Trust and research
Our safety and privacy principles, compliance mapping and vulnerability reporting channel.
Privacy principles
Minimisation by default, consent before collection, append-only audit, and data-subject rights across every domain.
Security practices
Encryption, token separation, rate limiting, audit logging and a coordinated disclosure process are built into the design.
Compliance mapping
In developmentWe document how the design maps to APPI, GDPR, PIPL, COPPA-type rules, Japan's Specified Commercial Transactions Act and ePrivacy.
Vulnerability disclosure
We provide a reporting channel for researchers. We do not claim the existence of a paid bounty programme.