返回 CodeWhale
legal-content.tsx
根目录 / web / vendor / legal-documents / legal-content.tsx
1 // Shared verbatim legal content. Presentation differs by client; policy does not.
2 // Bracketed capitals such as [LIKE THIS] are placeholders for the founder to
3 // fill and approve. A document carrying one never takes effect:
4 // apps/web/tests/legal-paid-terms.test.ts refuses it once its metadata does.
5 // Founder facts, 2026-10-04: the seller is Shannon Labs, Inc., a Delaware
6 // corporation based in San Francisco; the paid terms take California law and
7 // San Francisco County courts. "Shannon Labs" alone names only the brand.
8 //
9 // Both documents are in effect from October 4, 2026 (founder decision, chat,
10 // 2026-10-04; LEGAL_DOCUMENTS in packages/contracts/src/legal-documents.js).
11 // Each page's status line comes from that record, so neither body carries a
12 // draft notice.
13
14 // The privacy policy effective October 4, 2026, served at /legal/privacy. It
15 // replaced the policy effective August 21, 2026 (plan step 19). It keeps that
16 // policy's sections word for word except the opening line, "Questions and
17 // requests" and "Changes", and adds who we are, the service providers we use
18 // and how payments are handled.
19 export function PrivacyContent() {
20 return <>
21 <p>This policy explains how Shannon Labs, Inc. (“we” or “us”) handles information when you use Codewhale, a Shannon Labs product.</p>
22 <section><h2>Information we collect</h2><p>We collect the identity information needed to create and protect your account, including your GitHub identity, display name, and a primary verified email when GitHub makes one available. We also store product information you create, such as preferences, projects, conversations, Work runs, approvals, usage totals, purchased-balance and payment receipts, and security or operational receipts. Codewhale does not store full payment-card details.</p></section>
23 <section><h2>How we use it</h2><p>We use this information to authenticate you, operate and secure Codewhale, preserve your requested product state, provide support, and—only when you have enabled the relevant communication—send product or waitlist updates. We do not sell personal information.</p></section>
24 <section><h2>Storage and processing</h2><p>Codewhale is one global product. There is no residency selector, no region-specific account, and no promise that your account data stays in a particular jurisdiction. Account authentication and session state is stored in Cloudflare Durable Objects, today configured in Cloudflare’s US jurisdiction; that placement is an operational choice we may change, and we will update this policy when we do. Durable product state is owned by Codewhale’s private product runtime. Cloudflare may perform TLS, request routing, and cryptographic processing on its global edge, so we do not describe edge processing as US-only. Hosted compute is a separate system from account storage and, when enabled, identifies its placement before launch.</p></section>
25 <section id="processors"><h2>Service providers</h2>
26 <p>We use these service providers to run Codewhale. Each processes information only as needed to provide its service to us.</p>
27 <p><strong>Stripe</strong> processes payments, calculates sales tax, and handles receipts, refunds and payment disputes when you make a purchase.</p>
28 <p><strong>Vercel AI Gateway</strong> routes the Codewhale-managed AI requests paid for from your AI balance, and <strong>DeepInfra</strong>, the model provider it uses today, serves the model and processes each request. Any other managed route uses the provider or gateway the product identifies, as described below.</p>
29 <p><strong>Cloudflare</strong> hosts the Codewhale web app and API, routes and secures requests, and stores account authentication and session state.</p>
30 <p><strong>Supabase</strong> provides sign-in and the database that holds your account and product records.</p>
31 <p><strong>PostHog</strong> may receive the anonymous usage totals described under Settings, Usage data, and only while that setting is on: whole-number counts and a random install identifier that is not tied to your account, never your content.</p>
32 <p><strong>Resend</strong> delivers email we send you.</p>
33 <p>Services you connect yourself, such as GitHub or your own model provider, handle information under their own terms.</p>
34 </section>
35 <section id="payments"><h2>Payments</h2><p>When you buy a pack, you pay on a checkout page hosted by Stripe. Your card details go to Stripe and never reach Codewhale’s servers. To open checkout we give Stripe your account identifier and, when we have it, your email address; Stripe collects the billing details it needs to take the payment and calculate tax. We keep a record of each purchase: Stripe’s identifiers for you and for the payment, what you bought, the amounts charged (price, Platform fee and tax), the payment’s status, and any refund or dispute. We use these records to grant and account for your balance, answer your questions, prevent fraud, and meet tax and accounting duties, and we keep them as long as those duties require, including after account deletion. Stripe also uses payment information under its own privacy policy, including to prevent fraud.</p></section>
