Skip to content

feat: add terms & privacy links to providers - #2290

Merged
smakosh merged 5 commits into
theopenco:mainfrom
analogpvt:feat/provider-compliance
May 15, 2026
Merged

smakosh merged 5 commits into
theopenco:mainfrom
analogpvt:feat/provider-compliance

Conversation

@analogpvt

@analogpvt analogpvt commented May 14, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Add termsUrl and privacyPolicyUrl fields to ProviderDefinition interface and all provider entries
  • Display Terms of Service and Privacy Policy links on each provider's hero page (/providers/<id>)
  • Links open in new tab with external link icon indicator

Changes

  • packages/models/src/providers.ts — added URL fields to interface + all 30 providers
  • apps/ui/src/components/providers/hero.tsx — render links below action buttons

Test plan

  • Visit /providers/openai and verify Terms/Privacy links appear and open correctly
  • Visit /providers/glacier (null URLs) and verify no links section renders
  • Verify TypeScript builds without errors

🤖 Generated with Claude Code

Summary by CodeRabbit

  • New Features
    • Added Terms of Service and Privacy Policy links for providers. These legal links now appear beneath primary action buttons when available, clearly marked with external link indicators for easy access.

Review Change Stack

@coderabbitai

coderabbitai Bot commented May 14, 2026 •

Copy link
Copy Markdown
Contributor

Walkthrough

This PR adds optional Terms of Service and Privacy Policy URLs to the provider model, populates those fields across all provider entries, and integrates UI rendering in the Hero component to display these legal links with external link icons when available.

Changes

Provider Legal Links Feature

Layer / File(s) Summary
ProviderDefinition legal URLs contract
packages/models/src/providers.ts
ProviderDefinition interface declares optional termsUrl and privacyPolicyUrl fields (nullable strings) for storing provider legal document URLs.
Provider entries legal URL population
packages/models/src/providers.ts
All 25+ provider entries in the providers array are populated with termsUrl and privacyPolicyUrl fields containing provider-specific legal document URLs or null when unavailable.
Hero component legal links UI
apps/ui/src/components/providers/hero.tsx
Hero component imports ExternalLink icon and conditionally renders Terms of Service and Privacy Policy links beneath action buttons, with a visual separator when both links exist.

🎯 2 (Simple) | ⏱️ ~12 minutes

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title accurately and concisely summarizes the main change: adding terms and privacy policy links to provider definitions and displaying them in the UI.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

Spec and plan for adding compliance & trust documentation
to provider definitions (terms, privacy, certifications,
data policy, additional links).

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 4

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@docs/superpowers/plans/2026-05-14-provider-compliance.md`:
- Around line 83-444: The plan currently hardcodes provider compliance claims
without provenance; add mandatory source citation fields to each provider
"compliance" object by introducing sourceUrl (string) and verifiedOn (ISO date
string) and require they be populated for every Step 1..27 and the "llmgateway"
entry; update all example compliance objects (the ones containing termsUrl,
privacyPolicyUrl, certifications, dataPolicy, additionalLinks) to include these
two new fields and add a note/validation rule in the document that entries
missing sourceUrl or verifiedOn are considered unverified and must be completed
before publishing.
- Around line 529-547: The provider schema and plan disagree on whether
compliance fields are top-level or nested under provider.compliance; pick one
shape (preferably the one used by Task 8 or whichever current runtime consumers
expect) and make it consistent: if you choose nested, modify providerSchema (the
z.object) to replace top-level fields (certifications, dataPolicy, termsUrl,
privacyPolicyUrl, additionalLinks, announcement, status, etc.) with a single
compliance: z.object({...}) property; if you choose flat, update all code that
reads provider.compliance (references like provider.compliance) to read
provider.certifications, provider.dataPolicy, etc., and then update DB sync
mappings, API schema/serializers, UI TypeScript types, and page usage to the
chosen shape so database writes, API payloads, and front-end access are aligned
across providerSchema and consumer code.

