Security Security If you as a Security Researcher found safety problems on our platform, we ask you to behave responsibly by sharing your information with us. If you have found security-related problems on our platform as Security-Researcher we ask you to handle responsible handling by providing your information. We appreciate your work by paying a generous bug bounty (private dreamdatedestiny bug bounty) for all reports that follow our rules and thank you for making dreamdatedestiny safer! Rules You may not access any private data from other user accounts, download it or save it. We refer to all data that is only viewable for the respective user personally. Only interact with accounts that are yours or for which you have an explicit permission to use. Any attacks, that target the availability or integrity of our services (e.g. destroy data, change data or delete data) are forbidden and not allowed. Any attacks that may compromise availability or integrity of our services (for example with automated vulnerability scans) are forbidden and not allowed. DDoS and spam attacks are not permitted. Social engineering, phishing as well as any physical intervention with dreamdatedestiny property (like data center) is not permitted. Attacks may not impede other users. Problems from the report may not already be published or prepared to be published. We must be given 60 days to fix the problem (before public disclosure or disclosure to a third party). Please follow the basic principles of responsible disclosure. All problems must be reproducible. All reports must contain instructions on the reproduction (proof of concept code, a clear request, e.g. HTTP call including request/response header and body). The report has to refer to a problem that is in scope as well as covered in qualification. Current or former employees of dreamdatedestiny , their legal representatives, their businesses or their relatives are excluded from participation. Scope The problem relates to one of the following domains: dreamdatedestiny .com, www.dreamdatedestiny .com, api.dreamdatedestiny .com, api.gateway.dreamdatedestiny .com. The problem refers to the currently available version of our iOS or Android app or the website. The problem relates to a service or a website operated by dreamdatedestiny . Qualification The reported problem must not already be known or submitted to us by another person. The problem has to be a risk which we do not accept. Timing attacks, for example of the kind that allow to verify the existence of a user, are not included in the bug bounty program. Attacks using brute force or problems that result from the use of brute force are not part of the program. Problems that are identified on older mobile devices, operating systems or browsers are not part of the program. The problem needs to be reproducible on the latest device, operating system and browser (without browser extensions).