Security
Report a security issue
FitSend exists to handle health data carefully, so security reports get our fastest attention. If you believe you’ve found a vulnerability in the FitSend app, API, or this site, we want to hear from you, directly and privately.
Security contact
We acknowledge reports within three business days and keep you updated while we investigate and fix. Machine-readable details live at /.well-known/security.txt.
What helps us fix it fast
- Steps to reproduce, with the endpoint, request, or screen involved.
- What you expected versus what happened, and why it matters.
- Your environment (app version, iOS version) if relevant.
Ground rules
- Test only against your own account and data — never anyone else’s health information.
- Don’t run denial-of-service tests, spam, or physical or social-engineering attacks.
- If you stumble into data that isn’t yours, stop, don’t save it, and tell us what happened.
- Give us reasonable time to fix the issue before any public disclosure; we’ll work with you on timing and gladly credit you if you’d like.
We won’t pursue action against good-faith research that follows these rules. We don’t run a paid bounty program today; if that changes, this page will say so.
How FitSend is built
The short version: health measurements pass through our servers in memory and are never stored there; credentials are envelope-encrypted; everything travels over TLS; and accounts hold no names or emails to leak. The privacy policy describes the architecture in plain English.