Terms of Service
DRAFT — pending legal review, not yet in force. This document is a working draft prepared for the founder's review and eventual sign-off by qualified legal counsel. It is not legal advice, and nothing in it should be relied on as a final, binding agreement until the placeholders below are filled in, the whole document has been reviewed by a lawyer, and it is published as final.
Service: Rillo
Document version: 2026-07-24
Last updated: 2026-07-24
Audience: members of the Rillo social discovery network and partner businesses listing events on our marketplace.
This document is the contract between you and Rillo. It explains what you can and can't do on the service, what we can and can't do, and what happens if something goes wrong. It works alongside two other documents: our Privacy Policy (what data we collect and your rights over it) and our Community Guidelines (the specific behaviour we expect from members — this document incorporates them by reference, and breaking them is a breach of these Terms).
Every behaviour described below is implemented in the product, not aspirational — the Appendix maps each claim to the code that backs it, in the same style as PRIVACY.md.
1. Who we are, and what the service is
Rillo (the "service", "we", "us", "our") is a social discovery platform for making platonic friends — it is explicitly not a dating service, and using it to solicit dates, romantic relationships, or sexual contact is against our Community Guidelines and these Terms.
The service has two sides:
- Members — individuals who create a profile, discover and message other nearby members, form small friend groups ("Circles"), and browse and attend events.
- Partner businesses — local businesses who create a partner account to publish events that members can register for and attend. §5 sets out partners' specific obligations.
The legal entity operating the service, and the jurisdiction whose law governs this agreement, are recorded in §14 and the placeholder checklist.
By creating an account, you agree to these Terms. If you don't agree, don't use the service.
2. Eligibility
- You must be at least 18 years old. We enforce this at sign-up (the onboarding date-of-birth step rejects anyone under 18) and again in the domain layer itself (
MemberProfile.Createraises a hard error if the supplied date of birth is under 18) — there is no path to a usable account for a minor. - You may hold one personal account. Creating multiple accounts to evade a ban, restriction, or moderation decision is a breach of these Terms.
- The information you give us at sign-up and in your profile must be accurate — in particular your date of birth and your display name must genuinely be yours. Impersonating another person, or presenting a fictional persona as if it were you, is prohibited (see Community Guidelines §2).
- You must have the legal capacity to enter into this agreement in your jurisdiction.
- Partner businesses must be a genuine, operating business and must provide accurate business details and verification documents when requested (§5.2).
3. Your account
- You are responsible for keeping your login credentials secure. If you sign in with a social provider (Google, Microsoft, Apple), you are also bound by that provider's terms.
- We support two-factor authentication (TOTP) and recommend enabling it.
- You must tell us promptly if you believe your account has been accessed without your authorisation.
- You can pause your account at any time ("Deactivate my account" in-app) without deleting your data, or permanently delete it under §9 — both are described in
PRIVACY.md§7.2.
4. Acceptable use
You agree to use the service only for its intended purpose — meeting and building platonic friendships with other members, and discovering and attending local events — and to comply with our Community Guidelines, which are incorporated into these Terms by reference. In summary, and without limiting the Community Guidelines, you must not:
- harass, threaten, hate on, or endanger another member or partner;
- use the service to solicit dating, romantic relationships, or sexual contact;
- post or send content that is illegal, sexually explicit, violent, or that promotes self-harm;
- impersonate another person or misrepresent your identity, age, or affiliation;
- spam, scam, or attempt to sell goods or services to other members outside the events marketplace;
- scrape, reverse-engineer, or use automated means to access the service, or attempt to circumvent rate limiting or authentication;
- upload photos of anyone other than yourself, or photos that are not a genuine, current likeness of you;
- attempt to interfere with, disable, or overload the service, or bypass content moderation, photo verification, or reporting mechanisms;
- use the service if you are under 18, have previously been banned, or are legally prohibited from using it in your jurisdiction.
