Security & Vulnerability Disclosure
Health Targets is built so that the most valuable data — your health measurements — never leaves your devices. Security work therefore concentrates on the app itself, its use of Apple's platform protections (HealthKit consent, iCloud encryption, Face ID app lock), and this website. We still assume we can make mistakes, and we want to hear about them.
Reporting a vulnerability
Email security@healthtargets.app with: what you found, the app or website version, steps to reproduce, and the impact you believe it has. Encrypted mail is welcome but not required. Please don't include real personal health data in reports — synthetic data (the app's Demo mode) demonstrates any issue equally well.
What you can expect from us
- Acknowledgement of your report within 7 days, and an assessment or plan within 30.
- A fix delivered through an App Store update as fast as severity warrants, with reporting to authorities where EU Cyber Resilience Act obligations apply.
- Coordinated disclosure: we ask that you give us reasonable time to fix before publishing, and we credit reporters who wish to be named.
- No legal action against good-faith security research that respects users' data and doesn't degrade the service.
Scope
In scope: the Health Targets app (iPhone, iPad, Apple Watch, its widgets) and healthtargets.app. Out of scope: Apple's platforms themselves (report those to Apple), and issues requiring a jailbroken device or physical possession of an unlocked phone.
Keeping the app trustworthy
Updates are distributed exclusively through the App Store and carry Apple's code signing. The app requests read-only Health access, per measurement, and functions without any grant. There is no server side of ours to breach: no accounts, no databases, no third-party analytics.
Contact
Security: security@healthtargets.app · General: support@healthtargets.app