Last updated: October 5, 2026
We take reasonable care in designing the Extension, but no software is perfectly secure. This document describes how to report security issues and what you can expect.
| Version | Supported |
|---|---|
| Latest release on the Chrome Web Store | Yes |
| Older store versions | Best effort only |
| Unpacked / developer builds from source | Supported only for the current main branch at report time |
storage and https://www.twitch.tv/* only (see manifest.json).<all_urls> access.If you believe the Extension behaves differently (e.g. unexpected network requests, data exfiltration), please report it.
Please do not open a public GitHub issue for security-sensitive reports.
Prefer GitHub Private Security Advisories on the public contact repository:
https://github.com/kzmanakzm-cpu/MellowForTwitch-privacy/security/advisories/new
(If that repository cannot accept advisories, use the store developer contact email listed on the Chrome Web Store.)
Include: - A clear description and impact - Steps to reproduce - Affected Extension version and Chrome version - Any proof-of-concept (minimal is best)
Allow reasonable time to investigate and remediate before public disclosure. We aim to acknowledge reports within 14 days when possible.
We will not pursue legal action against researchers who report issues in good faith, avoid privacy violations and service disruption, and give us a reasonable opportunity to fix the issue—consistent with commonly accepted responsible disclosure practices.
Unless we explicitly announce one, there is no paid bug bounty program.
The following are generally out of scope for this policy:
This policy does not create a contractual obligation beyond applicable law. Security fixes are provided without warranty; see TERMS.md.