# Website Legal Readiness Packet ## Purpose This is the collected legal-readiness checklist for the public Tetrahedron website, subscriber onboarding, and paid-service launch. This is not legal advice. It is a product/legal-prep artifact so we know what counsel needs to review and what pages/agreements the website should eventually include. First-draft legal documents are stored in `docs/legal/`. ## Current Product Framing Assumption - Tetrahedron is a supervised crypto trading operations tool. - The user connects their own exchange account and remains responsible for enabling, stopping, and supervising automation. - The product may provide signals, rankings, automation controls, execution routing, reporting, and notifications. - The product should not be marketed as guaranteed profit, autonomous wealth management, or personalized registered investment advice unless counsel explicitly approves that positioning. ## Public Website Pages To Prepare | Page / Document | Required Before | Purpose | Notes | |---|---:|---|---| | Terms of Service / User Agreement | public beta | Main contract governing account use, liability limits, disputes, acceptable use, subscription access, and service boundaries. | Must be clickwrap at signup and again before live trading. | | Privacy Policy | public website | Explain what personal, account, exchange, trading, telemetry, alert, and support data is collected and why. | Must match actual product behavior. Avoid promises we cannot prove. | | Crypto Trading Risk Disclosure | public beta | Clear risk statement for crypto trading, automated execution, market data, exchange outages, slippage, liquidity, fees, shorts/margin, and loss of principal. | Should be visible before automation is enabled. | | No Financial / Investment Advice Disclaimer | public beta | Clarify that signals, scores, AI summaries, and reports are informational/supportive unless counsel approves a registered-advice model. | Do not rely on disclaimer alone if product behavior becomes personalized advice. | | Automated Trading Authorization | before automation | User explicitly authorizes bounded automated order submission under selected settings. | Must be separate from generic Terms. | | Exchange/API Connection Agreement | before exchange connection | User authorizes storage/use of API credentials, acknowledges third-party exchange terms, and accepts exchange outage/API risk. | Should mention read/trade permissions, credential revocation, and user responsibility. | | Live Trading Acknowledgment | before live mode | Extra high-friction consent before real orders can be submitted. | Should show current venue, order types, max size/exposure, and emergency stop behavior. | | Margin / Short Disclosure | before live shorts | Separate disclosure for shorting, margin, liquidation, borrow/availability, forced close, fees, and exchange-specific restrictions. | Keep disabled until legal/risk review is complete. | | Subscription / Billing Terms | before paid launch | Pricing, renewals, cancellation timing, refunds, failed billing, plan changes, beta/founding plan terms. | Align with Stripe configuration. | | Refund and Cancellation Policy | before paid launch | Plain-language refund/cancel rules. | Should be linked from checkout and account settings. | | Electronic Communications Consent | before account creation | Consent to receive account, service, billing, legal, and security notices electronically. | Include how notices are delivered and how users update contact info. | | Notification / SMS / Email Alert Terms | before alerts | Consent, message frequency, STOP/HELP behavior, carrier-delay disclaimer, quiet hours, alert categories. | Required if SMS is productized. | | Acceptable Use Policy | public beta | Prohibit abuse, scraping, credential sharing, evasion, illegal use, sanctions violations, attacks, and reverse engineering. | Helps with account suspension/termination. | | Security Policy | public beta | Explain credential protection posture, user responsibilities, and how to report security issues. | Include vulnerability disclosure path later. | | Cookie Notice / Tracking Notice | marketing site | Disclose analytics, cookies, pixels, ad tracking, and opt-out path if used. | Keep minimal if possible. | | Age / Eligibility Statement | public beta | State age requirement, legal capacity, and unsupported jurisdictions. | 18+ minimum; consider 21+ if counsel