Legal TODO
Tracking legal elements/pages that need to be added, updated, or completed. Items marked ⚠ COUNSEL require a legal/business decision before publishing. Items checked[x] were applied to terms-of-use.mdx (v0.7) / privacy-policy.mdx (v0.8); latest pass 2026-05-22.
Analytics: PostHog replaced with self-hosted, open-source Matomo (in-house); Google Analytics and Sentry retained.
Affiliate / Exchange Disclosure
- Affiliate Disclosure page —
legal/affiliate-disclosure.mdxfinalized (May 22, 2026): removed the draft TODO, discloses commission + geo-gating in FTC-clear wording, cross-links to ToS/PP, contact set to info@. Per owner request the page is kept generic — it does NOT name the exchanges or state live scope; those specifics live in ToS §5.3. Counsel sign-off still recommended. - Exchange naming — handled in ToS §5.3 and PP §6 (affiliate page intentionally defers to them).
- Affiliate page per-exchange policy links — optionally add direct links to each exchange’s terms/privacy/AML on the affiliate page (currently cross-linked via ToS §3.5 / PP §6).
- Name all six exchanges — Binance, OKX, Bybit, KuCoin, Indodax, Tokocrypto disclosed individually in ToS §3 and PP §6 (each a separate legal entity / independent data controller).
- Affiliate links live only for Bybit & KuCoin — business/counsel to confirm scope before launch (no longer stated on the affiliate page). Binance/OKX/Indodax/Tokocrypto links currently disabled.
- ⚠ COUNSEL — placeholder benefit figures — do NOT publish placeholder promo figures (e.g. “-20% fees”, “$10,000 rewards”); replace with contractually accurate terms or risk advertising-law exposure.
- Update Terms of Use affiliate section — ToS §5.3 (formerly §4.3) updated: names the six exchanges, discloses commission, adds geo-gating; uses “affiliate” terminology throughout.
Exchange Legal-Document Links
- Embed exchange legal links — referenced in ToS §3.5 (exchange Terms) and PP §6 (exchange Privacy Policies). Links verified working on 2026-05-19; re-check before publishing. Note: only Terms (ToS) and Privacy (PP) are embedded; AML/compliance links are not embedded in the user-facing docs (most exchanges have no standalone AML URL — see notes below).
Notes on gaps (no standalone, verifiable AML-policy URL exists):
- Binance — no global standalone AML page; AML is inside the Terms. The dedicated compliance page exists only on the US entity. The global Privacy Notice is jurisdiction-specific, so the Privacy Portal is the canonical entry point.
- Bybit — no standalone canonical AML document; the User Protection & Compliance page is the closest official page. AML obligations are also embedded in the Terms.
- KuCoin — no standalone public AML/CTF URL; AML/CTF content is incorporated into the Terms of Use and Privacy Policy.
- Indodax — no standalone AML page; AML/CFT is covered within the Terms and Privacy Notice. Help-center pages are bot-protected (HTTP 403 to automated browsers) but confirmed published.
- Tokocrypto — all three documents (incl. a dedicated AML/CFT policy) confirmed via the help-center API.
Privacy Policy updates
- Disclose exchange/portfolio financial data collected — PP §2 now covers credentials, balances/holdings, full trade/order/transfer/ledger history, open positions & PnL, net-worth history, public wallet addresses and on-chain transaction IDs, with a sensitivity warning.
- Sub-processor list — PP §6 “Third Parties and Sub-Processors” lists the 6 exchanges, AWS, Alchemy, CoinGecko, the LLM providers, and the existing analytics/payment processors.
- AI provider transparency — PP §7 names the LLM providers (OpenAI, Anthropic, Google, Groq, xAI, DeepSeek), discloses that portfolio data is sent as context, and notes routing varies by tier/backend.
- ⚠ COUNSEL — DeepSeek routing — decided (disclosed in PP §7) & applied; counsel still to confirm acceptability of China-based routing of financial data for EU/UK users.
- ⚠ COUNSEL — full-history ingestion — lawful basis stated as Contract in PP §2 & applied; counsel to confirm (GDPR Art. 6).
