Legal
Privacy Policy
Last updated: August 1, 2026
This Privacy Policy explains how Pikt Rewards (“Pikt,” “we,” “us”) collects, uses, and shares information when you use the Pikt website, applications, and services (the “Service”). By using the Service, you agree to the practices described here.
1. Information We Collect
We collect the following categories of information:
- Account information. Your name, email address, and authentication data, managed through our identity provider (Clerk).
- Financial connectivity data. When you link a financial account, Plaid retrieves the data described in Section 2 below. We do not receive or store your bank login credentials; those are handled exclusively by Plaid.
- Usage data. Simulations you run, offers you add, recommendations shown, and similar activity within the Service.
- Billing data. Subscription status and customer identifiers. Card and payment details are collected and stored by Stripe, not by Pikt.
- Technical data. IP address, device and browser information, and log data used for security and reliability.
1a. Pikt Checkout Browser Extension
The optional Pikt Checkout browser extension provides rewards-card assistance on checkout pages you are already visiting: it names your best-earning card, points at the card-number field so your browser’s own saved cards can fill it, may show related card-offer reminders, and may show a clearly labeled sponsored pick of a card you already have. It never issues a card, never processes or moves money, and never sits in the middle of a payment. This section describes exactly what the extension reads, what it sends, and what stays on your device.
Where the extension runs
We want to be straightforward about this, because it is the most privacy-relevant thing about the extension: once you install it, a small piece of Pikt code loads on every ordinary https web page you open — not only shopping sites, and not plain http pages. There is no published list of which pages on the internet are checkout pages, so the only way for Pikt to show up at the right moment is to be present and check.
What that code does on each page is narrow. It looks at the page you are on and asks one question: does this look like a checkout — is there a card-number field, or does the web address plus a real “place order” button plus a payment form point at a payment step? On the overwhelming majority of pages the answer is no. When the answer is no:
- nothing is sent to Pikt, and nothing is stored;
- no panel appears and you never see Pikt on the page;
- the code keeps watching that one page for up to about three minutes, in case a payment step loads in later (many stores build checkout that way), and then stops watching. That watching happens entirely on your device.
- it runs only on the main page, never inside embedded frames such as ads, and only on pages you open yourself.
Pikt does not build a history of the sites you visit, and the list of pages you open is never sent to us. Only a page that passes the checkout question above leads to anything leaving your device, and what leaves is described next.
What the extension reads from the page
- On a page that passes the checkout check above, the extension reads page content to identify the merchant, the purchase category, and an approximate purchase amount, and to locate the payment form fields. On every other page it reads nothing beyond what that check needs, keeps what it saw on your device, and sends nothing. It does not collect or transmit your browsing history.
What the extension sends to Pikt
- Recommendation request. To name your best card, the extension sends the merchant name or website domain and the approximate purchase amount to Pikt’s servers (
www.trypikt.com), authenticated with your signed-in Pikt session. We never receive the contents of the page, the other items in your cart, or any card number from this request. - Card-offer alerts. On a detected checkout, the extension may ask Pikt whether a tracked or commonly available offer matches the merchant and a card in your wallet. Soft alerts remind you to confirm or turn on the offer in your issuer’s app; they never turn an offer on for you. If you tap yes/no on “Did you have this offer?,” that verdict is sent to improve offer confidence for members.
- Sponsored recommendations. When an issuer pays to feature a card you already have for a matching category and that card ties your unpaid best earn for the purchase, the pick is labeled Sponsored in the UI and the unpaid best card stays available under Switch card. A clear unpaid winner is never replaced by a paid placement. The extension may send a placement attribution event to Pikt. Sponsors receive aggregate metrics only (for example impression counts); they do not receive your identity, browsing history, or card numbers. Pikt never injects affiliate links, promo codes, or cookies into the merchant checkout page.
- Usage events. When a recommendation is shown, accepted, switched, or declined, the extension records that event, associated with your Pikt account, to improve recommendation quality. These events contain no card number, CVV, or payment-card data.
- Optional feedback. If you use the thumbs up/down control, your rating and any optional comment are sent to Pikt (with merchant domain, recommended card name, approximate amount, and extension version) so we can improve the product. Feedback is never sold.
- Swipe Correct (optional). If you choose to report that a different card was used, that report is sent to help verify recommendations against real purchases. You initiate it; nothing is sent automatically from that control.
- If you are not signed in, the extension falls back to a generic, on-device category estimate and makes no personalized request.
