Legal TODO
Tracking legal elements/pages that need to be added, updated, or completed. Items marked ⚠ COUNSEL require a legal/business decision before publishing. Items checked[x] were applied to terms-of-use.mdx (v0.7) / privacy-policy.mdx (v0.8); latest pass 2026-05-22.
Analytics: PostHog replaced with self-hosted, open-source Matomo (in-house); Google Analytics and Sentry retained.
Affiliate / Exchange Disclosure
- Affiliate Disclosure page —
legal/affiliate-disclosure.mdxfinalized (May 22, 2026): removed the draft TODO, discloses commission + geo-gating in FTC-clear wording, cross-links to ToS/PP, contact set to info@. Per owner request the page is kept generic — it does NOT name the exchanges or state live scope; those specifics live in ToS §5.3. Counsel sign-off still recommended. - Exchange naming — handled in ToS §5.3 and PP §6 (affiliate page intentionally defers to them).
- Affiliate page per-exchange policy links — optionally add direct links to each exchange’s terms/privacy/AML on the affiliate page (currently cross-linked via ToS §3.5 / PP §6).
- Name all six exchanges — Binance, OKX, Bybit, KuCoin, Indodax, Tokocrypto disclosed individually in ToS §3 and PP §6 (each a separate legal entity / independent data controller).
- Affiliate links live only for Bybit & KuCoin — business/counsel to confirm scope before launch (no longer stated on the affiliate page). Binance/OKX/Indodax/Tokocrypto links currently disabled.
- ⚠ COUNSEL — placeholder benefit figures — do NOT publish placeholder promo figures (e.g. “-20% fees”, “$10,000 rewards”); replace with contractually accurate terms or risk advertising-law exposure.
- Update Terms of Use affiliate section — ToS §5.3 (formerly §4.3) updated: names the six exchanges, discloses commission, adds geo-gating; uses “affiliate” terminology throughout.
Exchange Legal-Document Links
- Embed exchange legal links — referenced in ToS §3.5 (exchange Terms) and PP §6 (exchange Privacy Policies). Links verified working on 2026-05-19; re-check before publishing. Note: only Terms (ToS) and Privacy (PP) are embedded; AML/compliance links are not embedded in the user-facing docs (most exchanges have no standalone AML URL — see notes below).
Notes on gaps (no standalone, verifiable AML-policy URL exists):
- Binance — no global standalone AML page; AML is inside the Terms. The dedicated compliance page exists only on the US entity. The global Privacy Notice is jurisdiction-specific, so the Privacy Portal is the canonical entry point.
- Bybit — no standalone canonical AML document; the User Protection & Compliance page is the closest official page. AML obligations are also embedded in the Terms.
- KuCoin — no standalone public AML/CTF URL; AML/CTF content is incorporated into the Terms of Use and Privacy Policy.
- Indodax — no standalone AML page; AML/CFT is covered within the Terms and Privacy Notice. Help-center pages are bot-protected (HTTP 403 to automated browsers) but confirmed published.
- Tokocrypto — all three documents (incl. a dedicated AML/CFT policy) confirmed via the help-center API.
Privacy Policy updates
- Disclose exchange/portfolio financial data collected — PP §2 now covers credentials, balances/holdings, full trade/order/transfer/ledger history, open positions & PnL, net-worth history, public wallet addresses and on-chain transaction IDs, with a sensitivity warning.
- Sub-processor list — PP §6 “Third Parties and Sub-Processors” lists the 6 exchanges, AWS, Alchemy, CoinGecko, the LLM providers, and the existing analytics/payment processors.
- AI provider transparency — PP §7 names the LLM providers (OpenAI, Anthropic, Google, Groq, xAI, DeepSeek), discloses that portfolio data is sent as context, and notes routing varies by tier/backend.
- ⚠ COUNSEL — DeepSeek routing — decided (disclosed in PP §7) & applied; counsel still to confirm acceptability of China-based routing of financial data for EU/UK users.
- ⚠ COUNSEL — full-history ingestion — lawful basis stated as Contract in PP §2 & applied; counsel to confirm (GDPR Art. 6).
- ⚠ COUNSEL — retention period — event-based retention adopted & applied in PP §4 (retained until disconnect/account deletion); counsel to confirm against GDPR Art. 5(1)(e) storage limitation.
