Bug Reports

Effective for all bug reports received on or after September 10, 2026 at 2:00 PM PT.

We care deeply about protecting your words and your privacy. If you have found a bug in TextJam, whether it is a visual glitch or a serious vulnerability, we want to hear about it. This page covers how to tell us.


Found an Ordinary Bug?

Email us and tell us what happened, what you expected, and what you were doing when it went wrong. A screenshot helps. So does the document name, if it is something we can look at.

bugs@textjam.com

We read every message, and this is genuinely the fastest way to get something fixed.


Found a Security Issue?

Same address: bugs@textjam.com. Please include:

  • A clear description of the issue
  • Steps to reproduce it against an account you own
  • Evidence that you have reproduced it yourself

Real impact matters more than severity labels. If you find sensitive data during testing, stop and tell us.

We ask that you give us up to 60 days to fix a vulnerability before you discuss it publicly. That is a request, not a condition of anything.

If you act in good faith and follow these rules, we will not take legal action or involve law enforcement.


Reports Written With AI

Reports written with AI assistance are welcome. Reports forwarded from a tool without verification are not, and we will close those without replying.

If a tool found it, assume the same tool found it for someone else too. What makes your report worth reading is that you confirmed it against a running system and can show your working.


How We Respond

We read everything that comes in. We are a small team, so we prioritise replies to reports that include:

  • Steps we can follow
  • Evidence you reproduced the issue yourself
  • A clear account of what an attacker actually gets

Those get answered first. Everything else we still read, but it may not get a reply.


How We Say Thank You

If you are the first to report an issue that we end up fixing, we will credit you in the changelog entry that ships the fix. Those entries name people and do not describe the issues. They read like this:

Security fixes addressing issues raised by Ada Lovelace and @kestrel.

Tell us how you would like to appear: a name, a handle, or a link. If you would rather not be named at all, say so and we will leave you out.

We do not pay bounties. There is no monetary reward at any severity.


Out of Scope

The following are out of scope. Reports about them will be closed without a reply:

  • Denial of service (DoS) or brute-force attacks
  • Social engineering or phishing attempts
  • Attacks requiring physical access to or theft of someone else's device
  • Prompt injections to retrieve system prompts / details or avoid model safeguards
  • Non-critical CSP headers omitted, or CSP exemptions required for site operation
  • Missing DNSSEC / DS records (not adopted by google.com, github.com, or other major sites)
  • Profile picture, name, or email visible to document collaborators (like Google Docs)
  • Unenforced usage limits (e.g. rate limits, quota caps, free-tier ceilings)
  • Long-lived login tokens (by design)
  • 500 errors from probing endpoints with invalid inputs
  • Bugs in third-party services (e.g. Stripe, Google APIs)
  • Cosmetic/UI issues and typos

Note: Viewing fields in your own JWT (e.g. email or role claims) or seeing intentionally public info like names or avatars does not qualify as unauthorized access.


Responsible Disclosure Rules

When you test, you must:

  • Test only against accounts you own
  • Avoid accessing or modifying real user data
  • Never use phishing, social engineering, or spam
  • Avoid disrupting or degrading the service
  • Use manual testing or low-impact automated tools (no excessive scanning)
  • Do not publicly disclose vulnerabilities for at least 60 days after reporting

If you encounter sensitive data during testing, stop immediately and report it.

By testing TextJam, you agree to follow these rules.


About Our Former Bug Bounty Program

We ran a paid bug bounty program until September 10, 2026 at 2:00 PM PT. It is closed.

We closed it because bug bounty submission has become an automated operation. Most of what reached our security inbox was generated output sent to many companies at once: the same small set of findings, in confident technical language, from senders who had not reproduced them and often had not read the scope. Sorting careful research out of that volume was taking more time than we have, and the people doing careful work were the ones left waiting.

We are not the only ones. The curl project ended its bug bounty in January 2026 after nine years and more than one hundred thousand dollars in payouts, for the same reason. Linus Torvalds has described the Linux kernel security mailing list as almost entirely unmanageable under the same pressure.

We would rather be honest about it than run a program we cannot keep up with. Our security testing is not going away; it is getting more focused. We continue to invest in ongoing, in-depth testing with selected researchers and the latest frontier models, on scopes we define.

If you reported something while the program was open: we are working through those reports. Anything that turns out to be new, in scope and reproducible will be assessed and compensated under the terms that applied when you sent it. Thank you for your patience, and for the time you put in.

Read our letter about closing the program.

— The TextJam Team


Prior policy versions: April 30, 2026 to September 10, 2026 · September 15, 2025 to April 29, 2026

Bug Reports - TextJam