Community Guidelines vs Code of Conduct vs Terms of Service: Differences
Three similar-sounding documents confuse many nonprofits: community guidelines, code of conduct, and terms of service. They overlap enough that organizations often assume having one means they have covered the others, and different enough that the assumption fails at exactly the wrong moment. Understanding what separates them helps you write the right policies for your organization, publish them in the right places, and know which one you are actually relying on when someone behaves badly.
Three Definitions
The clearest way to tell these documents apart is to look at five things for each one: what it is, who it applies to, why it exists, what tone it takes, and whether it is legally binding. Those five attributes explain nearly every practical difference between them, including which one a lawyer needs to see.
Code of Conduct
What it is. A set of behavioral expectations for people in your community, programs, or events. It defines what is acceptable and what is not, and it includes enforcement procedures, which is the part that distinguishes a code of conduct from a statement of values.
Who it applies to. Members, volunteers, staff, participants in programs and events, and guests. The scope is people rather than platforms, which is why a code of conduct follows your community into whatever spaces it occupies.
Why it exists. To create psychological and physical safety, to prevent harm including harassment, discrimination, and violence, and to give you a framework for addressing violations when they occur. Without the third purpose, the first two are aspirations you have no method of defending.
Tone. Aspirational but also protective. A characteristic pair of sentences reads: "We expect respect and dignity. We will not tolerate harassment." The first sentence describes the community you are trying to build; the second draws the boundary you will enforce.
Legal nature. A code of conduct is not a legal contract. It can be used to support disciplinary actions such as removing someone from events or terminating their membership, but it does not create binding legal obligations. Its authority comes from being clearly published, consistently applied, and paired with a procedure people can see.
An example. A nonprofit's code of conduct states: "We don't tolerate harassment based on identity. If you experience harassment, report it to [email]. We will investigate and take action." Notice how short it is, and that it still manages to name the prohibited conduct, the reporting route, and the organization's commitment to act.
Community Guidelines
What it is. A broader set of norms for how people interact in a shared space, whether that space is physical or digital. Guidelines usually cover tone, respectfulness, and constructive discussion, alongside specific prohibitions on things you do not want in the space.
Who it applies to. Anyone using the space, which means members, volunteers, staff, guests, and online users alike. The scope is defined by the space rather than by membership status, so a person who has never joined anything is still covered while they are there.
Why it exists. To maintain a healthy community culture, to encourage constructive dialogue, and to keep spaces from being overrun by spam, commercial promotion, and off-topic discussion. Those last three are the everyday work of moderation, and a code of conduct written around safety does not give moderators clear authority over them.
Tone. Often more permissive than a code of conduct. A characteristic formulation reads: "We encourage diverse perspectives. We ask that discussion remain respectful and on-topic." The verb is "ask" rather than "will not tolerate", which is deliberate.
Legal nature. Usually not a legal contract; these are guidelines rather than rules. They can still be enforced through actions like removing posts and suspending accounts, because access to the space is something you control regardless of whether a contract exists.
An example. A nonprofit's online community guidelines state: "Welcome! This space is for discussing our mission. Please be respectful. Off-topic discussion and spam will be removed." The document tells a newcomer what the space is for before it tells them what is forbidden.
Terms of Service
What it is. A legal contract defining the relationship between your organization and a user, usually a user of a website, app, or digital platform. It sets out your responsibilities as the provider and the users' rights and responsibilities in return.
Who it applies to. Anyone using your website or service. The trigger is use of the service rather than membership of your community, so it can cover people who have no other relationship with your organization at all.
Why it exists. Legal protection. Terms of service limit your liability and set clear rules about what users can and cannot do with your service. This is the only one of the three documents whose primary audience, in the moment it matters, may be a court rather than a community member.
Tone. Formal and legal, opening with something like: "By using this service, you agree to the following terms." Nobody reads this document for inspiration, and it should not try to inspire.
Legal nature. A binding legal contract. Users must agree to the terms before using the service, and violation can result in legal action. That binding quality is precisely why the drafting standard is different from the other two documents.
