SharetoBoard
Security

Responsible disclosure.

Found a security issue in the SharetoBoard Android app or this website? Thanks for telling us. Here's how to do it safely and what you can expect in return.

Last updated: 2026-09-08. See also /.well-known/security.txt.

Get releases directly from SharetoBoard

Our tools are offered directly through SharetoBoard.com: web tools open here, and installable tools download here when released. We are launching directly, not through Google Play or the Chrome Web Store.

Only install signed Android packages and check the download's published verification details. Download updates from SharetoBoard.com and follow the instructions for your product; Chrome Basic updates are installed manually. Keep your device's security protections on, and contact support if they block installation.

We do not ask customers to share Poppy accounts, passwords or API keys for app-store review. Sign in to Poppy yourself, and never email credentials to support. See how direct access works.

Signing in to Poppy

Use Poppy’s email-and-password option inside SharetoBoard Android. Google sign-in is not supported in the app’s embedded Poppy window.

SharetoBoard does not copy a Google or Clerk sign-in session into the app. Never send passwords, sign-in codes, session cookies or API keys to support.

This limit applies to SharetoBoard’s sign-in window, not to the safety of Google sign-in elsewhere.

How to report

Email security@sharetoboard.com with:

  • A clear description of the issue and why it matters
  • Steps to reproduce (URLs, APK build, Android version)
  • Any proof-of-concept, logs, or screenshots
  • Your preferred contact and whether you want credit

If you need to send sensitive material, ask for a PGP key in your first message and we'll reply with one.

What we commit to

  • Acknowledge your report within 3 business days.
  • Keep you updated with a realistic timeline as we investigate.
  • Fix confirmed issues as quickly as the severity warrants and publish signed Android updates through SharetoBoard.com.
  • Credit you publicly (with your permission) once the fix is live.
  • Never pursue legal action against good-faith researchers who follow this policy.

In scope

  • The SharetoBoard Android app (com.stb.sharetoboard) distributed directly through SharetoBoard.com
  • sharetoboard.com and its subdomains we operate
  • The Notion OAuth endpoints at /api/notion/*
  • Data handling described in our Privacy Policy

Out of scope

  • Third-party services we don't control (Poppy, Notion, Google Play, ThriveCart, Vercel)
  • Vulnerabilities that require a rooted / compromised device
  • Rate-limit or best-practice issues with no demonstrated impact
  • Reports from automated scanners without validation
  • Social engineering of the maintainer or users

Please do not

  • Access, modify, or delete data that isn't yours
  • Run automated scanners that generate significant traffic
  • Attempt denial-of-service, spam, or phishing
  • Publish the issue before a fix is available and we've agreed on a disclosure date

Safe harbor

If you act in good faith, follow this policy, stop at proof-of-concept, and don't harm users or data, we will not consider your research a violation of our Terms of Use and will not pursue legal action. This is not a paid bug bounty, but credit and our sincere thanks are guaranteed.