Skip to content

Publish a privacy policy and terms of use - #133

Merged
Isma-L154 merged 1 commit into
mainfrom
feat/legal-pages
Sep 24, 2026
Merged

Isma-L154 merged 1 commit into
mainfrom
feat/legal-pages

Conversation

@Isma-L154

Copy link
Copy Markdown
Owner

Closes #132.

Summary

A privacy policy at /privacy and terms of use at /terms, linked from the app's footer (a Legal navigation) and from each other, with info@cloudils.com as the contact.

What the privacy policy says, and how each claim was checked

Claim Evidence
Code is processed in the browser, never uploaded Client-only architecture (ADR-0001); CSP connect-src 'self'
.tfstate and .terraform are skipped on import workspace/import.ts
Workspace stored on the device (IndexedDB), cleared by Reset or site data persistence/storage.ts, useSession.reset
Share links carry code in the # fragment, never sent to the server persistence/share.ts
No cookies Set-Cookie checked on /, /analyzer.wasm, /favicon.svg in production: none
Cloudflare sees the IP, path, time and headers; logs kept up to 7 days; cookie/credential headers redacted wrangler.jsonc observability (sampling 1); Cloudflare docs: Workers Logs retention 3 days Free / 7 days Paid, header redaction
Rate limit of 1,000 requests/minute per IP wrangler.jsonc ratelimits, deploy/rate-limit.ts
No analytics; Cloudflare's injected beacon is blocked CSP script-src 'self'; #100
Only external link is the Terraform Registry documentation, opened on click NodeDetails.tsx

The terms cover: acceptance; what the tool is; the limits of the diagrams (not a substitute for terraform plan); ownership of content and responsibility for what is imported and shared; acceptable use; the Apache 2.0 license of the code; trademarks and non-affiliation; availability; no warranty; limitation of liability; changes; and contact.

Implementation

  • web/public/privacy.html, terms.html: static HTML with no script. The asset server maps /privacy → privacy.html, and /privacy.html redirects with a 307.
  • web/public/legal.css: external, because the CSP refuses inline styles. Uses the app's tokens, with light and dark schemes and a phone layout.
  • The footer links are at least 24 px tall (WCAG 2.5.8; the existing target-size test caught this).
  • Docs: the deployment README lists the pages and notes that the policy has to change whenever logging, storage or the CSP does. The README links them.

Tests

  • New web/e2e/legal.spec.ts (through the Worker): both pages return 200 with the CSP, show their heading and the contact email, are styled by the external sheet, pass axe, and log no CSP refusals. The footer links reach them and they link back.
  • npm run verify: pass (281 unit tests). Browser suite: 78/78.
  • Checked by eye in light, dark and at 390 px.

Known limitations

  • The terms name no governing law or jurisdiction, since neither was specified. Add one if needed.
  • These texts describe the product accurately but are not legal advice; a lawyer's review is worthwhile before relying on them.

Security considerations

Static pages under the same security headers; no script, no new origin, no inline style.

Static pages at /privacy and /terms, linked from the application's footer
and from each other. The privacy policy states only what was verified on
the deployed site: code stays in the browser, the workspace is in
IndexedDB, share links travel in the fragment, no cookies or analytics,
and Cloudflare's request logs (IP address included) kept up to seven days.
Contact: info@cloudils.com.
@github-actions

Copy link
Copy Markdown

Preview: https://f229d690-terravisual.ilsproj.workers.dev

Security headers were verified against this deployment.

@Isma-L154
Isma-L154 merged commit 355bf48 into main Sep 24, 2026
7 checks passed
@Isma-L154
Isma-L154 deleted the feat/legal-pages branch September 24, 2026 04:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Publish a privacy policy and terms of use

1 participant