Report a vulnerability
Describe the affected version or URL, the observed behavior, its security impact, and the smallest safe reproduction. Please do not include live OAuth tokens, passwords, complete emails, or another person’s personal information.
support@terse.emailResponsible research
- Test only with accounts and information you own or have explicit permission to use.
- Do not access, change, retain, or disclose another person’s data.
- Do not send email, disrupt service, automate high-volume requests, or degrade third-party providers.
- Give us a reasonable opportunity to investigate before public disclosure.
Product safeguards
Terse is local-first. OAuth refresh tokens are stored in macOS Keychain, provider traffic uses encrypted HTTPS, and mailbox actions pass through exact identity and readback checks. AI and browser agents cannot activate Send or Schedule.
See the Privacy Notice for data handling and the machine-readable security.txt contact.