Draft — to be reviewed by counsel before launchThis page is a working draft. It isn’t final legal text yet, and the highlighted placeholders still need details from the company or its lawyer.
Security and Responsible Disclosure
Last updated:
How we protect your data
- Access control: every database table has row-level security, so each person can only read and change their own rows. Automated tests try to read, change, delete and forge another user’s rows on every table, and every release must pass them.
- No secrets in the app: API keys and the database service key live only in server functions, never in the app you download.
- On-device encryption: journal text and all cycle data are encrypted on your phone with AES-256-GCM before they sync. A backup of your key is held in a secure vault and released only to you after sign-in, so a new phone can read your data. A leak of the database alone would expose only scrambled text for these fields. Because we hold a backup of the key, this is not “zero-knowledge” encryption, and we say so plainly.
- In transit: all traffic between the app and our servers is encrypted with TLS.
- Where: data is stored in the EU (Frankfurt).
- Backups and incidents: daily backups, and a written breach plan that includes notifying authorities within 72 hours where the law requires.
- Deletion: deleting your account erases your rows, files and escrowed key.
More detail in plain language on our Privacy by design page.
Report a vulnerability
Email To fill in security@getholimo.com (confirm the mailbox exists). Our contact details are also in /.well-known/security.txt. Please include:
- what you found and where (app version, URL or endpoint);
- steps to reproduce it;
- the impact you think it has;
- how to reach you.
What we commit to
- We will acknowledge your report within To fill in number working days.
- We will keep you updated while we fix it, and tell you when it’s fixed.
- With your permission, we will thank you by name once it’s fixed.
We don’t run a paid bug bounty at launch.
Safe harbour
If you act in good faith and follow this policy, we will not take legal action against you or ask anyone else to. Please:
- only test with accounts you own, and never access, change or keep other people’s data;
- stop and tell us if you come across personal data;
- give us reasonable time to fix the issue before telling anyone else;
- not degrade the service for others.
Out of scope
- Social engineering or phishing of our team or users.
- Denial-of-service or load testing.
- Physical attacks.
- Issues in third-party services (Apple, Google, Supabase, RevenueCat) — please report those to them.
- Reports from automated scanners without a demonstrated impact.