Back to Safety & Support

SECURITY

Help keep Ground Games secure.

Ground Games treats account, movement, location, and identity information as sensitive. This page explains how to report a security issue responsibly and the safeguards we use at a high level.

Last updated August 19, 2026

Report a security issue

Email support@kndrd.fit with the subject “Ground Games Security Report.” Include a concise summary, the affected screen or public URL, steps to reproduce, and the potential impact.

Do not send passwords, access tokens, authorization codes, full GPS routes, private keys, or another person’s personal data. We aim to acknowledge reports within 2 business days.

Responsible disclosure

Use only accounts and data you own or have explicit permission to test. Stop testing and contact us immediately if you encounter another person’s data or a risk to service availability.

Do not use social engineering, phishing, denial-of-service activity, destructive changes, privacy invasion, spam, or automated testing that could degrade Ground Games or its service providers. This page does not create a bug bounty or authorize access beyond normal product use.

What we protect

  • Account sessions, profile identity, and role-based Crew access.
  • Activities, saved scores, Region decisions, and personal Ground Records.
  • Precise location and route evidence used for activity and Region verification.
  • Private Profile and Crew media and their short-lived access links.
  • Future provider credentials and exercise data only when a provider connection is explicitly approved and built.

Safeguards

Ground Games uses authenticated access, server-side ownership and role checks, private media storage, short-lived signed media access, protected server credentials, and duplicate-safe activity and score authority. Sensitive credentials are not placed in public app configuration.

Precise routes are kept private. Region evidence coordinates are processed by protected server authority and are not returned in public results or stored in public tables. Security controls are reviewed as Ground Games changes, but no service can guarantee absolute security.

Connected activity sources

Ground Games GPS is currently the only official V1 activity source. Ground Games has not enabled Apple Health, Garmin, Health Connect, Polar, COROS, Fitbit or Google Health API, or Samsung Health connections.

Before any future connection launches, access must be user-authorized and limited to the minimum exercise data needed. Provider tokens and webhook secrets must remain server-side, webhook requests must be authenticated and replay-resistant, and precise route evidence must remain private and transient.

Incident response

When a credible report is received, Ground Games will triage the issue, limit exposure where possible, investigate affected systems, preserve necessary security records, and notify affected people or authorities when required by applicable law.

Related resources

Ground Games operates this service. This page does not claim a security certification, penetration test, HIPAA compliance, or a paid vulnerability-reward program.