Common sections. A license grant, in which you grant users the right to use the service; intellectual property, covering who owns the content; limitation of liability; dispute resolution; and privacy policy. An example clause reads: "By creating an account on our platform, you agree that any content you post remains your property, but you grant [nonprofit] the right to use it for our mission."
Quick Comparison
The table below puts the three documents side by side on the attributes that decide which one applies to a given situation. Read across a row when you are unsure which document should govern a problem you are facing.
| Feature | Code of Conduct | Community Guidelines | Terms of Service |
|---|---|---|---|
| Primary purpose | Safety and behavior | Community culture | Legal contract |
| Applies to | Members/participants | All users | All users |
| Legally binding? | Not usually | No | Yes |
| Enforcement | Removal, termination | Removal of content | Legal action |
| Tone | Protective | Inviting | Formal |
| Examples of violations | Harassment, discrimination | Spam, off-topic posts | Unauthorized commercial use, IP violation |
Where They Overlap
All three documents often prohibit similar things: harassment, discrimination, hate speech, commercial spam, and illegal content. That shared surface is why organizations assume the documents are interchangeable. What actually differs is emphasis and enforcement, and those differences determine what you can do when a rule is broken.
A code of conduct focuses on the psychological safety violation: this behavior is harmful to a person. Community guidelines focus on maintaining community health: this behavior undermines the culture of the space. Terms of service focus on legal liability: this behavior violates your agreement with us. The same incident can therefore be described three ways, and which framing you choose determines whether the response is a conversation, a deleted post, or a matter for a lawyer.
Which Do You Need?
Every nonprofit should have a code of conduct if it has members, volunteers, or participants. Even small organizations benefit from clarity about acceptable behavior, and the smaller you are, the more likely it is that expectations currently live in the heads of a few long-serving people rather than in a document anyone can consult.
You should have community guidelines if you run an online community, a forum, or a social media group, or if you want to maintain a healthy discussion culture in any shared space. The moment you have a space that people can post into, someone will eventually post something that is not harmful but is not what the space is for, and guidelines are what let a moderator address that without escalating it into a conduct matter.
You should have terms of service if you run a website where users create accounts or input data, if you have a membership platform, or if you want legal clarity about intellectual property or liability. The threshold is functional rather than aspirational: it is about what your systems do, not about how formal your organization feels.
Writing Approach by Document
Code of conduct. Write it with community input rather than in a back office. Focus on values and safety, use accessible language, and include both enforcement and appeals procedures so the document describes a complete process. Publish it prominently and discuss it with the community, because a code that people first encounter at the moment it is used against someone will not carry authority.
Community guidelines. Write them collaboratively with the community leaders or moderators who will actually apply them, since they know which behaviors recur. Focus on maintaining healthy discussion, be specific about what you do and do not tolerate, and keep the document shorter than your code of conduct. Length is itself a signal: guidelines are meant to be read on the way in.
Terms of service. Hire a lawyer or use one of the many templates that exist for nonprofits. This is legal language, and the point of it is that it functions when tested, so make sure it actually protects your organization rather than merely resembling the terms you have seen elsewhere. Have a lawyer review it before publishing.
Many nonprofits use a code of conduct plus community guidelines and skip terms of service entirely unless they run a digital platform. That is a perfectly reasonable position. You do not need all three. Start with the code of conduct and add the others when your circumstances call for them.
Keeping Them Consistent
If you have multiple documents, they need to be compatible with one another. Do not prohibit something in the code of conduct and permit it in the community guidelines, and do not declare that you value consent in the code while using terms of service language that ignores it. Inconsistency between published policies is worse than a gap, because anyone facing enforcement can point at the document that helps them, and you have supplied the argument yourself.
Review all of the documents together at least annually rather than one at a time as problems surface. Check that they still reflect your current values and, just as importantly, your current enforcement capacity. A policy promising an investigation process you no longer have the staff to run is a commitment you will break in public.
