If you find a security vulnerability, please contact us privately at security@notaapp.dev
Do not disclose it publicly until we release a fix.
| Version | Supported |
|---|---|
| main | ✅ |
| dev | ✅ |
| old branches | ❌ |
- Firebase Firestore rules restrict unauthorized access.
- API keys are never committed to the repo.
- All communications with Gemini API use HTTPS.
- Sensitive user data is anonymized before AI processing.
- Confirm receipt within 48h.
- Investigate and reproduce issue.
- Apply fix and release update.
- Credit reporter if applicable.