Licensing had been a single screen trying to cover four separate relationships: what a contributor grants us, what we grant a reader, what our trademarks cover, and what open-source software we build on. Those are four different questions asked by four different people, and answering them in one document meant none of them was answered properly. They are now four documents.
The Privacy Policy had committed to publishing a list of sub-processors — the third parties that handle data on our behalf — and that list did not exist. A policy that promises a document and does not publish it is worse than one that never promised, because it looks compliant to anybody who does not check. It is published.
We also stopped reproducing our parent company’s policies as though they were our own. They describe a different company doing different things with different data, and copying them here produced documents that were inaccurate about us in specifics that matter. Where a parent policy genuinely governs, it is now linked rather than copied.
The open-source acknowledgement takes a deliberate position worth flagging: it acknowledges the licences and does not publish the package-and-version manifest. A published manifest states exactly which libraries at exactly which versions run on every installation, which is directly useful to somebody matching them against known vulnerabilities and of little use to anybody else. The full attribution list is provided on request.
Everything in this release
- Added
Licensing split into four documents: contributor licence, platform licence, trademark, and open-source acknowledgement.
- Added
The Sub-processors document the Privacy Policy had promised.
- Removed
Copies of our parent company’s policies, which described a different company.
Where a parent policy genuinely governs, it is linked instead.