CONTENT SAFETY POLICY
Last updated: August 24, 2026

1. PURPOSE

This Policy explains how DeCode manages safety risks across AI chat, coding assistance, image generation, voice and realtime interaction,
files, web-assisted tools, the Roblox Studio Assistant, and future connected services.

It is intended to complement the Acceptable Use Policy and Terms of Service. It does not promise that every harmful request will be detected
or that every Provider applies identical safety controls.

2. SAFETY PRINCIPLES

DeCode’s safety approach may include authenticated access, eligibility checks, automated moderation, Provider safeguards, server-side
controls, prompt checks, output checks where supported, rate limits, Credit limits, account-history review, human review of flagged cases,
user reporting, graduated enforcement, and disabling a feature when safeguards are unavailable.

3. AUTHENTICATION AND ELIGIBILITY

Supported AI features require an authenticated Account unless DeCode explicitly provides a limited public feature.

Account controls may include email verification, sign-in-provider verification, session checks, eligibility confirmation, rate limits,
account-status checks, subscription checks, and re-authentication for sensitive actions.

Eligible email-and-password Accounts may use a passkey whose private key remains on the user’s device or password manager. Accounts with a
verified email may add a compatible Authenticator app and may then be required to enter a current six-digit code at sign-in. DeCode may also
use short-lived email codes, login alerts, active-session records, and device disconnection. These controls reduce risk but do not guarantee
that an Account cannot be compromised.

4. REQUEST SAFETY CHECKS

Before or during processing, DeCode may evaluate user text, image prompts, uploaded images, voice transcripts, code requests, requested
actions, model selection, feature selection, account enforcement status, usage rate, previous safety findings, and limited technical
metadata.

5. PROVIDER SAFEGUARDS

External AI Providers may apply their own moderation and safety systems. A Provider may refuse, limit, classify, withhold, or modify a
request or output under its own rules.

Provider safeguards are an additional layer. They do not replace DeCode’s own request checks, image rules, account controls, enforcement, or
responsibility for operating the Product safely. DeCode may block a request even where another Provider would allow it.

6. CHAT SAFETY

Chat requests may be blocked or limited for sexual exploitation, adult sexual content, illegal activity, fraud, identity theft, violent
wrongdoing, malware, credential theft, privacy abuse, deepfake creation, voice impersonation, intellectual-property infringement, safety
evasion, prohibited regulated services, or other serious abuse.

7. CODE SAFETY

Code assistance is prohibited for malware, ransomware, spyware, phishing, credential theft, destructive payloads, unauthorised intrusion,
account takeover, CAPTCHA bypass, security bypass, fraud, botnets, or platform abuse.

Lawful debugging, defensive security, and authorised testing may be allowed when appropriately scoped.

8. IMAGE SAFETY

Image generation is available only when required safeguards are operating.

Prohibited image content includes adult or NSFW content, sexual content involving minors or young-looking people, nudification,
non-consensual intimate content, face swaps, deceptive deepfakes, fake evidence, impersonation, unauthorised likeness use, fake
endorsements, counterfeit products, copyright infringement, trademark infringement, unauthorised brands or characters, and removal of
ownership marks. NSFW content generation and harmful AI generation are prohibited.

When image generation is enabled in an environment, the server-side image pipeline applies multiple checks. It first applies DeCode’s local
request safety rules, then screens the raw user-supplied image prompt through Creem’s Moderation API before calling an image-generation model
and before reserving Credits. A Creem decision of “deny” or “flag” blocks the request. A missing key,
timeout, network failure, unsuccessful response, malformed response, or unknown decision also blocks generation until the required screening
can be completed. An “allow” decision permits only the next safety checks; it does not guarantee that the request or output is safe.

DeCode sends a non-sensitive internal generation identifier in Creem’s optional external_id field for audit traceability. It does not put the
Account identifier, API key, uploaded reference image, or generated image in that field. After a valid Creem response, the server records
limited verification metadata—environment, endpoint host, credential class, Creem moderation-result ID, external generation identifier,
decision, and time—in a server-only integration record. It does not put the prompt or API key in that verification record or related
structured log. Sandbox and production verification records are separate.

After Creem prompt screening, DeCode applies its own text rules and semantic image-identity classifier. Uploaded image-edit inputs and
generated image bytes are also screened server-side with the enabled AI Provider’s image-capable moderation model. The image Provider may
apply its own safeguards. These layers supplement one another; no single layer replaces DeCode’s controls or promises perfect detection.

