Privacy Policy

Last updated: July 24, 2026

This policy explains what we collect, why we collect it, and what we do (and don't do) with it. If anything here is unclear, email [email protected] and we'll walk you through it.

1. Information We Collect

Account Information

When you create an account we collect your name, email address, and a securely hashed password if you sign up with email. If you sign in with Google, we receive your name, email, and profile picture from Google.

Financial Data (via Plaid)

When you connect a credit card through Plaid, we receive transaction amounts, dates, merchant names, and merchant categories, plus basic account metadata like the institution name, account nickname, last four digits, and account type. That data is what lets us tell you which card earned the most rewards on each purchase and build your Trip Plans. Plaid's account response also carries your balances, available credit, and credit limits; Plaid provides no way to suppress them, so we receive them, but we do not store them or use them anywhere in the product.

We do not receive any of the following from Plaid:

  • Your name, address, email address, or phone number from your bank records (we only have what you typed into your PointBagel account)
  • Full account numbers, full card numbers, CVV, or expiration dates
  • Routing numbers or any other ACH-related identifiers
  • APRs, interest rates, late-payment data, or rewards balances
  • Statement balances, minimum payments, or payment history
  • Investment holdings, loan terms, or mortgage details
  • Online banking credentials, Social Security Number, or identity documents

The PointBagel integration requests only one Plaid product: transactions. Plaid handles the bank login itself, so we never see those credentials. We also configure Plaid Link to show you credit-type accounts only - credit cards, charge cards, and similar revolving credit products. Checking, savings, loan, and investment accounts don't appear as selectable options.

We maintain an internal Plaid data-collection audit that lists every Plaid API call we make, every database field we persist, and every field that arrives from Plaid but is intentionally discarded. The audit is updated whenever the integration changes. Email [email protected] to request a copy.

Plaid is our data processor and operates under our agreement with them and their own End User Privacy Policy. You can review or revoke any app's access to your bank data at my.plaid.com (the Plaid Portal). Under CFPB Section 1033, your authorization to share data with us is valid for up to 12 months from your most recent authorization. We'll prompt you to re-authorize before that window closes.

User-Entered Data

You can manually enter credit cards, loyalty program point balances, travel preferences, and spending estimates. We use this only to produce recommendations for you.

Eligibility Outcome Reports

If you choose to tell us the actual approval or denial decision you received on a credit card application, we store that report so our team can compare real outcomes against the prediction we showed you and improve the accuracy of our eligibility estimates. Each report contains the card and issuer, the prediction we had made, the outcome you report (approved, approved without the bonus, denied, or pending), the date it happened, and any optional denial reason or note you add. We deliberately do not collect, and ask that you do not enter, sensitive financial details such as your Social Security number, income, or credit score. These reports are read by our staff only and are never used to automatically change any eligibility rule; a human reviews them and a human decides whether to update our published estimates. Submitting a report is optional, it is included in your data export, and it is deleted along with everything else if you delete your PointBagel account.

Smooth-Reconnect Mapping Memory

When you disconnect a Plaid bank connection, we permanently delete the transaction-level detail and the Plaid-side card records, while your card-year value summaries stay visible (see the Data Retentionpage). To make reconnecting smooth later, we keep three small fields on each of your portfolio cards: the bank's identifier, the last 4 digits of the card, and the timestamp of the snapshot. When you reconnect that bank, we use these to suggest “this is the card you previously linked” so you can confirm the mapping with one click instead of re-mapping from scratch. These fields are your own card metadata (your last 4 + your bank name, both of which you already know about your card), not Plaid-derived data, so they are exempt from the 60-second deletion that applies to Plaid transactions and are kept on your account indefinitely. They are deleted along with everything else if you delete your PointBagel account.

Payment Information

Subscription payments run through Stripe. PointBagel does not store your payment card number, expiration date, or CVV. Stripe's privacy policy covers how they handle that data.

