This policy covers Korat as a whole product — the Android app named Korat (com.koratland.korat), the web app at koratland.com/app, and this website. Korat is a super-app with chat, a feed, groups, a dating module and shop pages. The minimum age to hold an account is 13, so teenagers are officially part of our user base, and this policy is written on that assumption rather than on the hope that they are not here.
1. Banned outright
These prohibitions have no exception by country, by context or by the poster's explanation, and they do not depend on how strict the law where you are happens to be. They are a floor, not a ceiling.
- Child sexual abuse material (CSAM) — sexual content involving a person under 18, in any form: real imagery, drawings, anything generated or altered with AI, and adults made to appear as children. It may not be sent, posted, requested, traded or linked to.
- Grooming — building trust with a minor for sexual purposes, including moving the conversation elsewhere, asking for photos, asking to meet, and asking them to hide it from a parent.
- Sexualising a child — captions, comments or framing that make a minor a sexual target, even where the image itself is not nudity.
- Sextortion — threatening to publish imagery in order to coerce a minor into anything.
- Child prostitution and trafficking — recruiting, offering, advertising or arranging sexual services involving a minor, however obliquely it is worded.
- Posing as a minor, or creating an account on a child's behalf in order to reach other minors.
This does not end at removal. Clause 2.2 of the Terms says it literally: content of this kind is reported, not merely removed. The accounts involved are terminated permanently, not suspended. Thai Criminal Code s.287/1 and s.287/2 make possession and dissemination of child pornography criminal offences in Thailand.
2. Where to report inside the app
Reporting is our primary route to finding these things, not a backstop — for the reason set out plainly in section 5. So the report button sits in the ⋮ menu of everything that can be reported, one tap from the content, and it is one report sheet across the whole app, so that the reason list on one screen cannot quietly fall out of date.
- Report content
- A post · a comment · a story · a chat message · a shop page · a group · an event — the ⋮ menu on the corner of the thing itself.
- Which reason to pick for a child-safety matter
- The reason list does not yet have a separate “child safety” category. Pick Sexual content or Illegal goods or services, then write in the free-text box that it involves a minor. Those words are what pushes the report up the queue.
- Block the person
- The report sheet carries a Block this person too checkbox in the same tap, and unblocking lives in Settings. Blocking is symmetric and enforced in the database rather than hidden on screen: they can no longer message you, open a chat with you, call you, send a friend request, follow you, or match with you in Dating.
- Blocking deletes nothing
- Deliberately — you still need what happened as evidence when you report it, and the blocked person is never told they were blocked.
- Nobody learns who reported them
- The reported person never sees the reporter's identity, whatever the outcome, and the database offers moderators no way to trace it back either.
After picking a reason you can add detail in the text box. For a chat message that box is mandatory, because it is the only evidence a reviewer will ever see — the reason is in section 6.
Reporting a whole account has no in-app button today. We write that here rather than leave you hunting for it. At account level, use three things together: block, to stop contact immediately · report their public content (a profile with posts on it, a dating card with photos, a message they sent you) · and write to childsafety@koratland.com, which is the route that can act on the account itself.
3. Reporting outside the app, and to the authorities
If a child is in immediate danger, call the police first — 191 in Thailand. Email is not an emergency channel. Nobody watches the inbox around the clock, and saying so plainly is better than leaving someone waiting for a reply in the minute they should have been dialling.
- Child-safety contact
childsafety@koratland.com— for users, parents, teachers, law enforcement and other platforms. It reaches a person, not an automated queue, and it is the only route that takes a screenshot attachment.- Emergencies in Thailand
- 191 (police) · 1300 (Social Assistance Centre, Ministry of Social Development and Human Security) · TICAC, the Royal Thai Police task force on internet child sexual exploitation.
- Cross-border reports
- The NCMEC CyberTipline at report.cybertip.org accepts reports from anyone, anywhere. Use it where the victim or the offender may not be in Thailand.
