1. Entity and contacts
[ ] Confirm legal entity name, registered address, and governing law in operator configuration records.
[ ] Confirm privacy@ and legal@ inboxes are monitored; publish EU representative if Article 27 applies.
[ ] Verify insurance (cyber, E&O) limits align with liability caps in Terms.
2. Regulatory positioning
[ ] Confirm no marketing copy implies advice, signals, custody, or execution (see GTM Legal Review).
[ ] Confirm tier entitlements match Terms §3 (analysis-only) and Schedule A jurisdictions.
[ ] Review persona chat and screenshot beta disclaimers in-product and in Terms §8.
3. Privacy and data
[ ] Map subprocessors (Clerk, Stripe, host, optional LLM) to DPA and SCCs.
[ ] Validate account deletion and export flows against Privacy Policy retention claims.
[ ] Cookie consent banner if non-essential cookies expand beyond the categories described in the Cookie Policy.
[ ] CPRA / GDPR rights request workflow and SLA documented internally.
4. Consumer and enterprise
[ ] Arbitration clause enforceability for target markets; consider EU consumer carve-out.
[ ] Stripe terms, refund policy, and tax/VAT display for jurisdictions sold into.
[ ] Execute signed DPA + order form for enterprise; do not rely on outline alone.
5. Integrations and exports
[ ] Webhook allowlist and payload description accurate in Terms §10.
[ ] Notion token handling and user responsibility for third-party ToS.
[ ] Export bundle notices match NFR-L1 compliance copy.
6. Launch gate
[ ] All public routes link to Terms and Privacy; subscribe checkbox matches live documents.
[ ] Store listing / ads reviewed if any paid acquisition planned.
[ ] Incident response and breach notification playbook signed off.