VELVET ROOMLEGAL • DRAFT
§

Safety, Enforcement & Appeals Policy

Version 0.2 | 21 August 2026
Development legal draft. This document is installed in the development app for review and architecture alignment. It is not publication-ready, is not wired as the final acceptance document, and remains subject to unresolved publication blockers and qualified counsel review.

1. Purpose

This Policy describes how Velvet Room proposes to receive, assess, investigate, enforce, document, and review safety and policy matters. It is designed to accompany the Terms of Service and Community Guidelines and to align enforcement with the Service's privacy, persona, access, location, and value-bearing architecture.

2. Governing Principles

3. Current Moderation Authority - Source-Backed

The Legal/Policy Authority Audit identified an authenticated admin moderation route protected by JWT authentication and an admin-role requirement. That route expressly allows admins to view gated media URLs for moderation and states that message body content is not logged by that admin moderation surface.

The audit also identified an account-level isBanned field used in profile availability checks, a Channel status field capable of representing banned/paused states, and event/audit hooks in the moderation route. These are current technical signals; they do not prove that every enforcement action described below is already implemented. The audit additionally identified a WhisperDiscipline model containing screenshotSuspensionCount and suspendedUntil fields, which supports an existing screenshot-discipline concept but does not prove platform-wide capture detection or a final escalation policy.

4. How a Safety Matter May Begin

A safety or policy matter may be initiated by a user report where a verified reporting tool exists, authorized moderator review, security/abuse signals, a valid legal notice, a payment/fraud dispute, or information that reasonably indicates a potential violation. This draft does not claim a universal report endpoint until the live core workflow is verified.

5. Triage Framework

5.1 Critical / Immediate Risk

Examples include credible imminent threats, child sexual exploitation, trafficking, severe stalking/location abuse, account compromise creating immediate danger, or other circumstances requiring urgent safety action. Velvet Room may take temporary protective action before a full review where delay would materially increase risk.

5.2 High-Risk Abuse

Examples include non-consensual intimate material, extortion, repeated stalking or harassment, serious impersonation/fraud, coordinated abuse, dangerous attempts to defeat private access, or repeated evasion after prior enforcement. Repeated or deliberate capture of private/gated sexual content, intimate communications, or other high-sensitivity material in violation of the no-screenshot rule may also be treated as high-risk abuse.

5.3 Standard Policy Matters

Examples include spam, lower-severity harassment, misleading promotion, first-time boundary violations, copyright/policy disputes, or other conduct that ordinarily allows time for evidence review and notice. A first or lower-risk screenshot/capture violation may enter this category where there is no evidence of exploitation, redistribution, stalking, extortion, or evasion.

These triage labels are policy design categories introduced by this draft; they are not represented as existing database states.

6. Investigation and Evidence

7. Available Enforcement Actions

Depending on severity, confidence, context, repetition, legal obligations, and technical capability, Velvet Room may use one or more of the following actions. Not every action below is yet proven to be implemented in production and publication requires an engineering enforcement matrix.

8. Account-Level and Persona-Level Enforcement

A violation may originate from a specific Social, Friends, or Work persona, but serious enforcement may apply to the root account because the personas are extensions of one account. Velvet Room should not reveal hidden sibling personas to the public as part of enforcement notices or user-facing actions unless disclosure is lawful and necessary.

Creating or using another persona, account, device, invite, or private link to evade a valid restriction is itself a policy violation and may increase the severity of enforcement.

9. 18+ Eligibility Enforcement

If Velvet Room reasonably determines that an account is controlled by or being used for a person under 18, it may restrict, suspend, or terminate access under the Terms and applicable law. The launch product must provide a real server-side age-eligibility path; a client-only statement is insufficient.

Any evidence involving possible sexual exploitation of a minor must be handled under the highest-priority safety path and applicable legal obligations. This policy does not publish operational details that could weaken protective procedures.

10. Radar and Location Protective Actions

Because location and proximity information can create physical safety risk, credible misuse may justify fast restriction of Radar/location capability, access grants, proximity visibility, or account access while a matter is reviewed. Location features are not emergency services, and Velvet Room does not promise continuous monitoring or real-time intervention.

11. Notice of Enforcement

Where legally permitted, technically feasible, and not likely to create additional safety risk, the affected account should receive notice that identifies the action taken, a plain-language reason category, the policy section implicated, whether the action is temporary or permanent, and whether an appeal is available.

Notice may be delayed, limited, or omitted where necessary to protect another person, preserve an investigation, comply with law, prevent evasion, protect system security, or respond to an emergency.

12. Appeals - PROPOSED FRAMEWORK / IMPLEMENTATION REQUIRED

The Legal/Policy Authority Audit did not establish a complete canonical Velvet Room appeals workflow. The following is the required launch design, not a claim that it already exists.

13. Repeat Violations, Evasion, and Severity Escalation

Repeated violations, coordinated abuse, retaliation, evasion, use of alternate personas/accounts/devices to bypass restrictions, or conduct showing deliberate exploitation of safety/access controls may result in stronger action than an isolated first incident. A single severe incident may justify immediate suspension or termination without prior warnings.

14. Abuse of Reporting and Enforcement Systems

15. Emergency, Law-Enforcement, and Preservation Requests

Velvet Room may preserve or disclose information when reasonably necessary to comply with valid legal process, applicable law, or a genuine emergency request, subject to legal and operational safeguards. Velvet Room is not an emergency response service and should not promise 24/7 human moderation unless that capability is actually staffed and verified.

16. Records, Auditability, and Retention

Significant moderation actions should record, where technically implemented, the relevant account/resource identifiers, action, reason category, policy version, actor or automated authority, timestamps, evidence references, and appeal outcome. The current admin moderation route includes an audit-safe event hook, supporting the principle of traceable enforcement.

Exact retention periods for moderation evidence, safety reports, notices, and appeals are blocked until the platform adopts the final data-retention matrix. Records should not be kept indefinitely merely because they relate to moderation.

17. Transparency and Privacy Limits

Velvet Room may provide high-level transparency about enforcement practices when accurate and useful, but should not publish security-sensitive methods, expose reporters, reveal hidden persona relationships, disclose private location, or provide details that materially enable evasion or retaliation.

18. Engineering Requirements Before Publication

19. Operator, Contact, and Publication Gate

Operator: GGIRL Technologies LLC, New Hampshire, United States.

Safety/report contact: [SAFETY CONTACT / SUPPORT PATH] | Legal contact: [LEGAL EMAIL] | Legal notice address: [LEGAL NOTICE ADDRESS]