- Legal requests
- Law enforcement seeking data for an investigation, or asking us to preserve data, should write to the address above stating the agency, the legal basis and what is sought.
You do not need a Korat account to report a child-safety matter to us, and we will not ask you to create one first.
4. What happens when we receive a report
- Ordered by severity, not by arrival time. The queue sorts by category — child safety, trafficking and self-harm come before spam, always. We publish no response-time number, because Korat is run by a small team in one timezone, and a response time we miss is worse evidence than no commitment at all.
- A human reads every report. Nothing is closed automatically and nothing is decided by a model.
- Content is hidden, not deleted, in the ordinary case, because hiding is reversible and deletion is not. Hidden content disappears for everyone including its author — a post its author can still see but nobody else can is a shadow-ban the author does not know about. An outcome has three values and they are kept distinct: actioned / reviewed, nothing wrong / nobody has looked yet. The last two are not the same answer, and we do not delete dismissed reports, because a person reported repeatedly and unfairly becomes invisible if we do.
- For CSAM we do not stop at hiding. Hiding a post does not automatically delete the image from storage — we know this and record it as a known gap — so in this case we delete the stored object by hand in the same step, and terminate the account permanently.
- Written down before anything is deleted. Korat's administrative action log is a table that is append-only and cannot be deleted from, enforced by a database trigger rather than by convention — even a holder of the system-level key cannot erase their own tracks. One moderator also cannot suspend another.
- Referred onward. Where we believe a criminal offence against a child has occurred we refer it to the Thai police, and file a CyberTipline report with NCMEC where the matter may cross borders. We do not wait for a warrant before reporting.
- The content's owner is always told, with the reason. Hiding content and suspending an account both require the moderator to enter a reason; the system refuses a blank one, and that reason is delivered to the owner. The moderator's identity is not sent with it, and neither is the reporter's.
Suspension on Korat means you cannot speak, not your data is gone — a suspended person still reads their own account, still sees the reason and the end date, and can still opt out of marketing. That is deliberate: an empty screen and a screen that says what happened communicate opposite things. Termination for CSAM is the exception, and it is permanent.
What we cannot yet do, said here rather than discovered: the system does not tell a reporter the outcome. You will not receive a message saying how your report ended. If you need an answer on a specific case, send it by email as well.
5. What we do not have, and will not claim to
This section is on the page on purpose. A safety document copied from a template promises things a team this size cannot deliver, and a false promise in a safety document is more dangerous than a declared gap.
- No pre-publication review. Nothing is checked before it goes up — not posts, not photos, not listings.
- No AI screening and no hash matching. We have no image classifier, no PhotoDNA and no database of known CSAM hashes. Moderation on Korat is entirely human and always starts from a report. If this page claimed automated detection, you should disbelieve the whole page.
- No scanning of private chat — and we could not scan it even if we wanted to. See section 6.
- No document-based age verification. We have the birth date a user typed and a staff ID check at a restaurant table for alcohol. What a profile badge can actually evidence is set out under trust and safety. ID-document verification needs a human review queue we do not have, and it would make us hold PDPA s.26 sensitive data that today we do not hold.
- No 24/7 response. See the box in section 3.
The consequence has to be said out loud rather than left to be discovered: user reports are the primary way these things are found here, not a second net. That is why the report button is one tap from everything, why email reporting works with no account, and why it is the part of this page we put the most work into.
6. Moderators cannot read your chats — and what that means
Private chat content is unreachable at every admin role, permanently and by design — stated in the database migration itself, not only in a policy — the security page describes how those rules are written: no policy, no RPC, no way round. Counting messages never requires reading them.
This is a trade, and we state both halves. What it buys: no employee, no moderator and no contractor of Korat's can read your conversations, in any circumstance. What it costs: we cannot detect grooming that happens inside a chat, and we will not claim that we can.
So the effect on a chat report is clear, and it was designed for: when you report a message, the reviewer sees only what you typed, never the message in the database. That is why the text box is mandatory, and why the action is taken against the account rather than the message — the system has no command to hide a chat message at all. Please give the whole of it: who, what they said, what they asked for, and when. If you have a screenshot, send it to childsafety@koratland.com.
