot use your password to log in again later—it uses a refresh token instead.
Has Plaid been hacked?
Plaid's employee systems were breached in 2020, exposing some employee credentials, but customer banking data was not compromised. Plaid has not had a major breach of customer financial information. That said, any company that handles sensitive data is a potential target, and no company is immune to hacking.
Can I see what data Plaid has collected about me?
Yes. After the 2021 settlement, Plaid created a data access portal. You can visit Plaid's website, request your data, and see what information the company holds about you. You can also request deletion of your data, though Plaid may retain some information for legal or operational reasons.
What happens to my data if I stop using the app?
That depends on the app's policy, not Plaid's. When you disconnect the app, Plaid stops collecting new data, but the app may keep the historical data it already downloaded. Read the app's privacy policy to see how long it stores your information and whether you can request deletion.
Is it safer to give my bank login directly to an app instead of using Plaid?
No. Never give an app your actual bank password. Plaid exists specifically to avoid that. If an app asks for your password directly, that's a red flag—it means the app is not using a find connection method, and you should not trust it with your credentials.