Culture Dive — Terms of Service
DRAFT FOR LEGAL REVIEW. This is not legal advice. This document was written by reading the Culture Dive codebase and describes what the system actually does today. No lawyer has reviewed it. Do not publish it, link to it, or ask anyone to agree to it until Spanish counsel has reviewed it and every [PLACEHOLDER: …] below has been filled in with a real, checked fact.
Version: [PLACEHOLDER: version number and effective date — set at publication]
1. Who we are
Culture Dive is operated by APC Labs SLU, a company registered in Spain.
- Registered name:
[PLACEHOLDER: exact legal name — APC Labs SLU is used throughout the repository, "Apc labs" appears on the live marketing site, and the two drafts in documents/ differ. Company secretary to confirm one spelling.] - Registration number:
[PLACEHOLDER: company registration / NIF — must come from the incorporation documents, not from the website.] - Registered address:
[PLACEHOLDER: registered office address — company secretary.] - Contact for these terms:
[PLACEHOLDER: single contact address. Today the draft ToS in documents/ gives a gmail.com address and the live site gives a different one. Pick one, on the company domain.]
In these terms, "we", "us" and "our" mean APC Labs SLU. "You" means the organisation that has bought Culture Dive, and the people that organisation invites to use it.
2. What Culture Dive is
Culture Dive is a managed service, not a self-serve software tool. That distinction runs through everything below.
Our staff research your brand, read what they find, and write the reports you receive. Software does the collecting and a first pass of the reading. A named person at APC Labs decides what goes into a report and publishes it.
Concretely, today:
- We ask AI answer engines a fixed set of questions about your brand and category, on a schedule, and store their answers.
- An AI model reads each stored answer and proposes a sentiment, a confidence figure, some themes and a one-sentence summary.
- A member of our staff reviews those proposals, decides what is true and what matters, and writes the report.
- You read the report in the Culture Dive portal.
You do not operate any AI system. There is no chat, no query box, no model selection and no API in the client portal. You receive a document. Section 12 sets out what that means in more detail.
3. Access is by invitation
There is no sign-up. Nobody can create an account.
- We create your organisation and workspace.
- A workspace administrator (yours or ours) invites a person by email address, and chooses their role.
- The invitation email contains a single-use link. It expires 48 hours after it is sent.
- Accepting the invitation creates the account and the workspace membership together.
If an invited person never accepts, the invitation record stays in our system. The Privacy Policy explains what that record contains and how long we keep it.
We may withdraw an invitation before it is used, and a workspace administrator may do the same.
4. Accounts and sign-in
- Sign-in is by emailed magic link. No password is set for you.
- You may add two-factor authentication (an authenticator app) or a passkey. We recommend both.
- "Sign out everywhere" immediately invalidates every existing session for your account.
- Your account is yours. Do not share the link, the credential or the session with anyone else. Each person who needs access needs their own invitation.
- We may end all of an account's sessions immediately if we believe it has been compromised or is being misused.
Identity and credentials are handled by Supabase Auth. Your password (if you set one), your authenticator secret and your passkeys are held there, not by us.
5. Organisations, workspaces and seats
- Your organisation is the contracting party.
- A workspace is one brand, market or programme of work. An organisation may have more than one.
- Data is isolated per workspace at the database level. A member of one workspace cannot read another workspace's data.
- Roles are: client, workspace administrator, and two internal staff roles. Only workspace administrators can invite people or change memberships.
- Some plans include a seat limit. When the limit is reached, no further invitations can be sent until a membership is revoked or the plan is changed.
Revoking a membership removes access. It does not delete the person's account record — see the Privacy Policy, section 12.
6. What you get, and what a report is
- A dashboard is a named, recurring report for one workspace.
- Each publication of a dashboard is a revision. Revisions are immutable: we never edit a published revision in place, we publish a new one. A report you read last month is still the report you read last month.
- Reports are period-scoped. Each carries the period it covers.
- Reports are served inside the portal in a locked-down frame, and cannot load anything from the internet. This is a security control, not a limitation on your use of the content.
We do not warrant that any dashboard will be published on a particular date unless a delivery schedule has been agreed in writing. [PLACEHOLDER: agreed delivery cadence and any lateness remedy — commercial, per contract.]
7. Buying: subscription and entitlement are separate
This is unusual and you should read it.
Paying us does not, by itself, unlock anything. Access is granted by an entitlement — a record we create against your workspace saying what you may see. Our authorisation system reads entitlements and nothing else. It never asks Stripe what you have paid for.
Why: it lets us serve arrangements that no standard plan describes — a bespoke scope, a pilot, a €0 beta, a dashboard granted while an invoice is in flight. The trade-off is that fulfilment is a step, not an automatic consequence of payment.
