feat(legal): phase 6 — the privacy policy and the terms #9
Reference in New Issue
Block a user
No description provided.
Delete Branch "feat/phase-6-legal"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
PLAN.md §9.
/privacy,/terms, the footer links, and the Play Data Safety notes.AI-assisted: written with Claude Code (Claude Opus 5).
The four decisions, taken before either page was written
Recorded in
PLAN.md§9 under "How phase 6 built the legal pages" — the count of record is now thirty-three.PLAY_DATA_SAFETY.mdis generated fromsrc/data/collection.mjsand checked in CI.What the pages are
/privacyis three separately-scoped sections, because "we" means three different parties and §9 is explicit that conflating them "would be wrong in both directions":Every row names the file it was read out of.
checkFacts.mjscannot verify prose, so the citation is what a reviewer uses instead — and a row that cannot name its source is a row somebody guessed./termsgoverns only what we run: this site, the beta list, the APK we publish. The software is governed by its licence; a community's deployment by that community. A terms page claiming authority over every installation of a GPL program is both unenforceable and the single thing a generated template most reliably gets wrong.Also in this PR
CONSENT_TEXT, which is stored per row rather than versioned — so rows written from now on carry the new sentence and older rows keep theirs.CONSENT_VERSIONgained a suffix rather than a new date: the change landed on the day the original wording was written, and two sentences must not share the label an operator groups a CSV by.PLANNED_ROUTESis now empty. These were its last two entries, and its reverse check is what forced the deletion. The list stays — §10's documentation routes land in phases 7 and 8 under the same convention.test/legal.test.mjsasserts what no build check can see: every scope renders something (an empty section reads as a claim, not an omission), every app row maps to a console question, and every mapped row still answers "not collected, not shared" — failing with the reason, so a telemetry endpoint added later cannot produce a row that contradicts the lede three inches above it.--checknormalises line endings. The repo has no.gitattributesand Windows checkouts runcore.autocrlf=true, so a byte comparison would fail for every Windows developer while passing in CI — the worst shape a check can have.Verification
npm run verifygreen end to end: tokens · brand · data safety ·astro check(0 errors) · 36 tests · build · 214 links · 19 facts.🤖 Generated with Claude Code
PLAN.md §9. Builds /privacy and /terms, links them from the footer on every page, and generates the Play Data Safety notes from the same inventory the policy renders. Four decisions taken by the org lead before either page was written, recorded in §9 under "How phase 6 built the legal pages": D30 DNS-only records, so the reverse proxy on the host keeps the only access log. Described qualitatively — the retention belongs to the proxy, and a policy that quotes a number the deployment does not enforce is worse than one that does not. D31 Eighteen or older. Above the children's-consent threshold everywhere in the EEA, so consent works with no parental-consent machinery this form could not honestly operate. Four surfaces render it from src/data/legal.mjs, and every one says plainly that nothing verifies it. D32 No governing-law clause. Nothing of value is contracted for here. D33 PLAY_DATA_SAFETY.md is generated from src/data/collection.mjs and checked in CI, so the published policy and the answers given to Google cannot drift. /privacy is three separately-scoped sections because "we" means three different parties: this site (one form, no cookies, no third-party requests), the Android app (we operate no server it talks to — the rows are what the DEVICE holds), and a self-hosted deployment (the operator is the controller, not us). Every row names the file it was read out of, because a policy is the document most likely to be written from a template and least likely to be re-read against the software. /terms governs only what we run: this site, the beta list, and the APK we publish. The software is governed by its licence, and a community's deployment by that community — a terms page claiming authority over every install of a GPL program is the thing a generated template gets wrong. Also here: - the age clause changed CONSENT_TEXT, so CONSENT_VERSION gained a suffix; rows written from now on carry the new sentence and older rows keep theirs - PLANNED_ROUTES is now empty — these were its last two entries, and its reverse check is what forced the deletion; the list stays for phases 7 and 8 - test/legal.test.mjs asserts the structural promises no build check can see, including that every mapped Play row still answers "not collected, not shared" - --check normalises line endings: the repo has no .gitattributes and Windows checkouts are CRLF, so a byte comparison would fail for every Windows developer while passing in CI Verified: npm run verify green end to end (tokens, brand, data safety, astro check, 36 tests, build, 214 links, 19 facts), both pages walked in a browser, and neither overflows at 390px. One defect the checks could not see and a look could: the retention line was being pushed to the foot of the tallest card in its row, opening a void in the middle of the short ones. Co-Authored-By: Claude <noreply@anthropic.com>