Blog

All posts
John Damask · 2026-03-12
devloglegalarchitecturelaunch

The Problem

Now I Get It! takes copyrighted scientific papers and transforms them into public, interactive web pages. That's the whole point -- making research accessible to anyone. But "takes copyrighted papers and publishes them on the internet" is the kind of sentence that should make you think carefully about the legal foundation underneath.

With user accounts and payments on the roadmap, the legal groundwork couldn't wait. I needed three things: a privacy policy that covers real data collection, terms of service that define the relationship between users and the platform, and -- most importantly -- a copyright management system that lets us operate responsibly under the DMCA.

Privacy Policy

The privacy policy covers CCPA, GDPR, CAN-SPAM, and a handful of newer state laws that took effect in 2026. The interesting decision was how much to say about specific vendors. Most frameworks only require disclosure of "categories of third parties" -- so the default is generic language like "cloud infrastructure providers" and "analytics providers."

There's one exception where I wanted to be more specific. The privacy policy claims "your documents are not used to train AI models." That's a strong promise, and I didn't want to make it without receipts. Anthropic's Commercial Terms of Service state it plainly: "Anthropic may not train models on Customer Content from Services." Those exact contract quotes went into the privacy policy -- the only vendor named by name, and the only place I cite contract language verbatim. If the terms ever change, the quotes make it obvious the policy needs updating.

Terms of Service

The ToS defines the intellectual property relationship. Users retain all rights to the PDFs they upload. Amroja LLC (my company) owns the platform and the generated presentation format. Users get a license to share their translations, but we retain the right to remove content if it violates third-party rights.

One deliberate choice: unlike the privacy policy, the ToS keeps all AI references generic -- "third-party AI services" rather than naming Anthropic. The ToS governs the user relationship, and switching providers shouldn't require a legal update.

Copyright Management -- The Big One

This is the piece I care most about. Now I Get It! exists to make science more accessible. But making science accessible doesn't mean ignoring the rights of the people who created it. If a publisher or author says "take this down," I need to be able to respond quickly and transparently.

The DMCA's safe harbor framework provides strong legal protection for platforms -- but only if you follow the rules. The rules are straightforward: don't knowingly host infringing content, respond quickly to valid takedown notices, maintain a repeat-infringer policy, and register a designated agent with the US Copyright Office.

The Takedown System

I built a full takedown request pipeline. The copyright policy page includes an embedded form where anyone can report content they believe infringes copyright law. The form captures what you'd expect -- the copyrighted work, the infringing URL, the claimant's relationship to the work, and legal declarations under penalty of perjury. When someone submits a request, it writes to a dedicated DynamoDB table, sends me an email notification through SNS, and fires off a confirmation email to the claimant via Postmark.

On the admin side, I can review requests and take four actions: approve (which backs up the page and replaces it with a "removed" notice), reject (with notes explaining why), restore (if a takedown was approved in error), or just list and filter requests. The backup-and-replace approach was a deliberate choice over hard deletion -- S3 deletes are permanent, but keeping a backup means mistakes are reversible.

What Goes on Every Page

Every translation now includes a copyright notice, and the language varies by mode. Transformative translations (non-technical and kid-friendly modes) note that the page is "an AI-generated transformative work" that "does not reproduce the original work in its entirety." Native-mode translations -- which stay closer to the original text -- carry stronger language: "for personal use only" and "does not replace the original publication."

Registering as a DMCA Agent

The last step was outside the codebase entirely. I registered Amroja LLC as a DMCA designated agent with the US Copyright Office. This is a legal requirement for safe harbor -- the Copyright Office maintains a public directory, and platforms that aren't listed can't claim protection if sued. The registration covers both "Amroja LLC" and "Now I Get It!" as service names.

What's Next: Private by Default

Right now, all translations are public. That changes when user accounts ship. Once accounts are in place, every translation will be private by default -- visible only to the person who created it. Users will decide what they share, not us. That's a better model for copyright too: if a translation never leaves someone's personal workspace, the fair use argument is much stronger. Public sharing becomes an explicit choice, not an automatic consequence of uploading a PDF.

The Full Picture

All three documents -- privacy policy, terms of service, and copyright policy -- live on a policies hub page linked from every footer across the site. It's not the most exciting feature I've built, but it might be the most important. Making science accessible is the mission. Doing it in a way that respects the people who created the science is how the mission stays sustainable.