Mia is a client-only PWA: there is no backend, database server, or user accounts. All personal data stays in the browser (IndexedDB) on the user's device.
If you find a security problem, please open a GitHub issue with a clear description. Do not post live exploit details publicly until a fix is available, if the issue is severe.
- No API keys, tokens, passwords, or private credentials in the repository
- Backup import validates file size, row count, and schema; blocks
__proto__/constructorkeys - User-visible strings are escaped before insertion into HTML (
esc()) - Share links encode to-do data in the URL (base64); they are not encrypted — anyone with the link can read them
- PIN is a local screen lock (SHA-256 hash in IndexedDB), not encryption of stored data
- HTTP security headers via
vercel.json(CSP,X-Frame-Options,nosniff, etc.)
| Topic | Note |
|---|---|
| PIN | Convenience lock only; data on disk is not encrypted |
| Share links | Readable by anyone who has the URL |
| Backup JSON | Contains all app data in plain text — treat exports as sensitive |
| Offline cache | Service worker caches static assets; no user data in the cache |
- jsPDF (
jspdf.umd.min.js) — bundled minified build for PDF reports
Keep third-party files updated when you bump Mia releases.