Security fixes are applied to the latest released version and the default branch.
Please do not open a public issue for a suspected vulnerability. Use GitHub's private vulnerability reporting for this repository and include:
- the affected version and platform;
- steps to reproduce with synthetic data;
- the expected and observed impact; and
- any suggested mitigation, if known.
Do not include real Life Diff backups, personal timeline data, signing credentials, or access tokens. If private vulnerability reporting is unavailable, open a minimal public issue asking the maintainer to enable a private contact channel without disclosing technical details.
Life Diff stores workspace data in the local WebView profile and can export readable JSON backups. It does not claim to encrypt data at rest. Users are responsible for protecting their operating-system account, device, and exported backups.