Legal · Security

Security and Vulnerability Disclosure

A responsible channel for reporting vulnerabilities, account compromise, privacy exposure, and platform abuse.

Effective August 13, 2026

Report a vulnerability

Email [email protected] with “Security Report” in the subject. Include the product or URL, description, reproduction steps, impact, and a safe contact method. Do not include real user data, credentials, tokens, or destructive payloads.

Good-faith testing

Test only accounts, data, systems, and environments you own or are authorized to assess; avoid other users’ data; minimize traffic; stop when sensitive data is encountered; and give Finkkle a reasonable opportunity to investigate before public disclosure.

Product areas

Reports may involve Search, Finkkle Igno, the Android assistant, Finkkle One, APIs, Arachnid, authentication, billing, storage, plugins, or connected services. For account takeover or exposed credentials, contact us immediately and rotate the credential if possible.

Response

We will acknowledge reports when practicable, assess scope and severity, coordinate remediation, and communicate when we can share a resolution. We may request evidence or ask that a report remain confidential during remediation.

Use Acceptable Use for abuse reports, Content and Copyright for copyright complaints, and Contact Finkkle for general legal requests.