/* Privacy Policy + Acceptable Use Policy — required legal pages, no emoji */

const LEGAL_EFFECTIVE = "August 11, 2026";

function LegalShell({ title, kicker, children }) {
  return (
    <div className="m-root">
      <Header current={title} />

      <section className="m-section" style={{paddingTop:56, paddingBottom:24}}>
        <div className="m-container" style={{maxWidth:780}}>
          <StampBadge>{kicker}</StampBadge>
          <h1 style={{marginTop:20, marginBottom:12, textWrap:'balance'}}>{title}</h1>
          <p style={{fontSize:15, color:'var(--charcoal-soft)'}}>
            Effective {LEGAL_EFFECTIVE} · Last updated {LEGAL_EFFECTIVE}
          </p>
        </div>
      </section>

      <section className="m-section" style={{paddingTop:0}}>
        <div className="m-container" style={{maxWidth:780}}>
          {children}
          <div style={{marginTop:48, padding:24, background:'var(--cream-2)', border:'1.5px solid var(--mist-2)', borderRadius:16}}>
            <h3 style={{marginTop:0, marginBottom:8}}>Questions about this policy?</h3>
            <p style={{margin:0, color:'var(--charcoal-soft)', lineHeight:1.7}}>
              Email <a href="mailto:richard@mammoth-dev.com">richard@mammoth-dev.com</a> and we will respond within
              30 days, or sooner where the law requires it.
            </p>
          </div>
        </div>
      </section>

      <Footer />
    </div>
  );
}

function LegalSection({ heading, children }) {
  return (
    <div style={{marginBottom:36}}>
      <h2 style={{fontSize:26, marginBottom:12}}>{heading}</h2>
      <div style={{fontSize:17, color:'var(--charcoal-soft)', lineHeight:1.75}}>{children}</div>
    </div>
  );
}

function LegalList({ items }) {
  return (
    <ul style={{margin:'12px 0 0 0', paddingLeft:22, display:'grid', gap:8}}>
      {items.map((it, i) => <li key={i}>{it}</li>)}
    </ul>
  );
}

function PrivacyPage() {
  return (
    <LegalShell title="Privacy Policy" kicker="Legal">
      <LegalSection heading="Who we are">
        <p>
          Mammoth-dev ("Mammoth-dev", "we", "us") operates mammoth-dev.com and the Mammoth-dev managed AI
          service, including the customer portal at app.mammoth-dev.com. This policy explains what personal
          information we collect, why we collect it, and what control you have over it. We are based in the
          United States and serve business customers.
        </p>
      </LegalSection>

      <LegalSection heading="Information we collect">
        <p><strong>Information you give us.</strong> When you book a call, submit a form, sign up, or email us:</p>
        <LegalList items={[
          'Name, business email address, phone number, and company name',
          'What you tell us about your firm, your tools, and what you want help with',
          'Account credentials and billing contact details if you become a customer',
        ]}/>
        <p style={{marginTop:16}}><strong>Information collected automatically.</strong> When you visit the site:</p>
        <LegalList items={[
          'IP address, browser type, device type, operating system, and referring page',
          'Pages viewed, time on page, and links clicked',
          'Cookies and similar technologies used to keep you signed in and to measure site performance',
        ]}/>
        <p style={{marginTop:16}}>
          We do not intentionally collect special categories of personal data (health, biometric, racial or
          ethnic origin, political opinions), and we ask that you do not send them to us through this site.
        </p>
      </LegalSection>

      <LegalSection heading="Customer data in the service">
        <p>
          If you are a Mammoth-dev customer, the service connects to business tools you authorize — for example
          email, calendar, CRM, file storage, and messaging accounts. We access that data only to operate the
          service you asked us to run. We process it on your instructions as your service provider, we do not
          use it to train third-party models on your behalf without your instruction, and we do not sell it.
          Each customer's data is isolated from every other customer's data.
        </p>
      </LegalSection>