What remains fully enforceable is the public half — the profile, the post, the group, the shop page and the dating card that led to the conversation. That half we really can review and hide.
7. Age — the gate is in the database, not on the screen
Korat's age gates are enforced by database triggers, not by filters on a screen, so modifying the app, calling the API directly or writing your own client does not get past them. Each age rule is per-country data in a table, not a number buried in code — and a country with no ruleset yet is a country where the feature is unavailable, not one with no restrictions.
- Minimum account age
- 13 (Thailand), enforced by a trigger at sign-up, and both sign-up screens read the number from the database rather than carrying their own copy of it.
- Dating
- 18 (Thailand), with five triggers covering every entrance: enabling the module, sending a like, writing a dating profile prompt, opening a matched chat room, and sending a message in it.
- Accounts whose age we do not know
- They are in nobody's deck at all — not merely refused on tap; the server excludes them from the result. Dating is also off by default for a new account and must be switched on.
- Alcohol · licensed venues
- 20, per Thai law, re-checked server-side on every order rather than only on entry.
- Other minor-account gates
- Public posts and stories · public profile · being found by phone number and by friend suggestions · sharing an exercise route (forced private, because a regular route is a home and a school) · marketing · owning a shop · a paid subscription · a résumé before 15 — 23 rules in all, held as data.
Leaving your birth date blank is not a shortcut. Korat's age system has three values, not two: ok / under age / unknown — and unknown is refused exactly like under age at every gate that controls adult content. If unknown passed, leaving the field blank would be the winning move and every gate would be meaningless within a day. The single exception is account creation itself, which allows it, because otherwise every existing account that never filled the field in would be cut out of the whole product overnight.
8. If you are a parent
- If your child is under 13 and has an account, write to
childsafety@koratland.comand we will delete it — no documents, no long proof procedure, and no attempt to talk you out of it. - If your child is 13 or over and you want the account deleted, write to the same address. There is also a delete button in the app's Settings, with a 30-day window to change your mind — and the account holder is always notified when a deletion is requested, even when they requested it themselves, because that notification is what catches a hijacked account.
- If someone has contacted your child inappropriately, block the account, report whatever content you can see, and email us the screenshots — because we cannot read the chat ourselves (section 6).
- The parental-consent mechanism PDPA s.20 requires is not implemented. The age of 13 is a product decision, not a Thai statutory threshold. We record that as a known gap rather than passing over it in silence.
9. The law we are bound by
Korat operates from Thailand and is bound by Thai law. We certify that we comply with child sexual abuse and exploitation laws in every country where we distribute the app. The provisions most directly relevant are:
- Criminal Code s.287/1 and s.287/2 — child pornography; both possession and dissemination are criminal offences.
- Anti-Trafficking in Persons Act B.E. 2551, s.6 — an offence even where the victim initially consented.
- Child Protection Act B.E. 2546 — the basis for several of the age thresholds in section 7.
- Computer-Related Crime Act B.E. 2550 — a service provider's duties on notice.
- Personal Data Protection Act B.E. 2562 — including s.20, discussed in section 8.
We cooperate with lawful orders and requests from law enforcement, and we will preserve data on a lawful preservation request.
10. Point of contact
Korat's child-safety point of contact is the product owner, who reads the moderation queue personally — Korat employs no outsourced moderation team, and the fact that one person reads the queue is exactly why section 4 orders by severity instead of promising a time. Write to childsafety@koratland.com about anything on this page, including requests from authorities and from other platforms. privacy@koratland.com is for data-protection rights, and hello@koratland.com for everything else.
11. Language, changes and version
The Thai text is the only binding version. The other nine languages are provided for convenience and have no independent legal effect; in the event of any conflict, the Thai text governs. This policy may change, and a material change will be announced in the app. Version 1.0 — last updated 28 July 2026.