- ⚠ COUNSEL — retention period — event-based retention adopted & applied in PP §4 (retained until disconnect/account deletion); counsel to confirm against GDPR Art. 5(1)(e) storage limitation.
- Document deletion mechanics — PP §5 “Erase” extended: disconnect hard-deletes that exchange’s data; account deletion cascades to all portfolio data. Cross-references
legal/account-deletion.mdx. - Net-worth snapshot retention — disclosed in PP §2 and §4 (retained for the life of the account, deleted on account deletion).
- International data transfer disclosure — PP §8 “Third-Party Processing” updated for the new sub-processors and the EU/US/Singapore/China jurisdictions.
- Per-exchange data-coverage differences — noted in PP §2 (some connected exchanges provide spot-only data).
Terms of Service / Terms of Use updates
- Read-only API key / non-custodial disclaimer — ToS §3 “Read-Only Exchange Connections” added: read-only keys only, no order-execution/trading/withdrawal capability.
- No financial advice for AI portfolio commentary — ToS §4.4 added covering AI-generated commentary on the user’s connected portfolio.
- NFA / DYOR disclaimer — extended in ToS §4 (informational only, not advice, DYOR, consult professionals).
- Jurisdiction / eligibility clause — ToS §5.3 documents affiliate-link geo-gating (sanctions: Iran/North Korea/Cuba/Syria; UK FCA regime; per-exchange blocks) and clarifies it affects affiliate-link display only.
Critical review findings (2026-05-22) — counsel / engineering required
From the four-agent legal review of PR #77. These are NOT pure wording fixes — each needs a legal or engineering decision before launch.- ⚠ COUNSEL — EU & UK Art. 27 representatives (MISSING) — a US-only controller serving/monitoring EU/UK users must appoint, and disclose, both an EU and a UK representative. Neither is named. Standalone GDPR breach.
- ⚠ COUNSEL — DeepSeek/China transfer mechanism — bare “SCCs where applicable” is likely indefensible for China (no adequacy; Schrems II TIA; live DPA bans on DeepSeek in Italy/Germany). Exclude DeepSeek for EU/UK users or hold a documented TIA. (Strengthens the existing DeepSeek item.)
- ⚠ COUNSEL — UK FCA core-service exposure — ToS §5.3 states geo-gating does not restrict the core Services, but promoting $BRO + AI Alpha to UK consumers may itself be a regulated financial promotion (criminal exposure) regardless of affiliate links. Decide: geo-block core promotional/AI Alpha/token surface for the UK, or obtain a lawful route. ToS currently understates this.
- ⚠ COUNSEL — consumer arbitration clause — ToS §13 mandatory Delaware arbitration is likely unenforceable against EU/UK consumers (UCTD/Brussels Ia) and omits a US class-action waiver. Add a class-action waiver + EU/UK/Canada consumer carve-out.
- ⚠ COUNSEL — CCPA/CPRA California section — add notice-at-collection, California consumer rights, and the SPI right-to-limit (exchange API credentials = Sensitive Personal Information under CPRA). Currently only one line.
- ⚠ COUNSEL — Art. 22 profiling/ADM disclosure — disclose the existence, logic, and significance of AI profiling of user portfolios (AI Alpha, portfolio commentary).
- ⚠ COUNSEL — lawful-basis reconciliation — ToS §9.2 grants a “perpetual license … for training” while PP §7 says LLM data is used “solely to generate the response you requested.” Reconcile, and give training/improvement its own basis (consent or LI + balancing test).
- ⚠ COUNSEL — ePrivacy cookie/analytics consent — GA/Matomo/Sentry client SDKs require prior opt-in consent in EU/UK; PP labels analytics “legitimate interest” in places. Confirm the cookie banner is prior, granular, opt-in and align the stated basis.
- ⚠ COUNSEL — MSB/custody framing — ToS §2 states “not a money-services business / not a custodian” as fact. Soften to a position and obtain a FinCEN + state-MTL + $BRO buy-back-mechanic memo.
- ⚠ COUNSEL — AML/sanctions reconciliation — ToS §1.2 and §5.3 carry two different sanctions lists; reference the live OFAC program rather than enumerating, and align the “we screen users” claim with the identity data actually collected (social/email login + read-only key, no KYC).
