Moderation for your apps. Enforcement that sticks.
Limenia receives reports from your apps via API. Your team decides in the dashboard, and every decision goes back to the app with a statement of reasons under the Digital Services Act.
For app teams that must meet the DSA and the Apple and Google rules for user-generated content.
- Operated in Frankfurt (Google Cloud, europe-west3)
- Decisions back via webhook, Firebase and RevenueCat
- 30-day trial
How it works
Your app’s data stays in your app. Limenia is the management layer for reports, decisions and sanctions.
- App
Users report in the app
A report button in your app, for posts, comments, profiles or messages.
- Your backend
Your backend forwards it
One REST call with an API key sends the report with a snapshot of the content to Limenia. The key stays on your server.
- Limenia
Limenia groups and preserves
Reports on the same content become one case. Limenia keeps the content as evidence and sorts the queue, optionally with rules and an AI assessment.
- Dashboard
Your team decides
Moderators decide in the dashboard. Every decision comes with a statement of reasons under Art. 17 DSA.
- App
The decision goes back
Via a signed webhook to your backend and, if you like, directly in Firebase Authentication or RevenueCat. Your app enforces it and shows the reasons.
2 · Send a report
POST /v1/reports
Authorization: Bearer lm_live_…
{
"source": "user",
"reasonCategory": "harassment_hate",
"subject": { "externalUserId": "u_112" },
"content": {
"externalContentId": "comment_5521",
"text": "…"
}
}5 · Receive the decision
Limenia-Event-Type: decision.created
Limenia-Signature: t=…,v1=…
{
"decision": {
"action": "suspend_user",
"suspendUntil": "2026-11-08T10:00:00Z",
"statementOfReasons": { "text": "…" }
}
}What Limenia does today
Everything you need for notice and action, decisions and appeals, plus the tools that make sanctions stick.
Reports and cases
Reports via REST API, grouped into cases. A queue with filters, assignment and priorities. Content snapshot and media copy as evidence.
Statements of reasons (Art. 17 DSA)
For every restrictive decision a statement of reasons, structured and as ready-to-show text for your app.
Appeals and reporter feedback
Internal complaint handling under Art. 20 DSA for affected users and reporters, feedback to reporters under Art. 16(5).
Pre-moderation
Review content such as profile pictures or listings before it goes live. Types per app, single and bulk approval.
User records and sanctions
Warn, suspend, ban, restore. The user record shows the history per app.
Trusted flaggers and misuse
Trusted flaggers under Art. 22 DSA with priority in the queue. Protection against misuse of the reporting system under Art. 23.
Transparency
Transparency report export in the EU’s harmonised format. Submission of statements of reasons to the DSA Transparency Database.
Store checklist
A checklist per app for the Apple (App Review Guidelines 1.2 and 5.1.1(v)) and Google Play rules on user-generated content.
Signals and rules
Your app sends signals; rules with thresholds and time windows open cases or raise priority. Test a rule against past signals first.
AI pre-check
An assessment against your policies, a suggestion to adopt and prioritisation. A human decides. Opt-in, processed in Frankfurt.
Retention and legal hold
You set the retention periods, Limenia deletes automatically afterwards. Legal hold for single cases. An audit log for every action.
Moderator wellbeing
Images blurred by default, roles per team member, two-factor sign-in for owners and admins.
Coming soon
Planned, no fixed dates yet.
- AI automationNarrowly scoped decisions under your rules, never against accounts, with sampling and a kill switch.
- Supabase connectorBans directly in Supabase Auth, as with Firebase today.
- Ban evasion across appsNotice when a banned person becomes active in another one of your apps.
- App healthCrashes, performance and usage per app, next to moderation.
- Store reviewsCollect reviews, classify them and prepare replies.
Pricing
Three plans. The DSA obligations are part of every plan.
Prices and limits to follow. All values in square brackets are placeholders.
Basic
For one app that wants a proper notice-and-action process.
[PRICE] / month
Request a trial- [X] app
- Reports, cases, decisions with reasons
- Appeals and feedback to reporters
- Transparency report and database
- Signed webhooks
- AI pre-check as an add-on
Pro
RecommendedFor teams whose sanctions need to stick.
[PRICE] / month
Request a demo- Up to [X] apps
- Everything in Basic
- Pre-moderation
- Firebase, RevenueCat and device connectors
- Signals and rules
- AI pre-check with [N] checks per month
Premium
For several apps, higher volumes and individual contracts.
from [PRICE] / month
Get in touch- Apps by agreement
- Everything in Pro
- AI pre-check with [M] checks per month
- AI automation (soon)
- Ban evasion across all apps (soon)
- Billing by contract possible
- New accounts start with a 30-day trial.
- Limenia always accepts reports. The reporting channel is never blocked because of your plan.
- AI pre-check add-on: [PRICE] / month with [N] checks. Beyond that [PRICE] per check, only if you switch overage on.
- Monthly or yearly billing. Prices exclude VAT.
