Revorks — requirements analysis for Terms of Use and related legal documents
Status: working legal/product requirements brief — not legal advice and not publishable Terms of Use.
Prepared: 2026-08-27.
Product assumed: a paid web platform that lets users submit text, images, video, audio, faces, voices and other assets to third-party AI providers; receive generated images/video/audio; buy credits and subscriptions; and store/download outputs.
Purpose: give counsel and product owners a complete clause-by-clause specification for a legally reviewed Terms of Use package. It is intentionally stricter and more specific than generic SaaS boilerplate.
1. Critical framing
Revorks is not merely a “credits app.” It is simultaneously:
- a consumer and/or business digital service;
- an intermediary for user-supplied content and model outputs;
- a reseller or facilitator of capacity from multiple model providers;
- a processor/controller of potentially sensitive personal data, including images, voice and biometric-adjacent material;
- a payment/subscription merchant, or a merchant using a Merchant of Record (MoR);
- a content-moderation service; and
- potentially a platform that enables synthetic-media creation.
Terms must be paired with documents and operational controls. A clause cannot cure a missing refund workflow, consent check, deletion process, age gate, moderation process, provider right, tax configuration, or payment-record system.
2. Documents to publish or execute
| Document | Who needs it | Why it is separate | Owner |
|---|---|---|---|
| Terms of Use / Customer Agreement | every account holder | service rules, contract, credits, liability, disputes | Legal + Product |
| Acceptable Use & Generative AI Policy | every user; incorporated into Terms | precise prohibited content, enforcement and appeals | Trust & Safety |
| Privacy Notice | all visitors/users | required transparency for personal-data processing | Privacy |
| Cookie Notice and consent mechanism | visitors in applicable regions | analytics/advertising technologies and choices | Privacy + Web |
| Credits, Subscription, Cancellation & Refund Policy | all purchasers | plain-language commercial terms and consumer disclosures | Billing + Legal |
| Content/IP, Notice-and-Takedown & Counter-Notice Policy | rights holders and users | copyright/trademark/personality complaints and process | Legal + Trust & Safety |
| Biometric, Likeness, Voice & Avatar Consent Policy | avatar/lip-sync/voice users and subjects | explicit rights, proof standards, deletion and escalation | Privacy + Safety |
| Community/Sharing Rules | only if public gallery, links, remixing or marketplace exist | publication, discoverability, reporting and takedown | Product + Safety |
| Data Processing Addendum (DPA) | qualifying B2B customers | controller/processor allocation and GDPR-style terms | Legal + Privacy |
| Enterprise Order Form / SLA / Support Policy | enterprise customers | negotiated availability, limits, security, indemnity, fees | Sales + Legal |
| Subprocessor list and transfer notice | where privacy law requires or contracts promise it | model providers and storage/analytics vendors change over time | Privacy |
| Copyright agent page / DMCA policy | US-facing hosting service | safe-harbor process; designated agent if relied upon | Legal |
| Transparency and internal-complaint information | EU-facing intermediary where applicable | explain restrictions, moderation tools/human review and complaint process | Legal + Safety |
3. Decisions required before drafting final language
No terms can accurately resolve these points by assumption. Answers should be recorded with an owner and effective date.
| ID | Decision | Why it changes the terms |
|---|---|---|
| D1 | Contracting entity: legal name, registered address, registration number, Kazakhstan tax status, and support/legal email | mandatory party and notice information |
| D2 | Launch markets, languages, currencies and geo-blocked countries | consumer law, sanctions, tax, arbitration and language rules |
| D3 | Customer mix: consumers, businesses, minors, schools, agencies, resellers, enterprise | eligibility, authority, consumer waivers, DPA and resale rights |
| D4 | Minimum age and whether verified parental consent will ever be supported | child-data and safety obligations |
| D5 | Merchant of Record or direct processor; processor name; card/wallet methods | seller-of-record, VAT, refunds, chargebacks and invoice wording |
| D6 | Exact credit rules: price, tax, expiry, transferability, promotional-credit rules, refundability, chargeback treatment, account closure treatment | must be disclosed before purchase and applied consistently |
| D7 | Subscription rules: tiers, renewal period, trial, cancellation path, downgrade/upgrade, unused credit carryover and annual vesting | recurring-payment and cancellation compliance |
| D8 | Model-provider routes actually enabled and each provider’s customer-facing/resale permission | Revorks cannot promise rights it does not receive |
| D9 | Input/output retention periods, backup period, deletion method, public-sharing default, staff access and model-training use | privacy notice, customer promises and data architecture |
| D10 | Whether Revorks or providers may use content for quality/safety/training; opt-in/opt-out choice | IP license and privacy lawful basis |
| D11 | Whether public galleries, share links, remixing, team workspaces, APIs, marketplace or user-to-user messaging will exist | intermediary, publication, moderation and IP regime |
| D12 | Moderation policy and appeal SLA; human-review capability; countries/sanctions screening | policy text must match actual enforcement |
| D13 | Likeness/voice feature scope; consent evidence required; verification and deletion path | deepfake, privacy, publicity and provider restrictions |
| D14 | Governing law, courts/arbitration and consumer-rights carve-outs | enforceability varies materially by user residence |
| D15 | Liability cap, indemnity appetite, insurance and enterprise exceptions | risk allocation and pricing |
3.1 Provisional launch decisions — 2026-08-27
These are recommended defaults based on the founder’s current answers. They are product decisions to approve, not legal advice. They are intentionally conservative for a near-term Kazakhstan-to-Europe consumer launch.
