Security & Vulnerability Disclosure

Effective 18 August 2026 · Our coordinated-disclosure channel under the EU Cyber Resilience Act

Health Targets is built so that the most valuable data — your health measurements — never leaves your devices. Security work therefore concentrates on the app itself, its use of Apple's platform protections (HealthKit consent, iCloud encryption, Face ID app lock), and this website. We still assume we can make mistakes, and we want to hear about them.

Reporting a vulnerability

Email security@healthtargets.app with: what you found, the app or website version, steps to reproduce, and the impact you believe it has. Encrypted mail is welcome but not required. Please don't include real personal health data in reports — synthetic data (the app's Demo mode) demonstrates any issue equally well.

What you can expect from us

Scope

In scope: the Health Targets app (iPhone, iPad, Apple Watch, its widgets) and healthtargets.app. Out of scope: Apple's platforms themselves (report those to Apple), and issues requiring a jailbroken device or physical possession of an unlocked phone.

Keeping the app trustworthy

Updates are distributed exclusively through the App Store and carry Apple's code signing. The app requests read-only Health access, per measurement, and functions without any grant. There is no server side of ours to breach: no accounts, no databases, no third-party analytics.

Contact

Security: security@healthtargets.app · General: support@healthtargets.app