1 · What’s in scope
The CroppickVoice desktop app (every supported 1.x release) and the services behind it: this
website (voice.croppick.com), the licence service (license.croppick.com) and the download
host (dl-voice.croppick.com).
Not ours to fix — please report these to their owners instead: the Polar
checkout, and Cloudflare’s or Hugging Face’s own infrastructure. Not treated as security issues: flooding a service with traffic (denial of
service), tricking people rather than software (social engineering, phishing), anything that
needs physical access to a machine or a computer that is already compromised, and
automated-scanner output without a demonstrated impact.
2 · How to report
Email security@croppick.com. The more of this you
can include, the faster we can act: the affected version (Settings → About) or service,
steps to reproduce it, what someone could do with it, and a small demonstration if you have
one. English or Lithuanian, whichever you prefer.
While you look, please don’t access, change or copy other people’s data, don’t disrupt the
services, and give us reasonable time to fix the issue before you publish anything about it.
The machine-readable version of this page is /.well-known/security.txt.
3 · What we promise
- A prompt acknowledgement of your report.
- An assessment and a target fix date as soon as we’ve looked into it, and
word from us as the fix moves along.
- Fixes ship as digitally signed updates through the app’s normal updater,
and security fixes are called out as such in the release notes.
- Credit on this page, if you’d like it. There is no bug-bounty programme —
we say so plainly rather than hint at rewards that don’t exist.
- Safe harbour. Research done in good faith and within this policy will not
be met with legal action by MB Croppick.
4 · How fixes reach you
The app checks for updates on its own (you can turn that off in Settings), and every update
is digitally signed and verified before it installs — a
security fix reaches you exactly the way any other update does.
Support period: we provide security updates for CroppickVoice 1.x until at
least 9 July 2031 — five years from the 1.0 release. The same
commitment is part of the terms.
5 · Advisories
No security advisories have been published yet. When one is, it appears here with the
date, the version that fixes it, its severity and a CVE number if one was assigned.
Last updated: September 2026 · MB Croppick