Skip to content
Pocket Genes

Security

Incident-Reporting Contact

Explains how to report privacy, account, safety, accessibility, and security concerns, including a vulnerability-disclosure path.

Purpose and scope

This page explains how to report a privacy incident, account issue, exposed access reference, community safety problem, organization concern, accessibility support request, or security report involving Pocket Genes.

It separates user incidents from vulnerability research so reporters know what to include, what not to include, and what Pocket Genes will do next.

Who this page applies to

  • Pocket Genes users, caregivers, invited users, and account holders.
  • People affected by a privacy, community, accessibility, or organization issue.
  • Security researchers reporting a vulnerability in good faith.
  • Integrators, providers, and Trusted Organizations reporting a workflow issue.

Definitions

Privacy, account, or safety incident

A concern involving unauthorized account access, unexpected exposure of personal information, misdirected invitations, disclosed links or codes, community safety issues, organization misuse, or loss of account control.

Security vulnerability

A technical weakness that could affect confidentiality, integrity, availability, authentication, authorization, or access controls in Pocket Genes.

Good-faith research

Testing that stays within the published scope, avoids harm, avoids unnecessary data access, reports promptly, and gives Pocket Genes a reasonable opportunity to remediate.

Report a privacy, account, accessibility, or safety incident

Email support@goldencrowvs.com with a subject such as "Pocket Genes privacy incident", "Pocket Genes account compromise", "Pocket Genes exposed report link", "Pocket Genes accessibility support", or "Pocket Genes community safety report".

Reportable situations include unauthorized account access, an invitation sent to the wrong person, unexpected exposure of personal information, a private link or access code disclosed, information received without expected authority or basis, community disclosure of another person information, suspected abuse by an organization, and loss of account control.

What to include and what not to include

  • Include the affected page, app screen, organization, account workflow, report code type, community area, or API if known.
  • Include approximate date, time, time zone, device, browser, app version, assistive technology, and steps to reproduce when relevant.
  • Include screenshots only when useful and redact passwords, tokens, full genetic reports, unrelated medical information, and other people personal information where possible.
  • Do not send passwords, one-time codes, authentication tokens, full reports, full medical records, or private keys unless Pocket Genes asks for a limited item through a safer follow-up path.

Triage and updates

Pocket Genes reviews reports, classifies the issue, checks urgency, limits internal access to people who need the information, and may request identity verification before discussing account-specific details.

Urgent risks involving active account compromise, exposed report-access references, vulnerable users, organization abuse, or broad security impact are prioritized. Updates may be limited when disclosure would affect another person privacy, security, legal obligations, or an active investigation.

Report a security vulnerability

Security vulnerabilities can be reported to support@goldencrowvs.com. The public security.txt file also points researchers to this channel.

Covered scope includes public Pocket Genes pages, Pocket Genes Trust Center, Pocket Genes account and report-access APIs, Pocket Genes mobile app surfaces, RareFriends community features, and trusted-organization publishing workflows controlled by Pocket Genes.

Authorized research and prohibited activity

  • Allowed: good-faith testing against accounts and data you control, passive inspection of public pages, and minimal proof-of-concept testing needed to demonstrate impact.
  • Do not perform denial-of-service testing, social engineering, physical attacks, destructive testing, spam, credential stuffing, or attempts to bypass rate limits at scale.
  • Do not access, copy, retain, modify, delete, or share another user information beyond the minimum needed to demonstrate a vulnerability.
  • Do not publish details before Pocket Genes has had a reasonable opportunity to investigate and remediate.

Safe harbor and response process

Pocket Genes intends not to pursue good-faith researchers for accidental, limited activity that follows this policy, avoids privacy harm, avoids service disruption, and is reported promptly. This safe-harbor statement is subject to applicable law and does not protect extortion, privacy violations, destructive activity, or bad-faith conduct.

A useful vulnerability report includes affected component, reproduction steps, impact, supporting evidence, researcher contact, whether any user information was accessed, and whether the issue appears actively exploitable. Pocket Genes aims to acknowledge receipt, triage based on severity, provide status updates when practical, remediate according to risk, and coordinate disclosure where appropriate.

Pocket Genes responsibilities

  • Maintain clear reporting channels for incidents and vulnerabilities.
  • Triage reports according to privacy, safety, security, accessibility, and operational risk.
  • Contain and remediate confirmed issues according to severity.
  • Communicate with reporters where appropriate and preserve records needed for accountability.

Reporter responsibilities

  • Report promptly and provide enough detail to investigate.
  • Avoid unnecessary access to private information.
  • Do not disrupt services or test outside scope.
  • Keep vulnerability details confidential until coordinated disclosure is agreed or a reasonable remediation window has passed.

Exceptions and limitations

  • Pocket Genes is not an emergency medical, crisis, law-enforcement, or 24/7 monitoring service.
  • Some reports may belong to a provider, app store, external website, or organization outside Pocket Genes control.
  • Legal, security, and privacy constraints may limit the detail Pocket Genes can share about outcomes.

How to make a request or report a problem

Privacy, account, deletion, accessibility, safety, trusted-organization, and security requests can be sent to support@goldencrowvs.com. Use a subject line that identifies the issue, the affected Pocket Genes account or workflow, and whether the request is urgent.

Pocket Genes may need to verify the requester before changing or disclosing account information. Verification is handled proportionally to the request, the sensitivity of the information, and the risk of giving account access or private information to the wrong person.

Effective date, version, and review history

ItemValue
Effective dateAugust 14, 2026
Version1.1
Last reviewedAugust 2026
Material changesExpanded Trust Center format, operator identity, data-map boundaries, request paths, and responsibility sections.
Previous versionJuly 2026 Trust Center overview copy.

Related pages

Related pages