CONTENT SAFETY POLICY Last updated: August 24, 2026 1. PURPOSE This Policy explains how DeCode manages safety risks across AI chat, coding assistance, image generation, voice and realtime interaction, files, web-assisted tools, the Roblox Studio Assistant, and future connected services. It is intended to complement the Acceptable Use Policy and Terms of Service. It does not promise that every harmful request will be detected or that every Provider applies identical safety controls. 2. SAFETY PRINCIPLES DeCode’s safety approach may include authenticated access, eligibility checks, automated moderation, Provider safeguards, server-side controls, prompt checks, output checks where supported, rate limits, Credit limits, account-history review, human review of flagged cases, user reporting, graduated enforcement, and disabling a feature when safeguards are unavailable. 3. AUTHENTICATION AND ELIGIBILITY Supported AI features require an authenticated Account unless DeCode explicitly provides a limited public feature. Account controls may include email verification, sign-in-provider verification, session checks, eligibility confirmation, rate limits, account-status checks, subscription checks, and re-authentication for sensitive actions. Eligible email-and-password Accounts may use a passkey whose private key remains on the user’s device or password manager. Accounts with a verified email may add a compatible Authenticator app and may then be required to enter a current six-digit code at sign-in. DeCode may also use short-lived email codes, login alerts, active-session records, and device disconnection. These controls reduce risk but do not guarantee that an Account cannot be compromised. 4. REQUEST SAFETY CHECKS Before or during processing, DeCode may evaluate user text, image prompts, uploaded images, voice transcripts, code requests, requested actions, model selection, feature selection, account enforcement status, usage rate, previous safety findings, and limited technical metadata. 5. PROVIDER SAFEGUARDS External AI Providers may apply their own moderation and safety systems. A Provider may refuse, limit, classify, withhold, or modify a request or output under its own rules. Provider safeguards are an additional layer. They do not replace DeCode’s own request checks, image rules, account controls, enforcement, or responsibility for operating the Product safely. DeCode may block a request even where another Provider would allow it. 6. CHAT SAFETY Chat requests may be blocked or limited for sexual exploitation, adult sexual content, illegal activity, fraud, identity theft, violent wrongdoing, malware, credential theft, privacy abuse, deepfake creation, voice impersonation, intellectual-property infringement, safety evasion, prohibited regulated services, or other serious abuse. 7. CODE SAFETY Code assistance is prohibited for malware, ransomware, spyware, phishing, credential theft, destructive payloads, unauthorised intrusion, account takeover, CAPTCHA bypass, security bypass, fraud, botnets, or platform abuse. Lawful debugging, defensive security, and authorised testing may be allowed when appropriately scoped. 8. IMAGE SAFETY Image generation is available only when required safeguards are operating. Prohibited image content includes adult or NSFW content, sexual content involving minors or young-looking people, nudification, non-consensual intimate content, face swaps, deceptive deepfakes, fake evidence, impersonation, unauthorised likeness use, fake endorsements, counterfeit products, copyright infringement, trademark infringement, unauthorised brands or characters, and removal of ownership marks. NSFW content generation and harmful AI generation are prohibited. When image generation is enabled in an environment, the server-side image pipeline applies multiple checks. It first applies DeCode’s local request safety rules, then screens the raw user-supplied image prompt through Creem’s Moderation API before calling an image-generation model and before reserving Credits. A Creem decision of “deny” or “flag” blocks the request. A missing key, timeout, network failure, unsuccessful response, malformed response, or unknown decision also blocks generation until the required screening can be completed. An “allow” decision permits only the next safety checks; it does not guarantee that the request or output is safe. DeCode sends a non-sensitive internal generation identifier in Creem’s optional external_id field for audit traceability. It does not put the Account identifier, API key, uploaded reference image, or generated image in that field. After a valid Creem response, the server records limited verification metadata—environment, endpoint host, credential class, Creem moderation-result ID, external generation identifier, decision, and time—in a server-only integration record. It does not put the prompt or API key in that verification record or related structured log. Sandbox and production verification records are separate. After Creem prompt screening, DeCode applies its own text rules and semantic image-identity classifier. Uploaded image-edit inputs and generated image bytes are also screened server-side with the enabled AI Provider’s image-capable moderation model. The image Provider may apply its own safeguards. These layers supplement one another; no single layer replaces DeCode’s controls or promises perfect detection. Creem’s published AI-wrapper requirements require prompt screening and clear prohibitions on NSFW or harmful generation and on face-swap, deepfake, and face-manipulation tools. They do not state that every visible human or fictional face must be disabled. See https://docs.creem.io/merchant-of-record/account-reviews/ai-wrapper-compliance and https://docs.creem.io/features/moderation. 