What Pikt never sees
- There is no card vault. Pikt does not store, receive, or transmit your card number (PAN), expiry date, or CVV — on your device or on our servers — in any form, ever. There is no “save a card” step and nothing to back up.
- Chrome fills it, not Pikt. The extension names your best card and points at the card-number field, inside your own click, so Chrome’s own saved-card autofill (the cards you’ve saved at
chrome://settings/payments) can offer to fill it. Pikt never types, reads, or transmits the number.
Browser permissions we use
- Access to web pages. Chrome will tell you the extension can “read and change your data on all websites.” That is the page access described under “Where the extension runs” above: the code is present on every https page so it can spot a checkout, and does nothing on the rest.
- activeTab. So the toolbar popup, when you click it, can see which site the tab you are looking at is on.
- storage. To keep a small amount of on-device state — your login session, a per-site dismissal counter, a cached year-to-date badge total, and one-shot flags that let the popup show a single dismissible prompt right after a confirmed win, inviting you to rate the extension or invite a friend. Each flag clears the first time you open the popup, whether or not you act on it. Separately, on the merchant’s own page, the extension notes in that page’s temporary session storage whether you already dismissed the Swipe Correct prompt for that one recommendation, so it does not ask twice; that note disappears when you close the tab. One exception: when you dismiss Pikt on the same store three times, we send that store’s address and the date the quiet period ends to your Pikt account, so the same store shows as muted in your web settings and un-muting it there clears it here too. Nothing else here is sent to Pikt, and none of it is ever card data.
- Host access to
www.trypikt.com. So the extension can fetch your personalized recommendation, offer alerts, and related events from your own Pikt account. This is the only address the extension sends anything to; no other server, ours or anyone else’s, is contacted.
Your control
Uninstalling the extension permanently deletes the small amount of on-device state above. Pikt holds no copy of it, and never held a copy of any card number.
1b. Reservation Alerts (Android Notification Access)
On Android, you can optionally let Pikt read reservation alerts so it can warm up your best card before you arrive. This is off by default and uses Android’s system Notification Access permission, which you grant yourself in your device settings.
- Which apps we read. Only reservation notifications from Resy and OpenTable. Pikt ignores notifications from every other app; their content is never read.
- What we keep. From a matching alert we derive a single upcoming visit (the venue name and reservation time). We do not store the notification text itself beyond deriving that visit.
- Your control. Turn this off any time in Settings, or revoke Notification Access in your Android system settings. iOS does not support reading other apps’ notifications, so this feature is Android-only.
1c. Calendar & Email (Pre-Trip Reminders)
Pikt can optionally use your calendar and your email to prepare your best card before you arrive somewhere you have a reservation. Each source is a separate opt-in, off by default, and you can turn either off at any time. Pikt uses these as a hint to get ready early. It never claims to know where you are going, and a reminder still fires at reservation time even if your phone’s location is slow indoors.
- Calendar. When you turn this on, Pikt reads upcoming events that have a location to prepare card reminders before you arrive. Events without a location are ignored. We keep only the upcoming visit we derive (the place and time), not your calendar contents.
- Email (Gmail). When you connect Gmail, Pikt reads only reservation-confirmation emails from services like Resy and OpenTable (and airline itineraries) to find an upcoming visit. We don’t store your email content. We keep only the single visit (place and time) we derive from it. You can disconnect at any time, which removes Pikt’s access.
1d. Pikt Insights Program (Opt-In)
Pikt Insights is a completely optional program, separate from linking your bank account and separate from accepting our Terms of Service. Nobody is enrolled automatically. You may be offered the program once during onboarding and can join or leave at any time from Settings. If you choose to join, here is exactly what that means:
- What we use. Your spending patterns (merchant category, amount range, and card used), used only in anonymized, aggregated form. We do not use your name, email, or any other directly identifying information as part of the aggregated data set.
- What it’s used for. To help Pikt understand which offers and categories actually earn rewards for people, so your own recommendations get sharper and so we can build features like Community benchmarks. This is never a report about you individually, and it never leaves Pikt.
- We do not sell your data. Pikt does not sell reports built from your data, or your data itself, to advertisers, data brokers, researchers, or any other third party. If that ever changes for a specific, clearly described purpose, we will ask everyone already enrolled again before it applies to them — see “If this program changes” below. Grouped, in-app figures (like Community benchmarks) still clear two floors before they are ever shown to anyone: a group is only included if at least 25 different members are in it, and we will not compute one at all on fewer than 50 purchases.
