Skip to content
UseQR
ESC

↑↓ MOVE↵ OPEN48 PLACES

Report abuse

Last updated 23 August 2026.

UseQR has no accounts, no database and no email system. That means there is no support inbox and no ticket queue behind a contact form — so we have not built one. A form that posts nowhere is worse than no form, because it makes a person believe they have been heard. Instead, every route below reaches a real, checkable place.

Abuse of something we host

A malicious QR image being served from a useqr.app address, misuse of the API or MCP server, or anything else that breaks the Acceptable Use Policy on infrastructure we run.

Open a GitHub issue →

Issues are public. Do not paste personal data, credentials, or anything you would not want indexed. If the report itself is sensitive, use the private route below instead.

A security vulnerability, or a sensitive report

Anything that should not be public until it is fixed, and anything in the child-safety category. Private GitHub security advisories are end-to-end private between you and the maintainers until we publish.

Open a private security advisory →

The full scope, safe harbour and disclosure terms are on the security policy page.

What to include

A report that can be acted on in one pass, rather than after three rounds of questions, contains:

  • The exact URL on our domain, copied in full including its query string. For a hosted image this is the whole /q/… or /api/… address. This is usually the single most important line in the report.
  • The destination the code resolves to, written as plain text rather than a clickable link so nobody triggers it by accident.
  • The category — phishing, malware, payment redirection, harassment, child safety, or other — using the names from the Acceptable Use Policy.
  • When and where you saw it, with a timestamp in UTC. If it was a physical sticker or a poster, say so and give the location — that changes what can usefully be done about it.
  • Evidence — a screenshot or a photo. Redact anything personal before you attach it to a public issue.

What to expect

Being straight about this matters more than sounding professional. UseQR is maintained by a very small number of people in their own time. There is no rota, no on-call and no service level agreement, and we are not going to invent one.

  • Acknowledgement: we aim to reply within five working days.
  • Child sexual abuse material is handled as fast as it reaches us, ahead of everything else, and is referred to law enforcement. Send it through the private advisory route.
  • Active phishing or fraud using something we host is treated as urgent.
  • Everything else is best effort, in public, in the issue tracker — where you can see the status yourself rather than wondering.

What we can actually do is described on the Acceptable Use Policy page: we can refuse to serve things from our own endpoints and ask our host to block traffic. We cannot revoke a static QR code, because we never had it — it was built in the creator’s browser and we hold no copy or record of it.

A scam QR code we did not host

Most people who arrive on a page like this one have scanned a sticker on a parking meter, a restaurant table or a package, and something went wrong. If UseQR is not hosting it, a report to us achieves nothing, and we would rather send you somewhere useful in the next sixty seconds than take your report politely.

  • If you paid money or entered a password: contact your bank or payment provider first, immediately, and change the password everywhere you reused it. Do that before you report anything to anyone.
  • The malicious page: report it to Google Safe Browsing and to Microsoft, which puts a warning in front of the next person to scan it.
  • The physical sticker: tell whoever owns the surface — the shop, the council, the car park operator. A code pasted over a genuine one is usually news to them, and they can remove it today.
  • Law enforcement: report the fraud to your national body. In India that is cybercrime.gov.in or the 1930 helpline; in the UK, Action Fraud; in the US, the FBI IC3.

You can also paste the code into our scanner to read its destination safely without opening it, which is a good habit before trusting any code you did not print yourself.

Something on this site is wrong

A factual error in the documentation, a broken claim in a policy, an accessibility barrier: all of it is a bug and all of it goes to the same issue tracker. The source is open, so if you already know the fix, a pull request is faster than a conversation.

Security policy → · Acceptable Use Policy → · Privacy Policy →