Skip to content

Legal

Vulnerability disclosure policy

Last updated 1 October 2026.

The short version. Emailsecurity@nyuchi.com with the subject "Security". We acknowledge within 3 working days, keep you updated, and will not pursue good-faith research that follows this policy.

Scope

In scope:

Out of scope:

How to report

Email security@nyuchi.com with the subject "Security". Please include:

Do not include real personal data or student data in a report; describe it instead. Please do not disclose the issue publicly until we have released a fix, or agreed a date with you.

What we commit to

There is no bug bounty. We are grateful for reports, and will say so publicly if you wish, but we do not pay for them.

Safe harbour

We will not take legal action against, or ask anyone to take action against, research done in good faith that follows this policy. That means testing that:

If you come across personal data, stop, report it to us straight away, and do not keep, copy or share it. If you are unsure whether something is allowed, ask us first atsecurity@nyuchi.com.

This safe harbour covers Nyuchi's own systems only. It cannot authorise testing of Toddle or of any third party's service.

Related