- What you get. A one-time Pikt Cash credit for joining (the exact amount is shown in Settings before you join, and it is a single welcome credit, not a recurring payment), plus:
- Community benchmarks — grouped stats showing how your wallet’s earnings compare to other enrolled members. Hidden behind “not enough members yet” until at least 3 members have contributed.
- Sharper, more personalized picks — your history helps Pikt recommend better for you specifically, not just the average member.
- Early access to new Pikt features as we ship them.
- Coming soon: tracking more cards in your wallet and priority access to Pikt Bills subscription tracking. Not live yet — we will update this page when they are.
- Your control. Join or leave the program at any time from Settings. Leaving stops future collection immediately; it does not retroactively remove aggregated data already published in a report. You can also use “Do Not Sell or Share My Personal Information” in Settings, which has the same immediate effect.
- Age check. You must be 18 or older to join. We ask for your date of birth to confirm this, and we delete it if you leave the program. Your exact date of birth is never used for anything else, never shown to partners, and never stored on your main account record.
- Age range. If you agreed to the version of this program dated July 2026 or later, we also work out an age range from that date — a band such as 25–34 — and use it, alongside your spending categories, to improve which card Pikt suggests to you and to members at a similar life stage. We use the band, never the exact date. Members who joined under an earlier version are not included in this until they are asked again and agree; their existing choices continue to be honored exactly as made.
- If this program changes. When we expand what the program does, we do not apply the change to people who already joined. We show you what changed and ask again, and nothing new happens with your data unless you say yes. Saying no leaves everything exactly as it is and takes nothing away.
- Global Privacy Control. If your browser sends a Global Privacy Control (GPC) opt-out signal, we honor it automatically: the program is turned off for you and cannot be joined from that browser while the signal is active.
- If you say no. Declining is always respected. For California residents, if you decline we will wait at least 12 months before presenting the offer again.
1e. Pikt Copilot (Ask About Your Cards)
Pikt Copilot lets you ask questions in plain English about the cards you have added — which one to use for a purchase, why Pikt chose a card, how a welcome bonus is coming along, or whether a spending cap is close to running out. This section explains what happens to what you type.
Most questions never reach an AI model
Common questions are answered directly by Pikt’s own calculation engine using a fixed set of written responses. No third party is involved and nothing leaves our systems. Only questions our engine cannot match are sent to an AI model.
What is sent to the AI model, and what is not
When a question does go to an AI model, we send our third-party AI provider (Anthropic, which operates Claude) only:
- the question you typed;
- the display names, issuers, reward types, and everyday earn rates of the cards in your wallet;
- the results of the specific lookups needed to answer you — for example a reward rate, a dollar amount earned on the purchase you asked about, or how much is left on a welcome bonus.
We do not send your name, email address, account identifiers, card numbers or masked card numbers, balances, credit limits, credit utilization, or any individual transaction or transaction history. The AI model never receives your Plaid data and never sees anything that identifies you. It also performs no calculations: every figure in an answer is produced by Pikt’s own engine and is only phrased by the model.
We send this information to Anthropic for the sole purpose of generating your answer, and we do not permit it to be used for any other purpose, including model training. Anthropic is a service provider under Section 5. Pikt Copilot data is never sold, never shared for advertising, and never included in the optional Pikt Insights Program described in Section 1d.
Whether your conversations are stored
Where conversation logging is enabled, we retain the questions you ask and the answers you receive for up to 30 days, to diagnose incorrect answers and improve accuracy. Before a question is stored, we automatically remove long sequences of digits (such as card, account, or routing numbers) and email addresses. Stored conversations are included in your data export, are deleted when you delete your account, and are permanently deleted at the end of the retention period.
What Pikt Copilot cannot do
Pikt Copilot is informational only. It cannot move money, make a payment, change your settings, open or close a card, or access anything beyond the card information described above. It is not financial, tax, or investment advice, and it does not provide credit scores, credit reports, or approval odds.