recommends. | | Jurisdiction Availability / Restricted Use | public beta | Disclose where service is offered and that some exchanges/features are region/state limited. | Necessary for exchange-specific execution and shorts. | | AI / Model Limitations Disclosure | public beta | Explain AI summaries/signals may be wrong, stale, incomplete, or unavailable. | Important for OpenClaw and recap videos. | | Performance / Backtest Disclosure | before marketing claims | Explain paper, backtest, simulated, hypothetical, and live results are different. | Never mix paper PnL with live PnL in marketing. | | Testimonials / Affiliate Disclosure Policy | before marketing | Rules for user testimonials, affiliate/referral compensation, founder claims, and social proof. | Needed before launch campaigns. | | Support and Complaint Contact Page | public beta | Tell users how to contact support, security, billing, privacy, and legal. | Also helps regulatory posture. | ## In-App Consent Gates | Moment | Required Consent / Disclosure | |---|---| | Signup | Terms, Privacy, Electronic Communications, age/eligibility. | | Connect exchange | Exchange/API Connection Agreement and credential handling notice. | | Enable paper trading | Paper/simulated-results disclosure. | | Enable live trading | Live Trading Acknowledgment, risk disclosure, order/exposure settings. | | Enable automated buying | Automated Trading Authorization. | | Enable shorts/margin | Margin / Short Disclosure and exchange-specific risk disclosure. | | Choose buy execution style | Explain Conservative Limit, Market Buy, and paper-only Instant Paper Fill. | | Subscribe/pay | Subscription Terms, Refund/Cancellation Policy, Privacy, tax/payment processor notice. | | Enable SMS/email alerts | Notification terms, opt-in consent, STOP/HELP language, message frequency. | | View/report performance | Paper/backtest/live labeling and performance limitations. | ## High-Risk Legal Questions For Counsel | Topic | Why It Matters | |---|---| | Investment adviser status | SEC materials describe investment advisers as those compensated for providing investment advice about securities. Crypto assets and strategy recommendations can create a legal classification question. | | Broker-dealer / exchange / ATS risk | If the platform routes orders, recommends specific trades, receives compensation tied to activity, or intermediates execution, counsel must confirm whether any broker-dealer/exchange/ATS rules are implicated. | | Commodity trading adviser / CFTC risk | Crypto spot, futures, perps, margin, and automated commodity-like trading signals can trigger CFTC analysis. | | Money transmitter / MSB risk | FinCEN guidance focuses on accepting/transmitting convertible virtual currency. Our current safest posture is user-owned exchange accounts, no custody, no transmission of funds by us. Counsel must confirm. | | Custody and control of API keys | Trade-enabled API credentials create serious security/liability questions even if we never custody funds directly. | | Automated trading liability | User must authorize automation, but we need counsel-approved limitations, monitoring obligations, and error-handling language. | | State-by-state availability | Crypto services, money transmission, investment advice, and exchange access can vary by state. | | Margin/short selling | Live shorts require separate legal/risk review; disclosure alone is not enough. | | Marketing claims | “AI,” “profitable,” “beats market,” “best exchange,” and performance claims require substantiation and careful disclosure. | | Paid referrals/affiliates | FTC endorsement rules require clear disclosure of material connections. | | SMS alerts | TCPA/CTIA/Twilio rules require consent, opt-out, sender identification, and message-frequency disclosure. | ## Source Collection ### Regulatory / Government Sources - CFTC virtual currency risk advisory: `https://www.cftc.gov/LearnAndProtect/AdvisoriesAndArticles/understand_risks_of_virtual_currency.html` - CFTC pump-and-dump advisory: `https://www.cftc.gov/LearnAndProtect/AdvisoriesAndArticles/beware_virtual_currency_pump_dump.html` - SEC / Investor.gov crypto asset securities risk alert: `https://www.investor.gov/index.php/introduction-investing/general-resources/news-alerts/alerts-bulletins/investor-alerts/crypto-asset-securities` - SEC investor alert on crypto scams: `https://www.sec.gov/oiea/investor-alert-5-ways-fraudsters-may-lure-victims-scams-involving-crypto-asset` - SEC