Security & Breach Notification

Reporting a vulnerability, and what we do if there is a breach.

Version 4 · in force since 24 September 2026 · what changed. Drafted in good faith; not legal advice.

This document is incomplete.
The operator has not yet published: legal entity name, registered address, governing law / jurisdiction, legal contact address, privacy contact address. Each missing item is marked in the text below. Until they are published this service should not be taking money from the public.

Reporting a vulnerability

[not yet published: security contact address]. Tell us what you found and how to reproduce it. We will acknowledge within 5 working days and keep you informed until it is fixed.

We will not pursue legal action against anyone who reports a vulnerability in good faith, who does not access, modify or delete other people's data, who does not degrade the service, and who gives us a reasonable chance to fix it before publishing. Testing that involves other users' accounts, denial of service, or physical or social-engineering attacks on people is outside that protection.

What we do to protect data

If there is a breach

Our commitment, and the timetable the law holds us to:

  1. Contain. Cut off the access, rotate what needs rotating, preserve the evidence.
  2. Assess. What data, whose, and what could follow from it.
  3. Notify the regulator within 72 hours of becoming aware, where the breach is likely to risk people's rights and freedoms (GDPR Art. 33), and as US state breach laws require.
  4. Notify you without undue delay where the risk to you is high (Art. 34): what happened, what data, what we are doing, and what you should do.
  5. Publish a post-incident account once the immediate risk has passed.

We will not delay telling you in order to have a better story to tell.

What has changed

24 September 2026 · version 4

20 September 2026 · version 3

20 September 2026 · version 2

12 July 2026 · version 1

Whinchat · All documents · Open the app