Compare all features
| Feature | Basic | Pro | Premium |
|---|---|---|---|
| DSA essentials (in every plan) | |||
| Reports via API, cases, moderation queue | |||
| Decisions with statement of reasons (Art. 17) | |||
| Internal complaint handling (Art. 20), feedback to reporters | |||
| Trusted flaggers, misuse of the reporting system (Art. 22, 23) | |||
| Transparency report, submission to the Transparency Database | |||
| Store checklist for Apple and Google Play | |||
| Retention periods, legal hold, audit log | |||
| Signed webhooks | |||
| Team roles, two-factor sign-in | |||
| Limits | |||
| Apps | [X] | up to [X] | by agreement |
| Reports | never blocked | never blocked | never blocked |
| Enforcement and connectors | |||
| Pre-moderation | |||
| Firebase connector | |||
| Supabase connector | Soon | Soon | |
| RevenueCat connector | |||
| Device connector (Play Integrity, DeviceCheck) | |||
| Signals and rules | |||
| Ban evasion across all apps | Soon | ||
| AI pre-check | |||
| Level A: assessment and suggestion | Add-on | [N] / month | [M] / month |
| Level B: automation | Soon, add-on | Soon | |
| Planned | |||
| App health | Soon | Soon | |
Integrations
Any backend that speaks HTTPS can connect to Limenia. For common platforms there are connectors and examples.
- Available
Webhooks
Every decision as an event to your backend, signed with HMAC-SHA256, with retries and a delivery log.
- Available
Firebase
Disable and re-enable accounts in Firebase Authentication directly. No shared keys, just permissions in your own project.
- Available
RevenueCat
On a ban, cancel web subscriptions and revoke promotional access as far as the stores allow. Notice when purchases of banned users move to a new account.
- Available
Device check
Bans that survive a reinstall, without fingerprinting: via Google Play Integrity and Apple DeviceCheck. With the Flutter plugin limenia_device.
- Available
DSA Transparency Database
Submit the statements of reasons for your decisions to the European Commission’s database.
- Soon
Supabase
Bans directly in Supabase Auth. An example with Supabase Edge Functions is available today.
Examples for your backend
Small, runnable examples: send a report, receive a webhook with signature verification, check a device. Open source under Apache 2.0.
- Node.js (Express)
- Python (FastAPI)
- Go
- PHP (Laravel)
- AWS Lambda
- Supabase Edge Functions
- Firebase Cloud Functions
Data protection and EU operation
Limenia processes reported content. That is why it is built for data minimisation and short paths.
Frankfurt
Servers, database, queues and secrets run in the Google Cloud region europe-west3 in Frankfurt am Main, Germany.
Private media
Media copies live in private storage in the EU (Cloudflare R2 with EU jurisdiction), reachable only through short-lived signed links after a permission check.
Data minimisation
Limenia only stores snapshots of reported content. Reporters only as a hash, no email addresses of your users. No content in logs.
Deletion on schedule
You set the retention periods. Afterwards Limenia deletes automatically, unless a legal hold is active.
Protected keys
API keys are stored only as a hash. Webhook secrets and credentials live in Secret Manager in Frankfurt.
AI only with opt-in
The AI pre-check runs on Google Cloud Vertex AI in Frankfurt and only if you switch it on.
Exceptions
- Your team signs in through Google’s Firebase Authentication. Moderator account data may also be processed outside the EU.
- Firebase Hosting only passes requests to the dashboard domain through, without storing them.
- Stripe processes the billing data for your subscription.
- The device connector uses Google Play Integrity and Apple DeviceCheck under your own agreements with Google and Apple.
Limenia is a tool and does not replace legal advice.
Frequently asked questions
Who is Limenia for?
For teams that run one or more apps with user-generated content, such as comments, profiles, images or messages, and need a reporting process, moderation and sanctions for it.
Does my app have to comply with the Digital Services Act?
If your app stores content from users and is available in the EU, DSA obligations usually apply, such as notice and action (Art. 16) and statements of reasons (Art. 17). Further obligations depend on the size of the company. Have this checked for your case. Limenia helps you implement the obligations but does not replace legal advice.
What do Apple and Google require?
For apps with user-generated content, both require among other things a way to report content, to block other users and a timely response to reports. The store checklist in Limenia shows per app what is in place and what is still missing.
Which data leaves my app?
Only what your backend sends with a report: a snapshot of the reported content, media copies as evidence and the external user ID of the reported person. Reporters are stored only as a hash. Everything is deleted after the retention periods you set.
Where is the data processed?
Servers, database and queues run in Frankfurt (Google Cloud, region europe-west3); media copies live in storage with EU jurisdiction. Exceptions are the moderators’ sign-in through Firebase Authentication, billing through Stripe and the device connector with Google and Apple.
Does the AI decide on its own?
No. The AI pre-check assesses content against your policies, suggests a decision and raises the priority where needed. A human makes the decision. A narrowly scoped automation is planned; actions against accounts and appeals will stay with humans even then.
Which backend do I need?
Any backend that can send and receive HTTPS requests. There are examples for Node.js, Python, Go, PHP, AWS Lambda, Supabase Edge Functions and Firebase Cloud Functions. For Firebase and RevenueCat, Limenia can also enforce bans directly.
What happens when my subscription ends?
Limenia keeps accepting reports and appeals, and you can still decide open cases. Only new apps, new API keys, new pre-moderation requests and add-ons are blocked.
How do I get started?
Write to us. We set up your account, then a wizard guides you through policies, retention periods and your first app. The first 30 days are a trial.
Let’s talk about your app
We show you Limenia with an example and work out what your app needs for the DSA and the app stores.
Email: [KONTAKT-E-MAIL]