Skip to content

docs(legal): correct the terms and privacy pages to ObjectOS's editions and licence facts (PR 2 of #171) - #294

Merged
os-zhuang merged 1 commit into
mainfrom
claude/pm-dispatch-objectos-ju9td1
Oct 6, 2026
Merged

os-zhuang merged 1 commit into
mainfrom
claude/pm-dispatch-objectos-ju9td1

Conversation

@objectstack-fleet

Copy link
Copy Markdown
Contributor

Fixes #171 — PR 2 of two (ruling 5993036810, Q3). PR 1 (#293) landed as b754364. #167 (the page titles) is a separate card and is not addressed here. Held for the maintainer: it stays a draft until the maintainer approves or merges it.

What this does

Corrects the two legal pages to the licence and edition facts this repository already states, in English and in the zh-Hans entry beside it, and widens rule (c) of check-positioning.mjs so the English text of both pages is scanned for the sentences this PR removes. Nothing else: no MDX, no positioning.ts, no wiring change (the Positioning step in ci.yml, the run-self-tests.mjs entry and pnpm check:positioning are as they were).

Only statements contradicted by in-repo facts are corrected. No new legal term, data-collection practice, retention period, processor or jurisdiction is introduced. Where a sentence's truth depends on facts not in this repository (what ObjectOS Cloud collects), the page says only that ObjectOS Cloud's data handling is governed by its service agreement, and the point is raised below as an open question.

Sources of truth, as read on main @ b754364:

  • README.md:19 ObjectOS is a commercial product; :28-29 the product source is developed privately, there is no open-source edition of ObjectOS; :86-87 the contents of this repository (documentation and site code) are Apache-2.0; :26-27 the name and logo are trademarks not covered by the code licence.
  • content/docs/resources/license.mdx:8-11 two deliveries, ObjectOS Cloud (we operate it) and ObjectOS Self-Managed (you operate it, under a commercial licence), no open-source edition; :94-95 the ObjectStack framework is Apache-2.0; :129-130 FAQ, not open source; :150-152 "ObjectOS Self-Managed validates its license online (Enterprise air-gapped licenses are offline-validated). The open-source ObjectStack runtime has no telemetry, no license check, and no update ping."
  • apps/docs/lib/positioning.ts OBJECTOS_EDITIONS: hosted (ObjectOS Cloud) or self-managed on your own infrastructure (ObjectOS Enterprise), per the maintainer's rulings Q1 and Q2 on [Decision] What does docs.objectos.ai target — the root URL is a redirect, the index title is "ObjectOS | ObjectOS", and the brand is spelled three ways #171.

Every changed sentence

path:line is the line in this PR; the first number is the en entry, the second its zh-Hans sibling, which makes the same claims sentence for sentence.

apps/docs/app/[lang]/terms/page.tsx

Where Before After Fact
:8 / :35 Last updated: May 27, 2026 Last updated: October 6, 2026 the commit date
:12 / :39 License ObjectOS is distributed under the Apache License 2.0. You may use, modify, and redistribute the software in accordance with that license. ObjectOS is a commercial product with no open-source edition. Your use of ObjectOS is governed by the license or service agreement of the edition you use — ObjectOS Cloud or ObjectOS Enterprise. The contents of the repository behind this documentation site (the documentation and the site code) are licensed under the Apache License 2.0, and the open-source ObjectStack framework and its runtime are licensed under the Apache License 2.0 in their own repository. README.md:19, 28-29, 86-87; license.mdx:8-11, 94-95; editions per positioning.ts
:12 / :39 trademark sentence The "ObjectOS" name and logo are trademarks of ObjectStack AI LLC and are not granted under the Apache 2.0 license — see TRADEMARK.md in the repository. unchanged README.md:26-27, true as it stood
:16 / :43 Self-hosted deployments When you run ObjectOS inside your own infrastructure, you are solely responsible for the operation, security, availability, backups, and compliance of that deployment. ObjectStack AI LLC provides no warranty for self-hosted use beyond what the Apache License 2.0 specifies. When you run ObjectOS self-managed inside your own infrastructure (ObjectOS Enterprise), you are solely responsible for the operation, security, availability, backups, and compliance of that deployment, and ObjectStack AI LLC provides no warranty for it beyond what your commercial agreement specifies. When you self-host the open-source ObjectStack runtime instead, it is licensed under the Apache License 2.0, and ObjectStack AI LLC provides no warranty beyond what that license specifies. license.mdx:8-11 (self-managed is under a commercial licence), :94-95 (the open runtime is Apache-2.0); the "you are responsible for your own deployment" substance is kept
:20 / :47 Hosted services Any hosted services operated by ObjectStack AI LLC (for example, the optional control plane or future SaaS offering) are subject to a separate service agreement that will be presented at the time you sign up. Nothing on this site constitutes such an agreement. Any hosted services operated by ObjectStack AI LLC (for example, ObjectOS Cloud) are subject to a separate service agreement that will be presented at the time you sign up. Nothing on this site constitutes such an agreement. license.mdx:8-9, ObjectOS Cloud exists now; the agreement sentence is kept