We enforce this through a mix of human moderation and reporting tools members already have access to: any member can report another member's profile (reasons: inappropriate content, fake profile, harassment, spam, safety concern, or other) or a specific photo, and both are reviewed by our moderation team, who can approve or remove the reported content; a profile found in breach of these Terms or the Community Guidelines can be banned, which immediately deactivates it. We also reserve the right to review and remove any other content on the service, including your bio, that breaches these Terms or the Community Guidelines. See §10 — Suspension and termination for what that means in practice, and the Community Guidelines for how reporting works from a member's point of view.
5. The marketplace: events and partner businesses
5.1 For members
Partner businesses list real-world events (for example, coffee meetups, hikes, and classes) that you can browse, register for, and attend. When you register:
- your registration may be immediately confirmed, or placed on a waitlist if the event is full, and promoted automatically if a space opens up;
- you can cancel your own registration at any time before the event;
- a partner business can also cancel your registration on their side (for example, if they need to cancel or reschedule the event) — you'll be notified either way;
- attending in-person events involving people you have not met before carries inherent real-world risk. Read §8 — Disclaimers and the Community Guidelines' safety guidance before you go. We do not vet attendees or partner businesses' venues for safety, and we are not responsible for what happens at an event.
5.2 For partner businesses
If you create a partner account to list events, you additionally agree that:
- you will provide accurate information about your business, and, where we ask you to verify it, genuine verification documents. Businesses go through a verification review (
Pending→Verified, orRejectedif we can't confirm you are who you say you are) before certain partner features unlock; - event listings must be accurate — date, time, location, price, capacity, and description must reflect the real event. Misleading listings are a breach of these Terms;
- you will honour registrations you accept. If you need to cancel or change an event, you must do so promptly and the affected members must be notified — the platform records this as a partner-initiated cancellation, distinct from a member cancelling their own attendance;
- your own conduct, and the conduct of your staff at your events, is subject to the same standards of respect and safety as members' conduct under the Community Guidelines;
- we may suspend your partner account (temporarily) or close it (permanently) if you breach these Terms, misrepresent your business, or repeatedly fail to honour listed events. A suspended account can be reinstated once the issue is resolved; a closed account cannot;
- these Terms do not make you our agent, employee, franchisee, or joint venturer — you operate your own business independently, and you're responsible for your own compliance with the laws that apply to your business (health and safety, insurance, licensing, and so on) at any event you host.
6. Content you post, and the licence you grant us
You retain ownership of the content you create and post on the service — your profile photos, bio, messages, and anything else you upload ("your content").
By posting content, you grant Rillo a non-exclusive, worldwide, royalty-free licence to host, store, reproduce, and display your content for the purpose of operating the service — for example, showing your profile photo and bio to other members in discovery, displaying your messages to the people you sent them to, and showing your event registration to the partner hosting that event. This licence:
- ends when you delete the specific content, or your account, subject to the retention windows described in
PRIVACY.md§4 (for example, backups aren't purged instantly) and the fact that a past match's conversation history is preserved for the other person in that match (PRIVACY.md§4, soft-delete vs. hard-delete); - does not give us the right to use your content for external advertising, to sell it, or to sublicense it to third parties outside the operation of the service;
- requires that the content you post is actually yours to post, and doesn't infringe anyone else's rights.
We also run content moderation: any member can report a specific photo, which queues it for our moderation team to approve or remove, and we reserve the right to review and remove any content — including your bio — that breaches these Terms or the Community Guidelines. If your content is removed for a Community Guidelines breach, you'll typically be notified. Photo verification (the optional "verified" badge) is reviewed by a human member of our team comparing your selfie to your existing photos — we do not run automated face-matching or biometric comparison, and your verification selfie is never shown to other members (see PRIVACY.md §2.7 for the full mechanism).
The Rillo name, logo, and the software and design of the service itself are our intellectual property (or licensed to us) and are not covered by the licence above — you don't get any rights to them by using the service.
7. Subscriptions and billing
The service offers a Free tier and two paid tiers, Plus and Premium, each unlocking additional features (for example, higher daily limits and visibility into who has viewed your profile).
- Auto-renewal. Paid subscriptions automatically renew at the end of each billing period unless you cancel before the renewal date. The renewal price is the price in effect at the time of renewal.
