AI Moderation Policy
Reading note. Each operative section states its Purpose, Scope, Implementation status, Trigger, Possible evidence, Decision maker, Possible outcomes, and Appeal availability. The governing principles run throughout: AI assists moderation and does not replace human judgment; AI outputs are treated as evidence and recommendations, not final decisions; AI recommendations are reviewed by a person where the decision is consequential; a permanent ban is never issued solely by AI; human reviewers may override AI; confidence thresholds are configurable; and AI systems are continuously evaluated.
1. Purpose
Purpose. To govern every use of artificial intelligence and automated decision-support in moderation on Tirvea: how AI is used, where human review is required, what AI may and may not decide, and the transparency, rights, and safeguards that apply.
Scope. All automated moderation and decision-support systems.
Implementation status. Framework section.
Trigger. Not applicable.
Possible evidence. Not applicable.
Decision maker. WiseWave Limited, through its Trust & Safety and AI-governance functions.
Possible outcomes. A clear, accountable framework for AI-assisted moderation.
Appeal availability. Moderation decisions are appealable under the Appeals Policy (/legal/appeals).
2. Scope
Purpose. To state what this Policy covers.
Scope. All automated systems that assist moderation, verification, and safety, and the human processes that govern them. It does not cover product features unrelated to moderation.
Implementation status. Framework section.
Trigger. Not applicable.
Possible evidence. Not applicable.
Decision maker. Trust & Safety and AI-governance functions.
Possible outcomes. Consistent governance of AI-assisted moderation.
Appeal availability. As in §1.
3. Definitions
Purpose. To define AI terms used here. Conduct rules are in the Community Guidelines (/legal/community-guidelines); enforcement states in the Account Suspension Policy (/legal/account-suspension); data terms in the Privacy Policy (/legal/privacy).
- "AI system" - an automated system that classifies, scores, or flags content or signals to assist a moderation or safety decision.
- "Provider" - a third-party or internal adapter that returns a moderation or verification result.
- "Score" / "confidence" - a numeric output indicating the strength of a signal.
- "Risk band" - a normalised classification (low, medium, high, critical) produced by the verification risk engine.
- "Human review" - assessment or confirmation of a decision by a trained person.
Implementation status / trigger / evidence / decision maker / outcomes / appeal. Not applicable (definitional).
4. AI Governance Principles
Purpose. To state the principles that constrain every AI system.
Scope. All AI-assisted moderation.
Implementation status. Implemented as operating principles.
Trigger. Not applicable.
Possible evidence. Not applicable.
Decision maker. Trust & Safety and AI-governance functions.
Possible outcomes. AI assists moderation and does not replace human judgment; AI outputs are evidence and recommendations, not final decisions; consequential decisions are subject to human review; a permanent ban is never issued solely by AI; human reviewers may override AI; confidence thresholds are configurable; and AI systems are continuously evaluated.
Appeal availability. All eligible decisions are appealable (§22).
5. Legal Framework
Purpose. To situate this Policy in law.
Scope. The legal regimes relevant to AI-assisted moderation.
Implementation status. Framework section.
Trigger. Not applicable.
Possible evidence. Not applicable.
Decision maker. Legal and AI-governance counsel.
Possible outcomes. This Policy is intended to operate consistently with applicable law, including the EU AI Act, the GDPR (including provisions on automated processing), and the Digital Services Act. We do not claim certification under any regime. [Legal review required before publication - confirm EU AI Act classification and obligations for the moderation systems described here.]
Appeal availability. Not applicable (framework).
6. AI Systems Used
Purpose. To identify the actual automated systems in use.
Scope. Moderation and verification systems.
Implementation status. Implemented; provider activation is configuration-dependent.
Trigger. Content upload, a verification flow, or a safety signal.
Possible evidence. Provider results, scores, labels, and risk bands.
Decision maker. The systems produce signals; people make consequential decisions (§9).
Possible outcomes. The systems in use are: photo moderation through a configurable, ordered provider chain (adapters for OpenAI moderation, AWS Rekognition, and Azure Content Safety), returning adult/sexual, violence, and minor-risk scores with labels and confidence; a verification risk engine producing a risk band; AWS Face Liveness and AWS Rekognition for photo verification; and Stripe Identity for identity verification. Which provider is active depends on configuration; where none is configured, automated photo moderation does not run. We do not use AI to moderate messages or profile text (an implementation gap).
Appeal availability. Decisions informed by these systems are appealable (§22).
