Skip to content
CUNICULA

Privacy.com

KYC bank-linked virtual cards with spend limits and API/MCP controls for AI agents.

privacy.com

KYC bank-linked virtual cards with spend limits and API/MCP controls for AI agents.

Common useCapping AI-agent spendVirtual/Physical Card / Developer ToolsOperator dataHosted
Identity checksfull KYCDocument check: full · identity exposure level 4/4
Evidence and riskVerified evidenceCautionMaterial claims checked against current sources.; those sources show trade-offs worth reading.
Last reviewedReviewed 4 Jul 2026KYC checked 4 Jul 2026 · verified jurisdiction · Source → official siteHow to cite this pageEvidence confidence94/100
Evidence and facts

Evidence and facts

JURISDICTIONUS
CAUTIONStrong spend-control surface, weak identity privacy. Privacy.com, its issuing bank, linked bank account, merchants, API/MCP usage, and transaction logs remain in the payment data path. Use for card-number isolation and hard caps, not for no-KYC financial privacy.
AUDITED BYNo audit listed
OPERATOR DATAHosted operator recorded
EVIDENCE CONFIDENCE
THIRD-PARTY REPORTED1/8
Why evidence is 94/100Formula 3.1
Source coverageMaterial claims checked against current sources
+70
Review ageOldest recorded check is 50 days old
+24

Full scoring method

LAST CHECKED2026-07-04
LAST UPDATED2026-07-04

Specs

DOCUMENT CHECKfull
IDENTITY EXPOSURELevel 4/4
KYC TRIGGERSOfficial FAQ says personal information is required for mandatory KYC before using virtual cards. Developer docs say all end users must pass Customer Identification Program checks before they can transact.
FEEFree domestic personal plan; paid plans from $5/mo; Personal foreign transactions incur fees
NETWORKSVISA, MASTERCARD, ACH, API, MCP
CATEGORIESVirtual/Physical Card, Developer Tools, Private Payments, Agent Money
COMMON USESCapping AI-agent spend, Merchant-locked subscriptions, Reducing merchant card-number exposure
FEATURESVirtual cards, Single-use cards, Merchant-locked cards, Category-locked cards, Spend limits, Pause and close cards, Transaction listing, Developer API, +3 more
TORNot listed
REGIONS1 country: United States
Review analysis, source material, related services, and history
Agent payments

Spend controls and data exposure

Useful for bounding autonomous spend and isolating merchant card numbers, but not anonymous: KYC, US banking, issuer logs, API/MCP activity, and transaction metadata remain linkable.

Protocols
Virtual cardMCPMerchant API
Autonomy3 / scoped spend
CustodyIssuer custody
Approval
API keyMerchant lockCategory lockSession budget
Controls
APICLIMCPDashboard
Limits
Spend limitsYes
Merchant lockYes
Category lockYes
Pause / closeYes
WebhooksYes
Privacy
SettlementBank / Card
FundingBank linked
IdentityFull KYC
Logging riskHigh
RevocationStrong

This is the clearest agent-spend control rail in the set, but it is also the clearest identity-bearing rail: legal identity, linked bank funding, issuer records, card-network records, API/MCP logs, and merchant data all remain in scope.

Where payment data goes
  1. 1AI agent
  2. 2Privacy API/CLI/MCP
  3. 3Privacy.com
  4. 4Patriot Bank issuer
  5. 5linked US bank account
  6. 6card network
  7. 7merchant

About

US bank-linked virtual cards with merchant locks and spend limits, requiring KYC and a US checking account.

Analysis

OVERVIEW

Privacy.com issues merchant-locked and single-use virtual cards with spend limits, pause and close controls, and an API, CLI and MCP server for capping AI-agent payments, with card issuance running through Patriot Bank, N.A.

LIMITS

Mandatory Customer Identification Program checks apply before any card can transact, and the record describes this as a spend-control tool rather than a no-KYC privacy rail: identity, the linked US bank account, issuer records and transaction logs all remain in the payment data path.

USEFUL FOR

US residents wanting card-number isolation and hard spend caps, including for AI-agent purchases, rather than identity-free payment.

Sources · reviewed 2026-07-16

Corporate identity

Registry-sourced, not audited. The facts below come from cited web research rather than a direct registry query. Each claim links its own source.

LEGAL ENTITY
Lithic, Inc. (d/b/a Privacy.com)source ↗
INCORPORATED IN
Delawaresource ↗
REGISTERED ADDRESS
228 Park Ave S, PMB 57488, New York, NY 10003-1502, United Statessource ↗
Registry research · reviewed 2026-08-08

We wrote about this

Frequently Asked Questions

Is identity verification required?

The recorded KYC level is "full". Official FAQ says personal information is required for mandatory KYC before using virtual cards. Developer docs say all end users must pass Customer Identification Program checks before they can transact.

Which payment methods are accepted?

Accepted payment methods: VISA, MASTERCARD, ACH, API, MCP.

Where is it available?

Recorded availability: US.

Is the operator based in a Five Eyes country?

Yes. The recorded jurisdiction is US, a Five Eyes country (US, UK, CA, AU, NZ). This is jurisdiction context and does not by itself establish that a service is safer or less safe.

How are identity, operator, and evidence fields reported?

Identity exposure is level 4 of 4. A hosted operator is recorded. Jurisdiction is shown as context, not a safety verdict. Evidence confidence is 94/100 and recorded risk is caution.

Which payment networks are supported?

Accepted networks: VISA, MASTERCARD, ACH, API, MCP.

Related Services

Sources and history

Terms and privacy policy

No changes to the documents we watch since we started checking on 8 Aug 2026. Last checked 9 Aug 2026.

Evidence basis: Claims on this page are linked to published sources for comparison, not certification, audit, endorsement, or recommendation; read the methodology and coverage map before relying on an entry.