This page is maintained by the FigWize team to answer common questions about how the app handles security, privacy, and your data. It describes practices currently in place and is not an independent certification.
Sign-in is handled by managed authentication. Passwords are never stored by FigWize in plaintext, and sessions use short-lived tokens that refresh automatically.
Google sign-in is available alongside email/password. You can delete your account from the Account page at any time.
Each user's trees, propagations, harvests, photos, journal entries, and chats are scoped to their account at the database level using row-level security. Administrative tools are gated to users with an explicit admin role.
Server-side privileged operations run only inside trusted server functions and verified webhooks — never from the browser.
FigWize runs on Lovable Cloud, which hosts the database, file storage, and server functions. Data is transmitted over HTTPS. Photos you upload (trees, propagations, listings) are stored in object storage scoped to your account.
We do not sell your data. Your fig data is used to power the features you see in the app (recommendations, analytics, community stats in aggregate).
Account emails (sign-up confirmation, password recovery, magic links) and app notifications are sent from a FigWize-controlled sender domain. Every marketing or broadcast email includes a one-click unsubscribe link. Addresses that bounce or unsubscribe are recorded and suppressed from future sends.
If you believe you've found a security issue, please contact us through the support channel in the app or by replying to any FigWize email. We review reports promptly and will follow up directly.
FigWize secures the application, database, and infrastructure described above. You are responsible for keeping your password and devices secure, and for the content you choose to upload or share publicly (for example, marketplace listings and community posts).
Questions? Visit your account settings or reach out through in-app support.