- ⚠ COUNSEL — Indonesia PDP Law cross-border transfer — transfers of Indonesian users’ financial data to the US/China need a PDP-compliant mechanism (in addition to the PSE/ITSK reviews below).
- ⚠ COUNSEL — DPIA — perform and document a Data Protection Impact Assessment (large-scale sensitive financial data + portfolio monitoring + China transfer trigger Art. 35).
- In-product affiliate disclosure (FTC) — FTC 16 CFR Part 255 requires a clear-and-conspicuous disclosure adjacent to each affiliate link in-product, not only on the policy page.
- Per-exchange data-coverage table — current disclosure is a light inline note; consider a per-exchange breakdown of what data each exchange exposes.
NeuroWallet (mobile self-custodial wallet + spot trading) — added 2026-07-07
Applied toterms-of-use.mdx (v0.8) and privacy-policy.mdx (v0.9): NeuroWallet is positioned as a non-custodial embedded wallet (Privy, Solana + Base), spot-only, with trades routed via Relay and priced via Codex. Verified against neurobro-terminal-mobile and neurobro-terminal-backend (dev + wallet branches).
- ToS Section 2 restructured — “Non-Custodial Nature & NeuroWallet”: embedded wallet (Privy/TEE), non-custodial key model, “not exchange/broker/custodian/adviser” conduit disclaimer, user-initiated trades + third-party infra + delegated signing, spot-only, eligibility, wallet risk.
- ToS §5.2 fee — discloses 0.50% (50 bps) NeuroWallet platform fee + third-party routing/service fee + gas (contradicted the prior “no platform fee” wording, now scoped to Neurobro Web only).
- ToS §13 — added class-action + jury-trial waiver + 1-year claim limitation (fomo parity).
- PP — added NeuroWallet embedded-wallet data, trade/withdrawal activity, wallet net-worth snapshots; Privy/Relay/Codex sub-processors; US/Canada international transfer; retention + deletion + public-ledger warning.
- ⚠ COUNSEL — key export claim — per owner instruction the docs state key export is “coming soon.” The current build’s
exportPrivateKey()is a stub that throws (no in-app export UI). Ship the export flow before, or shortly after, launch so the “self-custodial / you control your keys” representation is fully supported; otherwise reconcile the wording. - ⚠ COUNSEL - delegated signer / custody characterization - SUPERSEDED BY CUSTODY V2, PARTIALLY. Trades and withdrawals are now signed on-device by the user and merely relayed by the backend; no new delegations can be granted. BUT
WALLET_LEGACY_DELEGATED_EXECUTEstill defaultsTrue, so an execute request arriving without client signatures still falls through to server-quorum signing for older installed builds. ToS §2.4 now discloses this wind-down. The absolute “we can never sign for your wallet” wording becomes safe only oncewallet_grantsholds no activelegacy_trade_executionrows and the flag is flipped. Historic note follows: the backend held a policy-scoped Privy delegated signer and submitted user-initiated swaps server-side with no per-tx prompt (session-signer model). Confirm the “limited delegated swap authorization” disclosure adequately characterizes this and does not undermine the non-custodial / not-an-MSB position. Also tighten the on-chain policy allowlist (a broad wildcard exists on Base in the current build - engineering security ticket) before launch. - ⚠ COUNSEL - NeuroWallet country blocklist + EU/MiCA - STALE FACTS CORRECTED 2026-08-19. There is no tier gate (the wallet is open to all tiers) and no US/GB/JP 451. The wallet is GLOBAL:
WALLET_AVAILABLE_COUNTRIES,WALLET_BLOCKED_COUNTRIESandWALLET_COMING_SOON_COUNTRIESare all empty. Live restrictions are CU/IR/KP/SY plus occupied Ukraine (451 app-wide), RU/BY/VE/MM (403 on execution only), and US/GB on perpetual futures and tokenized equities only. Unknown geo fails CLOSED for wallet execution, not open. Now documented in ToS §1.4. Docs currently say “select jurisdictions” generically per owner instruction. Finalize the definitive list and decide the EU position (MiCA: exchange/execution/RTO/advice/portfolio-management exposure even though non-custodial) before launch. - ⚠ COUNSEL - MSB/MTL for execution + fee - URGENT, gated on the Apple App Review response. The fee is not a flat 0.50%: it is tier-scaled (Basic 0.50% / Pro 0.40% / Ultra 0.30%) with a 0.50 withdrawal fee and a 0.05% perpetual-futures builder fee, all now disclosed in ToS §5.2. The ToS no longer states a position on money-transmitter or MSB status (owner decision 2026-08-19, following a comparison with FOMO Labs, Inc., a direct comparable that states none): §2.1 now says only that Neurobro is not registered with or licensed by any regulatory authority. The FinCEN “total independent control” argument remains available and is architecturally supportable post-Custody-v2, but it is now an unpublished position held in reserve, and it is contingent on the legacy delegated path above being closed. Refresh the FinCEN + state-MTL memo to cover NeuroWallet specifically.