9. CREEM REQUIREMENT AND DECODE’S IDENTITY RULE Creem requires the prompt-screening and prohibited-content controls described above for covered AI image products. DeCode permits an otherwise safe, clearly fictional or generic face when Creem returns “allow” and every other required safeguard also passes. DeCode separately blocks recognizable real-person faces and likenesses, face swaps, deepfakes, face manipulation, identity transfer or preservation, fake endorsements, fabricated evidence, deceptive impersonation, and related harmful uses. Sandbox configuration uses Creem’s test endpoint and a test key. Production configuration requires https://api.creem.io, a production key, and a successful production moderation result recorded by the server. A sandbox result is not treated as proof that production moderation is active. DeCode keeps public production image generation unavailable whenever that production configuration and verification are absent; authorised sandbox testing does not make image generation a public production feature. 10. FICTIONAL AND REAL-PERSON FACE RESTRICTIONS Otherwise safe image generation may depict a clearly fictional, generic, or invented human character, including realistic, photorealistic, stylized, illustrated, cartoon, and animated faces. A fictional face alone does not trigger DeCode’s identity refusal. Requests involving a recognizable real person’s face or likeness, an uploaded real-person identity that would remain recognizable, face swaps, deepfakes, face manipulation, identity transfer or preservation, fake endorsements, fabricated evidence, deceptive impersonation, or an uncertain identity classification are blocked. Safe non-human image generation remains allowed when the required safeguards are operating. 11. VOICE AND REALTIME SAFETY Voice features may include microphone input, transcription, realtime conversation, Provider-supplied synthetic voices, and generated spoken output. DeCode does not provide a feature intended to clone a real person’s voice. Prohibited voice uses include impersonation, unauthorised voice models, fake evidence, fraudulent calls, fake endorsements, harassment, threats, identity-verification bypass, and synthetic speech deceptively presented as authentic. 12. ROBLOX SAFETY The Roblox Studio Assistant is intended for lawful development. It must not assist with exploit scripts, cheating, account theft, anti-cheat bypass, stolen assets, payment fraud, malicious code, unauthorised access, or circumvention of Roblox rules. 13. INTELLECTUAL-PROPERTY SAFETY DeCode prohibits counterfeit content, piracy, unauthorised copying, protected-character infringement, brand infringement, stolen code or assets, removal of ownership marks, unauthorised likeness use, and unauthorised voice use. 14. PRIVACY SAFETY DeCode prohibits doxxing, leaked-data searches, invasive private-person profiling, unauthorised biometric use, stalking, identity theft, stolen credentials, Account access without permission, and unnecessary exposure of sensitive information. Memory is designed for durable preferences and working context, not secrets or high-risk personal data. Users should review the Memory summary, remove anything that should not be retained, and turn Memory off when they do not want it used in General Chat. Turning it off stops use and updates but does not erase the existing summary; the user must clear it or delete the Account. Redeem codes are one-time Product entitlements. Guessing, automated redemption, resale, multiple-Account abuse, or attempts to alter Credit records may be blocked, logged, and treated as account or payment abuse. 15. FINANCIAL, MEDICAL, AND HIGH-IMPACT SAFETY DeCode is not intended to operate as a regulated financial, medical, legal, or other licensed professional service. DeCode prohibits personalised financial or investment advice, asset-specific buy, sell, or hold recommendations, trading signals, individual portfolio allocations, leverage or margin recommendations, entry or exit points, and strategies intended to maximise a person’s investment profits. DeCode prohibits medical diagnosis, personalised treatment, prescriptions, medication selection or changes, and medication dosing for a person. DeCode prohibits ranking, scoring, categorising, selecting, or making high-impact judgments about people based on faces, profiles, personal information, or inferred traits. This includes judgments about trustworthiness, character, suitability, dangerousness, reliability, or personal risk and decisions involving credit, employment, housing, insurance, medical access, education admission, or similar regulated contexts. Normal coding, writing, neutral research, general health education, general financial education, and safe non-human image generation remain allowed when they do not become a prohibited use described in this Policy or the Acceptable Use Policy. 