Pikt credit card rewards
Your best card before you pay online.
Pikt estimates which card in your wallet is likely to earn the most. Issuers decide. You choose the card and pay as usual.
Pikt credit card rewards
Your best card before you pay online.
Pikt estimates which card in your wallet is likely to earn the most. Issuers decide. You choose the card and pay as usual.
Legal
Last updated: September 12, 2026
Current beta. Beta signup requires a beta code. This policy describes the Service as it operates today. Optional bank linking and transaction history are off until you choose them; card recommendations work when you add cards by name without sharing card numbers.
This Privacy Policy explains what Pikt Rewards LLC, a Delaware limited liability company (“Pikt,” “we,” “us”) collects when you use the Pikt website, applications, and services (the “Service”), what we do with it, and the choices you have. By using the Service, you agree to the practices described here.
We collect what we need to estimate which card in your wallet is likely to earn the most, and not much else. We never sell your data. We never see or store your card numbers. When we measure how Pikt is doing, we look at grouped, aggregated numbers — never a report on your individual spending, and our analytics tools never receive it. And everything optional — bank linking, the insights programs, checkout history — is off until you opt in.
We collect the following categories of information:
The optional Pikt Checkout browser extension provides rewards-card assistance on checkout pages you are already visiting: it estimates which card is likely to earn the most, points at the card-number field so your browser’s own saved cards can fill it, may show related card-offer reminders, and may show a clearly labeled sponsored pick of a card you already have. It never issues a card, never processes or moves money, and never sits in the middle of a payment. This section describes exactly what the extension reads, what it sends, and what stays on your device.
Where the extension runs
Once you install it, a small piece of Pikt code loads on every ordinary https web page you open — not only shopping sites, and not plain http pages. There is no published list of which pages on the internet are checkout pages, so the only way for Pikt to show up at the right moment is to be present and check.
What that code does on each page is narrow. It looks at the page you are on and asks one question: does this look like a checkout — is there a card-number field, or does the web address plus a real “place order” button plus a payment form point at a payment step? On the overwhelming majority of pages the answer is no. When the answer is no:
Pikt does not build a history of the sites you visit, and the list of pages you open is never sent to us. Only a page that passes the checkout question above leads to anything leaving your device — except the optional Swipe Correct answer described below, which you may send from the order page, and unexpected throws inside Pikt’s own packaged scripts — and what leaves is described next.
What the extension reads from the page
What the extension sends to Pikt
www.trypikt.com), authenticated with your signed-in Pikt session. The merchant name is a catalog label for known stores, a cleaned checkout page title on hosted payment pages, or — on a marketplace with no catalog name — a short “Sold by” label read from the page. We never receive the rest of the page, the other items in your cart, or any card number from this request.Checkout history (optional, separate consent)
Separately from everything above, you can choose to let Pikt keep a record of your own checkouts, so future recommendations are based on your own history instead of averages across all members. This is off by default. You are asked once, during onboarding or from Settings, and nothing is recorded until you turn it on.
What Pikt never sees
chrome://settings/payments) can offer to fill it. Pikt never types, reads, or transmits the number.Browser permissions we use
www.trypikt.com. So the extension can fetch your personalized recommendation, offer alerts, and related events from your own Pikt account, and so a crash in Pikt’s own packaged scripts can be reported. This is the only address the extension sends anything to; no other server, ours or anyone else’s, is contacted.Your control
Uninstalling the extension permanently deletes the on-device-only state above. Pikt does not hold a copy of that local state. The separate merchant-mute record described above is already part of your Pikt account and remains until you delete the account or request its removal. Pikt never held a copy of any card number.
When you remove the extension, Chrome opens one page on our site telling you it is gone and how to add it back. Opening that page adds one to a daily tally of removals (Section 1) — no cookie, no identifier, nothing that says who removed it. If you accepted analytics, it also records that the page was viewed, the same as any other page on our site. The page asks you nothing and we do not email you about it.
Pikt Personal is one optional program — the only one. You turn it on or you don’t. It is separate from linking your bank account and separate from accepting our Terms of Service, and nobody is enrolled automatically. You can join or leave at any time from Settings → Privacy & data.
