1. What Is Absolutely Prohibited
The following are prohibited on OnFire without exception. No context, artistic claim, or stated intent makes any of them acceptable, and there is no warning stage.
- Child sexual abuse material — any visual depiction of sexually explicit conduct involving a person under 18.
- Sexualised depictions of minors that are drawn, animated, computer-generated, or produced with AI. That the child is not real does not make this permitted.
- Editing or generating an image to place a real child in sexual content.
- Grooming — building a relationship with a child in order to sexually exploit them, including moving a conversation to another service for that purpose.
- Sexual extortion of a minor, including threatening to share images to obtain more.
- Soliciting, offering, trading, or advertising any of the above, including through coded language.
- Arranging or facilitating the trafficking or sexual exploitation of a child offline.
- Sexual or romantic approaches by an adult to a person they know or believe to be a minor.
Accounts responsible for any of the above are removed permanently.
AI-generated material is covered, and is becoming a prohibition on the tool itself. From 2 December 2026 the EU AI Act (Art 5(bb)) bans placing on the market, putting into service, or using an AI system that generates or manipulates child sexual abuse material. A companion prohibition (Art 5(ba)) bans generating realistic intimate imagery of an identifiable person without their explicit consent.
These are prohibitions on what a system is capable of, not disclosure duties. Meeting them requires controls on the generation pipeline itself, which is work we have ahead of us rather than behind us.
Some content involving children is not sexual but still causes harm — physical abuse, exploitation of a child's labour, or content identifying a child in a way that puts them at risk. This is also prohibited and can be reported the same way.
2. How to Report a Child at Risk
Where a working report option exists — feed posts, gallery photos, products shared in chat, and marketplace and rental listings and users — use it and choose the child or minor safety category. Reports in that category are flagged as suspected child exploitation in our systems and separated from ordinary content reports.
You cannot currently report a chat message, story, or profile in the app
Those surfaces have no working report route. On chat messages a control appears but does not submit anything. This matters more here than anywhere else on this page: private messaging is the principal grooming vector, and it is the surface where in-app reporting does not work.
If a child is at risk in a chat message, story, or profile, do not rely on the in-app report. Contact the police, report to the NCMEC CyberTipline or the IWF directly, and email [email protected] so that we have a record.
Please do not download, forward, or keep a copy of the material as evidence. Possessing it is itself a criminal offence in most countries, including where you are trying to help. Report it and leave it where it is; we can retrieve what is needed from our own systems.
You do not need to be certain. A report made in good faith that turns out to be mistaken is not held against you.
3. What Happens After a Report
When you submit a report in the child safety category, the report is recorded and flagged as suspected child exploitation, a copy of the reported content is captured so that it survives deletion, and the report is placed in a queue.
We cannot currently tell you what happens after that, because we cannot commit to it. We do not operate a staffed review desk, we do not guarantee that child safety reports are looked at ahead of other reports, and we do not commit to a time within which a report will be reviewed.
That is why the advice at the top of this page is to report to NCMEC, the IWF, or the police directly. Those organisations act on reports; at present we cannot promise that we will act on yours quickly. We would rather you knew that and used a faster route than trust a commitment we are not in a position to keep.
4. Our Legal Reporting Obligations
Where a provider obtains actual knowledge of apparent child sexual abuse material, US federal law (18 U.S.C. § 2258A) requires a report to the National Center for Missing & Exploited Children as soon as reasonably possible, and requires the associated material to be preserved. Comparable duties apply under UK and EU law. These duties are not discretionary and nothing in our other policies waives them.
We take those obligations seriously and will meet them where they are engaged.
To be straightforward with you: OnFire has not to date filed a report with NCMEC, and the automated reporting pathway in our systems is not yet operational. Where a report is required, it would currently be prepared and filed manually. We are working to bring the automated route into service.
5. Age on OnFire
Our Terms of Service set a minimum age of 13 (or the minimum age in your jurisdiction), 16 in the European Union unless a parent consents, and 18 for payments, marketplace and accommodation features. Users under 18 must have parental or guardian consent.
Those are contractual conditions, not verified facts. OnFire does not currently record a date of birth or an age for any account. No account on the service has one. We therefore do not know how old any individual user is, and nothing on OnFire should be read as an assurance that the person you are talking to is the age they claim.
The consequences follow directly, and we would rather state them than let the design imply otherwise:
- We cannot tell whether a given account belongs to an adult or a child.
- We cannot apply different settings, protections, or defaults to a minor's account, because we cannot identify one.
- We cannot exclude minors from any feature, including features intended for adults.
- We do not verify age.
A separate parental-consent process exists and has been used in a small number of cases; it is triggered by the jurisdiction inferred from a user's network location rather than by anyone declaring an age, so it does not identify minors generally. A further age check applies to specific regulated transactions such as vehicle rental, and is confined to those flows.
6. What We Detect, and What We Do Not
| Control | Status |
|---|---|
| User reporting with a dedicated child safety category | In operation |
| Content snapshot preserved at the time of report | In operation |
| Automated assessment of message and post text | Not currently running |
| Matching uploads against known-illegal image databases | Not in operation |
| Image or video classification on upload | Not in operation |
| Staffed review of reports and flagged content | Not in operation |
Where automated safety assessment does run, it covers text and audio only. Since child sexual abuse material is overwhelmingly an image and video problem, the detection that would matter most is the detection we do not currently have. Reporting is what finds this material on OnFire.
7. Visibility and Minors
There are no protections on OnFire specific to minors — no private-by-default accounts for under-18s, no restriction on adults contacting young users they are not connected to, no limits on discoverability, and no reduced engagement prompts. None of these can exist while no age is recorded, because there is no attribute to apply them to.
Posts and stories are readable by anyone on the internet. Content posted to the feed or to stories can be read without an OnFire account, and is returned together with the poster's first name, last name, username, profile photo and, where set, a location name.
There is no per-user privacy or visibility setting for posts or profiles — that control does not exist for anyone, adult or child. So a young person's posts, name, photograph and location are public on exactly the same terms as an adult's. Location sharing is the one exception: it is off unless switched on, and can be limited to contacts.
If that is not the visibility you want, the effective control today is to not post to the feed or to stories. We are treating the absence of a privacy default as a priority to fix.
8. Information for Parents and Carers
We would rather give you an accurate picture than a reassuring one, so that you can make your own decision.
OnFire is a general-purpose messaging and social application. It is not designed for children and has no children's mode. We do not know the age of our users, we do not verify age, and we do not apply any protection specific to minors. Messages are not end-to-end encrypted. There are no parental controls, no supervised accounts, and no facility for a parent to view or manage a child's account.
The point most likely to matter to you: anything your child posts to the feed or to stories can be read by anyone on the internet, without an OnFire account, together with their name, profile photograph and any location they have set. There is no privacy setting that changes this, for adults or for children. If that is not what you want for your child, the only effective control today is not using those features.
If you believe a child is using OnFire and you want the account removed, email [email protected]. To exercise data rights on a child's behalf, see the Privacy Policy.