Protecting your data
- Data minimisation. We collect as little as possible; see the privacy policy. We never ask for Instagram credentials.
- Encryption in transit. The whole site is served over HTTPS.
- No credential handling. There is no account login on this site, so there are no passwords for us to lose.
Reporting a vulnerability
If you believe you’ve found a security issue in this website, we want to hear from you. Send a clear report (what you found, where, and how to reproduce it) through the contact page (select “Security”) so it routes to the right place.
Please do not publicly disclose an unresolved issue, access or modify other people’s data, run automated scans that degrade the service, or use social engineering. Give us a reasonable window to fix it first.
Scope
- In scope: this website and its assets.
- Out of scope: the third-party viewers we review (report those to their operators), volumetric denial-of-service, and issues in software we don’t control.
Safe harbor
We will not pursue or support legal action against researchers who act in good faith, follow this policy, avoid privacy violations and service disruption, and give us time to remediate before disclosure.
Our response
- We aim to acknowledge a report promptly and keep you updated as we investigate.
- Valid, in-scope issues are prioritised for a fix.
- With your permission, we’re glad to credit you once an issue is resolved.
Contact
Use the contact form and choose the Security topic. For anything about how we collect and keep data, see the privacy policy.