- Fiat on-ramp and cash-out - LIVE, and now documented - both rails ship through Onramper (MoonPay named as the live EEA sell partner); the earlier Crossmint/Transak note is obsolete. Covered in ToS §2.8 and PP §2/§6/§8 as independent controllers collecting KYC directly from users. Open item: the merchant of record is not established anywhere in code or contract - confirm against the Onramper agreement before making any representation about who contracts with the user.
- Provider legal links to verify before publish — Privy Terms/Privacy (privy.io), Relay Terms/Privacy (relay.link — Cloudflare-blocked to automated checks; confirm exact paths + operating entity Uneven Labs, Inc. in a browser), Codex Terms/Privacy (dashboard.codex.io).
- Auth branding vs code — docs use “Neurobro Pass” for auth; NeuroWallet uses Privy Custom Auth (backend-minted JWT) under the hood. Confirm “Neurobro Pass” remains the correct user-facing brand for the wallet login.
Non-custodial doctrine — references for counsel (ToS §2 language maps to these)
The §2 non-custodial wording was deliberately drafted to track the regulatory tests below. The words are only true if the facts hold — specifically (i) ship key export and (ii) tighten the Base delegated-signer allowlist so it genuinely cannot divert funds.- FinCEN “total independent control” test — FIN-2019-G001 §4.2 (four-factor test; money transmission = “acceptance and transmission of value”), §4.2.1 (unhosted-wallet safe harbor), §4.2.2 (multi-signature safe harbor: a key acting “at the request of the owner” that “does not have total independent control” is not a money transmitter), §4.5.1–4.5.2 (software/tool vs. service). Also FIN-2013-G001. Counsel to confirm exact section numbers against the PDF.
- Coin Center control test — “execute unilaterally or prevent indefinitely a transaction”; non-custodial + multi-sig participants are not money transmitters.
- Commercial precedent for the delegated signer — Coinbase “spend permissions” / session keys marketed as non-custodial (“under your sole control,” scoped, revocable); Privy delegated-actions (user consent, revocable, key never accessible, TEE-only signing). Privy’s User Terms make the developer (us) responsible for disclosing delegation and obtaining consent — now done in §2.4.
- ⚠ COUNSEL — MiCA RTO/execution (custody-independent) — non-custodial does NOT exempt: receiving swap requests and transmitting them to Relay is likely Reception & Transmission of Orders (Art. 3(1)(23)), and the delegated signer risks tipping into Execution of Orders (Art. 3(1)(21)). Recital 22’s “fully decentralised without any intermediary” carve-out does not apply to a fee-charging interface with a legal operator and backend execution. This is a licensing analysis for any EU launch, not a drafting fix. ESMA Level-3 guidance on the decentralization test expected 2026.
- Weakening phrases to keep out of docs/marketing/UI — “we execute trades for you / on your behalf,” “we hold/store your balances,” “funds in your Neurobro account,” “we send/move/transmit your crypto,” “we control routing,” “we can pause/freeze/seize/reverse,” “spread,” “we fill your order.” (ToS audited; keep the app UI aligned.)
