OpenClassOpenClass Legal
Safety instructions
We protect accounts, course materials, and model credentials based on the principles of least privilege, session isolation, and revocable access, and continue to improve protection.
Last updated: July 28, 2026
Accounts and Sessions
Formal accounts use HttpOnly security cookies issued by the server to maintain sessions and support password rotation and exit from all sessions. Login, registration, verification code, and password retrieval are subject to frequency limits and Cloudflare Turnstile human verification.
Data and transmission
Production traffic is encrypted via HTTPS; sensitive configurations are not written to the public code repository; user-level model credentials are isolated by account. Public sharing and community posting should not automatically include private material, and users should still review content before posting.
security response
We will record necessary security events, limit abnormal requests, and after confirming the event, take measures such as revoking sessions, fixing vulnerabilities, retaining evidence, and notifying affected users. The specific notification time will be subject to applicable laws and incident investigation needs.
Responsible Disclosure
If you discover a vulnerability that may affect OpenClass or its users, please send an email to hello@open-classes.com, describing the impact, steps to reproduce and necessary evidence. Do not access other people’s data, disrupt services, conduct social engineering, or expose unpatched vulnerabilities.
We will acknowledge receipt of the report and assess the risk, but are not committing to bug bounties at this time. Tests that are legitimate, in good faith, and adhere to the above boundaries will be prioritized for coordination.
What users can do
Use a unique and long enough password to protect your email and third-party accounts, and check your login status regularly; if any abnormalities are found, immediately change your password and log out of all sessions. Do not paste passwords, payment credentials, or API keys in courses, chats, or public communities.