A subscription tracker needs three facts about each thing you pay for: what it's called, what it costs, and when it renews. Audible Premium, $14.95, the 3rd. Add a currency and maybe a note, and that's the whole job. You don't have to link a bank to get there.
Connect your bank to a tracker instead, and those three fields arrive inside a much bigger package. In a lot of US apps, the screen that asks for your bank username belongs to Plaid, the company behind the same step in Venmo, Coinbase and Cash App. Plaid publishes what it collects when you go through that screen. The policy is long and unusually specific, and almost none of it is anything a subscription tracker needs.
A bank link hands over your transaction history on a schedule, and deleting the app doesn't reliably end it. The real case for linking is finding the charges you forgot, and typing your subscriptions in has a real cost of its own. I'll take both head on.
What the bank link hands over
Plaid's policy lists what it may collect when you connect an account. Here it is next to what a tracker uses. The quotes here and below are from Plaid's End User Privacy Policy, effective December 8, 2025, as I read it on September 28, 2026.
| What Plaid's policy says it may collect | What a subscription tracker needs |
|---|---|
| "login data when required by the provider of your account, like your username and password, account and routing number, or a security token" | Nothing. It never has to sign in anywhere as you. |
| "Data about account transactions, including amount, date, payee, type, quantity, price, location, involved securities, and a description of the transaction" | The handful of charges that recur, not every pharmacy run and bar tab or where each one happened. |
| "Data about an account balance, including current and available balance" | Nothing. |
| The account owner's "name, email address, phone number, date of birth, and address information" | An email address to send the reminder to. |
| Data "from all accounts (e.g., checking, savings, credit card, and joint accounts) accessible through a single set of account credentials" | The one card your subscriptions are billed to. |
| "we may infer your geolocation, your annual income, or the type of account or subaccount you've chosen to connect" | Nothing. |
The joint-accounts row means that if you share a checking account with a partner, their spending comes along with yours, and they never saw the connect screen.
The inference row goes past storage. Plaid says it may work out things your bank never stated, like your income. One of its listed uses is to "develop insights based on the data we've collected about you," which "includes your transaction data, other financial data, data about which financial accounts you have connected to which apps." The stated purpose is to help Plaid, your bank and your apps "provide services and/or a better user experience to you," fraud detection included. That's a reasonable purpose, but notice what counts as input: the list of apps you've connected is itself data about you.
Then there's the schedule. A renewal date changes once a billing cycle. Plaid's developer docs say it checks for new transactions "typically between one and four times per day, depending on the institution," and a connection can pull "up to 24 months of transaction data." A bank link keeps pulling for as long as it stays connected.
That's Plaid's side. The tracker you connected gets your transactions too, under its own policy, and that policy isn't always the tracker's alone. Rocket Money's is the Rocket Family of Companies policy, effective July 1, 2026, one document covering Rocket Mortgage, Rocket Loans and Rocket Homes too, and the companies "use and share your information with each other." It counts "information about account balance" and "information about account transactions" among what a connection like Plaid brings in. It also says Rocket shares personal information "with our Partners or other third parties for their own services and marketing purposes," and, under California's definition of a sale, "sells" identifiers, commercial information and inferences to "Affiliate and non-affiliated third parties."
Plaid prints all of this openly. My objection is the fit: a three-field question, answered with your whole financial life and refreshed daily.
Deleting the app doesn't end it
Plaid's retention section says that when a developer removes your connection, "Plaid's systems are designed to automatically delete your personal data, subject to certain exceptions." Then it lists them. Plaid may keep your data if:
- "(a) you've established a connection with another developer's app through Plaid that is still active"
- "(b) Plaid needs your data to continue providing you with a Plaid product or service you requested"
- "(c) Plaid is required by law to keep your data"
- "(d) Plaid needs your data to help protect against or prevent fraud or protect privacy, provide support, or investigate misuse and misconduct"
- "(e) Plaid has aggregated, de-identified, or anonymized your data such that it cannot be reasonably reidentified"
- (f) Plaid asks to keep it and you specifically agree.
