← Vooka

Security

Last updated: 3 August 2026

Vooka is operated by UNLIKE ANOTHER LLC. This page explains how to reach us about a security problem and what happens after you do.

We would rather hear about a problem from you than from someone exploiting it. If you have found something, please tell us — you will not be penalised for reporting in good faith.

Reporting a security issue

Email security@vooka.studio.

Use this address for:

  • a security vulnerability in Vooka, our website, or our browser extension
  • a privacy concern about how data is handled
  • suspected misuse of advertising data, including data belonging to a connected Amazon Advertising account
  • anything that looks like unauthorised access to an account or to data

If the issue affects your own account and is urgent, say so in the subject line.

What to include

The more of this you can give us, the faster we can act:

  • what you found, described plainly
  • the URL, page, or API endpoint involved
  • the steps to reproduce it
  • what you expected to happen and what actually happened
  • any screenshot, request or response that shows it (with your own credentials removed)
  • whether you believe any real customer data was exposed, and roughly how much
  • how you would like to be credited, if you want to be

Please do not include passwords, API keys, or access tokens in your report. If a credential is part of the finding, tell us that it is and we will arrange a safe way to share it.

What we will do

  1. Acknowledge. We confirm we have received your report and give you a reference for it.
  2. Triage. We assess severity and what is affected.
  3. Investigate and fix. We work the issue through to a resolution and keep it tracked until it is closed, not until it goes quiet.
  4. Tell you the outcome. We let you know what we found and what we changed.

Vooka is a small operation and we do not staff a 24/7 security desk. We would rather tell you that than publish a response time we cannot honour. Reports are read on business days and anything that looks like an active compromise is picked up as soon as we see it.

Incidents involving Amazon Advertising data

Vooka connects to the Amazon Advertising API on behalf of authors who choose to link their advertising accounts. If an incident affects Amazon Advertising credentials or advertising data, we follow our internal incident-response process, which requires us to report the incident to Amazon at security@amazon.com as well as notifying affected customers.

Amazon advertising credentials are encrypted and are never sent to Anthropic or any other AI provider. They are processed only by authorized infrastructure providers as necessary to operate the integration — the hosting, database and monitoring services Vooka runs on. Anthropic, our AI provider, receives only aggregate campaign figures: never credentials, account identifiers, keywords, customer search terms, ASINs or book titles.

Testing, and what we ask of you

If you are investigating a potential issue, please:

  • only test against an account you own
  • do not access, modify, or delete anyone else's data
  • do not run denial-of-service tests, spam, or automated scans that degrade the service
  • do not use social engineering against our people or our customers
  • give us a reasonable opportunity to fix the issue before making it public

We do not currently run a paid bug bounty. We are genuinely grateful for reports and will credit you if you would like us to.

Other contacts

  • Privacy questions and data requests: privacy@vooka.studio
  • General support: support@vooka.studio

See also our Privacy Policy and Terms of Service.

Vooka is a product and trading name operated by UNLIKE ANOTHER LLC, a Florida limited liability company, Document Number L22000197361.

See also Privacy Policy.