What this means in practice:
- When you place an order, we record it. Some orders complete automatically. Others need us to configure the workspace first, and we record a target date for that.
- We will grant the matching entitlement when we fulfil your order. If you have paid and the corresponding access has not appeared, tell us and we will fix it or refund it.
[PLACEHOLDER: the refund / service-credit commitment — commercial decision.] - If a subscription lapses, is cancelled or goes unpaid, we may revoke the entitlements it supported.
[PLACEHOLDER: notice period before revocation on non-payment.]
Payment is taken on a Stripe-hosted page. We never see or store your card details.
8. Fees, invoicing and tax
[PLACEHOLDER: this entire section — prices or a reference to an order form, currency, invoicing cycle, payment terms (the portal already displays Net 30 / Net 60 language), late payment interest, VAT treatment for EU and non-EU customers, and whether prices exclude tax. Finance to supply; counsel to check Spanish invoicing requirements.]
9. Your material
You give us material so we can do the work — most importantly your intended positioning: what you believe your brand stands for. You may also give us briefs, product information and context.
- You keep ownership of everything you give us.
- You grant us a licence to use it to run the service for you, for as long as we are running it.
- You confirm you have the right to give it to us.
- We treat it as confidential (section 14).
- We do not sell it, and we do not use it to build a product for anyone else.
[PLACEHOLDER: confirm whether aggregated, de-identified benchmark use across clients is permitted. Nothing in the code does this today. If the commercial answer is yes, it needs its own clause and a hard rule that it can never be re-identifying.]
10. Our material, and what you may do with a report
We own the Culture Dive platform, the methodology, the prompts, the templates and the report formats.
Subject to your having paid, we grant you a non-exclusive, non-transferable licence to use the reports we deliver, inside your organisation, for your own business purposes. That includes sharing them with your own staff and with advisers who are under a duty of confidentiality to you.
You may not:
- resell, syndicate or publish a report, in whole or in substantial part, outside your organisation;
- remove attribution or present our work as your own to a third party;
- use a report to build a competing product or service.
If you want to quote a report publicly, ask us. We will usually say yes with attribution. [PLACEHOLDER: confirm the public-quotation position and whether it needs written approval each time.]
11. Third-party content in reports
Reports quote and describe material that we did not write: answers produced by AI answer engines, and — when the relevant collectors are built — public posts, articles and reviews.
- We quote briefly, as evidence for a point. Our editorial rule is a 125-character cap on any quote from third-party content.
[PLACEHOLDER: this rule is stated in our internal conventions but is not enforced anywhere in the software. Either enforce it in code before this sentence is published, or delete the sentence. Do not publish a control we do not have.] - We do not grant you any licence to the underlying third-party content. Rights in it stay with whoever holds them.
- Some sources are marked in our system as link-only. Material from those sources is referenced by link and is not reproduced or sent to any AI model.
- If you want to reuse a quoted item beyond the report itself, you need permission from its owner, not from us.
12. AI: what we use, where it stops, and what we will tell you
We want this to be plain, because the market is full of vague claims.
Where AI is used today
1. Asking. We send a fixed set of questions about your brand to AI answer engines and store what they say. The questions are deliberately neutral. We do not steer the model towards a favourable answer, because the answer is the measurement.
2. Reading. One AI model reads each stored item and proposes a sentiment, a self-reported confidence figure, themes and a one-sentence summary.
Where AI is not used today
Insight generation, narrative generation and semantic search are designed but not built and not running. Nothing in the report you read has been written by a model.
The human gate
An AI proposal is a candidate, not a conclusion. A member of our staff keeps, kills or merges every candidate before it can inform a report, and a named person authors and publishes every report. Nothing reaches you unruled. This is a design rule of the product, not a courtesy.
What we record
For every AI call we record which model we asked for, which model actually answered, the version of the prompt contract used, and the tokens consumed. The reading attached to an item carries the model that produced it on the row itself.
What we commit to
- If we ever publish AI-generated prose in a report, we will label it as such and name the model, in the report. We will not slip generated narrative in unmarked.
- We will tell you before we introduce any AI feature that you operate directly, or that makes or supports a decision about an identifiable person.
- No automated decision is made about any individual that produces legal effects or similarly significant effects on them. There is no scoring, ranking or profiling of natural persons in this product.
AI accuracy — read this
AI answer engines are non-deterministic and frequently wrong. Their answers are the *subject* of our measurement, not a source of truth. We measure what they say about you. We do not warrant that what they say is accurate, and we do not warrant that a model's reading of an item is correct. That is why a person rules on everything.
