ShuffleCrush

Moderation Policy

Last updated: June 5, 2026

ShuffleCrush is a one-to-one live video chat platform. Calls are peer-to-peer real-time streams: they are not recorded, not stored, and cannot be replayed by us or by anyone else. Moderation therefore operates on the layers we do control — who is allowed on the platform, what users can do during a live call, what happens the moment a report is filed, and what we do with the evidence afterwards. This policy describes those controls exactly as they are implemented in production.

1. No Recording, and What That Means for Moderation

ShuffleCrush does not record, store, transcode, or archive video or audio from any call. There is no recording infrastructure in the product. This is a deliberate privacy design decision and it is technically enforced: no server component receives a copy of a call stream for storage.

Because no recording exists, we do not claim to review call video after the fact. Instead, moderation is enforced through pre-call gating, in-call user controls, report-triggered investigation of the metadata and evidence we do hold, and account-level enforcement.

Separately from any after-the-fact review, authorised moderation personnel may observe a live session in real time where there is a safety, compliance or enforcement reason to do so. Real-time observation is limited to authorised moderation staff, requires the session to be selected explicitly, is logged in an internal moderation access log, and produces no recording: nothing from the observed session is captured, stored or replayed.

The evidence available to a moderator for a reported call consists of: the report itself (reason, free-text description, reporter, reported user, call identifier, timestamp), the session record for that call (participants, duration, join and leave events, device and network signals, disconnect reason), any text chat exchanged during that call, and the full enforcement history of both accounts.

2. Who Is Allowed on the Platform

Access is restricted to adults (18+). No one can appear on camera as a host without passing identity and age verification first.

  • every account must confirm it is 18 or older at registration;
  • hosts must additionally complete identity verification before they can ever be matched. A new host verification requires a declared legal name, a declared date of birth that is checked against the 18+ requirement, a supported government-issued photographic identity document — a passport, a national identity card, or a residence permit — and the live gesture evidence described below;
  • the live gesture evidence consists of images captured in the moment showing specific requested hand gestures, used to establish that a real, present adult is behind the account;
  • every submission is reviewed by an authorised human reviewer, not by an automated pass. The reviewer checks the declared identity details against the document and compares the portrait on the identity document with the live gesture evidence;
  • a submission cannot be approved while the required identity-document evidence is missing or incomplete; this is enforced by the platform itself, not only by the reviewer;
  • only approved hosts may participate as verified hosts. Unverified, pending or rejected accounts cannot be shown to other users as hosts;
  • hosts approved before the government-identity-document requirement was introduced remain approved under the rules in force at the time of their verification;
  • verification can be revoked at any time by a moderator. Revocation is a distinct, recorded enforcement state: the account is immediately taken offline, removed from matching, and cannot host again unless it is re-verified.

To be explicit about what this process is not: ShuffleCrush does not perform automated biometric or facial-recognition matching, does not query any government or third-party identity database, does not run automated document text extraction as a verification step, and does not use a third-party identity-verification provider. The comparison between the identity document and the live evidence is made by an authorised human reviewer.

Identity documents and live verification images are stored in restricted, non-public storage. They are never shown to other users, and are accessible only to authorised administrators and compliance personnel through short-lived, single-use links generated for a specific review.

3. Controls During a Live Call

Every user has immediate, one-tap safety controls available at all times during a call, without leaving the call or navigating away:

  • end or skip the call instantly, which terminates the stream on both sides;
  • mute their own microphone or disable their own camera;
  • report the other participant from inside the call, without ending it;
  • leave at any time — no user is ever required to stay in a call.

Filing a report always and automatically separates the two accounts. This is unconditional: the two users are permanently excluded from ever being matched with each other again by the matchmaking system. It is not an optional checkbox, and it does not depend on the outcome of the review.

4. Reporting and Human Review

Reports can be filed during a call or afterwards, and are categorised by reason (for example nudity or sexual content involving a non-consenting party, harassment, threats, scams, underage suspicion, or illegal content). Users may add a free-text description.