When you start a paid subscription, Stripe collects your billing address (at minimum a postal code) to calculate US state and local sales tax where required by law. This address is stored by Stripe under their privacy policy and used solely for tax calculation, invoice processing, and fraud prevention. PointBagel does not use billing address data for marketing, advertising, or any non-tax-related purpose.

When you delete your account, we cancel any active subscription and delete your Stripe customer record, so your name and email no longer live at Stripe. Stripe retains records of past invoices and payments as required by financial and tax law.

Usage Data

We collect basic usage data such as pages visited, the web address that referred you to a page, features used, and error logs so we can find bugs and improve the product. While you are signed in, these usage events are associated with your account; the referring address is stripped of any per-user identifiers before it is stored. Your browser's localStorage holds UI preferences like view settings and your last-used sign-in method. We use Google Analytics for aggregate traffic and acquisition-source measurement - see the subprocessor list in Section 3 and the cookie details in Section 8. We do not run advertising networks, ad-targeting cookies, or cross-site ad tracking.

2. How We Use Your Information

  • To run the Service: transaction enrichment, card recommendations, Trip Plans.
  • To process your subscription payments.
  • To send transactional emails (account verification, password reset, subscription confirmations).
  • To send the PointBagel newsletter, if you opted in. You can unsubscribe at any time.
  • To detect and stop fraud, abuse, and security incidents.
  • To help you with support questions and billing issues.
  • To improve the product using aggregated, anonymized usage patterns.

Authorized PointBagel staff may look at your account, card portfolio, or transaction data when it's needed to run the Service, help you with a support request, or verify data accuracy. Access is limited to people with a real operational reason to see it, and every access is logged in an internal audit trail.

Aggregate Detection-Catalog Improvement

To make our automatic benefit detection more accurate over time - for example, recognizing that a transaction labeled “Platinum Walmart+ Credit” is an Amex Platinum statement credit - we may analyze de-identified merchant labels and merchant categories across our user base. This analysis works on aggregated tokens only: merchant strings and category counts, with no user identifiers, account numbers, balances, or transaction amounts attached. The output expands our internal catalog of recognized issuer credits and merchants so every user gets better attribution accuracy. We do not share or sell any of this aggregated output, and no individual user's transactions, identity, or financial activity is exposed - to us or to anyone else - through this process.

Mapping-Click Telemetry

When you map a bank-connected card to a card in our catalog (during the “link your accounts” flow), we log a de-identified event capturing the product name your bank sent (e.g. “Platinum Card®”), the catalog card you selected, and whether our matcher had suggested that card. Before the event is stored, the bank-supplied name is reduced to our public card-catalog vocabulary: any word that is not a recognized card product, issuer, or banking term (including all digits, single letters, and text in other alphabets) is replaced with a placeholder. If your bank labels the account with something personal, such as your own name, the words of that name are not stored unless they happen to match our card-catalog vocabulary (some common first and last names are also retail or bank brand names). Words of a name that coincide with that vocabulary can remain, and in rare cases a name composed entirely of brand words (such as a name matching a store brand) can remain whole - always inside an entry with no user identifier attached - no link to your account, your email, your IP, or any other personal data. These events are used only to improve our automatic suggestions so future users get more accurate first-try matches. Because the rows are de-identified, there is nothing tied to your account to delete on closure. We maintain and use them only in de-identified form and will not attempt to re-identify them, except to test that our de-identification works.

Apply-Click Telemetry

When you click an “Apply” button for a card, the click passes through a PointBagel redirect before it reaches the card issuer. We log that click - the card, the page you clicked from, and, if you are signed in, your account along with a small snapshot of your portfolio at that moment (which cards you track, how old your account is, and whether you have connected a bank) - so we can measure demand and decide which card partnerships to pursue. This happens for every Apply click, whether or not we have an affiliate link for that card. The snapshot stays with us: the redirect is a server-side hop, so we do not send it to the issuer or to any affiliate partner, and the issuer only sees you when you land on its own application page. When you delete your account, we remove the link between these click records and you; the anonymized rows are kept as part of the long-term analytics described in Section 6.

