
Pineappl
.
Responsible Disclosure
Last updated: 25 September 2026
Pineappl holds some of the most private information people share online. If you've found a security weakness in the app or website, please tell us privately first so we can fix it before anyone misuses it. We appreciate it, and we won't take legal action against anyone who follows the rules below in good faith.
1. How to report
Email abuse@pineappl.nl with "Security" in the subject line. Please include:
- what you found, and where (the page, screen or address involved);
- the steps needed to reproduce it;
- what an attacker could do with it, as far as you know;
- how we can reach you, if you'd like to hear back.
Reports in English or Dutch are both fine.
2. What we ask of you
- Don't look at other members' data. Test with accounts you created yourself. If you come across someone else's information by accident, stop, don't keep or share it, and mention it in your report.
- Do no more than needed to show the problem — no changing or deleting data, no downloading more than a single example.
- Keep it confidential until we've fixed it, or until we've agreed a date with you to publish.
- Don't disrupt the service — no denial-of-service attacks, no spam, no automated scanning that puts heavy load on the app.
- Leave our members and staff alone — no social engineering, phishing, or contacting members, and no physical attempts to access our systems.
3. What you can expect from us
- We confirm we've received your report within 5 working days.
- We keep you informed while we investigate and fix the problem, and tell you when it's resolved.
- We treat your report and your details confidentially and won't pass your details on without your permission, unless the law requires it.
- If you'd like, we'll thank you by name once the problem is fixed. We don't run a paid bug bounty.
- If you've followed these rules, we won't report you to the police or take other legal action against you over your report.
4. Not in scope
Please don't report these unless you can show a real way to misuse them:
- findings from automated scanners without a demonstrated impact;
- missing security headers or cookie flags on their own;
- that members can take screenshots (we can't prevent this; see "Photo leak protection" in our Privacy Policy);
- problems that need a device that's already compromised, or physical access to someone's unlocked phone.
5. Something else?
To report content or a member rather than a security weakness, use the report button in the app or see our Content Removal & Abuse Reporting policy. For questions about your personal data, email privacy@pineappl.nl.
← Back to Pineappl