The "Changes" and "Contact" sections and the contact address are byte-identical.

apps/docs/app/[lang]/privacy/page.tsx

Where Before After Fact
:8 / :31 Last updated: May 27, 2026 Last updated: October 6, 2026 the commit date
:12 / :35 Overview ObjectOS is a customer-hosted runtime. When you self-host ObjectOS inside your own infrastructure, ObjectStack AI LLC does not collect, store, or process the data flowing through your deployment. ObjectOS runs hosted (ObjectOS Cloud) or self-managed on your own infrastructure (ObjectOS Enterprise). When you run ObjectOS self-managed inside your own infrastructure, ObjectStack AI LLC does not collect, store, or process the data flowing through your deployment. The data handling of ObjectOS Cloud is governed by its service agreement, presented at the time you sign up. positioning.ts OBJECTOS_EDITIONS; the Cloud sentence says only what the terms page already says of hosted services (open question 1)
:12 / :35 covered properties This policy describes the limited information we collect when you interact with our public web properties (objectstack.ai, docs.objectstack.ai) and optional cloud services. unchanged open question 2
:20 / :43 What we do not collect We do not collect data that lives inside a self-hosted ObjectOS deployment. The runtime does not phone home, and your application records never leave the perimeter you operate. We do not collect data that lives inside a self-managed ObjectOS deployment (ObjectOS Enterprise) or inside a deployment of the open-source ObjectStack runtime, and your application records never leave the perimeter you operate. ObjectOS Self-Managed validates its license online (Enterprise air-gapped licenses are offline-validated); the open-source ObjectStack runtime has no telemetry, no license check, and no update ping. license.mdx:150-152, quoted as it stands, nothing added

The "What we collect" and "Contact" sections and the contact address are byte-identical.

zh-Hans. Each changed entry is rewritten to the corrected English, sentence for sentence: 商业产品、没有开源版本; 按所用版本(ObjectOS Cloud 或 ObjectOS Enterprise)的许可协议或服务协议; 仓库内容以 Apache License 2.0 授权、开源 ObjectStack 在其自己的仓库中以 Apache License 2.0 授权; 自管部署的保证以商业协议为准、开源运行时以 Apache License 2.0 为准; 托管服务例子改为 ObjectOS Cloud; 隐私页按 Cloud / Enterprise 两个版本陈述, Cloud 的数据处理"受其在你注册时呈现的服务协议约束". The licence-validation sentence uses the wording license.zh-Hans.mdx:130-132 already carries ("ObjectOS Self-Managed 会在线校验许可证(Enterprise 隔离网络许可证为离线校验);开源的 ObjectStack 运行时没有遥测、没有许可证校验、没有更新探活"), and self-managed is 自管, as that page spells it.

The gate change (.github/scripts/check-positioning.mjs, 173 → 189 lines)

Rule (c) only; rules (a) and (b), the ci.yml step, the self-test runner entry and the check:positioning script are untouched.

