Trust & safety
Security at AboutByMe
Found a security problem?
Tell us privately and we'll work with you to fix it quickly. Please don't share it publicly until it's fixed.
✉ [email protected]security.txtHow we protect your account
🔒Encrypted connectionEvery page and request uses HTTPS, with strict security headers on the whole site.
🔑Protected passwordsPasswords are stored only as salted cryptographic hashes and checked against known data breaches when you create them.
📱Two-factor authenticationTurn on a code from an authenticator app, with single-use recovery codes, in Account & security.
🛡️Anti-abuse protectionRate limits on logins, sign-ups and posts, plus protection against cross-site attacks.
📍Photo location removedGPS and camera data are removed from JPEG photos when you upload them.
👁️You control visibilityPublic, semi-private or private profiles, extra protections for members under 18, and reporting tools on every profile and post.
Keep your account safe
Use a unique passwordDon't reuse the password of your email or social networks.
Turn on two-factorApp → Profile → Account & security → Two-factor authentication. Save your recovery codes somewhere safe.
We never ask for your passwordAboutByMe will never ask for your password or your 2FA codes by email, message or phone.
Report anything suspiciousUse the Report button on profiles and posts, or write to [email protected].
Reporting a vulnerability
Email [email protected] with:
- A description of the issue and the page or feature affected.
- Steps to reproduce it, and screenshots or a short video if possible.
- The possible impact, and how we can contact you.
✅ In scopeaboutbyme.com, public profile and community pages, the app at
/app/ and its API.🚫 Out of scopeDenial-of-service or load testing, spam, social engineering or phishing, physical attacks, third-party services (Cloudflare, Stripe, YouTube), and automated scanner reports with no demonstrated impact.
Rules for good-faith research
- Only test with your own accounts. Don't access, change or delete other people's data; if you reach any by accident, stop and tell us.
- Don't disrupt the Service, degrade performance or send spam.
- Give us reasonable time to fix the issue before any public disclosure (we aim for 90 days or less).
If you follow these rules and act in good faith, we will not pursue or support legal action against you for your research, to the extent within our control.
What happens next
1 · ConfirmationWe acknowledge your report within 3 business days.
2 · InvestigationWe verify the issue and keep you updated.
3 · Fix & creditWe fix it and, if you want, thank you publicly. We don't offer paid bug bounties at this time.
Other issues
For account help, abusive content or a profile that impersonates someone, write to [email protected] or use the Report button. For copyright complaints, see the DMCA section of our Terms. If someone is in immediate danger, call 911 or your local emergency number.