Good Contact is built privacy-first: your contacts are stored locally on your device and, if you enable sync, in your own private iCloud account. We take security seriously and welcome reports from the research community. If you believe you have found a vulnerability, please tell us privately first and give us a reasonable chance to fix it before any public disclosure.
How to report
Email security@goodcontact.io. Please include enough detail for us to reproduce the issue: the affected URL, endpoint, or app surface; the steps you took; and any proof of concept. If the issue could expose another user’s account data, allow access to contact data, or bypass authentication, please flag it as high severity in the subject line so we can triage it quickly.
Scope
The following are in scope for this policy:
- The goodcontact.io website.
- The Good Contact apps for iOS, iPadOS, and macOS.
- Our account and subscription backend (the API that manages your profile and subscription state).
The following are out of scope — please report issues with these to the relevant vendor directly:
- Apple iCloud, CloudKit, Sign in with Apple, and other Apple platform services. Your synced contact data lives in your own private iCloud account; we are never in the sync path.
- Third-party providers we rely on (for example Supabase, Loops, and Sentry), which run their own security programs.
- Findings that require a physical or jailbroken device, a rooted/compromised OS, or social engineering of our staff or customers.
- Reports from automated scanners with no demonstrated, exploitable impact.
What to expect
- We aim to acknowledge your report within three business days.
- We will keep you updated as we assess and remediate the issue.
- We practise coordinated disclosure: we will agree a disclosure timeline with you and, if you would like, credit you once a fix is released.
Safe harbour
We will not pursue legal action for good-faith security research that respects user privacy, does not access or exfiltrate other users’ data beyond the minimum needed to demonstrate the issue, and avoids data destruction or service degradation. Please stop and report to us as soon as you have confirmed a vulnerability.
Please do not
- Access, modify, or delete data that is not your own.
- Run automated scanning that degrades the service for other people.
- Use the issue to access contact data, account data, or any data belonging to other users.
- Publicly disclose the issue before we have had a reasonable chance to fix it.
Our machine-readable security contact is published at /.well-known/security.txt, following RFC 9116.
Thank you for helping keep Good Contact and its users safe.
Report a vulnerability at security@goodcontact.io