How we protect your account & data
This page is maintained by the FILus team to answer common security and privacy questions about FILus. It describes controls that are currently enabled in the app. It is not a certification and is not independently verified.
Last updated: June 19, 2026
Access & authentication
FILus accounts are protected by email + password sign-in and optional Google sign-in.
- Passwords must be at least 8 characters and include a number and a special character.
- Passwords are checked against the Have-I-Been-Pwned breach corpus on sign-up and password change.
- Sessions are managed by our authentication provider with short-lived access tokens and automatic refresh.
- Sign-in attempts are rate-limited to slow brute-force attacks.
- Password reset is self-service via a one-time email link.
Platform & hosting
FILus is built on the Lovable platform. Application code runs on Lovable's edge network; data is stored in a managed PostgreSQL backend with row-level security. We describe Lovable platform capabilities factually — we don't claim certification by Lovable or any third party.
Backups, infrastructure patching, and platform-level network security are handled by our hosting and database providers under their own published practices.
Data collection & use
We collect only what's needed to run the social network for OFWs:
- Account: name, email, host country, phone country code.
- OFW verification (optional): OWWA number and proof image — visible only to you and to FILus admins/moderators.
- Content you post: posts, comments, reels, stories, messages, reactions, and any media you upload.
- Operational data: device push tokens (if you opt in), basic usage events to debug and improve the app.
For the full legal text, see our Privacy Policy.
Who can see your data
- Public profile fields (display name, avatar, host country, occupation, bio) are visible to other signed-in users.
- Sensitive profile fields (OWWA number, OWWA proof, phone country code, push preferences) are visible only to you and to FILus admins/moderators for verification purposes.
- Posts respect the audience you choose (public, friends, specific people, only me).
- Direct messages are visible only to the sender and recipient (and to admins/moderators when responding to abuse reports).
Subprocessors & integrations
FILus relies on the following categories of subprocessors. Their use is governed by their own terms and privacy policies:
- Hosting & database (Lovable platform / managed PostgreSQL).
- Authentication (managed auth provider, including Google OAuth when you choose Google sign-in).
- Push notifications (Web Push via your browser/OS vendor).
- AI assistance for the in-app coach and content safety checks.
- Third-party job feeds and remittance-rate sources used inside FILus features.
If you need an itemized list for compliance purposes, contact us using the link below.
Cookies, analytics & ads
FILus uses first-party storage (cookies and local storage) for sign-in sessions and app preferences. Optional analytics and any monetization scripts are gated by a consent banner; they only load after you accept. You can change your choice at any time from the cookie banner.
Retention & deletion
Account and content data are retained while your account is active. You can delete individual posts, comments, reels, stories, and messages from inside the app. To delete your entire account and associated content, contact us at the address below and we'll process the request.
Privacy requests
You can request a copy, correction, or deletion of your personal data, or withdraw a previously given consent. Send the request from the email address on your FILus account so we can verify it. We respond within the timelines required by the Philippine Data Privacy Act (RA 10173).
Security contact & vulnerability reporting
If you believe you've found a security issue, please report it privately before disclosing publicly. Use the form on our Contact page and mark the message as a security report. We'll acknowledge receipt and work with you on a fix.
Please do not run automated scans, denial-of-service tests, or access accounts that are not your own.
Shared responsibility
Keeping FILus safe is a shared effort. The Lovable platform secures the underlying infrastructure; FILus configures application-level controls (authentication, row-level security, content moderation); and you protect your account by using a strong, unique password, not sharing your sign-in code, and reporting suspicious behavior.
This page reflects the FILus team's current practices and is updated as the app evolves. It is editable project content and is not an independent audit or certification.