Threats and harassment
Direct threats of violence, stalking, sustained harassment, blackmail, doxxing (disclosure of personal information without consent).
Abuse Policy
Mango Private is a corporate messenger with end-to-end encryption. Each Mango Private instance is operated by an organization on its own infrastructure. The organization's administrator bears primary responsibility for moderation and handling user complaints within their instance. OffshoreLabs (the developer) does not have direct access to message content or user data unless the operator grants it. This page explains who handles what, what can be reported, and how escalation to OffshoreLabs works.
Mango Private is a self-hosted product. Each organization deploys and operates its own instance. This means:
Within your organization: contact your Mango Private administrator directly. They have the tools and access to investigate and act on complaints within your instance.
Escalation to OffshoreLabs: send abuse reports to abuse@mango-private.com. This is a separate mailbox from general inquiries and legal requests — we prioritise abuse mail.
Please include:
@handle
form, visible on the profile card);@handle form), if the incident occurred there;If you use the "Report" button on a message inside the app, you select a report topic and the report sends that topic and the five latest messages from the chat to the moderation service for your organization's instance.
Direct chats offer three separate actions. They are handled by the moderation service for the organization that operates your Mango Private instance.
The excerpt is sent only when you choose Report or Block & Report. It does not give the organization or OffshoreLabs access to the rest of the conversation.
The categories below are what we accept reports about and are prepared to act on. The list is non-exhaustive — if something looks like abuse but doesn't fit a bucket here, write anyway.
Direct threats of violence, stalking, sustained harassment, blackmail, doxxing (disclosure of personal information without consent).
CSAM, sexualised contact attempts toward minors (grooming), recruitment into related activity. These reports are treated with priority and, where required by law, information is shared with law-enforcement authorities.
Distribution of intimate images without the depicted person's consent (NCII / "revenge"), and threats to do so.
Mass unsolicited messaging, attempts to harvest credentials, impersonation of support services, links to malware.
Accounts created to deceive: posing as a specific private individual, organisation, or Mango Private support.
Bot networks, account farms, coordinated attacks on a specific user or group, manipulation campaigns.
Sale of weapons, drugs, stolen data, malware, commissioned services of an unlawful nature.
Calls to violence against specific people or groups, terrorism, organised hate.
Neither OffshoreLabs nor the organization's server infrastructure can arbitrarily read your messages, voice notes, photos, or video. Each is encrypted on the sender's device with keys held only by the chat participants (more about how encryption works). The exception is the excerpt a user deliberately sends by choosing Report or Block & Report. That obliges both the organization's administrator and OffshoreLabs to handle abuse differently from messengers that store content server-side:
End-to-end encryption prevents the node operator and OffshoreLabs from seeing message content, but it does not prevent the app from warning you. Everything described below runs entirely on your device: nothing is matched against databases, sent to a server, or reported to the operator, OffshoreLabs, or any third party.
How a link is written. Before opening a link in a
message, the app examines how its address is written and warns you
if it appears deceptive: it contains an @ character
that would send the browser to a different site; the site name uses
look-alike characters from another alphabet; invisible characters
are hidden in the address; or a numeric server address is used
instead of a site name. The link is neither blocked nor hidden —
the app shows where it actually leads, and you decide whether to
continue.
Warning about an unfamiliar sender. Until you reply in a chat that you did not start, a panel at the top offers Delete, Block, and Report.
Notice when entering a public group. When you first open a public group, the app tells you that it is a public surface and offers to report it or leave if its content is not right for you.
What we do not do. The node operator and OffshoreLabs do not scan the content of your messages — on the device, on a server, against databases of prohibited material, or by any other means. Any such scan would disclose the conversation's contents without the sender's and recipient's consent and would be incompatible with the promise of end-to-end encryption itself.
Public groups and channels work differently from direct conversations and are moderated differently. Anyone can become a member of a public surface, so the node operator treats it as a publication, rather than a private conversation, when a report is received.
What the operator can do. Following a substantiated
report, a public group or channel is hidden from search and no
longer opens at its @channel_name or
@group_name address; it stops accepting new messages,
while its history remains available to existing members. The owner
and administrators receive a notice in the group itself, and the
suspension warning is also visible to group or channel members.
48 hours to object. From suspension, the owner has 48 hours to write to the node operator at igetbanned@mango-connect.com. The surface cannot be deleted before that period ends — this is a restriction built into the moderation system. If an objection is received, the decision is reconsidered before deletion, not after. If none is received, the group or channel is deleted after 48 hours without the possibility of restoration.
How moderation currently works. At present, the node operator does not apply automated anti-spam filtering or hash matching to material in public groups and channels. A human moderator promptly reviews every report; CSAM and credible threats of violence are handled immediately and receive the highest priority.
A person makes the decision. Each suspension, reinstatement, and deletion is performed manually by an organization moderator and recorded in a log with the reason and the person who took the action. We do not automatically delete publications.
The organization operating your Mango Private instance is responsible for handling every report:
By the organization's administrator (within their instance):
By OffshoreLabs (when escalated to abuse@mango-private.com):
If the decision was made by your organization's administrator, appeal through your organization's internal process.
If the decision was made by OffshoreLabs, you can appeal within 14 days of our response by replying to abuse@mango-private.com with the subject "Appeal: [case number]". Appeals are reviewed by a different reviewer than the one who issued the original decision. If the appeal is upheld we roll back the action and explain why we reversed.
Escalated reports: user-generated content, spam, threats, CSAM, phishing.
General questions about the product and deployments.
Requests from government bodies, courts, and legal representatives. Please do not use this mailbox for user reports — we will route you back to abuse@.
Mango Private is developed by OffshoreLabs Studio LTD, a company registered in the United Kingdom under company number 17387215. Each Mango Private instance is operated by the purchasing organization on its own infrastructure. Legal and operational correspondence reaches OffshoreLabs through the mailboxes listed above.