Data Retention Policy
Last updated: August 12, 2026
This page explains how long PointBagel keeps your data and what happens when you disconnect a card or delete your account. It is a companion to our Privacy Policy.
1. Account & Financial Data
PointBagel retains your account information, manually-entered card data, point balances, and Plaid-derived transaction history for the lifetime of your account. We keep this data because it powers the historical portfolio charts, redemption logs, and Trip Plans that make the product useful. A few categories carry shorter limits, including the raw imported transactions of a bank you disconnected by downgrading or canceling, which we keep only for about two years after disconnection (see Section 3).
2. Bank Authorization Lifecycle (CFPB §1033)
Your authorization to share data with us via Plaid is valid for up to 12 monthsfrom your most recent re-authorization, consistent with the CFPB's Section 1033 framework (the Personal Financial Data Rights Rule). When you disconnect a connection yourself, we hard-delete its derived data within 60 seconds (see Section 4). In the rare case a technical delay interrupts that step, the deletion completes automatically a short time afterward, and we monitor it until it does. Pseudonymized detection-learning records are governed separately: they are removed when you opt out at Privacy Choices or delete your account.
Here is how the re-authorization workflow works:
- About 30 days before your authorization expires, we email you and show an in-app banner with a one-click re-authorization button. We send a second urgent reminder one day before expiry.
- On the day your authorization expires, the connection moves to an “expired” status. New transaction syncing stops, but your existing transaction history, mappings, and derived data are preserved for a 30-day grace period. You can re-authorize at any point in the grace period and pick up exactly where you left off, no data lost.
- Halfway through the grace period (15 days after expiry), we send one more reminder email so you do not miss the window by accident.
- At the end of the grace period (30 days after expiry, ~395 days from your last re-authorization), if the connection is still actively authorized and you have not re-authorized it, we automatically revoke it and run the same hard-deletion described in Section 4: transaction history and linked-card records for that connection are permanently deleted within 60 seconds, or, in the rare case a technical delay interrupts that step, automatically a short time afterward under monitoring. Pseudonymized detection-learning records are governed separately: they are removed when you opt out at Privacy Choices or delete your account. This automatic expiry-deletion applies only to connections that lapse this way. A connection whose syncing you paused by downgrading or canceling your plan is handled differently: it is retained so you can resume, then subject to the longer disconnected-bank limit in Section 3.
- You can re-authorize at any time by clicking the banner on Settings → Connections, or directly from any of the reminder emails. You can also revoke access yourself at any point via Plaid at my.plaid.com (the Plaid Portal).
Your PointBagel account, manually-entered cards, point balances, optimization history, and subscription status remain untouched whether your bank link is active, expired, or revoked. One caveat about detail versus summary: after a connection is fully revoked, we permanently delete that bank's underlying imported transactions, but the value summary we already saved to your Lifetime Scorecard for those cards stays visible. You keep the scorecard number; only the transaction-level detail behind it is deleted. Pseudonymized detection-learning records are governed separately: they are removed when you opt out at Privacy Choices or delete your account.The one operational metadata we update on each of your portfolio cards during a Plaid revocation is a smooth-reconnect snapshot (the bank's identifier, the last 4 digits, and the snapshot timestamp) so that if you reconnect that bank later we can suggest the prior card mapping for one-click confirmation. See the “Smooth-Reconnect Mapping Memory” section of our Privacy Policy for the full picture. If you would prefer that we delete the account in full, you can do that yourself anytimefrom Settings → Delete account.
When your bank ends a connection
Sometimes your bank, not you, ends a data-sharing connection (for example, when it changes how it works with Plaid). When that happens we show you an in-app alert and a banner asking you to reconnect, and we keep the connection's data so you can reconnect without losing history. If the connection is not restored within about 30 days of the bank's scheduled end date, we treat the bank's action as the end of your authorization for that connection: we release the access token and permanently delete that connection's transaction history and linked-card records, the same way we do when you disconnect (Section 4). Pseudonymized detection-learning records are governed separately: they are removed when you opt out at Privacy Choices or delete your account. Your portfolio cards, point balances, Trip Plans, and account itself are not affected, and you can connect that bank again at any time as a fresh connection.
3. When You Downgrade or Cancel Your Plan
Downgrading to a lower tier or canceling your subscription does not immediately delete your data. Your transaction history, point balances, Lifetime Scorecards, and all derived data are preserved. A downgrade or cancellation is a billing change, not a request to erase your data. The one limit is on the raw imported transactions of a bank you disconnect this way, which we keep for about two years - see “How long we keep a disconnected bank's data” below.
