Trust & Security
This page is maintained by the Fin OS team to answer common security and privacy questions about the application. It describes practices currently in place; it is not an independent certification or audit.
Every Fin OS account requires an authenticated sign-in. Orchestra data — programs, schedules, rosters, leave requests, and dashboard preferences — is scoped per orchestra. Row-level security policies in the database enforce that signed-in users can only read or modify data belonging to their own orchestra, and write actions on shared resources (programs, schedules) are restricted to orchestra administrators.
Fin OS runs on Lovable Cloud, which provides managed application hosting, an authenticated database, and storage. Data in transit is protected with TLS.
Fin OS stores the operational data orchestra staff enter to run rehearsals, concerts, and substitute coverage: musician contact details, scheduling and attendance records, repertoire libraries, and supporting documents uploaded for leave requests. We do not sell this data.
Fin OS is built on the Lovable platform and uses its managed database, storage, and authentication services. Additional integrations are enabled per orchestra by an administrator.
Operational records are retained for as long as your orchestra uses Fin OS. Orchestra administrators can edit or delete records they manage from within the app. For account- or orchestra-wide deletion requests, contact us using the address below.
If you believe you have found a security vulnerability, please contact your Fin OS administrator or reach out to the maintainers so the issue can be triaged and fixed. Please avoid publicly disclosing details until a fix is in place.