FinchLabs logo FinchLabs.com

FinchLabs.com

Privacy Policy

This policy explains the limited information the FinchLabs platform may collect and how that information is used and protected.

Effective April 11, 2026

1. Scope

This Privacy Policy applies to websites, applications, and services operated as part of the FinchLabs platform, including FinchLabs applications that use shared FinchLabs services such as authentication and account management.

Individual FinchLabs applications may collect different types of information depending on their purpose and functionality.

2. Information We Collect

FinchLabs may collect information that you provide directly when creating or using a FinchLabs account or application. This may include:

  • Name or display name
  • Username
  • Email address
  • Account and application-access information
  • Information entered into or created within individual FinchLabs applications
  • Communications you send to FinchLabs

FinchLabs may also collect limited technical information necessary to operate and secure the platform, such as login times, session information, IP addresses, browser or device information, and security-event information.

Passwords are not stored in readable form.

3. How Information Is Used

FinchLabs uses information collected through the platform to:

  • Provide and operate FinchLabs applications
  • Create and maintain user accounts
  • Authenticate users
  • Determine which applications and functions a user is authorized to access
  • Maintain application data and user preferences
  • Send account, invitation, verification, password-reset, or other service-related communications
  • Diagnose technical problems
  • Protect the security and integrity of the FinchLabs platform
  • Improve FinchLabs applications and services

FinchLabs does not sell personal information.

4. Cookies and Sessions

FinchLabs may use cookies or similar browser technologies that are necessary to authenticate users, maintain secure sessions, remember authorized users, and support application functionality.

Authentication cookies may contain randomly generated session identifiers. FinchLabs applications are designed so that sensitive authentication credentials are not stored directly in browser cookies.

FinchLabs does not use authentication cookies for advertising.

5. Sharing and Disclosure

FinchLabs does not sell, rent, or trade personal information.

Information may be shared with service providers when reasonably necessary to operate the FinchLabs platform, such as hosting, database, or email-delivery providers. Such providers receive only the information necessary to perform the applicable service.

Information may also be disclosed when reasonably necessary to comply with applicable law, respond to lawful legal process, protect the security of the FinchLabs platform, or prevent fraud, abuse, or unauthorized access.

6. Security

FinchLabs applications use a common security and identity layer known as FinchLabs Roost. Roost provides centralized authentication, session management, application access control, account verification, invitation management, and security-event logging across participating FinchLabs applications.

Roost is designed using modern web-application security practices, including secure password hashing, cryptographically generated session and verification tokens, server-side session validation, role-based application access, protection against cross-site request forgery (CSRF), secure and HTTP-only authentication cookies, controlled session expiration and revocation, and audit logging of significant security events. Passwords and authentication tokens are not stored in plaintext.

FinchLabs also separates identity and security data from application-specific data wherever practical. Individual applications rely on Roost to determine user identity and authorization while retaining responsibility for their own application data. This architecture reduces duplication of authentication logic and provides a consistent security layer across the FinchLabs platform.

FinchLabs security practices are informed by generally accepted web-security principles and industry guidance, including concepts reflected in OWASP security guidance and the NIST Cybersecurity Framework. References to these frameworks describe principles considered in the design of FinchLabs systems and do not represent a claim of certification, attestation, or independent compliance audit.

While no system can guarantee absolute security, FinchLabs uses reasonable administrative and technical safeguards intended to protect account information and other data against unauthorized access, disclosure, alteration, or destruction.

For a visual overview of the shared identity, authentication, session, permission, and API-access model used across FinchLabs, see the Roost Security Framework.

7. Data Retention

FinchLabs retains account and application information for as long as reasonably necessary to operate the applicable service, maintain the integrity and security of the platform, or satisfy legitimate operational requirements.

Security and audit information may be retained separately from application data when necessary to investigate security events, maintain system integrity, or document account activity.

Information that is no longer reasonably required may be deleted, anonymized, or otherwise removed from active systems.

8. Changes to This Privacy Policy

FinchLabs may update this Privacy Policy as the FinchLabs platform, its applications, or its security practices evolve.

Material changes will be reflected in the policy published on FinchLabs.com, and the effective date will be updated when appropriate.

Continued use of the FinchLabs platform following publication of an updated Privacy Policy constitutes acknowledgment of the revised policy.

9. Contact and Information Security

Questions regarding privacy, data protection, account security, or the security of the FinchLabs platform may be directed to FinchLabs Information Security.

Contact FinchLabs Information Security

Email: Contact InfoSec

LinkedIn: FinchLabs, Chief of Security

If you believe a FinchLabs account or application may have been compromised, please include enough information for us to identify the affected account or application, but do not send passwords, authentication tokens, or other credentials by email.