If you discover a security vulnerability in 24Picture, please report it responsibly.
Do not open a public issue. Instead, email us at:
We will respond within 48 hours and work with you to address the issue promptly.
The following areas are in scope:
- Cross-Site Scripting (XSS) vulnerabilities
- Client-side data exposure issues
- Service Worker security concerns
- API endpoint vulnerabilities
- Issues that require physical access to a user's device
- Social engineering attacks
- Denial of service via excessive tool usage (all processing is client-side)
We will not pursue legal action against anyone who:
- Makes a good faith effort to avoid privacy violations and data destruction
- Provides us reasonable time to fix the issue before public disclosure
- Does not exploit the vulnerability beyond what is necessary to demonstrate it
Thank you for helping keep 24Picture secure.