  • LEGAL names the two pages. englishEntry() keeps a page's en: { … } entry, anchored on the two-space }, that closes it (the inner closers sit at four and six spaces), and blanks everything else character for character, so a finding's path:line is the real line. A page with no such entry, or no file, is a finding ("has no English text this gate can read, so it was not measured"), never a silent pass.
  • Three patterns join STALE: does not phone home, ObjectOS is distributed under the Apache (said of ObjectOS only; the open ObjectStack runtime is, and may say so) and customer-hosted runtime. They apply to the 79 English content/docs sources too, where they have zero hits today; the lowercase open-runtime forms (no license server, no license check, the FAQ question "Does ObjectOS phone home?") stay green by the same design as before.
  • Self-test: two cases, pinned to exact counts. A true en entry beside a zh-Hans entry that carries the stale words gives 0 (the other locale is not read); the three sentences, one wrapped across lines, plus a page with no en entry give 4.
  • The verdict line now ends "… and the en entry of 2 legal pages".

Verification on d5cbe48

The build and the renders were taken from the working tree whose files are byte-identical to d5cbe48 (the commit followed with no further edit; git status clean).

  • pnpm turbo run type-check --continue --force --filter=@objectos/docs then pnpm turbo run build --force, through the shared verify lock: VERDICT command-exit 0 · held the lock 77s; type-check ✓ Types generated successfully, Tasks: 1 successful, 1 total, zero error TS; build Tasks: 1 successful, 1 total. The OG font-fetch warnings in the build log are the container's TLS proxy, as on PR 1.
  • pnpm turbo run test --force under the lock: VERDICT command-exit 0; ✓ 9 self-test(s) passed, including check-positioning.mjs --self-test → ✓ self-test: every rule fails its bad fixture and passes its good one (8 cases, the two new ones at 0 and 4).
  • node .github/scripts/check-positioning.mjs and pnpm run check:positioning (wiring): ✓ positioning: 3 copies equal the constant; the brand is right in 659 pages and 2 llms bodies; no stale sentence in 79 English sources and the en entry of 2 legal pages.
  • node .github/scripts/check-locale-surface.mjs: ✓ every advertised URL has a source file and every source file is advertised; ….
  • node apps/docs/scripts/gen-zh-hant.mjs --check: ✓ zh-Hant: 65 generated file(s) match the zh-Hans sources byte for byte.
  • node .github/scripts/check-translations.mjs: ✓ translations gate passed.
  • Ownership with the workflow's argv (git diff --name-status --no-renames origin/main...HEAD, --actor objectstack-fleet[bot]): TRANSLATION_BOT_LOGIN unset → exit 0, "touches 0 translation artifact(s) and 3 other file(s)"; set to a placeholder → exit 0, ✓ 3 file(s) changed, no translation artifacts touched.
  • Control bytes: the C0/DEL scan over the three files finds nothing.
  • Browser: next start from this build, Playwright Chromium, /terms, /privacy, /zh-Hans/terms, /zh-Hans/privacy at 1440×900 and 390×844. All eight answer 200 with the expected H1 and "Last updated" line, serve the corrected paragraphs, and scrollWidth equals the viewport on every one (no horizontal overflow). The eight screenshots were viewed: no layout regression. The server was stopped by its own PID; the port is free afterwards.

Ablation (one-time; nothing is left in the tree):

  • Self-test fixture flips, on scratch copies of the script, each mutation read back from disk (anchor count 1 → 0, injected count 1): the good legal fixture given ObjectOS is a customer-hosted runtime. → only "a true en entry …" red, 1 finding(s), expected 0, exit 1; the bad fixture's does not phone home changed to does not ring home → only "the three licence sentences …" red, 3 finding(s), expected 4, exit 1.
  • Gate mode on the committed worktree with both pages swapped for their origin/main bytes (blob hashes differ from HEAD's; the three removed sentences counted once each on disk): the original gate (origin/main's script, copied beside the new one so ROOT resolves the same) stays green on that text — the gap this widening closes; the widened gate exits 1 with exactly three (c) findings: terms/page.tsx:12 "ObjectOS is distributed under the Apache", privacy/page.tsx:20 "does not phone home", privacy/page.tsx:12 "customer-hosted runtime".
  • Restore by git checkout HEAD -- path under a trap, proven by git diff HEAD empty, git status clean and each page's blob hash equal to HEAD's; the widened gate is green again on the restored tree.