| Topic | Provisional decision | Reason / implementation requirement |
|---|---|---|
| Contracting company | Form a Kazakhstan Limited Liability Partnership (LLP / ТОО) before taking payment. Insert its exact registered name, BIN, registered address, support email and legal-notice email into the final documents. | An LLP is the common Kazakhstan commercial form; the contracting party cannot be “Revorks” as a brand only. Kazakhstan’s official guidance describes LLP as the most common form and requires a legal address during registration. gov.kz |
| Launch market | EU/EEA consumers and businesses; exclude UK, Switzerland and non-EEA Europe from the first consumer launch unless separately approved. Use English as the authoritative contract language; add reviewed translations later. | “Europe” is not a single legal market. This limits the initial legal surface while the payment/tax/legal stack is validated. Do not market into countries that are not enabled. |
| Age | 18+ only at launch. No accounts, purchases, public sharing, uploads of a minor’s likeness, or avatar/voice use by/for minors. | A 14+ service would require a country-by-country digital-consent/parental-consent design, stronger child-safety controls and additional provider checks. It is not realistic for a 5 September launch. |
| Customer type | Permit both consumers and businesses. A person choosing a business workspace must represent authority to bind that business. | Consumer protections continue for personal/non-business purchases; B2B terms, DPA and negotiated enterprise terms remain separate. |
| Payments | Recommended: Merchant of Record (MoR) for the first EU consumer launch. If no MoR is live and contractually confirmed, do not enable EU consumer checkout. | The MoR should calculate/collect/remit consumer taxes and operate the payment/refund transaction. Confirm in writing who is merchant/seller of record, who issues invoices, and which party handles refund/chargeback notices. |
| Governing law / disputes | For B2B: Kazakhstan law and courts in Astana, subject to counsel review. For consumers: preserve all mandatory law and forum protections of the consumer’s habitual residence; do not impose mandatory arbitration or a class-action waiver at launch. | A choice-of-law clause does not remove mandatory EU consumer protections when the trader directs activity to the consumer’s country. Use clear non-waivable-rights language. |
| Purchased credits | Sell prepaid credits with a 12-month expiry, prominently displayed at checkout and in the account. Credits are non-transferable, non-cash and not stored money. | A long, transparent validity period is commercially reasonable. Keep a precise per-lot ledger and send reminders before expiry where feasible. |
| Subscription credits | Grant monthly, not annually in advance. Allow a one-month rollover; expired subscription credits then lapse. Cancel anytime to stop the next renewal; access continues through the paid period. | Avoids annual-plan refund/chargeback exposure and is fairer than immediate monthly expiry. The exact subscription price/tier must be specified later. |
| Promotional credits | Expire after 30 days unless the promotion clearly states another date; never convert to cash; spend after subscription credits and before purchased credits only if this is made explicit. | Keeps promotions limited without quietly destroying paid credits. |
| Refunds | (1) Automatically release/refund credits for any failed, cancelled-before-start, duplicate, policy-blocked-before-processing, or undelivered/corrupt generation. (2) Offer refund of unused purchased credits within 14 days where required or as the launch policy; do not deduct used credits from that refund. (3) Keep statutory withdrawal and nonconformity remedies intact. (4) No automatic refund for a successfully delivered conforming output merely because a user dislikes it, but provide support review for material defects. | This is clearer and safer than “all sales final.” Checkout must collect a legally valid immediate-performance acknowledgement only where it actually applies; it cannot erase mandatory remedies. |
| Provider/API shutdown | Never promise a particular provider/model forever. Honor accepted quote price; do not charge more after route failure; release a reservation if no durable usable output was delivered. If a paid core capability is retired, stop selling it, notify users, preserve credits for alternatives and assess refund/extension required by law. | Directly solves the paid-credit/API-closure scenario. |
| Privacy and training | No training or product-improvement use of customer inputs/outputs by default. Use content only to operate, secure, moderate, troubleshoot and provide support for the user’s request. Default content to private. | This is the clearest, most trust-preserving launch policy. Any future training program must be separate, explicit opt-in with purpose, providers, withdrawal and retention terms. |
