Reporting abuse
How to report misuse of Kelu, a security flaw, or a server using it to harm people.
What is reported here
Anything Kelu is part of. If a server is using it to harass, to spam, to distribute illegal content or to get around somebody having blocked them, that reaches us and we act on it. Also a bug that shows one person the data of another, and anything that made you think «this should not have been possible».
Two things do not go here, and sending them here delays them:
- What happened on Discord without Kelu in the middle —a message, a user, a server— is reported to Discord, who can act on the account. Their form is in the Discord support centre.
- What a server decides for itself —a sanction you disagree with, a ticket that went unanswered, being removed— is decided by whoever administers that server. We are not above their team and we do not overturn their decisions.
And if what you want is for Kelu to stop being in your server: anybody with the "Manage Server" permission can remove it from the server settings, and thirty days later everything of that server is deleted, as the Data Retention Policy explains.
How to report it
Write to [email protected]. There is no form and no account required: a report from somebody who does not use the dashboard is worth exactly as much as any other.
What helps us get there faster:
- The server ID, and the channel or message link if there is one.
- When it happened, with the time zone or an approximation.
- What you saw, in your own words. A screenshot is worth more than a summary.
- Whether you have already written to that server team, and what they told you.
You can ask us not to repeat your name to anybody. We keep the report while we handle it and to spot repeat behaviour by the same server, and we do not use it for anything else.
What happens next
Every report is read by a person. We answer within five business days at most, even if the answer is that we are still looking into it.
What we can do, in order of how much it costs whoever is on the other side: turn off a module for a server, revoke its API keys, cancel its plan, remove Kelu from it and refuse to go back in, and delete its data. What we cannot do is act inside a server without its team, or return content Discord has already deleted.
Security flaws
If you found something that lets you read or change what is not yours, write to [email protected] with "security" in the subject line and we will answer as a priority. Tell us what you did, step by step, and stop there: proving that a door opens does not require going through it.
Give us a reasonable time to fix it before publishing it. If you report in good faith, do not touch third-party data beyond what proving the flaw requires and do not degrade the service, we will not take legal action against you and we will credit you if you want us to.