Harm Watch

Terms of Use

Effective from 1 August 2026. Version 1.0.

These terms govern your use of www.harm.watch and everything connected to it, including the public reporting form, the organisation portal and the API. By using the service you accept them. If you do not, please do not use it.

The service is operated by volunteers and submissions are passed to governing bodies once verified. The creator, Pete Trainor, oversees its operation. In these terms, “we” and “us” mean The Harm Watch and its volunteers, and “you” means whoever is using the service.

1. What The Harm Watch is

The Harm Watch collects reports from members of the public about websites that appear to be unlawful, harmful, or in breach of the Online Safety Act 2023, and makes those reports available in a structured form to organisations we have approved.

We are an independent private organisation. We are not a regulator, not a public body, not a law enforcement agency, and not connected to Ofcom, the Internet Watch Foundation or any police force.

2. What The Harm Watch is not

Please read this section properly, because it is the part people most often assume the opposite of.

  • We do not verify reports. A record in our database means somebody told us about a website. It does not mean the website is unlawful, harmful, or in breach of anything. We do not investigate, we do not adjudicate, and we do not make findings.
  • We cannot remove anything. We have no technical or legal power to take down a website, block it, or compel anyone else to. We do not contact hosting providers or registrars on your behalf.
  • We do not act on your report ourselves. Submitting a report does not create any obligation on us to do anything with it, to review it within any timescale, or to tell you what happened next.
  • We are not an emergency service. If somebody is in immediate danger, call 999. If a crime has been committed, report it to the police. If you have lost money to fraud, report it to Action Fraud. Reporting to us is not reporting to the authorities, and it does not start any official process.
  • We do not host or store the reported content. We record web addresses and classifications only. We do not copy, mirror, cache or archive anything from the sites reported to us.

3. Reporting a website

You may use the reporting form if you are 13 or over.

When you submit a report you confirm that you are acting in good faith and genuinely believe the site is harmful or unlawful, that the information you have given is accurate as far as you know, and that you are not submitting it to harass, damage or take revenge on anyone.

You must not use the form to submit reports about sites you know to be lawful and harmless, to run automated or bulk submissions, to launch a coordinated campaign against a competitor, a former partner, or anyone you have a grievance with, or to include personal information about yourself or any other person in the free text field.

Malicious reporting is a serious matter. It can expose the reporter to civil liability, and depending on the circumstances it can amount to a criminal offence. We log the technical origin of every report in hashed form, and we will cooperate with law enforcement where the form is being abused.

Two categories we will not accept.Reports of child sexual abuse material must go to the Internet Watch Foundation, and reports of terrorist content must go to the government's terrorism reporting route. If you select either category we will stop your submission and send you to the right place. We do this because a stored, searchable, exportable list of those addresses would itself cause harm.

4. Rights in what you submit

You keep whatever rights you have in the text you write. By submitting a report you grant us a worldwide, royalty free, perpetual, irrevocable licence to store it, classify it, aggregate it with other reports, and share it with approved organisations in accordance with these terms and our Privacy Notice.

The licence is perpetual because records are never deleted from our dataset. This is the point of the service, and it is set out plainly here so nobody is surprised by it later.

5. Organisation access

Applying. Any organisation may apply for access. We approve applications at our sole discretion, and we may decline without giving a reason.

Accounts. Your organisation is responsible for everything done under its accounts. Keep credentials secure, use a unique password, enable two factor authentication, tell us immediately at access@harm.watch if you suspect a compromise, and tell us promptly when a colleague leaves so we can deactivate them. Accounts are for named individuals and must not be shared.

Permitted use.You may use the data for research and analysis, for regulatory or enforcement work within your remit, for protecting your own users or networks, for supporting people who have been harmed online, and for evidencing systemic problems to a regulator, including through the Online Safety Act's super complaints route.

Prohibited use. You must not republish the dataset or any substantial part of it publicly, sell, licence or otherwise commercialise it, pass it to a third party without our written agreement, use it as a blocklist that produces automatic consequences for a site without your own assessment, present any record as a finding that a site is unlawful, scrape the portal or attempt to circumvent rate limits, or use it to harass, threaten or defame any person or organisation.

Accuracy. You accept that records are unverified public allegations and that you are responsible for your own verification before acting.

Suspension. We may suspend or revoke access at any time, with or without notice, if these terms are breached, if the basis on which access was granted no longer holds, or if we consider it necessary to protect the service or the people it exists to help.

6. API access

API access is granted separately from portal access and only to organisations we have specifically enabled for it.

API keys are confidential. Do not commit them to source control, embed them in client side code, or share them between organisations. You are responsible for all activity under your keys. Tell us straight away if one is exposed and we will revoke and reissue.

The API is rate limited, and the current limits are published in the API documentation. Do not attempt to work around them by rotating keys or distributing requests.

Data retrieved through the API is subject to exactly the same permitted and prohibited uses as data in the portal.

7. If your website has been reported

A record about your site does not mean we have found against you. It means someone reported it.

If you believe a report is inaccurate, malicious or mistaken, write to listings@harm.watch from an address connected to the domain, identifying the site and explaining the position. We will review it within a reasonable period and, where the report does not stand up, mark the record so it is excluded from everything we share.

We do not delete records, and we do not disclose who reported you.

8. Availability

We provide the service as it is and as it is available. We do not promise it will be uninterrupted, error free, or complete. We may change, suspend or withdraw any part of it, and we may stop operating it entirely, without liability to you.

9. Liability

Nothing in these terms limits our liability for death or personal injury caused by our negligence, for fraud or fraudulent misrepresentation, or for anything else that cannot lawfully be limited.

Subject to that, we are not liable for any loss arising from your use of or reliance on the service or its data, including loss of profit, business, goodwill or reputation, or any indirect or consequential loss. In particular we are not liable for anything that follows from a report being inaccurate, incomplete, out of date or maliciously made, from any action or inaction taken on the strength of our data, or from a harmful website not appearing in our data at all.

Where liability cannot be excluded, our total liability to any organisation is capped at £100 or the amount that organisation has paid us in the preceding twelve months, whichever is higher.

You agree to indemnify us against claims arising from your breach of these terms, from reports you submit in bad faith, or from your use of the data in a way these terms prohibit.

10. Intellectual property

The site, its design, its code, its harm taxonomy and the name The Harm Watch belong to us. Access to the service grants you no rights in any of it beyond the permitted uses set out above.

11. Changes

We may update these terms. The version number and effective date at the top will change, and material changes will be notified to organisation account holders by email. Continuing to use the service after a change means you accept the revised terms.

12. General

If any provision is found unenforceable, the rest continues to apply. A delay in enforcing a term is not a waiver of it. These terms are between you and us, and nobody else may enforce them under the Contracts (Rights of Third Parties) Act 1999.

These terms and any dispute arising from them are governed by the law of England and Wales, and the courts of England and Wales have exclusive jurisdiction.

13. Contact