Regulatory position
Our own assessment is that the AI systems we run are limited-risk under Regulation (EU) 2024/1689 (the EU AI Act): they are not prohibited practices, and they do not fall in any Annex III high-risk category. We do not train or place general-purpose AI models on the market. We will re-assess before building anything that profiles or ranks named individuals. [PLACEHOLDER: counsel to confirm this classification and to confirm the current application dates for Article 50, which may have been amended after this draft was written.]
13. Acceptable use
Do not:
- share sign-in links or sessions;
- attempt to reach another organisation's workspace or data;
- probe, scan or load-test the platform without our written permission;
- reverse-engineer, decompile or copy the platform;
- scrape the portal or automate access to it;
- upload material that is unlawful, or that you do not have the right to give us.
We may suspend access immediately if we reasonably believe any of these is happening, and will tell you why.
14. Confidentiality
Each of us will keep the other's confidential information confidential, use it only to perform this agreement, and protect it at least as carefully as our own. This does not cover information that is public through no fault of the recipient, was already known, or must be disclosed by law — in which case the recipient will tell the other first, if it is lawful to do so.
Your reports, your intended positioning and your briefs are your confidential information. The platform, our methodology and our prompts are ours.
[PLACEHOLDER: confidentiality survival period after termination.]
15. Data protection
- For the personal data of your staff and users, and for the material you give us, you are the controller and we act on your instructions.
- For our own operation of the service — running accounts, security, billing, our own records — we are the controller. Our Privacy Policy covers that.
- For public content we collect and analyse, we are the controller. The Privacy Policy covers that too, including how a person named in that content can object.
A data processing agreement is required and is not yet in place. [PLACEHOLDER: DPA — must be drafted and executed before any client personal data is processed under these terms. Counsel in Spain. The current sub-processor list is in the Privacy Policy and must be attached to the DPA and kept accurate.]
We will tell you without undue delay if we become aware of a personal data breach affecting your data, and give you what you need to meet your own 72-hour notification duty.
16. Availability and support
[PLACEHOLDER: this whole section. There is no uptime commitment, no support-hours commitment, no response-time commitment and no recovery objective agreed anywhere. The system emits an hourly liveness signal, so an uptime figure could be measured, but none has been chosen. A prototype screen advertises "Mon–Fri, 9:00–18:00 GMT" and a phone number that appears malformed — do not publish either without checking. Also decide: RPO/RTO, and whether point-in-time database recovery is purchased. It is not, today.]
We may take the service down for maintenance. We will give notice where we reasonably can.
17. Warranties and disclaimers
We warrant that we will provide the service with reasonable skill and care, and in line with the description in these terms.
We do not warrant that:
- the service will be uninterrupted or error-free;
- any AI answer engine's output is accurate;
- any conclusion in a report is correct, or that acting on it will produce a particular commercial outcome.
Reports are analysis and opinion. They are not financial, legal or regulatory advice, and they are not a substitute for your own judgement.
Everything else that can lawfully be excluded is excluded. Nothing in these terms limits any right you have as a consumer, or any liability that cannot lawfully be limited.
18. Liability
[PLACEHOLDER: this entire section — liability cap (typically fees paid in the preceding 12 months), exclusion of indirect and consequential loss, carve-outs for death or personal injury, fraud, wilful misconduct, breach of confidentiality, IP infringement and data protection liabilities. Counsel to draft against Spanish law. Do not publish a placeholder cap.]
19. Term, suspension and termination
- These terms run for as long as you have an active subscription or entitlement with us.
[PLACEHOLDER: initial term, renewal, notice period to cancel.] - Either of us may terminate for material breach that is not fixed within
[PLACEHOLDER: cure period]days of written notice. - We may suspend access immediately for non-payment or for a serious acceptable-use breach.
On termination:
- Your access to the portal ends.
- Your licence to reports already delivered continues, so you can keep using what you paid for.
[PLACEHOLDER: what happens to your data on termination — whether we return it, in what format, within what period, and what we then delete. This is currently unanswerable: the system has no deletion or export function of any kind, and no retention schedule has been set. Decide the policy first, build the mechanism, then write this clause. Do not promise deletion the platform cannot perform.]
20. Changes to these terms
We may change these terms. We will tell you in advance of any material change and give you a reasonable period to object. [PLACEHOLDER: notice period, and the effect of objecting.]
How acceptance works. [PLACEHOLDER: there is currently no mechanism anywhere in the product that shows a user a legal document or records that they accepted one. The tables to store documents and acceptances are specified and not built, and there is no screen on which acceptance could be captured — invitations are claimed silently. Until that is built, acceptance has to be handled in the signed order form or contract, and this clause must say so accurately.]