NeuroAPI (developer API) — added 2026-07-21
New pagelegal/api-terms.mdx (v0.2, DRAFT) created for GitHub issue #87. Also applied to terms-of-use.mdx (v0.9) and privacy-policy.mdx (v0.10), and added to the Legal nav in docs.json + linked from the NeuroAPI product page (technical/neuroapi/index.mdx). Evidence base for the copy: whitepaper NeuroAPI page + neurobro-terminal-backend agent_core (agent_neuroapi.py, neuroapi_pipeline.py, neuroapi.yaml), read-only. NeuroAPI = paid public API, single-turn/stateless, caller sends a question (+ optional custom system prompt + optional output schema), returns AI-generated analysis across crypto/stocks/forex/commodities; three modes (FAST/SMART = DeepSeek, MAX = OpenAI). The API HTTP service (auth/billing/rate-limit/logging) is a separate origin (api.neurobro.ai / neuroapi backend) not checked out locally.
- API Terms page — grant/scope, API-key security, permitted/prohibited uses (rate-limit circumvention, resale/redistribution, competing-model training, reverse engineering, infra abuse, unlawful use, Output misrepresentation, unlawful Input), fees/plans/rate limits (by reference), Output rights + AI disclaimers + End-User disclosure, data/privacy + third-party AI transmission, availability/deprecation, suspension/termination, disclaimers/indemnity/governing law (by reference to ToS §11–13).
- ToS incorporation — NeuroAPI added to Operator & Scope services list; API Terms incorporated by reference (API Terms control for NeuroAPI on conflict); clarified NeuroAPI ≠ read-only exchange “API keys” (ToS §3).
- PP disclosures — new NeuroAPI developer account & request-data accordion (API-key identifiers, request Inputs/Output, usage metadata; stateless single-turn); LLM-provider section extended to NeuroAPI Inputs (DeepSeek/OpenAI); Summary bullet + retention entry.
- [~] ⚠ COUNSEL — Output rights + training conflict (training half RESOLVED in drafting) — Per owner instruction (2026-07-24), the training half is now resolved for NeuroAPI: ToS §9.2 amended to carve NeuroAPI Inputs/Output out of the perpetual training license; API Terms §7.3 states an affirmative “we do not train on your Inputs/Output” commitment; API Terms §8.2 + PP §7 disclose that third-party providers train independently (OpenAI does not train on API data; DeepSeek may). STILL OPEN: (a) the Output-rights model — license (drafted) vs assignment, and reconciliation with ToS §9.1’s blanket ownership claim; (b) confirm the no-training commitment matches the actual API logging/retention pipeline (separate origin); (c) the consumer-app ToS §9.2 vs PP §7 conflict is unaffected by this API carve-out and remains tracked separately.
- ⚠ COUNSEL — DeepSeek/China routing of Developer Inputs — Developer Inputs may be routed to DeepSeek (China) by the backend’s automated routing (currently the FAST/SMART tiers); Inputs may be at scale and may contain End-User personal data. Disclosure strengthened (2026-07-24): API Terms §8.2 now describes automated routing (no mode→provider mapping pinned in the public terms, per owner instruction) and names DeepSeek’s China storage + model-training use with a citation, telling Customers to treat every Input as if it may reach any listed provider. Disclosure alone likely does not cure the transfer — still decide whether DeepSeek must be excluded for EU/UK Inputs or a region-pinned model offered; refresh the TIA.
- ⚠ COUNSEL — controller/processor + DPA — where a Customer submits its End Users’ personal data as Input, Neurobro likely acts as the Customer’s processor, requiring a Data Processing Agreement / API-specific data terms and Art. 28 language. None exists yet.
- ⚠ COUNSEL — fee model reconciliation — marketing states subscriptions from $49.99/mo + enterprise; the internal pipeline is implemented as pay-per-call with no per-call tier gating. Confirm whether NeuroAPI is billed by subscription, metered usage, or both, before publishing (API Terms §6.1 currently defers to the pricing page + ToS §5.1).
- ⚠ COUNSEL — x402 coverage — decide whether these API Terms also govern the x402 pay-per-request interface (same agent/toolset, no API keys) or whether x402 needs its own terms.
- TODO-owner — publish concrete rate limits — the product docs state no numeric rate limits/quotas/concurrency caps; API Terms §6.2 references “published limits” generically. Populate real per-plan figures.
- TODO-owner — API retention periods — confirm retention for NeuroAPI Inputs, Output, and usage/billing logs (not verifiable from the docs repo) so PP §4 can state a concrete period instead of “pending confirmation”.
