These are drafts, not yet binding agreements.

Everything below is an accurate description of what OnBetterTerms does with what you write, and it is published now so you can read it before deciding to use the product. It has not been reviewed by a lawyer and is not written for a particular jurisdiction, so it is not offered to you as a contract yet. Where a clause needs a legal answer we do not have, it says so in place rather than being filled in with a plausible-looking one — the full list is here.

Security & vulnerability disclosure

Machine-readable version: /.well-known/security.txt

Reporting something

Email security@onbetterterms.com with enough detail to reproduce the issue. You do not need to have a working exploit, and you do not need to be sure — a clear description of something that looks wrong is worth sending.

We aim to acknowledge a report within three working days and to tell you what we intend to do about it, including when we think it is not a problem and why.

What we ask

  • Use your own accounts. Do not read, modify, or retain anybody else’s data — the content in this product is the most private thing most people write down, and access obtained to prove a point is still access.
  • Stop at proof. Confirming that a door opens is a finding; walking through it and looking around is not necessary and we will treat it differently.
  • Give us a reasonable chance to fix it before publishing. We will not ask you to stay quiet indefinitely, and we will not ask you to delete a report.
  • Do not run denial-of-service tests, send bulk automated traffic, or attempt social engineering against staff or members.

What we commit to

  • We will not pursue legal action against anybody who follows the above in good faith, and we will say so in writing if you ask.
  • We will credit you when a report leads to a change, unless you would rather we did not.
  • If a flaw exposed member data, we will say so publicly — including when it would have been easier not to.

Out of scope

Reports about a person rather than the software — abuse, harassment, or concern about somebody’s safety — should go to support@onbetterterms.com, which is read by people who can act on them. Missing security headers, weak TLS ciphers, and automated scanner output with no demonstrated impact are usually already known; send them anyway if you think they matter, but expect a short answer.

There is no paid bounty programme at this time. We would rather say that plainly than imply one.

Security & Vulnerability Disclosure — OnBetterTerms