36 <section><h2>Model providers and repositories</h2><p>When you use bring-your-own-key inference, Codewhale sends the content needed for the request to the provider you connect, under your provider agreement. When you use managed inference, Codewhale sends the required prompt, context, tool results, and response data through the model provider or gateway identified by the product. Managed operator credentials remain inside Codewhale&apos;s trusted broker and are not exposed to you or to a provider sandbox. Provider retention, training, and regional processing are governed by the selected provider&apos;s terms and disclosed controls. Repository access is limited to the grants you approve with the source provider.</p></section>
37 <section><h2>On-demand execution providers</h2><p>When a managed run starts a cloud sandbox, Codewhale sends the repository content, instructions, environment values, and session data needed for that work to the execution provider and region identified before launch. The sandbox is ephemeral capacity acquired for that run and released afterward. Computer Use, when available, provides interactive control inside the live sandbox. Durable account, Agent, task, repository binding, artifact, and explicitly retained workspace state is stored separately. Provider-backed resources are not treated as deleted until the provider confirms deletion.</p></section>
38 <section><h2>Retention and deletion</h2><p>You can review export and deletion controls after signing in under Account, Data &amp; privacy. Content is deleted according to the displayed retention and deletion process. Privacy-minimal security, audit, deletion, and financial receipts may be retained when necessary to prove an action, prevent abuse, or meet legal obligations. Provider-backed resources are not treated as deleted until the provider confirms deletion.</p></section>
39 <section id="contact"><h2>Questions and requests</h2><p>Use Account, Data &amp; privacy after signing in to request an export or deletion. For anything else, or if you cannot sign in, email <a href="mailto:help@codewhale.net">help@codewhale.net</a>.</p></section>
40 <section><h2>Changes</h2><p>This version replaces the policy effective August 21, 2026. It adds who we are, the service providers we use, how payments are handled, and how to contact us. We may update this policy as the product and its processors change. The effective date above identifies the version that applies.</p></section>
41 </>;
42 }
43
44 export function TermsContent() {
45 return <>
46 <p>These terms govern your use of Codewhale, a Shannon Labs product provided by Shannon Labs, Inc., a Delaware corporation (“we” or “us”). By creating an account or using the service, you agree to them. You can reach us at <a href="mailto:help@codewhale.net">help@codewhale.net</a>.</p>
47 <section><h2>Your account</h2><p>You are responsible for your account, connected providers, repositories, runners, and credentials. Keep access methods secure and provide accurate information. Do not share authority you are not permitted to grant.</p></section>
48 <section><h2>Acceptable use</h2><p>Do not use Codewhale to break the law, harm people or systems, evade access controls, distribute malware, interfere with the service, or process data you lack authority to use. Automated actions remain subject to the permissions, reviews, and stop conditions shown in the product.</p></section>
49 <section><h2>Your content and connected services</h2><p>You retain ownership of your content. You give us the limited permission needed to process it to provide Codewhale. With bring-your-own-key, the model provider you connect processes content and bills you under your agreement with it. With Codewhale-managed inference or a managed cloud sandbox, we may process the content needed for your request through the model, gateway, repository, and execution providers identified by the product. Computer Use, when available, is interactive screen, mouse, and keyboard control inside the selected computer. Those providers have their own terms. You must have authority to use every account, repository, credential, and item of content you provide.</p></section>
50 <section id="purchases"><h2>Purchases and balances</h2>
51 <p>You can buy packs of prepaid balance. Shannon Labs, Inc. is the seller, Stripe processes the payment, and every price is in US dollars. Packs are offered to buyers internationally where the service and payment method are available.</p>
52 <p>Codewhale keeps two separate prepaid balances: an AI balance for Codewhale-managed AI models, and a computer balance for hosted computer time when that is offered. Each is bought with its own packs, and neither balance ever pays for the other.</p>
53 <p>We deduct managed AI use from your AI balance at the model provider’s price for the model and route used, for input, cached input and output tokens, with no markup. Before a request is sent, we reserve the most it could cost at that price. If it ends before the provider reports its usage, for example because you cancel it mid-reply, the connection drops or it times out, we deduct that reserved amount. Using your own provider key never spends either balance; that provider bills you under your agreement with it.</p>
54 </section>
55 <section id="platform-fee"><h2>Platform fee</h2><p>Each purchase of AI balance includes a Platform fee, shown as its own line at checkout before you pay and on your receipt. The Platform fee is our charge for providing Codewhale. It is the same however you pay, and it is not added to your balance.</p></section>