21. General
- Assignment. You may not assign these terms without our consent. We may assign them to a successor to our business.
- Subcontracting. We use the service providers listed in our Privacy Policy and remain responsible for what they do on our behalf.
- Entire agreement. These terms, plus any order form signed by both of us, are the whole agreement. An order form wins where they conflict.
- Severability. If a clause is unenforceable, the rest survives.
- No waiver. Not enforcing something once does not waive it.
- Force majeure. Neither of us is liable for delay caused by something genuinely outside our control.
- Notices. In writing, to the contact addresses in the order form.
22. Governing law and venue
[PLACEHOLDER: governing law and exclusive venue. The existing draft in documents/ still reads "[Insert EU Member State]" and "[Insert Location]". The company is established in Barcelona, so Spanish law and the courts of Barcelona are the obvious answer — but this must be a decision, not an inference, and it interacts with the liability cap and with any enterprise customer's own procurement requirements.]
23. Contact
[PLACEHOLDER: contact address for notices under these terms, and a separate address for data protection questions if they differ. One address, on the company domain.]
Reviewer notes — Terms
Each note is a thing the draft above cannot state as fact until someone does something.
| # | Note | Evidence |
| T1 | There is no acceptance mechanism. content.legal_document and app.legal_acceptance appear in no migration; the content schema is created empty and stays empty. The audit vocabulary already has legal_terms_accepted and nothing emits it. Neither login page shows a legal link or a checkbox — the checkbox is in the design prototype only. | 0001_foundation.sql:21, :119; apps/portal/app/login/page.tsx; docs/design/handoff/Culture Dive Portal.dc.html:518 |
| T2 | The 125-character cap is not enforced. It exists once, as a comment on an enum value. Nothing truncates a quote. It is cited as policy in three internal documents and implemented in none. | 0016_signals.sql:41; CONVENTIONS.md:75; docs/06-DESIGN-SYSTEM.md:160; docs/04-OPEN-QUESTIONS.md:35 |
| T3 | Subscription/entitlement separation is real and is stated correctly above. The subscription table is explicitly a Stripe mirror that the authorisation path may not read; entitlement is the authorisation table and absence is denial. | 0009_commerce.sql:63-66, :85-110 |
| T4 | Seat entitlement is real. Plan tiers carry a seat count; a tier with no seat count refuses fulfilment rather than granting zero. | 0014_plan_seats.sql:1-40 |
| T5 | The 48-hour invitation expiry is real and is attributed in the schema to the client's own requirement. | 0002_tenancy.sql:106 |
| T6 | Report immutability is real. Renders are revisioned with a content hash and a period; nothing updates a published revision in place. | 0006_dashboard_render.sql:13-33; 0024_render_period.sql:14-23 |
| T7 | "You do not operate any AI system" is verified. The entire client API is 14 routes and none of them touches probes, signals, annotations or models. Model choice is staff-only. Annotations are REVOKE ALL from the client role. | apps/api/app/main.py:61-519; app/services/models.py:12-14; 0021_annotation.sql:185-193,227 |
| T8 | Insight/narrative/embedding are genuinely unwired — the admin UI says so itself. | apps/admin/app/(admin)/models/explain.ts:54-79 |
| T9 | No public dashboard has ever been published. app.published_dashboard exists with a public grant and has no writer anywhere in the application. If that changes, the AI Act Article 50(4) analysis changes with it. | 0004_dashboards.sql:120-133; grep for published_dashboard in apps/api/app/ returns nothing |
| T10 | Section 19's deletion clause is the hardest one. There is no delete route, no runtime role holds DELETE on app.app_user, 20 foreign keys reference it with zero CASCADE or SET NULL, and the soft-delete columns have readers but no writer. Write the policy, build the mechanism, then draft the clause. | 0002_tenancy.sql:54-55,220; 0012_self_service_columns.sql:47 |
| T11 | The live marketing site contradicts this draft. culturedive.ai/terms §5 states that no personal data is collected by scraping and that public data analysed "does not constitute personal data collection under GDPR". Nine sources including Instagram, TikTok, Reddit, YouTube and news RSS are registered in the schema, and app.signal has author_handle, body and a free raw jsonb. The site must be corrected before any social connector ships, and arguably before this document is published alongside it. | 0016_signals.sql:113-135, :249-261 |
| T12 | Model-choice changes are not audited. The staff routes that set a model binding, a probe set or a probe budget write no audit row, and the ai_usage audit value is emitted by nothing. Any clause claiming traceability of model decisions is not currently provable. | apps/api/app/api/staff.py:1214,1270,1430,1483; 0001_foundation.sql:114 |