Platform Rules — Content-Safety Taxonomy
This document is the operative content-safety catalog referenced by the Acceptable Use Policy in the "Terms of Service & Acceptable Use". The catalog below is version 1.1 of the platform's content-safety taxonomy (the taxonomy carries its own version, stated here so this document and the check that enforces it can be tied together). It is enforced by three moderation tools, each described as it actually operates:
- an automated, taxonomy-aware safety check classifies every build request against the catalog below before any app is built;
- where an app is proposed for public hosting, a different, second check runs: a static artifact-safety scan of the built app — looking for credential-harvesting forms, brand-clone submit targets, and obfuscated exfiltration endpoints — together with a block on any unresolved human-review flag raised by the build-time check (the taxonomy classifier itself runs at build request; it is not re-run at hosting time);
- the platform re-scans every stored hosted app bundle daily with the same artifact-safety scan and records the verdicts, so a hosted app is not checked once and forgotten.
RunMyB both builds apps from your request and hosts the public ones on a shared domain. To keep the platform and its users safe, every request is classified against the three-tier taxonomy below. The classifier judges what the app does, not merely what topic it mentions: an app that is about a hard topic in a legitimate way (recovery support, security education, journalism) is treated very differently from one that promotes or enables harm. The platform is designed so that when the check cannot tell, the request routes to a human reviewer rather than being auto-refused — that is the design posture the review flags implement, not a warranty that no borderline case will ever be refused.
Enforcement is graduated (a refusal to run, an unpublish, an account suspension, or termination), proportionate to the violation and any recurrence. Where we restrict a publicly-hosted app we provide a statement of reasons consistent with DSA Article 17, and you may appeal (see the "Notice-and-Action & Contact Points (DSA)" policy).
Tier A — Prohibited (always refused)
These are never permitted on RunMyB, and this tier is not configurable. A request that promotes or enables any of the following is refused with a reason:
csam— Child sexual abuse material: any sexual content involving minors, including AI-generated, fictional, or "nudifier" output.ncii— Non-consensual intimate imagery / nudify: intimate imagery of a real person without consent, including AI "undress"/nudify tools.terrorism— Terrorism & violent extremism: content that promotes, facilitates, or provides operational support for terrorism or violent extremism.weapons— Weapons design / procurement (incl. CBRN): design, procurement, or synthesis instructions for weapons, explosives, or chemical/biological/radiological/nuclear agents.malware— Malware & hacking tools: malicious software, exploits, or intrusion tooling built to compromise systems without authorization.phishing_fraud— Phishing / credential-harvesting / brand-impersonation / scam: credential-harvesting pages, brand-impersonation clones, fake-login sites, and fake-investment / crypto-drainer / scam schemes.child_endangerment— Child endangerment: content that grooms, exploits, sexualizes, or endangers minors (beyond CSAM itself).ai_act_prohibited— EU AI-Act Article 5 prohibited practices: manipulative or vulnerability-exploiting systems, social scoring, prohibited biometric categorization / emotion recognition, facial-scraping databases, and prohibited real-time biometric identification.
Tier B — Adult / Restricted (refused at this stage)
These are restricted and refused at the platform's current stage. The strictness of individual Tier-B categories may be adjusted by RunMyB over time (for example, a future age-gated tier); Tier A is never adjustable.
pornography— Pornography / explicit sexual content: adult pornographic or sexually explicit content (of adults).regulated_vertical— Regulated verticals: gambling, pharmaceutical sales, and unlicensed financial / medical / legal advice services.
