You can report security issues directly to us. We describe concrete app safeguards without claiming that any online service is risk-free.
Report an issue
Email hei@norge90.com with the subject Security. Include the affected URL, time, reproduction steps and likely impact. A short, harmless demonstration is more useful than a large data dump. Do not include passwords, access tokens or other people’s private information.
Responsible investigation
Only test information and systems you are authorised to use. Do not conduct denial-of-service attacks, social engineering or extraction of real user data. This page does not authorise testing Wikinews, Wikimedia, Open-Meteo or other providers. There is no announced bug bounty programme or fixed response time.
Safeguards and limits
API responses are checked before display, and URLs are validated before use. Images require HTTPS; server downloads to R2 are additionally restricted to approved domains and public IP addresses. The app has no accounts or payment data. These measures do not replace secure hosting, updates, access controls and incident handling in production. No security certification or independent audit has been completed here.
Incident communication
Reports are assessed for impact, evidence and opportunities to limit harm. Any notices to affected people or authorities must follow the requirements applicable to the incident. Ordinary email is not a secure channel for highly sensitive information; ask for a suitable channel first.
Contact us
The link opens your email app. No message is sent automatically.