Skip to content

Trust and research

Our safety and privacy principles, compliance mapping and vulnerability reporting channel.

Privacy principles

Minimisation by default, consent before collection, append-only audit, and data-subject rights across every domain.

Security practices

Encryption, token separation, rate limiting, audit logging and a coordinated disclosure process are built into the design.

Compliance mapping

In development

We document how the design maps to APPI, GDPR, PIPL, COPPA-type rules, Japan's Specified Commercial Transactions Act and ePrivacy.

Vulnerability disclosure

We provide a reporting channel for researchers. We do not claim the existence of a paid bounty programme.