We welcome reports from security researchers and players.
Wheel of Misfortune is a for-fun game, but we take the security and privacy of our players seriously. If you believe you've found a security vulnerability, we'd like to hear about it so we can fix it quickly.
This page is for security vulnerabilities (things that could put accounts or data at risk). For an ordinary bug, signed-in players can use Report a bug in the app footer instead.
Our commitment
We won't pursue or support legal action against researchers who act in good faith and follow this policy.
We'll acknowledge valid reports and keep you updated as we work on a fix.
We're a small volunteer project, so we can't offer a paid bug bounty - but genuine finds earn our sincere thanks (and credit, if you'd like it).
Please do
Give us a reasonable chance to fix an issue before disclosing it publicly.
Only test against your own account and teams.
Provide enough detail for us to reproduce the issue.
Please don't
Access, modify, or delete data that isn't yours, or degrade the service for other players (no denial-of-service or spam).
Use social engineering, phishing, or physical attacks against our team or infrastructure.
Run automated scanners that generate heavy traffic.
Report a vulnerability
Send us the details using the form below. Include what you found, the steps to reproduce it, and the potential impact. Leave your email if you'd like us to follow up.