How Cindr protects data
- OAuth authorization code flow with PKCE and a fresh, validated state value.
- Provider authentication in the iOS system authentication session; Cindr never receives mailbox passwords.
- OAuth tokens stored in iOS Keychain with device-only, after-first-unlock protection.
- Local files protected by iOS Data Protection and scoped App Group storage for aggregate widget values.
- No Cindr backend that receives or stores mailbox content.
- No client secrets embedded in the public iPhone application.
- Message bodies fetched only when opened, rendered as inert text, and not persisted.
- Remote images, tracking pixels, and JavaScript blocked from the native message viewer.
- Trash instead of permanent deletion, duplicate-action protection, durable recovery queues, and Undo receipts.
- Fixed, privacy-safe analytics vocabulary with no mailbox-content properties; analytics is disabled by default.
Report a vulnerability
Email dukesbarlow.web@gmail.com with:
- A concise description and potential impact.
- The Cindr version/build and iOS version.
- Reproduction steps or a minimal proof of concept.
- Your preferred contact information and disclosure timeline.
Do not include live OAuth tokens, passwords, or another person’s mailbox content. If sensitive supporting material is essential, ask for a secure transfer method first.
Good-faith research guidelines
Use only accounts and devices you own or have explicit authorization to test. Avoid privacy violations, data destruction, service disruption, phishing, social engineering, denial of service, automated high-volume requests, and attempts to access other users’ information. Stop and report if you encounter real user data.
No monetary bug bounty is promised. Authorization or safe-harbor commitments, if any, must be confirmed in writing before testing that could otherwise violate law, provider rules, or these Terms.
What to expect
We aim to acknowledge a credible report promptly, reproduce and prioritize it, communicate material progress, and coordinate disclosure after a fix is available. Timing depends on severity, provider dependencies, and release review.
Product support is separate
Sign-in failures, lost provider connectivity, questions about Trash or Undo, billing, and feature requests generally belong with Cindr Support. Suspected credential exposure, authentication bypass, data exfiltration, or unintended mailbox mutation belongs with the security contact.