Home
Abuse Policy
Abuse policy and reporting
Mango Private is a corporate messenger with
end-to-end encryption.
Each Mango Private instance is operated by an organization
on its own infrastructure. The organization's administrator
bears primary responsibility for moderation and handling
user complaints within their instance. OffshoreLabs
(the developer) does not have direct access to message
content or user data unless the operator grants it.
This page explains who handles what, what can be reported,
and how escalation to OffshoreLabs works.
Effective date: 25 August 2026
Who handles complaints
Mango Private is a self-hosted product. Each organization
deploys and operates its own instance. This means:
-
The organization's administrator is the
primary point of contact for all user complaints,
moderation decisions, and content disputes within their
Mango Private instance. The administrator has access to
account management, can warn, suspend, or remove users,
and controls server-side policies.
-
OffshoreLabs Studio LTD (the developer)
does not bear direct responsibility for handling
complaints within the private domain of a specific
organization, unless a report is sent directly to
abuse@mango-private.com.
-
If you cannot resolve an issue through your organization's
administrator, or if the complaint concerns the
administrator themselves, you may escalate directly to
OffshoreLabs.
Where to write
Within your organization: contact your
Mango Private administrator directly. They have the tools
and access to investigate and act on complaints within
your instance.
Escalation to OffshoreLabs: send abuse
reports to
abuse@mango-private.com.
This is a separate mailbox from
general inquiries
and
legal requests —
we prioritise abuse mail.
Please include:
- the reported user's nickname (in
@handle
form, visible on the profile card);
- the chat nickname (for groups and channels, in
@handle form), if the incident occurred there;
- the organization / instance where the incident took place;
- date and approximate time of the incident;
- screenshots, screen recording, or saved files — without
them we usually cannot verify the content (see the
end-to-end encryption section below);
- your own nickname so we can follow up with you.
If you use the "Report" button on a message inside
the app, most of these fields are filled in automatically —
the app inserts your ID, the reported user's ID, and the
chat ID without disclosing chat content.
What you can report
The categories below are what we accept reports about and
are prepared to act on. The list is non-exhaustive — if
something looks like abuse but doesn't fit a bucket here,
write anyway.
Threats and harassment
Direct threats of violence, stalking, sustained
harassment, blackmail, doxxing (disclosure of personal
information without consent).
Sexual exploitation of minors
CSAM, sexualised contact attempts toward minors
(grooming), recruitment into related activity. These
reports are treated with priority and, where required
by law, information is shared with law-enforcement
authorities.
Non-consensual intimate imagery
Distribution of intimate images without the depicted
person's consent (NCII / "revenge"), and threats to do
so.
Spam and phishing
Mass unsolicited messaging, attempts to harvest
credentials, impersonation of support services, links
to malware.
Impersonation
Accounts created to deceive: posing as a specific
private individual, organisation, or Mango Private
support.
Coordinated malicious behaviour
Bot networks, account farms, coordinated attacks on a
specific user or group, manipulation campaigns.
Illegal goods and services
Sale of weapons, drugs, stolen data, malware,
commissioned services of an unlawful nature.
Incitement to violence
Calls to violence against specific people or groups,
terrorism, organised hate.
What we don't act on
-
Internal organizational disputes.
Mango Private is a corporate messenger: workplace
disagreements, management decisions, and internal policy
matters are the responsibility of the organization, not
OffshoreLabs.
-
Content you have consented to.
If you are voluntarily part of a chat between adults and
you set its tone yourselves, we are not a moderator of
personal communication.
-
Disagreements over politics, religion, taste.
We do not moderate discussions between adults as long as
they do not cross into threats or the categories listed
above.
-
Third-party reports. The reporter must be
a participant of the chat (or the legal guardian of a
minor participant). Reports from outsiders who have no
access to the chat cannot be reviewed because we cannot
verify them.