| Retention/deletion | Store active private inputs/outputs for 90 days after creation, unless the user deletes them earlier. On deletion, remove from active systems within 30 days; retain encrypted backups for up to 90 additional days, plus minimal audit/billing/safety records where lawfully required. Do not promise immediate deletion from all backups. | Gives users time to download output and makes a truthful, operationally achievable privacy commitment. Engineering must validate that these periods are real. |
| Public galleries/share/remix | Not part of the binding launch promise. If enabled, make content private by default; require affirmative publish/share action; show public visibility, licence/remix choice, reporting and removal controls. No public gallery or remixing of face/voice/avatar content at launch. | Public UGC creates a materially larger moderation, IP, privacy and DSA workload. Launch it only after notice-and-action, appeals and reporting flows exist. |
| Likeness/voice/avatar | Defer all face, voice, lip-sync, avatar and replica features. Later require documented consent, a specific attestation at submission, deletion/withdrawal workflow and review queue. Never allow minor likeness/voice features at initial launch. | This matches the model integration plan and reduces the most acute deepfake/privacy exposure. |
| Adult/sexual content | Do not support NSFW, sexual content, non-consensual intimate imagery, or sexualized content involving any potentially underage person at launch. | Compatible with conservative provider and safety requirements; must be enforced in the AUP and product filters. |
| Creator marketing | Treat creator promotion as a separate commercial program: written creator/affiliate agreement, mandatory ad/affiliate disclosure, approved claims/creative rules, tax/payment terms, IP licence for campaign assets, and no promises of earnings/results. | Creator marketing is not governed adequately by customer Terms alone. |
3.2 Remaining answers that are still genuinely required
- What working company name do you want to use for registration and customer-facing branding (e.g. “Revorks AI LLP”)? The registered address can follow, but it must be obtained before payment launch.
- Which exact EU/EEA countries will be enabled on 5 September? Recommended first list: all EU/EEA only if the MoR supports them; otherwise choose a short list supported by the MoR. Is the UK deliberately excluded for this first launch?
- Are you willing to adopt the recommended 18+ only policy? If not, the launch needs a separate minor/parent-consent and child-safety workstream.
- Are you approving the recommended 12-month purchased-credit expiry, one-month subscription rollover, and 90-day storage/30+90-day deletion schedule?
- Will launch include only private image/video generations, or also any public sharing, gallery, creator referral/affiliate links, team workspace, API access or resale? List the features that are definitely live on 5 September.
- What customer support email and refund contact will be shown at launch, and who will own response to urgent safety/IP/privacy complaints?
- Which payment/MoR finalists are being considered? Before choosing, obtain written confirmation that the provider supports a Kazakhstan entity selling AI-generated digital services to your intended EU/EEA countries and handles the stated VAT/refund role.
4. Terms of Use: complete drafting specification
4.1 Header, acceptance and contract formation
Include all of the following:
- title, version, effective date, last-updated date and change log;
- full legal entity name, physical address, company registration/tax details where required, support contact and legal-notice contact;
- clear explanation of what actions accept the Terms: account creation, purchase, clicking an unchecked acceptance box, or using the service after a clearly notified effective change;
- statement that a user accepting for an organization represents authority to bind it;
- precedence order: Order Form/DPA/enterprise agreement, then payment policy, then Terms, then incorporated policies; say which document controls a conflict;
- accessible copies of every incorporated policy at the moment of acceptance; preserve an acceptance/version record;
- valid electronic-contract and electronic-notice consent, subject to non-waivable local law;
- severability, no waiver, assignment, force majeure, independent contractors, entire agreement, interpretation, survival and third-party-beneficiary rules;
- no hidden unilateral change power: give advance notice for material adverse changes, state effective date, and allow cancellation where required. Changes needed for security, law, provider withdrawal, fraud or safety can be immediate, but must still be communicated.
