We never see or store your card number
You never type your card number into Perqt. Plaid verifies your account with your bank and gives us a read-only token. We never see, store, or have access to your full card number, CVV, or PIN.
Perqt is built around a simple promise: you keep full control of what we know, what we store, and who can access it.
You never type your credit card number into Perqt. We don’t see it, store it, or have access to it. Account linking is handled entirely through Plaid.
01 · Data flow
You never type your card number into Perqt. Here's what actually moves between your bank, Plaid, and us.
Your full card number, CVV, and PIN stay with your bank. Plaid verifies the account and sends Perqt only a scoped, read-only token.
02 · The pillars
You never type your card number into Perqt. Plaid verifies your account with your bank and gives us a read-only token. We never see, store, or have access to your full card number, CVV, or PIN.
Plaid gives Perqt a read-only token. We can see transaction details to match benefits, but we cannot move money, make purchases, or change your account.
Your banking password is entered only inside Plaid's secure window. It never reaches Perqt.
HTTPS with TLS 1.2+ in transit. AES-256 at rest. Plaid tokens and Stripe payment data are encrypted separately.
Database policies ensure only your authenticated requests can access your data. No one else can see your wallet or transactions.
Passwords are hashed and checked against breach databases. Sessions are short-lived and rotated automatically.
No ads, no data brokers, and no sharing your personal information or spending patterns for marketing.
We only store the transaction fields needed to match benefits. We never store full card numbers, CVVs, PINs, or Social Security numbers.
Disconnect a card anytime. Export or delete your account permanently. Active deletion is 30 days; backups are 90 days.
SOC 2 certified hosting, automated patching, network isolation, and encrypted vault-stored secrets.
Same read-only Plaid connection. We can read transactions and Bitcoin rewards, but cannot trade, transfer, or move funds in your Coinbase account.
Sends only the wallet context needed to answer. Never credentials, card numbers, or payment data. AI cannot move money or take action on your behalf.
Every dollar figure Ask Perqt quotes — fees, redeemed value, rewards, ROI — comes from the same calculations that power your dashboard, not from the AI. If a number can't be computed, Ask Perqt says so instead of estimating one.
Card benefit amounts come from the issuer's own published terms. Coverage ceilings and per-use perks are shown as what they are, not as annual value. Where a figure isn't issuer-stated, Perqt either publishes an estimate with its methodology — for example elite status — or shows no number at all. Our catalog is reviewed by us, not audited by issuers, so confirm details with your issuer before you rely on them.
Found a vulnerability? Email contact@perqt.ai. We acknowledge reports within 2 business days and never pursue legal action for good-faith research.
03 · Data ledger
04 · Common questions
Plaid is a bank-grade connection service. You authenticate with your bank inside Plaid's secure window, and Plaid sends us a read-only token — never your card number, CVV, or password.
Only merchant, amount, date, and category. We do not see your full account number, balance, loans, investments, or other accounts.
No. Your card number and bank login are handled entirely by Plaid. We only store the encrypted read-only token and the transaction details needed to match your benefits.
No. The token is strictly read-only. We cannot make purchases, transfer funds, or change account settings. Disconnect the card anytime to revoke access.
Usually not. The connection is at the account level, not the printed card number, so a routine reissue on the same account keeps syncing. You never re-enter a card number in Perqt.
If your bank revoked aggregator access or opened a new account, Perqt flags the card and pauses syncing rather than showing stale numbers. Go to Settings → Connected Cards → Reconnect and authenticate inside the secure Plaid window. If the bank opened a new account, authorize it from the "Add new accounts" prompt and disconnect the old entry.
Banks require a fresh login after password changes, new MFA devices, expiring consents, or security events. Perqt pauses that card's sync until you reconnect so your numbers are never quietly out of date. Reconnecting happens inside Plaid — your banking password never reaches Perqt.
Reporting stops at the bank and syncing ends. Disconnect the card in Perqt to revoke read-only access immediately; that card's Plaid-sourced transaction history is deleted at the same time. If you want to keep historical transaction data for spend analysis, contact us — we can archive the card instead of purging it.
By default, disconnecting a card removes its Plaid-sourced transaction history because we only keep consumer data while we have a current business need to use it. If you want a closed or inactive card to remain visible in historical spend and Insights views, we can mark it as archived instead of disconnecting it. Reach out at contact@perqt.ai and we can set that up.
05 · Your side