16. ACADEMIC-INTEGRITY SAFETY DeCode may allow tutoring, explanation, practice material, and learning assistance, but it is not intended to operate as an essay mill, exam-answer resale service, student-impersonation service, or business that deceptively completes graded work for others. 17. SPAM AND MANIPULATION SAFETY DeCode may restrict spam, fake reviews, fake testimonials, artificial engagement, mass unsolicited messaging, deceptive advertising, or automated social-media manipulation. 18. FLAGGING An automated system may create a flag for a suspected policy violation. A safety flag may contain an Account identifier, timestamp, request identifier, category, severity, flagged user-submitted content or excerpt, feature involved, action taken, and limited metadata. 19. ADMINISTRATOR REVIEW Normal conversations are not routinely sent for manual review merely because they exist. A flagged case may be sent to an authorised administrator. The administrator may receive flagged user content, safety category, severity, Account identifier, technical request identifier, relevant enforcement history, and necessary context. Generated output is not routinely included unless needed to investigate a user report, harmful output, moderation failure, intellectual-property complaint, security incident, fraud, or legal obligation. 20. ENFORCEMENT GUIDELINES Low severity may result in request blocking, a safety notice, or a warning. Moderate or repeated violations may result in feature restriction, temporary suspension, or human review. Serious or repeated violations may result in longer suspension, paid features disabled, or further review. Extreme violations may result in permanent termination, prevention of Account recreation where appropriate, evidence preservation, or legally required reporting. 21. EXTREME VIOLATIONS Extreme violations may include sexual exploitation of minors, deliberate prohibited adult-content generation, non-consensual intimate imagery, harmful deepfakes, unauthorised voice cloning, fraud, malware, credential theft, identity theft, credible threats, serious stalking, repeated enforcement evasion, or other conduct creating severe harm. 22. USER REPORTING Users may report unsafe content through available reporting controls or by emailing hello@decodeai.net. Reports should include enough information to identify the issue but should not include passwords, full card numbers, API keys, recovery codes, or unnecessary identity documents. 23. APPEALS Users may appeal Account-level enforcement. A human reviewer may confirm, reduce, change, or remove the action. An appeal does not automatically restore access or delay urgent protective action. 24. SAFETY RECORD RETENTION Safety records are ordinarily scheduled for deletion after a reasonable retention period, which may be up to 180 days for routine safety records unless a longer period is needed for repeated abuse, fraud, a security incident, an intellectual-property complaint, a dispute, legal proceedings, protection of another person, or compliance with law. 25. AI LIMITATIONS AI output may be incorrect, incomplete, outdated, biased, offensive, insecure, fabricated, or unsuitable. Users must review output before relying on, publishing, distributing, or deploying it. 26. FEATURE SHUTDOWN DeCode may disable a feature when a safeguard is unavailable, a Provider changes policy, risk becomes unacceptable, Creem requires action, law changes, the feature is under development, or the feature cannot be operated safely. Image generation is configured to stay unavailable unless the generation, image-moderation, and Creem prompt-moderation gates are all enabled; a failed Creem moderation call blocks the request. 27. CREEM COMPLIANCE For eligible purchases processed through Creem, Creem acts as Merchant of Record for the resale Transaction. DeCode remains responsible for delivering and operating the software, defining and enforcing its user-facing safety rules, responding to safety reports, and maintaining the technical safeguards represented in this Policy. DeCode may take action necessary to meet Creem’s current Product, account-review, and AI-wrapper requirements or a Creem compliance request relating to DeCode’s eligibility. Legal text must accurately reflect the deployed Product. DeCode should not claim that a safeguard exists if it has not actually been implemented. Creem’s overview of its Merchant-of-Record role is available at https://docs.creem.io/merchant-of-record/what-is. 28. CHANGES DeCode may update this Policy when features, Providers, Creem requirements, safety systems, or law changes. 29. CONTACT Email: hello@decodeai.net Website: https://decodeai.net