Lucy← Back to home

Security & Disclosure

Last updated 2026. How to reach us about security, and how we handle reports.

Reporting an issue

If you believe you have found a security issue, email hello@hirelucy.com with the steps to reproduce it and any supporting detail. Please give us a reasonable chance to fix it before sharing it publicly.

We aim to acknowledge reports within three working days and to keep you updated while we investigate.

What we ask

Test only against your own account and your own connected sites. Do not access, modify or delete other people's data.

Do not run denial-of-service tests, spam, social engineering, or physical attacks against us or our providers.

Stop as soon as you have confirmed an issue, and tell us rather than exploiting it further.

Account safety on your side

Use a unique password, keep the email address on your account current, and remove integrations you no longer use from settings.

Only connect sites and search accounts you are authorised to manage. Access tokens you grant can be revoked at any time from your provider and from Lucy's settings.

Scope

This page covers hirelucy.com and the Lucy application. Issues in third-party services should be reported to those providers directly.

We do not currently run a paid bug bounty, but we are glad to credit researchers who report responsibly.

Contact

Security reports go to hello@hirelucy.com.