Security

Security Policy

How we protect data and how to report a vulnerability responsibly.

Last updated:

Scope

This policy covers the official TableRival app, public website and APIs controlled by the Operator. It does not cover Google, Apple, RevenueCat or other providers; report vulnerabilities in those services directly to their operators.

Security measures

  • local-first storage for training data by default;
  • minimisation and pseudonymisation of optional transmitted data;
  • encrypted HTTPS transport and allowlisted API fields;
  • no storage of payment-card numbers or user passwords;
  • purchase verification through the relevant store/provider when purchases are enabled, rather than an editable local flag;
  • platform signing required for distribution builds, restricted key access and regular regression tests;
  • dependency updates and risk-based vulnerability handling.

No system can guarantee absolute security. Controls are adjusted to the risk and nature of the data.

Responsible disclosure

Email tablerival@gmail.com with subject “TableRival security report”. Include version, platform, reproducible steps, impact and a safe proof. Do not include real data belonging to other users.

Safe-testing rules

  • Do not access or modify another person’s data.
  • Do not perform denial-of-service, spam, social-engineering or physical attacks.
  • Do not publish a vulnerability before a reasonable remediation period is agreed.
  • Stop testing when it may disrupt the service or expose data.

The Operator does not currently run a bounty programme, and a report does not create a right to payment.

Response

The Operator will acknowledge material reports, assess risk and prioritise remediation. Timing depends on complexity and impact. Legally required notifications will be made if a personal-data breach occurs.