Responsible reporting
Report a problem safely.
A notes app needs to respect your files. Reports about permission boundaries, unsafe links or unexpected file changes are especially useful.
Report privately
Use GitHub private vulnerability reporting. Include the affected version, a minimal example with fictional notes and reproduction steps.
Do not publish unpatched vulnerabilities or attach real Brains, passwords or tokens. Pedro Teixeira reviews reports; there is no guaranteed response-time SLA.
Package integrity
The installer checks release checksums against GitHub and validates archive paths before installing. These checks rely on the trusted GitHub release; they do not replace publisher signing. macOS notarization remains pending.