2. Financial Data We Access Through Plaid
Pikt uses Plaid Inc. (“Plaid”) to connect your financial accounts. By linking an account, you also agree to Plaid’s End User Privacy Policy. The specific financial data we access, the purpose for each category, and our retention period are:
| Data Category | Purpose | Retention |
|---|---|---|
| Auth (account number, routing number) | Verify account ownership when you link an account | Duration of active account; deleted within 30 days of closure |
| Identity (account holder name, address) | Cross-reference against verified identity to prevent third-party account linking | Consumed in-memory at linking; not persisted |
| Balance (available balance, current balance) | Show current balances and credit used in your dashboard | Short-lived application cache only; not stored persistently |
| Liabilities (credit limit, statement balance, APR, utilization) | Factor credit health into card recommendations; display wallet health dashboard | Duration of active account; deleted within 30 days of closure |
| Transactions (merchant, amount, date, purchase category) | Infer per-card reward rate by purchase category; improve card recommendations; spot recurring bills; track sign-up-bonus progress; year-end tax export | 13-month rolling window, then automatically deleted. Purchases you tag for taxes or attach a receipt to are kept until you remove the tag or receipt. Everything is deleted within 30 days of account closure. |
All financial data is processed server-side. No Plaid access token, account number, or routing number is ever transmitted to your browser or mobile device. We do not request write access to any financial account.
3. How We Use Information
- to recommend the best card for each purchase — the one that earns the highest reward for that store and spending category. Pikt only recommends; you always choose which card to pay with;
- to maintain and update per-card reward rate catalogs based on your transaction history;
- to display wallet health metrics, utilization scores, and savings history in your dashboard;
- to provide, maintain, and improve the Service, including reward recommendations;
- to process subscriptions and billing;
- to send transactional and, where permitted, product communications;
- to secure the Service, detect fraud, and maintain audit records of sensitive actions;
- to comply with applicable legal and financial regulations.
We do not use your financial data for advertising, cross-selling unaffiliated products, data brokerage, or credit scoring unrelated to our Service.
4. How We Protect Financial Data
We treat financial data as sensitive and apply the following controls:
- Encryption at rest. Sensitive tokens are encrypted with AES-256-GCM before they are written to the database, using keys held in our hosting provider’s encrypted secret store and never committed to code. Disk-level encryption alone is not relied upon.
- Encryption in transit. TLS 1.3 enforced on all connections between our services, database connections, and partner notifications.
- Secure storage. Plaid access tokens stored in a dedicated encrypted vault. Tokens never appear in logs, error messages, or analytics pipelines.
- Server-side only. All Plaid token exchanges and financial data requests are executed exclusively on our servers. No financial credential is ever transmitted to your browser or mobile device.
- Least-privilege access. Decrypted financial credentials are read by the automated card-recommendation service. Access to production secrets is limited to the founder and protected by multi-factor authentication on our hosting accounts.
- Audit logging. All Plaid token exchanges are logged with a timestamp, pseudonymized user ID, action type, and success/failure status. Token values are never logged. Logs are retained for five years per CFPB Section 1033 open-banking recordkeeping requirements.
5. How We Share Information
We do not sell your personal information. We share information only with service providers that help us operate the Service, under contractual confidentiality and security obligations, including:
- Plaid. Financial account connectivity.
- Stripe. Subscription billing and payment processing.
- Clerk. Authentication and account management.
- Resend. Transactional and notification email delivery.
- Anthropic. AI model used to phrase Pikt Copilot answers, limited to the fields described in Section 1e. Anthropic receives no Plaid data, no account identifiers, and nothing that identifies you.
- Hosting & infrastructure providers. To run the Service.
We may also disclose information to regulators or law enforcement where required by applicable law, without prior notice to you where such notice is prohibited by law.
6. Data Retention
We retain your information for as long as your account is active or as needed to provide the Service. Specific retention periods for financial data are set out in Section 2 above. When you delete your account, we delete your personal data and associated records (linked cards, simulations, offers, and history), except where retention is required by law:
- Audit trail logs. Retained for 5 years per CFPB Section 1033 open-banking data requirements.
Pikt Copilot conversations. Where conversation logging is enabled, questions and answers are retained for a maximum of 30 days and then permanently deleted, as described in Section 1e. They are deleted immediately if you delete your account.
7. Security
We use industry-standard safeguards, including AES-256-GCM field-level encryption, TLS 1.3, server-side-only token handling, and reliance on vetted providers (Plaid, Stripe, Clerk) for the most sensitive data. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
8. Your Rights & Choices
- Access & update. View and edit your profile from Settings.
- Delete. Permanently delete your account and data from Settings → Account → Delete account, subject to the audit-log retention period described in Section 6.
- Disconnect financial accounts. Unlink cards at any time from Settings. Disconnecting revokes our Plaid access token for that account and removes it from card recommendations within 24 hours.
- Email preferences. Opt out of marketing emails from Settings → Notifications or via the unsubscribe link. Account, security, and billing notices may still be sent.