56 <section id="no-automatic-charges"><h2>No automatic charges</h2><p>Every purchase is one you make yourself. Codewhale has no subscription, automatic top-up, overage or postpaid charge, and we never charge your payment method again without a new purchase from you.</p></section>
57 <section id="expiry"><h2>Expiry</h2><p>A pack’s balance expires 12 months after it is added to your account, which is normally when your payment completes. Checkout states this before you pay, and your receipt and your account show the expiry date. Expired balance cannot be used. Within a balance, whatever expires first is spent first, including a free starter.</p></section>
58 <section id="at-zero"><h2>When a balance runs out</h2><p>When a balance reaches zero, the managed use it pays for stops until you add more. Nothing is bought for you, and a balance never goes below zero. We may warn you when a balance is running low. Your own provider keys keep working.</p></section>
59 <section id="taxes"><h2>Taxes</h2><p>Prices do not include tax. Where sales tax or a similar tax applies, checkout calculates it from the billing details you give, shows it before you pay, and adds it to the total.</p></section>
60 <section id="refunds"><h2>Refunds</h2>
61 <p>If you ask within 30 days of a purchase, we refund the unspent part of that pack in full: the same share of everything you paid for it, including its Platform fee and any tax. A pack you have not used is refunded in full.</p>
62 <p>A refund takes back the whole balance it pays for, so refunded balance can no longer be spent. Balance you have already used stays used. After 30 days, refunds are at our discretion. Nothing here limits a refund the law requires.</p>
63 <p>To ask for a refund, email <a href="mailto:help@codewhale.net">help@codewhale.net</a> from the address on your account. Refunds go back to the original payment method.</p>
64 </section>
65 <section id="disputes"><h2>Payment disputes</h2><p>If something is wrong with a charge, please contact us first so we can fix it or refund it under the terms above. If you dispute a payment with your bank or card issuer, we pause all Codewhale-managed use on your account, including managed AI, while the dispute is open. If the dispute is withdrawn or closes in our favor, the pause ends. If it closes in your favor, the pause stays until we review the account, and we may remove the balance the disputed payment added. Your own provider keys keep working throughout.</p></section>
66 <section id="free-starter"><h2>Free starter</h2><p>A new account may receive a one-time free starter of AI balance and, when hosted computer time is offered, computer time, in the amounts the product shows. It opens on your first managed use and lasts 30 days from then. It is limited to one per person and cannot be bought, refunded, transferred or exchanged for cash. New starters are limited each day, so one may not be available right away. We may withhold or remove a starter obtained through extra accounts or other abuse.</p></section>
67 <section><h2>Service changes and termination</h2><p>We may change, suspend, or discontinue features and may restrict accounts that violate these terms or threaten the service. If we stop offering what a balance pays for, or close your account for a reason other than a breach of these terms, we refund your unspent purchased balance. Deleting your account ends its balances, so ask for any refund you are due first. Required security, audit, deletion, and financial receipts may survive account deletion as described in the privacy policy.</p></section>
68 <section><h2>Disclaimers and liability</h2>
69 <p>Codewhale is provided on an “as is” and “as available” basis to the extent permitted by law. Software agents can make mistakes; review important changes and keep independent backups. We do not promise uninterrupted or error-free operation and are not responsible for third-party services outside our control.</p>
70 <p>To the extent the law allows, we are not liable for indirect, incidental, special, consequential or punitive damages, or for lost profits, revenue, data or goodwill, and our total liability for all claims relating to Codewhale is limited to the amount you paid us for Codewhale in the 12 months before the event giving rise to the claim. Nothing in these terms limits liability that the law does not allow to be limited.</p>
71 </section>
72 <section id="governing-law"><h2>Governing law</h2><p>These terms are governed by the laws of the State of California, United States, without regard to its conflict-of-laws rules. Claims are brought in the state or federal courts located in San Francisco County, California, unless the law where you live gives you the right to bring them elsewhere. Nothing in these terms takes away rights you have under consumer protection laws that cannot be waived by contract.</p></section>
73 <section><h2>Changes</h2><p>When we change these terms, we update the date above. The version in effect when you buy a pack governs that purchase, and purchases made before these terms took effect keep the terms they were sold under. A change never shortens the expiry or reduces the balance of a pack you have already bought.</p></section>
74 </>;
75 }
76
76 lines Plain Text