If you find a vulnerability in afterglow.watch or in this code, mail hello@afterglow.watch with "security" in the subject and skip the public issue. That inbox is read by a person, usually within a day or two.
There is no user data here: no accounts, no visitor tokens, and the store holds nothing but public star counts. The surfaces worth probing are the badge and enrollment endpoints and the daily collector.
No bounty program; this is one person and a small service. Credit in the fix's commit message if you want it, gladly.