- Document deletion mechanics — PP §5 “Erase” extended: disconnect hard-deletes that exchange’s data; account deletion cascades to all portfolio data. Cross-references
legal/account-deletion.mdx. - Net-worth snapshot retention — disclosed in PP §2 and §4 (retained for the life of the account, deleted on account deletion).
- International data transfer disclosure — PP §8 “Third-Party Processing” updated for the new sub-processors and the EU/US/Singapore/China jurisdictions.
- Per-exchange data-coverage differences — noted in PP §2 (some connected exchanges provide spot-only data).
Terms of Service / Terms of Use updates
- Read-only API key / non-custodial disclaimer — ToS §3 “Read-Only Exchange Connections” added: read-only keys only, no order-execution/trading/withdrawal capability.
- No financial advice for AI portfolio commentary — ToS §4.4 added covering AI-generated commentary on the user’s connected portfolio.
- NFA / DYOR disclaimer — extended in ToS §4 (informational only, not advice, DYOR, consult professionals).
- Jurisdiction / eligibility clause — ToS §5.3 documents affiliate-link geo-gating (sanctions: Iran/North Korea/Cuba/Syria; UK FCA regime; per-exchange blocks) and clarifies it affects affiliate-link display only.
Critical review findings (2026-05-22) — counsel / engineering required
From the four-agent legal review of PR #77. These are NOT pure wording fixes — each needs a legal or engineering decision before launch.- ⚠ COUNSEL — EU & UK Art. 27 representatives (MISSING) — a US-only controller serving/monitoring EU/UK users must appoint, and disclose, both an EU and a UK representative. Neither is named. Standalone GDPR breach.
- ⚠ COUNSEL — DeepSeek/China transfer mechanism — bare “SCCs where applicable” is likely indefensible for China (no adequacy; Schrems II TIA; live DPA bans on DeepSeek in Italy/Germany). Exclude DeepSeek for EU/UK users or hold a documented TIA. (Strengthens the existing DeepSeek item.)
- ⚠ COUNSEL — UK FCA core-service exposure — ToS §5.3 states geo-gating does not restrict the core Services, but promoting $BRO + AI Alpha to UK consumers may itself be a regulated financial promotion (criminal exposure) regardless of affiliate links. Decide: geo-block core promotional/AI Alpha/token surface for the UK, or obtain a lawful route. ToS currently understates this.
- ⚠ COUNSEL — consumer arbitration clause — ToS §13 mandatory Delaware arbitration is likely unenforceable against EU/UK consumers (UCTD/Brussels Ia) and omits a US class-action waiver. Add a class-action waiver + EU/UK/Canada consumer carve-out.
- ⚠ COUNSEL — CCPA/CPRA California section — add notice-at-collection, California consumer rights, and the SPI right-to-limit (exchange API credentials = Sensitive Personal Information under CPRA). Currently only one line.
- ⚠ COUNSEL — Art. 22 profiling/ADM disclosure — disclose the existence, logic, and significance of AI profiling of user portfolios (AI Alpha, portfolio commentary).
- ⚠ COUNSEL — lawful-basis reconciliation — ToS §9.2 grants a “perpetual license … for training” while PP §7 says LLM data is used “solely to generate the response you requested.” Reconcile, and give training/improvement its own basis (consent or LI + balancing test).
- ⚠ COUNSEL — ePrivacy cookie/analytics consent — GA/Matomo/Sentry client SDKs require prior opt-in consent in EU/UK; PP labels analytics “legitimate interest” in places. Confirm the cookie banner is prior, granular, opt-in and align the stated basis.
- ⚠ COUNSEL — MSB/custody framing — ToS §2 states “not a money-services business / not a custodian” as fact. Soften to a position and obtain a FinCEN + state-MTL + $BRO buy-back-mechanic memo.
- ⚠ COUNSEL — AML/sanctions reconciliation — ToS §1.2 and §5.3 carry two different sanctions lists; reference the live OFAC program rather than enumerating, and align the “we screen users” claim with the identity data actually collected (social/email login + read-only key, no KYC).
- ⚠ COUNSEL — Indonesia PDP Law cross-border transfer — transfers of Indonesian users’ financial data to the US/China need a PDP-compliant mechanism (in addition to the PSE/ITSK reviews below).
- ⚠ COUNSEL — DPIA — perform and document a Data Protection Impact Assessment (large-scale sensitive financial data + portfolio monitoring + China transfer trigger Art. 35).
- In-product affiliate disclosure (FTC) — FTC 16 CFR Part 255 requires a clear-and-conspicuous disclosure adjacent to each affiliate link in-product, not only on the policy page.
