LEGAL / SECURITY

Security

Draft — not yet in force. This page is published for review during the beta. Bracketed items like [DATE] are still being filled in and a lawyer has not yet reviewed the text. It will say "in force" here when that changes.

Last updated: [DATE]

This page says how the hosted part of fair.ninja protects your data, in plain terms, including what is not done yet. The Privacy Policy says what we store; this page says how we keep it safe.

The design: your device first

Tomato keeps your data on your device and works without a server. Sync is an optional service on top. That design is itself a security property: if our server is unreachable, compromised, or gone, your timer still runs, your plan is still there, and your export still works. The hosted part holds only what you chose to sync.

In transit

At rest

Your account

Backups and recovery

Operations

Reporting a vulnerability

If you find a security problem, please tell us first: [security@fair.ninja]. Give us reasonable time to fix it before publishing. In return: we will not take legal action against research done in good faith that avoids other people's data and does not disrupt the service, we will answer you, and we will credit you here if you like. There is no bounty programme yet.

If something goes wrong

If we learn of a breach affecting your data, we investigate, contain it, notify the supervisory authority within 72 hours where the law requires it, and tell affected users directly, without undue delay, what happened and what to do. Incidents that affect the service are also published on our status/changelog page.

Generated from the repository's docs/legal/security.md. Questions: see section 1.