Do not disclose suspected vulnerabilities, secrets, authentication codes, cookies, personal data, or production configuration in a public issue.
Use GitHub's private vulnerability-reporting or private security-advisory channel for this repository when available. If that channel is unavailable, contact the project owner through an established private CalorieToken contact channel and share only the minimum information needed to establish a secure reporting path.
Current V1 scope is the non-financial, non-custodial CalorieApp food and nutrition application, including its backend, frontend, and separately licensed WordPress identity bridge.
Reports involving wallet custody, private keys, payments, token transfers, trading, or other financial execution are outside the implemented V1 product unless they demonstrate that such functionality is unexpectedly present.
Never include real secrets, credentials, private keys, seed phrases, database contents, authorization codes, session cookies, or unnecessary personal data in a report. Redact logs and screenshots.
This policy does not grant permission for destructive testing, denial of service, social engineering, privacy violations, accessing other users' data, or testing third-party systems such as WordPress, Xaman/XUMM, Open Food Facts, or Render without their authorization.
No bug-bounty payment or reward is promised unless separately agreed in writing.