- How you pay, and how you cancel, depends on where you subscribed:
- Via the Apple App Store (iOS): billing, renewal, and cancellation are all handled by Apple. Cancel any time in your Apple ID → Subscriptions settings. Apple's own terms and refund policy govern the transaction.
- Via Google Play (Android): billing, renewal, and cancellation are all handled by Google. Cancel any time in the Google Play → Subscriptions section of the Play Store app. Google's own terms and refund policy govern the transaction.
- Via Stripe (web/partner-adjacent billing): you can manage or cancel your subscription through the Stripe customer-portal link available from your subscription status screen in the app.
- If you subscribed through an app store, that store's rules govern the purchase — we cannot issue refunds on Apple's or Google's behalf, override their billing, or make promises about refund timing beyond what the relevant store's policy or applicable consumer law provides. If you subscribed via Stripe, ask us directly and we'll address it in line with applicable consumer-protection law; we make no separate refund guarantee beyond that.
- Restore purchases. If you reinstall the app or switch devices, you can restore a previous purchase from within the app, which re-validates your existing subscription with Apple or Google.
- Trials. Where a trial is offered, it's disclosed to you before you start it, including what happens (and what you'll be charged) when it ends.
- Changing tiers. Moving between tiers (upgrade or downgrade) takes effect and is billed according to the rules of the platform you subscribed through (Apple, Google, or Stripe).
- We do not store your full card number, CVV, or bank details — see
PRIVACY.md§2.5 for exactly what billing data we hold.
8. Disclaimers
The service connects you with other people; it does not, and cannot, vet them. We run content moderation, photo verification (optional, human-reviewed), age verification at sign-up, and a reporting system — but we cannot guarantee the identity, intentions, or conduct of any member or partner business you interact with, on or off the platform.
Meeting people in person is at your own risk. Whether that's a 1:1 meetup, a Circle group hangout, or a partner-hosted event, you are responsible for your own safety when meeting someone you met through the service. We strongly encourage the precautions in the Community Guidelines (meet in public, tell someone where you're going, arrange your own transport) but following them is your responsibility, not something the service enforces or guarantees.
The service is provided "as is." To the fullest extent permitted by law, we disclaim all warranties, express or implied, including fitness for a particular purpose, that the service will be uninterrupted, error-free, or secure, and that any particular result (making friends, finding events, a successful match) will occur.
Limitation of liability. To the fullest extent permitted by law, Rillo will not be liable for indirect, incidental, special, consequential, or punitive damages, or for any loss arising from your interactions with other members or partner businesses, including anything that happens at an in-person meeting or event. Nothing in these Terms excludes or limits liability that cannot lawfully be excluded or limited under the law that governs this agreement (for example, liability for death or personal injury caused by our negligence, or rights that cannot be excluded under applicable consumer-protection law).
9. Erasure (account deletion)
You can request deletion of your account and personal data at any time. This is fully described, including the exact review flow and timelines, in PRIVACY.md §7.2 — in short: you submit a request, a human reviewer approves or rejects it (typically same-day), and on approval your profile is anonymised, your photos are deleted, and you're signed out permanently. We only reject an erasure request where we have a legal basis to (an open fraud investigation, an unresolved billing dispute, or a legal hold), and we'll tell you why.
10. Suspension and termination
We may warn, temporarily deactivate, or permanently ban your account if you breach these Terms or the Community Guidelines, including (without limitation) harassment, fake profiles, using the service for dating/sexual solicitation, spam or scams, safety concerns raised by other members, or repeated moderation flags. A ban immediately deactivates the account and removes it from discovery, and a banned account cannot sign back in.
- Where practical, action is proportionate to the issue — a first minor breach may result in content removal or a warning rather than a ban.
- An account can also be temporarily deactivated while a report against it is under review, without that being a final decision — this uses the same reversible mechanism as the self-service "pause my account" option.
- Serious breaches (harassment, threats, safety concerns, illegal content, minors on the platform) can result in an immediate ban without a prior warning.
- You can also delete your own account at any time under §9 — that isn't a Terms enforcement action, it's your right.
- Partner accounts can be suspended or closed under the terms in §5.2.
- If your account is banned or your access is otherwise terminated for breach, you don't get a refund for any unused portion of a paid subscription, except where the platform you subscribed through (Apple, Google) or applicable law requires one.
