Security fixes target the latest code on main unless a release explicitly says otherwise.
Do not open a public issue for vulnerabilities, leaked credentials, or private reading data.
Contact the maintainer privately:
- GitHub: @joeseesun
- X: @vista8
- Website: qiaomu.ai
Include the affected version/file, reproduction steps, expected impact, and whether any private link or user data may be exposed.
- The app contains no bundled API key or account credential.
- Feed, article, translation, rewrite, and submitted-link requests go to
rss.qiaomu.aiby default. - Submitted links may be fetched and turned into public reading assets; do not submit private URLs.
- Read/favorite state, appearance settings, and cached snapshots are stored locally on the device.
- Development signing identities and provisioning profiles must never be committed.