7. Human Oversight
Purpose. To ensure people oversee and remain accountable for AI-assisted moderation.
Scope. All consequential moderation decisions.
Implementation status. Implemented (moderation queue, human review, human override).
Trigger. A case raised by an AI signal, a report, or an escalation.
Possible evidence. The signal, the content, and case history.
Decision maker. Trained reviewers in the Trust & Safety function.
Possible outcomes. Consequential decisions are made or confirmed by a person; automation may apply temporary, reversible measures pending review, but permanent removal requires human review (Account Suspension Policy, /legal/account-suspension). [Legal review required before publication - confirm human-oversight arrangements against EU AI Act requirements.]
Appeal availability. Yes (§22).
8. Automated Decision Support
Purpose. To explain how automation supports decisions.
Scope. Automated flagging, scoring, and provisional action.
Implementation status. Implemented for photos, verification, and risk.
Trigger. An upload, verification, or safety signal.
Possible evidence. Scores, labels, confidence, and risk bands.
Decision maker. Automation may flag, restrict a capability, require verification, or suspend pending review; it does not permanently ban.
Possible outcomes. A provisional action and a case for human review; the AI output is recorded as evidence, not a final decision.
Appeal availability. Yes (§22).
9. Human Decision Making
Purpose. To ensure people make final consequential decisions.
Scope. Permanent removals and other consequential outcomes.
Implementation status. Implemented (human-only bans; human confirmation of critical cases).
Trigger. A critical case or an action toward permanent removal.
Possible evidence. The AI output, the content, history, and any preserved material.
Decision maker. A trained human reviewer.
Possible outcomes. A confirmed, reasoned decision; a permanent ban requires this human step.
Appeal availability. Yes (§22).
10. Confidence Thresholds
Purpose. To explain how thresholds shape automated outcomes.
Scope. The photo-moderation decision engine and the risk engine.
Implementation status. Implemented and configurable.
Trigger. A provider score or risk signal.
Possible evidence. The score and the configured threshold.
Decision maker. Automation applies the configured thresholds; people tune them and review outcomes.
Possible outcomes. Scores at or above a threshold change the severity and the resulting action (for example, a minor-risk score at or above the configured level is treated as critical). Thresholds are configuration-driven and reviewed.
Appeal availability. Decisions are appealable (§22).
11. Risk Scoring
Purpose. To explain the privacy-preserving risk engine.
Scope. Verification and safety risk assessment.
Implementation status. Implemented.
Trigger. A verification flow or safety-relevant event.
Possible evidence. Normalised signals; the engine outputs only a band and signal names, and raw provider scores and biometric data never enter or leave it.
Decision maker. The engine bands risk; a critical band forces manual review; people decide consequential action.
Possible outcomes. A risk band that prioritises review and can gate automatic verification; it does not by itself permanently penalise an account (see the Trust & Safety Policy, /legal/trust-safety).
Appeal availability. Consequential decisions are appealable (§22).
12. Image Moderation
Purpose. To describe automated moderation of images.
Scope. Uploaded photos.
Implementation status. Implemented (provider-dependent); photos only.
Trigger. A photo upload.
Possible evidence. Provider scores (adult/sexual, violence, minor-risk), labels, confidence, and any face-detection signal.
Decision maker. Automation scores and can act provisionally; a person confirms consequential outcomes.
Possible outcomes. Content removal or restriction, a provisional account measure, and a case for human review. Self-harm is not a first-class enforced signal even where a provider surfaces a label (an implementation gap).
Appeal availability. Yes (§22).
13. Profile Moderation
Purpose. To describe moderation of profiles.
Scope. Profile photos and profile text.
Implementation status. Photos: implemented (as in §12). Profile text: not automatically moderated (an implementation gap).
Trigger. A photo upload, or a user report for profile text.
Possible evidence. Photo-moderation results; user reports for text.
Decision maker. Automation for photos; human review for reported text.
Possible outcomes. Photo removal or restriction; text handled through reports and human review under the Community Guidelines (/legal/community-guidelines).
Appeal availability. Yes (§22).
14. Identity Verification
Purpose. To describe automation in identity verification.
Scope. Members who undergo Identity Verification.
Implementation status. Implemented (Stripe Identity).
Trigger. A verification requirement or risk signal.
Possible evidence. The verification outcome and an opaque provider reference; no identity documents are stored (see the Identity Verification Policy, /legal/identity-verification).
