Security

Report a security issue

FitSend exists to handle health data carefully, so security reports get our fastest attention. If you believe you’ve found a vulnerability in the FitSend app, API, or this site, we want to hear from you, directly and privately.

Security contact

security@fitsend.app

We acknowledge reports within three business days and keep you updated while we investigate and fix. Machine-readable details live at /.well-known/security.txt.

What helps us fix it fast

  • Steps to reproduce, with the endpoint, request, or screen involved.
  • What you expected versus what happened, and why it matters.
  • Your environment (app version, iOS version) if relevant.

Ground rules

  • Test only against your own account and data — never anyone else’s health information.
  • Don’t run denial-of-service tests, spam, or physical or social-engineering attacks.
  • If you stumble into data that isn’t yours, stop, don’t save it, and tell us what happened.
  • Give us reasonable time to fix the issue before any public disclosure; we’ll work with you on timing and gladly credit you if you’d like.

We won’t pursue action against good-faith research that follows these rules. We don’t run a paid bounty program today; if that changes, this page will say so.

How FitSend is built

The short version: health measurements pass through our servers in memory and are never stored there; credentials are envelope-encrypted; everything travels over TLS; and accounts hold no names or emails to leak. The privacy policy describes the architecture in plain English.