Security End-to-end encryption Privacy policy Terms of use Data collection Delete account Abuse reporting
Mango Mango Private Your own messenger
Contact us
Home

Abuse Policy

Abuse policy and reporting

Mango Private is a corporate messenger with end-to-end encryption. Each Mango Private instance is operated by an organization on its own infrastructure. The organization's administrator bears primary responsibility for moderation and handling user complaints within their instance. OffshoreLabs (the developer) does not have direct access to message content or user data unless the operator grants it. This page explains who handles what, what can be reported, and how escalation to OffshoreLabs works.

Effective date: 25 August 2026

Who handles complaints

Mango Private is a self-hosted product. Each organization deploys and operates its own instance. This means:

  • The organization's administrator is the primary point of contact for all user complaints, moderation decisions, and content disputes within their Mango Private instance. The administrator has access to account management, can warn, suspend, or remove users, and controls server-side policies.
  • OffshoreLabs Studio LTD (the developer) does not bear direct responsibility for handling complaints within the private domain of a specific organization, unless a report is sent directly to abuse@mango-private.com.
  • If you cannot resolve an issue through your organization's administrator, or if the complaint concerns the administrator themselves, you may escalate directly to OffshoreLabs.

Where to write

Within your organization: contact your Mango Private administrator directly. They have the tools and access to investigate and act on complaints within your instance.

Escalation to OffshoreLabs: send abuse reports to abuse@mango-private.com. This is a separate mailbox from general inquiries and legal requests — we prioritise abuse mail.

Please include:

  • the reported user's nickname (in @handle form, visible on the profile card);
  • the chat nickname (for groups and channels, in @handle form), if the incident occurred there;
  • the organization / instance where the incident took place;
  • date and approximate time of the incident;
  • screenshots, screen recording, or saved files — without them we usually cannot verify the content (see the end-to-end encryption section below);
  • your own nickname so we can follow up with you.

If you use the "Report" button on a message inside the app, you select a report topic and the report sends that topic and the five latest messages from the chat to the moderation service for your organization's instance.

Block, Report, and Block & Report

Direct chats offer three separate actions. They are handled by the moderation service for the organization that operates your Mango Private instance.

  • Block. Moves the direct chat to your archive; you may delete it later. Blocking on its own does not submit a moderation report.
  • Report. You select a report topic, then that topic and the five latest messages from the chat are sent to moderation.
  • Block & Report. Moves the direct chat to your archive and submits the report with the selected topic and five latest messages at the same time.

The excerpt is sent only when you choose Report or Block & Report. It does not give the organization or OffshoreLabs access to the rest of the conversation.

What you can report

The categories below are what we accept reports about and are prepared to act on. The list is non-exhaustive — if something looks like abuse but doesn't fit a bucket here, write anyway.

Threats and harassment

Direct threats of violence, stalking, sustained harassment, blackmail, doxxing (disclosure of personal information without consent).

Sexual exploitation of minors

CSAM, sexualised contact attempts toward minors (grooming), recruitment into related activity. These reports are treated with priority and, where required by law, information is shared with law-enforcement authorities.

Non-consensual intimate imagery

Distribution of intimate images without the depicted person's consent (NCII / "revenge"), and threats to do so.

Spam and phishing

Mass unsolicited messaging, attempts to harvest credentials, impersonation of support services, links to malware.

Impersonation

Accounts created to deceive: posing as a specific private individual, organisation, or Mango Private support.

Coordinated malicious behaviour

Bot networks, account farms, coordinated attacks on a specific user or group, manipulation campaigns.

Illegal goods and services

Sale of weapons, drugs, stolen data, malware, commissioned services of an unlawful nature.

Incitement to violence

Calls to violence against specific people or groups, terrorism, organised hate.

What we don't act on

  • Internal organizational disputes. Mango Private is a corporate messenger: workplace disagreements, management decisions, and internal policy matters are the responsibility of the organization, not OffshoreLabs.
  • Content you have consented to. If you are voluntarily part of a chat between adults and you set its tone yourselves, we are not a moderator of personal communication.
  • Disagreements over politics, religion, taste. We do not moderate discussions between adults as long as they do not cross into threats or the categories listed above.
  • Third-party reports. The reporter must be a participant of the chat (or the legal guardian of a minor participant). Reports from outsiders who have no access to the chat cannot be reviewed because we cannot verify them.
  • Off-platform behaviour. Conflicts that happened on other services, messengers, or offline are outside our scope.
  • Reports without evidence. End-to-end encryption means we cannot independently see the content of a conversation. Without screenshots or other evidentiary material we can only take metadata-level action (see the next section).
  • Government / legal requests. Those go through a separate process — please write to legal@mango-private.com.

End-to-end encryption and what it means for reports

Neither OffshoreLabs nor the organization's server infrastructure can arbitrarily read your messages, voice notes, photos, or video. Each is encrypted on the sender's device with keys held only by the chat participants (more about how encryption works). The exception is the excerpt a user deliberately sends by choosing Report or Block & Report. That obliges both the organization's administrator and OffshoreLabs to handle abuse differently from messengers that store content server-side:

  • Content. An in-app report sends the selected topic and five latest chat messages; you may also attach screenshots, recordings, or chat exports. A request to "pull the message from the database" is technically impossible — what is on the server is an encrypted blob.
  • Metadata is available in a limited form: sender and recipient IDs, message timestamps, the fact that media was attached and its size, push-notification records, the forwarding count (an open metadata field showing how many times a message has been forwarded), account-level history (creation date, originating device class, previous abuse decisions).
  • Metadata-based action. The organization's administrator can block an account, stop a rolling spam wave, revoke active sessions and tokens, and limit new-account creation — without seeing content, when the behavioural pattern is already enough.
  • What won't work. "Read the old conversation for me", "produce the message content for a court", "restore a deleted message" — neither the administrator nor OffshoreLabs can do that. If a conversation matters as evidence, save it on your device immediately.

