Report the signal, not your private content.
Support reports are opt-in and attach nothing automatically.
Product or reliability issue
Send a private support report with app version, time and timezone, safe reproduction steps, expected/observed behavior, and any visible correlation or error ID. Do not attach workspace files, prompts, generated content, environment values, tokens, payment details, or credentials unless support requests a specific minimized sample and you approve it.
Security vulnerability
Email security@toyolabs.ca. Do not access other users' data, perform destructive testing, or disclose an unpatched issue publicly. Include the affected surface, impact, safe reproduction, and your contact details.
Suspected incident
Stop the affected action, preserve the visible error ID and time, and report it promptly. For suspected credential exposure, revoke the relevant session or integration where safe and contact support.