DRAFT — pending legal review. Not final counsel-approved wording.
Content Policy and reporting illegal content
Version 3.4.0 · Effective 2026-08-01 · Last updated 2026-08-14
Previous versions
- 3.3.0 · 2026-08-01 — Comparison audit 2026-08-14: DSA Art. 16(5)–(6) reporter notice; Art. 15(1) duty / Art. 15(2) exemption.
- 3.2.0 · 2026-08-01 — Formal re-audit 2026-08-13-3 (M-06): trim voluntary DSA extras (appeal targets, trusted-flagger priority, misuse process, transparency-report promise); microenterprise confirmed.
- 3.1.0 · 2026-08-01 — Formal legal re-audit draft (F-09): voluntary appeal/Art. 20–22 language; DSA Art. 11/12 contacts; non-binding timing.
- 3.0.0 · 2026-08-01 — Re-audit: good-faith all Art. 16 notices; Art. 18 threshold; UKE mandate; Art. 15 vs 19.
- 1.0.0 · 2026-08-01 — First published draft.
CramDeck hosts material that users create. This document says what is not allowed, how to report something, and what we do about it. It implements Articles 14, 16 and 17 of Regulation (EU) 2022/2065 (the Digital Services Act) and forms part of the Terms of Service.
1. What is not allowed
Illegal content. Anything that is unlawful under EU law or the law of a Member State, in particular:
- child sexual abuse material,
- content that incites violence, hatred or discrimination on grounds of race, religion, nationality, ethnicity, gender, sexual orientation or disability,
- terrorist content,
- material that infringes copyright, related rights or trade marks,
- defamation and unlawful threats,
- personal data of another person published without a legal basis,
- content that breaches consumer protection law, such as hidden advertising.
Content that breaches our rules, even where it is not illegal:
- sexual content, and any nudity presented for sexual purposes,
- graphic violence or gore without an educational purpose,
- harassment, bullying or targeted abuse of a person,
- promotion of self-harm, suicide or eating disorders,
- spam, bulk unsolicited advertising, engagement farming, link schemes,
- malware, phishing and attempts to circumvent our security,
- impersonating another person or organisation,
- payment card numbers, government identifiers, login credentials, or health data identifying a real person,
- exam material published in breach of an examination board's rules or an academic integrity policy.
Medical, legal, forensic and historical material with a genuine educational purpose is allowed even where it is graphic, provided it does not identify a real person without their consent and is described accurately.
2. Where these rules apply
To everything visible to someone other than you: public and unlisted Decks, deck titles and descriptions, card content, uploaded images, usernames, display names, profile biographies and avatars.
Private Decks are not moderated proactively. They remain subject to these rules, and we will act on them if we are notified of illegal content or are required to act by law.
3. How to report
In the application. Use the report button on a public Deck or profile. Choose a category, describe the problem, confirm a good-faith statement that the information and allegations are accurate and complete, and submit. If you are signed in we know who you are. For most categories we also ask for a name and email so the notice can qualify as a complete Article 16 notice. For reports involving child sexual abuse material or specified offences against sexual freedom or integrity, you may report without contact details.
Incomplete or anonymous voluntary reports. You may still send us information without the fields required for a complete Article 16 notice (for example without name/email outside the sexual-offence exception). We treat those as a voluntary product-safety channel and may still act, but they are not formally complete Article 16 notices.
By email. Write to hello@cramdeck.com. For a complete Article 16 notice include:
- a sufficiently substantiated explanation of why the information is illegal content,
- a clear indication of the exact electronic location (URL or equivalent),
- the name and email address of the individual or entity submitting the notice (except where the notice concerns the sexual-offence categories for which the DSA allows anonymity),
- a statement confirming that you have a good-faith belief that the information and allegations in the notice are accurate and complete — required for every Article 16 notice, not only when you assert an infringement of your own rights.
4. What happens next
- Acknowledgement. We confirm receipt without undue delay, by email where you gave us one, and give a reference number.
- Assessment. We review the report in a timely, diligent, non-arbitrary and objective manner. A person makes the decision. Automated tools are used only to prioritise reports and to detect duplicates.
- Decision. We may remove the content, restrict its visibility, disable a link, restrict features on the Account, suspend the Account, or reject the report as unfounded.
- Notification to the reporter (DSA Article 16(5)–(6)). We tell the reporter our decision on the notice, the redress routes available (court rights remain unaffected; as a microenterprise we do not operate a mandatory Article 20 internal complaint system), and whether automated means were used to process the notice or take the decision. Automated tools are used only to prioritise and triage; a person takes the decision.
- Statement of reasons. If we restrict content or an Account, we send the affected user a statement giving the restriction imposed and its territorial scope and duration, the facts and circumstances relied on, whether automated means were used, the legal ground or the contractual clause relied on, and how to contact us about the decision. Court rights remain unaffected.
Article 18 — authority notification. Where we become aware of any information giving rise to a suspicion that a criminal offence involving a threat to the life or safety of a person has taken place, is taking place or is likely to take place, we promptly inform the law-enforcement or judicial authorities of the Member State(s) concerned, and follow our internal escalation protocol. Awareness of content that is merely distressing or that broadly “indicates a threat” without that statutory suspicion is handled under ordinary moderation and safeguarding practice, not automatically as an Article 18 notification.
Timing. We act without undue delay.
5. Restrictions we can apply
| Measure | When |
|---|---|
| Content removed | Illegal content, or a clear breach of section 1 |
| Deck made private, removed from the feed or search | Borderline content, or content that is lawful but breaches our rules |
| Age restriction | Content suitable only for adults |
| Feature restriction, such as being unable to publish | Repeated breaches |
| Account suspended | Serious or repeated breaches |
| Account terminated | Child sexual abuse material, terrorist content, or a persistent pattern after suspension |
6. Size-based exemptions
As a confirmed microenterprise we rely on the DSA Article 19 exemption from Articles 20–28. Article 15(1) creates the transparency-reporting duty; Article 15(2) creates the relevant size-based exemption from that duty. While those exemptions apply we do not operate a mandatory Article 20 internal complaint system, do not present Article 21 certified out-of-court settlement as a statutory entitlement against CramDeck, and do not publish Article 15(1) transparency reports. We reassess periodically if our size status changes. Article 24(3) information-on-request obligations remain applicable where engaged.
We keep records of reports and decisions for as long as needed to handle the case and related claims.
7. Contact
JMS Sieracki sp. z o.o.
ul. ks. Pawła Pośpiecha 3A/7, 41-800 Zabrze, Poland
Email: hello@cramdeck.com · Phone: +48 604 550 335
DSA Article 11 (authorities): hello@cramdeck.com — subject "DSA authority". Monitored; not exclusively automated. Languages: Polish and English.
DSA Article 12 (recipients of the service): hello@cramdeck.com — subject "DSA contact", or /support. Same languages; human handling available.
Reports use the same inbox with the subjects described above.
In Poland, the President of the Office of Electronic Communications (UKE) currently performs a temporary and limited Digital Services Coordinator function under the transitional national arrangement — uke.gov.pl/uslugi-cyfrowe/koordynator/. Address: ul. Giełdowa 7/9, 01-211 Warszawa.