Decision maker. Provided by Stripe Identity; Trust & Safety assesses outcomes.
Possible outcomes. A verified outcome, or restriction and review on failure.
Appeal availability. Yes (§22).
15. Photo Verification
Purpose. To describe automation in photo verification.
Scope. Members who undergo Photo Verification.
Implementation status. Implemented (AWS Face Liveness and AWS Rekognition).
Trigger. A verification requirement or risk signal.
Possible evidence. Liveness and comparison outcomes and an opaque provider reference; no images or biometric templates are retained (see the Photo Verification Policy, /legal/photo-verification, and Biometric Information Policy, /legal/biometric-data).
Decision maker. Provided by AWS; Trust & Safety assesses outcomes; the risk engine can force manual review.
Possible outcomes. A verified outcome, or review, restriction, or revocation on failure.
Appeal availability. Yes (§22).
16. Child Safety Detection
Purpose. To describe automated support for child-safety detection.
Scope. Photo moderation minor-risk signals.
Implementation status. Implemented (minor-risk scoring); no hash-matching.
Trigger. A photo upload producing a minor-risk signal, or an underage report.
Possible evidence. The minor-risk score or the report.
Decision maker. Automation flags and can act provisionally; a person confirms; the Child Safety Policy (/legal/child-safety) governs.
Possible outcomes. Critical prioritisation, provisional removal or suspension, and human review. There is no perceptual-hash or known-database matching, and no automated reporting to authorities (see the Child Safety Policy).
Appeal availability. Yes (§22), subject to the overriding duties in the Child Safety Policy (/legal/child-safety).
17. Fraud Detection
Purpose. To describe automated support for fraud detection.
Scope. Verification and safety risk.
Implementation status. Implemented (risk engine and signals).
Trigger. A verification or behavioural signal.
Possible evidence. Risk bands and normalised signals.
Decision maker. Automation bands risk; people decide consequential action.
Possible outcomes. Prioritised review, gating of verification, restriction, or suspension; permanent removal is human-only (Account Suspension Policy, /legal/account-suspension).
Appeal availability. Yes (§22).
18. Spam Detection
Purpose. To describe how spam is handled.
Scope. Spam and unwanted bulk activity.
Implementation status. No automated spam classifier (an implementation gap).
Trigger. A user report or rate-limit signal.
Possible evidence. Reports and, where relevant, rate-limit signals.
Decision maker. Human review of reports; rate limits apply automatically to protect the Service.
Possible outcomes. Restriction or removal on human review under the Community Guidelines (/legal/community-guidelines). [Legal review required before publication - confirm whether automated spam detection is expected.]
Appeal availability. Yes (§22).
19. Duplicate Detection
Purpose. To describe duplicate and evasion detection.
Scope. Duplicate and ban-evasion accounts.
Implementation status. Implemented as signal-based detection (not an AI classifier).
Trigger. Account creation or activity matching duplicate or evasion signals.
Possible evidence. Privacy-safe signals, including a salted device hash and a verified phone identifier; no fingerprinting; raw identifiers are not persisted (see the Privacy Policy, /legal/privacy).
Decision maker. Automated detection with human review for consequential action.
Possible outcomes. Consolidation or removal of duplicates, or action across linked accounts for evasion (Account Suspension Policy, /legal/account-suspension).
Appeal availability. Yes (§22).
20. False Positives
Purpose. To address incorrect automated flags.
Scope. Cases where automation flags content or an account in error.
Implementation status. Implemented (human review and appeals correct errors).
Trigger. An automated flag that a person or an appeal finds incorrect.
Possible evidence. The AI output and the review or appeal finding.
Decision maker. A human reviewer, and the appeal process (§22).
Possible outcomes. Reversal of the action and restoration, and adjustment of thresholds where a pattern emerges (§28).
Appeal availability. Yes (§22).
21. False Negatives
Purpose. To address harmful content that automation misses.
Scope. Cases automation does not catch.
Implementation status. Implemented (user reporting and human review provide a safety net).
Trigger. A user report or later detection.
Possible evidence. The report and review findings.
Decision maker. Human review.
Possible outcomes. Action on the missed content and, where a pattern emerges, threshold or provider review (§28). Tirvea does not guarantee detection of all harmful content.
Appeal availability. Affected members may appeal a resulting action (§22).
22. Appeals
Purpose. To provide a route to challenge an AI-assisted decision.
Scope. Eligible moderation and enforcement decisions.
Implementation status. Implemented (Appeals Policy).
