Report a Security Vulnerability

Last updated: 20 September 2026

Email [email protected] with "SECURITY" in the subject. Tell us what you found and how to reproduce it. We will confirm we have it within three working days, and we will tell you what we are doing about it rather than going quiet.

Why this page exists

ZeroPercent holds phone numbers, dates of birth, battery history and a record of who someone reached for help, for families that include children. That is a small database with a high consequence if it is wrong, and the people best placed to find a flaw in it do not work here.

A researcher who cannot find a way to tell us has two options: give up, or post it publicly. Both are worse for the families using this app than an email address on a page. So here is the address, and here is what we promise in return.

What we promise

We are a small company and we do not run a paid bounty. We would rather say that plainly than imply a reward that never comes.

The rules

These exist because the accounts on this service belong to families, and a test that goes wrong lands on a real one.

In scope

Out of scope

We will read anything you send, but these are unlikely to get a fix, and saying so up front saves your time as well as ours.

What to include

The more of this you send, the faster it gets fixed.

If you think it is being exploited right now

Put "SECURITY URGENT" in the subject and say so in the first line. That is read differently from the rest.

If this is not a security flaw

If the app is simply not working for you, the help centre is the faster route. If you have had a suspicious message claiming to be from us, that belongs there too, and it is worth telling us: we will never ask for your Zero PIN, your password or a verification code.