legal: reconcile Terms with locked 18+ and never-auto-contact decisions; add Privacy Policy

The published Terms directly contradicted two locked safety decisions and the
shipping app copy, and the in-app Privacy Policy link 404'd. Both are legal
exposure under CA SB 243 (companion chatbots) and the AI-companion litigation.

Terms (§1, §11):
- Add an explicit "you must be 18 or older" eligibility statement. The old §11
  permitted "Children 13 and over" independently and under-13 via family
  accounts — the exact minor path the app's age gate forbids and the litigation
  epicenter targets.
- Replace §11 "Children and Family Accounts" with an honest "Safety Features"
  section. Removes the Hard Bell auto-notify block ("emergency services and
  trusted contacts are notified first", "cannot be changed") and the
  mandatory-reporting clause ("emergency services or relevant authorities may
  be contacted", "cannot opt out") — both promised an automatic escalation the
  product does not perform. New copy matches the app: Neuron shows you 988 and
  how to reach a contact you chose; it never contacts anyone on your behalf;
  there is no automatic escalation.

Privacy Policy (new):
- Add src/privacy.el + register it in main.el (generation, /legal/privacy route,
  state pointer, sitemap). Fixes the in-app link, which pointed at
  /legal/privacy (404 — no route, no doc existed).
- Ported from docs/legal/privacy-policy-companion-DRAFT.md (2026-07-14):
  local-first, 18+, and never-auto-contact stated verbatim from the locked draft.
- Wire privacy.html through Dockerfile.stage / Dockerfile / deploy.yaml; add the
  secondary /legal/privacy route to server.el for parity.

PENDING ATTORNEY (Daniel) SIGN-OFF before merge/publish. Bracketed legal
decisions (governing law, effective date, retention periods) left for counsel.
This commit is contained in:
2026-07-21 09:54:47 -05:00
parent b87b0bed24
commit 4989641b39
7 changed files with 177 additions and 23 deletions
+4
View File
@@ -16,6 +16,7 @@
// GET /api/founding-count {"sold":N,"total":N,"remaining":N}
// GET /assets/* static files under $LANDING_ROOT/assets/
// GET /brand/* static files under $LANDING_ROOT/assets/brand/
// GET /legal/privacy privacy.html
// GET /<other> 404 JSON
// Path helpers
@@ -118,6 +119,9 @@ fn handle_request(method: String, path: String, body: String) -> String {
if str_eq(clean, "/legal/terms") {
return fs_read(root_dir() + "/terms.html")
}
if str_eq(clean, "/legal/privacy") {
return fs_read(root_dir() + "/privacy.html")
}
if str_eq(clean, "/about") {
return fs_read(root_dir() + "/about.html")
}