Security
Found a way to see or change something you shouldn't? Tell us, and we'll fix it.
How to report
Use the support form and choose Security vulnerability. Say what you found, the steps to reproduce it, and what an attacker could do with it. Please leave out other members' personal data, and test only with accounts you own.
What we promise
- We read every security report and reply within five business days.
- We keep you updated until it's fixed, and credit you if you'd like.
- We won't pursue anyone who reports in good faith, stays within this page and doesn't harm members or their data.
Out of bounds
- Accessing, changing or deleting other members' data, or keeping any you come across.
- Denial of service, spam, social engineering, or testing against real members.
- Physical attacks and attacks on our providers (Apple, Convex, Netlify, Stripe and the rest).
A machine-readable version of this page is at /.well-known/security.txt.