Please do not disclose a suspected vulnerability in a public issue.
Email support@phrasa.app with the subject Phrasa security report. Include
the affected version, reproduction steps, likely impact, and any proposed fix.
Do not include another person's scripts, account data, credentials, private
keys, or access tokens.
We will acknowledge a reproducible report and coordinate a responsible disclosure timeline. This policy covers Phrasa source and developer-operated services; vulnerabilities in Apple, Supabase, GitHub, or another provider should also be reported through that provider's security process.