What changes is syncing, not your data:
- Downgrading between paid tiers (for example, Pro to Plus): we untrack any cards beyond your new plan's limit, but they remain in your portfolio and your bank connections stay live. Re-upgrade to re-track them instantly.
- Downgrading to Free or canceling: for bank connections beyond the Free plan's limit, we stop syncing and release their Plaid access tokens (so we are no longer billed for connections you are not actively using), but we keep the data we already collected. If you re-subscribe and reconnect the bank through Plaid, syncing resumes where you left off and we rebuild as much history as that bank shares - the full picture for most, even near two years, though some banks share a shorter window. After a bank has been disconnected for about two years, we save its value summary into your Lifetime Scorecard and permanently delete its raw imported transactions - see “How long we keep a disconnected bank's data” below.
This is deliberately different from disconnecting a card (Section 4) or deleting your account (Section 5), both of which erase the underlying data.
If you would rather not keep a disconnected connection's history, you can permanently delete that one connection's imported transactions yourself at any time from the "Disconnected banks" list in your bank connections. Your cards, points, scorecards, and account are not affected, and you do not have to delete your whole account to do it.
How long we keep a disconnected bank's data
When you disconnect a bank by downgrading or canceling, we keep its imported transactions so you can reconnect and resume your history. We keep them for about two years. A reconnect rebuilds as much history as that bank shares: for most banks that is the full picture even near two years, though some banks share a shorter window (Capital One about 90 days, Bank of America about a year). Once a bank has been disconnected for about two years, even the longest-window banks can no longer stitch their older transactions into a gapless timeline, so at that point we save the bank's value summary into your Lifetime Scorecard, which we keep, and then permanently delete the bank's raw imported transactions. This applies only to banks disconnected by a downgrade or cancellation; it does not affect your Lifetime Scorecard, cards, points, or account. Before any deletion we email you a reminder, and a deletion never happens without that prior notice. You can reconnect before then to rebuild as much history as your bank still shares, or delete a disconnected bank's data yourself at any time.
4. When You Disconnect a Card
When you disconnect a connection in Settings → Connections, we release the access token at Plaid and permanently delete all transaction history and linked-card records associated with that connection within 60 seconds. In the rare case a technical delay interrupts the deletion, it completes automatically a short time afterward, and we monitor it until it does. Pseudonymized detection-learning records are governed separately: they are removed when you opt out at Privacy Choices or delete your account. The connection record itself is retained as a revocation marker. The access token is released at Plaid and then blanked. If Plaid is briefly unreachable we keep the token encrypted and retry automatically, and an alarm fires if release takes more than a day. Either way we have an audit trail of when access ended.
The same hard-deletion happens automatically when your bank or Plaid Link signals that you have revoked access (Plaid webhook codes USER_ACCOUNT_REVOKED and USER_PERMISSION_REVOKED).
5. When You Delete Your Account
When you delete your account in Settings → Delete account, we run a cascading delete that removes all data tied to your user record within 60 seconds: credit cards, point balances, Trip Plans, transactions, notifications, household memberships, subscription metadata, your Plaid connections (the bank access tokens are released at Plaid), saved sessions, sign-in tokens, and any connected AI assistants (every assistant connection and its access and refresh tokens are deleted).
If you had a paid subscription, we cancel it (it will not bill again) and delete your Stripe customer record, so your name and email no longer live at Stripe. Stripe retains records of past invoices and payments as required by financial and tax law.
A small number of records are kept afterward, in anonymized form. In every case your personal identifiers (name, email) are removed or replaced with [deleted]; what remains is non-identifying operational history with no way to tie it back to you:
- Admin audit and gift-grant records. If an admin acted on your account (a refund, a comped membership), the action is preserved with your name and email replaced by
[deleted], for tax and accountability records. An anonymous internal identifier is kept so the accountability record stays traceable. - Subscription tier history. One row per tier change (upgrade, downgrade, cancellation) is kept for revenue and churn analytics, with your email and any free-text cancellation note removed. Only an anonymous identifier, the tier names, dates, and dollar figures remain.
- Support messages. If you contacted us through the contact form, the message is preserved with your name, email, subject, body, and our reply replaced by
[deleted]; only the category and status survive. - Product-usage and affiliate-click events. Page views, feature interactions, and any card-application clicks are kept indefinitely in anonymized form. When you delete your account, the fields that could identify you (your user identifier, your session identifier, the snapshot of which cards you held, the referring web address, and the event details) are permanently removed from each event row. What remains is non-identifying operational data (the event type, the page, the timestamp, and coarse figures such as a former plan tier or card count) that cannot reasonably be linked back to you.
- Referral records that belong to other people. If someone referred you or sent you a gift membership, that record is theirs, not yours; we remove your email from it and they keep their own record.
