# Legal Drafts (Counsel Review Required)

**Status:** Working drafts for [AV-T40](../mvp/TODO.md), [AV-T41](../mvp/TODO.md), and [AV-T42](../mvp/TODO.md). **Not legal advice.** Do not publish or link from signup/checkout until [AV-T22](../mvp/TODO.md) counsel review.

## Online Template Sources Used

| Source | License | Used for | URL |
|---|---|---|---|
| [37signals / Basecamp open policies](https://github.com/basecamp/policies) | [CC BY 4.0](https://creativecommons.org/licenses/by/4.0/) | Structure and clause patterns for privacy, terms, abuse, copyright/DMCA | https://github.com/basecamp/policies |
| [37signals live policies](https://37signals.com/policies/) | CC BY 4.0 (same lineage) | Current reference for subprocessors, GDPR sections | https://37signals.com/policies/privacy |
| [PolicyGen](https://github.com/imothee-io/policygen) | MIT | Alternative generator if regenerating from JSON config | https://policygen.dev/ |
| [ClauseKeeper](https://github.com/mityda/ClauseKeeper) | AGPL-3.0 | Optional compliance scanner / rule-based generator | https://github.com/mityda/ClauseKeeper |

## Audio Vault Drafts in This Folder

| File | Task | Product facts wired in |
|---|---|---|
| [privacy.md](privacy.md) | AV-T40 | Muse & Machine LLC, AcoustID/MusicBrainz, R2 US, Stripe, Resend auth mail, no export until beta ([D-120](../mvp/DECISIONS.md#legal-policies-and-accessibility)) |
| [terms.md](terms.md) | AV-T41 | Owner-only private library; $49/mo USD plan, trial, grace, simulated streamer, cancellation, **EU/EEA/UK/Norway statutory refund and withdrawal draft** |
| [content-policy.md](content-policy.md) | AV-T42 | Owner-only private library; no sharing or distribution; abuse@ + privacy@; DMCA notice outline |

## PWA and Signup Links (Draft)

The library PWA (`docs/app.html`) links to these drafts from the footer, Settings, and signup (terms acceptance checkbox + privacy/metadata consent). Links use in-repo Markdown paths until counsel approval ([AV-T22](../mvp/TODO.md)) and production URLs at go-live. Checkout withdrawal acknowledgments remain for Stripe UI ([AV-T41](../mvp/TODO.md)).

## Attribution (Required for Cc by Adaptations)

> Audio Vault policy drafts adapted from the [Basecamp open-source policies](https://github.com/basecamp/policies) / [CC BY 4.0](https://creativecommons.org/licenses/by/4.0/). Substantially modified for Muse & Machine LLC and Audio Vault product decisions in [DECISIONS.md](../mvp/DECISIONS.md).

## Before Go-Live Checklist

- [ ] Qualified counsel review ([AV-T22](../mvp/TODO.md))
- [ ] Working **`abuse@audiovau.lt`**, **`privacy@audiovau.lt`**, and **`support@audiovau.lt`** mailboxes ([AV-T43](../mvp/TODO.md)); Resend domain verified for auth mail ([D-131](../mvp/DECISIONS.md#infrastructure-and-operations))
- [ ] No **`export@`** mailbox until public beta ([D-120](../mvp/DECISIONS.md#legal-policies-and-accessibility))
- [ ] Register DMCA agent with U.S. Copyright Office if claiming §512 safe harbor
- [ ] Stripe Customer Portal and checkout disclosure links match published URLs
- [ ] EU/UK DPA and Norway/EEA obligations reviewed ([AV-R33](../mvp/REQUIREMENTS.md))
