Skip to main content
Back to Home

Report a security issue

Last updated: October 6, 2026

If you think you've found a security issue in Champ, please tell us before anyone else. Email hello@champ.plus and start the subject line with "Security". A person reads every report, and we reply within 48 hours.

What to send

  • What you found and where: the URL, the API endpoint or the app screen
  • The steps to reproduce it, and what an attacker could do with it
  • Your app version and iOS version, if the issue is in the app
  • Whether and how you'd like to be thanked

In scope

  • The Champ app for iPhone
  • The backend the app talks to: Champ's Firebase database, storage and cloud functions
  • The champ.plus website and its API (everything under champ.plus/api/)

Out of scope

  • Denial of service, load testing, or anything else that slows the service down for other people
  • Social engineering or phishing of Champ users or of the people who run Champ, and physical attacks
  • Bugs in the third-party services Champ uses, such as Apple, Google and Firebase, OpenAI, RevenueCat and Resend. Please report those to the vendor. How Champ configures them is in scope.

Safe harbor for good-faith research

If you follow this page in good faith, we'll treat your research as authorized. We won't take legal action against you or ask anyone else to. Good faith means you:

  • Use only your own accounts, and test only what you need to show the issue
  • Stop as soon as you reach data that isn't yours, and don't keep, change, delete or share it
  • Don't degrade the service for anyone else
  • Give us a fair chance to fix the issue before you talk about it in public. We'll agree on a date with you.

No bounty

Champ doesn't pay bug bounties. If you'd like, we'll thank you by name on this page once the fix is live.

What happens next

  • We reply within 48 hours to confirm we have your report.
  • We keep you posted while we work on it, and tell you when the fix is live.
  • The same inbox handles account help and billing, so the "Security" subject line helps us spot your report quickly.

The same contact details are published for automated tools at champ.plus/.well-known/security.txt.