      <LegalSection heading="How we use information">
        <LegalList items={[
          'To respond to enquiries, schedule calls, and provide the service',
          'To operate, secure, debug, and improve the site and the service',
          'To send service and account notices, and — where permitted — occasional relevant updates you can opt out of at any time',
          'To bill customers and keep accurate financial records',
          'To meet legal, tax, and regulatory obligations, and to establish or defend legal claims',
        ]}/>
      </LegalSection>

      <LegalSection heading="Legal bases (UK/EU visitors)">
        <p>
          Where the UK GDPR or EU GDPR applies, we rely on: performance of a contract (providing the service),
          legitimate interests (running and securing our business, and business-to-business marketing you can
          object to), consent (non-essential cookies and marketing email where consent is required), and legal
          obligation (tax and accounting records).
        </p>
      </LegalSection>

      <LegalSection heading="Sharing">
        <p>
          <strong>We do not sell personal information, and we do not share it for cross-context behavioural
          advertising.</strong> We disclose information only to:
        </p>
        <LegalList items={[
          'Service providers who host, secure, analyse, or support the site and the service, under contract and only for those purposes',
          'Professional advisers such as accountants and lawyers, under a duty of confidentiality',
          'Authorities or other parties where we are legally required to, or to protect our rights and the safety of others',
          'A successor entity in a merger, acquisition, or sale of assets, subject to this policy',
        ]}/>
      </LegalSection>

      <LegalSection heading="Cookies">
        <p>
          We use strictly necessary cookies to make the site work and to keep signed-in sessions active, and
          analytics cookies to understand which pages are useful. You can block or delete cookies in your
          browser settings; strictly necessary cookies cannot be turned off without breaking parts of the site.
        </p>
      </LegalSection>

      <LegalSection heading="Retention">
        <p>
          We keep enquiry and prospect records for up to 24 months from the last contact. Customer account and
          service data is kept for the life of the account and for up to 90 days after termination, after which
          it is deleted or anonymised, except where we must keep records longer for tax, accounting, or legal
          reasons. You can ask us to delete your data sooner.
        </p>
      </LegalSection>

      <LegalSection heading="Security">
        <p>
          We use encryption in transit and at rest, encrypted storage of third-party credentials, access
          controls, audit logging, and rate limiting. No system is perfectly secure, but if a breach affects
          your personal data we will notify you and the relevant regulator where the law requires it.
        </p>
      </LegalSection>

      <LegalSection heading="Your rights">
        <p>
          Depending on where you live, you may have the right to access, correct, delete, or port your personal
          information, to object to or restrict processing, to withdraw consent, and to not be discriminated
          against for exercising these rights.
        </p>
        <p style={{marginTop:12}}>
          <strong>California residents (CCPA/CPRA):</strong> you may request the categories and specific pieces
          of personal information we collected, request deletion or correction, and opt out of sale or sharing.
          We do not sell or share personal information, so there is nothing to opt out of, but the request will
          be honoured if that ever changes.
        </p>
        <p style={{marginTop:12}}>
          To exercise any right, email <a href="mailto:richard@mammoth-dev.com">richard@mammoth-dev.com</a>. We
          will verify your identity before acting. UK/EU visitors also have the right to complain to their local
          supervisory authority.
        </p>
      </LegalSection>

      <LegalSection heading="International transfers">
        <p>
          We are based in the United States and our providers may process data in the United States and
          elsewhere. Where data is transferred out of the UK or EEA, we rely on appropriate safeguards such as
          the Standard Contractual Clauses.
        </p>
      </LegalSection>

      <LegalSection heading="Children">
        <p>
          The site and the service are for business use and are not directed at children under 16. We do not
          knowingly collect information from children. If you believe a child has given us information, email us
          and we will delete it.
        </p>
      </LegalSection>

      <LegalSection heading="Changes">
        <p>
          We may update this policy. The effective date at the top will change, and material changes will be
          notified to customers by email or in the portal before they take effect.
        </p>
      </LegalSection>
    </LegalShell>
  );
}

function AcceptableUsePage() {
  return (
    <LegalShell title="Acceptable Use Policy" kicker="Legal">
      <LegalSection heading="Scope">
        <p>
          This Acceptable Use Policy applies to everyone who uses mammoth-dev.com, app.mammoth-dev.com, our
          APIs, and the Mammoth-dev managed AI service (together, the "Services"). It exists to keep the
          Services safe, lawful, and available. If you use the Services, you agree to this policy, and you are
          responsible for anyone you allow to use your account.
        </p>
      </LegalSection>

