Security Policy — Mellow for Twitch

Last updated: October 5, 2026

We take reasonable care in designing the Extension, but no software is perfectly secure. This document describes how to report security issues and what you can expect.

Supported versions

Version Supported
Latest release on the Chrome Web Store Yes
Older store versions Best effort only
Unpacked / developer builds from source Supported only for the current main branch at report time

Design intent (security-relevant)

If you believe the Extension behaves differently (e.g. unexpected network requests, data exfiltration), please report it.

Reporting a vulnerability

Please do not open a public GitHub issue for security-sensitive reports.

  1. Prefer GitHub Private Security Advisories on the public contact repository:
    https://github.com/kzmanakzm-cpu/MellowForTwitch-privacy/security/advisories/new
    (If that repository cannot accept advisories, use the store developer contact email listed on the Chrome Web Store.)

  2. Include: - A clear description and impact - Steps to reproduce - Affected Extension version and Chrome version - Any proof-of-concept (minimal is best)

  3. Allow reasonable time to investigate and remediate before public disclosure. We aim to acknowledge reports within 14 days when possible.

Safe harbor

We will not pursue legal action against researchers who report issues in good faith, avoid privacy violations and service disruption, and give us a reasonable opportunity to fix the issue—consistent with commonly accepted responsible disclosure practices.

No bug bounty

Unless we explicitly announce one, there is no paid bug bounty program.

Out of scope

The following are generally out of scope for this policy:

Disclaimer

This policy does not create a contractual obligation beyond applicable law. Security fixes are provided without warranty; see TERMS.md.