4.2 Definitions
Define precisely and consistently: Account; Authorized User; Business User; Consumer; Content; Input; Output; Generation; Credits; Promotional Credits; Subscription Credits; Credit Lot; Quote; Provider; Provider Route; Feature; Beta Feature; User Assets; Prohibited Content; Sensitive Personal Data; Likeness; Voice; Consent Evidence; Public Content; Service; Fees; Taxes; Refund; Chargeback; Applicable Law; and Usage Policy.
Avoid defining “credit” as money, stored value, currency, deposit, gift card, investment, guaranteed generation, or ownership in provider capacity. It should be a limited contractual right to request eligible Service usage under the then-current product rules, subject to mandatory law and the specific purchased plan.
4.3 Eligibility, accounts, identity and security
- age threshold and parental-consent rule; do not collect known child data where the product is not designed for children;
- legal capacity and organization authority;
- restricted territories, sanctioned persons/entities and prohibited export-control use;
- accurate account information; one account per person/business if that is the rule;
- credential confidentiality, MFA expectation, notification of compromise, and responsibility for activity until a report is received (without overriding mandatory fraud protections);
- Revorks right to verify identity, payment method, age, ownership/consent or source-of-funds where lawful and proportionate;
- account suspension/closure triggers and a reasonable appeal/contact route;
- estate, insolvency, inactive account and non-transferability handling;
- no account sale, credential sharing, scraping, botting, API-key sharing, circumvention of limits or evasion through new accounts.
4.4 Service scope, availability and provider dependency
State exactly what Revorks promises and what it does not:
- service gives access to available features; no promise that every model, route, resolution, output format, country, price, capacity or feature will remain available;
- providers may change prices, capabilities, policy, regions, model versions, safety filters, availability, result quality or discontinue APIs without notice to Revorks;
- Revorks may replace, restrict, disable or retire a route/model/feature for provider, legal, safety, fraud, operational or commercial reasons;
- a route change never retroactively changes an accepted generation quote; unsupported queued work must be refunded/released or re-quoted with affirmative user choice;
- maintenance windows, rate limits, queueing, peak demand, third-party outages and quality variability;
- no reliance for emergency, safety-critical, medical, legal, financial, employment, insurance, law-enforcement, immigration, credit or other high-impact decisions;
- support scope, hours, channels, target response times and no guaranteed response/resolution unless an SLA expressly says otherwise;
- beta/preview terms: experimental, may be changed or ended, may have lower/no availability or support, no production reliance, and separate risk disclosure. Do not use a beta label to defeat mandatory consumer remedies.
4.5 Quotes, job lifecycle and failed provider/API events
This is the required answer to the “API closed after paid credits” scenario.
- A generation quote must disclose the selected capability/parameters, exact credits, expiry, provider-price estimate where variable, and whether the job has started.
- On acceptance, the quote amount is locked. Revorks may not later debit more credits for that job because a provider cost rose, an API failed, a provider rerouted a job, or an estimate was low.
- Credits are reserved only while the job is pending. Confirm/debit only after Revorks has persisted a usable output asset meeting disclosed minimum validation; otherwise release/refund the reservation exactly once.
- If a provider permanently closes a route before the user submits a job, Revorks must either preserve the credits for other eligible services through their disclosed expiry or refund them where law, the purchase terms, or an inability to provide the paid core service requires it. Never represent provider-specific capacity as guaranteed unless it is actually reserved.
- If closure happens after a quote but before submission, automatically release the reservation and offer a new quote/alternative only with the user’s affirmative selection.
- If closure/outage happens after submission but before a usable output, release/refund the reserved credits; do not charge for a failed, unavailable, policy-blocked or unusable job except where the user expressly received a disclosed, separately valuable completed service and law permits the charge.
- If a valid output was delivered and later becomes unavailable due to an external provider URL, Revorks must use its own durable storage policy; provider URL expiry is not a valid reason to charge without delivery.
- If Revorks retires a whole paid feature, publish advance notice where practical, stop selling it, provide a reasonable remaining-use/migration path, and evaluate refund/credit extension obligations by jurisdiction and plan. A blanket “no refunds on shutdown” term is high risk for consumers.