Every report enters a moderation queue and is reviewed by a human moderator. Automated analysis is used only to prioritise and to surface patterns across an account's history; it never issues an enforcement decision on its own.

  • reports flagging child safety or other illegal content are triaged ahead of all other work;
  • moderators see the full report, the session record, chat content from that call, and both accounts' complete enforcement history;
  • every moderator action is written to an immutable audit log identifying the moderator, the action, the reason, and the timestamp;
  • repeat reports against the same account escalate automatically to higher-severity review;
  • accessing a moderation case is itself logged, so review activity is auditable.

5. Enforcement Actions

Depending on severity and history, a moderator may:

  • record a warning on the account;
  • restrict specific capabilities, including removing an account from matching;
  • revoke host verification, taking the account off camera immediately;
  • suspend the account temporarily;
  • permanently ban the account and block re-registration signals associated with it;
  • withhold or reverse payouts associated with the conduct;
  • escalate to law enforcement or the relevant national hotline.

Enforcement is applied to the account, not merely to a single call, because we cannot re-watch a call. Patterns of reports are therefore weighted heavily.

6. Illegal Content and Child Safety

Child sexual abuse material, any sexual content involving a minor, non-consensual content, coercion or trafficking indicators, and violent or terrorist content are absolutely prohibited and result in immediate permanent removal.

Any report or moderator observation of this kind is entered into a dedicated illegal-content escalation register, separate from ordinary moderation. For each escalation we record the category, the accounts involved, the originating report, the reviewing moderator, the action taken, whether an authority or hotline was notified, the name of that authority, and any reference number they returned.

Opening an escalation automatically places a preservation hold on all associated evidence. Records under preservation hold are exempt from every automated retention purge and cannot be deleted by routine data lifecycle jobs; they are retained until the hold is explicitly released by a moderator after the matter is concluded.

We cooperate with law enforcement and with national reporting hotlines, and will preserve and disclose the evidence described in section 1 in response to a valid legal request.

7. Evidence Retention

Moderation records are retained under a published retention schedule that is enforced automatically by a scheduled daily job, not manually. The schedule distinguishes between record types: enforcement decisions and audit logs are retained longer than transient technical session data, and in-call chat content is purged on a short cycle.

Host verification evidence is handled separately from moderation records. Raw evidence — the identity-document images and the live gesture images — is kept only while it is legitimately required for the active verification and compliance relationship, and is separated from the minimal verification metadata we keep for longer. That metadata is limited to the submission reference, the verification result, the document type, the review timestamp, the reviewer or audit reference, and the retention or hold state of the record. We do not keep document image contents, full document numbers, extracted document text, or reusable access links beyond that point.

Raw verification evidence is scheduled for deletion under one central, server-side retention configuration. At the time of publication the applicable retention period has not yet been finally determined with our legal advisers and payment processors, and automated deletion of production evidence is therefore deliberately switched off rather than run against an arbitrary period. Once the period is set, deletion runs automatically from that single configuration point.

Two exceptions override every schedule: records under a preservation hold from an illegal-content escalation, and records under a documented legal or compliance hold — a regulatory or legal request, a fraud investigation, a chargeback or dispute, or a complaint or investigation. A hold is opened only for a specific documented reason, never by default for every account. While a hold is open, the evidence it covers is exempt from automated deletion and is also preserved if the account itself is deleted; the rest of that account's data is still deleted or anonymised as normal.

Because no call video or audio exists, none is retained.

8. Appeals

Any user subject to a suspension, ban, or verification revocation can see the decision and its reason in their account, and can submit an appeal from within the product.

Appeals are reviewed by a human moderator, and the outcome, the reviewing moderator, and the reasoning are recorded. Where an appeal succeeds, the enforcement action is reversed and the reversal is logged.

Moderation decisions are final once the appeal process is exhausted, where permitted by law. Nothing in this policy limits your statutory rights, including your rights under the GDPR.

9. Contact

Safety, abuse, and illegal-content reports: support@shufflecrush.com. Reports concerning child safety or an immediate risk of harm are prioritised over all other correspondence.