DRAFT FOR A LAWYER TO REVIEW. Not final legal advice. This document deals with one of the genuinely unresolved questions in the whole build — read the "18 U.S.C. §2257" section below carefully before treating anything here as a compliance position.
Record-Keeping Policy
What we keep, and why
- Moderation logs. Every
/moderatedecision — verdict, category, which classifier made the call, and a timestamp — is written to an append-only log (moderation_log, schema owned by our accounts/queue service, written by our Trust & Safety service; see PLAN.md §4). Nothing in this log can be edited or deleted after writing. This exists because a moderation system a regulator or a payment-processor underwriter can't audit isn't one they have any reason to trust — see our Trust & Safety page. - Age-verification records. Where a jurisdiction legally requires age verification (UK, Texas, per our Age Verification Policy), we keep a record of the method used and the result, not the underlying ID document beyond what our verification provider's integration requires. The UK's Online Safety Act specifically requires a written record of the age-assurance method used, plus a published summary — we maintain both.
- Prompt and account records. Retained per our Privacy Policy.
18 U.S.C. §2257 — genuinely unsettled, and we're saying so rather than guessing
US federal law (18 U.S.C. §2257 and §2257A) requires producers of actual sexually explicit content depicting actual human beings to keep age-and-identity records for every performer and to label the content with where those records are kept. LAGOON's mature lane, where it exists, generates content from AI models — there is no human performer being filmed.
Whether §2257 applies to purely synthetic, AI-generated sexual content with no real human performer is an open legal question that has not been authoritatively resolved as of this research pass, and this document is not going to assert a comfortable answer it can't back up. The statute's text is built around "actual sexually explicit conduct" performed by an identifiable person whose age needs verifying — a category AI generation with no real performer arguably falls outside of by its own terms, but "arguably" is not the same as "confirmed," and no independent verification of current case law, FTC guidance, or Justice Department enforcement posture on this specific question was performed in the research this build is based on. This is a launch-relevant open item for a lawyer, not a settled position — flag it for counsel explicitly rather than letting it default to either "clearly doesn't apply" or "clearly does."
What we do regardless of how that question resolves: our deny list's undisclosed_deepfake
and ncii categories already require, respectively, disclosure and consent whenever a real,
identifiable person is depicted — so the scenario §2257 is actually worried about (an
unverifiable real person in sexual content) is independently restricted by our own policy,
whatever the §2257 answer turns out to be.
Retention periods
Not yet finalized. Moderation logs, age-verification records, and account data each need a specific retention period set with input from counsel — balancing the underwriting and safety value of a longer record against data-minimization obligations under GDPR/FADP (see Privacy Policy). This section will state exact periods once set.
Who can request records
Law enforcement, with appropriate legal process, and the safety partners named on our Trust & Safety page for the specific reports we file with them (NCMEC, once registered). We do not provide moderation-log access to anyone else, including the account holder whose prompt generated a given log entry, beyond what our Privacy Policy's access-rights section covers.