Legal & trust
Security
How Typing Station protects accounts and data, and how to report a potential vulnerability.
Effective 12 July 2026 · Beta version
Current safeguards
Typing Station uses Supabase authentication, row-level database policies, user-scoped reads and writes, private attempt details, restricted admin roles and HTTPS hosting. Passwords are handled by the authentication provider and are not stored in the Typing Station application database.
Account controls
You can change your password, make your public profile private, delete saved statistics or permanently delete your account. Use a unique password and sign out on shared devices.
Responsible disclosure
If you believe you found a vulnerability, submit a private vulnerability report with clear reproduction steps and the affected URL. Do not access other users’ data, disrupt the service, perform denial-of-service testing or publicly disclose an unresolved issue.
Response
We will acknowledge useful reports when practical, investigate based on severity and work toward a proportionate fix. This Beta does not currently operate a paid bug-bounty programme.
Limits
No system is perfectly secure. This page describes current practices rather than a warranty, certification or independent security audit.