3. Data Sharing & Subprocessors

We do not sell, rent, or trade your personal information. We share your data only with service providers that help us operate, support, secure, and improve PointBagel - and only as needed for those purposes - under written agreements that hold them to at least the same confidentiality and security standards described here. These currently include:

  • Plaid: financial account connection and transaction retrieval. Plaid is our data processor and is separately governed by the Plaid End User Privacy Policy.
  • Stripe: subscription payment processing.
  • Resend: transactional and newsletter email delivery.
  • Sentry: application error monitoring. PII is scrubbed from event payloads before they leave our infrastructure.
  • Neon: managed PostgreSQL database hosting.
  • Vercel: web application hosting and content delivery.
  • Cloudflare: network delivery and security. Your requests reach our application through Cloudflare's network, so Cloudflare processes standard request metadata (including your IP address and the address of the page requested) to route traffic, cache content, and block abuse. It sets no cookies of ours, does not track you across sites, and we do not run Cloudflare's web-analytics product.
  • Google Analytics (Google LLC): aggregate website analytics. Google Analytics sets first-party cookies (named _ga, plus a related cookie whose name begins with _ga_) and reports aggregate site traffic and the sources visitors arrive from (for example search, direct, or referral). We enable IP anonymization and keep Google Signals and advertising features turned off, so the data is not used for cross-site advertising. We see only aggregate reports, not individual identities, and we suppress analytics on pages whose address could contain sensitive information (password-reset, email-verification, account-impersonation, unsubscribe, and bank-connection redirects) and on admin pages.
  • Upstash: serverless Redis used for API rate limiting (processes request identifiers such as user IDs and IP-derived keys, not your financial data).
  • NextAuth.js / Google OAuth: authentication for Google sign-in.
  • AI service providers, currently including Anthropic: help our team review and resolve data-correction and support requests. See “How we use AI” below.

We keep this list current and update it as the providers we use change.

How we use AI

We use third-party AI service providers (currently Anthropic) to help our team review and resolve data-correction requests and support tickets more quickly. We send only the information needed to handle your request, such as the text of the request and the data point it concerns - we do not send your bank-login credentials or your connected-account identifiers to these providers. Under our agreements with these providers, your information is not used to train their AI models, and the data is deleted within a short retention window (currently up to 30 days), except where the provider must keep it to comply with law or to investigate misuse. A member of our team reviews any change before it is applied. We do not use AI to make automated decisions that have legal or similarly significant effects on you.

Connecting an AI assistant (MCP)

You can connect PointBagel to an AI assistant (such as Claude or ChatGPT) using the Model Context Protocol. When you do, you direct us to give that assistant read-only access to your own PointBagel data - your point balances, your cards, your fee analysis, and spending estimates from your imported transactions (for example, your welcome-bonus progress) - so it can answer your questions. This access is your choice: it never moves money, never sees your login, and only ever reaches your own account. Whatever your assistant does with the data it reads is governed by that assistant provider's own privacy policy, not ours. You can review and disconnect any connected assistant at any time from Settings, and signing out of all devices also revokes every connection.

We do not sell, rent, or trade your personal information. Except where you yourself direct us to - such as connecting an AI assistant as described above - your individual transaction data, point balances, and card portfolio are never shared with card issuers, loyalty programs, advertisers, or any other third party. We may publish or sell aggregated, anonymized statistics that cannot identify an individual user, like industry averages or trends - never any individual's data, and never your bank-transaction data.

4. Affiliate Links

When we have an affiliate relationship for a card, some credit card links on the Service may be affiliate links. When you click one, the destination site may collect information about your visit. We do not share your PointBagel account data with any affiliate partner. Affiliate relationships are disclosed in line with FTC guidelines - see our Affiliate & Advertising Disclosure.

