← Spyglass

Security Policy

Last updated: July 15, 2026

Supported versions

Spyglass is a rolling release. Only the latest published build receives security fixes. If you are running an older build, update before reporting an issue.

Reporting a vulnerability

Please do not open a public issue for security vulnerabilities. Report privately through one of:

Please include:

What to expect

Please give a reasonable window to release a fix before any public disclosure.

Scope

Spyglass is a Quick Look Preview Extension plus a host app that signs into Google (OAuth) to fetch rendered previews of Google Workspace files. It uses the read-only drive.readonly scope, caches previews only on your Mac, and has no server. Reports touching credential handling, OAuth token storage, the Google client-secret configuration, or preview fetching are in scope. Do not include real secrets, tokens, or personal documents in a report — redact them.