The trust and safety model behind Seldeo
The three pillars
Every Trust & Safety model rests on three pillars:
- Prevention — the rules and product controls that make it harder for abuse to happen in the first place.
- Response — the reporting, review, and enforcement flow that runs when abuse does happen.
- Recourse — the appeal path for users who believe an enforcement action against them was wrong.
Seldeo's model is deliberately open about all three. This post is the plain-language walk-through.
Prevention: the rules and the product
The user-facing rules live in the Community Guidelines. At a high level, they cover:
- Harassment and personal safety. No targeted abuse, no doxxing, no coordinated pile-ons.
- Hate. No content that dehumanises people on the basis of who they are.
- Sexual exploitation. Zero-tolerance for the exploitation of minors, and a strict set of controls on adult content even where legal.
- Violence. No credible threats of violence, and specific limits on graphic content.
- Self-harm. Careful handling — support pathways for people in crisis, without stigmatising or celebrating self-harm.
- Deception. No impersonation, no coordinated inauthentic behaviour, no synthetic media that misleads.
- Regulated goods. No sale of firearms, drugs, or other restricted items through Seldeo's messaging or posts.
Alongside the rules, the product itself is designed to reduce the surface area for abuse:
- Direct messages from non-friends are rate-limited and require an invitation acceptance before follow-up messages are delivered.
- Under-18 accounts default to strong privacy: no DMs from outside the friends list, no discovery beyond friends-of-friends.
- Posting to Public requires an explicit tap; the default audience is Friends.
- Circle names are private to the account owner.
Prevention is not glamorous. But every abuse case that doesn't happen is one that doesn't require a report, a review, and an enforcement action.
Response: the report
When something goes wrong, the fix starts with a report. The report path is:
- Long-press the offending content (a post, a story, a comment, a message, a profile) and pick "Report."
- Choose a category — the categories map to the Community Guidelines sections above. Choosing the right category speeds up review; if you're not sure, "Something else" is always available.
- Add optional context. A sentence or two describing why this is a problem for you or someone you know.
- Submit. The report is queued.
Behind the scenes, when you report a message (which is end-to-end encrypted), your device also uploads the plaintext of the specific reported message and its immediate context to a review-only decryption channel. Nothing else in the thread is shared. For posts, stories, and comments, the material is already visible to us — there is no additional disclosure.
Response: the review
Reviews are queued to a human review team. We use automated tooling as a triage layer: reports about content that clearly and objectively violates the rules (e.g. CSAM that's caught by an established hash) get pushed to the top of the queue and, in the case of established hash-match categories, actioned automatically pending post-hoc human audit.
Everything else — the vast majority of reports — is reviewed by a person. The reviewer:
- Reads the report and the context provided.
- Reviews the reported content against the Community Guidelines.
- Decides: no violation, minor violation, or serious violation.
- If a violation is found, chooses an enforcement action: content removal, temporary posting restriction, account suspension, or permanent termination.
- Documents the reasoning.
The review team includes members with regional language expertise and members with topical expertise (child safety, domestic-violence context, hate content). Reviews for high-severity categories are double-reviewed before enforcement.
Response: the enforcement action
Actions we take:
- Content removal. The specific piece of content comes down. The account gets an in-app notice with the excerpt removed and the category cited.
- Feature restriction. For repeated moderate violations, the account temporarily loses the ability to post publicly, send DMs to non-friends, or use specific product surfaces.
- Suspension. The account is signed out and cannot sign back in for a defined period (typically 7 or 30 days).
- Termination. The account is closed. Termination for serious violations (CSAM, credible violent threats, coordinated harm) is permanent and appended to our internal ban record.
Every enforcement action generates a notification to the account holder with:
- The rule that was found to have been violated.
- The specific content or behaviour cited (with excerpt where the content itself has been removed, so the user knows what the action was about).
- The action taken.
- The appeal path.
Recourse: the appeal
Every enforcement action is appealable. The appeal:
- Goes to a different reviewer than the one who made the original decision, in a different region where possible.
- Reviews the same evidence with fresh eyes, plus any additional context the user provides.
- Confirms, reduces, or reverses the original action.
- Reverses cleanly. A reversed content removal restores the post to its original position with its comments and reactions intact. A reversed suspension restores the account to the state it was in at suspension.
Appeal decisions are final at Seldeo. If a user disagrees with the appeal outcome, they have the standard external recourses: dispute resolution under the Terms, and, in the EU, the specific Digital Services Act out-of-court dispute settlement pathways (see the EU trader information page).
What we don't do
- We do not scan the plaintext of end-to-end encrypted messages in aggregate. Message content is only reviewed when a party to the conversation reports a specific message.
- We do not use enforcement history as a background input to feed ranking. A user whose posts have been enforced in the past does not have their non-violating posts quietly de-ranked. Enforcement is per-piece-of-content or per-account-state; it does not manifest as invisible shadow-ranking.
- We do not sell moderation data. Reports, review outcomes, and enforcement records are never provided to third parties for research or commercial use.
The numbers we publish
The Transparency Report is published semi-annually and includes:
- Total reports received, by category.
- Content removal counts, by category.
- Account suspension and termination counts.
- Appeal volume and appeal-reversal rate.
- Law-enforcement requests received (US and non-US), with per-category breakdowns.
- Median time from report to first review action.
- Median time from suspension to appeal resolution.
The first Seldeo Transparency Report will land in early 2027. The template it will follow — down to specific category and jurisdiction — is already public on the Transparency page.
Working with law enforcement
The Law Enforcement Guidelines page is the operational reference for police, prosecutors, and government authorities requesting user data. In summary:
- We require valid legal process for content data. In the US, a warrant issued under 18 U.S.C. § 2703(d) for stored content, or an equivalent process outside the US.
- We honour emergency-disclosure requests in genuine imminent-harm scenarios, with a strict internal review gate.
- We provide the user with notice of a legal-process disclosure unless we are legally prohibited from doing so or the disclosure would create a specific risk of harm.
- We publish the aggregate legal-process numbers in the Transparency Report.
Working with us
If you have a specific safety concern that doesn't fit the in-app reporting flow, the human contact addresses are:
- General safety: safety@seldeo.com
- Time-sensitive threats: urgent@seldeo.com
- Child safety (NCMEC & equivalent): child-safety@seldeo.com
- Journalists and researchers: transparency@seldeo.com
We answer those addresses every day, including weekends, because harm doesn't wait for a Tuesday.
The line we don't cross
Trust & Safety is a place where the temptation to opacity is strong. Every operational detail has some rationale for staying private. But taken together, opacity is exactly what lets platforms drift away from the promises they made when they were small.
We publish this framework in advance so that if we ever drift from it, someone can hold up the receipt.
