Abuse and removal
How to report content on this site, how to have your own taken out of the index, and what removal can and cannot do.
Where to send it
Email security@bulleted.app. It is one address for reports of every kind — abuse, removal requests, and security — and it reaches the maintainer directly. One inbox that is read is worth more than three that are announced.
What to include
The address of the thing. Every bullet, note, outline, and
comment on this site has one, and it is in your browser's address bar when you
are looking at it: a URL under /public/. Paste that. If you have the
at:// URI instead — the Copy address control on a bullet
produces one — that is better still, because it names the record itself rather
than a page that renders it.
Then say what is wrong with it, in your own words. If the problem is that the content is yours and you did not expect to find it here, say that; that is the most common request this address gets and it is dealt with below. Nothing else is required. A report is not a legal filing and will not be held to the standard of one.
What happens next
Bulleted is built and run by one person, so the honest answer is that reports are read and acted on when they are seen rather than within a fixed window. You will get a reply. If a report is acted on you will be told what was removed; if it is not, you will be told why rather than met with silence.
Removal takes effect on the next page load. It is not a queue and there is no review period — the entries are applied at read time, so a repository, a record, a server, or an image stops being served the moment it goes on the list.
What removal can and cannot do
This site is an index, not a home. Every bullet it renders is a record in somebody's own repository on their own personal data server. Bulleted keeps a local copy so that reading an outline is fast, and removal takes that copy out and refuses to make another. It does not, and cannot, touch the record. The bullet stays exactly as readable as it was to anyone who queries the network directly, through any other client, without this service's involvement.
That is worth being blunt about, because it is the difference between what people usually want and what is actually on offer. If the content is yours, deleting it in your own repository is the thing that removes it from the network, and this index will follow within seconds — that is what the firehose is for. Asking here removes it from this site and nowhere else. If the content is somebody else's, this site is one of the places it appears, and the others are not ours to do anything about.
What can be removed
Four kinds of thing, at four different sizes. A single record —
one bullet, one note, one comment — leaving its children in place exactly as
deleting it would. A whole repository, which takes out every
record from it, every page under /public/ for that identity, and
every image. A personal data server, which covers every identity
hosted there and is the blunt instrument for a server that exists to host abuse.
And a single image, wherever it appears and including the cached
copy.
An image already delivered can outlive its removal at a cache edge for up to a year — Privacy explains why, and it is a real limit rather than an excuse.
If you would rather not be indexed at all
You do not have to have signed in here for your outline to be rendered here. Viewing any identity's outline causes Bulleted to fetch and index that repository, and following a transcluded bullet does the same for the repository it points into. If you would rather that not happen to yours, say so at the address above and the identity goes on the list — no explanation needed and no account required. Privacy describes the indexing in full.
Security problems go to the same place
If what you have found is a vulnerability rather than content — something that lets one account reach another's data, or gets script onto a page — it is the same address, and Security describes what is in scope, what happens next, and the one rule about testing against your own account.