Unpound

Reporting a vulnerability

Email support@unpound.com with Security in the subject line. Say what you found, how to reproduce it, and what you think it lets somebody do.

That is the same address as ordinary support, on purpose: it is an inbox a person reads every day, which is worth more than a dedicated one that nobody has got round to watching. The subject line is what lifts your report out of the questions about step counts.

You will get an acknowledgement within 72 hours and an assessment within 10 working days. If it is real you will be told when it is fixed, and credited if you would like to be.

Please do not test against other people's accounts, and please give us a chance to fix it before publishing. There is no bounty programme — this is a small product, and the honest thing is to say so rather than to imply a payment that is not coming.

What is in scope

The Unpound app on iPhone and Android, its home-screen widgets, and the API behind them at api.unpound.com. This website too, although it holds nothing.

Out of scope: Apple's and Google's own sign-in and billing services, our hosting providers' platforms, and anything that needs a jailbroken device or physical access to an unlocked phone.

What we take most seriously

What you can expect from us

A reply from a person, a fix or an explanation of why there will not be one, and — where a report turns out to affect users' data — a notification to the competent supervisory authority where required and, if the breach is likely to create a high risk for them, a notification to the affected users without undue delay.