01 / Security approach
otherthing separates private member records from narrow public projections. Authentication, authorisation and storage rules are enforced through the connected service as well as in the app.
We do not describe otherthing as independently audited, penetration-tested or security-certified. Those claims would require separate evidence.
Never send passwords, Sign in with Apple credentials, camera serial numbers, precise location or source photographs when reporting a security concern.
02 / Current controls
- Member authentication through Sign in with Apple or controlled email registration.
- Row-level access policies separating owner-only records from approved public projections.
- Private storage for photographic derivatives and exact, member-scoped paths for public profile images.
- Newly rendered JPEG sharing copies with source metadata, precise location, filename and original path removed.
- Account-scoped blocking, content reporting and authenticated account deletion.
03 / Member responsibilities
Use a strong, unique password if you register by email. Keep your device and operating system current, review content before publishing and remove access from a device you no longer control.
Capture metadata can be sensitive even when it does not contain precise GPS. Share only the context you are comfortable making visible to other members or guests.
04 / Report a concern
Use the operator contact route and identify the message as an otherthing security report. Include the affected surface, the time observed, a concise reproduction path and the least sensitive evidence needed to understand the issue.
Do not access, alter or retain another person's data to prove a concern. There is no public bug-bounty or safe-harbour programme at this stage.
Contact the operator