Archived
legal: reconcile Terms with locked 18+ and never-auto-contact decisions; add Privacy Policy
The published Terms directly contradicted two locked safety decisions and the
shipping app copy, and the in-app Privacy Policy link 404'd. Both are legal
exposure under CA SB 243 (companion chatbots) and the AI-companion litigation.
Terms (§1, §11):
- Add an explicit "you must be 18 or older" eligibility statement. The old §11
permitted "Children 13 and over" independently and under-13 via family
accounts — the exact minor path the app's age gate forbids and the litigation
epicenter targets.
- Replace §11 "Children and Family Accounts" with an honest "Safety Features"
section. Removes the Hard Bell auto-notify block ("emergency services and
trusted contacts are notified first", "cannot be changed") and the
mandatory-reporting clause ("emergency services or relevant authorities may
be contacted", "cannot opt out") — both promised an automatic escalation the
product does not perform. New copy matches the app: Neuron shows you 988 and
how to reach a contact you chose; it never contacts anyone on your behalf;
there is no automatic escalation.
Privacy Policy (new):
- Add src/privacy.el + register it in main.el (generation, /legal/privacy route,
state pointer, sitemap). Fixes the in-app link, which pointed at
/legal/privacy (404 — no route, no doc existed).
- Ported from docs/legal/privacy-policy-companion-DRAFT.md (2026-07-14):
local-first, 18+, and never-auto-contact stated verbatim from the locked draft.
- Wire privacy.html through Dockerfile.stage / Dockerfile / deploy.yaml; add the
secondary /legal/privacy route to server.el for parity.
PENDING ATTORNEY (Daniel) SIGN-OFF before merge/publish. Bracketed legal
decisions (governing law, effective date, retention periods) left for counsel.
This commit is contained in:
@@ -55,7 +55,7 @@ jobs:
|
||||
echo "$CHANGED"
|
||||
# Asset-only: files that don't require rebuilding the El binary.
|
||||
# migrations/, scripts/, tests/ are data/infra/test changes — no binary rebuild needed.
|
||||
NON_ASSET=$(echo "$CHANGED" | grep -v '^src/assets/' | grep -v '^src/shares/' | grep -v '^src/index\.html' | grep -v '^src/about\.html' | grep -v '^src/terms\.html' | grep -v '^src/enterprise-terms\.html' | grep -v '^src/llms\.txt' | grep -v '^migrations/' | grep -v '^scripts/' | grep -v '^tests/' | grep -v '^\.gitea/' | grep -v '^$' || true)
|
||||
NON_ASSET=$(echo "$CHANGED" | grep -v '^src/assets/' | grep -v '^src/shares/' | grep -v '^src/index\.html' | grep -v '^src/about\.html' | grep -v '^src/terms\.html' | grep -v '^src/privacy\.html' | grep -v '^src/enterprise-terms\.html' | grep -v '^src/llms\.txt' | grep -v '^migrations/' | grep -v '^scripts/' | grep -v '^tests/' | grep -v '^\.gitea/' | grep -v '^$' || true)
|
||||
if [ -z "$NON_ASSET" ] && [ "$CHANGED" != "unknown" ]; then
|
||||
echo "asset_only=true" >> "$GITHUB_OUTPUT"
|
||||
echo "=> Asset-only change detected, will use fast path"
|
||||
@@ -104,7 +104,7 @@ jobs:
|
||||
- name: Touch HTML placeholder files
|
||||
# El binary regenerates these at startup via fs_write. They must exist
|
||||
# in the build context for Dockerfile COPY to succeed.
|
||||
run: touch src/index.html src/about.html src/terms.html src/enterprise-terms.html
|
||||
run: touch src/index.html src/about.html src/terms.html src/privacy.html src/enterprise-terms.html
|
||||
|
||||
# ── El SDK setup ──────────────────────────────────────────────────────
|
||||
|
||||
|
||||
Reference in New Issue
Block a user