- Define objective “successful generation,” “technical failure,” “moderation rejection,” “user cancellation before start,” “duplicate request,” “partial output,” “corrupt output,” and “provider cancellation.” Specify the credit treatment for each.
- Keep an auditable job, quote, output-delivery and credit-ledger record; show the user job status and credit result.
4.6 Fees, taxes, credits, subscriptions and billing
Pre-purchase disclosures
- currency; price inclusive/exclusive of tax; applicable VAT/sales-tax treatment; total price before checkout; what credit amount buys; expiry; restrictions; auto-renewal; next renewal date/price; cancellation route; trial end/price; and invoice/receipt availability;
- an explicit affirmative purchase control. No pre-ticked paid extras, hidden fees, or dark patterns;
- credit valuation must be a product rule, not a claim of cash value or a promised number of outputs; model prices and parameter combinations vary;
- distinguish purchased, subscription, promotional, refunded, expired and disputed credit lots. State spend order and whether credit grants are transferable.
Credit rules
- when credits are granted; when they expire; time zone; displayed expiry date; whether unused subscription credits roll over; whether promotional credits expire earlier; and notice before material expiry where required;
- no cash redemption or transfer except where mandatory law requires otherwise; no resale, exchange, gambling, lending or use as payment outside Revorks;
- price and credit-cost changes apply prospectively only, with required notice. Existing accepted quotes are honored; do not silently alter a purchased credit balance;
- fraud, unauthorized payment, chargeback and account-negative-balance process. Do not confiscate unrelated credits automatically without legal review and notice;
- account closure: access/export/deletion timeline; treatment of unused paid credits by closure reason and local mandatory law;
- promotional-credit eligibility, non-combinability, abuse prevention, withdrawal and expiration.
Refunds, cancellation and consumer rights
- distinguish: (a) refund for failed/non-delivered generation; (b) discretionary goodwill refund; (c) statutory withdrawal/cooling-off; (d) statutory remedy for nonconforming digital service; (e) payment reversal/chargeback; and (f) MoR-managed refund;
- describe the exact request channel, required evidence, deadline, acknowledgement, investigation time, partial refund logic, original payment method and tax reversal;
- do not say “all purchases are final” without jurisdiction-specific exceptions;
- for EU consumers, obtain the required separate, affirmative consent to immediate performance of digital content/service and acknowledgement of loss of withdrawal right only where the legal conditions actually apply. Preserve evidence. If conditions are not met, do not claim the withdrawal right was lost. Consumers may have remedies for faulty/nonconforming digital services even after use;
- show a compliant cancellation mechanism for recurring subscriptions; cancellation should stop future renewal, and state whether the current paid period continues;
- state that mandatory consumer protections, chargeback rights and law cannot be waived. MoR terms may control the payment transaction but Revorks remains responsible for clearly allocating support/fulfilment responsibility.
4.7 User content, rights, permissions and AI outputs
- user retains rights in input to the extent they own them; user grants Revorks a limited worldwide, non-exclusive, sublicensable-to-providers license solely to host, reproduce, transform, transmit, process, moderate, secure, troubleshoot and generate outputs from the input, plus any separately chosen public-sharing license;
- require user to have every necessary right, permission, release, privacy/biometric consent and legal basis for input, references, faces, voices, trademarks, copyrighted works, personal data and instructions;
- no warranty that output is unique, available for copyright, non-infringing, fit for purpose, accurate, or eligible for trademark/other registration; similar output may be generated for others;
- allocate output rights only “as between Revorks and user” and only to the extent Revorks receives rights and law permits. Pass through any provider-specific conditions. Do not promise ownership in a model/provider output when the applicable provider terms do not allow it;
- clarify commercial-use scope per plan/route. If commercial use is allowed, it does not grant rights in third-party subjects, trademarks, copyrighted source material or real persons;
- no use of Revorks names/logos/model-provider marks except permitted brand guidelines;
- user obligation to review output before publishing/using it and to label synthetic or altered media when required by law, platform policy, audience context or provider terms;
- no automatic claim by Revorks to train on user content. If any improvement/training use is wanted, identify scope, legal basis, whether opt-in is required, withdrawal effect, retention and provider involvement in the Privacy Notice and contract;
- preserve necessary safety/audit records even after user deletion where lawful; disclose the retention basis and duration.
4.8 Likeness, voice, avatars, lip-sync and synthetic media
These require a dedicated affirmative attestation at job submission, not only a buried ToU clause.
