In scope
- The SharetoBoard Android app (
com.stb.sharetoboard) from Google Play sharetoboard.comand its subdomains we operate- The Notion OAuth endpoints at
/api/notion/* - Data handling described in our Privacy Policy
Found a security issue in the SharetoBoard Android app or this website? Thanks for telling us. Here's how to do it safely and what you can expect in return.
Last updated: 2026-07-10. See also /.well-known/security.txt.
SharetoBoard Beta supports Poppy email-and-password sign-in only. The current Poppy/Clerk integration does not provide a supported way to return a completed Google sign-in session to SharetoBoard's embedded experience.
SharetoBoard blocks Google sign-in navigation instead of extracting, copying, or relaying Google or Clerk identity tokens. Google sign-in may be reconsidered only through a provider-supported native handoff or a first-party Poppy integration.
This is a limitation of the current independent integration. It is not a claim that Google sign-in is unsafe or that email/password is inherently more secure.
Email security@sharetoboard.com with:
If you need to send sensitive material, ask for a PGP key in your first message and we'll reply with one.
com.stb.sharetoboard) from Google Playsharetoboard.com and its subdomains we operate/api/notion/*If you act in good faith, follow this policy, stop at proof-of-concept, and don't harm users or data, we will not consider your research a violation of our Terms of Use and will not pursue legal action. This is not a paid bug bounty, but credit and our sincere thanks are guaranteed.