Implementation
Start with the code of conduct. It is the most important of the three for nonprofit culture and safety, and it is the one that most directly shapes what happens to a person who is harmed in your community. If you run online spaces, add community guidelines next, written with the people who moderate them. If you operate digital platforms where users hold accounts or submit data, add terms of service, but consult a lawyer rather than assembling them yourself.
For deeper guidance on drafting the first of these, work through How to Write a Code of Conduct for Your Nonprofit Community. For the question of whose norms end up encoded in a policy that reads as neutral, see Inclusive Community Guidelines: Dominant-Culture Norms Hidden in Policies.
Anti-Patterns
- Publishing terms of service and calling it a code of conduct. Terms of service protect the organization from users. A code of conduct protects people from each other. An organization that has only the first has no framework for responding when a member harasses another member.
- Writing a code of conduct with no enforcement or appeals procedure. Without those sections you have a values statement. It may be a good values statement, but it will not support a decision to remove someone, and it offers the person removed no route to contest it.
- Treating community guidelines as a lighter code of conduct. They are not a milder version of the same document; they govern a different thing. Using guidelines language to address harassment signals that the harm was a tone problem.
- Assembling terms of service from other organizations' pages. This is the one document whose value is entirely in whether it works when tested. Templates written for nonprofits are a legitimate starting point, and legal review is the step that makes them yours.
- Letting the documents contradict each other. Prohibiting something in one policy and permitting it in another hands anyone facing enforcement a ready-made defence.
- Reviewing policies only after an incident. Annual joint review catches drift between what the documents promise and what the organization can currently deliver, before the gap is discovered by someone relying on it.
- Publishing and never discussing. A code posted to a website and never mentioned again is invisible until it is used, at which point it looks like a rule invented for the occasion.
Practice Prompts
- List every space your organization runs, physical and digital, and note which of the three documents currently governs each one. Gaps in that grid are the spaces where a problem would have no policy behind it.
- Take a recent incident, real or plausible, and describe it three ways: as a safety violation, as a culture violation, and as a contract violation. Decide which framing you would actually use and why.
- Read your existing policies side by side and find one place where they disagree or where the same behavior is treated at different levels of seriousness. Draft the sentence that reconciles them.
- Write the reporting and appeals sections your code of conduct would need to support removing someone from an event, then check whether your organization currently has the capacity to deliver what you just promised.
- Draft community guidelines for one of your online spaces in a single short paragraph that a newcomer would read: what the space is for, what is expected, and what gets removed.
- Audit whether your website collects personal data or lets users create accounts. If it does, list the terms of service sections you would need and identify who will review them.
Reflection
Think about the last time someone in your community behaved in a way that made others uncomfortable. Which document did you reach for, and did it actually tell you what to do? Many organizations discover in that moment that their published policy names the behavior but not the process, so the response gets improvised by whoever is available, and the outcome depends on how confident that person feels rather than on what the organization decided in advance.
Then ask a question about audience. Your code of conduct is written for members, your community guidelines for anyone in the space, and your terms of service for a legal reader. Do the documents on your website sound like they were written for those three different audiences, or do they all sound like they were written by the same person on the same afternoon? Documents that serve different purposes should read differently, and a code of conduct written in contract language will not do the work of setting a culture.
Glossary
- Code of conduct. A set of behavioral expectations for members, volunteers, staff, participants, and guests, including enforcement procedures. Not a legal contract, but usable to support disciplinary action.
- Community guidelines. Norms governing how people interact in a shared physical or digital space, covering tone, respectfulness, and constructive discussion alongside specific prohibitions. Enforced by removing content or suspending accounts.
- Terms of service. A binding legal contract between the organization and a user of a website, app, or platform, setting out both parties' rights and responsibilities. Violation can result in legal action.
- Scope. The statement of who a policy applies to, which is the attribute that most often distinguishes these documents: people in your community, users of a space, or users of a service.