- user represents they are the depicted/sounded person or have documented authorization from each identifiable person, including voice and likeness rights; for minors, verified parent/legal guardian authority and a stricter product policy;
- prohibit non-consensual intimate/deceptive deepfakes, impersonation for fraud or harassment, political/election deception where prohibited, fabricated evidence, unauthorized endorsements, harmful sexualization, and evasion of watermark/disclosure controls;
- require a separate consent record with subject identity, scope, media, purpose, date, withdrawal channel and verifier; define retention/deletion handling;
- explain content-review, refusal, suspension, escalation to rights holders/authorities where required, and appeals;
- require users to make required “AI-generated/altered” disclosures and prohibit removal/obscuring of safety labels, provenance metadata or watermarks;
- consent withdrawal cannot retroactively undo already lawfully completed jobs, but must stop future use/generation subject to law and allow prompt assessment/takedown/deletion requests;
- state that Revorks does not verify every claimed right or consent, but may require evidence or refuse/suspend a job/account.
4.9 Acceptable Use and enforcement
Make the policy readable, enumerated and provider-compatible. Prohibit at minimum:
- illegal activity, sanctions/export violations, fraud, phishing, deception, malware, credential theft, evasion of safety controls, scraping/service abuse and unauthorized automation;
- exploitation/sexualization of minors; CSAM; grooming; non-consensual intimate imagery; sexual violence; doxxing; stalking; threats; extortion; hate or targeted harassment as defined by policy/law;
- instructions/assets intended for physical harm, weapons, self-harm promotion, terrorism/extremism, illicit drugs or criminal facilitation;
- deceptive impersonation, financial scams, fabricated official documents/evidence, false medical/legal/financial claims, or political/election manipulation where prohibited;
- infringement of copyright, trademark, privacy, publicity, trade-secret or other rights; circumvention of rights-management measures;
- collecting/uploading sensitive personal data without lawful authority; biometric/face/voice misuse;
- generating outputs for prohibited high-impact automated decision-making;
- reverse engineering, benchmark publication where provider terms prohibit it, model extraction, competing-model training, resale of raw provider access, bypassing rate/spend limits, or use of service to build/operate a competing model where the applicable provider disallows it;
- use that violates provider terms or documentation. Maintain a route-specific restrictions register; a broad pass-through clause alone is insufficient if users cannot see material restrictions.
Set the enforcement ladder: pre-generation block; post-generation removal; warning; credit release where no service was delivered; credit forfeiture only for deliberate abuse after legal review; feature restriction; temporary suspension; permanent termination; payment-fraud action; report to authority where legally required. State evidence handling, non-retaliation for good-faith reports, and an accessible appeal process.
4.10 Moderation, notices, complaints and transparency
- explain what automated classifiers, provider filters, hash matching, metadata checks and human review may be used; do not overstate accuracy;
- disclose that content may be reviewed by trained personnel or processors for safety, abuse, support, legal compliance, billing/fraud and quality where the Privacy Notice permits;
- give clear user notices for account/content decisions, reason category, scope/duration, available appeal method and relevant evidence limits;
- establish reporting channels for illegal content, IP claims, privacy/likeness claims, child-safety emergencies, security reports and law-enforcement requests;
- define response priority and recordkeeping; distinguish urgent non-consensual intimate imagery/child-safety reports from ordinary IP disputes;
- if EU intermediary obligations apply, Terms must describe user-content restrictions, moderation policies/tools including algorithmic and human review, and internal complaint rules in clear, accessible, machine-readable language. The Digital Services Act Article 14 requires this transparency. EUR-Lex, Article 14
- if hosting user-accessible/public content in the US and relying on DMCA safe harbor, name and register a designated agent, publish the notice process, act expeditiously on valid notices, provide counter-notice handling, and adopt/implement a repeat-infringer policy. U.S. Copyright Office
4.11 Privacy, data protection and security references
The ToU should incorporate but not duplicate the Privacy Notice. It must accurately state:
- controller identity/contact, privacy contact/DPO if applicable, data categories, purposes, legal bases, recipients/subprocessors, international transfers, retention, security summary and data-subject rights;
- special/sensitive data treatment for face, voice, identification documents, payment data, prompts containing personal data, and moderation data;
- cross-border processing by model providers and storage providers; region availability must be truthful;
- user duty not to submit personal data absent authority, but that duty does not eliminate Revorks’ own obligations;
- account security, incident communication and legal-disclosure policy;
- enterprise controller/processor role and DPA availability. Controller/processor allocation must follow actual decision-making, not merely labels. ICO guidance
- cookie/SDK choices belong in a Cookie Notice and consent implementation; do not bury cookie consent inside the ToU.