In `@docs/superpowers/specs/2026-05-14-provider-compliance-design.md`:
- Around line 84-87: The Data Population section currently omits provenance and
freshness requirements for compliance claims; update the spec to require
provenance fields (e.g., sourceUrl/sourceTitle), a verificationDate,
lastReviewedBy/reviewerId, a reviewCadence or expiryDate, and an
evidenceConfidenceLevel for each provider compliance entry, and specify that
even if other fields are undefined these provenance/freshness fields must be
populated and re-validated on the defined cadence; reference the "Data
Population" section and the compliance claim model when adding these required
fields and the periodic review process.
- Around line 56-62: The certifications column definition in the schema snippet
is inconsistent with the implementation plan; pick a single canonical form and
update both places to match (either use certifications: text().array() or
certifications: text().$type<string[]>().array()). Locate and change the schema
snippet that defines certifications as well as the implementation plan entry so
both use the same form, and ensure related symbols (termsUrl, privacyPolicyUrl,
certifications, dataPolicy, additionalLinks) remain syntactically consistent
after the change.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro

Run ID: 2aa547fd-efe1-4715-ae58-e59d2bc1fa46

📥 Commits

Reviewing files that changed from the base of the PR and between 91fd2d7 and 5a4a21b.

📒 Files selected for processing (2)
  • docs/superpowers/plans/2026-05-14-provider-compliance.md
  • docs/superpowers/specs/2026-05-14-provider-compliance-design.md

Comment thread docs/superpowers/plans/2026-05-14-provider-compliance.md Outdated
Comment thread docs/superpowers/plans/2026-05-14-provider-compliance.md Outdated
Comment thread docs/superpowers/specs/2026-05-14-provider-compliance-design.md Outdated
Comment thread docs/superpowers/specs/2026-05-14-provider-compliance-design.md Outdated
- Add sourceUrl + verifiedOn fields for provenance tracking
- Clarify flat-vs-nested architecture (models: nested, DB/API: flat)
- Align certifications column syntax to text().array() consistently
- Add verification/freshness policy (90-day review cadence)

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@analogpvt
analogpvt force-pushed the feat/provider-compliance branch from 5a4a21b to 4d5307d Compare May 14, 2026 18:19
Add termsUrl and privacyPolicyUrl fields to all provider definitions
and display them on the provider hero page with external link icons.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@analogpvt analogpvt changed the title feat: add provider compliance & trust docs feat: add terms & privacy links to providers May 14, 2026
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🧹 Nitpick comments (1)
apps/ui/src/components/providers/hero.tsx (1)

73-99: ⚡ Quick win

Use next/link for the new legal links.

The newly added legal links use raw <a> elements; this frontend guideline requires next/link for link navigation.

Suggested patch
 import { ExternalLink, Play } from "lucide-react";
+import Link from "next/link";
@@
-							{provider.termsUrl && (
-								<a
-									href={provider.termsUrl}
-									target="_blank"
-									rel="noopener noreferrer"
-									className="inline-flex items-center gap-1 hover:text-foreground transition-colors"
-								>
+							{provider.termsUrl && (
+								<Link
+									href={provider.termsUrl}
+									target="_blank"
+									rel="noopener noreferrer"
+									className="inline-flex items-center gap-1 hover:text-foreground transition-colors"
+								>
 									Terms of Service
 									<ExternalLink className="h-3 w-3" />
-								</a>
+								</Link>
 							)}
@@
-							{provider.privacyPolicyUrl && (
-								<a
-									href={provider.privacyPolicyUrl}
-									target="_blank"
-									rel="noopener noreferrer"
-									className="inline-flex items-center gap-1 hover:text-foreground transition-colors"
-								>
+							{provider.privacyPolicyUrl && (
+								<Link
+									href={provider.privacyPolicyUrl}
+									target="_blank"
+									rel="noopener noreferrer"
+									className="inline-flex items-center gap-1 hover:text-foreground transition-colors"
+								>
 									Privacy Policy
 									<ExternalLink className="h-3 w-3" />
-								</a>
+								</Link>
 							)}

As per coding guidelines, "Use next/link for links and next/navigation's router for programmatic navigation".

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@apps/ui/src/components/providers/hero.tsx` around lines 73 - 99, Replace the
raw <a> elements used for provider.termsUrl and provider.privacyPolicyUrl with
Next.js Link components: import Link from 'next/link', then render <Link
href={provider.termsUrl} target="_blank" rel="noopener noreferrer"
className="...">Terms of Service<ExternalLink .../></Link> and similarly for
provider.privacyPolicyUrl, preserving the existing className, target/rel,
ExternalLink icon, and the conditional separator; ensure the conditional checks
still use provider.termsUrl and provider.privacyPolicyUrl so behavior is
unchanged.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Nitpick comments:
In `@apps/ui/src/components/providers/hero.tsx`:
- Around line 73-99: Replace the raw <a> elements used for provider.termsUrl and
provider.privacyPolicyUrl with Next.js Link components: import Link from
'next/link', then render <Link href={provider.termsUrl} target="_blank"
rel="noopener noreferrer" className="...">Terms of Service<ExternalLink
.../></Link> and similarly for provider.privacyPolicyUrl, preserving the
existing className, target/rel, ExternalLink icon, and the conditional
separator; ensure the conditional checks still use provider.termsUrl and
provider.privacyPolicyUrl so behavior is unchanged.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro

Run ID: 41b06047-4977-4423-99bc-1b35adf4882b

📥 Commits

Reviewing files that changed from the base of the PR and between 4d5307d and c9cf05b.