- Entity-name inconsistency — RESOLVED (2026-07-24) — Aligned the whole corpus to NeuroFoundation, LLC (matching
legal/license.mdx) per owner instruction, in a dedicated commit: renamed across Terms of Use, Privacy Policy, API Terms, Affiliate Disclosure, Account Deletion, and the Company page. Counsel to confirm this is the correct registered legal name.
Data Security Statement (new document — not yet started)
- Create a Data Security Statement — new legal page describing the security model.
- Encryption model — exchange credentials protected with AWS KMS envelope encryption (AES-256-GCM), a unique per-record data-encryption key, encrypted blob stored as binary in PostgreSQL; production-isolated CMK (
alias/neurobro-exchange-credentials-prod); supports in-place credential rotation with key-version audit trail. - Read-only access model — no execution capability (
supports_execute = Falsehardcoded; sandbox/paper-trading disabled). - Transport & scoping — HTTPS/TLS in transit; all data user-scoped; cascading deletion.
- Describe memory handling honestly — credentials held in memory only for the duration of a single connect/sync operation; do not overstate (Python cannot guarantee explicit memory zeroization).
- Self-hosted observability — note that the memory sync service uses no third-party error-tracking SDK; observability there is self-hosted (Loki). (Product analytics is also self-hosted via Matomo.)
Regulatory / jurisdiction reviews
- Indonesia PSE / foreign ESO registration — review whether registration as a foreign Electronic System Operator (PSE) is required.
- OJK ITSK framework — review applicability of the OJK ITSK framework (covers technology innovation affecting products, activities, services, or business models in the digital financial ecosystem).
- ⚠ COUNSEL — confirm country blocklists — code blocklists are “starter data from 2026-05-18 legal research” and must be counsel-confirmed before launch; specifically flagged: Indonesia, the UK FCA regime, and Bybit-in-Malaysia.
- ⚠ COUNSEL — core-service jurisdiction restriction — decide whether the core portfolio/exchange-connect service (not just affiliate links) needs country-based access control.
Product documentation
- API key creation guidelines — add per-exchange API key creation guidelines, broken down by supported region, covering required permissions (read-only) and regional availability.
Engineering prerequisites (block accurate legal copy)
- Scrub Sentry SQL parameters — SQLAlchemy integration may capture SQL query parameters (user IDs, financial values) despite
send_default_pii=False; add explicit scrubbing before claiming no financial data leaves systems for monitoring. - Sanitize exchange error logs — raw exchange error messages (
str(exc)) can contain balance amounts or masked API-key fragments; sanitize before launch. - Enforce
REDIS_PASSWORDin production — the sync queue is unauthenticated if unset. - Decide on a retention-purge job — confirm/decide whether old trade/order/ledger/transfer history is purged on a schedule.
Opened 2026-08-19 (ToS v1.0 / PP v0.11)
Raised by the full reconciliation of the legal corpus against the shipped app. Each has a matching⚠ COUNSEL comment inline in the document.
- ⚠ COUNSEL / BLOCKING - OFAC withdrawal-address list is a placeholder - ToS §6.2 now states that withdrawal destinations are screened against OFAC-designated digital-currency addresses. The shipped list (
src/assets/ofac_sdn_crypto_addresses.jsonl) holds five non-real placeholder rows, one of them a literal fake address, has no refresh cadence (refresh is a manual script), and the gate fails OPEN on a missing or malformed list. Populate the authoritative set and set a cadence before publishing v1.0, or §6.2 overstates the control. The same claim already appears, in stronger terms, inproducts/neurowallet/safety.mdx. - ⚠ COUNSEL - perpetual futures licensing - offering leveraged derivatives to retail users engages EU MiCA/MiFID, the UK FCA regime, and US CFTC/CEA analysis. US and GB are blocked in code today; no other jurisdiction has been reviewed. ToS §2.6.
- ⚠ COUNSEL - tokenized equities - the xStocks and Robinhood-Chain tokens may be securities in several jurisdictions, and operating an interface to them may itself be a regulated activity. US and GB blocked; remaining scope unreviewed. ToS §2.7.
- ⚠ COUNSEL - merchant of record for fiat rails - not established in code or in the documents. Confirm against the Onramper agreement. ToS §2.8.
- ⚠ COUNSEL - sanctions sets are self-described drafts -
EMBARGOED_COUNTRIEScarries “DRAFT pending counsel sign-off” (Syria most likely to shift) andHIGH_RISK_EXECUTION_COUNTRIEScarries “starter data (2026-05 legal research)”. Separately, the Ukraine sub-region block may never match: the Cloudflareregion_codealphabet was never verified, and it fails open. ToS §1.4. - Referral program terms - now covered in ToS §5.5 and PP. Confirm the payout-refusal discretion, the 30-day hold, and the clawback on refund are enforceable as drafted, and whether paying commissions in USDC creates any licensing or tax-reporting obligation.
- UK FCA financial promotions - spot crypto trading is currently offered in the UK with no FCA-authorised approver for financial promotions. Apple’s App Review has asked for evidence of compliance under Guideline 3.1.5. Either block GB for all NeuroWallet execution or obtain an approver.
- Verify private-key export actually ships - ToS §2.2 still says “coming soon” and the mobile docs now describe a biometric-gated signing path used by key export. Confirm against the current build and update the
<Info>if it has shipped.
Opened 2026-08-27 (ToS v1.1 - tokenized-equity expansion)
Raised by reviewing the spot-stocks work ondev against the legal corpus. The catalogue went from 17 rows and one issuer in the released build to 699 active rows across four spot issuers (Ondo 435, Robinhood 194, xStocks 47, Backpack 13), which is what prompted the v1.1 amendments. Items marked ⚠ COUNSEL have a matching comment inline in ToS §2.7.
- ⚠ COUNSEL / BLOCKING - issuing entities are named at product level only - §2.7 now names Backed Finance, Ondo, Backpack and Robinhood Europe UAB. Only Robinhood Europe UAB is a verified registered entity; the other three are product-level names, because the registered issuer was not establishable from our own systems. Confirm each before publication - the Section tells the user their claim lies against that entity.
- ⚠ COUNSEL / BLOCKING - per-issuer restricted jurisdictions - the app enforces a single
["US","GB"]block across all four issuers, but their own distribution scopes differ and are narrower. Robinhood Europe UAB distributes only within the EEA, so its 194 tokens are currently routable to users outside it; Ondo and Backed each publish restricted lists broader than US/GB. Obtain each issuer’s list, then either gate per issuer or narrow the country allowlist. §2.7 is drafted forward-compatibly, but the code does not yet match it. - ⚠ COUNSEL - market data licensing - stock price history and the 52-week band come from Yahoo Finance via the unofficial
yfinancescraper, served to users in a paid commercial product. Yahoo’s terms prohibit commercial redistribution and the underlying series is exchange-licensed. Decide whether to license a redistributable feed or disable the charts. - ⚠ COUNSEL - analyst recommendations under MAR - the asset page shows a Buy/Hold/Sell consensus, a target price and an implied upside, with no source, no as-of date and no “not advice” statement. The consensus tier is computed by the app, which may make Neurobro the producer of an investment recommendation rather than a disseminator, engaging EU MAR Art. 20 and Delegated Regulation 2016/958 (producer identity, date, conflicts).
- Third-party image licensing - commodity logos hotlink Wikimedia Commons thumbnails (CC BY / CC BY-SA, shown with no attribution, which the licence requires) and stock logos hotlink a paid vendor CDN (
images.financialmodelingprep.com) directly from the client. Self-host both, and carry attribution for the Wikimedia set or replace it. - Point-of-order representation is not collected - §2.7 states the user represents and warrants their U.S. Person status, location and non-circumvention “by placing a tokenized-equity order”. The app never asks. Perpetual futures implement exactly this gate; tokenized equities have no equivalent. Tracked as MOB-01 in
neurobro-terminal-mobile. - Reconcile the in-app dividend copy with §2.7 - the asset page states dividends are “automatically reinvested into the token’s value” for tokenized stocks generally, which describes one issuer’s mechanism. §2.7 has been rewritten to make distribution treatment issuer-specific; the app copy must be made per-issuer or removed to match. Tracked as MOB-04.