4.12 Intellectual-property complaints and repeat infringement
- provide a dedicated contact/form and required fields for copyright, trademark, right-of-publicity, privacy and defamation complaints;
- distinguish claimed infringing input, output, public share and private storage; define what can actually be disabled or deleted;
- good-faith and authority statements, anti-abuse warning, counter-notification/appeal path, restoration criteria, and repeat-infringer escalation;
- preserve evidence without public disclosure; balance claimant/user privacy;
- no assertion that AI output is automatically copyrightable or cleared; users remain responsible for downstream clearance;
- legal-hold exception to deletion and disclosure of legal demands;
- if public assets can be accessed, implement notice-and-action and complaint controls before launch, not later.
4.13 Warranties, disclaimers, liability and indemnity
- state services and outputs are provided as available/as is to the maximum lawful extent, with no warranty of availability, accuracy, quality, uniqueness, legality, non-infringement, fitness, merchantability, merchantable quality or results;
- specific warning that generative outputs may be inaccurate, offensive, unsafe, similar to others’ outputs, improperly filtered or unavailable; users must apply human review;
- preserve non-excludable statutory consumer rights and do not use disclaimers that contradict advertised service functionality;
- choose a liability cap that is defensible for the customer type: e.g., fees paid in a stated prior period for B2B, subject to mandatory law; no cap for fraud, willful misconduct, death/personal injury where non-excludable, or other mandatory exceptions;
- exclude indirect/consequential/lost-profit/data/reputation damages only to the extent lawful;
- user indemnity for unauthorized inputs, likeness/voice rights, unlawful use and breach of terms; define notice, control of defense, cooperation and settlement limits. Do not rely solely on an indemnity for consumer claims;
- any Revorks IP indemnity must be separately negotiated/limited and must not purport to pass through an upstream indemnity beyond its actual scope. For example, OpenAI’s API-related output indemnity has material exclusions, including lack of input rights, ignored safeguards and trademark claims. OpenAI Service Terms
4.14 Suspension, termination, account closure and survival
- suspension must be proportionate where feasible; immediate suspension is allowed for legal, child safety, security, fraud, sanctions, severe abuse, provider requirement or material risk;
- explain effect on pending jobs, stored content, paid credits, subscription renewal, public shares and data export/deletion;
- do not seize paid credits simply because a user ends an account unless a clearly disclosed, lawful expiry/closure rule applies; distinguish user-initiated closure, abuse termination, fraud, bankruptcy and platform discontinuance;
- define post-termination access window, export format, deletion/backups/legal holds and survival of payment, IP, audit, liability, dispute and enforcement provisions.
4.15 Disputes, law, notices and local mandatory rights
- choose governing law and venue/arbitration only after D1–D3 and D14 are decided;
- include a consumer-residence mandatory-law carve-out; do not assert a foreign-law choice eliminates statutory consumer protection;
- make arbitration/class-action terms optional and jurisdiction-reviewed; provide any legally required opt-out and small-claims/regulator rights;
- include informal resolution process, correct notice addresses, time limits only if enforceable, language and accessibility;
- identify EU online-consumer complaint alternatives only where current law requires/recommends them; do not copy obsolete platform links;
- version-controlled notice method for material changes, legal notices and service notices.
