Reviewed Jun 2026 · policies are checked weekly for changes · stated — every cell is read from American Express's published policy; none has been tested (run by us) yet.
1Sells / sharesstated
Amex states "We do not sell personal information" but expressly shares data for cross-context behavioral advertising with a "Do Not Sell or Share" opt-out link and Global Privacy Control support; its GLBA notice separately confirms it shares with affiliates and for joint marketing by default (only creditworthiness/affiliate-marketing sharing is opt-out-able), so sharing is scored at the shares-with-opt-out level.
Amex — California Privacy Notice §3/§6 + U.S. Consumer GLBA Notice (Rev. 3/2024) · accessed Jun 2026 ↗
2API access — feeds Agent Readiness, not the /12stated
Amex operates a real customer-permissioned Open Banking / Account Financials API using OAuth2, OpenID Connect and Financial-grade API (FAPI) standards, letting you grant and revoke third-party app connections (via Plaid, MX, Akoya) without sharing your Amex password; access is aggregator-mediated rather than a first-party consumer developer key, but is genuinely consumer-directed, tokenized and manageable. (Context: the CFPB Section 1033 open-banking rule is currently enjoined and under reconsideration, so this access is voluntary/contractual, not mandated.)
Amex — Developer Open Banking portal (page CSS-only; OAuth/FAPI + Plaid details corroborated via secondary sources) · accessed Jun 2026 ↗
Reviewed Jun 2026 from American Express's own California Privacy Notice (effective Feb 19, 2026) and U.S. Consumer GLBA Privacy Notice (Rev. 3/2024), which were read in full, plus corroborating secondary sources where amex.com pages returned CSS/JS-only to automated fetch (transaction-export formats, AI/ML language, and the Open Banking OAuth/FAPI details). All cells "stated", not tested. Amex is a regulated financial institution, so its transaction core is legally retained under financial-recordkeeping law and its deletion score reflects that floor.