I haven't heard any reports of Plaid doing bad stuff with user transaction data, so I suspect there's a bit of paranoia in the comments here.
On the other hand, there's an underlying (and valid) concern that handing over bank credentials to a third party is risky and, even assuming good faith from Plaid, they have to store passwords on their servers somehow (probably encrypted).
Since they make money from integrations with startups/big banks, there is definitely a conflict of interest between keeping user credentials safe and growing their revenue.
I think as a whole, relying on a modern company which specializes in authentication is better than trusting that thousands of app developers, some of which might big legacy banks with woefully understaffed IT departments, will keep your credentials safe. I'm aware that I'm more optimistic than most people in this thread (and on HN) though.
Here's a stackexchange question with some good discussion about Plaid security:
https://security.stackexchange.com/questions/198005/is-plaid...
Here's a github issue on Plaid's repo, showing that they are at least considering oauth on their roadmap:
https://github.com/plaid/link/issues/68
And here's Plaid's page on security, which is frankly short and a bit vague:
https://plaid.com/security/