Tier C — Flag for human review
These are sensitive topics that are frequently legitimate — the app is about the topic rather than promoting harm. Such a build may proceed, but a human reviewer at RunMyB reviews it before it can be published to the public showcase.
sensitive_support— Sensitive-topic support / education / harm-reduction: recovery or self-harm support, harm-reduction, security education, or journalism about hate/violence.ip_adjacent— IP / trademark-adjacent: content that sits close to a third party's intellectual property or trademark (not a one-to-one clone).sensitive_personal_data— Sensitive-personal-data collection: apps that collect special-category or otherwise sensitive personal data at scale.spam_or_inauthentic_behavior— Spam / coordinated inauthentic behavior: apps or content built to manipulate platforms or feign authenticity — bulk unsolicited messaging, engagement-farming or fake-review schemes, astroturfing, bot-amplification networks. Composing ordinary marketing or social-media content for your own venture is not this category; the flag is manipulation or feigned-authenticity intent.undisclosed_advertising— Undisclosed advertising / hidden sponsorship: marketing content designed to hide that it is paid — sponsored or affiliate material presented as organic opinion, undisclosed paid endorsements. Clearly-labelled advertising and ordinary promotional copy are not this category; the flag is the deception (hiding the commercial relationship).
Ratings and earnings claims
Two conduct rules that apply on the platform's own surfaces, beside the app-content taxonomy above:
- Fake ratings and reviews. Submitting, commissioning, or incentivising fake ratings or reviews anywhere on the platform's surfaces — including the public catalogue — is a violation of these rules.
- Deceptive earnings claims. Deceptive earnings or income claims in content published on platform surfaces are a violation of these rules.
Business models the platform does not carry
Separate from the harm taxonomy above — which classifies content — the platform declines to carry certain business models at all, whatever their content rating:
- pyramid or multi-level-marketing recruitment schemes;
- "lifetime access" or perpetual-delivery promises sold to end users;
- ticket-resale automation;
- timeshare-exit services;
- debt-relief, lending, and unregistered financial services;
- identity-document services;
- unauthorised streaming or piracy resale.
Stated honestly, this list is enforced where a human looks: it is assessed at admission and at the human go-live review, and a hosted product found to operate one of these models may be unpublished under the enforcement section of the "Terms of Service & Acceptable Use". If you are unsure whether your business model is one of these, ask first: write to support@runmyb.com describing the model, and you will receive a recorded answer you can rely on.
Child safety
Where apparent child sexual abuse material is discovered in hosted content, RunMyB preserves the material and the associated records and reports to the National Center for Missing & Exploited Children (NCMEC) as US law (18 U.S.C. § 2258A) requires — the same commitment the "Terms of Service & Acceptable Use" states, repeated here because this catalog is where the prohibition lives.
Appeals
If your request is refused or flagged, you may appeal: send the decision reference (or a description of the decision) and why you disagree to support@runmyb.com, or use the contact points described in the "Notice-and-Action & Contact Points (DSA)" policy. An appeal is reviewed afresh by a human — never adjudicated by the automated check that produced the decision — and we aim to respond within 14 days. Nothing here waives our right to act immediately where the law requires it or where there is an imminent risk of serious harm.
Changes
This document is published, dated, and versioned; changes take effect on posting, with the version number, effective date, and changelog as the notice.
Version history (the document's changelog)
1.0 — initial draft edition; the enforcement taxonomy referenced by the Terms AUP. 1.1 — added the Tier-C spam/coordinated-inauthentic-behavior and undisclosed-advertising categories (the social-content module, 0432/E4). 2.0 — final edition: the draft banner removed and replaced with a neutral operative-catalog sentence; the taxonomy content unchanged (0529/E5). 2.1 — accuracy and completeness (effective on posting): the enforcement description corrected to say truthfully what runs where (the taxonomy classifier at build request; a static artifact-safety scan plus a human-review-flag block at the public-hosting flip; a daily re-scan of stored hosted bundles, disclosed as a moderation tool); the human-review sentence restated as the design posture it is; the taxonomy version stated (1.1) so the catalog and the check that enforces it are tied; new rules on fake ratings/reviews and deceptive earnings claims; a new section naming the business models the platform does not carry, with the ask-first route; the child-endangerment definition regains its beyond-CSAM qualifier so the categories do not overlap on their face; the appeal paragraph concretized (route, human review, response aim); the child-safety preservation-and-reporting sentence added (18 U.S.C. §2258A), matching the Terms.