Security
If you found a security problem in Gloss, please tell us. Email security@joingloss.app.
Reporting a vulnerability
- Email security@joingloss.app with what you found, how to reproduce it, and what an attacker could do with it.
- We confirm we got it within 2 business days and keep you updated until it's fixed.
- Please give us reasonable time to fix it before telling anyone else.
- Use only your own test accounts. Never access, change or delete another person's data. If you reach student data by accident, stop, don't keep a copy, and tell us.
- No denial of service, spam, social engineering of our team or students, or physical attacks.
We don't run a paid bug bounty yet. We're glad to credit you by name when the fix ships, if you'd like.
Machine readable contact details: /.well-known/security.txt.
In scope
- The Gloss iPhone app, the Gloss Mac and Windows apps
- The Gloss service behind them
- This website, joingloss.app
Google's, Microsoft's, Apple's and Anthropic's own systems are out of scope; report problems there to them.
How we protect student data
- Isolation: every table that holds student data uses database row level security, and automated tests that try to read another student's data run on every change and must fail.
- Encryption: email sign in tokens and stored email are encrypted with a key unique to each student, and calendar feed links with a separate key, all held outside the database. Deleting an account destroys the student's key, so their stored email and tokens can't be read again, even from a backup.
- Least access: email is read only, by the student signing in with Google or Microsoft. Gloss can't send, delete or change mail.
- Short retention: the subject and body of each email are deleted 30 days after Gloss reads it.
- AI safety: email that matches sensitive words or senders never goes to AI. Email text is treated as data, never as instructions; AI output must fit a strict format and can't trigger actions.
- Logs: email text is not written to logs, and error reports from the iPhone app and servers are scrubbed of email content, tokens and feed links.
- Accounts: no passwords stored anywhere. Sign in with Apple, Google or a one time email code; Face ID or Touch ID before sensitive actions; every signed in device visible and revocable.
- Support access: support can't see a student's account unless the student turns access on; it turns off after 24 hours, and every change is recorded. Never the text of emails.
If something goes wrong, we follow a written incident response plan and tell affected students and schools as the law requires.