# License acceptance

This edition identifies its application license as **CH-J Proprietary Software License, version 1.14**, dated October 11, 2026. Third-party components retain their own licenses.

## Installation and updates

- Website: downloading an application package first displays the complete Czech, German or English guidance according to the page language. Continue submits a CSRF-protected, short-lived, one-use session token tied to the selected release and exact guidance text. Only then does the browser redirect to the package. Plugin downloads and updater API remain compatible.
- Windows NSIS: interactive installation first displays guidance in the selected installer language, then the complete application license and requires license acceptance. Silent installation and updater modes may skip installer pages; the application always checks consent on launch.
- macOS DMG: the disk image includes complete guidance in Czech, German and English before the license in the system prompt. The prompt states that agreement applies only to the license section. Installation from an application ZIP has no installer dialog, so acceptance is required on first launch.
- Debian/Ubuntu DEB: package managers do not provide a reliable interactive agreement step. Acceptance is required on first launch.
- All platforms: after an update, acceptance is required before the new release can be used, even when the version number or license text is unchanged. An installer prompt does not replace the per-user application consent.

The startup window first displays complete operational guidance in Czech, German or English. Continue opens the complete bundled English license with Czech, German and English controls. Acceptance is blocked until the guidance step has been displayed. The checkbox is initially empty. Its label combines license consent with an acknowledgment of data-loss risks and appropriate backups; it does not turn the operational guidance into contractual terms. The Czech confirmation reads:

> Souhlasím s licenčními podmínkami CH-J Proprietary Software License 1.14.
>
> Beru na vědomí riziko ztráty nebo poškození dat a nutnost přiměřeného zálohování před rizikovými operacemi. Rozumím, že aplikace sama nezaručuje existenci ani obnovitelnost záloh.

Accepting saves a local record before any Vault, plugin, network, diagnostics or updater service starts. Declining or closing the license window exits the application. A failed save leaves the window open and the application locked. Missing or invalid license files prevent startup.

## Local record

The file `legal/license-acceptance.json` is stored under the Electron `userData` directory. It contains the license name and version, SHA-256 of the exact displayed text, application version, build ID, acceptance flag and timestamp, guidance display flag and SHA-256 of all three bundled guidance documents. Changes to the guidance require displaying it again before a new license acceptance. There is no license activation or reporting to a server. Any mismatch, deletion or unreadable record requires a new agreement. Downgrading to another build also requires acceptance. Repeated launches of the same accepted build do not.

Each release must have a unique `src/shared/buildInfo.json` build ID. The normal build scripts stamp one automatically. Do not reuse `CHJ_BUILD_ID` for different released builds.

This local record is an application workflow control, not tamper-proof evidence or a license key. Displaying operational guidance is mandatory in this workflow; following its recommendations is optional. Guidance is never included in the agreement checkbox. Direct/offline ZIP or DEB installations and silent installers cannot guarantee a pre-installation display; the mandatory startup step provides the fallback. Existing published binaries are not changed by website updates.

## Packaging and verification

`npm run legal:prepare` copies the root license and operational guidance into the app when building from the full workspace, validates the license version and prepares `build/license.rtf` for NSIS, UTF-16 guidance text for its custom first page, and `build/installation.rtf` with guidance followed by the license for DMG. The RTF version preserves the full text and Unicode characters, including the licensor's name, without the legacy Mac Roman limitation of DMG plain-text licenses. Standalone app sources retain their bundled copies and do not require the development/web folder. `prepare:release` runs this before packaging. The packager includes `resources/licenses/` and `resources/docs/`; `afterPack` checks their required contents.

Run `node --test test/licenseAcceptance.test.js test/licensePackaging.test.js test/i18n.test.js` and `npm run test:license:ui`. The macOS package smoke test creates an acceptance fixture only in its temporary test profile; production startup has no consent bypass.