- Per-exchange data-coverage table — current disclosure is a light inline note; consider a per-exchange breakdown of what data each exchange exposes.
NeuroWallet (mobile self-custodial wallet + spot trading) — added 2026-07-07
Applied toterms-of-use.mdx (v0.8) and privacy-policy.mdx (v0.9): NeuroWallet is positioned as a non-custodial embedded wallet (Privy, Solana + Base), spot-only, with trades routed via Relay and priced via Codex. Verified against neurobro-terminal-mobile and neurobro-terminal-backend (dev + wallet branches).
- ToS Section 2 restructured — “Non-Custodial Nature & NeuroWallet”: embedded wallet (Privy/TEE), non-custodial key model, “not exchange/broker/custodian/adviser” conduit disclaimer, user-initiated trades + third-party infra + delegated signing, spot-only, eligibility, wallet risk.
- ToS §5.2 fee — discloses 0.50% (50 bps) NeuroWallet platform fee + third-party routing/service fee + gas (contradicted the prior “no platform fee” wording, now scoped to Neurobro Web only).
- ToS §13 — added class-action + jury-trial waiver + 1-year claim limitation (fomo parity).
- PP — added NeuroWallet embedded-wallet data, trade/withdrawal activity, wallet net-worth snapshots; Privy/Relay/Codex sub-processors; US/Canada international transfer; retention + deletion + public-ledger warning.
- ⚠ COUNSEL — key export claim — per owner instruction the docs state key export is “coming soon.” The current build’s
exportPrivateKey()is a stub that throws (no in-app export UI). Ship the export flow before, or shortly after, launch so the “self-custodial / you control your keys” representation is fully supported; otherwise reconcile the wording. - ⚠ COUNSEL — delegated signer / custody characterization — the backend holds a policy-scoped Privy delegated signer and submits user-initiated swaps server-side with no per-tx prompt (session-signer model). Confirm the “limited delegated swap authorization” disclosure adequately characterizes this and does not undermine the non-custodial / not-an-MSB position. Also tighten the on-chain policy allowlist (a broad wildcard exists on Base in the current build — engineering security ticket) before launch.
- ⚠ COUNSEL — NeuroWallet country blocklist + EU/MiCA — code ships a placeholder blocklist (US, GB, JP → HTTP 451) flagged “needs legal sign-off,” restricts the wallet to paid tiers (pro/ultra), and fails open on unknown geo. Docs currently say “select jurisdictions” generically per owner instruction. Finalize the definitive list and decide the EU position (MiCA: exchange/execution/RTO/advice/portfolio-management exposure even though non-custodial) before launch.
- ⚠ COUNSEL — MSB/MTL for delegated execution + fee — taking a 0.50% fee to route/execute user trades via a delegated signer may implicate money-transmission / broker analysis differently than the read-only product. Refresh the FinCEN + state-MTL memo to cover NeuroWallet specifically.
- Fiat on-ramp (not yet live) — Crossmint/Transak/MoonPay are NOT wired (deposit sheet shows “coming soon”); off-ramp is crypto-only. Add on-ramp providers to ToS/PP as independent controllers (KYC/biometric data collected directly from users) only when the feature actually ships.
- Provider legal links to verify before publish — Privy Terms/Privacy (privy.io), Relay Terms/Privacy (relay.link — Cloudflare-blocked to automated checks; confirm exact paths + operating entity Uneven Labs, Inc. in a browser), Codex Terms/Privacy (dashboard.codex.io).
- Auth branding vs code — docs use “Neurobro Pass” for auth; NeuroWallet uses Privy Custom Auth (backend-minted JWT) under the hood. Confirm “Neurobro Pass” remains the correct user-facing brand for the wallet login.
Non-custodial doctrine — references for counsel (ToS §2 language maps to these)
The §2 non-custodial wording was deliberately drafted to track the regulatory tests below. The words are only true if the facts hold — specifically (i) ship key export and (ii) tighten the Base delegated-signer allowlist so it genuinely cannot divert funds.- FinCEN “total independent control” test — FIN-2019-G001 §4.2 (four-factor test; money transmission = “acceptance and transmission of value”), §4.2.1 (unhosted-wallet safe harbor), §4.2.2 (multi-signature safe harbor: a key acting “at the request of the owner” that “does not have total independent control” is not a money transmitter), §4.5.1–4.5.2 (software/tool vs. service). Also FIN-2013-G001. Counsel to confirm exact section numbers against the PDF.
