When you connect a bank to an AI finance app or assistant, two companies usually handle your data: the aggregator (most often Plaid) and the app you connected. Plaid’s privacy policy covers account and routing numbers, balances, transactions and investments. What the app keeps, whether your chats train its models, and how fast deletion happens depend on each company’s own documents. We compared ChatGPT, Claude, Gemini, Plaid, Monarch and YNAB below, quoting the documents as dated.
How we checked this
We read nine official privacy documents and help pages: OpenAI’s Finances in ChatGPT help article and Data Controls FAQ, two Anthropic privacy center articles, Google’s Gemini Apps Privacy Hub, Plaid’s End User Privacy Policy and a Plaid consumer help article, and the privacy policies of Monarch and YNAB. Each is linked below with its date. The table only uses what those documents say, with no guesses or marketing claims. Facts checked on September 24, 2026.
This is educational material about how these services describe their data handling. It is not legal advice. If you need to know your rights under a specific state or national privacy law, a privacy lawyer or your state attorney general’s consumer office is the right place to ask.
The comparison table
Each cell is taken from the company’s own page.
| Tool | What data it gets | Retention | Used for training? | How to delete |
|---|---|---|---|---|
| ChatGPT (Finances) — help page, shown as “Updated: 3 days ago” on Sept 24, 2026 | Via Plaid: balances, spending by category, bills, subscriptions, net worth, investments, holdings. Some banks share balances “but not full transaction history, investment holdings, loan details, APRs, due dates, or other fields.” Plus “financial memories” you choose to share | Synced account data deleted “within 30 days” of disconnecting | Finances chats “follow the same model training settings you choose across ChatGPT.” To stop it, turn off “Improve the model for everyone” (Data Controls FAQ) | Disconnect Finances or remove an account; delete financial memories from the Finances page |
| Claude (consumer) — training article, Mar 16, 2026; retention article, Jul 1, 2026 | Data reaches Claude through what you type or paste, or through connectors and MCP servers you add | Deleted chats: removed from history right away, deleted from back-end storage “within 30 days.” If Model Improvement is on: de-identified data kept “for up to 5 years” in training pipelines. Safety-flagged: inputs and outputs up to 2 years | Only if you allow it via “Model Improvement” (or if a chat is flagged for safety review). “Raw content from connectors (e.g. Google Drive), including remote and local MCP servers” is excluded, but content “directly copied into your conversation” can be included | Delete the conversation; turn off Model Improvement; use Incognito chats |
| Gemini Apps — Privacy Hub, last updated Aug 10, 2026 | Prompts, chats, files you share, and “Information from your Connected Apps.” | Keep Activity default: “auto-deleted after 18 months” (options: 3 or 36 months, or no auto-delete). Activity off: kept 72 hours. Human-reviewed chats: “up to three years” | Yes, “including training generative AI models,” and a subset of chats is read by human reviewers. With Keep Activity off, future chats “won’t be used to train our AI models” | Turn off Keep Activity, change auto-delete, delete activity |
| Plaid — End User Privacy Policy, effective Dec 8, 2025 | Account name, type, ownership, account number, routing number, balances, transactions, credit and loan details, investments, identity data, payroll and tax information | Kept “only as long as it is needed”; auto-deletion when an app removes the connection, with exceptions (legal, fraud, anonymized data) | Policy lists using data to “develop, train, test, and deploy artificial intelligence (AI) systems” | Plaid Portal (my.plaid.com) or Plaid’s privacy request form |
| Monarch — privacy policy, effective Aug 10, 2026 | “Transaction and balance information” via Plaid, Finicity, MX or Spinwheel. Does not receive your bank login | “As long as necessary to provide you with our Services” | Policy says it uses “vendors, such as OpenAI, to power portions of the Services, including AI Services” | Email support@monarch.com; backups “can take longer” |
| YNAB — privacy policy, effective Apr 20, 2026 | “Account balances, transactions and holdings” via bank data vendors including Plaid and MX | “Majority of your account data for up to 24 months after your subscription or trial expires”; support conversations up to 3 years | Its chatbot vendor “will not train AI models on your personal or financial data.” | Data Subject Rights Request form or privacy@ynab.com |
Read the table in two layers. The Plaid row is the aggregator, the pipe your bank data travels through. The other rows describe what the app on the other end does with it. When you link through Plaid, both rows apply to you.
