Security

How we protect accounts, and how to report a problem

Draft, not legal advice. This page is a placeholder written to show the structure. The final text will be written or reviewed by a lawyer before the iPhone app ships. Questions in the meantime: hello@whatsnuevo.com.

How we protect your account

  • No passwords. You sign in with a one-time email link that expires in an hour, so there's no password of ours to leak or reuse.
  • Encrypted connections. The website, the app and our database talk over HTTPS.
  • Your rows are yours. Our database only lets a signed-in person read and change their own saved places and notes.
  • Little to lose. We don't take payments or store card details, and we don't ask for your name, phone number or address.
  • Sign out everywhere. In the app, You → Account & security → Sign out of all other devices.

Report a vulnerability

If you think you've found a security problem in whatsnuevo.com or the iPhone app, please email hello@whatsnuevo.com security inbox to confirm with "Security report" in the subject. Include what you found, where, and steps to reproduce it.

Please:

  • Give us a reasonable time to fix it before telling anyone else.
  • Only test against your own account. Don't access, change or delete other people's data.
  • Don't run denial-of-service tests, spam, social engineering or physical attacks.

We'll acknowledge your report, keep you updated, and credit you if you'd like. We won't pursue anyone who reports in good faith and follows these rules. We don't run a paid bug bounty.

Our contact details for researchers are also in security.txt.

Out of scope

  • Partner sites we link to (reservations, ordering, tickets, maps).
  • Reports from automated scanners with no demonstrated impact.
  • Missing best-practice headers or settings without a working attack.

All policies · Terms · Privacy · Cookies · Guidelines · Accessibility · Security · Delete account · Licenses · Help · Contact

What's Nuevo · metro Detroit · radar · this week

About · Help · Contact · Terms · Privacy · Cookies · Accessibility · All policies