Security

How to report a security issue to us — and what happens next.

Found a security issue? Email us at security@egg-tracker.com. Please do not disclose it publicly before we have had a chance to fix it.

In brief

  • Reports go to security@egg-tracker.com, in German or English.
  • You will usually hear back within five working days.
  • No bug bounty — we do not pay rewards.
  • No user data on our systems — there is none.

What can actually be attacked here

Egg-Tracker is a purely local app. There is no server, no account, no sign-in, and no interface through which cycle data could leave the device. All data is stored encrypted on the device and processed there.

That leaves exactly two things in scope:

  • the app itself (Android and iOS), including local storage, backup, and restore
  • this website, which consists of purely static files

Out of scope: the Google and Apple app stores, our email provider, the PayPal donation link, and anything else we do not own. Please report those directly to the respective provider.

How to report

An informal email to is enough. Anything that saves us from having to guess helps:

What is affected (app or website), for the app the version and operating system, a description of the steps to reproduce, and what someone could actually achieve with it.

Please do not include cycle or health data, or data belonging to other people — we do not need it to assess the report.

What you can expect

Egg-Tracker is run by a sole trader, not a security department. So we promise nothing we cannot keep — but we do keep this:

You will usually hear back within five working days on whether we can reproduce the finding. Every report is assessed in writing: does it affect Egg-Tracker at all, is it exploitable, is it already being exploited? Confirmed vulnerabilities are fixed and shipped as an app update; we will let you know once it is out.

Where a legal reporting duty applies — in particular for an actively exploited vulnerability under the Cyber Resilience Act — we additionally report to the competent authority within the deadlines set out there.

What we ask of you

Give us reasonable time to close the issue before you make it public. Do not access or modify other people's data. Refrain from load or denial-of-service testing against the website, and from social engineering against us or third parties.

If you stick to this, you have nothing to fear from us: we will not pursue legal action over reports made in good faith and in line with these rules.

There is no bug bounty programme and we do not pay rewards. On request we will credit you by name when we mention the fixed issue in the release notes.

Not a support channel

This address is for security reports only. Questions about how to use the app, bug reports without a security impact, and feature requests belong on the support page; questions about your data and your rights go to .

The machine-readable version of this information is available under RFC 9116 at /.well-known/security.txt.