Trust & Security

How we protect your orchestra's data

This page is maintained by the Fin OS team to answer common security and privacy questions about the application. It describes practices currently in place; it is not an independent certification or audit.

Access & authentication

Every Fin OS account requires an authenticated sign-in. Orchestra data — programs, schedules, rosters, leave requests, and dashboard preferences — is scoped per orchestra. Row-level security policies in the database enforce that signed-in users can only read or modify data belonging to their own orchestra, and write actions on shared resources (programs, schedules) are restricted to orchestra administrators.

Hosting & platform

Fin OS runs on Lovable Cloud, which provides managed application hosting, an authenticated database, and storage. Data in transit is protected with TLS.

Data we collect

Fin OS stores the operational data orchestra staff enter to run rehearsals, concerts, and substitute coverage: musician contact details, scheduling and attendance records, repertoire libraries, and supporting documents uploaded for leave requests. We do not sell this data.

Subprocessors & integrations

Fin OS is built on the Lovable platform and uses its managed database, storage, and authentication services. Additional integrations are enabled per orchestra by an administrator.

Retention & deletion

Operational records are retained for as long as your orchestra uses Fin OS. Orchestra administrators can edit or delete records they manage from within the app. For account- or orchestra-wide deletion requests, contact us using the address below.

Reporting a security issue

If you believe you have found a security vulnerability, please contact your Fin OS administrator or reach out to the maintainers so the issue can be triaged and fixed. Please avoid publicly disclosing details until a fix is in place.