Cloak
Resources

Abuse policy

Specific prohibited conduct, evidence requirements, and an enforcement process that accounts for encrypted storage.

Scope and principle

This policy applies to Cloak accounts, Drive shares, Object buckets, API access, and use of Cloak infrastructure. Private storage does not give anyone permission to harm others, but encryption also does not justify indiscriminate scanning of customer files.

Prohibited conduct

  • Child sexual abuse material, grooming, or any sexual exploitation of minors
  • Malware, ransomware, credential theft, phishing, botnet control, or instructions tied to an active attack
  • Non-consensual intimate imagery, credible threats, stalking, doxxing, or targeted harassment
  • Material that infringes copyright, trademark, privacy, publicity, or other rights
  • Unauthorized access, vulnerability exploitation, denial of service, spam, or interference with another system
  • Fraudulent payments, reselling access without permission, evading technical limits, or repeatedly creating accounts to bypass enforcement
  • Content or conduct that is unlawful in the jurisdiction that validly governs Cloak or the person using it

Submit a report

Email [email protected] with the complete Cloak share URL or object reference, the category of harm, a factual description, where you found it, and evidence that can be reviewed safely. Include your authority to act when reporting copyright, trademark, or another person's private rights.

Do not send illegal content as an attachment. For imminent danger, contact the emergency service able to respond where the threatened person is located, then send Cloak the relevant reference and agency contact.

Review process

  • Validate that the reference belongs to Cloak and the report is specific enough to review
  • Preserve the minimum relevant records when required to prevent destruction during review
  • Assess applicable law, reporter authority, context, urgency, and risk of mistaken removal
  • Restrict a share, credential, object, feature, or account only as broadly as reasonably needed
  • Notify the account holder and provide a reason and appeal path unless law, safety, or an active investigation prohibits notice
  • Record the outcome for aggregate transparency reporting

Encrypted-content boundary

Cloak does not routinely scan Private Drive plaintext because it does not possess the keys. We may review information voluntarily supplied by a reporter, including a working share link and password, as well as account, request, sharing, network, and payment metadata already available to the service.

We do not require every customer to surrender a recovery key or weaken encryption because one account is reported.

Enforcement

Possible actions include warning, removing a public link, revoking a key, limiting a feature, preserving records, suspending an account, or terminating service. We consider severity, confidence, intent, repetition, immediate risk, and whether a narrower action can stop the harm.

Cloak does not reserve an unrestricted right to terminate paid service without reason or notice. Immediate restriction is limited to urgent safety, security, legal, fraud, or service-integrity needs. When possible, we give notice, an export opportunity, an appeal, and a refund of unused prepaid service under the Terms.

Appeals

Reply to the enforcement notice or email [email protected] with the account reference, action being challenged, and evidence of mistake, authorization, or remediation. A person not involved in the original decision should review the appeal when staffing allows.

Report abuse