The deletion starts when the developer removes the connection, and uninstalling a tracker from your phone isn't the same thing. Under exception (a), one live connection anywhere else, such as a brokerage or a payment app, lets Plaid keep your information after you've dropped the tracker.
What the $58 million settlement changed
Five class actions against Plaid, consolidated in federal court in Northern California in 2020, alleged that it "uses consumers' banking login credentials to harvest and sell detailed financial data without their consent." Plaid settled. In July 2022 the court gave final approval to a $58 million fund for a class of roughly 98 million people: US residents whose accounts Plaid had reached with their bank login between 2013 and November 2021.
The cash is the less interesting half. As part of the settlement, Plaid agreed to:
- delete data retrieved by its Transactions product for users whose connected app had never asked for transaction data
- delete data for users it no longer had valid credentials for
- put Plaid Portal on its homepage
- minimize the data it stores from users' accounts
- expand its privacy policy with "more detailed information about Plaid's data collection, storage, use, sharing, and deletion practices"
The first term only makes sense if Plaid was holding transaction history on people whose apps never asked for it. The last one is the policy quoted all through this post, so some of the detail you just read is there because a settlement required it.
Check your connections today
If you're in the US, go to my.plaid.com. You verify a phone number and email, set a password, and get a dashboard of every financial account you've connected to an app through Plaid, with the types of data each app gets. From there you can cut a connection and delete the data Plaid holds for it.
Plaid Portal is US-only, and it only shows Plaid. If an app used a different aggregator, read that company's policy the same way.
The real case for linking
Nobody links a bank to learn what Netflix costs. They link to find the charge they forgot. Rocket Money's own pitch is that job: link your accounts and it "automatically scans your transaction history to spot recurring charges," then "continually monitors your accounts, so when a new subscription shows up you'll know about it immediately rather than discovering it months later." That's the thing a bank feed does that a manual tracker can't do for you, and it's the part of the argument the no-bank-login crowd tends to skip.
That discovery finds recurring charges, on the accounts you linked, under whatever name the statement gives them. The last two conditions are where it goes wrong.
Rocket Money's help page on missing subscriptions says its algorithms "may not detect a subscription if the associated financial account used to pay for the subscription is not linked properly," warns that Apple subscriptions "will appear differently because of how Apple bundles their subscriptions," and ends with the fallback: "you can add them manually in the mobile app." The bank-sync tool's answer to its own blind spot is a manual tracker.
The bundling is the big one. A feed sees statement lines, and a statement line isn't a subscription. Roku bills HBO Max and Paramount+ as "Roku." Apple bills every App Store subscription as apple.com/bill, and Rocket Money's own Recurring tab folds all of them into a single $2.12 line. PayPal does the same for anything you signed up for through it. From r/Frugal in June:
"It only found 4 subscriptions, and none of them can be canceled. I've signed up for like a dozen things, like 4 or so paid AIs, and it doesn't even detect separate Roku subscriptions, like my HBO max + Paramount Plus. It says Roku is costing me 47 cents a month but I know it's like $24 a month." — u/bigdonut100, r/Frugal, June 2026
It cuts the other way too: some subscriptions only show up on the statement. One r/iphone poster started an AI app's free trial on an iPhone, looked under Settings → Subscriptions, and found nothing: "Pingo wasn't listed there at all. [...] I thought there was no active subscription left for me to cancel." Then $99.99 from LINK.COM PINGO AI INC, billed through Stripe's Link and never through Apple. A bank feed would have flagged that line. So would a 90-day statement pull, and so would the email Link had sent with the trial's end date.
You can do that discovery yourself, once. The 30-minute subscription audit is the job with a clock on it: 90 days of statements, then the five places a statement can't see. In half an hour you read the same lines a feed reads and open the platform bundles a feed can't.
What the audit doesn't do is keep going, and that's where a feed has two real edges. Plaid can hand an app up to 24 months of transactions, enough to surface an annual renewal that a 90-day pull won't. And a feed catches the subscription you start next month without you lifting a finger, where a manual tracker needs you to add it. So a bank link runs the audit for you every day and sees each platform as one row it can't open, while a manual tracker makes you run it yourself, once and then each quarter if you're the type, and after that only knows what you told it. For everything already on the list, what moves between audits is the renewal date and, now and then, the price, and neither needs a daily pull of everything you bought.
