← Back to Home

Security & Vulnerability Disclosure

Last updated: July 2026

DadTale handles photographs of small children. We treat that as the most sensitive thing we could possibly be trusted with, and we want to hear from you if you find a way it could go wrong. If you have found a security issue, please tell us before you tell anyone else — we will work the report and we will not come after you for it.

How to report

Email dad-tale-support@f13foundry.com with “SECURITY” in the subject line. Please include:

  • What you found and roughly how severe you think it is.
  • Steps to reproduce it — a short proof of concept beats a long description.
  • Any affected URLs, accounts, or requests.
  • How you would like to be credited, if at all.

Machine-readable contact details are published at /.well-known/security.txt per RFC 9116.

What we commit to

  • Acknowledgement within 3 business days that a human has read your report.
  • An initial assessment within 10 business days — whether we can reproduce it, and our severity call.
  • Progress updates at least every 14 days until the issue is closed.
  • Credit in our disclosure notes if you want it, and none if you do not.

We are a small team, so we would rather give you honest timelines than optimistic ones. If something is taking longer than this, we will tell you why.

In scope

  • dadtale.com and its subdomains
  • The DadTale web application and its API
  • Anything that could expose another user’s photos, books, children’s names, or account
  • Authentication, session handling, payment flows, and access control

Out of scope

  • Denial of service, volumetric, or stress testing of any kind.
  • Social engineering of our team, our users, or our vendors.
  • Physical attacks, or anything targeting an individual person.
  • Reports generated solely by an automated scanner with no demonstrated impact.
  • Missing hardening headers or weak TLS ciphers with no exploitable consequence.
  • Vulnerabilities in third-party services we use — please report those to the vendor.

Rules of engagement

Use only accounts and data you own. If you encounter another user’s personal data — especially a photograph of a child — stop immediately, do not download or retain it, and tell us what you saw so we can measure the exposure. Do not modify or delete data that is not yours. Do not run tests that degrade the service for anyone else.

Safe harbour

If you make a good-faith effort to follow this policy, we will not pursue or support any legal action against you for your research, and we will treat your activity as authorised under the Computer Fraud and Abuse Act and equivalent laws. If a third party brings action against you for research that followed this policy, we will make it known that your activity was authorised.

We do not currently run a paid bug bounty. Reports are handled on the terms above and credited on request.

Disclosure

Please give us 90 days before publishing, or less if we have already shipped a fix and agreed a date with you. We are happy to coordinate an announcement.

Related

For how we collect, use, and delete personal data — including the retention and deletion schedule for uploaded photos — see our Privacy Policy. For the terms governing use of the service, see our Terms of Service.