Legal
Vulnerability disclosure policy
Last updated 1 October 2026.
The short version. Emailsecurity@nyuchi.com with the subject "Security". We acknowledge within 3 working days, keep you updated, and will not pursue good-faith research that follows this policy.
Scope
In scope:
- This website,
learning.nyuchi.com. - The Toddle Enhancement Extension, version 0.8.2 and later from the Chrome Web Store (earlier versions are not supported; extension ID
ofliokikjmkkdkinbdnadbjjdmkjdjfi). - Nyuchi's licence server and its API at
licences.nyuchi.dev, and its webhook host onnyuchi-licence-server.nyuchi.workers.dev.
Out of scope:
- Toddle itself. Please report those to Toddle.
- Third-party services we use (such as Buy Me a Coffee, Formspree, Intercom, Google, Vercel and Cloudflare's own platform). Report those to the provider.
- Social engineering, phishing, or any attempt on our staff or customers.
- Denial of service, load or volumetric testing.
- Physical attacks.
How to report
Email security@nyuchi.com with the subject "Security". Please include:
- what is affected, with the URL or the extension version (shown in its menu);
- the steps to reproduce it;
- the impact: what an attacker could read, change or do;
- the browser and version you used, where it matters.
Do not include real personal data or student data in a report; describe it instead. Please do not disclose the issue publicly until we have released a fix, or agreed a date with you.
What we commit to
- Acknowledge your reportwithin 3 working days.
- Triage it within 10 working days: confirm whether it is a vulnerability and how severe, and tell you.
- Fix a critical or high-severity finding within 7 days, a medium within 30 days, and a low in the next release, and tell you when the fix is out.
- Keep you updated while we work on it.
- Credit you in the release notes and the review record, if you would like to be credited.
There is no bug bounty. We are grateful for reports, and will say so publicly if you wish, but we do not pay for them.
Safe harbour
We will not take legal action against, or ask anyone to take action against, research done in good faith that follows this policy. That means testing that:
- stays within the scope above;
- avoids privacy violations, and uses your own accounts and test data;
- does not destroy or alter data;
- does not degrade or interrupt a service for anyone else.
If you come across personal data, stop, report it to us straight away, and do not keep, copy or share it. If you are unsure whether something is allowed, ask us first atsecurity@nyuchi.com.
This safe harbour covers Nyuchi's own systems only. It cannot authorise testing of Toddle or of any third party's service.
Related
- Security — the extension's security model, testing and independent review.
- security.txt.