Data Retention Policy

Last updated: July 6, 2026

This page explains how long PointBagel keeps your data and what happens when you disconnect a card or delete your account. It is a companion to our Privacy Policy.

1. Account & Financial Data

PointBagel retains your account information, manually-entered card data, point balances, and Plaid-derived transaction history for the lifetime of your account. We keep this data because it powers the historical portfolio charts, redemption logs, and Trip Plans that make the product useful. A few categories carry shorter limits, including the raw imported transactions of a bank you disconnected by downgrading or canceling, which we keep only for about two years after disconnection (see Section 3).

2. Bank Authorization Lifecycle (CFPB §1033)

Your authorization to share data with us via Plaid is valid for up to 12 months from your most recent re-authorization, per CFPB Section 1033 (Personal Financial Data Rights Rule). When you disconnect a connection yourself, we hard-delete its derived data within 60 seconds (see Section 4). In the rare case a technical delay interrupts that step, the deletion completes automatically a short time afterward, and we monitor it until it does.

Here is how the re-authorization workflow works:

  1. About 30 days before your authorization expires, we email you and show an in-app banner with a one-click re-authorization button. We send a second urgent reminder one day before expiry.
  2. On the day your authorization expires, the connection moves to an “expired” status. New transaction syncing stops, but your existing transaction history, mappings, and derived data are preserved for a 30-day grace period. You can re-authorize at any point in the grace period and pick up exactly where you left off, no data lost.
  3. Halfway through the grace period (15 days after expiry), we send one more reminder email so you do not miss the window by accident.
  4. At the end of the grace period (30 days after expiry, ~395 days from your last re-authorization), if the connection is still actively authorized and you have not re-authorized it, we automatically revoke it and run the same hard-deletion described in Section 4: transaction history and linked-card records for that connection are permanently deleted within 60 seconds, or, in the rare case a technical delay interrupts that step, automatically a short time afterward under monitoring. This automatic expiry-deletion applies only to connections that lapse this way. A connection whose syncing you paused by downgrading or canceling your plan is handled differently: it is retained so you can resume, then subject to the longer disconnected-bank limit in Section 3.
  5. You can re-authorize at any time by clicking the banner on Settings → Connections, or directly from any of the reminder emails. You can also revoke access yourself at any point via Plaid at my.plaid.com (the Plaid Portal).

Your PointBagel account, manually-entered cards, point balances, optimization history, and subscription status remain untouched whether your bank link is active, expired, or revoked. One caveat about detail versus summary: after a connection is fully revoked, we permanently delete that bank's underlying imported transactions, but the value summary we already saved to your Lifetime Scorecard for those cards stays visible. You keep the scorecard number; only the transaction-level detail behind it is deleted.The one operational metadata we update on each of your portfolio cards during a Plaid revocation is a smooth-reconnect snapshot (the bank's identifier, the last 4 digits, and the snapshot timestamp) so that if you reconnect that bank later we can suggest the prior card mapping for one-click confirmation. See the “Smooth-Reconnect Mapping Memory” section of our Privacy Policy for the full picture. If you would prefer that we delete the account in full, you can do that yourself anytime from Settings → Account.

When your bank ends a connection

Sometimes your bank, not you, ends a data-sharing connection (for example, when it changes how it works with Plaid). When that happens we show you an in-app alert and a banner asking you to reconnect, and we keep the connection's data so you can reconnect without losing history. If the connection is not restored within about 30 days of the bank's scheduled end date, we treat the bank's action as the end of your authorization for that connection: we release the access token and permanently delete that connection's transaction history and linked-card records, the same way we do when you disconnect (Section 4). Your portfolio cards, point balances, Trip Plans, and account itself are not affected, and you can connect that bank again at any time as a fresh connection.

3. When You Downgrade or Cancel Your Plan

Downgrading to a lower tier or canceling your subscription does not immediately delete your data. Your transaction history, point balances, Lifetime Scorecards, and all derived data are preserved. A downgrade or cancellation is a billing change, not a request to erase your data. The one limit is on the raw imported transactions of a bank you disconnect this way, which we keep for about two years - see “How long we keep a disconnected bank's data” below.