- Coin Center control test — “execute unilaterally or prevent indefinitely a transaction”; non-custodial + multi-sig participants are not money transmitters.
- Commercial precedent for the delegated signer — Coinbase “spend permissions” / session keys marketed as non-custodial (“under your sole control,” scoped, revocable); Privy delegated-actions (user consent, revocable, key never accessible, TEE-only signing). Privy’s User Terms make the developer (us) responsible for disclosing delegation and obtaining consent — now done in §2.4.
- ⚠ COUNSEL — MiCA RTO/execution (custody-independent) — non-custodial does NOT exempt: receiving swap requests and transmitting them to Relay is likely Reception & Transmission of Orders (Art. 3(1)(23)), and the delegated signer risks tipping into Execution of Orders (Art. 3(1)(21)). Recital 22’s “fully decentralised without any intermediary” carve-out does not apply to a fee-charging interface with a legal operator and backend execution. This is a licensing analysis for any EU launch, not a drafting fix. ESMA Level-3 guidance on the decentralization test expected 2026.
- Weakening phrases to keep out of docs/marketing/UI — “we execute trades for you / on your behalf,” “we hold/store your balances,” “funds in your Neurobro account,” “we send/move/transmit your crypto,” “we control routing,” “we can pause/freeze/seize/reverse,” “spread,” “we fill your order.” (ToS audited; keep the app UI aligned.)
NeuroAPI (developer API) — added 2026-07-21
New pagelegal/api-terms.mdx (v0.2, DRAFT) created for GitHub issue #87. Also applied to terms-of-use.mdx (v0.9) and privacy-policy.mdx (v0.10), and added to the Legal nav in docs.json + linked from the NeuroAPI product page (technical/neuroapi/index.mdx). Evidence base for the copy: whitepaper NeuroAPI page + neurobro-terminal-backend agent_core (agent_neuroapi.py, neuroapi_pipeline.py, neuroapi.yaml), read-only. NeuroAPI = paid public API, single-turn/stateless, caller sends a question (+ optional custom system prompt + optional output schema), returns AI-generated analysis across crypto/stocks/forex/commodities; three modes (FAST/SMART = DeepSeek, MAX = OpenAI). The API HTTP service (auth/billing/rate-limit/logging) is a separate origin (api.neurobro.ai / neuroapi backend) not checked out locally.
- API Terms page — grant/scope, API-key security, permitted/prohibited uses (rate-limit circumvention, resale/redistribution, competing-model training, reverse engineering, infra abuse, unlawful use, Output misrepresentation, unlawful Input), fees/plans/rate limits (by reference), Output rights + AI disclaimers + End-User disclosure, data/privacy + third-party AI transmission, availability/deprecation, suspension/termination, disclaimers/indemnity/governing law (by reference to ToS §11–13).
- ToS incorporation — NeuroAPI added to Operator & Scope services list; API Terms incorporated by reference (API Terms control for NeuroAPI on conflict); clarified NeuroAPI ≠ read-only exchange “API keys” (ToS §3).
- PP disclosures — new NeuroAPI developer account & request-data accordion (API-key identifiers, request Inputs/Output, usage metadata; stateless single-turn); LLM-provider section extended to NeuroAPI Inputs (DeepSeek/OpenAI); Summary bullet + retention entry.
- [~] ⚠ COUNSEL — Output rights + training conflict (training half RESOLVED in drafting) — Per owner instruction (2026-07-24), the training half is now resolved for NeuroAPI: ToS §9.2 amended to carve NeuroAPI Inputs/Output out of the perpetual training license; API Terms §7.3 states an affirmative “we do not train on your Inputs/Output” commitment; API Terms §8.2 + PP §7 disclose that third-party providers train independently (OpenAI does not train on API data; DeepSeek may). STILL OPEN: (a) the Output-rights model — license (drafted) vs assignment, and reconciliation with ToS §9.1’s blanket ownership claim; (b) confirm the no-training commitment matches the actual API logging/retention pipeline (separate origin); (c) the consumer-app ToS §9.2 vs PP §7 conflict is unaffected by this API carve-out and remains tracked separately.
