Security
Last updated 9 October 2026
In plain words
Found a security problem? Thank you. Email security@glimby.app with the details, give us a fair chance to fix it, and we won’t take legal action against good-faith research.
How we protect your data
- Every connection is encrypted with HTTPS, with strict security headers.
- Passwords are stored only as slow, salted hashes. We can’t see them.
- New passwords need 15 or more characters and are checked against known leaked passwords; passkeys and Google sign-in avoid passwords altogether.
- Sign-in is rate limited, and sessions expire after 30 days without a visit.
- Every request checks that the data it touches belongs to you.
- No third-party scripts or trackers run on Glimby’s pages.
- The code is tested automatically before every release.
Reporting a vulnerability
Email security@glimby.app. Please include what you found, the steps to reproduce it, and what an attacker could do with it. Our security.txt has the same address.
We’ll acknowledge your report within three working days and keep you posted until it’s fixed.
Testing in good faith
Please:
- only test against your own accounts, and never access or change other people’s data;
- stop and tell us if you come across someone else’s data by accident;
- don’t run denial-of-service, spam or social engineering tests;
- give us 90 days to fix the issue before you share it publicly.
If you follow these rules, we consider your research authorised, we won’t pursue or support legal action against you, and with your permission we’ll thank you by name once it’s fixed. We can’t offer paid bounties at the moment.
Privacy questions
For questions about your data rather than security bugs, see the privacy policy.