Creem’s published AI-wrapper requirements require prompt screening and clear prohibitions on NSFW or harmful generation and on face-swap,
deepfake, and face-manipulation tools. They do not state that every visible human or fictional face must be disabled. See
https://docs.creem.io/merchant-of-record/account-reviews/ai-wrapper-compliance and https://docs.creem.io/features/moderation.

9. CREEM REQUIREMENT AND DECODE’S IDENTITY RULE

Creem requires the prompt-screening and prohibited-content controls described above for covered AI image products. DeCode permits an
otherwise safe, clearly fictional or generic face when Creem returns “allow” and every other required safeguard also passes. DeCode
separately blocks recognizable real-person faces and likenesses, face swaps, deepfakes, face manipulation, identity transfer or preservation,
fake endorsements, fabricated evidence, deceptive impersonation, and related harmful uses.

Sandbox configuration uses Creem’s test endpoint and a test key. Production configuration requires https://api.creem.io, a production key,
and a successful production moderation result recorded by the server. A sandbox result is not treated as proof that production moderation is
active. DeCode keeps public production image generation unavailable whenever that production configuration and verification are absent;
authorised sandbox testing does not make image generation a public production feature.

10. FICTIONAL AND REAL-PERSON FACE RESTRICTIONS

Otherwise safe image generation may depict a clearly fictional, generic, or invented human character, including realistic, photorealistic,
stylized, illustrated, cartoon, and animated faces. A fictional face alone does not trigger DeCode’s identity refusal.

Requests involving a recognizable real person’s face or likeness, an uploaded real-person identity that would remain recognizable, face
swaps, deepfakes, face manipulation, identity transfer or preservation, fake endorsements, fabricated evidence, deceptive impersonation, or
an uncertain identity classification are blocked. Safe non-human image generation remains allowed when the required safeguards are operating.

11. VOICE AND REALTIME SAFETY

Voice features may include microphone input, transcription, realtime conversation, Provider-supplied synthetic voices, and generated spoken
output.

DeCode does not provide a feature intended to clone a real person’s voice.

Prohibited voice uses include impersonation, unauthorised voice models, fake evidence, fraudulent calls, fake endorsements, harassment,
threats, identity-verification bypass, and synthetic speech deceptively presented as authentic.

12. ROBLOX SAFETY

The Roblox Studio Assistant is intended for lawful development. It must not assist with exploit scripts, cheating, account theft, anti-cheat
bypass, stolen assets, payment fraud, malicious code, unauthorised access, or circumvention of Roblox rules.

13. INTELLECTUAL-PROPERTY SAFETY

DeCode prohibits counterfeit content, piracy, unauthorised copying, protected-character infringement, brand infringement, stolen code or
assets, removal of ownership marks, unauthorised likeness use, and unauthorised voice use.

14. PRIVACY SAFETY

DeCode prohibits doxxing, leaked-data searches, invasive private-person profiling, unauthorised biometric use, stalking, identity theft,
stolen credentials, Account access without permission, and unnecessary exposure of sensitive information.

Memory is designed for durable preferences and working context, not secrets or high-risk personal data. Users should review the Memory
summary, remove anything that should not be retained, and turn Memory off when they do not want it used in General Chat. Turning it off stops
use and updates but does not erase the existing summary; the user must clear it or delete the Account.

Redeem codes are one-time Product entitlements. Guessing, automated redemption, resale, multiple-Account abuse, or attempts to alter Credit
records may be blocked, logged, and treated as account or payment abuse.

15. FINANCIAL, MEDICAL, AND HIGH-IMPACT SAFETY

DeCode is not intended to operate as a regulated financial, medical, legal, or other licensed professional service.

DeCode prohibits personalised financial or investment advice, asset-specific buy, sell, or hold recommendations, trading signals,
individual portfolio allocations, leverage or margin recommendations, entry or exit points, and strategies intended to maximise a person’s
investment profits.

DeCode prohibits medical diagnosis, personalised treatment, prescriptions, medication selection or changes, and medication dosing for a
person.

DeCode prohibits ranking, scoring, categorising, selecting, or making high-impact judgments about people based on faces, profiles, personal
information, or inferred traits. This includes judgments about trustworthiness, character, suitability, dangerousness, reliability, or
personal risk and decisions involving credit, employment, housing, insurance, medical access, education admission, or similar regulated
contexts.

