Home

Security

Last updated September 16, 2026

If you have found a way to read, change or delete something in Peachy that you should not be able to, we want to hear about it before anyone else does. Email support@pchy.app with “security” in the subject line, and a person will read it. This address is also published at /.well-known/security.txt.

What we promise

  • A reply within three working days saying we have it and who is looking at it.
  • A fix or a plan within thirty days for anything that exposes one person’s content or account to another. If it takes longer, we will say why and keep you updated.
  • Credit, if you want it, on this page once the fix has shipped, under the name you choose.
  • No legal action against research done in good faith under the rules below. We consider it authorised, and we will say so to anyone who asks.
  • A reward, at our discretion, for reports that show a real exposure. We are a small team and do not publish a tariff; what we can promise is that a serious finding, reported well, will not go unthanked.

What we ask

  • Test against your own accounts, or accounts you have made for the purpose. Do not read, change or delete other people’s content, even if a bug lets you. If you find you can, stop and tell us.
  • Do not run automated scanners against pchy.app or api.pchy.app at a rate that degrades the service for other people, and do not attempt denial of service.
  • Give us the thirty days above before publishing. If we ask for more time, we will explain why.
  • Do not use social engineering, phishing or physical access against our team or our providers.

In scope

  • The apps: Peachy for iPhone, Mac and Android, and the web app at pchy.app.
  • The API at api.pchy.app.
  • The way we use our providers, described in the Privacy Policy: anything that would send content to a provider we did not name, or to a provider under terms we did not describe, is a finding.

Out of scope: the providers themselves (Anthropic, Tinfoil, Twilio, Apple, Google, Render), which have their own programmes; issues that need a jailbroken or rooted device; missing best-practice headers with no demonstrated impact; and reports from automated tools with no working reproduction.

What Peachy does and does not claim

So you know where the bar is. Peachy stores messages on our servers in a form we can read, and is not end-to-end encrypted. Parts of your content go to the AI providers named in the Privacy Policy. One of them runs its models inside confidential-computing enclaves — you can verify which code from your own browser — but that is a property of where the model runs, not a claim that Peachy cannot read your messages. A report that Peachy’s servers can read content is therefore a description of the design, not a vulnerability. A report that content reaches somewhere the Privacy Policy does not say it goes is exactly what this page is for.

Thanks

Nobody yet. Be the first.