- Referral rewards you earned. If you referred someone and earned a reward for it, that record is kept after you delete your account: what was owed, what was actually delivered, whether it was capped, held or reversed, and the dates. It stays because it is the only explanation of why a referral paid what it paid, and the person you referred keeps their side of the story either way. What remains is an anonymous identifier, the amounts, the dates, and internal reference codes: no name and no email address.
- Auto-renewal consent records. The date and exact wording of your agreement to subscription terms are kept after account deletion with your personal details removed. What survives, stated plainly: the terms text you agreed to, the price and billing interval, the dates, a one-way hashed form of the network address the agreement came from, and the processor references for the subscription. What does not: your name, your email address, and the browser details captured at the time. They exist so either side can establish what was agreed.
- Records of the payment cleanup we ran when you left. Deleting your account queues two jobs at our payments processor: cancel the subscription so it cannot bill again, and delete the customer record that held your name and email. We keep the entry that tracked those two jobs indefinitely, as our own proof that both finished and when. It holds an anonymous identifier, the processor reference codes for the subscription and the customer record, and the dates each step completed: no name, no email address, no card details, and no amounts.
- Security audit records. Whenever an administrator or an automated process reads or decrypts sensitive stored data, we write an audit entry: what kind of access it was, an anonymous identifier for whoever performed it, an anonymous identifier for whose data was involved, and the time. These entries are kept after account deletion so that, if we ever had to notify people about a security incident, we could still tell whose data was affected, including former users. They contain no name, no email address, no financial data, and no transaction contents.
- Records of a deletion we could not finish on time. If a request to delete a bank connection's data cannot be completed on the first attempt, we keep a short entry noting which connection and which request it was, when we first could not complete it, and when we finally did. The entry holds an anonymous identifier, dates, and internal reference codes: no name, no email address, no amounts, and none of your transaction data. It outlives account deletion on purpose, because it is the record of whether we kept a deletion promise, and that question is usually asked after the account is gone.
None of these contain your name, email address, or payment card details after deletion. Three of them do keep figures: the subscription tier history keeps the dollar amounts of your plan changes, the auto-renewal consent record keeps the price and billing interval you agreed to, and the referral-reward record keeps what was owed and what was delivered. Those are amounts, not payment details, and they are what makes each record worth keeping at all. The consent record also keeps a one-way hashed form of the network address the agreement came from, which cannot be turned back into an address and which corroborates that two agreements came from the same device. We maintain and use these de-identified records only in de-identified form and will not attempt to re-identify them, except to test that our de-identification works. (This pledge covers our de-identified records. Pseudonymized detection-learning records are a separate class that we can re-link in order to honor your data-export and deletion rights, as the Privacy Policy describes.)
6. Operational Logs & Transient Tokens
Four operational log tables (incoming webhook events, background-job runs, email-delivery events, and the email-deduplication log) are capped at 90 days. A daily cleanup job deletes any row older than 90 days from these tables. None of them contain payment card numbers, account credentials, or full transaction contents; they are operational telemetry only. Product-usage and affiliate-click analytics are not on this 90-day schedule; they are kept indefinitely in anonymized form, as described in Section 5.
One narrow exception to the 90-day cap: the delivery records for subscription auto-renewal notices (your purchase acknowledgment, the renewal reminders we are required to send, and any copy of your plan terms you ask us to email you from Settings), plus the receipts and reward notices that state money or an entitlement (your paid office-hours receipt, referral reward notifications, and gift-expiry warnings), are kept for at least 4 years. Those records are how we can show that a legally required notice or a statement about your money was sent to you, and consumer-protection claims can be brought for up to four years. We keep a little more than four years rather than exactly four, so the record still exists at the very end of that window. The record holds the message type, the date, and the address it went to, and it is what lets us avoid sending you the same notice twice. Two of those delivery records are kept longer still: your purchase acknowledgment, and the one-time restatement we send to subscribers who predate this system. Each is sent once for a whole subscription rather than once per billing period, so we keep them for as long as your subscription exists, and beyond- a four-year clock measured from the send would delete a long-running subscriber's day-one acknowledgment while the subscription it documents, and everything it commits us to, is still running. If you delete your account, the email address on those records is removed exactly as it is on every other record described here. Separately, a short ledger entry noting which notice was sent for which billing period, and on what date, is kept indefinitely. That entry carries no email address and no name, and it is what lets us show years later that a notice was given at all. There are six kinds of subscription notice, and the ledger covers all of them: your purchase acknowledgment, the pre-renewal reminder, the once-a-year reminder, the one-time restatement sent to subscribers who predate this system, the heads-up before a free period starts charging, and any copy of your terms you ask us to email you.