-
Off-platform behaviour. Conflicts that
happened on other services, messengers, or offline are
outside our scope.
-
Reports without evidence. End-to-end
encryption means we cannot independently see the content
of a conversation. Without screenshots or other
evidentiary material we can only take metadata-level
action (see the next section).
-
Government / legal requests. Those go
through a separate process — please write to
legal@mango-private.com.
End-to-end encryption and what it means for reports
Neither OffshoreLabs nor the organization's server
infrastructure can read your messages, voice notes, photos,
or video. Each is encrypted on the sender's device with
keys held only by the chat participants
(more about how encryption works).
That obliges both the organization's administrator and
OffshoreLabs to handle abuse differently from messengers
that store content server-side:
-
Content reaches us only from the
screenshots, recordings, or chat exports you attach. A
request to "pull the message from the database" is
technically impossible — what is on the server is an
encrypted blob.
-
Metadata is available in a limited form:
sender and recipient IDs, message timestamps, the fact
that media was attached and its size, push-notification
records, account-level history (creation date, originating
device class, previous abuse decisions).
-
Metadata-based action. The organization's
administrator can block an account, stop a rolling spam
wave, revoke active sessions and tokens, and limit
new-account creation — without seeing content, when the
behavioural pattern is already enough.
-
What won't work. "Read the old
conversation for me", "produce the message content for a
court", "restore a deleted message" — neither the
administrator nor OffshoreLabs can do that. If a
conversation matters as evidence, save it on your device
immediately.
What happens after you report to OffshoreLabs
When a report is sent directly to
abuse@mango-private.com,
OffshoreLabs investigates within its capabilities:
-
Acknowledgement. Within 72 hours of
receipt we reply with a case number.
-
Triage. Spam and automated attack
patterns are handled automatically; reports that require
human judgement are routed to a reviewer.
-
Context gathering. We coordinate with the
organization's administrator (if identifiable and
cooperative), verify screenshot authenticity through
available metadata where possible, and cross-check against
earlier reports.
-
Decision. We tell you what action we took
without disclosing internal investigation detail or the
reported person's personal data.
-
Timing. Most reports are resolved within
7 days; CSAM, credible threats of violence, and
coordinated campaigns are prioritised and reviewed
within 48 hours.
Possible outcomes
By the organization's administrator
(within their instance):
- Warning to the reported user.
- Temporary suspension of the account.
- Permanent removal of the account from the instance.
- Restriction on new account creation.
By OffshoreLabs (when escalated to
abuse@mango-private.com):
-
Guidance to the operator. We may advise
the organization's administrator on appropriate action.
-
License-level action. For severe or
repeated violations, OffshoreLabs reserves the right to
suspend or revoke the organization's Mango Private
license.
-
Law-enforcement referral. CSAM, credible
threats of violence, and similar cases are referred to
the appropriate authorities and we share the metadata we
hold within the limits of the law.
If you disagree with a decision
If the decision was made by your organization's
administrator, appeal through your organization's internal
process.
If the decision was made by OffshoreLabs, you can appeal
within 14 days of our response by replying to
abuse@mango-private.com
with the subject "Appeal: [case number]". Appeals
are reviewed by a different reviewer than the one who
issued the original decision. If the appeal is upheld we
roll back the action and explain why we reversed.
Contacts
Abuse reports
abuse@mango-private.com
Escalated reports: user-generated content, spam, threats, CSAM, phishing.
Support
support@offshorelabs.dev
General questions about the product and deployments.
Legal requests
legal@mango-private.com
Requests from government bodies, courts, and legal
representatives. Please do not use this mailbox for
user reports — we will route you back to abuse@.
Mango Private is developed by OffshoreLabs Studio LTD, a company
registered in the United Kingdom under company number 17387215.
Each Mango Private instance is operated by the purchasing
organization on its own infrastructure. Legal and operational
correspondence reaches OffshoreLabs through the mailboxes
listed above.