Effective Date: August 2, 2026
Last Updated: August 2, 2026
1. Reporting a vulnerability
If you believe you have found a security vulnerability, please tell us at hello@mybirthbridge.com with "Security" in the subject line.
Please include what you found, where, and how to reproduce it. English is fine; so is French or Spanish.
What we commit to:
| Step | |
|---|---|
| We acknowledge your report | Within 2 business days |
| We give you our initial assessment | Within 10 business days |
| We keep you updated while we work on it | At least every 30 days |
| We tell you when it is resolved | As soon as it is |
We will credit you if you would like to be credited, and keep your name out of it if you would not.
2. Safe harbour
If you research in good faith under this policy, we will not pursue legal action against you, and we will not report you to law enforcement. If someone else brings a claim against you for research that followed this policy, we will make it known that your activity was authorized.
This is a commitment we intend to honour in spirit, not a document to be read against you on a technicality. If you are unsure whether something is in scope, ask us first.
In scope: mybirthbridge.com and its subdomains.
Out of scope: anything belonging to our service providers, which run their own disclosure programs, and third-party services a professional links to from a booking, such as their own video meeting link.
3. Please do not
- Access, modify, or delete anyone else's information. Use your own test accounts. If you find a way to reach another person's data, stop there and tell us.
- Download or keep personal information. If you come across any, tell us and delete it. A screenshot with details redacted is enough; please do not retain a copy as proof.
- Run denial of service or load testing, or automated scanning heavy enough to affect people using the service.
- Use social engineering, phishing, or physical intrusion against our team, our users, or our vendors.
- Publish before we have resolved it. Please give us 90 days, or longer if we agree it together. If you think we are moving too slowly, tell us and we will agree a date with you.
- Ask for payment in exchange for withholding a report.
Health information deserves extra care. This platform holds information about people's pregnancies. If your research leads toward message content or health information, please stop earlier than you otherwise would and tell us what you saw. We treat that as a more valuable report, not a less welcome one.
We do not currently offer a paid bug bounty. We offer acknowledgement, credit, and a responsive process.
4. How we protect information
Our safeguards are described in Section 8 of the Privacy Policy and Section 7 of the Health Information Policy. In summary: encryption in transit, message content encrypted at rest using per-user key pairs, access to production systems and personal information limited to staff whose role requires it and logged, and review of the service providers we rely on.
What we do not claim:
- No system is completely secure, and we do not say ours is.
- We do not offer end-to-end encryption. BirthBridge holds the technical means to decrypt message content and does so only in the limited circumstances listed in Section 3.1 of the Health Information Policy.
Organizations evaluating BirthBridge for a formal compliance review can request our security documentation at hello@mybirthbridge.com. See Section 10 of Health Information Agreements.
5. If something happens
If a security incident affects your information, we will investigate, notify you and the relevant regulators where required, tell you what happened and what information was involved, explain what we are doing about it, and tell you what you can do.
We aim to notify affected users without undue delay and within 72 hours of confirming a reportable breach, and we meet any shorter deadline the law imposes. Section 8 of the Privacy Policy sets out the notification rules that apply.
6. Contact
BirthBridge, LLC
Texas, United States
hello@mybirthbridge.com
Related documents
Related documents
- Terms and Conditions
- Privacy Policy
- Consumer Health Data Policy
- Health Information Policy
- Cookie Policy
- Trust and Safety Policy
- Referral and Affiliate Program Terms
- Copyright and DMCA Policy
Questions about any of this? Email hello@mybirthbridge.com.