- License grant. The terms of service section in which the organization grants users the right to use the service, commonly paired with a clause on who owns content that users post.
- Limitation of liability. The terms of service section that bounds the organization's legal exposure arising from a user's use of the service.
- Enforcement. The action a document authorizes when its rules are broken: removal or termination under a code of conduct, removal of content under community guidelines, legal action under terms of service.
- Psychological safety. The condition a code of conduct exists to create alongside physical safety, meaning that people can participate without fear of harassment, discrimination, or harm.
Related Lessons
- How to Write a Code of Conduct for Your Nonprofit Community
- Inclusive Community Guidelines: Dominant-Culture Norms Hidden in Policies
- Digital Conduct Policies for Nonprofit Staff and Board
- Enforcement Without Ego: How to Handle Code of Conduct Violations
- The Essential Policy Library: 15 Documents Every Nonprofit Needs
Closing
The three documents are not competing versions of the same idea, and the confusion between them is expensive in a specific way: it leaves organizations believing they are covered in situations where they are not. A code of conduct governs behavior between people and gives you a way to respond to harm. Community guidelines govern a space and give moderators something to point at when a post is not harmful but does not belong. Terms of service govern a service relationship and exist to be enforceable.
Most nonprofits do not need all three, and the sequence matters more than the completeness. Start with the code of conduct, because it is the document that determines what happens to a person who is harmed in your community. Add community guidelines when you run spaces where people talk to each other. Add terms of service when you run a platform that holds accounts or data, and get a lawyer to look at that one. Then read them together once a year and make sure they still describe an organization that exists.
Key Takeaways
- A code of conduct sets behavioral expectations for members, volunteers, staff, participants, and guests, and includes enforcement procedures. It is not a contract but supports disciplinary action.
- Community guidelines set norms for a shared space and apply to anyone using it. They are more permissive in tone and enforced by removing content or suspending accounts.
- Terms of service are a binding legal contract with users of a website, app, or platform, covering license grant, intellectual property, limitation of liability, dispute resolution, and privacy.
- All three commonly prohibit harassment, discrimination, hate speech, spam, and illegal content; they differ in emphasis and in what enforcement is available.
- Every nonprofit with members, volunteers, or participants should have a code of conduct. Add guidelines if you run online spaces, and terms of service if users hold accounts or submit data.
- Write the code with community input, the guidelines with moderators and community leaders, and the terms of service with a lawyer or a nonprofit-specific template plus legal review.
- Keep the documents mutually consistent and review them together at least annually against both your current values and your current enforcement capacity.
- Using a code of conduct plus community guidelines and skipping terms of service is a legitimate choice for organizations that do not run a digital platform.
Frequently Asked Questions
Is a terms of service legally required? Only if you are collecting personal data such as email addresses or payment information, or if users are creating accounts. If you have a basic website with no user interaction, you technically do not need one. It is still good practice if you collect any data at all, because the document is where you say what you do with it, and that explanation is easier to write before anyone asks than in response to a complaint.
Can we use someone else's code of conduct as a template? Yes. Many nonprofits and open-source projects publish their codes of conduct precisely so others can build on them. Use them as starting points, then customize for your context: your scope, your reporting routes, your consequences, your appeals process. A code copied verbatim without community input will not be embraced, and a community that had no hand in writing it will treat enforcement as something done to them rather than something they agreed to.
What if someone violates the code of conduct but the terms of service are silent on it? You can still enforce the code of conduct. Terms of service set minimum legal standards for the use of your service; the code of conduct sets your community standards, which are usually higher and cover behavior a contract would never address. If the code says something is unacceptable, you can act on it even where the terms of service do not mention it, provided you follow the enforcement procedure the code itself describes.
Who should approve these documents? For the code of conduct, staff, board, and community together. For community guidelines, the community moderators and staff who will apply them. For terms of service, the board, after legal review. Get broad input on the code of conduct in particular, because it affects everyone in the organization and its authority depends on people recognizing it as theirs rather than as something handed down.
Skill.re