Files
runicgateway.com/src/data/legal.mjs
wtclaude c8a293b8f6 docs(admin): the engagement rules screen, and the privacy inventory an engagement mailer changes
Engagement Phase 12a. The site had pages for where a message goes (Notifications and
email) and what it says (Message templates), and nothing at all for what makes one get
sent -- the four Engagement screens the workstream built.

New page: Engagement rules. Rules, Audiences, the trigger catalog and the send log on
one page, sitting between the two it joins up. Templates already has its own page and
Suppressions is in Troubleshooting, so neither is repeated here.

Two things it exists to state plainly:

  * Every rule ships disabled, including the ones a module brings. "Installed" is not
    "on", and an upgrade whose Team mail went quiet is the same fact.
  * The ceiling is a TREE, not a ladder. The tempting reading -- a staff-only event
    could obviously also go to one person -- is wrong, and the example is the argument:
    "one person" for cheat detection is the player it was detected on.

Troubleshooting gains the symptom that page answers ("nothing is sent for one
particular event"): the rule is off, the rule is dormant, its own cooldown held it, or
the audience is empty.

Privacy: two rows the engagement work makes necessary, and one sentence it made false.

  * app-content claimed "Nothing is cached for offline use". Phase 8 shipped a DataStore
    snapshot of the inbox, so it was untrue -- and that row feeds the generated Play Data
    Safety answers, which is a store-review matter rather than a doc nit. The snapshot now
    has its own row and its own Play mapping (Messages / Other in-app messages; not
    collected by us, stored on the device), and app-content's claim is narrowed to
    everything else.
  * deploy-engagement, for the deployment scope: an address is now used for more than
    getting into an account, there is a delivery log holding a one-way hash of it, and
    there is a suppression list. Its retention line says what is true rather than what a
    reader assumes -- none of these tables has a retention sweep.

PLAY_DATA_SAFETY.md regenerated from the inventory; legal.lastUpdated moved with the page
it dates.

Verified: the whole `verify` chain green -- checkSidebar (plannedSidebar moved with the
live tree), checkFacts 19/19, checkQuickstart 59, checkReference 22, checkLinks 2605,
checkA11y, checkCsp, playDataSafety --check, 42 + 7 tests. Read in a browser as well, in
the served build.

AI-assisted: written with Claude Code.

Co-Authored-By: Claude <noreply@anthropic.com>
2026-09-01 08:11:10 -05:00

54 lines
2.6 KiB
JavaScript

/**
* legal.mjs — the handful of values the legal pages and the signup form must agree on.
* PLAN.md §9, built in phase 6.
*
* ---------------------------------------------------------------------------------------
* WHY THESE THREE THINGS ARE HERE AND NOT IN THE PAGES
* ---------------------------------------------------------------------------------------
* Each is stated in more than one place and would be wrong in exactly one of them:
*
* `minimumAge` /terms says it, /privacy repeats it, the consent sentence beside the
* signup checkbox commits somebody to it, and the Play Data Safety notes
* answer a question about it. Four surfaces, one number (D31).
* `lastUpdated` A legal page with no date is a legal page nobody can reason about, and
* two pages with different dates invites the reader to work out which one
* is stale. They changed together; they say so together.
* `licence` Quoted on /terms and in the footer.
*
* The contact address is deliberately NOT here. It is a `brand.json` field read through
* `src/lib/brand.mjs` (D13), so that changing the published address stays a file copy on a
* mount rather than an edit to the source — and `checkFacts.mjs` fails the build if one is
* typed into any file under `src/`.
*/
export const legal = {
/**
* The date the legal pages last changed, in the format they render it.
*
* Bump it in the same commit that changes what either page says. It is not generated
* from git: a build timestamp would move on every rebuild and tell a reader nothing,
* and a commit date would move when a stylesheet changed.
*/
lastUpdated: '2026-09-01',
/**
* The minimum age to sign up for the beta. The org lead's decision, 2026-08-24 (D31).
*
* Eighteen, chosen over thirteen and sixteen: it is above the children's-consent
* threshold in every EEA state, so consent works as a basis with no parental-consent
* machinery — which this form has no way to obtain and no way to verify. It is the
* simplest thing to state truthfully for a beta that needs twelve people.
*
* A number rather than a sentence because four surfaces render it. What the site can
* actually enforce is a statement, not a check, and every one of those surfaces is
* written to say so plainly rather than implying verification that does not happen.
*/
minimumAge: 18,
/** The licence, quoted on /terms and in the footer. */
licence: {
id: 'GPL-3.0-or-later',
url: 'https://www.gnu.org/licenses/gpl-3.0.html',
},
};