Security Policy
Privacy Score is built by a single developer and ships a single iOS binary. If you have found a vulnerability that affects the application or the privacyscore.fr website, please disclose it responsibly using the contact below.
How to report
Email security@privacyscore.fr with a short description, reproduction steps and, if possible, a proof-of-concept. Replies are sent within 5 business days. A PGP key will be published here when one is generated; until then, send plain text and avoid attaching anything sensitive.
What we commit to
- Acknowledgment within 5 business days.
- Status update within 14 days, including the planned fix window.
- Public credit on this page once the fix ships, if you want it.
- No legal action for good-faith research that respects this policy.
Scope
- The Privacy Score iOS app (latest App Store build).
- The privacyscore.fr website and its
/.well-known/resources.
Out of scope: third-party services (Apple, Hostinger, Cloudflare), social-engineering, denial of service, automated scanner output without manual verification.
Acknowledgments
Researchers who have responsibly disclosed vulnerabilities will be listed here, with their consent. This wall is currently empty because the app has not yet shipped to the public App Store.
Related documents
- security.txt (machine-readable)
- Privacy Policy
- Legal Notice