Security

Security and Responsible Disclosure

Report vulnerabilities or data-protection concerns privately so the team can investigate before details are shared publicly.

Report a security issue

Email support@dancing-bee.com with subject "Security report" and include the affected URL or app area, device type, app or browser version, reproduction steps, and impact.

Never include passwords, sign-in or verification codes, authentication or deletion tokens, full identity documents, or other unnecessary personal data. If sensitive evidence is needed, support will arrange a safer transfer method.

Do not access other users data, run destructive tests, or publicly disclose an issue before we have had time to investigate.

Security posture

The backend uses HTTPS, JWT/refresh token controls, Firebase verification paths, Google Secret Manager, MongoDB, rate limits, audit logs, and redaction for sensitive diagnostics.

Production secrets must never be stored in GitHub, local repo files, public pages, or reviewer notes.

App-store privacy information

Testers and reviewers should compare the final signed app and its network behaviour with the privacy information published in each store. Store declarations include data processed by integrated third-party SDKs even when Dancing Bee does not use advertising or cross-app tracking.

The checked-in Apple App Privacy and Google Play Data safety worksheets remain owner-review drafts until they are reconciled with the exact submitted builds and published in the store consoles.