The honest cost of not linking
Manual tracking has a failure mode that the "just use a spreadsheet" crowd waves away. This is from r/personalfinance in September:
"I'm in my 40s and have severe (but well-managed) ADHD. I've spent literal decades trying many, many different ways to create and stay consistent with a manual budgeting spreadsheet. After 20+ years of effort, I can say pretty definitively that I need to find a different method." — u/mixturesun, r/personalfinance, September 2026
For some people, the only tracker that gets used is one that fills itself in. A linked tracker you open every week beats a manual one you gave up on in week two. If that's you, link, and then use Plaid Portal to keep your list of connections short.
If you'd rather not link, here's what people who've made that call use. I read about 60 Reddit threads on subscriptions and budgeting from June to September, and the answers sort into three jobs.
A list you keep:
- A spreadsheet. One row per subscription with the name, price, renewal date and card. Free, yours, and it fails exactly the way that quote describes.
- Wallos, if you run a server. Open source, self-hosted, and the name r/selfhosted reaches for first. Your list never leaves your box.
- A manual tracker. RecurDash is one, and I build it. It only knows what you tell it. Over a spreadsheet it adds an email before each renewal and a monthly total in your own currency.
A habit instead of a list:
- Card alerts plus a weekly sit-down. Most card issuers will text or email you on every transaction. Filter those into a folder and enter the recurring ones once a week.
- A calendar reminder the day you sign up, set for a few days before the trial ends. Cheapest of the lot.
A budget, which is a bigger purchase:
- Actual Budget, self-hosted. Open source, and bank import is an option it works fine without.
- Double-entry software. GnuCash, or plaintext tools like hledger and Beancount. More setup, and the plaintext ones leave you a file you can still read in ten years. Pick one because you want a budget, not to track subscriptions.
My pick: a spreadsheet if you'll keep it up, Wallos if you already run a box, RecurDash if you want the reminder without running anything.
Whichever you pick, the hard part is the first list. The 30-minute subscription audit walks through where to look, including the places a statement won't show you.
What RecurDash collects instead
RecurDash doesn't link banks. Cost ruled it out first: Plaid is a paid API, and RecurDash is one developer. The policy above is why it stays out. A tracker shouldn't hold more about you than the job needs, and I couldn't print the list below next to Plaid's if it did.
Here's ours, as it stands on recurdash.com on September 30, 2026:
- What you type in. Each subscription's name, price, currency, billing cycle and next renewal date, plus a category, notes, a link or a trial end date if you add them. Stored in a database on a Hetzner server in Finland.
- Your account. Name, email and a hashed password, or your Google account if you use "Sign in with Google."
- Analytics (PostHog). Page views and clicks. Session recording is off, Do Not Track is respected, and anonymous visitors are counted without a person profile. Once you're logged in, PostHog gets your user ID, email, name and plan, and when you add a subscription it gets the billing cycle and whether it's a trial. Never the name or the price.
- Error monitoring (Nightwatch). Requests, errors and logs, so I can see what broke. When you're logged in, those carry your user ID, name and email. Request bodies aren't captured.
- Email (Resend). Reminders go out through Resend, so it sees your address and the email itself: the subscription's name, price and renewal date.
- Bot check (Cloudflare Turnstile). On the sign-up, login and password-reset forms. It sees your IP address and browser details during the check.
- Fonts (Google Fonts). Pages load their fonts from Google, so Google sees your IP address when a page loads.
- Payments (Paddle). Only if you buy Pro. Paddle is the merchant of record, so it handles your card and RecurDash never sees the number. Its checkout script loads inside the app.
What RecurDash never has: your bank login, your balance, any transaction you didn't type in, or your income.
Leaving takes two buttons on your profile page. One downloads everything as JSON, and the other deletes your account. The privacy policy commits to removing your subscription data from our servers within 30 days.
Audible Premium, $14.95, the 3rd. That's what a subscription tracker needs from you. Anything asking for more should be able to tell you why.
Before you close this tab, open my.plaid.com and disconnect the apps you've stopped using.