Last updated: July 2026
DadTale handles photographs of small children. We treat that as the most sensitive thing we could possibly be trusted with, and we want to hear from you if you find a way it could go wrong. If you have found a security issue, please tell us before you tell anyone else — we will work the report and we will not come after you for it.
Email dad-tale-support@f13foundry.com with “SECURITY” in the subject line. Please include:
Machine-readable contact details are published at /.well-known/security.txt per RFC 9116.
We are a small team, so we would rather give you honest timelines than optimistic ones. If something is taking longer than this, we will tell you why.
dadtale.com and its subdomainsUse only accounts and data you own. If you encounter another user’s personal data — especially a photograph of a child — stop immediately, do not download or retain it, and tell us what you saw so we can measure the exposure. Do not modify or delete data that is not yours. Do not run tests that degrade the service for anyone else.
If you make a good-faith effort to follow this policy, we will not pursue or support any legal action against you for your research, and we will treat your activity as authorised under the Computer Fraud and Abuse Act and equivalent laws. If a third party brings action against you for research that followed this policy, we will make it known that your activity was authorised.
We do not currently run a paid bug bounty. Reports are handled on the terms above and credited on request.
Please give us 90 days before publishing, or less if we have already shipped a fix and agreed a date with you. We are happy to coordinate an announcement.
For how we collect, use, and delete personal data — including the retention and deletion schedule for uploaded photos — see our Privacy Policy. For the terms governing use of the service, see our Terms of Service.