We may also suspend or discontinue all or part of the service (for maintenance, legal reasons, or because we're shutting a feature or the service down) — where reasonably possible we'll give you notice.
11. Indemnity
You agree to indemnify and hold Rillo harmless from claims, damages, and expenses (including reasonable legal fees) arising from: your breach of these Terms or the Community Guidelines; your content; your interactions with other members or partner businesses, including at in-person meetings or events; or your violation of any law or third-party right. This is a standard clause and, like the rest of this document, is subject to legal review and to the limits that applicable consumer-protection law places on it.
12. Changes to these Terms
We may update these Terms from time to time. Material changes will be dated at the top of this document, and — matching the pattern already used for PRIVACY.md — where a change materially affects your rights or obligations, we will ask you to re-acknowledge before you can keep using consent-gated parts of the service. Continuing to use the service after a change takes effect means you accept the updated Terms. The history of this document is kept in source control, matching PRIVACY.md's approach.
13. Relationship to other documents
PRIVACY.md— what personal data we collect, why, how long we keep it, and your rights over it. Governs data handling; these Terms don't restate it.COMMUNITY-GUIDELINES.md— the specific behavioural rules for members and partners. Incorporated into these Terms by reference; breaching the Guidelines is a breach of these Terms.
If there's a conflict between this document and the Community Guidelines on a behavioural rule, the Community Guidelines control (they're the more specific document); if there's a conflict on data handling, PRIVACY.md controls.
14. Governing law
PRIVACY.md addresses the data-protection regimes that apply to your personal data (GDPR, UK GDPR, and the Australian Privacy Act, depending on where you're based) — that is settled and already reflected there. The governing law and jurisdiction for this contract itself has not yet been decided and is a placeholder pending a founder/legal decision — see the checklist below. It is not automatically the same as any of the data-protection regimes named in PRIVACY.md.
[GOVERNING-LAW JURISDICTION]
15. Contact
For questions about these Terms: [CONTACT EMAIL].
For data-protection questions, use the Privacy Policy contact path instead — see PRIVACY.md §13.
Placeholders to fill in before publication
This draft deliberately does not guess at facts only the founder or legal counsel can supply. Every one of the following must be resolved before this document is published or takes effect:
| Placeholder | Where it appears | What's needed |
|---|---|---|
[LEGAL ENTITY NAME] |
§1 (referenced, not yet inserted — see note below) | The registered legal entity operating the service |
[GOVERNING-LAW JURISDICTION] |
§14 | Which jurisdiction's law governs this contract, and where disputes are resolved (courts vs. arbitration, and venue if arbitration) — a decision, not a fact we can infer from the GDPR/UK GDPR/Australian Privacy Act coverage in PRIVACY.md, which addresses data protection only |
[CONTACT EMAIL] |
§15 | A support/legal contact address for Terms questions (may be the same mailbox as the Privacy DPO contact, or different — founder's call) |
Note on §1: this draft does not insert [LEGAL ENTITY NAME] inline in §1 because the entity may vary by region, mirroring PRIVACY.md §1's approach ("the legal entity operating the service in your region"). Confirm whether Terms should name a single global entity or follow the same per-region pattern as Privacy before publication — if a single entity, add it explicitly to §1.
Also carry over from PRIVACY.md: the postal address and DPO contact placeholders already flagged there apply here too, since §15 points back to that document rather than duplicating it.
Appendix: technical references for engineers
This appendix is not part of the published terms. It exists so an engineer can verify each behavioural claim above against the codebase, in the same spirit as PRIVACY.md's appendix.
