What to include
- what you were trying to do and the stage that failed;
- the approximate UTC time and browser/device class;
- a
cf-Cloudflare request ID only if Ultra displayed one in error details, plus release markers when available; - whether retry, resume, refresh, or another network changed the result.
Use the local redacted support-bundle control when available. Never substitute a UUID, share, transfer, target, or capability ID; these identifiers may authorize access.
Build a redacted support bundle
Never include
- file contents or filenames that disclose private information;
- share, transfer, target, or capability IDs;
- share-link fragments, passcodes, magic links, session cookies, API keys, delete tokens, or signed R2 URLs;
- full email headers or third-party personal data unless specifically requested through an approved secure channel.
Security and abuse
Security vulnerabilities should follow security.txt. Harmful content or account behavior should use the abuse report process. If someone faces immediate danger, contact the appropriate local emergency service first.
Authentication email recovery
Wait briefly, check spam or filtering, verify the address, and request one fresh link. Do not repeatedly request links. Provider acceptance does not prove inbox delivery; SPF, DKIM, DMARC, bounce, and suppression evidence remain pre-launch checks. Existing valid sessions can continue to be used while email delivery is investigated.