What the app does itself, without reading your messages

End-to-end encryption prevents the node operator and OffshoreLabs from seeing message content, but it does not prevent the app from warning you. Everything described below runs entirely on your device: nothing is matched against databases, sent to a server, or reported to the operator, OffshoreLabs, or any third party.

How a link is written. Before opening a link in a message, the app examines how its address is written and warns you if it appears deceptive: it contains an @ character that would send the browser to a different site; the site name uses look-alike characters from another alphabet; invisible characters are hidden in the address; or a numeric server address is used instead of a site name. The link is neither blocked nor hidden — the app shows where it actually leads, and you decide whether to continue.

Warning about an unfamiliar sender. Until you reply in a chat that you did not start, a panel at the top offers Delete, Block, and Report.

Notice when entering a public group. When you first open a public group, the app tells you that it is a public surface and offers to report it or leave if its content is not right for you.

What we do not do. The node operator and OffshoreLabs do not scan the content of your messages — on the device, on a server, against databases of prohibited material, or by any other means. Any such scan would disclose the conversation's contents without the sender's and recipient's consent and would be incompatible with the promise of end-to-end encryption itself.

Public groups and channels

Public groups and channels work differently from direct conversations and are moderated differently. Anyone can become a member of a public surface, so the node operator treats it as a publication, rather than a private conversation, when a report is received.

What the operator can do. Following a substantiated report, a public group or channel is hidden from search and no longer opens at its @channel_name or @group_name address; it stops accepting new messages, while its history remains available to existing members. The owner and administrators receive a notice in the group itself, and the suspension warning is also visible to group or channel members.

48 hours to object. From suspension, the owner has 48 hours to write to the node operator at igetbanned@mango-connect.com. The surface cannot be deleted before that period ends — this is a restriction built into the moderation system. If an objection is received, the decision is reconsidered before deletion, not after. If none is received, the group or channel is deleted after 48 hours without the possibility of restoration.

How moderation currently works. At present, the node operator does not apply automated anti-spam filtering or hash matching to material in public groups and channels. A human moderator promptly reviews every report; CSAM and credible threats of violence are handled immediately and receive the highest priority.

A person makes the decision. Each suspension, reinstatement, and deletion is performed manually by an organization moderator and recorded in a log with the reason and the person who took the action. We do not automatically delete publications.

What happens after a report

The organization operating your Mango Private instance is responsible for handling every report:

  1. Review. The organization operator reviews every report within 24 hours of receipt.
  2. Triage. Every report is assigned to a moderator for human review; an automated decision does not replace it.
  3. Context gathering. The organization operator verifies screenshot authenticity through available metadata where possible and cross-checks against earlier reports.
  4. Decision. The organization operator tells you what action it took without disclosing internal investigation detail or the reported person's personal data.
  5. Action and timing. Where a violation is substantiated, the organization operator removes the offending content from surfaces it controls and permanently ejects the account that provided it within the same 24-hour period. CSAM and credible threats of violence receive immediate, highest-priority handling.

Possible outcomes

By the organization's administrator (within their instance):

  • Warning to the reported user.
  • Temporary suspension of the account.
  • Permanent removal of the account from the instance.
  • Restriction on new account creation.

By OffshoreLabs (when escalated to abuse@mango-private.com):

  • Guidance to the operator. We may advise the organization's administrator on appropriate action.
  • License-level action. For severe or repeated violations, OffshoreLabs reserves the right to suspend or revoke the organization's Mango Private license.
  • Law-enforcement referral. CSAM, credible threats of violence, and similar cases are referred to the appropriate authorities and we share the metadata we hold within the limits of the law.

If you disagree with a decision

If the decision was made by your organization's administrator, appeal through your organization's internal process.

If the decision was made by OffshoreLabs, you can appeal within 14 days of our response by replying to abuse@mango-private.com with the subject "Appeal: [case number]". Appeals are reviewed by a different reviewer than the one who issued the original decision. If the appeal is upheld we roll back the action and explain why we reversed.

Contacts

Abuse reports

abuse@mango-private.com

Escalated reports: user-generated content, spam, threats, CSAM, phishing.

Support

support@offshorelabs.dev

General questions about the product and deployments.

Legal requests

legal@mango-private.com

Requests from government bodies, courts, and legal representatives. Please do not use this mailbox for user reports — we will route you back to abuse@.

Mango Private is developed by OffshoreLabs Studio LTD, a company registered in the United Kingdom under company number 17387215. Each Mango Private instance is operated by the purchasing organization on its own infrastructure. Legal and operational correspondence reaches OffshoreLabs through the mailboxes listed above.

Related documents

  • End-to-end encryption on Mango Private
  • Privacy policy
  • Delete account
Mango Private Your own messenger for your organization. request@mango-private.com support@offshorelabs.dev © 2026 OffshoreLabs Studio LTD, a company registered in the United Kingdom under company number 17387215.
MangoConnect Security End-to-end encryption Privacy policy Terms of use Data collection Delete account Abuse reporting