AI-generated content · Human-unverified · Entertainment only · May contain hallucinations

Privacy, data & security

Security, Account Protection and Vulnerability Reporting Policy

Security expectations, prohibited abuse and a responsible path for reporting vulnerabilities.

Last updated: September 2, 2026

Audience: All visitors and users

Important: This document is a product policy and risk-control statement, not personal legal advice. It does not waive non-waivable rights and must not be read as a claim that every listed law applies in every jurisdiction.

Security baseline

  • Use least privilege, secret separation, rate limits and repository-enforced infrastructure boundaries.
  • Do not expose internal state services or credentials publicly.
  • Preserve auditability for security-relevant changes and incidents.

Research and reporting

Good-faith vulnerability reports should describe the issue and reproduction safely without accessing unnecessary user data, persistence, extortion, destructive testing, credential harvesting or disruption. Authorization for security testing is not implied by this policy.