📒 Files selected for processing (2)
  • apps/ui/src/components/providers/hero.tsx
  • packages/models/src/providers.ts

@smakosh
smakosh enabled auto-merge May 15, 2026 09:06
@smakosh
smakosh added this pull request to the merge queue May 15, 2026
Merged via the queue into theopenco:main with commit 8825aca May 15, 2026
10 checks passed
steebchen pushed a commit that referenced this pull request May 15, 2026
## Summary

Fixes broken (404/403) terms of service and privacy policy URLs for 8
providers. All replacement URLs verified working.

### Changes

| Provider | Link | Old (broken) | New (working) |
|----------|------|-------------|---------------|
| anthropic | terms | `/policies/terms-of-service` (404) | `/terms` ✅ |
| anthropic | privacy | `/policies/privacy` (404) | `/privacy` ✅ |
| deepseek | terms | `chat.deepseek.com/downloads/...` (403) |
`cdn.deepseek.com/policies/en-US/deepseek-terms-of-use.html` ✅ |
| deepseek | privacy | `chat.deepseek.com/downloads/...` (403) |
`cdn.deepseek.com/policies/en-US/deepseek-privacy-policy.html` ✅ |
| zai | terms | `z.ai/terms` (404) |
`docs.z.ai/legal-agreement/terms-of-use` ✅ |
| zai | privacy | `z.ai/privacy` (404) |
`docs.z.ai/legal-agreement/privacy-policy` ✅ |
| moonshot | terms | `platform.moonshot.cn/docs/terms` (404) |
`moonshot.ai/terms` ✅ |
| moonshot | privacy | `platform.moonshot.cn/docs/privacy` (404) |
`moonshot.ai/privacy` ✅ |
| nebius | terms | `nebius.com/legal/terms-of-service` (404) |
`docs.nebius.com/legal/terms-of-use` ✅ |
| nebius | privacy | `nebius.com/legal/privacy-policy` (404) |
`docs.nebius.com/legal/privacy` ✅ |
| inference.net | terms | `/terms` (404) | `/terms-of-service` ✅ |
| inference.net | privacy | `/privacy` (404) | `/privacy-policy` ✅ |
| together-ai | privacy | `/privacy-policy` (404) | `/privacy` ✅ |
| nanogpt | terms | `/terms` (404) | `/legal/terms-of-service` ✅ |
| nanogpt | privacy | `/privacy` (200→canonical) |
`/legal/privacy-policy` ✅ |

### Verification

All 52 URLs (26 providers × 2 links) tested:
- **46** return HTTP 200
- **6** return HTTP 403 (bot-protected: OpenAI, xAI, Perplexity —
correct official URLs, work in browser)
- **0** failures

Closes #2290

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Chores**
* Updated terms of service and/or privacy policy URLs for multiple AI
provider integrations: Anthropic, Google AI Studio (privacy), Google
Vertex (privacy), DeepSeek, Alibaba, Zai, Moonshot, Nebius, Mistral
(terms), Inference.net, TogetherAI (privacy), NanoGPT,
BytePlus/Bytedance, Xiaomi.
  * Link updates only; no functional, behavioral, or public API changes.

<!-- review_stack_entry_start -->

[![Review Change
Stack](https://storage.googleapis.com/coderabbit_public_assets/review-stack-in-coderabbit-ui.svg)](https://app.coderabbit.ai/change-stack/theopenco/llmgateway/pull/2297)

<!-- review_stack_entry_end -->
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Link Fix Bot <bot@llmgateway.io>
Co-authored-by: Ismail Ghallou <ismai23l@hotmail.com>
Co-authored-by: openclaw-bot <bot@openclaw.ai>
@coderabbitai coderabbitai Bot mentioned this pull request May 29, 2026
4 of 6 tasks
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants