If you believe you found a security issue
Email [email protected] with enough information for us to understand and reproduce the issue. Do not include more personal or child information than is necessary.
Please do
- Act in good faith and avoid privacy harm.
- Stop testing if you encounter personal information you are not authorized to access.
- Give us a reasonable opportunity to investigate before making a vulnerability public.
- Use your own account and data where testing is necessary.
Please do not
- Access, download, alter or disclose child information that is not yours.
- Use social engineering, phishing, credential theft or physical attacks.
- Disrupt the service, send malware or intentionally degrade availability.
- Demand payment or threaten disclosure as a condition of reporting.
Our response
We will review good-faith reports, prioritize issues according to risk and communicate with the reporter where appropriate. This page does not create a bug-bounty payment obligation.