security & responsible disclosure

Found a security issue? Tell us first.

If you’ve found a way CroppickVoice or one of our services could be broken into or misused, we want to hear about it — privately, so it can be fixed before anyone else finds it. Here is what counts, how to reach us, and what you can expect back.

1 · What’s in scope

The CroppickVoice desktop app (every supported 1.x release) and the services behind it: this website (voice.croppick.com), the licence service (license.croppick.com) and the download host (dl-voice.croppick.com).

Not ours to fix — please report these to their owners instead: the Polar checkout, and Cloudflare’s or Hugging Face’s own infrastructure. Not treated as security issues: flooding a service with traffic (denial of service), tricking people rather than software (social engineering, phishing), anything that needs physical access to a machine or a computer that is already compromised, and automated-scanner output without a demonstrated impact.

2 · How to report

Email security@croppick.com. The more of this you can include, the faster we can act: the affected version (Settings → About) or service, steps to reproduce it, what someone could do with it, and a small demonstration if you have one. English or Lithuanian, whichever you prefer.

While you look, please don’t access, change or copy other people’s data, don’t disrupt the services, and give us reasonable time to fix the issue before you publish anything about it. The machine-readable version of this page is /.well-known/security.txt.

3 · What we promise

  • A prompt acknowledgement of your report.
  • An assessment and a target fix date as soon as we’ve looked into it, and word from us as the fix moves along.
  • Fixes ship as digitally signed updates through the app’s normal updater, and security fixes are called out as such in the release notes.
  • Credit on this page, if you’d like it. There is no bug-bounty programme — we say so plainly rather than hint at rewards that don’t exist.
  • Safe harbour. Research done in good faith and within this policy will not be met with legal action by MB Croppick.

4 · How fixes reach you

The app checks for updates on its own (you can turn that off in Settings), and every update is digitally signed and verified before it installs — a security fix reaches you exactly the way any other update does.

Support period: we provide security updates for CroppickVoice 1.x until at least 9 July 2031 — five years from the 1.0 release. The same commitment is part of the terms.

5 · Advisories

No security advisories have been published yet. When one is, it appears here with the date, the version that fixes it, its severity and a CVE number if one was assigned.

Last updated: September 2026 · MB Croppick