If you discover a security issue in Coinflip, please report it privately rather than opening a public issue:
- Use GitHub's Security Advisories ("Report a vulnerability") tab, or
- Open a regular issue only for non-sensitive reports.
Please include steps to reproduce and the version/commit you tested. You can expect an initial response within a reasonable timeframe.
Coinflip is a small, local desktop application designed to be safe by default:
- No network access — the app makes no outbound network calls and sends no telemetry.
- Local-only — it does nothing but display a window and flip a coin; no user data is collected, stored remotely, or transmitted.
- Hardened Electron configuration — the renderer runs with
contextIsolation: trueandnodeIntegration: false, and all communication between the renderer and the main process goes through a minimal, explicitpreload.jsIPC bridge.
Released binaries are currently unsigned. On first launch Windows SmartScreen may warn you; choose More info → Run anyway. Always download releases from the official Releases page.