investment adviser overview: `https://www.investor.gov/introduction-investing/getting-started/working-investment-professional/investment-advisers` - SEC automated investment advice page: `https://www.sec.gov/about/divisions-offices/office-strategic-hub-innovation-financial-technology-finhub/automated-investment-advice` - CFTC/SEC digital asset trading website fraud alert: `https://www.cftc.gov/node/221981` - FinCEN 2013 virtual currency guidance release: `https://www.fincen.gov/news/news-releases/fincen-issues-guidance-virtual-currencies-and-regulatory-responsibilities` - FinCEN virtual currency guidance: `https://www.fincen.gov/resources/statutes-regulations/guidance/application-fincens-regulations-persons-administering` - FTC privacy and security guidance: `https://search.ftc.gov/business-guidance/privacy-security` - FTC CAN-SPAM guide: `https://www.ftc.gov/business-guidance/resources/can-spam-act-compliance-guide-business` - FTC COPPA guide: `https://www.ftc.gov/business-guidance/resources/childrens-online-privacy-protection-rule-not-just-kids-sites` - California privacy rights / CCPA: `https://privacy.ca.gov/california-privacy-rights/your-right-to-privacy/` ### Messaging / Notification Sources - Twilio Messaging Policy: `https://www.twilio.com/en-us/legal/messaging-policy` - Twilio Messaging Campaign Terms: `https://www.twilio.com/en-us/legal/messaging-campaign-terms` - Twilio STOP/HELP opt-out handling: `https://help.twilio.com/hc/en-us/articles/223134027-Twilio-support-for-STOP-BLOCK-and-CANCEL-SMS-STOP-filtering-` - Twilio SMS compliance / A2P 10DLC overview: `https://help.twilio.com/articles/4408675845019` ### Comparable Trading / Exchange References - Gemini User Agreement: `https://www.gemini.com/legal/gemini-trust-user-agreement` - Coinbase User Agreement: `https://www.coinbase.com/legal/user_agreement/united_states` - Kraken Risk Disclosure: `https://assets-cms.kraken.com/files/51n36hrp/facade/ef730346914749ca6afd2a0425ee40314e8360e3.pdf` - Robinhood Crypto Customer Agreement: `https://robinhood.com/us/en/crypto-customer-agreement/` - Kraken API docs: `https://docs.kraken.com/api/docs/guides/global-intro/` ### Billing / Subscription References - Stripe subscription cancellation docs: `https://docs.stripe.com/billing/subscriptions/cancel` - Stripe refund docs: `https://docs.stripe.com/refunds` ## Website Footer Minimum Before a public beta, the footer should link to: - Terms - Privacy - Risk Disclosure - Subscription / Refund Policy - Contact / Support - Security - Do Not Sell or Share / Privacy Choices, if applicable ## Plain-Language Positioning Rules - Say `paper`, `simulated`, `backtest`, and `live` explicitly. - Do not call paper PnL “profit” without a paper/simulated label. - Do not imply guaranteed returns. - Do not imply the system is a registered adviser unless counsel confirms that status. - Do not imply exchange affiliation unless a formal relationship exists. - Do not hide exchange/API dependency risk. - Do not present AI output as certainty. - Keep user controls authoritative: start, stop, emergency stop, exchange revocation. ## Next Drafting Order 1. Terms of Service / User Agreement outline. First draft: `docs/legal/terms-of-service-draft.md` 2. Privacy Policy outline. First draft: `docs/legal/privacy-policy-draft.md` 3. Crypto Trading Risk Disclosure. First draft: `docs/legal/crypto-trading-risk-disclosure-draft.md` 4. Automated Trading Authorization. First draft: `docs/legal/automated-trading-authorization-draft.md` 5. Exchange/API Connection Agreement. First draft: `docs/legal/exchange-api-connection-agreement-draft.md` 6. Live Trading Acknowledgment. First draft: `docs/legal/live-trading-acknowledgment-draft.md` 7. Subscription / Refund Policy. First draft: `docs/legal/subscription-billing-refund-policy-draft.md` 8. Notification/SMS/Email Alert Terms. First draft: `docs/legal/notification-alert-terms-draft.md` 9. Website footer and signup consent language. First draft index: `docs/legal/README.md` ## Counsel Review Package Send counsel: - `docs/Launch-Policy-And-Disclosure-Draft.md` - `docs/Website-Legal-Readiness-Packet.md` - `docs/V1-PRD.md` - `docs/Security-And-User-Boundary-Model.md` - current exchange/API connection design - current automation authority model - planned payment/subscription model - planned SMS/email alert model - planned marketing claims and sample performance reporting