Perqt AI Wallet logo
Security & privacy

Your financial details are safeguarded.

Perqt is built around a simple promise: you keep full control of what we know, what we store, and who can access it.

You never type your credit card number into Perqt. We don’t see it, store it, or have access to it. Account linking is handled entirely through Plaid.

  • No card numbers on our servers
  • Read-only Plaid
  • AES-256 + TLS 1.2+
  • Row-level security
  • No data sales
  • You own your data
  • SOC 2 hosting

01 · Data flow

From your card to Perqt

You never type your card number into Perqt. Here's what actually moves between your bank, Plaid, and us.

Your card

Chase, Amex, Citi, etc.

Secure link

Plaid

Bank-grade connection

Token only

Perqt

Read-only token

Card number never shared

Your full card number, CVV, and PIN stay with your bank. Plaid verifies the account and sends Perqt only a scoped, read-only token.

02 · The pillars

How we protect you

We never see or store your card number

You never type your card number into Perqt. Plaid verifies your account with your bank and gives us a read-only token. We never see, store, or have access to your full card number, CVV, or PIN.

Read-only issuer access via Plaid

Plaid gives Perqt a read-only token. We can see transaction details to match benefits, but we cannot move money, make purchases, or change your account.

We never see your banking password

Your banking password is entered only inside Plaid's secure window. It never reaches Perqt.

Encryption in transit and at rest

HTTPS with TLS 1.2+ in transit. AES-256 at rest. Plaid tokens and Stripe payment data are encrypted separately.

Row-level security on every table

Database policies ensure only your authenticated requests can access your data. No one else can see your wallet or transactions.

Modern authentication

Passwords are hashed and checked against breach databases. Sessions are short-lived and rotated automatically.

We don't sell your data — ever

No ads, no data brokers, and no sharing your personal information or spending patterns for marketing.

Minimal data, by design

We only store the transaction fields needed to match benefits. We never store full card numbers, CVVs, PINs, or Social Security numbers.

You own your data

Disconnect a card anytime. Export or delete your account permanently. Active deletion is 30 days; backups are 90 days.

Hardened infrastructure

SOC 2 certified hosting, automated patching, network isolation, and encrypted vault-stored secrets.

Coinbase One Card: same read-only rules

Same read-only Plaid connection. We can read transactions and Bitcoin rewards, but cannot trade, transfer, or move funds in your Coinbase account.

Ask Perqt: private by default

Sends only the wallet context needed to answer. Never credentials, card numbers, or payment data. AI cannot move money or take action on your behalf.

The AI never does your math

Every dollar figure Ask Perqt quotes — fees, redeemed value, rewards, ROI — comes from the same calculations that power your dashboard, not from the AI. If a number can't be computed, Ask Perqt says so instead of estimating one.

A dollar amount only when we can back it

Card benefit amounts come from the issuer's own published terms. Coverage ceilings and per-use perks are shown as what they are, not as annual value. Where a figure isn't issuer-stated, Perqt either publishes an estimate with its methodology — for example elite status — or shows no number at all. Our catalog is reviewed by us, not audited by issuers, so confirm details with your issuer before you rely on them.

Responsible disclosure

Found a vulnerability? Email contact@perqt.ai. We acknowledge reports within 2 business days and never pursue legal action for good-faith research.

03 · Data ledger

What we store — and what we never touch

What we store

  • Email address

    Account login, reminders

  • Cards in your wallet

    Identify which benefits apply

  • Plaid connection token (read-only)

    Pull purchases from your card institution via Plaid

  • Transactions (merchant, amount, date, category)

    Match purchases to benefits & build analytics

  • Spending patterns & ROI metrics

    Power recommendations and insights

  • Subscription billing details via Stripe

    Process your subscription payment securely

  • Reminder & UI preferences

    Personalize the app

  • Manually logged benefit usage

    Track benefits that can't be detected from transactions alone

What we never touch

  • Online banking password

    Plaid handles auth — we never see it

  • Full credit card numbers / CVV / PIN

    You never enter them on Perqt. Plaid handles account linking with your bank.

  • Ability to move money or make purchases

    Read-only access only

  • Social Security number

    Not needed

04 · Common questions

How Plaid handles your card data

How does Plaid process my card data?

Plaid is a bank-grade connection service. You authenticate with your bank inside Plaid's secure window, and Plaid sends us a read-only token — never your card number, CVV, or password.

What does Perqt actually see from my bank?

Only merchant, amount, date, and category. We do not see your full account number, balance, loans, investments, or other accounts.

Does Perqt store my card number or bank login?

No. Your card number and bank login are handled entirely by Plaid. We only store the encrypted read-only token and the transaction details needed to match your benefits.

Can Perqt move money or make payments from my account?

No. The token is strictly read-only. We cannot make purchases, transfer funds, or change account settings. Disconnect the card anytime to revoke access.

My card expired or was reissued — do I need to do anything?

Usually not. The connection is at the account level, not the printed card number, so a routine reissue on the same account keeps syncing. You never re-enter a card number in Perqt.

My card was replaced after fraud. What do I do?

If your bank revoked aggregator access or opened a new account, Perqt flags the card and pauses syncing rather than showing stale numbers. Go to Settings → Connected Cards → Reconnect and authenticate inside the secure Plaid window. If the bank opened a new account, authorize it from the "Add new accounts" prompt and disconnect the old entry.

Why am I asked to reconnect a card?

Banks require a fresh login after password changes, new MFA devices, expiring consents, or security events. Perqt pauses that card's sync until you reconnect so your numbers are never quietly out of date. Reconnecting happens inside Plaid — your banking password never reaches Perqt.

What happens if I close a card or a card is closed for me?

Reporting stops at the bank and syncing ends. Disconnect the card in Perqt to revoke read-only access immediately; that card's Plaid-sourced transaction history is deleted at the same time. If you want to keep historical transaction data for spend analysis, contact us — we can archive the card instead of purging it.

Can I keep historical transaction data from a card I no longer use?

By default, disconnecting a card removes its Plaid-sourced transaction history because we only keep consumer data while we have a current business need to use it. If you want a closed or inactive card to remain visible in historical spend and Insights views, we can mark it as archived instead of disconnecting it. Reach out at contact@perqt.ai and we can set that up.

05 · Your side

Rights & hygiene

Your rights

  • Access — download a full copy of your data anytime
  • Correction — update or fix any information in your profile
  • Deletion — remove your account and all associated data
  • Portability — export in standard JSON or CSV format
  • Objection — opt out of analytics and non-essential cookies

Account hygiene tips

  • Use a unique password manager–generated password for Perqt
  • Enable 2-factor authentication on the email tied to your account
  • Sign out on shared or public devices
  • Review your wallet periodically and remove cards you've closed

Talk to us

Questions about security, privacy, or how your data is handled? Our team responds personally — usually within one business day.

contact@perqt.ai

Last reviewed: July 5, 2026