1. What We Collect
- ›Email address — Required to create your account and communicate with you.
- ›Robinhood OAuth access token — A short-lived token issued by Robinhood after you authorize the connection. Used exclusively to read your Agentic account data and submit orders you approve. Never stored in plain text — encrypted at rest in our vault.
- ›Paper trading activity — Trade history, positions, and cash balance from the free paper trading mode, stored only in your browser's localStorage. We do not transmit or store this on our servers.
- ›Usage data — Standard server logs including page visits, API calls, and error events. Used for debugging and improving the Service. Not sold or shared with third parties.
- ›Billing data — Handled entirely by Stripe. We never see or store your full card number.
2. What We Do Not Collect
We never collect your Robinhood password, Social Security number, bank account numbers, or the contents of your Individual or IRA Robinhood accounts. Our API access is scoped exclusively to the Agentic account you explicitly authorize.
3. How We Use Your Data
- ›To provide the Service — connecting to your Robinhood account, running agent scans, and displaying proposals.
- ›To send transactional emails — account confirmation, billing receipts, and critical security notices.
- ›To improve the Service — analyzing aggregated, anonymized usage patterns.
- ›To comply with legal obligations.
4. Data Sharing
We do not sell your personal data. We share data only with:
- ›Supabase — Authentication and database hosting. Data is encrypted at rest and in transit.
- ›Stripe — Payment processing. Subject to Stripe's privacy policy.
- ›Robinhood — Via the Agent API for the express purpose of executing actions you approve.
- ›Law enforcement — Only when required by valid legal process.
5. Data Retention
We retain your account data for as long as your account is active. If you delete your account, we will delete your personal data within 30 days, except where retention is required by law.
Robinhood OAuth tokens are revoked when you disconnect from within Robinhood's Security & Privacy Settings. We delete our copy within 24 hours of detecting a revocation.
6. Your Rights
You may request access to, correction of, or deletion of your personal data at any time by emailing support@marketcaptn.com. We will respond within 30 days. Users in the EU/EEA have additional rights under GDPR.
7. Security
OAuth tokens are encrypted at rest using AES-256. All data is transmitted over TLS. Every API endpoint that reads or modifies your account data requires authentication, and order placement is additionally rate limited. No security system is perfect — please report vulnerabilities responsibly to security@marketcaptn.com.
8. Cookies
We use session cookies for authentication (via Supabase) and no third-party tracking cookies. We do not use advertising cookies or analytics pixels.
9. Changes to This Policy
We will notify you by email of material changes to this policy at least 14 days before they take effect.
10. Contact
Privacy questions: support@marketcaptn.com