What you get out of it. Pikt learns which cards actually earn the most for wallets like yours, so the card it names for you gets more accurate over time instead of leaning on averages across all members. Community benchmarks come with it, and a one-time free month of Pro when you join and connect a bank.
Pikt Copilot lets you ask questions in plain English about the cards you have added — which one to use for a purchase, why Pikt chose a card, how a welcome bonus is coming along, or whether a spending cap is close to running out. This section explains what happens to what you type.
Most questions never reach an AI model
Common questions are answered directly by Pikt’s own calculation engine using a fixed set of written responses. No third party is involved and nothing leaves our systems. Only questions our engine cannot match are even candidates for an AI model.
The AI model is opt-in, and off by default
Even for a question our engine cannot match, nothing is sent to Anthropic unless you have turned on “Share data with Pikt’s AI assistant” in Settings → Privacy. Until you turn it on, those questions get a direct answer that stays inside Pikt — no external model, and nothing described below leaves our systems. You can turn this off again at any time, and turning the universal “Do Not Sell” toggle on turns this off too.
What is sent to the AI model, and what is not
When a question does go to an AI model, we send our third-party AI provider (Anthropic, which operates Claude) only:
We do not send your name, email address, account identifiers, card numbers or masked card numbers, balances, credit limits, credit utilization, or any individual transaction or transaction history. The AI model never receives your linked-bank data and never sees anything that identifies you. It also performs no calculations: every figure in an answer is produced by Pikt’s own engine and is only phrased by the model.
We send this information to Anthropic for the sole purpose of generating your answer, and we do not permit it to be used for any other purpose, including model training. Anthropic is a service provider under Section 5. Pikt Copilot data is never sold, never shared for advertising, and never included in Pikt Personal (Section 1d).
Whether your conversations are stored
Where conversation logging is enabled, we retain the questions you ask and the answers you receive for up to 30 days, to diagnose incorrect answers and improve accuracy. Before a question is stored, we automatically remove long sequences of digits (such as card, account, or routing numbers) and email addresses. Stored conversations are included in your data export, are deleted when you delete your account, and are permanently deleted at the end of the retention period.
What Pikt Copilot cannot do
Pikt Copilot is informational only. It cannot move money, make a payment, change your settings, open or close a card, or access anything beyond the card information described above. It is not financial, tax, or investment advice, and it does not provide credit scores, credit reports, or approval odds.
Optional bank connections use Quiltt or Plaid, as named before you connect. Existing Stripe Financial Connections accounts may also be managed in Pikt. These providers receive the information you authorize under their own privacy notices: Quiltt Privacy Policy (opens in a new tab), Plaid End User Privacy Policy (opens in a new tab), and Stripe Privacy Policy (opens in a new tab). The data Pikt receives depends on your institution and permissions. The categories, purposes, and retention periods are listed below.
| Data Category | Purpose | Retention |
|---|---|---|
| Connection identifiers, encrypted Plaid access token, and last-four mask | Keep the read-only link alive; show which card is linked | Duration of the link; disconnect stops imports as described in Section 8; rows removed within 90 days of account closure |
| Balance (available balance, current balance) | Show current balances and credit used in your dashboard | Checking balance is cached in your account database record and refreshed when Pikt checks the linked account. Disconnecting clears this cached balance. |
| Liabilities (credit limit, statement balance, APR, utilization) | Factor credit health into card recommendations; display wallet health dashboard | Duration of active account; deleted within 90 days of closure |
| Transactions (merchant, amount, date, purchase category) | Infer per-card reward rate by purchase category; improve card recommendations; spot recurring bills; track sign-up-bonus progress; year-end tax export | 13-month rolling window, then automatically deleted. Purchases you tag for taxes or attach a receipt to are kept until you remove the tag or receipt. Everything is deleted within 90 days of account closure. |
All financial data is processed server-side. No bank-provider access token, account number, or routing number is ever transmitted to your browser or mobile device. We do not request write access to any financial account. We request only the balance and transaction-history products needed to create the link. We do not request account and routing numbers or an identity-verification product on the card-link path, and we do not store account numbers or routing numbers. If we later offer a regulated card and need identity verification, that flow will be described here before it launches.
We do not use your financial data for advertising, cross-selling unaffiliated products, data brokerage, or credit scoring unrelated to our Service. And when we measure how the Service is doing overall, we use grouped, aggregated reporting: internal dashboards show a group only when it is large enough that no single member stands out, and our analytics tools never receive your individual purchases (Section 5).
