Report abuse
Last updated 23 August 2026.
UseQR has no accounts, no database and no email system. That means there is no support inbox and no ticket queue behind a contact form, so we have not built one. A form that posts nowhere is worse than no form, because it makes a person believe they have been heard. Instead, every route below reaches a real, checkable place.
Abuse of something we host
A malicious QR image being served from a useqr.app address, misuse of the API or MCP server, or anything else that breaks the Acceptable Use Policy on infrastructure we run.
Email the maintainer →One inbox, read by one person. Include the URL and what you saw; a screenshot helps. Do not paste credentials or anything you would not want in an email.
A security vulnerability, or a sensitive report
Anything that should not be public until it is fixed, and anything in the child-safety category. It stays between you and the maintainer until a fix has shipped.
Email a private report →The full scope, safe harbour and disclosure terms are on the security policy page.
What to include
A report that can be acted on in one pass, rather than after three rounds of questions, contains:
- The exact URL on our domain, copied in full including its query string. For a hosted image this is the whole
/q/…or/api/…address. This is usually the single most important line in the report. - The destination the code resolves to, written as plain text rather than a clickable link so nobody triggers it by accident.
- The category: phishing, malware, payment redirection, harassment, child safety, or other, using the names from the Acceptable Use Policy.
- When and where you saw it, with a timestamp in UTC. If it was a physical sticker or a poster, say so and give the location, that changes what can usefully be done about it.
- Evidence, a screenshot or a photo. Redact anything personal before you attach it to a public issue.
What to expect
Being straight about this matters more than sounding professional. UseQR is maintained by a very small number of people in their own time. There is no rota, no on-call and no service level agreement, and we are not going to invent one.
- Acknowledgement: we aim to reply within five working days.
- Child sexual abuse material is handled as fast as it reaches us, ahead of everything else, and is referred to law enforcement. Send it through the private route above.
- Active phishing or fraud using something we host is treated as urgent.
- Everything else is best effort, and you will get a reply from a person rather than a ticket number.
What we can actually do is described on the Acceptable Use Policy page: we can refuse to serve things from our own endpoints and ask our host to block traffic. We cannot revoke a static QR code, because we never had it. It was built in the creator’s browser and we hold no copy or record of it.
A scam QR code we did not host
Most people who arrive on a page like this one have scanned a sticker on a parking meter, a restaurant table or a package, and something went wrong. If UseQR is not hosting it, a report to us achieves nothing, and we would rather send you somewhere useful in the next sixty seconds than take your report politely.
- If you paid money or entered a password: contact your bank or payment provider first, immediately, and change the password everywhere you reused it. Do that before you report anything to anyone.
- The malicious page: report it to Google Safe Browsing and to Microsoft, which puts a warning in front of the next person to scan it.
- The physical sticker: tell whoever owns the surface: the shop, the council, the car park operator. A code pasted over a genuine one is usually news to them, and they can remove it today.
- Law enforcement: report the fraud to your national body. In India that is cybercrime.gov.in or the 1930 helpline; in the UK, Action Fraud; in the US, the FBI IC3.
You can also paste the code into our scanner to read its destination safely without opening it, which is a good habit before trusting any code you did not print yourself.
Something on this site is wrong
A factual error in the documentation, a broken claim in a policy, an accessibility barrier: all of it is a bug and all of it goes to the same inbox. The source is open, so if you already know the fix, a pull request is faster than a conversation.
Security policy → · Acceptable Use Policy → · Privacy Policy →