- ⚠ COUNSEL — DeepSeek/China routing of Developer Inputs — Developer Inputs may be routed to DeepSeek (China) by the backend’s automated routing (currently the FAST/SMART tiers); Inputs may be at scale and may contain End-User personal data. Disclosure strengthened (2026-07-24): API Terms §8.2 now describes automated routing (no mode→provider mapping pinned in the public terms, per owner instruction) and names DeepSeek’s China storage + model-training use with a citation, telling Customers to treat every Input as if it may reach any listed provider. Disclosure alone likely does not cure the transfer — still decide whether DeepSeek must be excluded for EU/UK Inputs or a region-pinned model offered; refresh the TIA.
- ⚠ COUNSEL — controller/processor + DPA — where a Customer submits its End Users’ personal data as Input, Neurobro likely acts as the Customer’s processor, requiring a Data Processing Agreement / API-specific data terms and Art. 28 language. None exists yet.
- ⚠ COUNSEL — fee model reconciliation — marketing states subscriptions from $49.99/mo + enterprise; the internal pipeline is implemented as pay-per-call with no per-call tier gating. Confirm whether NeuroAPI is billed by subscription, metered usage, or both, before publishing (API Terms §6.1 currently defers to the pricing page + ToS §5.1).
- ⚠ COUNSEL — x402 coverage — decide whether these API Terms also govern the x402 pay-per-request interface (same agent/toolset, no API keys) or whether x402 needs its own terms.
- TODO-owner — publish concrete rate limits — the product docs state no numeric rate limits/quotas/concurrency caps; API Terms §6.2 references “published limits” generically. Populate real per-plan figures.
- TODO-owner — API retention periods — confirm retention for NeuroAPI Inputs, Output, and usage/billing logs (not verifiable from the docs repo) so PP §4 can state a concrete period instead of “pending confirmation”.
- Entity-name inconsistency — RESOLVED (2026-07-24) — Aligned the whole corpus to NeuroFoundation, LLC (matching
legal/license.mdx) per owner instruction, in a dedicated commit: renamed across Terms of Use, Privacy Policy, API Terms, Affiliate Disclosure, Account Deletion, and the Company page. Counsel to confirm this is the correct registered legal name.
Data Security Statement (new document — not yet started)
- Create a Data Security Statement — new legal page describing the security model.
- Encryption model — exchange credentials protected with AWS KMS envelope encryption (AES-256-GCM), a unique per-record data-encryption key, encrypted blob stored as binary in PostgreSQL; production-isolated CMK (
alias/neurobro-exchange-credentials-prod); supports in-place credential rotation with key-version audit trail. - Read-only access model — no execution capability (
supports_execute = Falsehardcoded; sandbox/paper-trading disabled). - Transport & scoping — HTTPS/TLS in transit; all data user-scoped; cascading deletion.
- Describe memory handling honestly — credentials held in memory only for the duration of a single connect/sync operation; do not overstate (Python cannot guarantee explicit memory zeroization).
- Self-hosted observability — note that the memory sync service uses no third-party error-tracking SDK; observability there is self-hosted (Loki). (Product analytics is also self-hosted via Matomo.)
Regulatory / jurisdiction reviews
- Indonesia PSE / foreign ESO registration — review whether registration as a foreign Electronic System Operator (PSE) is required.
- OJK ITSK framework — review applicability of the OJK ITSK framework (covers technology innovation affecting products, activities, services, or business models in the digital financial ecosystem).
- ⚠ COUNSEL — confirm country blocklists — code blocklists are “starter data from 2026-05-18 legal research” and must be counsel-confirmed before launch; specifically flagged: Indonesia, the UK FCA regime, and Bybit-in-Malaysia.
- ⚠ COUNSEL — core-service jurisdiction restriction — decide whether the core portfolio/exchange-connect service (not just affiliate links) needs country-based access control.
Product documentation
- API key creation guidelines — add per-exchange API key creation guidelines, broken down by supported region, covering required permissions (read-only) and regional availability.
Engineering prerequisites (block accurate legal copy)
- Scrub Sentry SQL parameters — SQLAlchemy integration may capture SQL query parameters (user IDs, financial values) despite
send_default_pii=False; add explicit scrubbing before claiming no financial data leaves systems for monitoring. - Sanitize exchange error logs — raw exchange error messages (
str(exc)) can contain balance amounts or masked API-key fragments; sanitize before launch. - Enforce
REDIS_PASSWORDin production — the sync queue is unauthenticated if unset. - Decide on a retention-purge job — confirm/decide whether old trade/order/ledger/transfer history is purged on a schedule.