Vulnerability disclosure policy
We publicly invite people to break this system, including the part of it that is supposed to protect people. This page is the rulebook for that invitation: what to test, what not to touch, what we promise in return, and the limits of what we are able to promise.
It applies to Life GPS, operated by WAADSU Inc. (Delaware, USA) and WAADSU s.r.o. (Czechia).
How to report
Email hello@lifegpsos.com with SECURITY in the subject line.
Include what you did, how to reproduce it, and what it would let someone do. If you would rather not use email, @LIFEGPS_SUPPORT_BOT on Telegram reaches us too.
What we do in return. We confirm receipt within five working days, tell you our assessment and rough timeline once we have one, keep you informed while we work, and credit you publicly if you want the credit. If we disagree that something is a problem, we say so with our reasoning rather than going quiet.
What is in scope
- The Life GPS iOS application and its backend services
lifegpsos.comand its subdomains- The protection layer itself — see below, because this is the part most people would not think to test
Third-party services we use, and anything belonging to someone else, are out of scope here. Report those to their owners.
The findings we care about most
A classic security finding is welcome. But the invitation on the antivirus page is broader than servers and code, and these matter to us as much:
- A way to make the protection pressure a person rather than support them
- A way to buy influence over what the system surfaces
- A way to make the system quietly favour a partner over the person using it
- A false positive that costs someone something real
- A path where a child gets around a protection meant for them
- A place where the protection exploits a weakness it learned while protecting
- A way to turn protection into censorship — deciding which idea a person may see rather than protecting the conditions of their choice
- A place where consent is theatre rather than a real choice
What we ask you not to do
- Do not use another person's real data. Test against your own account and your own data. If a finding seems to require someone else's data to demonstrate, stop and describe it to us instead.
- Do not degrade the service for other people. No denial-of-service, no resource exhaustion, no spam, no automated scanning heavy enough to affect others.
- Do not access, modify, delete or retain data that is not yours. If you come across someone's personal data by accident, stop, do not save it, and tell us what happened.
- Do not use social engineering, phishing or physical attacks against our people, our users, or our suppliers.
- Give us a reasonable window before publishing — ninety days is our default, and we will usually move faster. If you believe people are at immediate risk, tell us that and we will treat it accordingly.
Safe harbour
If you act in good faith and stay within this policy, we will not initiate or support legal action against you for your research, and we will not ask your employer, your platform or your host to act against you for it. If a third party brings an action against you for research we authorised here, we will make it known publicly and to that party that your activity was conducted within our policy.
We are stating the honest limits of that promise, because a safe harbour that pretends to be bigger than it is helps nobody.
- This commitment covers claims within our control. We cannot waive the rights of third parties, and we cannot override the law of any country.
- Activity that falls outside this policy — in particular using another person's data, degrading the service, or retaining data that is not yours — is outside the safe harbour.
- If you are uncertain whether something is in scope, write to us before you test it. We would rather answer that question than argue about it afterwards.
We do not currently pay bounties. We credit researchers publicly where they want it, and we say plainly that this may change as the project is funded.
What we do not promise
We are a small team building something we think should exist. We do not claim our systems are secure, and we do not claim this policy makes them so. Publishing the rules for breaking something is not a statement that it cannot be broken — it is the opposite.
Life GPS · WAADSU Inc. · hello@lifegpsos.com · machine-readable version: /.well-known/security.txt · published 21.09.2026
Every claim on this page carries a status