Safety on this Testgram deployment

Testgram is a self-hosted messenger run by a single operator. There is no moderation team, no automated content scanning, and no transparency reporting. This page says plainly what that means in practice, rather than presenting figures that do not exist.

How this deployment handles abuse

Registration is open: anyone can sign up, using the code bot at @gramtestcodebot. There is no application and no waiting list, which also means nobody reviews who joins. The operator can remove an account, but does not screen accounts up front.

Uploads are stored as files and served from this domain. Anyone holding a link to a file can fetch it; there is no per-file access control beyond that. Files also pass through third-party services when transcribed or translated — see the privacy policy.

Reporting something

Clients expose the standard Report action on a message. A report does not reach a moderation team, because there is none: it reaches the operator, who decides what to do. Expect a person rather than a process.

If something needs to come off this server and the operator has not acted, treat that as the end of the available route. There is no appeal body, no external ombudsman, and no regulator relationship behind this deployment.

What is not implemented here

These are upstream Telegram capabilities. None of them exist on this deployment today, and no claim is made that they do. Moderation in some form is planned, and automatic checking is expected, but what exactly will be checked automatically has not been decided yet — so nothing is promised here beyond that:

  • Automated scanning of public images against a child-abuse hash database.
  • Proactive machine-learning moderation of messages and media.
  • Automated takedown addresses, and any arrangement with reporting NGOs.
  • Transparency reports of any kind.
  • Cooperation with law-enforcement bodies, or with any external moderation organisation.
  • Digital Services Act transparency reporting and named contact points.

No block counters

Upstream this page shows how many groups and channels were blocked, along with charts of removals over time and a table of takedowns filed by external organisations. Those numbers are not reproduced here. Publishing a counter for a moderation function that does not exist would be the exact kind of claim this page exists to avoid.

A note on encryption

Traffic is encrypted with MTProto. That does not make the server blind to its own traffic: the operator hosts the server and can read what passes through it. There is no end-to-end guarantee against the operator of this particular deployment, and no external audit of the cryptography exists.

Related pages