OwnNode handles a private backend token and can optionally process authorized media and financial transaction alerts. Please do not disclose a suspected vulnerability in a public issue.
Report security concerns by emailing zenit027@proton.me with:
- the affected app version or commit;
- the impact and reproduction steps;
- whether the issue involves the Android app, backend, or both; and
- any suggested mitigation.
Remove tokens, backend URLs, SMS content, account identifiers, media, and other personal data from reports. There is currently no paid bug bounty program.