To exercise any of the rights below, file a request from Settings → Privacy & data → Make a privacy request. That records it against your account so the response clock is tracked. If you’d rather write to us, or you no longer have access to your account, email jesse@trypikt.com. Either way we will respond within 45 days. We will not discriminate against you for exercising your privacy rights.
8a. California Residents: CCPA / CPRA Rights
If you are a California resident, the California Consumer Privacy Act (“CCPA”) as amended by the California Privacy Rights Act (“CPRA”) gives you the following additional rights:
- Know. Request disclosure of the categories and specific pieces of personal information we have collected, the sources, the business purpose, and the categories of third parties with whom we share it.
- Delete. Request deletion of personal information, subject to the audit-log retention exception described in Section 6.
- Correct. Request correction of inaccurate personal information.
- Opt out of sale or sharing. We do not sell your personal information or share it for cross-context behavioral advertising. The only exception you can create yourself is the optional Pikt Insights Program (Section 1d), which uses de-identified, grouped data and which you can turn off at any time via “Do Not Sell or Share My Personal Information” in Settings. We also honor Global Privacy Control signals automatically.
- Financial incentive notice. The Pikt Insights Program is a voluntary financial-incentive program: enrolled members receive Pikt Cash as described at the point of opt-in. The value of the incentive is reasonably related to the value of the de-identified data described in Section 1d. You can join only by affirmative opt-in and can withdraw at any time from Settings, effective immediately.
- Limit use of sensitive personal information. We do not use sensitive personal information beyond what is necessary to provide the Service or satisfy our legal obligations.
How to submit a CCPA request. Email jesse@trypikt.com with subject line CCPA Privacy Request. Include your name, email address, and the specific right you wish to exercise. If you have a Pikt account, filing from Settings → Privacy & data is faster — it is already tied to your identity. We will verify your identity before processing and respond within 45 days.
8b. International Users (UK, EEA & Switzerland)
Pikt is built for U.S. credit cards and U.S. residents, but our website is not blocked anywhere, so people outside the United States can and do reach it. If you are in the United Kingdom, the European Economic Area, or Switzerland, this section applies to you and the UK GDPR / EU GDPR give you the rights described below. Pikt Rewards is the controller of your information, and you can reach us at jesse@trypikt.com.
Your information is processed in the United States
Pikt’s servers and every provider listed in Section 5 operate in the United States, so using Pikt means your information is transferred there. U.S. privacy law is not the same as the law where you live. For these transfers we rely on the Standard Contractual Clauses and equivalent safeguards in our providers’ data protection terms. You can ask us for more detail about those safeguards at any time.
Why we are allowed to use your data
- To give you what you signed up for. Running your account, connecting the cards you ask us to connect, working out your best card, and billing you if you subscribe. (Performance of our contract with you.)
- Because you said yes. The Pikt Insights Program, calendar and email access, Android reservation alerts, and marketing email all run on consent, are off until you turn them on, and you can withdraw at any time from Settings. Withdrawing stops future use; it doesn’t undo what was already done lawfully beforehand.
- To keep the service working and safe. Security, fraud prevention, debugging, and improving how well recommendations work. (Our legitimate interests, weighed against your rights.)
- Because the law requires it. Financial recordkeeping and responding to lawful requests. (Legal obligation.)
Your rights
You can ask us to give you a copy of your data, correct it, delete it, limit what we do with it, or hand it to another service in a portable format. You can object to processing we base on legitimate interests, and withdraw any consent you have given. To use any of these rights, email jesse@trypikt.com with subject line GDPR Privacy Request. We will confirm who you are and reply within one month. There is no charge.
Pikt does not make automated decisions about you that have a legal or similarly significant effect. Which card we suggest is a recommendation you are free to ignore, and you always choose the card you pay with.
If you are unhappy with how we handled it
Please tell us first — we would rather fix it. You also have the right to complain to your local data protection authority, or to the Information Commissioner’s Office in the UK. We are a small company and have not appointed an EU or UK representative under Article 27; requests come straight to us at the address above and we handle them ourselves.
9. Cookies
We use cookies and similar technologies for authentication, security, and to remember your preferences. You can control cookies through your browser settings, though some features may not function without them.
10. Children’s Privacy
The Service is not directed to children under 18, and we do not knowingly collect personal information from them. If you believe a child has provided us information, contact us and we will delete it.
11. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will provide notice through the Service or by email at least 30 days before changes take effect. The “Last updated” date above reflects the most recent revision.
12. Contact
Questions or requests regarding your privacy? Contact us at jesse@trypikt.com.