Throughout these terms and conditions
- “Abusing” user data refers to buying, selling, disclosing, transferring, or using Facebook or Instagram user data, to include credentials, in any manner prohibited by policies or terms governing the Facebook or Instagram platforms or any applicable laws
Before reporting, please review this page, including the General Terms, Requirements for Data Abuse Bounty reports, and Data Abuse Bounty program reward eligibility. If you are looking to report another type of issue or for other information about Facebook, please use the links below for assistance:
General terms
We aim to reward those who report a third-party app currently or formerly operating on Facebook or Instagram that has abused user data. Monetary rewards may be made to those whose reports lead to discovery of significant actionable abuse. Whether a specific report merits a reward is entirely at our discretion, based on impact, quality of the report, and other factors. To be eligible for a reward, you must not violate any applicable laws or regulations, including laws and regulations prohibiting unauthorized access to user data. You also must not violate any of Meta Terms and Policies or the terms and policies of any member of the Meta family of companies.
To participate in the program, you must:
-
Adhere to the Requirements for Data Abuse Bounty reports (see below).
-
Meet the eligibility requirements described in Data Abuse Bounty program reward eligibility (see below).
-
Submit your report via our report form and respond to follow up requests from Meta. Please do not contact Meta employees directly or through other channels about a report unless a Meta employee reaches out to you first.
In turn, we will follow these guidelines when evaluating reports under our program:
-
We determine reward amounts based on a variety of factors, including the impact and quality of the report. While there is no maximum, high-impact reports have garnered as much as $40,000* for people who bring them to our attention. If we pay a reward, payment will be made after we conclude our investigation into the issue you report.
-
We seek to pay similar amounts for similar issues, but reward amounts and qualifying reports may change with time. Past rewards do not necessarily guarantee similar rewards in the future.
-
In the event of duplicate reports, we provide a reward to the first person to submit a report that leads to discovery of significant actionable abuse. Meta determines which report qualifies for an award.
-
You may donate a reward to a recognized charity (subject to Meta approval), and we will double reward amounts that are donated in this way.
-
We reserve the right to publish the results of our investigation.
-
All rewards must be permissible under applicable laws, including US trade sanctions and economic restrictions.
Note that your use of Meta services and the services of any member of the Meta family of companies, including for purposes of this program, is subject to Meta Terms and Policies (https://www.facebook.com/policies) and the terms and policies of any member of the Meta family of companies (https://www.facebook.com/help/111814505650678) whose services you use. We (and any member of the Meta family of companies whose services you use) may retain any communications about issues you report for as long as we deem necessary for program purposes, and we may cancel or modify this program at any time.
Requirements for data abuse prevention reports
Your report must describe:
-
The operator of the applicable third-party app, including the name of the app and if known, the relevant appID;
-
The actions taken by the app or website that violate policies or terms governing the Facebook or Instagram platforms or are otherwise unlawful;
-
The nature and scope of the Facebook or Instagram user data abused;
-
Proof of the abuse being reported; and
-
Any information you have about the reason or purpose for the third-party app operator’s conduct.
Your report should include all instances of abusive conduct you are aware of that relate to a single third-party app. Do not submit multiple reports related to the same abusive conduct.
We require that:
-
You do not submit any of the misused user data or credentials to Meta with your report, or at any other time unless Meta specifically requests such information, at which point you should carefully follow any instructions Meta provides about what data to submit and how to submit it.
-
You give Meta reasonable time to investigate an issue you report before making public any information about the report or sharing such information with others.
-
You have specific and direct knowledge regarding the abuse that you are reporting.
-
You do not knowingly submit false information through the Data Abuse Bounty program. Meta will take all necessary actions in response to false submissions, including, but not limited to, banning you from Facebook.
If legal action is initiated by a third party against you and you have complied with our policies, we will take steps, as appropriate, to make it known that your actions were conducted in compliance with our policies.
Nothing in these Terms and Conditions should be construed to prevent you from sharing any information about Meta abuse of user data or credentials with law enforcement. Meta likewise reserves the right to share the information you provide with law enforcement as appropriate.
Data Abuse Bounty program reward eligibility
To be eligible for a Data Abuse Bounty program reward, you must not:
-
Be a resident of, or make your submission from, a country against which the United States has issued export sanctions or other trade restrictions (e.g., Cuba, Iran, North Korea, Sudan, Crimea Region of Ukraine, and Syria);
-
Be employed by Meta, Inc. or its subsidiaries or affiliates;
-
Be an immediate family member of a person employed by Meta, Inc. or its subsidiaries or affiliates; or
-
Be less than 14 years of age. If you are at least 14 years old, but are considered a minor in your place of residence, you must get your parent’s or legal guardian’s permission prior to participating in the program.
Scope
To be eligible for a reward, the situation must involve:
-
More than 10,000 Facebook and/or Instagram users.
-
Definitive abuse of user data—not just collection
-
A case we were not already aware of or actively investigating.
Explicitly out of scope scenarios:
-
Scraping. Note that in cases of datasets where there is evidence of active misuse and there are over 100,000 unique Facebook user records with PII (e.g. email, phone number, physical address, religious or political affiliation), you can report those at bugbounty@meta.com. Eligible findings will only be rewarded in the form of charity donations.
-
Malware or mass-scale tricking of users to install apps.
-
Non-Facebook or Non-Instagram cases (ex: WhatsApp).
Check back often as we hope to continue to expand the scope of this program.
To best understand the intent of the program see the FAQ page.
(Last updated June 18, 2024)