CozyBudget uses Plaid to securely connect to your bank so you can automatically pull in balances and transactions instead of typing them in by hand. Plaid is a trusted financial data network used by thousands of apps, including many major banks.
What Plaid does
- Shows a secure sign-in screen for your bank inside our app.
- Verifies you at your bank — we never see your bank username or password.
- Returns a limited access token that lets us read the accounts you selected.
What we receive from Plaid
- Account name, type, mask (last 4), balance.
- Transaction history: date, merchant, amount, and Plaid's suggested category.
What we do not receive
- Your online-banking login credentials.
- The ability to move money, initiate transfers, or make payments.
How we store it
Plaid access tokens are stored server-side only and are never sent to the browser. Your bank data is scoped to your account through row-level security. Only you (and household members you explicitly share with) can see it in the app. See our Information Security Policy for the full set of controls we use to protect your data.
Data retention and deletion
We retain your connected bank data only as long as it is needed to provide the service or as required by applicable law.
- Account active: Balances and transactions synced from Plaid are kept while your bank connection remains active and your CozyBudget account is open, so you can view trends, budgets, and subscription activity.
- Disconnect: When you disconnect a bank from CozyBudget, the Plaid access token is revoked and removed from our systems. Previously synced transaction and balance records are also deleted.
- Account closure: If you close your CozyBudget account, your bank connection data and synced records are deleted within a reasonable period, subject to any legal retention obligations.
- Policy review: This retention approach is reviewed periodically as part of our information security and privacy program.
MFA and access controls
We require multi-factor authentication (MFA) before you can connect a bank account through Plaid, and we strongly encourage MFA for all accounts. Supported factors include:
- Time-based one-time passcodes (TOTP) from an authenticator app.
- Email verification at sign-up.
- Optional email one-time passcodes (OTP).
MFA is also required (or prompted) for sensitive areas such as Connected Banks, household financial data, business financial data, the Subscription Manager, bills, and security settings. See our Information Security Policy for more details on access controls and authentication.
Compliance attestations for Plaid production keys
To qualify for Plaid production access, we attest to the following security controls. Each attestation is documented in our Information Security Policy and summarized in our Compliance Center.
- Periodic access reviews and audits
- Vulnerability patching within a defined SLA
- End-of-life (EOL) software monitoring
- Vulnerability scanning
- Automated de-provisioning/modification of access for terminated or transferred employees
- Zero trust access architecture
- Secure tokens and certificates for authentication
- Defined and documented access control policy
You can review the full mapping of these attestations on the Compliance Center.
You are in control
- Connecting a bank is optional. You can use CozyBudget without it.
- You can disconnect any bank anytime from Connected Banks. Disconnecting revokes our access at Plaid and deletes the token.
- You can also revoke access directly from your bank or from the Plaid Portal at my.plaid.com.
Plaid's own policies
Plaid's handling of your data is governed by Plaid's End User Privacy Policy, available at plaid.com/legal.
Questions
Reach us through the in-app support option in Settings.