5. Data Security

We take a layered approach to keeping your data safe. Plaid access tokens and other sensitive values are encrypted at rest with AES-256-GCM. Passwords are hashed with bcrypt at 12 rounds. All data in transit uses TLS 1.2 or higher. Rate limits on authentication and administrative endpoints fail closed rather than letting abuse through. Incoming webhooks are signature-verified. Admin access follows a least-privilege role model, with per-admin audit logging. Error-monitoring payloads are scrubbed of personally identifiable information, access tokens, and authentication headers before they leave our infrastructure. No method of transmission or storage is perfectly secure, but we design with the assumption that every layer will eventually be tested.

Email Verification

We require email verification on all accounts. This confirms you control the email address on your account and protects access to your financial data. If your email is not verified, you will be prompted to verify before using the app. You may delete your account at any time without verifying.

We may automatically mark your email as verified when you complete any flow that proves email control: clicking a verification link or completing a password reset.

Two-Factor Authentication & Backup Codes

When you enable two-factor authentication, we generate 10 single-use backup codes and display them to you once. These codes let you regain access if you lose access to your authenticator app. Codes are stored hashed (bcrypt), never in plaintext, and are retained only while two-factor authentication is enabled on your account. We delete all backup codes when you disable two-factor authentication or delete your account. If you lose your codes, you can regenerate a fresh set at any time from your security settings (the old codes are immediately invalidated).

Breach Notification

If a security breach affects your personal data, we'll notify you without undue delay, and no later than 30 days after discovery (or sooner if applicable law requires it). The notice will describe what happened, what data was involved, what we've done to fix it, and what you can do to protect yourself.

6. Data Retention

We keep your account data and Plaid-derived transaction history for as long as your account is active, because the product's historical charts and optimization reports rely on long-running history. For a bank you disconnect by downgrading or canceling, we keep its imported transactions for about two years, long enough for a reconnect to rebuild as much history as that bank shares, after which we save its value summary into your Lifetime Scorecard and permanently delete the raw transactions; see our Data Retention Policy for the criterion and the advance-notice email. When you disconnect a card, we permanently delete the transactions and linked-card records tied to that connection within 60 seconds. When you delete your account, a cascading delete removes everything attached to it within 60 seconds (transactions, cards, reports, point balances, household memberships, notifications, and subscription metadata). Authorization and revocation records stay for at least three years to satisfy CFPB Section 1033 record-keeping. Operational logs (webhook events, job runs, email events) are capped at 90 days. To protect the Service from automated scraping and abuse, we retain the IP addresses of detected automated/scraping activity (including from logged-out visitors) for up to 365 days under a legitimate-interest basis, then delete them; these are not tied to your account. Aggregated, anonymized product-usage analytics are kept indefinitely as a long-term business record; before they are stored we remove the identifiers that would link them to you, so they cannot be tied back to your account. See our Data Retention Policy for the full picture.

7. Your Rights

You can always:

  • Access your data through your dashboard, transaction list, and export features.
  • Export a complete, machine-readable (JSON) copy of your account data - not just transactions, but your cards, point balances, Trip Plans, redemptions, settings, and more.
  • Delete your account (and everything tied to it) from Settings.
  • Disconnect linked financial accounts anytime.
  • Delete a disconnected connection's data for any bank you stopped syncing on a downgrade or cancellation - permanently remove its imported transactions from the "Disconnected banks" list in your bank connections, without affecting your cards, points, scorecards, or account.
  • Unsubscribe from marketing emails using the link at the bottom of any email.
  • Opt out of the newsletter in your account settings.

California residents (CCPA/CPRA): California law gives you a few extra rights:

  • Right to Know: ask for a copy of the personal information we've collected about you in the last 12 months.
  • Right to Delete: ask us to delete your personal information. You can do this yourself from Settings - delete your whole account, or delete the retained data for any individual disconnected bank connection - or email us. We also delete a disconnected bank's raw transactions automatically at the disclosed retention horizon (about two years), described in our Data Retention Policy.
  • Right to Correct: ask us to fix inaccurate personal information we hold about you. You can update your name and profile details yourself in Settings, or email us for anything you can't edit directly and we'll correct it.
  • Right to Opt Out of Sale or Sharing: we do not sell your personal information for money. We do use Google Analytics and, where available, affiliate links, and we attach your account to first-party usage events - which under some state laws can count as “sharing” personal information for cross-context advertising or analytics. You can opt out of that sharing at any time on our Your Privacy Choices page, and we honor Global Privacy Control browser signals automatically.
  • Right to Non-Discrimination: we won't hold it against you for exercising any of these rights.

