DRAFT — not legal advice, not reviewed by counsel, not in force.
Community guidelines
A draft of the rules a rumo story is written under, and what happens when one is broken.
It has not been reviewed by counsel and it is not in force.
The one rule everything else follows from
rumo stories are about things, not people.
A story may be about:
- businesses and venues — restaurants, shops, cafés, gyms, clinics;
- buildings, apartment complexes and residential societies;
- institutions — colleges, schools, hospitals, offices as organisations;
- organisations — builders, residents’ associations, service providers, local government bodies;
- public events — festivals, closures, outages, construction;
- civic and infrastructure subjects — roadworks, power, water, transport.
A story may not be about a private individual, and may not be about a public figure or a celebrity.
The second is a different product with a different risk profile and no benefit here.
The first is the single highest-leverage safety decision available: it removes the largest category of legal exposure and real-world harm at almost no cost to anything people actually want to write about.
This is structural rather than aspirational.
There is no table of people in the database for a story to point at.
The absence is the enforcement.
A person may be in a story.
Their name may not.
Somebody can appear in a story as an actor in an event about a permitted subject.
What is not permitted is making that person the subject of the claim.
| Status | Example |
|---|---|
| Permitted | “The society’s new maintenance contract was cancelled. The secretary said the vendor failed inspection.” |
| Not permitted | “The society secretary is taking kickbacks.” |
The test is whether the person is the subject of the claim or a participant in an event.
Separately from that, the name itself:
| Status | What it looks like |
|---|---|
| Fine | “the secretary”, “the site engineer”, “a resident in Tower C” |
| Flagged | “Rajesh Kumar”, “Rajesh from B-402”, “the secretary, R. Kumar” |
| Untouched | The name of a place or an organisation, and your own name on your own update |
Why it happens as you type
Both checks run in the composer, not afterwards.
If the subject of what you are writing resolves to a person, it is refused there and then, with a plain explanation and a suggested reframe in the same response.
Nothing is written to the database.
This is deliberate: a queue whose only permitted outcome is rejection wastes a day of somebody’s time to arrive at the answer they could have had immediately.
If a name appears inside an otherwise fine story, it is flagged and a role is offered in its place.
One tap accepts.
Declining routes the update to moderation rather than refusing it — a guard with no way past it is defeated by a deliberate misspelling, and then the same exposure exists with none of the signal.
Compose-time refusal has to be cheap to comply with and obvious why it fired.
If it ever is not, that is a bug and worth reporting.
Real names, and nothing else
Every account is a verified phone number and a real name, and the name is shown on every update.
There are no handles, no pseudonyms and no anonymous mode.
Every contribution is attributed, including inside a Circle.
The reasoning is worth stating, because “use your real name” is usually a platform being high-handed and here it is not.
In a building of three hundred households, a contribution is identifiable from its content alone — the person evidently lives there, and the community is small.
A pseudonym in that setting does not protect you.
It gives you a false picture of your own exposure, so you say things you would not have said if you could see it.
Impersonating somebody else is one of the report reasons below.
Receipts
A receipt is media you attach to an update: a photograph, a video, a screenshot, a document, a recording.
Every upload is scanned against known-hash databases for child sexual abuse material and non-consensual intimate imagery before it is visible to anyone, stripped of location and device metadata on ingest, and attributed to the account that posted it.
Receipts cannot be downloaded. There is no save-to-device action anywhere in rumo.
These are photographs of real local places and the people in them, and a copy on somebody’s camera roll is past every control on this page: it survives deletion, takedown and account closure, and it travels with no context and no route back.
Viewing is in the app only.
Screenshots of private conversations are the riskiest category and are handled as such: permitted, reportable under their own reason, and removed at the request of any identifiable participant in the conversation.
A voice recording is read once by a model as a safety check before it can be heard by anybody else.
That is described plainly on the privacy page, and it exists to enforce the name rule above on speech, which a text-only check cannot hear.