Trigger. An action affecting the appellant.
Possible evidence. The appellant's grounds, assessed under the Appeals Policy (/legal/appeals).
Decision maker. A trained human reviewer; an appeal against an automated action is not decided solely by the same automated system.
Possible outcomes. The decision is upheld, reversed, or varied, with a statement of reasons and, where applicable, out-of-court dispute-settlement information, consistent with the Digital Services Act.
Appeal availability. This section is the appeal route; the process is in the Appeals Policy (/legal/appeals).
23. Human Override
Purpose. To confirm that people can override AI.
Scope. All AI outputs.
Implementation status. Implemented (human reviewers act through the queue and can overturn automated actions).
Trigger. A reviewer's assessment or a successful appeal.
Possible evidence. The reviewer's decision and reasons.
Decision maker. A trained human reviewer.
Possible outcomes. An AI recommendation or provisional action is confirmed, varied, or overturned; the human decision governs.
Appeal availability. Yes (§22).
24. Transparency
Purpose. To be transparent about AI-assisted decisions.
Scope. Statements of reasons and reporting.
Implementation status. Implemented (statements of reasons for significant actions; transparency reporting).
Trigger. A significant automated or AI-assisted action.
Possible evidence. The recorded decision, including whether automated means were used.
Decision maker. The Trust & Safety function.
Possible outcomes. A statement of reasons that discloses whether automated means were used and how to appeal, and reporting in the Transparency Report (/legal/transparency), consistent with the Digital Services Act.
Appeal availability. The statement of reasons explains how to appeal (§22).
25. User Rights
Purpose. To explain your rights in respect of automated processing.
Scope. Automated decisions involving personal data.
Implementation status. Implemented (human review, appeals, and data-subject rights).
Trigger. An automated decision affecting you.
Possible evidence. The decision and its basis.
Decision maker. The Trust & Safety and privacy functions.
Possible outcomes. Where a decision is based solely on automated processing and has legal or similarly significant effects, you have the rights described in the GDPR, including to obtain human intervention, express your view, and contest the decision (see the Privacy Policy, /legal/privacy, and GDPR & Your Rights, /legal/gdpr). You may also seek rectification of inaccurate data.
Appeal availability. Yes (§22).
26. Audit Logging
Purpose. To keep AI-assisted decisions traceable.
Scope. Moderation and verification events.
Implementation status. Implemented (append-only, PII-stripped records).
Trigger. An automated assessment or a moderation action.
Possible evidence. Not applicable (this section is about records).
Decision maker. The Trust & Safety function.
Possible outcomes. Automated assessments and actions are recorded in append-only records that are PII-stripped and hold no biometric data; human actions are attributed to a human actor. Records support appeals (§22), transparency (§24), and lawful requests, and are retained per the Data Retention Policy (/legal/data-retention).
Appeal availability. Records support the appeal process (§22).
27. Model Updates
Purpose. To explain how AI systems change.
Scope. Providers, thresholds, and configuration.
Implementation status. Implemented as configuration-driven change; version tracking is configuration-driven for verification and partial elsewhere.
Trigger. A provider, threshold, or configuration change.
Possible evidence. Configuration records and, for verification, versioned rollout controls.
Decision maker. The Trust & Safety and AI-governance functions.
Possible outcomes. Providers and thresholds may change to improve accuracy and safety; changes are controlled and reviewed. [Legal review required before publication - confirm technical-documentation and record-keeping requirements under the EU AI Act.]
Appeal availability. Not applicable (governance).
28. Accuracy Monitoring
Purpose. To keep automated moderation accurate.
Scope. Thresholds, providers, and outcomes.
Implementation status. Implemented in part (configurable thresholds, calibration for verification, appeal-outcome feedback); no formal automated accuracy dashboard across all systems.
Trigger. Ongoing review and appeal outcomes.
Possible evidence. Appeal outcomes, calibration data, and error patterns.
Decision maker. The Trust & Safety and AI-governance functions.
Possible outcomes. Threshold and provider adjustments to reduce error. [Legal review required before publication - confirm accuracy and robustness expectations under the EU AI Act.]
Appeal availability. Not applicable (governance).
29. Bias Monitoring
Purpose. To address fairness in automated moderation.
Scope. Provider outputs and thresholds.
Implementation status. No dedicated automated bias-monitoring pipeline (an implementation gap). Fairness is considered when selecting providers and setting thresholds.
Trigger. Review of outcomes or a concern raised.
