Curio is distributed as a signed APK from GitHub Releases. Only the latest published release receives security fixes — always update to the newest version.
Please do not open a public issue for a security vulnerability until it has been addressed.
- Preferred: use GitHub's private vulnerability reporting (repo Security → Report a vulnerability), if it is enabled on this repository.
- Alternative: open a GitHub Issue with
[security]in the title, and let the maintainer triage privately from there.
Please include:
- The app version (Profile → Support & diagnostics → Version) and Android version.
- A clear description of the issue and, if possible, steps to reproduce.
- Whether the issue affects stored data (the app is fully offline — captures live only on-device and in backups).
Curio is an offline-first app: there is no server, no accounts, and no cloud sync. Issues with the bundled topic content (factual errors in descriptions) belong in the issues tracker, not here.