      <LegalSection heading="You must not">
        <LegalList items={[
          'Break the law, or use the Services to help anyone else break the law',
          'Infringe intellectual property, privacy, publicity, or contractual rights',
          'Upload or transmit malware, ransomware, or any code designed to disrupt or gain unauthorised access',
          'Attempt to access accounts, data, systems, or networks you are not authorised to access, or probe, scan, or test our security without our prior written permission',
          'Scrape, crawl, harvest, or bulk-extract content or personal data from the Services by automated means, except for a search engine indexing public pages in line with our robots.txt',
          'Circumvent authentication, rate limits, usage quotas, or any technical restriction',
          'Overload, flood, or otherwise interfere with the operation of the Services or the infrastructure behind them',
          'Reverse engineer, decompile, or attempt to derive source code, except where that restriction is prohibited by law',
          'Resell, sublicense, or provide the Services to a third party except as expressly agreed in writing',
          'Misrepresent who you are, impersonate anyone, or forge headers to disguise the origin of traffic',
        ]}/>
      </LegalSection>

      <LegalSection heading="Content and communications">
        <p>You must not use the Services to create, store, or send:</p>
        <LegalList items={[
          'Unsolicited bulk email, spam, or messages that breach CAN-SPAM, CASL, GDPR/PECR, or equivalent rules — including sending to purchased lists or to people who have opted out',
          'Content that is unlawful, defamatory, harassing, abusive, or that sexualises minors',
          'Fraudulent, deceptive, or misleading material, including phishing and impersonation of a business or public body',
          'Third-party personal or confidential data you do not have the right to process',
        ]}/>
      </LegalSection>

      <LegalSection heading="AI-specific rules">
        <p>
          The Services use AI models to read, draft, and act on business data. In addition to the rules above:
        </p>
        <LegalList items={[
          'Do not use AI outputs to make legal, medical, financial, employment, credit, or insurance decisions about a person without qualified human review',
          'Do not submit data you are not permitted to disclose to a processor, including data subject to a confidentiality obligation you have not cleared',
          'Do not attempt to make the models produce content banned by this policy, or to extract another customer’s data, prompts, or credentials',
          'Review AI-generated output before sending it externally — you remain responsible for anything sent from your accounts',
        ]}/>
      </LegalSection>

      <LegalSection heading="Third-party accounts">
        <p>
          When you connect a third-party tool such as Microsoft 365, Google Workspace, HubSpot, Zoho, or Slack,
          you must have the authority to connect it and you must follow that provider's own terms. We may
          suspend a connection if a provider tells us it is being used in breach of theirs.
        </p>
      </LegalSection>

      <LegalSection heading="Enforcement">
        <p>
          We may investigate suspected breaches and may suspend or terminate access, remove content, or throttle
          traffic — with notice where practical, and without notice where there is an active risk to the
          Services, to other customers, or to anyone's safety. Serious or repeated breaches may be reported to
          law enforcement. Suspension for breach does not entitle you to a refund.
        </p>
      </LegalSection>

      <LegalSection heading="Reporting abuse">
        <p>
          Report anything that breaches this policy to{' '}
          <a href="mailto:richard@mammoth-dev.com">richard@mammoth-dev.com</a>. Include the URLs, accounts, or
          messages involved and the time it happened. Security vulnerabilities should be reported to the same
          address, and we ask that you give us a reasonable window to fix them before disclosing publicly.
        </p>
      </LegalSection>

      <LegalSection heading="Changes">
        <p>
          We may update this policy as the Services change or as new abuse patterns appear. The effective date
          at the top will change, and continued use after an update means you accept it.
        </p>
      </LegalSection>
    </LegalShell>
  );
}
