Report abuse
Last updated 23 August 2026.
UseQR has no accounts, no database and no email system. That means there is no support inbox and no ticket queue behind a contact form — so we have not built one. A form that posts nowhere is worse than no form, because it makes a person believe they have been heard. Instead, every route below reaches a real, checkable place.
Abuse of something we host
A malicious QR image being served from a useqr.app address, misuse of the API or MCP server, or anything else that breaks the Acceptable Use Policy on infrastructure we run.
Open a GitHub issue →Issues are public. Do not paste personal data, credentials, or anything you would not want indexed. If the report itself is sensitive, use the private route below instead.
A security vulnerability, or a sensitive report
Anything that should not be public until it is fixed, and anything in the child-safety category. Private GitHub security advisories are end-to-end private between you and the maintainers until we publish.
Open a private security advisory →The full scope, safe harbour and disclosure terms are on the security policy page.
What to include
A report that can be acted on in one pass, rather than after three rounds of questions, contains:
- The exact URL on our domain, copied in full including its query string. For a hosted image this is the whole
/q/…or/api/…address. This is usually the single most important line in the report. - The destination the code resolves to, written as plain text rather than a clickable link so nobody triggers it by accident.
- The category — phishing, malware, payment redirection, harassment, child safety, or other — using the names from the Acceptable Use Policy.
- When and where you saw it, with a timestamp in UTC. If it was a physical sticker or a poster, say so and give the location — that changes what can usefully be done about it.
- Evidence — a screenshot or a photo. Redact anything personal before you attach it to a public issue.
What to expect
Being straight about this matters more than sounding professional. UseQR is maintained by a very small number of people in their own time. There is no rota, no on-call and no service level agreement, and we are not going to invent one.
- Acknowledgement: we aim to reply within five working days.
- Child sexual abuse material is handled as fast as it reaches us, ahead of everything else, and is referred to law enforcement. Send it through the private advisory route.
- Active phishing or fraud using something we host is treated as urgent.
- Everything else is best effort, in public, in the issue tracker — where you can see the status yourself rather than wondering.
What we can actually do is described on the Acceptable Use Policy page: we can refuse to serve things from our own endpoints and ask our host to block traffic. We cannot revoke a static QR code, because we never had it — it was built in the creator’s browser and we hold no copy or record of it.
A scam QR code we did not host
Most people who arrive on a page like this one have scanned a sticker on a parking meter, a restaurant table or a package, and something went wrong. If UseQR is not hosting it, a report to us achieves nothing, and we would rather send you somewhere useful in the next sixty seconds than take your report politely.
- If you paid money or entered a password: contact your bank or payment provider first, immediately, and change the password everywhere you reused it. Do that before you report anything to anyone.
- The malicious page: report it to Google Safe Browsing and to Microsoft, which puts a warning in front of the next person to scan it.
- The physical sticker: tell whoever owns the surface — the shop, the council, the car park operator. A code pasted over a genuine one is usually news to them, and they can remove it today.
- Law enforcement: report the fraud to your national body. In India that is cybercrime.gov.in or the 1930 helpline; in the UK, Action Fraud; in the US, the FBI IC3.
You can also paste the code into our scanner to read its destination safely without opening it, which is a good habit before trusting any code you did not print yourself.
Something on this site is wrong
A factual error in the documentation, a broken claim in a policy, an accessibility barrier: all of it is a bug and all of it goes to the same issue tracker. The source is open, so if you already know the fix, a pull request is faster than a conversation.
Security policy → · Acceptable Use Policy → · Privacy Policy →