Skip to content

SECURITY

Report the weakness, not someone’s private data.

CueMeThen welcomes good-faith reports that protect users. Please minimize access, stop when private data may be exposed, and give us time to investigate.

Last updated
29 July 2026

Include

  • A concise vulnerability description and likely impact.
  • The affected URL, app version, route, or component.
  • Reproduction steps using your own account and synthetic data.
  • Logs or screenshots only after removing tokens, emails, note content, signed URLs, and purchase evidence.
  • A safe contact method and whether you want public credit.

Do not

  • Access, copy, change, or retain another person’s data.
  • Use denial of service, automated account creation, spam, social engineering, or physical attacks.
  • Test payment providers with unauthorized instruments or publish an exploit before remediation.
  • Send secrets or sensitive evidence through public issues or ordinary screenshots.

Response

CueMeThen aims to acknowledge valid reports promptly, establish a secure evidence channel when needed, investigate severity, keep reporters informed at reasonable intervals, and coordinate disclosure after a fix. Response times and rewards are not guaranteed.