Age-gating a generation product
If your product lets adults generate adult material, the generation API is the easy part. The hard parts are age assurance, consent, and a payment processor that agrees to keep processing. This guide is about those, in the order they will bite you.
- Binding constraint
- Payments
- Check first
- Processor
- Never optional
- Consent
Usually, not the law
Before you build
For real people
Start with the payment processor, not the feature
This is the inverted-order mistake that costs the most. Teams build the product, launch, take revenue, and then discover their processor classifies what they built as a prohibited business. The outcome is usually not a warning — it is termination, with a rolling reserve on funds already collected.
Mainstream processors generally place adult content on a prohibited or restricted list, and platforms that merely permit users to generate explicit material have been dropped on the same basis. Adult-specialist acquirers exist, cost more, and have their own compliance requirements. Read the list, and if your reading is optimistic, get it in writing before you build.
- Read your processor’s prohibited and restricted business list as a design input, not as legal boilerplate.
- Assume your public marketing is how you will be classified — the copy on your own site is the evidence a reviewer quotes.
- Have a second rail identified before you need it. Arranging one calmly is much cheaper than arranging one during a hold.
- Keep the entity carrying content risk separate from entities that do not, and take actual legal advice on the structure.
Age assurance is now a legal requirement, not a checkbox
The self-declared "I am 18" interstitial is no longer sufficient in a growing number of jurisdictions, several of which now require verifiable age assurance for adult material and attach real penalties. Which jurisdictions, and what counts as verification, changes constantly — treat this as something to check with counsel at launch and re-check on a schedule, not something to copy from a blog post.
- Decide whether you gate at signup, at first adult generation, or at payment. Gating late is friendlier and harder to get right.
- Prefer a specialist age-assurance vendor over building it. The failure modes are legal, not technical.
- Store the assurance result and its timestamp — not the identity document itself, unless you have a specific reason and a retention policy for it.
- Geo-detect and apply the stricter rule when a user’s location is ambiguous.
- Make the gate apply to shared and exported content too, not only to the logged-in view.
Consent for real people is the bright line
Identity features make this concrete rather than theoretical. Face ID generates from an uploaded photo and character training builds a likeness from a small photo set, and neither knows whether the person in those photos agreed to be there.
Sexual or otherwise harmful depictions of a real, identifiable person without their consent are prohibited by the Acceptable Use Policy, and in a growing number of jurisdictions they are also illegal. Non-consensual intimate imagery is the fastest route to losing your processor, your app store listing and your hosting, in roughly that order.
- Collect explicit consent at upload, recorded against the account and timestamped.
- Do not let users upload a third party’s photos into an adult pipeline. State it in your terms and enforce it on report.
- Give people a way to report a likeness of themselves without creating an account, and act on it fast.
- Set a retention window on uploaded reference photos and enforce it with a job, not a promise.
Label what you generate
The platform embeds no provenance metadata, so anything you want signalled you add yourself. Labelling is increasingly expected by regulators and app stores, and it is cheap to do at the point of export where you already control the pipeline.
- Mark generated media in your own UI so a user always knows what they are looking at.
- Consider embedding provenance metadata at export if your distribution channel reads it.
- Keep the generation record linkable from the asset, so a question about an image has an answer.
What the platform gives you to build on
The technical posture is simple and stable: prompts reach the model verbatim, outputs are not scanned, one minor-safety gate is enforced at the prompt and cannot be disabled, and moderation never takes automatic action against an account. Billing is a prepaid balance, so a runaway integration cannot run up a bill.
Outputs are deleted after 7 days. For an adult product that is a feature — it limits how much of your users’ material sits on someone else’s infrastructure — but it means anything your product displays later must be copied into storage you control and protect.
Frequently asked questions
- Can I build an adult product on this API?
- The API passes prompts through verbatim and does not scan output, so technically nothing stands in your way except the minor-safety prompt gate, which is absolute. Whether you may is a question for your jurisdiction, your app store and your payment processor — and the Acceptable Use Policy, which prohibits non-consensual likenesses and illegal content regardless of what the technology permits.
- Will my account be suspended for adult generations?
- No. Moderation here records an event; it does not suspend accounts, pause keys or issue strikes automatically. Enforcement is a human decision taken on report, and it is about the Acceptable Use Policy rather than about explicitness.
- Is a self-declared age checkbox enough?
- Increasingly not. Several jurisdictions now require verifiable age assurance for adult material with real penalties attached, and the list changes. Check with counsel for the markets you serve rather than copying a competitor.
- Does the platform handle age verification for my users?
- No. The platform’s customer is you, the developer. Your relationship with your end users — age assurance, terms, consent, moderation and takedowns — is entirely yours.
Related
Start generating
Create an account, add a prepaid balance, and call the API with a key from the console. No subscription, no minimum, no per-seat pricing.
Get an API key