Partner link clicks: When you follow a link from PointBagel to a partner site, we log the click: which partner, the page you clicked it from, the points program in view if that page had one, your plan tier, the commission the link was worth at that moment, and the time. Your account identifier is attached unless you are signed out or have opted out of the sale and sharing of your information, and it is removed if you delete your account; the row holds no IP address, no browser details, and nothing about your portfolio, and it is deleted automatically after 400 days, which leaves a full year of month-over-month comparison plus a margin for reconciling a partner's own report of the traffic we sent them.
Anti-abuse security signals (the IP addresses of automated scrapers we detect) are retained for up to 365 days under a legitimate-interest basis, then automatically deleted. They are not tied to your account.
Portfolio-value history snapshots (the data behind your value-over-time chart) are kept at full resolution for 90 days, then consolidated to one snapshot per day, and deleted entirely after 24 months - the same window the chart itself displays. Consolidation never changes what the chart shows.
Transient authentication tokens are single-use and short-lived: email verification tokens expire after 24 hours; password reset tokens expire after 1 hour; two-factor authentication setup tokens expire after 10 minutes. Session tokens expire after 24 hours of inactivity; a trusted device you approve stays signed in for up to 30 days. Newsletter subscriber records are deleted immediately upon unsubscription. Plaid access tokens are encrypted at rest while a connection is active. On disconnect or revocation the token is released at Plaid and then blanked (overwritten with an empty string). If Plaid is briefly unreachable we keep the token encrypted and retry automatically, and an alarm fires if release takes more than a day. Connected AI assistant (MCP) credentials are stored only as one-way hashes, never as usable tokens: a short-lived access token expires about 30 minutes after it is issued, refresh tokens rotate on use, and the whole connection is deleted the moment you disconnect it in Settings, sign out of all devices, reset your password, or delete your account.
Mapping-click events: de-identified - retained up to 24 months for matcher-quality improvement, then auto-pruned by a weekly cleanup job. Before storage, the bank-supplied card name in each event is reduced to our public card-catalog vocabulary; words that are not recognized card products, issuers, or banking terms (including all digits, single letters, and text in other alphabets) are replaced with a placeholder. Personal text a bank might place in an account name is stored only to the extent its words coincide with that public vocabulary (some common first and last names are also retail or bank brand names); such words can remain, and in rare cases a name composed entirely of brand words (such as a name matching a store brand) can remain whole, always in a row with no user identifier. Because these rows have no user identifier attached, there is nothing tied to your account to delete on closure - they survive account deletion by design, and they are designed so they cannot reasonably be linked back to you: they contain no account, session, or device identifiers, and we commit to never attempting to re-identify them.
Detection-learning samples - 24 months, then reduced to token-free aggregate counts (see the Privacy Policy's Improving Automatic Credit Detection section).
7. Authorization & Revocation Records (CFPB § 1033)
Consistent with the CFPB's Section 1033 framework (the Personal Financial Data Rights Rule), we retain records of each authorization and revocation event for at least three years after the most recent authorization, so we can demonstrate compliance. These records contain only the user identifier, the timestamp of the authorization or revocation, and the institution connected. They do not contain transaction data, account numbers, credentials, or Plaid access tokens. Your authorization to share data with us is valid for up to 12 months; before it expires we will prompt you to re-authorize the connection.
If you delete your account, these authorization records are deleted with it, even if the three years have not run. We treat your deletion request as taking precedence over our own record-keeping.
8. Backups
Our database provider (Neon) maintains point-in-time backups for up to 7 days for disaster recovery. Deletions you make through the product propagate to these backups on the same 7-day rolling window.
9. We Do Not Sell or Share Your Individual Data
PointBagel does not sell, rent, or share your individual personal data with third parties for their own marketing or analytics. This includes your transactions, card portfolio, point balances, email, and account activity. Those never leave our infrastructure for outside use.
We may use, publish, or sell aggregated, anonymized statistics that cannot identify any individual user. For example, we might publish or license a figure like “the average PointBagel user holds 4.2 credit cards” or “Chase cards represent 38% of tracked cards on the platform.” Aggregate statistics like these are built from data that has been stripped of identifying information and cannot be reverse-engineered back to any individual user. This does not include any individual's data, and it never includes your bank-transaction data.
The third-party services listed in our Privacy Policy (Plaid, Stripe, Resend, and others) act as data processors on our behalf. They are bound by written agreements with us and by their own privacy commitments, and they use your data only to deliver the specific service we hired them for.
10. Your Rights
You can disconnect a card, delete your account, or request a copy of your data at any time from Settings. For other privacy requests, including requests under CCPA, GDPR, or similar regulations, email [email protected].
