Credit card rewards apps, compared by privacy label

Verified August 22, 2026 · copied from each app's App Store page that day

Every app on the App Store has to publish an App Privacy label. It is the developer's own declaration of what the app collects, whether it is linked to you, and whether it is used to track you across other companies' apps and sites. Apple prints it as written.

Below are the labels for four credit card rewards apps, side by side. I built RightCard, so read this knowing that. The table is facts only. Each row is copied from the App Store page linked under it, on the date above. If a label changes, this page is out of date, and the link is the source of truth.

Label sectionRightCardKudosMaxRewardsCardPointers
Data Used to Track You None listed Usage Data Contact Info
Search History
Identifiers
Usage Data
None listed
Data Linked to You Contact Info
Identifiers
Usage Data
Purchases
Contact Info
Search History
Browsing History
Identifiers
Usage Data
Diagnostics
Contact Info
Search History
Identifiers
Usage Data
Diagnostics
Contact Info
User Content
Identifiers
Data Not Linked to You Location Financial Info None listed Usage Data
Data types, total 4 8 5 4

Sources, read August 22, 2026: RightCard · Kudos · MaxRewards · CardPointers. "Data types, total" counts distinct data types across all three sections. Apple's own definitions of each type are on its App Privacy Details page.

How to read the three sections

Other facts from the same pages

RightCardKudosMaxRewardsCardPointers
PriceFreeFree, in-app purchasesFree, paid tiers described in listingFree, in-app purchases
Rating4.8 (18 ratings)4.7 (9.3K ratings)4.5 (17K ratings)4.7 (10K ratings)
Download size4.9 MB160.6 MB144.1 MB129.8 MB
How it reads your bank offersOn-device Safari extension on the bank's own offers page. No credentials.Listing describes connecting your cards and a Safari extension for checkout.Listing: "securely connects to your card account".Safari extension on the bank's offers page, per listing.
Desktop browser extension
checked September 17, 2026
Chrome, free. What it does.Chrome.Chrome and Firefox.Chrome.

The desktop extensions, by what they ask for

An App Store privacy label says nothing about a browser extension, so this row needs its own table. A Chrome extension's permissions are public: they are in the manifest, the store shows them at install time, and anyone can unzip the package and read them. These are RightCard's, stated plainly. For the others, read their own permission prompts at install; we are not going to characterise what a competitor's code does from the outside.

RightCard for Chrome asks forWhy
storageKeeps your offers and session on your own machine.
alarmsRetries a sync that was interrupted.
scriptingRegisters the reader on a bank page, and only while you are signed in to RightCard. Signed out, it is not registered anywhere.
Seven bank hostsamericanexpress.com, chase.com, citi.com, citibank.com, bankofamerica.com, wellsfargo.com, usbank.com. That is the entire list in the manifest.
activeTabReads the address of the tab you are on at the moment you click the icon, to answer "which of my cards has an offer here". It is not stored.
Not requested: tabsDeliberate. Without it the extension cannot see any other site's URL, even in the background.
Not requested: capitalone.comCapital One's offers are a click-through portal, so the extension does nothing there at all.

No bundler, no transpile step and no remote code: the package uploaded to the Web Store is byte-identical to the source in our repository, so what a reviewer reads is exactly what runs.

Ratings and sizes change daily. They are here for context, not as a score. Those three apps have far more users than RightCard and each does things RightCard does not, like bill negotiation, credit score monitoring, or a desktop checkout extension. This page is about one thing: what each app says it collects.

What RightCard's own label means

RightCard's label is not empty, and I would rather explain it than hide it.

The things that are not on the label are the point. No bank login. No Plaid or aggregator. No purchase history. No browsing history. No search history. No tracking.

If you want the full picture: the RightCard privacy policy spells out every piece of data in plain words, including what is stored server-side (your synced offers and card list, under an anonymous ID) and how to delete it.

Get RightCard on the App Store

FAQ

What is an App Store privacy label?

Every iOS app's App Store page has an App Privacy section. The developer declares which kinds of data the app collects, whether that data is linked to your identity, and whether it is used to track you across other companies' apps and websites. Apple publishes the declaration as written.

Which credit card rewards app collects the least data?

As of August 22, 2026, RightCard and CardPointers declare no data used for tracking and three data types linked to identity each. Kudos declares seven linked types including Browsing History, Search History and Purchases, plus Usage Data used for tracking. MaxRewards declares four types used for tracking and five linked types. Source: each app's App Store page.

Does RightCard require a bank login?

No. RightCard never asks for bank credentials and does not use an account aggregator. Bank offers are read from the bank's own web page in Safari by an on-device extension, and recommendations are computed on the phone.

Why does RightCard's label list Contact Info and Location?

Contact Info covers the email address on an optional account, used only for backup and sign-in. Location covers the optional nearby-offer alerts, which run on the device; the coordinate is not sent to RightCard's servers. Both are declared so the label errs on the side of disclosure.

Will this page be kept current?

I re-check the four listings when I update the page and print the date at the top. If you spot a label that changed, tell me and I will fix it.

More: RightCard privacy policy · All guides · Why didn't my grocery bonus post?