Security
Your bank access, handled with care
Pikt connects through bank-grade, read-only access via Plaid. We never store your raw card numbers or move your money.
Read-only by design
Pikt connects to your accounts through Plaid in read-only mode. We can see balances and rewards to pick your best card — we cannot move, send, or withdraw your money.
Bank-grade connections via Plaid
We never see or store your bank passwords. Plaid — used by thousands of fintech apps — handles the secure connection and tokenized access.
Encrypted end to end
All traffic is encrypted in transit (TLS) and sensitive tokens are encrypted at rest. Access tokens are scoped and revocable at any time.
You're in control
Disconnect a bank or delete your account at any time. When you do, we revoke the associated access tokens and remove your linked data.
Least-privilege access
Privileged operations run server-side behind authenticated APIs. Secrets never reach the browser or mobile app.
No surprise money movement
Pikt recommends and helps you use the best card you've added — it can never start a transfer, charge you, or open accounts. Any automatic-payment feature will always require your explicit consent.
What we store — and what we do not
We store
- • Tokenized card identifiers (not raw card numbers)
- • Spending categories and merchant types used to select your best card
- • Which card we selected for each purchase, and why
- • Account preferences and notification settings
We never store
- • Bank login credentials — those stay with Plaid
- • Full card numbers, CVVs, or PINs
- • Social Security Numbers or government-issued IDs
- • Real-time account balances — we read them when selecting your best card and do not retain them
The browser extension: on-device only
There is no card vault
- • Pikt never stores, receives, or transmits your card number, expiry, or security code — on your device or ours — in any form
- • Chrome fills it, not Pikt: we point at the card-number field on your own click, and Chrome's own saved-card autofill fills in whatever you've saved at chrome://settings/payments
- • There's no “save a card” step and nothing to sync
What the extension can access
- • Pikt's code runs on every page so it can spot a checkout, but it only reads and sends anything on a page that actually has a payment form — see the Privacy Policy for exactly what leaves your device
- • One connection: to trypikt.com — no other site can read what it sees
- • No bank credentials, ever — Plaid stays read-only, same as the web app
- • At checkout you may see a card offer — an issuer deal at that store on a card you already have. Whichever card we name, the best pick from your own wallet is always shown right alongside it, so you can see what we'd have said either way
How Pikt makes money — and how it doesn't
We do recommend cards, and we may be paid
- • Pikt recommends credit cards, including cards you don't have yet when your spending points to a real gap
- • If you apply for a card through Pikt, we may earn a referral fee from the issuer. It costs you nothing, and it's the same card on the same terms
- • A card issuer can also pay to have one of the cards already in your wallet shown as a sponsored pick for a category
- • Pro subscriptions are the other way we get paid
What money never buys
- • A sponsor can never buy its way into a wallet you don't have — a paid pick only ever surfaces a card you already carry, and only when it ties your unpaid best earn
- • A clear unpaid winner stays primary; on a sponsored tie the unpaid best card stays under Switch card so you can compare and ignore us
- • We don't sell your data, and we never show third-party ads
- • Full details are in our Disclosures
If something goes wrong
In the unlikely event of a security incident involving your data, we will notify affected users within 72 hours of discovery and give clear guidance on next steps. To report a security concern directly, email jesse@trypikt.com.
Testing, retention, and your rights
Penetration testing
Independent third-party testing is planned, not yet completed. We plan annual tests ahead of releases that touch authentication, payments, or bank connectivity. Summary findings will be available to qualified partners under NDA once testing completes.
Data retention
Linked-account data is kept only while your account is active. On deletion we revoke access tokens and purge personal data, keeping a minimal anonymized record only where tax or legal compliance requires it.
CCPA requests
Access and deletion requests are handled within 45 days at jesse@trypikt.com. A formal CCPA program review is underway. The opt-in Pikt Insights Program and exactly what it collects are covered in our Privacy Policy.
Request a security report
Evaluating Pikt for your organization? Request our security documentation. Penetration test summaries will be shared once testing completes.
Pikt is operated by Pikt Rewards. Have a security question or want to report a concern? Email jesse@trypikt.com.