What does the aggregator hand over?
Plaid’s End User Privacy Policy (effective December 8, 2025) lists what it can collect from your bank: “Account data, including financial institution name, account name, account type, account ownership, branch number, IBAN, BIC, account number, routing number, and sort code,” plus balances, credit and loan details, investments, transactions, identifiers for the account holder, and payroll and tax information. That list is what Plaid may collect. It is not a promise that all of it reaches every app, because the app requests specific data products and your bank decides what it shares.
The app-side documents are narrower. OpenAI’s Finances help page describes ChatGPT working with spending by category, bills, subscriptions, net worth, investments, portfolio allocation, holdings and balances. It also warns that coverage varies: “an institution may share balances but not full transaction history, investment holdings, loan details, APRs, due dates, or other fields.” Monarch’s policy says it receives “transaction and balance information” through Plaid, Finicity, MX or Spinwheel and that “At no point will we receive your login information to any of your financial accounts.” YNAB’s policy names “account balances, transactions and holdings.”
Claude and Gemini are different. Bank data reaches them when you paste it, upload a file, or add a connector. Google’s Privacy Hub says Gemini collects “files, videos, screens you ask about, photos” you share and information from Connected Apps. So a CSV export you upload counts as chat content. It falls under the same retention and training rules as everything else you type. Our Claude MCP connectors guide covers which connectors exist for Claude.
Is my data used for model training, and can I opt out?
The answers differ more here than anywhere else.
ChatGPT. Finances conversations “follow the same model training settings you choose across ChatGPT,” according to the help page. OpenAI’s Data Controls FAQ puts the switch at Settings > Data controls > “Improve the model for everyone.” The FAQ is written around turning it off: “When Improve the model for everyone is off, your new conversations won’t be used to train OpenAI models.” Note the word “new”: turning it off does not reach back to earlier chats. Business, Enterprise and Edu workspaces are not used for training by default.
Claude. Anthropic’s training article (March 16, 2026) says consumer chats are used when “You choose to allow us to use your chats and coding sessions to improve Claude,” when a conversation is flagged for safety review, or when you join a program such as the Trusted Tester Program. The control is “Model Improvement” in Privacy Settings. The article also excludes “raw content from connectors (e.g. Google Drive), including remote and local MCP servers” from training, “though data may be included if it’s directly copied into your conversation with Claude.” In practice, if a finance connector pulls your transactions, that raw feed is excluded. If you paste the same transactions into the chat, the exclusion does not cover them.
Gemini. The Privacy Hub (August 10, 2026) says Google uses Gemini data “to provide, develop, and improve its services (including training generative AI models),” and that “A subset of chats are reviewed by human reviewers.” Turning off Keep Activity means “Your future chats won’t appear in your Activity, and won’t be used to train our AI models.” For Connected Apps, Gemini “saves and uses info from Connected Apps according to this notice, including to provide and improve Gemini Apps.”
Plaid. The aggregator’s own policy lists using data to “develop, train, test, and deploy artificial intelligence (AI) systems,” as well as creating “aggregated, de-identified, or anonymized data.” The practical control is limiting which apps you connect and deleting data through Plaid Portal.
Monarch and YNAB. Monarch says it uses “vendors, such as OpenAI, to power portions of the Services, including AI Services.” YNAB is more specific about one part: “Our chatbot vendor will process your data according to our instructions and will not train AI models on your personal or financial data.”
What is deleted when I disconnect, and when?