Possible evidence. Outcome patterns and appeal data.
Decision maker. The AI-governance function.
Possible outcomes. Provider or threshold changes where fairness concerns arise. [Legal review required before publication - confirm fundamental-rights and bias-mitigation expectations under the EU AI Act.]
Appeal availability. Individual decisions are appealable (§22).
30. Security
Purpose. To protect AI systems and their data.
Scope. Moderation and verification systems.
Implementation status. Implemented (access controls, PII-stripped records, no retained biometric data).
Trigger. Not applicable.
Possible evidence. Not applicable.
Decision maker. The Security function.
Possible outcomes. AI systems and their records are protected under the Security Policy (/legal/security); provider keys and configuration are access-controlled.
Appeal availability. Not applicable.
31. Data Protection
Purpose. To govern personal data in AI-assisted moderation.
Scope. Personal data processed by moderation and verification systems.
Implementation status. Implemented (data minimisation; PII-stripped records; opaque verification references).
Trigger. An automated assessment.
Possible evidence. Not applicable.
Decision maker. The privacy function.
Possible outcomes. Processing is described in the Privacy Policy (/legal/privacy), retention follows the Data Retention Policy (/legal/data-retention), and biometric processing is governed by the Biometric Information Policy (/legal/biometric-data). We do not redefine retention periods here.
Appeal availability. Data-subject rights apply (§25).
32. Incident Response
Purpose. To respond to failures or incidents in AI systems.
Scope. Provider outages, misclassification incidents, and security events.
Implementation status. Implemented in part (provider fallback chain; configuration-driven kill switches for verification).
Trigger. A provider failure, an incident, or a safety concern.
Possible evidence. System signals and incident findings.
Decision maker. The Trust & Safety and Security functions.
Possible outcomes. Failover to another provider, disabling of an affected system by configuration, and reliance on user reporting and human review while a system is degraded (§33). Security incidents follow the Security Policy (/legal/security).
Appeal availability. Affected decisions are appealable (§22).
33. AI System Failures
Purpose. To explain what happens when automation is unavailable or wrong.
Scope. Degraded or failed AI systems.
Implementation status. Implemented (fallback and human review).
Trigger. A provider outage, no configured provider, or systematic error.
Possible evidence. System signals and error patterns.
Decision maker. The Trust & Safety function.
Possible outcomes. Where automated moderation is unavailable, content relies on user reporting and human review; safety is not solely dependent on automation. Automation being unavailable does not remove a member's obligations or the human enforcement processes.
Appeal availability. Yes (§22).
34. Third-Party AI Services
Purpose. To identify the third-party services used.
Scope. External providers of moderation and verification.
Implementation status. Implemented; activation is configuration-dependent.
Trigger. Content upload or a verification flow.
Possible evidence. Provider results and opaque references.
Decision maker. Providers return results; people make consequential decisions.
Possible outcomes. The services with adapters in the platform are OpenAI moderation, AWS Rekognition and AWS Face Liveness, Stripe Identity, and Azure Content Safety. Each acts as a processor under written data-processing terms (see the Privacy Policy, /legal/privacy). We do not list a service as active unless it is configured. We do not use any provider not implemented in the platform.
Appeal availability. Decisions informed by these services are appealable (§22).
35. Policy Updates
Purpose. To explain how this Policy changes.
Scope. This AI Moderation Policy.
Implementation status. Governance section.
Trigger. Changes in the systems, our practices, or the law.
Possible evidence. Not applicable.
Decision maker. WiseWave Limited, with AI-governance and legal counsel.
Possible outcomes. We update the "Last Updated" date and, for material changes, take reasonable steps to communicate them.
Appeal availability. Not applicable.
36. Contact
Purpose. To tell you how to reach us about AI-assisted moderation.
Scope. AI-moderation contact.
Implementation status. Not applicable.
Trigger. Not applicable.
Possible evidence. Not applicable.
Decision maker. Not applicable.
Possible outcomes. To appeal a decision, follow the Appeals Policy (/legal/appeals). For other enquiries:
- Operator: WiseWave Limited (Company Number 762171)
- Registered office: 39 Cooley Park, Dundalk, Co. Louth, A91 AP2V, Ireland
- Email: info@tirvea.com
For how moderation and safety operate, see the Trust & Safety Policy (/legal/trust-safety); for data rights, GDPR & Your Rights (/legal/gdpr).
Appeal availability. Appeals are handled under the Appeals Policy (/legal/appeals).