Contents
1. Age Restriction & Access Control
Troy Circle is an 18+ platform exclusively. Approved membership is not open to the public — every prospective member must submit an application that is reviewed manually by Troy Circle staff before approved member access is granted.
Minors are strictly prohibited. No person under the age of 18 may submit a membership application, receive approved member access, or use Troy Circle's member features. A preliminary authentication account may be created before date of birth is collected. The supported application flow requires a date of birth and rejects an underage applicant; Firestore rejects an under-18 date when one is supplied, while manual review must catch missing or inconsistent information. An account discovered to belong to a minor is subject to termination.
Our age enforcement measures include:
- The supported access-application flow requires a date-of-birth declaration, checks it in the client, and submits it to Firestore age rules
- Manual review of each application by Troy Circle staff prior to approval
- Immediate and permanent account termination upon discovery that a user is or was a minor at time of registration
- Firestore rules reject a supplied under-18 date of birth in application and legacy public-profile writes (dateOfBirth + 568,036,800 seconds ≤ request timestamp), and reject an under-18 age value on the main profile; manual review remains necessary because preliminary account documents may exist before birth information is supplied
2. Prohibited Content & Conduct
The following are strictly prohibited on Troy Circle and constitute grounds for immediate account termination and mandatory reporting to law enforcement authorities:
- Any imagery, video, audio, or text that sexually depicts, exploits, or abuses minors (CSAM)
- Grooming — any communication designed to gain the trust of a minor for the purpose of sexual exploitation
- Solicitation — requesting or distributing CSAM in any form, including links to external sources
- Trafficking — content facilitating the sexual trafficking or commercial sexual exploitation of minors
- Sextortion — coercing minors into producing or sharing sexual content through threats
- Any attempt to circumvent age verification or access controls to engage with minors
There are no exceptions to these prohibitions. Artistic, educational, or fictional framing does not exempt content from this policy.
3. Legal Framework
Troy Circle operates in compliance with the following legal instruments:
European Union
- EU DSA 2022/2065 Digital Services Act — obligations for online platforms regarding illegal content, including CSAM, effective February 2024
- EU 2011/93 Directive on combating the sexual abuse and sexual exploitation of children and child pornography
- GDPR 2016/679 General Data Protection Regulation — special protections for data relating to minors
Spain
- CP Art. 183–189 Código Penal — delitos contra la libertad e indemnidad sexuales de menores
- LO 8/2021 Ley Orgánica de protección integral a la infancia y la adolescencia frente a la violencia (LOPIVI)
- LO 3/2018 Ley Orgánica de Protección de Datos Personales y garantía de derechos digitales (LOPDGDD)
- Ley 34/2002 Ley de Servicios de la Sociedad de la Información (LSSI)
International
- UNCRC 1989 United Nations Convention on the Rights of the Child
- Budapest Convention 2001 Council of Europe Convention on Cybercrime — Art. 9 (child pornography)
- Lanzarote Convention 2007 Council of Europe Convention on Protection of Children against Sexual Exploitation and Abuse
4. Technical & Organisational Measures
Troy Circle implements the following technical and organisational safeguards:
- Application-only membership — a person may register to submit an application, with or without an invitation, but cannot become an approved member without manual review; an invitation does not guarantee admission
- Layered age checks — date of birth is requested in the application flow, minimum-age constraints are applied in the client and Firestore rules, and staff review remains required; this is not identity-document verification
- Firebase App Check — platform attestation is enabled and protected Cloud Functions require a valid App Check token, reducing calls from unauthorised clients without claiming complete bot prevention
- Message encryption at rest — new chat-message text uses AES-256-GCM authenticated encryption before storage. It is not end-to-end encryption: authorised service and moderation workflows can decrypt message text when necessary
- FCM token isolation — push notification tokens stored in private subcollections, inaccessible to other users
- Scoped ephemeral-photo protection — while the one-time-photo viewer is active, Android uses FLAG_SECURE to block platform screenshots and screen recording. iOS has no public absolute screenshot-blocking API: the App covers active recording or mirroring, protects background snapshots, and closes the viewer after the system reports a screenshot
- Firestore security rules — users cannot read, write, or modify data outside their authorised scope
- Admin moderation panel — dedicated admin interface for reviewing reports, approving/rejecting applications, and adjusting user standing
- Moral Score system — behavioural scoring system that surfaces and penalises abusive conduct
5. Detection & Moderation
Troy Circle employs the following detection and moderation procedures:
- All new member applications are reviewed manually before access is granted — this is our primary prevention layer
- In-app reporting lets a user report another member from profile or chat contexts; the selected reason and optional note enter the restricted moderation queue
- Reports enter a restricted admin moderation queue; suspected-underage reports use a dedicated reason so staff can identify them
- Report records and related evidence are retained only as long as reasonably necessary for investigation, enforcement, legal claims, or a binding legal obligation; no fixed technical retention period is claimed
- Authorised administrators and moderators can suspend an account while a credible report is investigated
- When a report identifies two members and the investigation requires conversation context, authorised admins or moderators can use a restricted server-side tool to review decrypted message text for safety investigation
Proactive detection: Profile photos are checked by an automated image classifier before upload and again after storage as a safety net, including checks for a possible minor and prohibited nudity. Flagged photos can be blocked and routed to the moderation panel. This classifier is not a general-purpose CSAM hash-matching system and does not replace user reports or human review.
