Security & Vulnerability Disclosure
Version 1.0 ยท Effective 26 July 2026
How to report a security issue to us, what we promise in return, and our safe-harbour commitment for good-faith research.
Reporting a vulnerability
If you have found a security issue in crocodata.net or in any Crocodata app (FotoPost, Askra, CleanFotos, AppSwipe), please tell us before telling anyone else:
Include what you found, where, how to reproduce it, and what an attacker could do with it. Proof-of-concept code or screenshots help. Tell us how you would like to be credited, or say if you prefer to stay anonymous.
What we commit to
- We acknowledge your report within 3 business days.
- We give you an initial assessment within 10 business days.
- We keep you updated at least every 14 days until the issue is closed.
- We credit reporters who want credit, once a fix is live.
- We do not run a paid bug bounty. We are a small company; what we offer is a fast, honest response.
Safe harbour
If you make a good-faith effort to follow this policy, we will not pursue or support legal action against you for your research, and we will treat your work as authorised. Good faith means: you do not access, modify, exfiltrate or destroy data belonging to other people; you do not degrade our services or those of our providers; you use only your own test accounts; you stop as soon as you have confirmed the issue; and you give us reasonable time to fix it before publishing.
Out of scope
- Findings from automated scanners without a demonstrated impact.
- Missing security headers or best-practice suggestions with no exploitable consequence.
- Social engineering, phishing or physical attacks against our people.
- Denial-of-service and volumetric testing.
- Vulnerabilities in third-party services (Google, Firebase, Cloudflare, Stripe, Apple) โ please report those to the provider directly.
How we handle a data breach
If a personal-data breach occurs, we assess it immediately and, where it is likely to result in a risk to people's rights and freedoms, notify the Polish supervisory authority UODO within 72 hours under Art. 33 GDPR, and notify affected users without undue delay where Art. 34 requires it. We keep an internal breach register regardless of whether notification is required, and we notify under other applicable regimes (for example US state laws, UK GDPR, LGPD) where they apply.
How we build
- All traffic is served over HTTPS.
- Payment card data is handled exclusively by Stripe and the app stores โ we never see or store card numbers.
- Backend access is protected with Firebase Authentication and Firebase App Check.
- On-device apps (CleanFotos, AppSwipe) keep user content on the device; there is no server to breach.
- Dependencies are updated regularly and secrets are kept out of source control.
Machine-readable policy
See /.well-known/security.txt.
© 2026 Crocodata sp. z o.o. · Spółka z ograniczoną odpowiedzialnością · KRS 0001241145 · NIP 7582407044