PREVIEW — not the final published text. The following entity details are still unset: ADDRESS, ANSCHRIFT, COMPANY, COMPETENT GERMAN STATE DATA PROTECTION AUTHORITY, DATE, DATENSCHUTZ-E-MAIL, DATUM, Impressum: URL, JURISDICTION, Managing director(s): NAME, POSTCODE, CITY, PRIVACY EMAIL, STREET, NO., SUPPORT EMAIL, SUPPORT-E-MAIL, URL, legal form. Complete docs/legal/site/entity.json, rebuild and redeploy before submitting the app to App Review.

Security

Reporting a vulnerability

Write to the security contact published at /.well-known/security.txt. Please include what you

did, what you observed, and how to reproduce it. We aim to acknowledge within 72 hours and to

give an assessment within 10 working days.

Please do not: access other people's data, degrade the service, or run automated scanning that

generates load. Testing against your own installation is welcome.

We do not currently run a paid bug bounty. We will credit reporters who wish to be named.

How the product is built

hash of an install token, a plan flag and counters.

not trusted from the client.

and removed before the model sees it.

launch.

Out of scope

Reports produced solely by automated scanners without a demonstrated impact; missing headers on

endpoints that serve no content; social engineering; physical attacks; and issues in Apple's or

Cloudflare's own infrastructure, which should go to those vendors.