Reracked

Security & Vulnerability Reporting

Last updated: 8 August 2026

Thank you for taking the time to report a problem responsibly. This page tells you where to send it, what happens next, and — importantly — what not to include.

Report to security@reracked.app. Please use this address rather than a public issue, an app-store review, or social media. A public report exposes other people’s data before anything can be fixed.

Reracked is a closed beta built and operated by one person, Brendan Hamilton. The response times below are honest for a single maintainer rather than copied from a template.

What to include

What NOT to send — please read this part

Email is not an encrypted channel, and your report will sit in a mailbox. Sending any of the following turns a helpful vulnerability report into a data incident of its own:

If your proof genuinely requires sensitive material, say so in your first email and we will arrange a channel for it before you send anything.

What we ask of you

What you can expect from us

StageTarget
Acknowledgement that a human has read it3 business days
Initial assessment — reproducible, and how severe7 business days
Fix, or a written plan with dates, for High/Critical issues30 days from confirmation
Coordinated public disclosure, if you want oneBy agreement, normally after a fix ships

If you have not heard anything within the acknowledgement window, assume the mail went astray and send it again — that is a failure on our side, not an invitation to disclose.

We will tell you what we found, whether we are fixing it, and when it ships. If we decide not to fix something, we will say so and explain why rather than going quiet.

There is no bug-bounty programme and no monetary reward. We will credit you by name or handle if you would like that, and we are glad to say so publicly.

Supported versions

WhatSupported
BackendOnly the version currently deployed to production. No maintained release branches, no backports.
Android appOnly the most recent build on the active Play track.

Reracked is a hosted service in closed beta, not distributed software — everyone is on the deployed version, so “supported” means what is running now. Older builds of the app can also be refused by the server and asked to update; that is an upgrade mechanism, not a security boundary.

Scope

In scope

Out of scope

Things that are deliberate

So you do not spend time confirming behaviour we chose on purpose:

Finding a way around any of these is exactly the kind of report we want.

Machine-readable contact

This policy is also advertised at /.well-known/security.txt (RFC 9116).