DuckyHelper
HomeFeatures
StudentsAboutPricingSign inDownload
Download
HomeFeaturesStudentsAboutPricingSign inDownload

Security & Responsible Disclosure

Version 1.0 · Effective October 1, 2026
1. How we protect DuckyHelper
2. Reporting a vulnerability
3. Good-faith research and safe harbor
4. Rewards
5. Contact

In short

  • Found a security problem? Email security@duckyhelper.com. We'll reply within 5 business days.
  • Test in good faith, only with your own accounts, and give us time to fix it before you tell anyone. If you do, we won't take legal action against you.
  • We don't run a paid bug bounty, but we'll gladly thank you publicly if you'd like.

This page is from MingLLM, Inc., which makes DuckyHelper. It describes how we protect your information and how to report a vulnerability.

1. How we protect DuckyHelper

  • In transit: the app, the website and our servers talk only over HTTPS. The voice connection to our AI provider is encrypted (WebRTC with DTLS-SRTP).
  • At rest: our databases and file storage are encrypted at rest by AWS. Files are never public, and links to them expire after one hour.
  • Secrets: passwords are stored only as salted PBKDF2-SHA256 hashes. Google connection tokens are encrypted with a managed key. AI and payment provider keys stay on our servers and never reach your Mac.
  • Access: every request is checked against your sign-in and can reach only your own information. Sign-ins expire after 7 days. A child's information is reachable only by the child's account and the parent's.
  • The app: signed with our Apple Developer ID and notarized by Apple. Updates are signed with our own key and checked before they install, so a tampered update is refused. On-screen actions refuse password fields, and live viewing pauses while a password field has focus.
  • Payments: card details are handled only by Stripe.
  • Data minimization: we don't keep your voice audio or screen pictures (unless saved to memory), and we keep your age group, never your birthday.

No system is perfectly secure. If a breach affects your information, we'll tell you and the authorities as the law requires.

2. Reporting a vulnerability

Email security@duckyhelper.com with:

  • what you found and where (the app version, the page or the API path),
  • how to reproduce it, step by step,
  • what an attacker could do with it,
  • how to reach you.

Please don't put sensitive data (yours or anyone's) in the report beyond what's needed. We'll acknowledge your report within 5 business days, keep you updated, and tell you when it's fixed.

3. Good-faith research and safe harbor

If you research and report in good faith under these rules, we consider it authorized, we won't pursue legal action or ask law enforcement to act against you for it, and we'll work with you to understand and fix the problem.

Please:

  • test only with accounts you own or have permission to use;
  • stop as soon as you see someone else's data, don't keep or share it, and tell us;
  • don't degrade the service (no load or denial-of-service testing, no spam);
  • don't use social engineering, phishing or physical attacks against people or our providers;
  • don't test our providers' systems (AWS, OpenAI, Google, Stripe, Apple); report issues in them to them;
  • give us a reasonable time to fix the problem (we aim for 90 days) before telling anyone else.

Out of scope: reports from automated scanners without a demonstrated impact, missing security headers without an exploit, self-cross-site-scripting, clickjacking on pages with no sensitive actions, and attacks that need a compromised device.

This safe harbor covers only MingLLM's own claims. We can't authorize testing of other companies' systems. If you're unsure whether something is in scope, ask us first.

4. Rewards

We don't offer paid bounties at this time. If you'd like, we'll thank you by name on this page once the issue is fixed.

5. Contact

security@duckyhelper.com. For anything else: support@duckyhelper.com.

Product
The DuckyHelper pill, listening
DuckyHelper for Mac

A live voice tutor for anything on your screen. Press fn, ask out loud, and Ducky shows you.

Get the Mac app
The streak card from the DuckyHelper dashboard
Your dashboard

Time learned, your streak, topics and mastery, tests, and everything Ducky made for you.

See features
Product
Home
Features
Students
Get the Mac app
Try it free in your browser
Sign in
Resources
Pricing
Help
Study guides
Free tools
Compare
Best AI tutors
Changelog
Company
About
Press
MingLLM
Legal
Privacy
Terms
Cookies
All legal
DuckyHelper
Copyright © 2026 MingLLM, Inc. All rights reserved.
Terms
Privacy
Cookies
Your privacy choices
DuckyHelper app icon
DuckyHelper
The AI tutor that shows you
FREE TO TRY
Try it free