Legal
Admin Access Policy
When staff can access account data, and how that access is limited and logged.
1. Least privilege
Staff access is role-based: each role grants only the specific permissions needed for support, safety, moderation, or legal compliance. Most staff cannot see private content, and the most sensitive queues (such as minor/CSAM review) are limited to a small trust-and-safety group.
2. Accountability
Sensitive admin actions are audit-logged against the accountable staff member. If a staff member ever needs to act as a user for support, that impersonation is clearly indicated, time-limited, off by default, and recorded against the real staff identity — never hidden.
3. Verified-creator IDs
Government IDs submitted for creator verification are encrypted and viewable only by reviewers with the identity-review permission; each view is logged.
4. Support access to questionnaire answers
To help with support requests or investigate a problem, a small number of high-trust staff hold a dedicated permission that lets them view your own answers to Sparks questionnaires (the compatibility decks) and the status of any shared sessions you're part of. This access is limited: staff see only your own answers, never another member's answers and never the private results of a shared reveal — those stay between you and your partner.
Every time a staff member opens this view they must record a reason, and each access is logged against their identity. As with all staff access, it is role-based and least-privilege — most staff cannot use it at all.