All documents · Legal posture

Legal and compliance posture

Date: 18 September 2026
This is not legal advice. Counsel reviews before any public Terms, Privacy, or launch. Operator of the site; VPS in Germany; do not invent a US entity in the footer.

Raw challenge: /root/cryptobook-next/challenges/legal.md.


1. Intended operating picture (if a later SaaS ships)

EU AI Act: full high-risk regime from 2 August 2026. Most ordinary SaaS is limited risk (Article 50 transparency) if it is not Annex III. Disclosure: if a playground uses a scripted “demo agent,” say it is not a human reviewer.


2. United States — lines we will not cross

Topic Rule for this project
Money transmission Do not hold customer funds or resell model tokens as a wallet
Securities / crypto tokens No token, no “receipt coin”
CFAA / unauthorized access No product that logs into third-party sites for the user. Ninth Circuit Amazon v. Perplexity, No. 26-1444 (2026): agents act for the user. After an allow, the user is the actor. We do not originate vendor-to-site TCP
Consumer reports Receipts are logs, not employment/credit scores
Medical / hiring / credit decisioning Out of scope
Children’s data Out of scope
“We make you compliant” Forbidden. No SOC 2 / HIPAA / AI Act / NIST certification claims

3. Data we may collect (holding page)

3b. Data we may collect (later SaaS, if GO)

Retention sketch from the killed spec (reuse only if applicable): Free inbox 7 days; paid 90 days; playground 2 hours.


4. Copy required on every public page

Not legal advice. Not a compliance certification. Not an auditor. US-oriented. 18+.

Holding page additional:

CryptoBook social features are not offered here. This is a Virtus Labs property.


5. Contact

Do not publish root@ as a public legal address. Use a mailbox you will actually read, e.g. legal@cryptobook.space after it exists, or the Virtus contact already on virtusblockchainlabs.com.


6. Counsel checklist before launch