Version: 1.0
Effective date: 2026-08-04
These terms govern participation in project-operated LifeOS community surfaces and use of upstream reference materials that are not governed exclusively by a separate agreement. They do not replace the Apache License 2.0 for source-code use, reproduction, modification, or distribution.
An independent LifeOS deployment is operated by the person or organization that deploys or offers it. That operator is responsible for its own service terms, privacy notice, security controls, support commitments, regulatory obligations, and user relationships. The upstream project does not operate or endorse every deployment.
LifeOS source code is licensed under the Apache License 2.0 in LICENSE. The license includes conditions for notices, modified files, redistribution, patents, trademarks, warranties, and liability. NOTICE contains attribution and trademark information that must be preserved when required by the license.
Documentation and other repository content are included in the licensed work unless a file clearly states different terms. Third-party components remain subject to their respective licenses.
Contributions are governed by CONTRIBUTING.md and Section 5 of the Apache License 2.0. Unless clearly designated otherwise in writing before submission, an intentionally submitted contribution may be incorporated and distributed under Apache-2.0 without additional terms.
Contributors must have the right to submit their work and must not include secrets, personal data, confidential employer or customer material, unlawfully obtained content, or code that knowingly violates third-party rights.
When using project-operated community surfaces, do not:
- violate applicable law or third-party rights;
- publish credentials, tokens, private keys, production exports, or sensitive personal information;
- probe, exploit, or disrupt project or third-party systems outside an authorized security-testing scope;
- submit malware, intentionally deceptive changes, fabricated evidence, or concealed destructive behavior;
- harass, threaten, impersonate, or expose another person; or
- use project names or branding in a way that falsely suggests sponsorship, certification, or endorsement.
Maintainers may edit, hide, lock, reject, or remove project content and restrict participation when reasonably necessary to protect the project, its users, or third parties.
LifeOS is reference software, not a turnkey compliance certification. Deployment operators are responsible for, at minimum:
- authentication, authorization, tenant isolation, secrets management, encryption, network controls, logging, monitoring, backup, recovery, patching, and incident response;
- lawful collection and use of personal data, user notices, consent or other lawful bases, retention, deletion, export, and data-subject requests;
- licenses and terms for infrastructure, identity, calendar, model, messaging, analytics, storage, and other integrated providers;
- validating migrations, configuration, scaling, availability, and rollback procedures before production use; and
- determining whether the deployment is suitable for regulated, safety-critical, employment, education, health, financial, legal, or other high-impact uses.
Project documentation may describe recommended controls, but documentation is not a warranty that a particular deployment satisfies legal, contractual, security, or operational requirements.
AI-assisted output can be incomplete, inaccurate, biased, insecure, or unsuitable for a user's circumstances. LifeOS is designed to favor explainable proposals and explicit confirmation over silent mutation, but operators and users remain responsible for reviewing output and controlling any action execution.
Do not treat LifeOS output as professional medical, legal, financial, mental-health, emergency, employment, or other regulated advice. Do not use it as the sole basis for decisions that materially affect a person's rights, safety, livelihood, access, or eligibility.
LifeOS may interoperate with third-party providers. Their availability, security, output, pricing, data practices, and terms are outside the upstream project's control. References or integration code do not imply endorsement. Operators and users must evaluate and contract with third parties separately.
Report suspected vulnerabilities through the private-first process in SECURITY.md. Public disclosure before maintainers have a reasonable opportunity to assess and remediate an issue may increase risk to users and deployments.
Nothing in these terms authorizes testing against systems, accounts, or data you do not own or have explicit permission to test.
The public repository, documentation, examples, issue tracker, and release artifacts do not create an uptime, maintenance, support, compatibility, data-retention, migration, or remediation commitment. Any such commitment must be stated in a separate written agreement.
The warranty disclaimer and limitation of liability in Sections 7 and 8 of the Apache License 2.0 apply to the licensed work. These project terms do not expand contributor warranties or liabilities.
To the extent a community surface or non-code reference material is not covered by that license, it is provided on an "as is" and "as available" basis to the maximum extent permitted by applicable law, without implied warranties of merchantability, fitness for a particular purpose, title, non-infringement, availability, or error-free operation.
The project may evolve, rename, deprecate interfaces, change release practices, or discontinue community surfaces. The Apache License 2.0 does not grant trademark rights except for reasonable attribution and identification of origin.
A separately executed commercial, hosting, support, contributor, or enterprise agreement controls to the extent it expressly conflicts with these terms. Otherwise, these terms, LICENSE, NOTICE, CONTRIBUTING.md, SECURITY.md, and docs/legal/privacy.md describe the upstream project boundary.
Material changes will be committed to this file with an updated version or effective date. Continued participation in project-operated community surfaces after a published change is subject to the updated terms, while source-code rights already granted remain governed by the applicable license.