5. Required product controls behind the legal text
| Control | Why the terms need it |
|---|---|
| Versioned acceptance ledger | prove which Terms/policies/consents a user accepted |
| Quote snapshot + idempotency key | honor price and prevent double charge |
| Credit reservation/confirm/release ledger | prove success/failure/refund treatment |
| Provider route lifecycle and kill switch | safely withdraw discontinued/blocked APIs |
| Durable output storage and validation | never charge without deliverable output |
| Price/version registry | avoid silent price or route changes |
| Billing/refund/chargeback case system | apply published policy consistently |
| Consent records for face/voice/avatar | prove authority and honor withdrawal/deletion |
| Notice-and-takedown + appeal system | handle IP/privacy/safety complaints |
| Moderation decision log | give required reasons, audit and appeal |
| Account suspension and sanctions controls | enforce terms fairly and legally |
| Data retention/deletion/subprocessor inventory | make Privacy Notice and DPA true |
| Accessible cancellation and export flows | consumer and privacy compliance |
| Public-sharing controls | only if shares/galleries are enabled |
6. Provider-contract audit: mandatory before enabling a route
For every provider and model route, retain a dated legal/commercial record containing:
- agreement URL/version or signed order form;
- whether Revorks may provide the API/model in a customer-facing product, resell access, and pass output rights to customers;
- territory, sanctions/export and age restrictions;
- allowed and prohibited use categories;
- input/output ownership and commercial-use terms;
- training/retention/use of customer data;
- privacy role, DPA, subprocessors and transfer mechanism;
- moderation, reporting, provenance/watermark and disclosure obligations;
- price, minimum commitment, wallet/prepayment, tax and refund rules;
- rate limits, availability, deprecation/termination notice, export/output retrieval window;
- API key/account-sharing restrictions;
- warranty, indemnity, liability cap, audit and insurance terms;
- operational contact and escalation path;
- a product decision: ENABLED, LIMITED, CONTRACT REQUIRED, TERMS BLOCKED, DEPRECATED or RETIRED.
The launch specification already flags key examples: do not launch Sora; Imagen 4 is removed; D-ID requires contract pricing; Hedra’s public API terms prohibit customer-facing integration absent written commercial permission. Treat all current provider terms as volatile and re-review at each model/price/policy change.
7. Minimum checkout and generation disclosures
At account creation
- links to Terms, Privacy Notice and Acceptable Use Policy;
- age/authority attestation;
- country/region availability and any sanctions notice;
- marketing consent separate from service acceptance.
At credit/subscription checkout
- seller/MoR identity; item, credits, price, currency, tax, expiry/carryover, renewal terms; cancellation path; refund/withdrawal rights; and invoice;
- separate immediate-performance/withdrawal acknowledgement where legally appropriate;
- no default opt-ins and no misleading “credits equal cash” presentation.
Immediately before a generation
- parameters, exact credit quote, expiry, expected variability, selection/availability of route, whether content is sent to a third-party provider, and estimated processing status;
- for likeness/voice: separate consent/authority attestation, synthetic-media disclosure duties and prohibited-use reminder;
- for sensitive input: warning not to upload unless authorized.
At completion or failure
- durable download/view link, retention deadline, status, charged/refunded credits, reason category, support/appeal path, and preservation of accepted price;
- no vague “something went wrong” when a meaningful provider/moderation/cancellation/asset reason can be safely provided.
8. Launch gate for legal publication
Do not publish “final” Terms until each item is complete:
- D1–D15 are decided and recorded.
- Counsel reviews governing law, markets, consumer cancellation/refund language, privacy, AI/deepfake and IP rules.
- Payment/MoR agreement, tax ownership and checkout disclosures are confirmed.
- Every enabled provider passes the provider-contract audit.
- Pricing, credit lots, expiration, refund, failed-job and shutdown behavior match live code.
- Privacy Notice/DPA/subprocessor list match actual data flows and retention.
- Consent evidence, takedown, moderation, appeal and deletion workflows are operating and staffed.
- Terms, AUP, Privacy, Refund/Cancellation, Consent, IP and cookie documents are cross-linked and versioned.
- Translations are legally reviewed; Russian/English precedence is expressly chosen.
- Customer support macros and dashboards match the published rules.
9. Research notes and source baseline
This brief is not a substitute for jurisdictional legal advice. It reflects current official baseline sources checked on 2026-08-27:
- The EU Consumer Rights Directive harmonises pre-contract information and withdrawal rights for distance contracts; digital content has specific conditions for loss of the withdrawal right. European Commission
- EU digital-content/digital-services rules provide consumer remedies where services are faulty, including where the consumer provides personal data instead of money. European Commission
- EU DSA Article 14 requires intermediary-service terms to explain restrictions, content moderation tools (including algorithms and human review) and internal complaint procedures in clear, accessible language. EUR-Lex
- A US service provider seeking DMCA hosting safe-harbor protection needs a current designated agent and a compliant notice process. U.S. Copyright Office
- Provider terms may allocate output rights, commercial use, data use and indemnity differently, and their restrictions flow downstream. For example, OpenAI’s output indemnity contains specific exclusions. OpenAI Service Terms
- Runway publicly says users retain rights in their generations as between them and Runway and may use them commercially, but this cannot replace verification of the particular API/enterprise route used by Revorks. Runway Help