A focused privacy page for end users connecting their bank — what happens during connection, what data we keep, how to revoke access, and how to ask for deletion. For the engineering view of how data is protected, see Security & data handling.
When you connect your bank, you do that inside Plaid Link — a flow operated by Plaid Inc., not by Delegate. Plaid is the open-banking provider used by Robinhood, Wealthfront, Venmo, and most modern fintechs.
We retain the minimum needed to produce, justify, and audit a verification verdict. We do not collect or store more than this.
The seven-year window matches the standard fraud-investigation retention period and what regulated financial-services partners require of their vendors. Customers can delete an individual end-user's record at any time on request; see "Data deletion" below.
You can revoke Delegate's read-only access to your bank account at any time, directly from Plaid — no email required.
You have the right to request deletion of your data. Two paths, depending on what you want removed.
Plaid is the only third party that touches your bank data. No marketing-tech, no advertising, no data brokers, no analytics-with-PII partners are involved in the bank-verification pipeline.
For full transparency, here is the complete list of sub-processors Delegate uses — including ones that touch infrastructure or billing but not bank data — so you can see the whole picture:
We update this list and notify customers at least 30 days before adding any new sub-processor that processes user data.
We try to be precise about what is in place versus what is in progress. Calling something "certified" before an auditor has signed a report would be misleading — so we don't.