Image policy
Effective 6 October 2026. Check version: sable-image-policy-v1.
Why images have their own policy
Chat on Sable is permissive by design. Images are held to a stricter standard, because a picture can be used against a real person in ways a sentence usually cannot. This policy covers every image made through Sable: in the Studio, through the API, and the icons and memes made for launchpad coins.
What you may not make
- Any sexual or sexualised image of a minor, or of anyone who appears to be one. No exceptions, in any style.
- Sexual or intimate images of a real, identifiable person.
- Images of a real, named person in violent or degrading scenes.
- Images made to deceive: fake documents, fake evidence, or a real person shown saying or doing something they did not.
- Images that promote violence against a group, or that glorify a terrorist act.
These rules apply to every image made here. Sable's gateway checks for some of them automatically, as described below. It does not test for the rest. They are still the rules.
What Sable checks before an image is made
Before a description is sent to the image model, and before anything is charged, Sable's gateway reads it. This check runs on every image request from every caller, and no setting turns it off: not a developer's, and not the switch that lets an operator run other checks in watch-only mode. It refuses a description that:
- uses a word or phrase from a fixed list of terms for the sexual abuse of children, for sexual violence and sex without consent, and for making nude images of real people (for example “nudify” or “undress her”). One of these words is enough;
- mentions a child and anything sexual or revealing anywhere in the same description. A child is a word from a fixed list such as “child”, “kid”, “teen”, “baby” or “schoolgirl”, or an age from 1 to 17 written as “12 year old”, “12-year-old”, “12yo” or “aged 12”. Sexual or revealing is a word from a second list, such as “nude”, “sexy”, “lingerie”, “bikini” or “swimsuit”. This is deliberately broad: a child in a swimsuit at the beach is refused too;
- is not in English. The lists can only read English, so a description they cannot read is refused rather than let through. That includes a description where one letter in ten or more is from another alphabet, one where about one letter in seven or more carries an accent, and one of 40 letters or more that uses none of the common small English words such as “the”, “of” or “with”.
Words are matched whole, and capital letters make no difference, so “grape” does not match “rape”. Letters spelled out one at a time, such as “n u d e” or “n.u.d.e”, are joined back into a word and read. A description longer than 32 KB is refused.
The image service's own content filter is also switched on for every request. Nobody can turn it off, and only a fixed set of settings is passed to the service.
A developer can add their own rules to an API key. Those run after this check, never instead of it.
What the check cannot do
- It is a list of words, not a judge of pictures. A description written in other words, misspelled, or phrased indirectly can get past it.
- Sable does not check the finished image. What looks at the picture itself is the image service's own filter, nothing else.
- It reads English only, and refuses everything else.
- Of the rules above, it tests only for the ones it names. The others are not checked automatically.
- It covers image descriptions. Descriptions for video are not checked by it.
When a description is refused
Nothing is sent to the model and nothing is charged. The Studio says the description was refused and links here. A developer gets an HTTP 422 answer. Either way you receive a signed receipt showing that the check ran, its version, and which of the three rules it used: a listed term, a child with sexual content, or not English. The receipt never contains the words that matched, and Sable does not keep them.
What is kept
Sable does not store the description or the image. The receipt for each request records a fingerprint of the description, the model, the count, the cost and which version of this check ran. Each image carries a signed record of where and when it was made, which anyone can check in the Studio.
Changes to the check
Every receipt names the version of the check and carries a fingerprint of its exact word lists. If a list changes, the fingerprint changes, and this page is updated with it.