Please do not open a public issue for security problems.
Report privately via GitHub: Security → Report a vulnerability, or email support@splitease.app with the subject "Security".
Include what you found, steps to reproduce, and the potential impact. We aim to acknowledge reports within 5 days.
Anything in this repository: the mobile app, its auth flow, handling of tokens and payments/UPI links, and deep links. Please don't test against other users' accounts or production data.
If you spot a committed credential, report it the same way rather than opening an issue.