im-ok — Security
Last updated: 5 October 2026
How to report a security problem in im-ok, what happens after you do, and how long im-ok gets security updates.
Report a vulnerability
Email security@im-ok.com, in English or Swedish. It helps if you include:
- what you found and where: the app, its server, im-ok.com or the im-ok pages on emilalm.app;
- the steps to reproduce it, and the app and iOS version if it concerns the app;
- what an attacker could do with it;
- whether you want to be credited, and under what name.
Don't put other people's personal data in your report. If you came across some, tell us what kind it was, not the data itself.
For anything that is not about security, write to support@im-ok.com instead.
What happens next
- We confirm that we got your report within 5 working days.
- We assess it and tell you what we found and what we plan to do.
- We fix confirmed vulnerabilities as quickly as their severity calls for, and tell you when the fix is out.
- Once it is fixed, we credit you if you want us to.
There is no bug bounty.
Coordinated disclosure
Please don't publish a vulnerability until a fix is out, or until 90 days have passed since your report, whichever comes first. If a fix needs longer, we will tell you why and agree on a new date with you.
Testing in good faith
We will not take legal action against you, or report you to the police, for research that follows these rules:
- Use only your own accounts, or accounts whose owners have agreed to it.
- Access no more of other people's data than you need to show the problem. If you reach someone else's data, stop, don't keep it, and tell us.
- Don't send login codes in bulk or to numbers that aren't yours. Each code costs money and reaches a real phone.
- Don't trigger missed-check-in alerts or notifications to people who haven't agreed to it.
- No denial of service, spam or social engineering.
- Don't attack the services im-ok runs on, such as Apple, Google, Supabase, Twilio or Vercel. Report problems in them to them.
How we tell users
The App Store release notes say when an update fixes a security problem. If a vulnerability in im-ok is being actively exploited, or a security incident affects im-ok, we tell the users affected directly: what happened, and what they can do to protect themselves. We report such vulnerabilities and incidents to the authorities as EU law requires.
Security updates
im-ok 2.0 and later versions get security updates until at least October 2031. Updates come through the App Store, so install them when they are offered, or turn on automatic updates. im-ok 1.x no longer works and gets no updates (see our privacy policy, section 3).
Who is responsible
im-ok is made by Emil Alm, an individual based in Sweden. His postal address is in section 23 of our terms. This page is also available in machine-readable form at im-ok.com/.well-known/security.txt.