Help us keep Collie safe.
Effective date: August 1, 2026
Collie is built around local first data handling and explicit approval for consequential actions. Early access is still early, and responsible reports help us find and fix gaps.
Report a vulnerability privately
When this repository offers GitHub's private vulnerability reporting control, use it first. If it is not available, email hello@heycollie.com. Please include a clear description, affected version or page, steps to reproduce, the likely impact, and any proof of concept that does not expose another person's information.
Please do not post vulnerability details publicly before we have had a reasonable opportunity to investigate and respond.
Safe research boundaries
Only test accounts, devices, and data you own or are explicitly authorized to test. Do not access other users' information, interrupt the website or service, use social engineering, or attempt to obtain credentials. Stop testing if you encounter real personal data or an unexpected security boundary.
What we will do
We will review good faith reports, work to understand the issue, and communicate when we have a meaningful update. We may ask follow up questions or request a safer, redacted reproduction. We cannot promise a bounty, a publication timeline, or a specific fix date.
Data and providers
Collie is designed to keep its working state on the Windows device by default. If a person connects a model provider, the content needed for that request may be sent to that provider. Security reports should not include API keys, passwords, full personal documents, or other secrets.
Other help
For a non security product problem, use hello@heycollie.com. For waitlist or privacy requests, see Privacy.