And folks, this is why you sell your exploits to the highest bidder. Being "good" and giving companies free work is a HORRIBLE idea. They're never gonna pay, or even than you. If they're not willing to treat security researchers properly, I see no reason to return the favor. Remember security groups: if your company wont pay, there are others that will.
Did you not see the part where applicants info was exposed? Make a few bucks by selling their data to is 10000x worse than the chatr dev not securing the files.
Actually downloading the data from a hack and selling it is expressly illegal.
Now if the person/group you're selling to expresses illegal actions as a result, you have a duty not to sell. So, don't ask, and dont tell!
The real solution: companies all should allow for bug bounties and good-faith reporting and proper compensation for reported issues. But as long as they don't another group WILL pay.