Gift cards, top-ups and eSIMs bought with crypto.
Privacy.com
KYC bank-linked virtual cards with spend limits and API/MCP controls for AI agents.
privacy.com
- KYC: full
- US
- Evidence and facts →
KYC bank-linked virtual cards with spend limits and API/MCP controls for AI agents.
Evidence and facts
Evidence and facts
Why evidence is 94/100Formula 3.1
- Source coverageMaterial claims checked against current sources
- +70
- Review ageOldest recorded check is 50 days old
- +24
Specs
Review analysis, source material, related services, and history
Spend controls and data exposure
Useful for bounding autonomous spend and isolating merchant card numbers, but not anonymous: KYC, US banking, issuer logs, API/MCP activity, and transaction metadata remain linkable.
This is the clearest agent-spend control rail in the set, but it is also the clearest identity-bearing rail: legal identity, linked bank funding, issuer records, card-network records, API/MCP logs, and merchant data all remain in scope.
- 1AI agent
- 2Privacy API/CLI/MCP
- 3Privacy.com
- 4Patriot Bank issuer
- 5linked US bank account
- 6card network
- 7merchant
- Privacy.com homepageprovider
- Privacy agent controlscontrols
- Privacy MCP announcementprotocol
About
US bank-linked virtual cards with merchant locks and spend limits, requiring KYC and a US checking account.
Analysis
Privacy.com issues merchant-locked and single-use virtual cards with spend limits, pause and close controls, and an API, CLI and MCP server for capping AI-agent payments, with card issuance running through Patriot Bank, N.A.
Mandatory Customer Identification Program checks apply before any card can transact, and the record describes this as a spend-control tool rather than a no-KYC privacy rail: identity, the linked US bank account, issuer records and transaction logs all remain in the payment data path.
US residents wanting card-number isolation and hard spend caps, including for AI-agent purchases, rather than identity-free payment.
Corporate identity
Registry-sourced, not audited. The facts below come from cited web research rather than a direct registry query. Each claim links its own source.
- LEGAL ENTITY
- Lithic, Inc. (d/b/a Privacy.com)source ↗
- INCORPORATED IN
- Delawaresource ↗
- REGISTERED ADDRESS
- 228 Park Ave S, PMB 57488, New York, NY 10003-1502, United Statessource ↗
Frequently Asked Questions
Is identity verification required?
The recorded KYC level is "full". Official FAQ says personal information is required for mandatory KYC before using virtual cards. Developer docs say all end users must pass Customer Identification Program checks before they can transact.
Which payment methods are accepted?
Accepted payment methods: VISA, MASTERCARD, ACH, API, MCP.
Where is it available?
Recorded availability: US.
Is the operator based in a Five Eyes country?
Yes. The recorded jurisdiction is US, a Five Eyes country (US, UK, CA, AU, NZ). This is jurisdiction context and does not by itself establish that a service is safer or less safe.
How are identity, operator, and evidence fields reported?
Identity exposure is level 4 of 4. A hosted operator is recorded. Jurisdiction is shown as context, not a safety verdict. Evidence confidence is 94/100 and recorded risk is caution.
Which payment networks are supported?
Accepted networks: VISA, MASTERCARD, ACH, API, MCP.
Sources and history
Terms and privacy policy
No changes to the documents we watch since we started checking on 8 Aug 2026. Last checked 9 Aug 2026.
Evidence basis: Claims on this page are linked to published sources for comparison, not certification, audit, endorsement, or recommendation; read the methodology and coverage map before relying on an entry.