UpScrolled promised us freedom from censorship. We need it to promise us security too.
When platforms that billions rely on become hostile to your voice, you look for alternatives. This is exactly what happened across the SWANA region over the past year. Palestinian journalists, activists, and ordinary people documenting atrocities and war crimes found their content suppressed by algorithmic moderation systems that are biased against Arabic-language content.
Major platforms like Meta, YouTube, and X often classify these posts under vague community standards, which leads to systematic policy over-enforcement. This is frequently driven by opaque government requests and the application of restrictive policies that fail to distinguish between prohibited material and legitimate human rights documentation. These structural failures have created a pattern of suppression that our ongoing monitoring has tracked in detail.
UpScrolled emerged from this failure. Built by Palestinian-Australian entrepreneur Issam Hijazi, it was designed as a direct answer to the censorship people were experiencing: a platform where, in Hijazi’s words, every voice gets equal power. Its launch coincided with growing unease over TikTok’s transition to majority US ownership, which deepened a wider sense that mainstream digital spaces were becoming politically compromised. Within two weeks, 2.5 million people signed up.
That number tells a story. People weren't drawn to UpScrolled by an advertising campaign. They joined because they needed a place to speak without being silenced. Many are human rights defenders, journalists, and activists living and working in authoritarian contexts where being identified online can lead to detention or harassment. To us, this is not just an abstract user base. These are our own communities.
Rapid growth demands equally rapid investment in user safety
In early February 2026, external technical analysis published on GitHub flagged potential security gaps in UpScrolled’s infrastructure. The findings pointed to risks in four areas: location data leaking through media uploads, IP addresses being exposed through embedded content in comments, the possibility of unauthorised actions being triggered on user accounts, and deleted content remaining accessible on the platform’s servers.
For a general-purpose social network, these would be concerning. For a platform that has become a primary space for activism and frontline documentation in a conflict-affected region, they carry a different weight entirely. Location data, even at an approximate level, can narrow the search for someone a government wants to find. An IP address can confirm which network a person is using. What seems like insignificant metadata in one context can quickly become a precise targeting tool for state surveillance and physical targeting.
We wrote to UpScrolled on 7 February 2026. Our letter asked for specific details on how the platform acknowledged the reported issues and its timeline for fixing them. We also requested information on immediate measures to protect users in high-risk contexts and plans for a formal vulnerability disclosure process. We provided a deadline and confirmed that the platform’s response, or its absence, would be noted in our final publication.
UpScrolled’s response: a constructive step that opens important questions
UpScrolled responded substantively to our letter. Their willingness to engage with the substance of our concerns is noted and appreciated. We set out the key elements of their response below, alongside our assessment.
On the nature and scope of the vulnerability
"Our review identified a configuration affecting how approximate location information derived from IP geolocation could be accessed under certain technical conditions. The data involved only broad, city-level information; no precise GPS coordinates or raw IP addresses were exposed to third parties. The vulnerability was fully remedied on 5 February 2026. Our forensic analysis found no evidence that third parties accessed, exfiltrated, or exploited user data during the period in which the issue existed."
The swift remediation is a positive signal. That said, describing the exposed data as "broad, city-level information" understates the risk for the people actually using this platform. For a human rights defender in a SWANA country or a journalist in exile whose city of residence is already partially known to the authorities they fled, city-level geolocation is operationally useful rather than broad. Combined with other data points, it can narrow the search for a specific individual. The key question is whether UpScrolled has structurally reviewed its architecture to prevent similar issues or simply patched this one.
On structural security improvements
"The recent issue prompted us to conduct a broader review of all points at which user data is handled to ensure that our data minimisation principles are applied consistently at every layer of the platform. … We have strengthened our backend data-handling processes to prevent recurrence and plan to publish our updated Privacy Policy to provide clearer and more comprehensive information about the data we collect, how it is processed, and the safeguards in place."
"We are expanding our Security and Trust & Safety capacity to establish a dedicated safety channel for individuals at heightened risk. … We remain open to collaborating with civil society organisations, including SIHR, to develop additional safeguards that meet the specific needs of activists operating in hostile environments."
These are promising commitments. A broader data handling review, a safety channel for at-risk users, and a willingness to work with civil society organizations are exactly the structures a platform serving this community should implement. We welcome these steps. Two factors will determine whether these commitments translate into real protection.
First, the platform needs transparency. Publishing an updated Privacy Policy is a good start, but the digital rights community needs specific details on what data is collected, how long it is retained, and who can access it. Second, the platform must build capacity. Developing a Trust & Safety function requires more than just staffing. It necessitates deep expertise in the specific threats facing users in the SWANA region, such as state-level surveillance, platform-enabled harassment, and politically motivated account targeting. We encourage UpScrolled to draw on the experience of civil society partners while building this capacity.
We also note positively that UpScrolled does not require a phone number for registration and supports VPN and Tor usage, which are features that meaningfully lower the barrier to anonymous participation.
On user notification
"We recognise that users, particularly those in high-risk contexts, deserve to know when their security may have been affected. Our policy is to assess notification obligations promptly and provide user notice where appropriate under applicable law and platform policy. In this instance, our investigation did not meet that threshold."
Standard notification thresholds are built for platforms where the worst case is fraud or spam. On UpScrolled, the worst case is that sensitive user data is exposed to repressive regimes and weaponized to identify, track, and arbitrarily detain human rights defenders. We encourage UpScrolled to adopt a proactive notification policy for users in high-risk contexts, informed by consultation with digital rights organisations.
The importance of protecting good-faith security research
One element of UpScrolled’s response merits a closer look.
"It is important to note that the individual who identified this issue accessed and tested aspects of the platform in a manner inconsistent with our Terms of Service. The methods used involved probing technical constraints and interacting with outside authorised interfaces, conduct expressly prohibited under our acceptable use provisions. … Such actions may expose both the platform and its users to avoidable risk and may carry legal and reputational consequences. … We reserve all rights in relation to breaches of our Terms of Service."
UpScrolled's response touched on how the vulnerability was originally identified, noting that the researcher's methods were inconsistent with the platform's Terms of Service and referencing potential legal and reputational consequences.
While SIHR did not identify or publish the technical findings, we note that the vulnerability UpScrolled has now fixed came to light through that researcher's work. Across the technology sector, the relationship between platforms and security researchers is most productive when it is built on cooperation rather than legal deterrence. When vulnerability disclosures are met with enforcement language, researchers are less likely to report issues, leaving users to bear the cost.
UpScrolled has established a dedicated channel for reporting vulnerabilities, which is a positive development. For this channel to function effectively, it must be supported by a clear policy that distinguishes good-faith security research from malicious activity. Providing explicit protections for researchers acting in the public interest is essential to building trust with the security community.
Protecting yourself while the platform matures
We have prepared the following digital security tips for UpScrolled users:

A platform worth getting right
UpScrolled was not created by a major technology company seeking market share. It was built by a member of the community it serves, in direct response to the censorship that community was experiencing on other social media platforms. That origin carries both credibility and responsibility.
We engaged with UpScrolled because we share a commitment to digital rights in the SWANA region, and their willingness to respond is a foundation we intend to build on.
The people who migrated to UpScrolled did so because they entrusted it with something they had lost on other platforms: the ability to speak freely. Sustaining that trust requires an equally serious commitment to protecting their data, their location, and their identity. For the communities UpScrolled serves, privacy and freedom of expression are not separate rights. They are inseparable.