Security
Report vulnerabilities responsibly.
If you believe ImageSave or imagesave.app has a security issue, send a concise report to security@imagesave.app. Please minimize sensitive data and give us a reasonable opportunity to investigate before public disclosure.
What to include
- Affected ImageSave version, page, or website URL.
- Impact and the conditions required to reproduce it.
- Minimal, step-by-step reproduction instructions.
- A safe proof of concept, if one is necessary.
- Any suggested mitigation or disclosure timeline.
Do not attach raw browser profiles, passwords, access tokens, private images, or unrelated personal information. Ordinary email is not end-to-end encrypted, and no PGP key is currently published.
Safe research boundaries
Test only on systems and data you own or have explicit permission to use. Avoid privacy violations, denial of service, persistence, data destruction, automated high-volume traffic, or attempts to bypass authentication, paywalls, DRM, or browser security controls.
What happens next
Reports are reviewed on a best-effort basis. We may ask for clarification, confirm whether the issue is reproducible, prepare a fix, and coordinate a reasonable disclosure window. No acknowledgement or resolution deadline is guaranteed during the pre-release period.
Security design notes
The current extension candidate has no remote code, developer-owned image service, install-time persistent all-sites grant, account system, ad code, or runtime analytics SDK. Optional image-host and clipboard access are requested at the point of use. These choices reduce exposure, but they do not make the software free of defects.
For the exact access model, read Permissions. For product data boundaries, read the Privacy Policy.