Theo Stealth is built for adult creative work. That makes it deliberately permissive about things other tools refuse, and absolutely not permissive about two of them. This page explains both, and what happens to what you make.
Two things are refused outright, on every engine, with no setting that turns them back on.
Anything sexualising a minor.
Real or drawn, described directly or implied, in any style and under any framing. There is no artistic, fictional or stylistic exception, and no account tier that changes it.
Sexual imagery of a real, identifiable person who has not consented.
You can build and reuse a character. You cannot use this to make intimate imagery of someone who did not agree to it.
Everything else on this surface is the point of the product and is not treated as a violation. That includes nudity, explicit acts between adults, and subject matter mainstream tools decline to touch.
Requests are checked before anything is generated, and again before anything is returned to you. We do not publish the specifics, for the same reason a lock manufacturer does not publish the key. A detailed description of a check is a guide to walking around it.
What we will say is how it fails.
Theo Stealth has two modes and you choose which one you are in.
Ephemeral, the default
Nothing is written to your account. The conversation, the prompts and the renders live in the tab and end with it. Close it and there is nothing to come back to, including for us.
One exception, set out below: Theo Moonlight runs on our own hardware and keeps your prompt and render for safety review.
History, opt in
You can choose to keep a session. It is saved to your own account, in storage only you can read, and you can delete it at any time. Nothing from Stealth appears in your normal chat history, search or activity.
On engines run by our infrastructure partners, our server logs record that a render happened, with timings, sizes, and whether it succeeded. They never contain your prompt text or your images.
Theo Moonlight is the exception, and it is deliberate.
Moonlight runs on our own hardware, which makes us directly responsible for what it produces. So when you use it, we keep your prompt and the image it made, and a small team can review them. Every other engine on this surface stays as described above: nothing of what you write or make is kept.
We keep it to check our own safety controls are working and to act on anything that should not have been made. It is held for a limited time, it is never used to train anything, it is never sold or shared for advertising, and access is restricted and logged. Material connected to a report of child sexual abuse is retained longer because the law requires it.
If that is not a trade you want to make, pick a different engine. The picker names Moonlight clearly and nothing routes you to it without your choosing it.
Ephemeral is about your work. It is not anonymity.
We do not keep what you make. We do know who made it. Every request is recorded against your account, including what kind of request it was, when, and what it cost, and that record outlives the session. Requests we refuse are recorded too.
So if you are here to make something this page says we will not make, understand that not keeping your prompt is not the same as not knowing it was you. Accounts are identifiable, we act on credible reports, and we respond to lawful legal process.
Theo Stealth offers more than one engine, and they do not all run in the same place. What does not vary is the limit. Every engine on this surface is subject to the two refusals at the top of this page. There is no engine you can pick that relaxes them, and no combination of settings that does either.
Engines we host ourselves: the Theo Moonlight line
Moonlight runs on hardware we operate. Your prompt is not sent to an outside company at all, and the model weights are ones we have reviewed and pinned, so we know exactly what is generating your image, down to the file.
Hosting it ourselves means the safety checks are ours to run rather than someone else's to promise, so they run on both sides of the render. If they cannot run, Moonlight does not render. An unavailable check is a refusal, never a pass.
And if the hardware itself is unavailable, the request fails rather than being quietly re-routed elsewhere. Choosing Moonlight is a real choice about where your work goes, so we do not override it behind your back.
Being ours also means we keep what it makes. Your prompt and the resulting image are retained for safety review, which is the trade for running an uncensored engine we are answerable for. The retention section above sets out exactly what that covers.
Engines served by infrastructure partners
The rest are served by partners who retain nothing from these requests and who enforce their own controls against illegal material as a condition of serving them. We do not name them here, for the same reason we do not describe our own checks in detail.
Two independent sets of controls in front of one limit is the design, not redundancy we tolerate. A control nobody else can inspect is a control you have to take on faith.
These are our models, running on our infrastructure, under limits we set. We do not treat the engine as a third party we merely resell. When Theo makes something, that is us.
That cuts both ways, and we would rather be plain about it than reassuring.
This page describes how the product behaves. The agreement between us, including any warranties, liability and indemnities, is the Terms of Service, and those terms govern where the two differ.
If you believe someone is using OpenCharts to produce content involving a minor, or intimate imagery of a real person without their consent, tell us and we will act on it.
If you are depicted in imagery that was made or shared without your consent, the Canadian Centre for Child Protection's Project Arachnid can help have it removed across the wider internet, not only from us.