Trust Center
Security, privacy & data handling
This page is maintained by the Foremio team to answer common security and privacy questions about the Foremio contractor workspace. It describes the controls currently enabled in the application and the platform capabilities we rely on. It is editable project content, not an independent certification or third-party audit.
Shared responsibility
Foremio is built on the Lovable platform (which uses Supabase for database, authentication, storage, and serverless functions, and Cloudflare for hosting). Platform-level infrastructure controls are provided by those vendors. Application-level controls — account access, what data is collected, how long it is kept, and who it is shared with — are the responsibility of Foremio as the app owner. You, as a customer, are responsible for keeping your account credentials safe and for the accuracy of data you enter.
Access & authentication
Foremio supports email + password sign-in and Google sign-in. Passwords are never stored by Foremio directly — authentication is handled by the platform's managed auth service. Workspace membership and role-based access controls (owner, admin, member) gate access to projects, estimates, invoices, and team data.
Hosting & platform
The Foremio application is hosted on the Lovable platform. Server-side logic runs in a managed serverless runtime, and the database is a managed Postgres instance with row-level security policies that restrict each workspace's data to its own members.
Data we collect
Foremio stores the information you enter to run your contracting business: company profile, team members, clients, projects, estimates, invoices, expenses, calendar events, and the inputs and results of calculator runs. We also store the email address and basic profile metadata associated with your sign-in.
Subprocessors & integrations
Foremio uses the following third-party services to operate: Lovable (application hosting and platform), Supabase (database, auth, storage, edge functions), Cloudflare (edge delivery), and Stripe (payment processing for subscriptions). Google is used only when a user chooses to sign in with Google.
Cookies & analytics
Foremio uses cookies and local browser storage that are necessary to keep you signed in and to remember your in-app preferences (such as unit system and locale). We do not run third-party advertising trackers inside the authenticated product.
Retention & deletion
Data you create in Foremio is retained for as long as your workspace is active. You can delete individual records (clients, projects, estimates, invoices) from inside the app. To request deletion of your entire account and associated workspace data, contact us at the address below.
Privacy requests
If you would like to access, correct, export, or delete personal data that Foremio holds about you, contact us using the security contact below and we will respond within a reasonable timeframe.
Security & vulnerability contact
To report a suspected security issue or to ask a security question, email security@foremio.com. Please include steps to reproduce and avoid accessing or modifying other users' data while testing.
Compliance
Foremio does not currently claim SOC 2, ISO 27001, HIPAA, PCI, or GDPR certification. Payment card data is handled by Stripe and never stored on Foremio servers. If you need specific contractual or compliance commitments for your organization, contact us before subscribing.