Scope
This policy covers the official TableRival app, public website and APIs controlled by the Operator. It does not cover Google, Apple, RevenueCat or other providers; report vulnerabilities in those services directly to their operators.
Security measures
- local-first storage for training data by default;
- minimisation and pseudonymisation of optional transmitted data;
- encrypted HTTPS transport and allowlisted API fields;
- no storage of payment-card numbers or user passwords;
- purchase verification through the relevant store/provider when purchases are enabled, rather than an editable local flag;
- platform signing required for distribution builds, restricted key access and regular regression tests;
- dependency updates and risk-based vulnerability handling.
No system can guarantee absolute security. Controls are adjusted to the risk and nature of the data.
Responsible disclosure
Email tablerival@gmail.com with subject “TableRival security report”. Include version, platform, reproducible steps, impact and a safe proof. Do not include real data belonging to other users.
Safe-testing rules
- Do not access or modify another person’s data.
- Do not perform denial-of-service, spam, social-engineering or physical attacks.
- Do not publish a vulnerability before a reasonable remediation period is agreed.
- Stop testing when it may disrupt the service or expose data.
The Operator does not currently run a bounty programme, and a report does not create a right to payment.
Response
The Operator will acknowledge material reports, assess risk and prioritise remediation. Timing depends on complexity and impact. Legally required notifications will be made if a personal-data breach occurs.