what gets removed, and who decides.
LAST UPDATED 14 SEPTEMBER 2026
Messages are end-to-end encrypted, which shapes everything here: we cannot read them, so moderation happens where the plaintext legitimately exists and nowhere else.
messages: on your device
A deterministic screen runs on your phone before a message is encrypted. It catches contact details, money solicitation, and attempts to turn this into a dating app.
We cannot screen message content on the server because we do not have it. That is a consequence of encryption we accept rather than a gap we are working around.
the feed: before it exists
Every post and comment is classified before it is stored. Two layers: deterministic rules for contact details and crisis language, then Gemini 2.5 Flash Lite for the harder question — does this text identify the other person.
A post is rejected when it combines a physical description, a specific place, and a time. Any one of those alone is fine; the combination is what lets a reader point at someone.
Comments are filtered for sarcasm, condescension, and advice nobody asked for. If it would land badly on someone who just did something hard, it does not go through.
reports
A report attaches the excerpt from the reporter’s own decrypted copy, which is the only place we can legitimately see it.
The reported person is never told who reported them. Harassment ends an account on the first instance.
what we do not moderate
Awkwardness, boredom, disappointment, and admitting an evening did not work. Those are what the feed is for, and a classifier that removes them has misunderstood the product.
QUESTIONS
Open a ticket at /support and say it is a legal matter. It goes straight to a person — the automatic first line is not allowed to touch legal, press, or data-access requests. There is no email address, for us or for you: a legal question sent by mail arrives with no case file and no way to prove later what was asked or when.