Security
Last updated: August 26, 2026
Todoza takes the security of user accounts and data seriously, including data connected through integrations such as the Amazon Ads API.
Reporting a vulnerability or security concern
If you believe you've found a security vulnerability, a privacy issue, or you suspect a security incident affecting Todoza or your account, please report it to us directly at:
When reporting, please include as much detail as you can:
- a description of the issue and its potential impact;
- steps to reproduce it, if applicable;
- any relevant URLs, account identifiers, or timestamps.
Please do not include passwords, API keys, or other secrets in your report. Please also avoid testing against other users' accounts or data without authorization.
What happens next
We review security reports as they come in and respond directly to the reporter. Confirmed issues are triaged, fixed, and handled under our internal incident response process, including notifying affected users where appropriate.
Amazon Ads API integration
Where Todoza connects to a user's Amazon Ads account, any suspected incident involving Amazon Ads credentials, tokens, or data is also reported to Amazon in accordance with Amazon's applicable policies.
We appreciate responsible disclosure and will not pursue legal action against good-faith security research that follows this process.