The right of reply
This is the most important surface in rumo and the one a subject should reach for first.
A business, institution or organisation can claim its entity — by email at its own domain, by callback to the number on its public listing, by registration documents, or by a code posted to its listed address.
A verified subject can:
- be notified within the hour when a new story names it;
- post an official response, pinned at the top of the story and visually distinct from ordinary updates;
- contribute ordinary updates like anybody else;
- submit a correction request or a takedown request through the same queue as anybody else.
A verified subject cannot delete the story, cannot delete or edit anybody else’s updates, and cannot suppress ranking or stop the story appearing.
The pinned summary that describes the record is also closed to it, deliberately: a subject gets the official reply, and does not also get the line that characterises the record about it.
An official response counts toward settling the story.
The incentive is to answer, not to litigate.
Any contributor with at least one live update on a story may write its pinned summary.
There is no owner and no promotion, and there is no edit — a change is a new version, signed, with the old one still visible.
Nobody owns the pin; the remedy for a bad one is a real name beside it and a report if it is worse than that.
Reporting
Reports are specific rather than generic, because a vague category produces a queue nobody can work:
- false information;
- harassment or targeting of an individual;
- private information published — an address, a phone number, a workplace, an identity document;
- sexual content, or intimate imagery shared without consent;
- violent or graphic content;
- impersonation;
- spam or promotion;
- off-subject — this is a story about a person, not a place.
What happens next
Every report enters one queue, including reports made inside a Circle, and the queue runs at the strictest clock that applies to anything in it rather than in the order things arrived.
- Acknowledgement within 24 hours, and resolution within 15 days.
These are two separate clocks; acknowledgement may be automatic, resolution requires a person. - Reports naming intimate imagery, or private information published, are escalated ahead of the general queue and removed within 24 hours of the complaint.
- The clock on a report is set by the server from the reason given.
It is not something a reporter can set for themselves. - A story under heavy report load is demoted pending review.
Being reported does not make a story travel further.
Action is graduated: no action, a correction notice attached, media hidden, an update removed, a story removed, an account restricted, an account closed.
Every action is logged with the person who took it, the reason, and the time.
Automated systems may hold something for review; they do not permanently remove it without a human, except for media that matches a known hash, which goes immediately and is reported as the law requires.
A complaint from the subject of a story enters this queue like any other and is decided on policy.
It is not obeyed.
There is no control in rumo that lets a subject remove a story about itself — the right of reply above is the remedy, on purpose.
A removal obligation with a clock on it starts only on real legal process: a court order, or a notification from an authorised government agency.
How to reach the named officer who answers for those clocks, and how to appeal a decision beyond rumo, is on the grievance page.
Stories end, and that is the point
A story with nothing new for fourteen days settles, and a verified subject’s official reply settles it at once.
Settled is not deleted and not hidden: the story stays readable, its pearl goes cool, and it stops competing for attention.
Nothing is owed to a story that is over.
There is no streak to keep and no number that goes down if you stop.
Nothing to farm, either: no likes, no followers, no reposts.
A story that ends is a story that worked.
What is still owed
Every item below is a gap in this page, not a summary of one.
They are listed rather than implied so that nobody reads a placeholder as a commitment.
- The named grievance officer the reporting clocks above belong to does not exist yet.
See the grievance page. - The appeal route for a moderation decision inside rumo — what a person is told when their update is removed or their account restricted, and how they contest it — is not written down here.
- Transparency reporting. Counts of reports by type and outcome are meant to be published annually.
Nothing has been published and no format has been chosen. - Screenshot receipts. Whether publishing a screenshot of a conversation raises a separate problem under wiretap or two-party-consent laws in some US states, or under India’s rules, is a counsel question and is unanswered.
- Coverage. A 24-hour clock spanning Indian and US time zones cannot be answered inside one person’s working day and does not pause at weekends.
The staffing behind these promises is not in place. - Counsel. No lawyer in either country has read this page.