Two direct links California law asks us to surface:

  • Do Not Sell or Share My Personal Information: our Your Privacy Choices page. Opting out turns off Google Analytics, stops us from attaching your account to affiliate “Apply” clicks, and stops us from attaching your account to first-party usage events - for this browser, and for your signed-in account across devices. It does not affect the network-level request logging our hosting and security providers perform to deliver and protect the site, which we cannot switch off and which is not used to profile you.
  • Limit the Use of My Sensitive Personal Information: not applicable to us. We do not use sensitive personal information to infer characteristics about you, and we never use it for targeted advertising, profiling, or sharing, so there is nothing here to limit. If that ever changes, we'll add the control and say so.

To exercise any of these rights, email [email protected]. We'll respond to verifiable requests within 30 days, or sooner if applicable law requires. If we need more time (up to the 45-day maximum CCPA allows), we'll let you know in writing within the first 30 days.

8. Cookies and Local Storage

PointBagel uses essential cookies for authentication. These include your sign-in session token and a small set of strictly-necessary security cookies our login system sets to protect the sign-in process (a cross-site-request-forgery token and other short-lived sign-in-flow values, with additional values set only while you are signing in with Google). Your browser's localStorage holds UI preferences like view mode and your last-used sign-in method. We also use Google Analytics, which sets first-party analytics cookies (named “_ga”, plus a related cookie whose name begins with “_ga_”) to measure aggregate site traffic and understand which sources visitors arrive from. We have IP anonymization enabled, we keep Google Signals and advertising features turned off, and we do not use advertising cookies, tracking pixels, or cross-site ad tracking. We do not sell your personal information for money. To the extent analytics or affiliate links count as “sharing” under state law, you can opt out on our Your Privacy Choices page, and we honor Global Privacy Control browser signals automatically.

If you turn on two-factor authentication and choose “remember this device for 30 days” at sign-in, we set one additional first-party cookie (“pa_trusted_device”). It is a signed token that stores only your account identifier and a revocation counter - no name, email, location, or device fingerprint - and it lets that one device skip the second-factor code (never the password) for 30 days. It is cleared, and stops working, when you sign out of all devices, change or reset your password, or turn off two-factor authentication. It is a security cookie, not a tracking cookie.

If you arrive through a referral or gift invitation link (for example, a link ending in “?ref=”), we store a single first-party cookie (“pa_ref”) that records only the referral code so we can credit the person who invited you if you later subscribe. It contains no name, email, or browsing history, expires after 30 days, is never shared with anyone, and is not used to track you across other sites. It is not required to use PointBagel.

9. Children's Privacy

The Service isn't intended for anyone under 18, and we don't knowingly collect data from children. When you create an account you confirm you are 18 or older: our registration page requires an affirmative 18+ checkbox before you can sign up with either email or Google, and our sign-in page shows the same 18+ confirmation next to Google sign-in. For accounts created since this practice took effect, we record the date of that confirmation on your account. If we find out we've collected information from someone under 18, we'll delete it right away.

10. International Users

The Service is hosted in the United States. If you're using it from somewhere else, your information will be transferred to and processed here. By using PointBagel, you're agreeing to that transfer.

11. Changes to This Policy

We may update this policy from time to time. If we make a meaningful change, we'll post the updated version on this page with a new “Last updated” date. Continuing to use the Service after a change means you accept the update.

12. Contact Us

Any privacy questions, or ready to exercise one of your rights? Email us at [email protected].