Responsible reporting

Report a problem safely.

A notes app needs to respect your files. Reports about permission boundaries, unsafe links or unexpected file changes are especially useful.

Report privately

Use GitHub private vulnerability reporting. Include the affected version, a minimal example with fictional notes and reproduction steps.

Do not publish unpatched vulnerabilities or attach real Brains, passwords or tokens. Pedro Teixeira reviews reports; there is no guaranteed response-time SLA.

Package integrity

The installer checks release checksums against GitHub and validates archive paths before installing. These checks rely on the trusted GitHub release; they do not replace publisher signing. macOS notarization remains pending.

Read the distribution and trust model