How Fincai handles your brokerage connection and your data
Fincai never receives or stores your Robinhood password. You authenticate on Robinhood's own site using OAuth 2.1 with PKCE, grant the permissions there, and can disconnect or revoke that authorization. Fincai stores the resulting authorization encrypted at rest and cannot deposit, withdraw, or transfer funds or securities.
What Fincai can read: after authorization, the connected agent can read the account information returned by Robinhood's Trading API, including live positions and portfolio value. It uses that information to display the portfolio, prepare manual order previews, and operate the trading tools the user requests. The exact OAuth scope labels are pending operator verification and are not invented here.
What Fincai can do: the connected agent can place equity orders. Manual trades prepared in the chat or terminal require explicit confirmation before they are sent. A live autonomous strategy is a separate authorization by the user: after the user opts a run into live mode, the runner can place and close orders automatically within configured limits.
What Fincai can never do: it cannot deposit, withdraw, or transfer money or securities; it does not receive a Robinhood password; and it implements no bank-link or funds-transfer feature. Its access is limited to the Trading API authorization granted by the user.
Fincai cannot deposit, withdraw, or transfer funds or securities out of your brokerage account. Fincai's access is limited to the permissions you grant during authorization, and you can revoke it at any time from your Robinhood account settings.
Fincai connects to Robinhood using the OAuth 2.1 authorization-code flow with PKCE and dynamic client registration — you authorize on Robinhood's own domain, never inside Fincai. The connection runs over the Model Context Protocol, and the OAuth callback URL is derived only from trusted server configuration, never from request headers, to prevent authorization-code redirection attacks.
OAuth tokens and the registered OAuth client information are stored encrypted at rest using AES-256-GCM, keyed by an HttpOnly session cookie, so the connection is durable across server restarts and is restored only when needed. Disconnecting — or an invalid or unrefreshable token — clears the stored record, and you can revoke Fincai's access at any time from your Robinhood account settings.
Data storage, retention, and deletion: brokerage OAuth tokens and registered client information are encrypted at rest and deleted when the user disconnects or when an authorization cannot be refreshed. The product stores account-scoped strategies, watchlists, conversations, and related records in its database. The complete retention schedule and deletion detail remain pending operator and counsel verification.
Can an AI agent lose money? Yes. A live trade can lose money, and an AI system can be incomplete or wrong. Market data can be delayed, software can fail, and connectivity can be interrupted. Paper defaults, confirmation-first manual orders, live opt-in, position and notional caps, market-hours checks, paused error states, and a kill switch reduce specific risks but do not eliminate loss.
New strategy runs use paper mode by default. Live autonomous trading requires a connected brokerage and an explicit per-run opt-in, is long-only in the current version, and can be paused or stopped. Fincai holds no third-party security certification such as SOC 2 or ISO 27001 at this time.
Fincai is not affiliated with, endorsed by, or sponsored by Robinhood Markets, Inc. Robinhood and the Robinhood logo are trademarks of Robinhood Markets, Inc. Fincai connects to your Robinhood account through Robinhood's official Trading API, only with your explicit authorization, and only for as long as you keep that authorization active.
Fincai is for informational purposes only and is not a registered investment adviser. It does not provide personalized financial advice. Trading stocks and options involves risk, including the possible loss of principal.
Not affiliated with or endorsed by Robinhood Markets, Inc.