Confiança e segurança

Como a moderação funciona, o que permitimos, o que não permitimos e como lidamos com abusos.

Esta página ainda não foi traduzida. A versão em inglês é exibida abaixo. Se quiser ajudar a traduzir, escreva para [email protected].

Last updated 2 Sep 2026

Pre-publish moderation

Every review is checked before it publishes — not after complaints. Automated checks run first: length limits, all-caps ratio, URL detection, IP rate limits, and account age. Reviews that clear those checks land in a human moderation queue where a person reads them before we make them public. Reviews that don't clear the checks are held, not silently rejected.

Anti-fraud

  • Rate limits. A single account can't post more than a few reviews per day, and can't review the same business twice.
  • IP hashing. We hash the IP of each submission so we can spot networks of accounts posting the same content without storing anyone's raw address.
  • Reviewer quality signals. Accounts that have written only one review, or whose reviews get flagged repeatedly, carry less weight in a business's average score.
  • Velocity gate. A sudden burst of new positive reviews on a low-traffic business triggers a hold on the newest ones until a moderator looks.
  • Turnstile. Signup, unverified-account review submissions, and anonymous flags all go through Cloudflare Turnstile.

No paid removals

Businesses cannot pay to have genuine negative reviews taken down. What they can do is reply publicly, which puts their version of events next to the reviewer's. If a review breaks the guidelines it comes down under the guidelines — not because someone paid.

Business responses

Once a business is claimed (see how claiming works), verified owners and team members can reply to any review. Replies are public and alternate — the reviewer can reply to the reply, and so on. Owner replies are logged and can be revoked by an admin if they cross the guidelines.

Community flags

Anyone can flag a review as spam, fake, offensive, off-topic, containing personal information, or "other". Three unresolved flags on a live review auto-hide it pending a fresh moderator look. Flag reasons and notes are visible to moderators only — they never appear next to the review.

Admin actions

Every moderation action — publish, hide, remove, restore — is logged with the moderator's identity and the reason. Removed reviews are excluded from the public rating and search results but the row is preserved for audit. Deleted reviews can be restored by an admin.

Claim verification

A business is only "claimed" once ownership of its domain has been proven. We support five methods — role-based email at the domain, a DNS TXT record, a DNS CNAME record, an HTML file on the webroot, and a meta tag in the home page's <head>. Every check runs server-side; we never trust a client-supplied "I did it, I promise". Admins can revoke a claim if it's disputed — for example after a domain transfer.

Where we're honest about limits

Nothing catches every fake review. Determined attackers with real accounts and real domains can still slip a small number through. What we do is make it expensive, keep the record auditable, respond fast when patterns emerge, and always publish a reply channel next to any review — because a public response is more powerful than a quiet takedown.

Report a problem

See a review that shouldn't be up? Use the Report this review control on the business page. For a broader concern — a whole account, a pattern of abuse, a security issue — contact support.