Normal coding, writing, neutral research, general health education, general financial education, and safe non-human image generation remain
allowed when they do not become a prohibited use described in this Policy or the Acceptable Use Policy.

16. ACADEMIC-INTEGRITY SAFETY

DeCode may allow tutoring, explanation, practice material, and learning assistance, but it is not intended to operate as an essay mill,
exam-answer resale service, student-impersonation service, or business that deceptively completes graded work for others.

17. SPAM AND MANIPULATION SAFETY

DeCode may restrict spam, fake reviews, fake testimonials, artificial engagement, mass unsolicited messaging, deceptive advertising, or
automated social-media manipulation.

18. FLAGGING

An automated system may create a flag for a suspected policy violation. A safety flag may contain an Account identifier, timestamp, request
identifier, category, severity, flagged user-submitted content or excerpt, feature involved, action taken, and limited metadata.

19. ADMINISTRATOR REVIEW

Normal conversations are not routinely sent for manual review merely because they exist.

A flagged case may be sent to an authorised administrator. The administrator may receive flagged user content, safety category, severity,
Account identifier, technical request identifier, relevant enforcement history, and necessary context.

Generated output is not routinely included unless needed to investigate a user report, harmful output, moderation failure,
intellectual-property complaint, security incident, fraud, or legal obligation.

20. ENFORCEMENT GUIDELINES

Low severity may result in request blocking, a safety notice, or a warning.

Moderate or repeated violations may result in feature restriction, temporary suspension, or human review.

Serious or repeated violations may result in longer suspension, paid features disabled, or further review.

Extreme violations may result in permanent termination, prevention of Account recreation where appropriate, evidence preservation, or
legally required reporting.

21. EXTREME VIOLATIONS

Extreme violations may include sexual exploitation of minors, deliberate prohibited adult-content generation, non-consensual intimate
imagery, harmful deepfakes, unauthorised voice cloning, fraud, malware, credential theft, identity theft, credible threats, serious
stalking, repeated enforcement evasion, or other conduct creating severe harm.

22. USER REPORTING

Users may report unsafe content through available reporting controls or by emailing hello@decodeai.net.

Reports should include enough information to identify the issue but should not include passwords, full card numbers, API keys, recovery
codes, or unnecessary identity documents.

23. APPEALS

Users may appeal Account-level enforcement. A human reviewer may confirm, reduce, change, or remove the action.

An appeal does not automatically restore access or delay urgent protective action.

24. SAFETY RECORD RETENTION

Safety records are ordinarily scheduled for deletion after a reasonable retention period, which may be up to 180 days for routine safety
records unless a longer period is needed for repeated abuse, fraud, a security incident, an intellectual-property complaint, a dispute,
legal proceedings, protection of another person, or compliance with law.

25. AI LIMITATIONS

AI output may be incorrect, incomplete, outdated, biased, offensive, insecure, fabricated, or unsuitable. Users must review output before
relying on, publishing, distributing, or deploying it.

26. FEATURE SHUTDOWN

DeCode may disable a feature when a safeguard is unavailable, a Provider changes policy, risk becomes unacceptable, Creem requires action,
law changes, the feature is under development, or the feature cannot be operated safely. Image generation is configured to stay unavailable
unless the generation, image-moderation, and Creem prompt-moderation gates are all enabled; a failed Creem moderation call blocks the request.

27. CREEM COMPLIANCE

For eligible purchases processed through Creem, Creem acts as Merchant of Record for the resale Transaction. DeCode remains responsible for
delivering and operating the software, defining and enforcing its user-facing safety rules, responding to safety reports, and maintaining
the technical safeguards represented in this Policy. DeCode may take action necessary to meet Creem’s current Product, account-review, and
AI-wrapper requirements or a Creem compliance request relating to DeCode’s eligibility.

Legal text must accurately reflect the deployed Product. DeCode should not claim that a safeguard exists if it has not actually been
implemented.

Creem’s overview of its Merchant-of-Record role is available at https://docs.creem.io/merchant-of-record/what-is.

28. CHANGES

DeCode may update this Policy when features, Providers, Creem requirements, safety systems, or law changes.

29. CONTACT

Email:
hello@decodeai.net

Website:
https://decodeai.net