ChatGPT and Plaid (for the ChatGPT connection). OpenAI’s help page gives the clearest statement we found: “When you disconnect Finances or remove a connected account, synced account data is deleted from OpenAI’s systems within 30 days, and data associated with that ChatGPT connection is deleted from Plaid within 30 days.” Financial memories are separate. You delete those yourself from the Finances page. Disconnecting does not remove chats in which you discussed your finances. Those follow ChatGPT’s normal chat rules. Our ChatGPT and Plaid guide walks through the revoke steps.
Claude. Deletion is about chats. Anthropic’s retention article (July 1, 2026) says a deleted conversation is “Removed from your chat history immediately” and “Deleted from our back-end storage systems within 30 days,” and “if you delete a chat from your chat history, it will not be used to train future models.” There are two exceptions. If Model Improvement is on, “We may retain your data in a de-identified format for up to 5 years in our model training pipelines”. Safety-flagged content keeps inputs and outputs “for up to 2 years.”
Gemini. Deletion runs through activity controls. The default auto-delete is 18 months. Chats held with Keep Activity off are “retained with your account for 72 hours.” Human-reviewed chats “are retained for up to three years.” Because that three-year period is listed separately from the auto-delete options, do not assume that changing auto-delete shortens it.
Plaid directly. Plaid’s help article (no date shown) says Plaid Portal lets you “view and manage the connections you’ve made using Plaid, as well as delete your financial data from Plaid’s systems,” and that “Plaid may retain some information after the completion of the data deletion request, as permitted or required by applicable law.” Whether an app keeps data it already received depends on the app’s own policy, which is why you usually need two steps: disconnect or delete in the app, and delete in Plaid Portal.
Monarch. Deletion is by email to support@monarch.com. The policy warns that “Deletion from backup and archived systems can take longer” and that closing an account “does not erase every copy of your information from our systems.”
YNAB. YNAB keeps “the majority of your account data for up to 24 months after your subscription or trial expires.” You can ask for deletion through its Data Subject Rights Request form or privacy@ynab.com.
Which tool is the most conservative?
No single tool wins on every column, so the answer depends on the question. (For how these tools compare on features rather than privacy, see our AI money tools hub.)
- Clearest deletion clock after disconnecting a bank: ChatGPT Finances. It is the only app document we read that gives a number of days for both its own systems and Plaid’s.
- Least training exposure, going by the documents: Claude excludes raw connector and MCP content from training even with Model Improvement on, and uses chats only if you allow it. YNAB is the only finance app that says in writing that its chatbot vendor will not train on your financial data.
- Longest stated retention: YNAB (up to 24 months after your subscription ends), Gemini (18 months by default, up to three years for reviewed chats) and Claude (up to five years, de-identified, if Model Improvement is on).
Whatever app you choose, Plaid’s policy applies on top of it if Plaid is the connection. That includes Plaid’s own stated use of data to train AI systems.
Where it goes wrong
Disconnecting only one side. Removing an app in Plaid Portal and deleting the app account are separate actions. Do both, and keep a note of the date.
Pasting instead of connecting. In Claude, connector content is excluded from training but pasted content is not. In Gemini, an uploaded bank statement is just a file you shared. Pasting a statement “just once” puts it under the more permissive rules.
Assuming “off” reaches back in time. OpenAI’s wording is “new conversations.” Gemini’s is “future chats.” Turning training off after you have already discussed your finances does not undo earlier use. Delete the older chats as well.
Forgetting memories. ChatGPT’s financial memories are a separate store with their own delete control. Disconnecting accounts does not delete them.
Human review. Gemini states that trained reviewers read a subset of chats and keep them up to three years. If a chat contains your account details, assume a person may see it.
Documents change. OpenAI’s help pages had been updated within days of our check. Monarch’s policy took effect August 10, 2026. Re-read the page before you connect, and compare its date with the ones above. For general account hygiene, see our 12-point account protection checklist.
Go deeper
- AI money tools, our hub for this cluster
- How to connect your bank to ChatGPT (Plaid): what it sees, how to revoke
- Claude for personal finance: the MCP connectors that work in 2026
- Richify vs Monarch vs YNAB: which AI budgeting app actually understands your spending
- Best AI personal finance assistants (2026)



