Security

Security policy

How to tell us about a security problem in Orgasmly, what we do with the report once it arrives, and what this page deliberately does not authorise.

Last reviewed: 24 September 2026

1. Report a vulnerability

Email hello@orgasmly.org. This is a small project run by one developer, so that inbox is read directly — there is no ticket portal, no triage vendor, and no form.

Useful reports contain:

  • The URL, endpoint, or app screen affected
  • What you expected to happen and what happened instead
  • The smallest set of steps that reproduces it, if you have one
  • The impact you think it has — especially if it touches data belonging to someone other than you
  • How you would like to be credited, or a note that you would rather stay anonymous

Please do not send us other people's data. If a flaw exposed session logs, notes, partner labels, share links, or account details that are not yours, stop there, tell us what you saw and where, and do not download, copy, screenshot, or forward it. A description of the exposure is enough for us to fix it. Sending the data on makes the incident worse, not more urgent.

There is no bug bounty. We do not pay for reports, and we cannot offer a reward, a swag credit, or a spot on a leaderboard. See section 2 for what we can offer instead.

2. What happens after you report

  • We aim to acknowledge your report within 3 working days, and to give you a first assessment within 10.
  • We will tell you whether we consider it a vulnerability, and roughly what fixing it involves.
  • We will keep you updated when there is something to report — a fix going out, or a decision not to change anything, with the reasoning.
  • We will credit you on this page, or keep you anonymous, whichever you asked for.

We ask for 90 days before public disclosure, or until a fix is deployed, whichever comes first. If we are slower than that, publishing is a reasonable thing to do; we would rather you told us you were about to than have it appear without warning.

If a report is accurate and affects a release users are running, we may publish a short note describing the issue and the fix once it is deployed, without naming the reporter unless they agreed to be named.

3. This page is not permission to test

Publishing this policy — and the /.well-known/security.txt file that points at it — is an invitation to report, not a safe-harbour clause and not an authorisation to probe. Nothing here grants permission to test, scan, or access the service.

We do not operate a bug bounty, we do not run a vulnerability disclosure programme with pre-authorised scope, and we do not accept unsolicited security testing. Because Orgasmly stores intimate personal data, unauthorised probing is treated as a privacy incident affecting real users, not as a favour. Section 6 of the terms of service sets out what is prohibited and the possible consequences.

If you want to test the service, ask first. Send a written, scoped, time-boxed request to hello@orgasmly.org describing what you intend to do, to which hostnames, and in what window. We will consider it and answer in writing. Until that answer arrives, treat the service as off-limits for testing — including scanning, fuzzing, and enumeration.

A vulnerability you came across incidentally, while using the app normally, is exactly what we want to hear about. Reporting it costs you nothing and step 2 applies. What we do not want is a report that begins with damage already done.

4. What we want to hear about

Things that would worry us most, in order:

  • Reading, changing, or deleting another account's sessions, notes, tags, or share links
  • Bypassing authentication, session expiry, or the re-authentication gate on account deletion
  • Re-identifying a person from anonymous aggregate statistics, or defeating the k-anonymity floor
  • Share links that expose more than the owner configured, or that survive revocation or expiry
  • Access to infrastructure, credentials, or logs that are not yours
  • Cross-site scripting, HTML injection, or anything that lets a page act as the signed-in user

The service runs at www.orgasmly.org and api.orgasmly.org, in the AWS Sydney region. Both are in scope for a report.

5. What we would rather you took elsewhere

  • Volumetric denial-of-service, load testing, and anything designed to degrade availability
  • Spam, phishing, or social-engineering attempts against us or our users
  • Physical attacks, or anything against a person rather than the service
  • Automated scanner output pasted in bulk with no demonstrated impact
  • Missing hardening headers or version banners with no exploitable consequence — tell us if you have a path that uses them
  • Flaws in AWS, Cognito, or another third party's service; those belong with the vendor, though we are glad to hear about them if they affect us

Dependency updates with no security consequence are also not incidents. Open an issue or a pull request instead.

6. What we will never ask you for

We will never ask for your password, an MFA or verification code, an API key, or a copy of another person's data — and we will not ask you to keep a problem secret indefinitely, beyond the window in section 2. If someone claiming to be Orgasmly asks for any of those, they are not us; the only address that matters is hello@orgasmly.org.

7. Machine-readable policy

The policy above is also published at /.well-known/security.txt in the format described by RFC 9116:

Contact: mailto:hello@orgasmly.org
Expires: 2027-09-01T00:00:00.000Z
Preferred-Languages: en
Canonical: https://www.orgasmly.org/.well-known/security.txt
Policy: https://www.orgasmly.org/security

The file is unsigned. The Expires date is a little under a year out and is refreshed when this page is reviewed, so if it has passed, treat the file as stale and ask us to confirm the current contact address.

8. Contact

Security reports and testing authorisation requests: hello@orgasmly.org

Privacy questions and data requests: privacy@orgasmly.org — see the privacy policy.

Legal: legal@orgasmly.org