Report a security problem

  • What you found, where (URL or API route), and the steps to reproduce it.
  • The impact as you understand it. A short proof of concept is plenty.
  • How to reach you if you want a reply. We read every report by hand and will answer as soon as we can, but we cannot promise a response time.
  • Test only against accounts you own. Do not read, change or delete other people's data. If you reach someone else's data by accident, stop and tell us.
  • No denial-of-service, spam, social engineering of our team or users, or physical attacks.
  • Give us a reasonable chance to fix the problem before you publish details.
  • Do not include real personal data in your report.

We do not run a bug bounty and do not pay for reports. We are glad to thank you by name in release notes if you want that.

  • Connections use HTTPS, with HSTS and standard browser security headers.
  • Passwords are stored as salted scrypt hashes, never in plain text. Sign-in, sign-up and reset requests are rate limited.
  • Optional two-factor sign-in with any authenticator app (TOTP), with one-time recovery codes. Turn it on in Account.
  • You can see every device signed in to your account and sign out of one or all of them on your Account page. A password reset signs out your other devices.
  • When your account signs in from a browser or operating system it has not used before, we email the address on the account with a link that signs out every device.
  • Tokens for apps you connect are encrypted before they are stored.
  • You can download your data and delete your account from the Account page.
  • We hold no security certifications (no SOC 2, ISO 27001 or similar) and have not had an independent audit or penetration test.
  • Optional passkeys (fingerprint, face or device PIN) as an extra way to log in; a passkey login counts as two factors. Add one in Account. Two-factor sign-in and passkeys are both optional, so accounts that have turned on neither are protected only by their password, email link or Google/Microsoft login.