| Claim | Reference |
|---|---|
| 18+ enforcement at sign-up and in the domain layer | DateOfBirth.Create; MemberProfile.Create (src/FacesOfFriendship.Domain/Profiles/MemberProfile.cs) |
| Not-dating positioning | docs/aso/2026-07-23-store-copy.md — existing App Store copy already states this positioning |
| Profile reporting (reasons, pending → reviewed) | src/FacesOfFriendship.Domain/Profiles/ProfileReport.cs, ReportReason enum, ProfileReportedHandler |
| Photo reporting → flag → staff approve/remove | ProfilePhotoApplicationService.ReportPhotoAsync → MemberProfile.FlagPhoto; AdminModerationApplicationService.ApprovePhotoAsync/RemovePhotoAsync; AdminPhotoModerationController |
Bio moderation status model exists (Pending on every edit; Flagged/Approved/Removed states; admin review endpoint) |
MemberProfile.UpdateBio/FlagBio/ApproveBio/RemoveBio (MemberProfile.cs); AdminModerationApplicationService.ReviewBioAsync; AdminBioModerationController. Caveat for engineers, not asserted in the published Terms: FlagBio() has no application-layer caller as of this draft, so no code path currently promotes a bio from Pending to Flagged — the admin "flagged bios" queue (ListFlaggedBiosAsync, filtered on BioModerationStatus.Flagged) is consequently unpopulated today, and ReviewBioAsync would fail with bio.not_flagged if called. The Terms deliberately phrase bio moderation as a reserved right, not a described automated pipeline, to stay accurate regardless of this gap. Worth a backlog item to either wire a trigger or remove the dead path. |
| Profile ban → immediate deactivation | MemberProfile.Ban() sets ModerationStatus = Banned and IsActive = false (MemberProfile.cs) |
| Profile deactivation (pause, reversible; also used for admin review-in-progress) | MemberProfile.Deactivate() (MemberProfile.cs); admin path via AdminModerationApplicationService.SuspendProfileAsync (AdminProfileModerationController POST /admin/profiles/{userId}/suspend) |
| Report review → ban or dismiss | AdminProfileReportsController POST /admin/profile-reports/{reportId}/ban calls MemberProfileApplicationService.BanProfileAsync → profile.Ban(); POST .../approve calls ApproveProfileAsync → profile.ApproveModeration() (dismiss, no action) — both mark the report reviewed |
| Blocking another member | BlockedRelationship (Domain), BlockListApplicationService, BlockListService (Infrastructure) |
| Photo verification — human review, no biometric matching | PhotoVerificationApplicationService; MemberProfile.RequestPhotoVerification/ApprovePhotoVerification/RejectPhotoVerification; PRIVACY.md §2.7 |
| Event lifecycle (Draft/Published/Cancelled/Completed) | EventStatus enum (src/FacesOfFriendship.Domain/Marketplace/Enums/EventStatus.cs) |
| Attendance lifecycle incl. waitlist and partner-initiated cancellation | AttendanceStatus enum — Registered, Cancelled, CancelledByPartner, Waitlisted (src/FacesOfFriendship.Domain/Marketplace/Enums/AttendanceStatus.cs); AttendanceWaitlistedDomainEvent |
| Partner account lifecycle (Invited → Active → Suspended/Closed) | PartnerAccount.Activate/Suspend/Reinstate/Close (src/FacesOfFriendship.Domain/Marketplace/PartnerAccount.cs) |
| Business verification (Pending/Verified/Rejected) | VerificationStatus enum (src/FacesOfFriendship.Domain/Marketplace/Enums/VerificationStatus.cs); Business entity |
| Subscription tiers (Free/Plus/Premium) | SubscriptionTier enum (src/FacesOfFriendship.Domain/Subscriptions/Enums/SubscriptionTier.cs) |
| Apple/Google purchase validation and restore | SubscriptionController.ValidateApplePurchaseAsync/ValidateGooglePurchaseAsync; IBillingBridge.RestorePurchasesAsync on Mobile (AppleBillingBridge, GoogleBillingBridge) |
| Stripe billing-portal link for self-service cancellation | StripeCheckoutService (BillingPortal.SessionService); SubscriptionStatusDto.ManagementUrl/ManagementMessage |
| No full card data stored | PRIVACY.md §2.5 |
| Erasure request/approval/rejection flow | PRIVACY.md §7.2 and its Appendix — same endpoints and state machine apply here by reference |
| Content moderation audit trail | ModerationAuditLog table — same mechanism referenced in PRIVACY.md's appendix for verification decisions |
This document is a draft. It has not been reviewed by a lawyer and does not take effect until the placeholders above are resolved and the document is formally published.