Safety & Moderation
Last updated: July 24, 2026
This page is a plain-language account of what Arkwork actually does to keep the service safe and respectful — including where the real, honest limits of that are. We'd rather tell you exactly what exists than imply protections that aren't there.
Automated Safety
Arkwork uses automated moderation to review uploaded images and text before AI generation. These systems help detect content that violates our Community Guidelines before content is generated.
AI processing
Three separate AI calls can happen per submission, all via OpenAI: a moderation check (below), the card image itself, and the suggested social caption. Generation is built from instructions that explicitly forbid inventing achievements, titles, or facts about the recipient beyond what you wrote, and that direct the model to stay respectful regardless of the recipient's gender, race, nationality, religion, politics, family situation, health, or age. See AI Disclosure for more.
Moderation
Every submission is checked before a card is generated — this isn't a manual or after-the-fact process for the checks below; it runs automatically, in real time, on every request:
- Photo moderation — if you attach a photo, it's screened by OpenAI's moderation model before it ever reaches image generation. A flagged photo is refused outright; it is never used, and never becomes a card.
- Text moderation — your recipient's name, role, any extra context, and your appreciation message are each screened for hate, harassment, sexual content, violence, self-harm, and illicit-activity categories. Anything flagged is refused.
- Tone review — your appreciation message specifically gets a second pass: if it's mildly negative, backhanded, or lukewarm but honestly salvageable, it may be automatically rewritten into something encouraging, using only what you actually wrote — never inventing anything new. If it can't honestly be reframed as a celebration (insults, bullying, defamation, harassment, and similar), it's refused rather than rewritten.
Because your appreciation message can be automatically rewritten for tone, the exact wording on the finished card may differ slightly from what you typed — the underlying facts and the person you're celebrating never change, only the framing.
A known limitation, stated plainly
OpenAI's moderation model's specific child-sexual-content classification only applies to text, not images — it is not a dedicated, specialized child-exploitation-imagery detector for photos. Generically sexual imagery is still caught by the general “sexual content” category regardless of the subject's apparent age, and any flagged photo is refused outright with no further processing — but this pipeline does not claim to provide the specialized, hash-matching detection (e.g. PhotoDNA/NCMEC) that a dedicated child-safety system would use. We are transparent about this rather than implying a protection that isn't there.
Content rejection
A card generation request is rejected before it ever reaches image generation if:
- The recipient's name or your appreciation text fails a basic quality check (too short, mostly numbers or punctuation, keyboard-mashed, or excessively repetitive) — this catches spam and gibberish, separately from moderation.
- A photo is attached without confirming you have permission to use it.
- The moderation checks above flag your photo or any text field, and — for the appreciation message specifically — it isn't honestly salvageable as a positive rewrite.
- The request fails Cloudflare's bot-verification check, or you've exceeded the rate limit for free generations.
If the moderation service itself is unreachable or fails (a network error, for example), your request is rejected too, with a message asking you to try again — we never treat “couldn't check” as “safe.”
Privacy sanitisation
Uploaded photos have their metadata — including embedded GPS/location data — stripped, and their orientation normalized, before they're moderated, used for generation, or stored even temporarily.
Retention
- Free previews and purchased HD images: deleted automatically after about 6 hours.
- Public shares ("Celebrate Publicly"): deleted automatically after about 14 days, or immediately if you revoke your own share.
- Nothing is kept indefinitely by default — a card only outlives the 6-hour window if you deliberately choose to make it public.
Public sharing
“Celebrate Publicly” is opt-in and off by default. It publishes the already-moderated preview-quality image, the recipient's name, and your appreciation text to an unlisted page anyone with the link can view — never the full-resolution HD image, and never anything identifying you, the sender. Moderation happens once, at generation time — going public doesn't re-run it, since the content is already the same content that was checked.
Continuous Improvement
While we employ industry-standard safeguards, no automated moderation system is perfect. We continuously review and improve our safety measures and investigate reports submitted by our community.
If you believe content should not appear on Arkwork, please report it so our team can review it.
Reporting
Every public card includes a “Report this card” link. To report a card — public or otherwise — use that link, or email privacy@arkwork.co with the link or as much detail as you have. A person reviews every report we receive — automated moderation can't catch every edge case, including whether a submission was uploaded by someone with the right to share it.
Request Removal
Selecting “Report this card” on any public share opens a pre-filled email to privacy@arkwork.co referencing that card, so we can find it quickly.
If you shared a card yourself, it's already deleted automatically within 14 days, and you can request removal sooner at any time. If you're requesting removal of someone else's public share, we'll review it against our Community Guidelines — removal isn't automatic or instant, since it goes through a person, not a system.
Questions
Reach us at privacy@arkwork.co with anything this page doesn't answer.