Open questions for the maintainer

  1. ObjectOS Cloud's data handling. The repository states nothing about what ObjectOS Cloud collects, stores or processes, so the privacy page now says only that its data handling is governed by the service agreement presented at sign-up (the same basis the terms page gives hosted services). If a fuller statement is wanted, it needs facts that are not in this repository and should come from you.
  2. Covered web properties. The privacy page names objectstack.ai, docs.objectstack.ai as the covered properties, while apps/docs/wrangler.jsonc routes this site at docs.objectos.ai and www.objectos.app. The list is deliberately left as it was; whether it should name the objectos.ai properties is your call.

Acceptance notes

  • Observation, not filed: license.mdx also sells Business Self-Managed (single node) as a self-managed delivery. The pages follow ruling Q1's two-edition naming (Cloud, Enterprise) and hang the licence on "the edition you use", so a Business Self-Managed customer is covered by that clause; PR 1 took the same line.
  • Observation, not filed: both legal pages ship their page title as the bare brand ("ObjectOS", the root template with no page title), the shape ruling A fixed for the index. Outside this card's rows and with no bearing on the legal text.
  • Observation, not filed (carrier: none): the comment above the Positioning step in ci.yml still says rule (c) reads the sources under content/docs/; it now also reads the two pages. ci.yml is outside this PR's file surface; a one-line comment fix for whoever next touches it.

维护者速读(草稿)

改了什么。 两个法律页面(服务条款、隐私政策)的英文与简体中文:条款页改三处(许可、自托管部署、托管服务),隐私页改两处(概述、我们不会收集什么),两页的"最近更新"日期改为 2026 年 10 月 6 日。门禁脚本 check-positioning.mjs 的规则 (c) 多扫这两个页面的英文条目,并把本 PR 删掉的三句过时表述加入黑名单。没有碰任何 MDX 文档,没有碰 positioning.ts,没有改 CI 接线。

为什么改。 条款页写着"ObjectOS 以 Apache License 2.0 发布,你可以使用、修改与再分发本软件",隐私页写着"ObjectOS 是客户自托管的运行时,运行时不会回传任何信息"。这与 README(ObjectOS 是商业产品,没有开源版本,只有本仓库的文档与站点代码是 Apache-2.0)和 license.mdx(Self-Managed 在线校验许可证,Enterprise 隔离网络许可证离线校验)正面矛盾,而且是对外发布的法律文本。裁决 5993036810 的 Q3 要求席位改正并在合并前给你看。改法只纠正与仓库事实矛盾的句子:版本写成 Cloud / Enterprise,许可按所用版本的协议走,Apache-2.0 只说仓库内容与开源 ObjectStack,许可证在线校验照 license.mdx 原话写,Cloud 的数据处理只说"受注册时呈现的服务协议约束",不新增任何条款、数据项、保留期或司法辖区。

风险与代价(含回滚)。 影响 docs.objectos.ai 的 /terms 与 /privacy 两页(英文与简中;其他语言回退英文)。风险在措辞而不在代码:类型检查、构建、门禁、翻译门禁全绿,8 张截图(两页 × 两种语言 × 桌面与手机宽度)无版式回归。回滚 = revert 本 PR 的单个 commit(d5cbe48),不涉及数据或部署状态;门禁随之回退,不会误报。两个开放问题(Cloud 的数据处理、隐私页列的域名)不阻塞合并,但要你拍板。

席位意见。

你要做的(一个动作)。 逐句读上面两张表的 before / after(中文条目逐句对应英文),没问题就 Approve 或合并;顺手对两个开放问题各回一句话:Cloud 的数据处理是否就按"受服务协议约束"写;隐私页覆盖的域名要不要改成 docs.objectos.ai / www.objectos.app。


Generated by Claude Code

…ns and licence facts (PR 2 of #171)

The terms page said ObjectOS "is distributed under the Apache License 2.0",
framed the self-hosted warranty on that licence and called the hosted
service "the optional control plane or future SaaS offering". README.md
says ObjectOS is a commercial product with no open-source edition and that
only this repository's contents (docs and site code) are Apache-2.0;
resources/license.mdx names the editions (ObjectOS Cloud, self-managed
ObjectOS Enterprise) and the open-source ObjectStack runtime as the
Apache-2.0 one. The License section now says exactly that, the warranty is
framed on the edition's commercial agreement (and on Apache-2.0 only for
the open ObjectStack runtime), and the hosted-services example is ObjectOS
Cloud. The trademark sentence is kept as it was.

