Skip to main content

Legal

DMCA & Abuse Reporting

How to report copyright infringement or abuse of an Inkrypt link — and an honest account of what we are technically able to determine.

Last reviewed Reviewed by Inkrypt Editorial

What we can and cannot see

This has to come first, because it determines what any report can realistically achieve. Inkrypt stores notes as ciphertext encrypted in the user's browser with a password we never receive. We cannot read the contents of any note.

That means we cannot review a note to determine whether it infringes copyright, contains prohibited material, or is being used abusively. We can see that a note exists at a given address, when it was created, and how many times its encrypted payload has been fetched. Nothing more.

What we can do

We can delete a stored note, making the link permanently non-functional. That is the substantive remedy available to us, and we will apply it where a report is valid.

If you believe material accessible through an Inkrypt link infringes a copyright you own or represent, send a notice to work.securetext@gmail.com with "DMCA" in the subject line.

To be actionable, a notice should include:

  1. Your physical or electronic signature.
  2. Identification of the copyrighted work you claim has been infringed.
  3. The specific URL of the note. We cannot search for content we cannot read, so a report without an exact URL cannot be acted on.
  4. Your name, address, telephone number and email address.
  5. A statement that you have a good-faith belief the use is not authorised by the copyright owner, its agent, or the law.
  6. A statement, under penalty of perjury, that the information in the notice is accurate and that you are the copyright owner or authorised to act on their behalf.

On receiving a valid notice we will remove the identified note. Because notes are encrypted, we cannot verify the infringement claim by inspection — we act on the notice itself, and we will tell you what action we took.

Counter-notification

If your note was removed and you believe that was a mistake or a misidentification, you may send a counter-notification to the same address, including your signature, identification of the removed material and its location, a statement under penalty of perjury that you believe the removal resulted from mistake or misidentification, and your contact details with consent to the jurisdiction of the appropriate courts.

Removal is not reversible

Because we hold no readable copy and no backup of note contents, a deleted note cannot be restored even if a counter-notification succeeds. A successful counter-notification means we will not act on further notices from that party regarding the same material — it does not bring the note back.

Reporting abuse

To report an Inkrypt link being used for phishing, harassment, malware distribution, or to share unlawful material, email work.securetext@gmail.com with "Abuse" in the subject line and include the exact URL.

Please describe how the link was used and what harm it caused or risked. Since we cannot inspect the note, that context is what allows us to assess the report. Where credible, we will delete the note.

  • Phishing — an Inkrypt link used as part of a credential-harvesting attempt.
  • Harassment — a note used to target or intimidate an individual.
  • Malware — a note distributing malicious code or instructions.
  • Unlawful material — content prohibited by applicable law.

Reports involving an immediate risk of harm to a person should go to law enforcement first. We will cooperate with valid legal process, though the technical reality above bounds what we can produce: we hold ciphertext, not content.

Bad-faith reports

Because we cannot inspect notes, a takedown request is a request to destroy data we cannot evaluate. That makes this process open to abuse — for example, an attempt to destroy someone else's note by falsely claiming infringement.

Submitting a knowingly false notice may carry legal liability under applicable law. We record all notices received and the action taken on each.

Our position

We built a system we cannot read, and we think that is the right design for a tool people use to move sensitive information. The unavoidable consequence is that we cannot police its contents in the way a platform hosting readable material can.

What we can offer is a responsive process: a real address that a person reads, prompt deletion where a report is valid, and an honest account of what we are and are not able to determine. We would rather state that limitation clearly than imply a moderation capability we do not have.

Frequently asked questions

Can you tell me what is inside a specific note?

No. Notes are encrypted in the user's browser with a password we never receive. We hold ciphertext and cannot decrypt it, for any requester, under any process.

How do I get a note removed?

Email work.securetext@gmail.com with the exact URL and either "DMCA" or "Abuse" in the subject line, plus the details listed on this page. Without the exact URL we cannot locate the note, because we cannot search content we cannot read.

How quickly do you act on reports?

We aim to review reports within a few business days and act promptly on valid ones. You will receive a response telling you what action was taken.

Can a removed note be restored?

No. We hold no readable copy and no content backups, so deletion is permanent — including where a counter-notification later succeeds.

Reporting something?

Email work.securetext@gmail.com with the exact URL and "DMCA" or "Abuse" in the subject line.

Open the notepad