6. Mandatory Reporting Obligations
Upon identifying confirmed or credible suspected CSAM on the platform, Troy Circle will take the following actions without delay:
- Immediately remove the content and suspend the associated account
- Preserve relevant evidence (content, metadata, account data, and available service or security logs) as required by law
- Submit a report to the National Center for Missing & Exploited Children (NCMEC) CyberTipline at missingkids.org pursuant to 18 U.S.C. § 2258A
- Notify the Agencia Española de Protección de Datos (AEPD) where required under GDPR Art. 33
- Report to Spanish law enforcement — Brigada de Investigación Tecnológica (BIT) of the Policía Nacional or the Grupo de Delitos Telemáticos of the Guardia Civil
- Cooperate fully with Europol's European Cybercrime Centre (EC3) and Interpol upon request
- Submit reports to the INHOPE network hotline for Spain (Protégeles / CTIC) where applicable
No safe harbours. Troy Circle will not provide legal protection, confidentiality, or any form of cover to users who generate, share, or distribute CSAM. We will comply fully with all lawful requests from competent authorities.
7. User Reporting
Troy Circle lets users report another member from profile and chat contexts. Reports are profile-level and support the following reasons:
- Fake or impersonation profiles
- Inappropriate or illegal content
- Harassment or threatening behaviour
- Suspected underage users
- Suspected child-safety or exploitation concerns, described in the report note
Reports relating to child safety are escalated immediately and treated as the highest priority. Users who submit good-faith reports are protected from retaliation.
To report outside the app or for urgent concerns, contact us directly at hello@troycircle.app with subject line CHILD SAFETY REPORT.
8. Enforcement & Account Actions
Violations of this policy result in the following actions, which may be applied individually or in combination:
- Immediate account suspension — pending investigation of any credible report
- Permanent account termination — for confirmed violations, with no possibility of reinstatement
- Evidence preservation and mandatory reporting — as described in Section 6
- Referral to law enforcement — Troy Circle will proactively refer confirmed cases to the appropriate authorities without waiting for a formal request
Troy Circle does not offer appeals processes for violations of child safety policy. These decisions are final.
9. Law Enforcement Cooperation
Troy Circle will respond to lawful requests from competent authorities in Spain, the European Union, and internationally. This includes:
- Preservation and disclosure of account data, message metadata, and available service or security logs upon receipt of a valid legal order
- Emergency disclosure of data where there is an imminent risk to the life or safety of a child, without requiring a formal order
- Full cooperation with Europol, Interpol, and national law enforcement agencies in cross-border investigations
- Compliance with orders from the Fiscalía de Menores and Spanish judicial authorities
Law enforcement agencies may direct formal requests to: hello@troycircle.app
10. Contact & Responsible Disclosure
Child Safety Contact
For child safety reports, CSAM disclosures, law enforcement requests, or questions about this policy:
Email: hello@troycircle.app
Subject line: CHILD SAFETY REPORT
Child-safety reports are prioritised according to their urgency and any applicable legal deadline. Response time depends on the facts, available evidence, and required coordination with competent authorities.