Keeping your account safe.
What we do to protect your account and record, what you can do yourself, and how to tell us if you find a problem.
Last updated 4 October 2026
1What we do
- Encrypted everywhere. Every connection to sublevo.app is HTTPS, and browsers are told never to connect over plain HTTP.
- Your rows are yours. Every row of account and study-record data in our database is locked to the account that owns it, enforced by the database itself, not just by the app. A signed-in student cannot read or change anyone else’s data, and a visitor who is not signed in can read none of it.
- Passwords are never stored. Only a one-way hash is kept, by our authentication provider. Passwords must be at least 8 characters.
- Safe password resets. A reset link works once, for a short time, and changing your password signs you out of every other device.
- No secrets in your browser. The pages are static questions and notes. The only key they carry is a public one that can do nothing a signed-out visitor could not; your password is sent straight to sign-in and is never kept in the page.
- Hardened pages. Sublevo cannot be embedded inside another site (which blocks click-jacking), and after signing in you are only ever sent to a page of this site.
- Little to lose. We hold no payment details, no phone numbers and no addresses; see the privacy policy.
2What you can do
- Use a password you do not use anywhere else, or sign in with Google.
- Sign out on shared or school computers: signing out also removes the copy of your record kept on that device.
- Sublevo will never ask you for a password, a payment or personal details by email. Only type your password on sublevo.app.
- If something looks wrong on the site, write to support@sublevo.app.
3Reporting a vulnerability
If you think you have found a security problem in Sublevo, please write to support@sublevo.app with “Security” in the subject line. Include what you found, the steps to reproduce it, and the pages or requests involved. Please do not share it publicly until we have fixed it.
We will acknowledge your report within a few working days and keep you told as we fix it.
4Testing in good faith
We will not take action against anyone who reports a problem to us in good faith and follows these rules:
- test only against your own account: never access, change or delete anyone else’s data;
- if you reach someone else’s data by accident, stop, and tell us what you saw;
- no denial-of-service, flooding, spam, or automated scanning that degrades the site;
- no phishing or social engineering of students or of us.
Sublevo is a small, free project and does not run a paid bug bounty, but we are genuinely grateful, and will credit you if you would like.