The privacy page called ObjectOS "a customer-hosted runtime" and said "the
runtime does not phone home", against license.mdx ("ObjectOS Self-Managed
validates its license online (Enterprise air-gapped licenses are
offline-validated)"). The overview now states both editions, scopes the
"we do not collect data inside your deployment" claim to self-managed
ObjectOS and the open-source ObjectStack runtime, quotes the licence
validation fact as license.mdx states it, and says only that ObjectOS
Cloud's data handling is governed by its service agreement. The covered
web properties and contact addresses are unchanged.

The zh-Hans entries make the same claims sentence for sentence, and both
pages' "Last updated" lines move to today.

check-positioning.mjs rule (c) now also reads the `en` entry of the two
legal pages (everything else blanked so a finding's line number holds; a
page with no entry is a finding) and gains the three sentences this change
removes: "does not phone home", "ObjectOS is distributed under the
Apache …" and "customer-hosted runtime". The lowercase open-runtime
wording stays green as before. Two self-test cases pin the new scan: a
true `en` entry beside a stale zh-Hans one gives 0, the three sentences
(one wrapped) plus an entry-less page give 4.

Co-Authored-By: Claude <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01FeA1nwBz1ohH65dvffUGKr
@objectstack-fleet

Copy link
Copy Markdown
Contributor Author

维护者速读 · 2026-10-06T00:38Z

改了什么

  • docs.objectos.ai 的「服务条款」和「隐私政策」两页,英文和简中同步改:
    • 条款页改 3 段:许可、自托管部署、托管服务;
    • 隐私页改 2 段:概述、我们不会收集什么;
    • 两页的「最近更新」都改为 2026-10-06。
  • 门禁 check-positioning.mjs 多扫这两页的英文,防止删掉的三句旧话再回来。脚本 173 → 189 行。
  • 别的都没碰:文档正文、定位常量、CI 接线。

为什么改

两页原来的说法和仓库里的事实正面冲突,而且是对外的法律文本:

  • 条款页写「ObjectOS 以 Apache 2.0 发布,可使用、修改、再分发」。实际上 ObjectOS 是商业产品,没有开源版。
  • 隐私页写「ObjectOS 是客户自托管的运行时,不回传任何信息」。实际上自管版会在线校验许可证。
  • 条款页把托管服务称作「未来的 SaaS」,但 ObjectOS Cloud 已经在卖了。

按你 10-05 的裁决 Q3,由席位改正,合并前给你看。这次只改了与 README 和 license 页矛盾的句子:

  • 许可按所用版本(Cloud / Enterprise)的协议走;
  • Apache 2.0 只用来说这个文档仓库,以及开源的 ObjectStack;
  • 许可证校验一句照抄 license 页原话;
  • Cloud 的数据处理只写「受注册时的服务协议约束」。

没有新增任何条款、数据项、保留期或司法辖区。

风险与代价(含回滚)

  • 影响两页,其他语言回退英文。风险在措辞,不在代码:构建、类型检查、各门禁全绿,8 张截图(两页 × 中英 × 桌面/手机)版式正常。
  • 回滚:revert 这一个 squash 提交即可,不涉及数据或部署状态。

席位意见:可以合

我逐句对照了 README.md、license.mdx 和 license.zh-Hans.mdx。中文和英文逐句等价,许可证校验那句和中文 license 页一字不差。

有三处要你拍板,都不阻塞合并:

  1. Cloud 的数据处理:仓库里没有任何关于 Cloud 收集什么数据的事实,所以现在只写「受服务协议约束」。建议这次就这样;你有具体事实再单独补。
  2. 隐私页列的域名:页面写的是 objectstack.ai、docs.objectstack.ai,但这个站点实际挂在 docs.objectos.ai 和 www.objectos.app。按指示没改,要不要改由你定。
  3. 自管版的括号:「自管(ObjectOS Enterprise)」沿用了你批过的版本说法。但 license 页还在卖单机的 Business Self-Managed。这些句子并没有多承诺什么,Business 客户照样落在「你所用版本的协议」之下,只是括号里没点它的名。要点名的话,每种语言改两处括号就行。

你要做的(一个动作)

在 PR #294 上点 Approve(或者直接合并)。上面三问,有意见回我一句;不回就按现状落地。


Generated by Claude Code

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

3 participants