1. Our Commitment
We take the security of Superparent and the data our users entrust to us — including Gmail content and Google account data — seriously. We welcome reports from security researchers and will work with you in good faith to verify, fix, and acknowledge valid findings.
2. Scope
In scope
superparent.ioand its subdomains, includingapp.superparent.io.- The Superparent web application, marketing site, and admin app.
- The Superparent mobile apps (iOS / Android).
- The Superparent backend APIs.
Out of scope
- Denial-of-service (DoS/DDoS), volumetric, or resource-exhaustion testing.
- Social engineering, phishing, or physical attacks against Superparent staff, users, or facilities.
- Findings that require a rooted/jailbroken device, a physically stolen/unlocked device, or a compromised account you do not own.
- Reports from automated scanners without a demonstrated, exploitable impact.
- Missing best-practice headers/config with no demonstrated security impact (report welcome, low priority).
- Vulnerabilities in third-party sub-processors’ own infrastructure (report those to the vendor; tell us if our data is affected).
- Spam, rate-limiting, or content-policy issues.
3. Safe Harbor
If you make a good-faith effort to comply with this policy during your research, we will consider your research to be authorized, we will not pursue or support legal action against you, and we will work with you to understand and resolve the issue quickly. This authorization is limited to activity that:
- Stays within the scope above;
- Avoids privacy violations, data destruction, and service degradation;
- Uses only your own test accounts / data, and does not access, modify, or retain other users’ data;
- Stops and reports immediately if you encounter any user data (especially Gmail content or children’s data), and does not exfiltrate it.
If legal action is initiated by a third party against you for activity conducted under this policy, we will make this authorization known.
4. How to Report
Email security@superparent.io. Please include:
- A clear description of the vulnerability and its potential impact.
- Step-by-step reproduction instructions (proof-of-concept, requests/responses, screenshots).
- The affected URL / endpoint / app and version.
- Any accounts or test data you used (use your own test accounts only).
Please do not publicly disclose the issue until we have confirmed a fix, and give us a reasonable window to remediate (see the response targets below). Do not access, download, or retain data belonging to other users.
5. What to Expect (Response Targets)
| Stage | Target |
|---|---|
| Acknowledge receipt | Within 3 business days |
| Initial triage / severity assessment | Within 10 business days |
| Status updates | At least every 2 weeks until resolved |
| Remediation | Timeline depends on severity; we will share our target and keep you updated |
Severity is assessed using our internal incident-response severity model. If a report reveals that user data — particularly Google user data — was accessed without authorization, we invoke our incident-response plan, including the obligation to notify security@google.com where applicable.
6. Recognition
We are grateful for responsible disclosure. We do not currently run a paid bug-bounty program. With your permission, we are happy to publicly credit you once an issue is resolved. (A public acknowledgments / hall-of-fame page is a future addition; there is no PGP key published yet.)
For questions about how we handle personal data, see our Privacy Policy.
Still have questions?
We’re parents too — reach out any time and we’ll walk you through it.