Skip to content
UseQR
ESC

Jump to

MOVEOPEN50 places

Report abuse

Last updated 23 August 2026.

UseQR has no accounts, no database and no email system. That means there is no support inbox and no ticket queue behind a contact form, so we have not built one. A form that posts nowhere is worse than no form, because it makes a person believe they have been heard. Instead, every route below reaches a real, checkable place.

Abuse of something we host

A malicious QR image being served from a useqr.app address, misuse of the API or MCP server, or anything else that breaks the Acceptable Use Policy on infrastructure we run.

Email the maintainer →

One inbox, read by one person. Include the URL and what you saw; a screenshot helps. Do not paste credentials or anything you would not want in an email.

A security vulnerability, or a sensitive report

Anything that should not be public until it is fixed, and anything in the child-safety category. It stays between you and the maintainer until a fix has shipped.

Email a private report →

The full scope, safe harbour and disclosure terms are on the security policy page.

What to include

A report that can be acted on in one pass, rather than after three rounds of questions, contains:

  • The exact URL on our domain, copied in full including its query string. For a hosted image this is the whole /q/… or /api/… address. This is usually the single most important line in the report.
  • The destination the code resolves to, written as plain text rather than a clickable link so nobody triggers it by accident.
  • The category: phishing, malware, payment redirection, harassment, child safety, or other, using the names from the Acceptable Use Policy.
  • When and where you saw it, with a timestamp in UTC. If it was a physical sticker or a poster, say so and give the location, that changes what can usefully be done about it.
  • Evidence, a screenshot or a photo. Redact anything personal before you attach it to a public issue.

What to expect

Being straight about this matters more than sounding professional. UseQR is maintained by a very small number of people in their own time. There is no rota, no on-call and no service level agreement, and we are not going to invent one.

  • Acknowledgement: we aim to reply within five working days.
  • Child sexual abuse material is handled as fast as it reaches us, ahead of everything else, and is referred to law enforcement. Send it through the private route above.
  • Active phishing or fraud using something we host is treated as urgent.
  • Everything else is best effort, and you will get a reply from a person rather than a ticket number.

What we can actually do is described on the Acceptable Use Policy page: we can refuse to serve things from our own endpoints and ask our host to block traffic. We cannot revoke a static QR code, because we never had it. It was built in the creator’s browser and we hold no copy or record of it.

A scam QR code we did not host

Most people who arrive on a page like this one have scanned a sticker on a parking meter, a restaurant table or a package, and something went wrong. If UseQR is not hosting it, a report to us achieves nothing, and we would rather send you somewhere useful in the next sixty seconds than take your report politely.

  • If you paid money or entered a password: contact your bank or payment provider first, immediately, and change the password everywhere you reused it. Do that before you report anything to anyone.
  • The malicious page: report it to Google Safe Browsing and to Microsoft, which puts a warning in front of the next person to scan it.
  • The physical sticker: tell whoever owns the surface: the shop, the council, the car park operator. A code pasted over a genuine one is usually news to them, and they can remove it today.
  • Law enforcement: report the fraud to your national body. In India that is cybercrime.gov.in or the 1930 helpline; in the UK, Action Fraud; in the US, the FBI IC3.

You can also paste the code into our scanner to read its destination safely without opening it, which is a good habit before trusting any code you did not print yourself.

Something on this site is wrong

A factual error in the documentation, a broken claim in a policy, an accessibility barrier: all of it is a bug and all of it goes to the same inbox. The source is open, so if you already know the fix, a pull request is faster than a conversation.

Security policy → · Acceptable Use Policy → · Privacy Policy →