What changes is syncing, not your data:

  • Downgrading between paid tiers (for example, Pro to Plus): we untrack any cards beyond your new plan's limit, but they remain in your portfolio and your bank connections stay live. Re-upgrade to re-track them instantly.
  • Downgrading to Free or canceling: for bank connections beyond the Free plan's limit, we stop syncing and release their Plaid access tokens (so we are no longer billed for connections you are not actively using), but we keep the data we already collected. If you re-subscribe and reconnect the bank through Plaid, syncing resumes where you left off and we rebuild as much history as that bank shares - the full picture for most, even near two years, though some banks share a shorter window. After a bank has been disconnected for about two years, we save its value summary into your Lifetime Scorecard and permanently delete its raw imported transactions - see “How long we keep a disconnected bank's data” below.

This is deliberately different from disconnecting a card (Section 4) or deleting your account (Section 5), both of which erase the underlying data.

If you would rather not keep a disconnected connection's history, you can permanently delete that one connection's imported transactions yourself at any time from the "Disconnected banks" list in your bank connections. Your cards, points, scorecards, and account are not affected, and you do not have to delete your whole account to do it.

How long we keep a disconnected bank's data

When you disconnect a bank by downgrading or canceling, we keep its imported transactions so you can reconnect and resume your history. We keep them for about two years. A reconnect rebuilds as much history as that bank shares: for most banks that is the full picture even near two years, though some banks share a shorter window (Capital One about 90 days, Bank of America about a year). Once a bank has been disconnected for about two years, even the longest-window banks can no longer stitch their older transactions into a gapless timeline, so at that point we save the bank's value summary into your Lifetime Scorecard, which we keep, and then permanently delete the bank's raw imported transactions. This applies only to banks disconnected by a downgrade or cancellation; it does not affect your Lifetime Scorecard, cards, points, or account. Before any deletion we email you a reminder, and a deletion never happens without that prior notice. You can reconnect before then to rebuild as much history as your bank still shares, or delete a disconnected bank's data yourself at any time.

4. When You Disconnect a Card

When you disconnect a connection in Settings → Connections, we release the access token at Plaid and permanently delete all transaction history and linked-card records associated with that connection within 60 seconds. In the rare case a technical delay interrupts the deletion, it completes automatically a short time afterward, and we monitor it until it does. The connection record itself is retained as a revocation marker. The access token is released at Plaid and then blanked. If Plaid is briefly unreachable we keep the token encrypted and retry automatically, and an alarm fires if release takes more than a day. Either way we have an audit trail of when access ended.

The same hard-deletion happens automatically when your bank or Plaid Link signals that you have revoked access (Plaid webhook codes USER_ACCOUNT_REVOKED and USER_PERMISSION_REVOKED).

5. When You Delete Your Account

When you delete your account in Settings → Account, we run a cascading delete that removes all data tied to your user record within 60 seconds: credit cards, point balances, Trip Plans, transactions, notifications, household memberships, subscription metadata, your Plaid connections (the bank access tokens are released at Plaid), saved sessions, sign-in tokens, and any connected AI assistants (every assistant connection and its access and refresh tokens are deleted).

If you had a paid subscription, we cancel it (it will not bill again) and delete your Stripe customer record, so your name and email no longer live at Stripe. Stripe retains records of past invoices and payments as required by financial and tax law.

A small number of records are kept afterward, in anonymized form. In every case your personal identifiers (name, email) are removed or replaced with [deleted]; what remains is non-identifying operational history with no way to tie it back to you:

  • Admin audit and gift-grant records. If an admin acted on your account (a refund, a comped membership), the action is preserved with your name, email, and user identifier replaced by [deleted], for tax and accountability records.
  • Subscription tier history. One row per tier change (upgrade, downgrade, cancellation) is kept for revenue and churn analytics, with your email and any free-text cancellation note removed. Only an anonymous identifier, the tier names, dates, and dollar figures remain.
  • Support messages. If you contacted us through the contact form, the message is preserved with your name, email, subject, body, and our reply replaced by [deleted]; only the category and status survive.
  • Product-usage and affiliate-click events. Page views, feature interactions, and any card-application clicks are kept indefinitely in anonymized form. When you delete your account, the fields that could identify you (your user identifier, your session identifier, the snapshot of which cards you held, the referring web address, and the event details) are permanently removed from each event row. What remains is non-identifying operational data (the event type, the page, the timestamp, and coarse figures such as a former plan tier or card count) that cannot reasonably be linked back to you.
  • Referral records that belong to other people. If someone referred you or sent you a gift membership, that record is theirs, not yours; we remove your email from it and they keep their own record.

