Current capability
No model or provider is active and the preview accepts no generation requests or uploads. This avoids exposing user content before the operating controls below exist.
User rights and reference images
Users must have the right to submit any prompt or reference image. Real-person images require approved consent, age, privacy, publicity, impersonation, and abuse rules before support can be enabled.
Safety controls
The launch implementation must validate inputs, apply rate and abuse controls before paid provider work, enforce the reviewed moderation policy, use timeouts and bounded retries, and show controlled feedback without exposing provider payloads or raw errors.
Data minimization
Prompts, uploads, outputs, email addresses, personal data, provider payloads, and raw stack traces must not enter product analytics. Temporary content requires a defined purpose, retention period, deletion path, failure cleanup, and access boundary.
Provenance and limitations
Watermark and provenance behavior must be verified for the selected provider and model. Generated images require human review for factual errors, visual defects, unwanted resemblance, unsafe details, and intellectual-property risks.
Reporting and appeals
A verified reporting channel, response ownership, escalation path, and appeal process must exist before public generation launches.