Pikt’s recommendation engine is our product. If you have set your data dial to “Improve Pikt” or turned on Pikt Personal, the recommendation outcomes you generate help train the models behind it — and we may license that technology to partners so their products can offer card recommendations powered by Pikt. Age-range features train only on Pikt Personal grants recorded under the July 2026 or later program terms described in Section 1d. Here is exactly what that does and does not mean:
We treat financial data as sensitive and apply the following controls:
This is not anonymization.
One honest note on wording, because it does real work in a privacy policy. We would rather not call the coded IDs something they are not. The code can be matched back to you — that is exactly what lets you open your own activity history and download a copy of your own data — so your spending is still your personal information, and we handle it as such. What the coding gives you is that the match can only be made inside Pikt, with a key that never sits next to the data.
Day to day, nobody at Pikt is reading any of it. The matching happens automatically, inside the app, so that your own history is there when you open it. The only time a person at Pikt would look at an individual member’s spending is where the law requires it, which Section 5 describes.
If Pikt is involved in a merger, acquisition, financing, or sale of some or all of its assets, your information may be transferred as part of that transaction. We will provide notice — through the Service or by email — before your information is transferred and becomes subject to a different privacy policy, and the protections in this policy continue to apply until that happens.
We retain your information for as long as your account is active or as needed to provide the Service. Specific retention periods for financial data are set out in Section 2 above. Website deletion requests have a 14-day recovery period after email confirmation. Permanent deletion follows within 90 days unless a legal hold applies. Deleting from the iOS or Android app instead starts permanent deletion immediately, with no recovery period, as described in Section 8. Deletion removes personal data and associated records (linked cards, simulations, offers, and history), with the following retention exceptions:
Deleting your account does not delete analytics events already recorded. Once you are signed in, those events are labelled with your account identifier, so we want to be straight about this rather than imply they vanish: they stay until they age out on the 12-month schedule above. They carry no spending, no merchant, and no amount. If you want them removed sooner, ask us and we will do it — Settings → Privacy & data → Make a privacy request, or email support.
Pikt Copilot conversations. Where conversation logging is enabled, questions and answers are retained for a maximum of 30 days and then permanently deleted, as described in Section 1e. They are deleted immediately if you delete your account.
Pikt uses HTTPS to protect data sent between your browser and our service. Stored Plaid access tokens and dates of birth use AES-256-GCM encryption. These controls do not mean that Pikt has completed a security certification. Our providers also process data under their own privacy notices. No method of transmission or storage is completely secure.
To exercise any of the rights below, file a request from Settings → Privacy & data → Make a privacy request. That records it against your account so the response clock is tracked. If you’d rather write to us, or you no longer have access to your account, email [email protected]. Either way we will respond within 45 days. We will not discriminate against you for exercising your privacy rights.
If you are a California resident, the California Consumer Privacy Act (“CCPA”) as amended by the California Privacy Rights Act (“CPRA”) gives you the following additional rights:
How to submit a CCPA request. Email [email protected] with subject line CCPA Privacy Request. Include your name, email address, and the specific right you wish to exercise. If you have a Pikt account, filing from Settings → Privacy & data is faster — it is already tied to your identity. We will verify your identity before processing and respond within 45 days.
Pikt is built for U.S. credit cards and U.S. residents, and the Service is not offered outside the supported U.S. region. We use the network country reported for a request to block requests that appear to come from elsewhere. This check does not prove where a person lives, and it does not decide which privacy laws or rights apply.
The Service is not for people under 18. If someone tells us they are under 18, we refuse product access and do not keep the age or a derived birth date. The account identity and a limited security record of the rejected attempt may remain under Section 6 until the account is deleted. If you believe a child created an account, contact us so we can review and delete the account through that process.
We may update this Privacy Policy from time to time. If we make material changes, we will provide notice through the Service or by email at least 30 days before changes take effect. The “Last updated” date above reflects the most recent revision.
Questions about your privacy, or a request this page didn’t cover? Email us at [email protected]. Use the contact form if you prefer not to email. Pikt Rewards LLC, 126 Melrose Street, 3L, Brooklyn, NY 11206, United States · 401 702 7458.