None of these contain your name, email, payment details, or financial data after deletion. We maintain and use these de-identified records only in de-identified form and will not attempt to re-identify them, except to test that our de-identification works.

6. Operational Logs & Transient Tokens

Four operational log tables (incoming webhook events, background-job runs, email-delivery events, and the email-deduplication log) are capped at 90 days. A daily cleanup job deletes any row older than 90 days from these tables. None of them contain payment card numbers, account credentials, or full transaction contents; they are operational telemetry only. Product-usage and affiliate-click analytics are not on this 90-day schedule; they are kept indefinitely in anonymized form, as described in Section 5.

Anti-abuse security signals (the IP addresses of automated scrapers we detect) are retained for up to 365 days under a legitimate-interest basis, then automatically deleted. They are not tied to your account.

Portfolio-value history snapshots (the data behind your value-over-time chart) are kept at full resolution for 90 days, then consolidated to one snapshot per day, and deleted entirely after 24 months - the same window the chart itself displays. Consolidation never changes what the chart shows.

Transient authentication tokens are single-use and short-lived: email verification tokens expire after 24 hours; password reset tokens expire after 1 hour; two-factor authentication setup tokens expire after 10 minutes. Session tokens expire after 24 hours of inactivity; a trusted device you approve stays signed in for up to 30 days. Newsletter subscriber records are deleted immediately upon unsubscription. Plaid access tokens are encrypted at rest while a connection is active. On disconnect or revocation the token is released at Plaid and then blanked (overwritten with an empty string). If Plaid is briefly unreachable we keep the token encrypted and retry automatically, and an alarm fires if release takes more than a day. Connected AI assistant (MCP) credentials are stored only as one-way hashes, never as usable tokens: a short-lived access token expires about 30 minutes after it is issued, refresh tokens rotate on use, and the whole connection is deleted the moment you disconnect it in Settings, sign out of all devices, reset your password, or delete your account.

Mapping-click events: de-identified - retained up to 24 months for matcher-quality improvement, then auto-pruned by a weekly cleanup job. Before storage, the bank-supplied card name in each event is reduced to our public card-catalog vocabulary; words that are not recognized card products, issuers, or banking terms (including all digits, single letters, and text in other alphabets) are replaced with a placeholder. Personal text a bank might place in an account name is stored only to the extent its words coincide with that public vocabulary (some common first and last names are also retail or bank brand names); such words can remain, and in rare cases a name composed entirely of brand words (such as a name matching a store brand) can remain whole, always in a row with no user identifier. Because these rows have no user identifier attached, there is nothing tied to your account to delete on closure - they survive account deletion by design, and they are designed so they cannot reasonably be linked back to you: they contain no account, session, or device identifiers, and we commit to never attempting to re-identify them.

7. Authorization & Revocation Records (CFPB § 1033)

Consistent with the CFPB's Section 1033 framework (the Personal Financial Data Rights Rule), we retain records of each authorization and revocation event for at least three years after the most recent authorization, so we can demonstrate compliance. These records contain only the user identifier, the timestamp of the authorization or revocation, and the institution connected. They do not contain transaction data, account numbers, credentials, or Plaid access tokens. Your authorization to share data with us is valid for up to 12 months; before it expires we will prompt you to re-authorize the connection.

8. Backups

Our database provider (Neon) maintains point-in-time backups for up to 7 days for disaster recovery. Deletions you make through the product propagate to these backups on the same 7-day rolling window.

9. We Do Not Sell or Share Your Individual Data

PointBagel does not sell, rent, or share your individual personal data with third parties for their own marketing or analytics. This includes your transactions, card portfolio, point balances, email, and account activity. Those never leave our infrastructure for outside use.

We may use, publish, or sell aggregated, anonymized statistics that cannot identify any individual user. For example, we might publish or license a figure like “the average PointBagel user holds 4.2 credit cards” or “Chase cards represent 38% of tracked cards on the platform.” Aggregate statistics like these are built from data that has been stripped of identifying information and cannot be reverse-engineered back to any individual user. This does not include any individual's data, and it never includes your bank-transaction data.

The third-party services listed in our Privacy Policy (Plaid, Stripe, Resend, and others) act as data processors on our behalf. They are bound by written agreements with us and by their own privacy commitments, and they use your data only to deliver the specific service we hired them for.

10. Your Rights

You can disconnect a card, delete your account, or request a copy of your data at any time from Settings. For other privacy requests, including requests under CCPA, GDPR, or similar regulations, email [email protected].