Boundary types
A boundary set is structured data chosen from a closed vocabulary, because both sides — the creator writing the rule and the engine enforcing it — have to mean the same thing by it.
Prohibited platform-wide (4)
Checked before any creator’s own rules are read. No boundary set can permit these, and a boundary set that tries is rejected at write time rather than silently trimmed.
Any depiction of, or alongside, a person under 18, and any framing that presents an adult likeness as a minor.
A creator cannot consent on behalf of a child, and no boundary set may authorise output that sexualises or juvenilises a likeness. Refused platform-wide, before the creator's own rules are read.
Depictions framed as taken without knowledge or against the subject's will — hidden-camera, leaked, coerced or restrained framing.
The product exists to make consent legible. Output that performs the absence of consent contradicts the artifact it would be stamped with, whatever the boundary set says.
Output styled as journalism, a news broadcast, a police or court record, or an official government communication.
A licensed likeness in a fabricated news frame deceives third parties who never entered into the licence. Creators may license endorsement; they may not license the appearance of a fact.
Depictions placing the likeness in the commission of a crime, in terrorist or extremist iconography, or in hate propaganda.
Defamatory by construction and unlawful in most of the markets this operates in. Not a creator-level choice.
Creator-controlled categories (11)
Each creator decides these for themselves. Three of them — sexual content, nudity and intimate-partner framing — are forbidden unless explicitly permitted, because silence must not read as agreement.
Sexual acts, sexualised posing, or explicitly erotic framing.
Full or partial nudity, lingerie, and see-through or topless framing.
Output framed as the creator being in a romantic or domestic relationship with the requester.
The likeness supporting, opposing or campaigning for a party, candidate, referendum or cause.
The likeness placed in worship, religious iconography, or as a religious figure.
Consuming or promoting alcohol, tobacco, vaping, cannabis or gambling.
The likeness endorsing a treatment, supplement, procedure, diagnosis or health outcome.
Weapons, fighting, injury or gore.
The likeness promoting an investment, token, trading scheme or financial product.
Named brands the creator's existing commercial agreements exclude.
The likeness depicted grieving, seriously ill, dying, dead, or in evident psychological distress.
Contexts (10)
An allowlist. A context the creator has not permitted is refused — omission is not permission.
- Portrait
- Head-and-shoulders or standing portraiture with no additional narrative setting.
- Fashion & editorial
- Styled clothing, lookbook and magazine-editorial framing.
- Fitness & sport
- Training, athletic and sportswear contexts.
- Cosplay & character
- Costume and fictional-character framing, subject to third-party IP being cleared separately.
- Brand endorsement
- The likeness shown using, holding or recommending a named product or brand.
- Music & performance
- Stage, studio and performance settings.
- Gaming avatar
- In-game character and streaming-overlay use.
- Seasonal & holiday
- Festive, seasonal and calendar-event framing.
- Travel & lifestyle
- Location, food, interiors and day-in-the-life framing.
- Stylised fan art
- Deliberately non-photographic interpretation — illustration, painterly, anime, 3D-render.
Realism tiers
Ordered. A request may not exceed the creator’s ceiling, and photoreal additionally requires a fully identity-verified requester.
- 1stylised
Obviously synthetic rendering. The lowest-risk tier and the most common ceiling.
- 2illustrative
Clearly non-photographic — illustration, painterly, anime, 3D render.
- 3photorealID verification required
Photographic realism of a real person, which is where the stakes on knowing who asked stop being a formality.
Questions
- Why a closed vocabulary instead of free text?
- Because the boundary set has to be evaluated before a model runs, not read by a human afterwards. A rule written in prose is a rule somebody has to interpret, and two people interpreting it differently is exactly the failure this replaces.
- How is a request matched to a category?
- Each category carries a lexicon of terms. The request is normalised and matched on word boundaries — so 'analysis' does not match a term inside it — and the matched term is quoted back in the refusal. There is no model and no scoring threshold in this path: a boundary that only refuses 'usually' is not a boundary a creator can rely on.
- What if the lexicon misses a phrasing?
- Then the request reaches the context allowlist, the realism ceiling and the verification gates, which are structural rather than lexical and do not depend on wording. A miss is possible; it is why the refusal path is not the only control, and why the audit log records every request so a creator can see what was asked.