We take the security of PrivacyGPT seriously. If you discover a security vulnerability, please disclose it responsibly.
Do not report security vulnerabilities through public GitHub issues, discussions, or pull requests.
Instead, please report them via email to me@lynicis.dev.
You should receive a response within 48 hours. If you don't, please follow up to ensure we received your message.
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Any suggested fixes (if known)
This security policy covers:
- The PrivacyGPT web application
- The associated Cloudflare Workers and cron workers
- The build and deployment pipeline
Only the latest version of the main branch is supported with security updates.
We ask that you:
- Give us reasonable time to investigate and fix the issue before disclosing it publicly
- Avoid exploiting the vulnerability or violating the privacy of other users
- Act in good faith to help make the project secure for everyone
We believe in recognizing security researchers who help keep our users safe. With your permission, we will acknowledge your contribution in the release notes and changelog once the vulnerability is resolved.