Nine Launch Details That Keep Your App Out of Legal Trouble

Most founders worry about the wrong legal risks. They lose sleep over trademarks and incorporation, then ship an app that loads its fonts from Google, records every keystroke with a replay tool and sends the launch email with no address in the footer. None of that looks like a legal problem. It looks like the default setup.

That is exactly why it catches people. Each item below is a small fix before launch and an expensive one after. These are the nine details I check on every product now, what the rule actually says, and the fix for each one.

One note first. I design and ship products; I am not a lawyer. This is the checklist that makes sure the obvious things are done, with the primary source for each rule. If your product handles health data, payments or children at scale, pay for an hour with a real lawyer.

1. Ask for age before you collect anything

In the US, COPPA covers any service directed at children under 13, and any service that knows it is collecting personal information from a child under 13. The FTC rewrote the rule in 2025, and compliance became mandatory on April 22, 2026. The new version requires separate parental consent before a child's data goes to third parties for things like targeted advertising, and it limits how long you can keep that data.

The fix is one question on the signup screen, before the email field. A birth year works, or a simple "I am 13 or older" choice (18 if your product has an adult threshold). Ask it neutrally, without hinting at the right answer. If someone is under 13, stop the signup or send them to a parent consent flow, and do not let them press back and pick a different year.

Then write it down. Your terms and privacy policy should say plainly that the product is not for children under 13. In the EU the digital age of consent is 16 by default, and each member state can lower it to no less than 13, so check where your users are.

2. Serve your fonts from your own domain

When a page loads a font from fonts.googleapis.com, the visitor's browser connects to Google and hands over its IP address before any consent banner appears. In January 2022 a regional court in Munich ruled that doing this without consent broke the GDPR and awarded the visitor €100 in damages (LG München I, 3 O 17493/20). A hundred euros sounds small. The ruling set off a wave of mass demand letters to German site owners, and the fix takes ten minutes.

Download the .woff2 files, put them next to your CSS and declare them yourself:

@font-face {
  font-family: "Inter";
  src: url("/fonts/inter-600.woff2") format("woff2");
  font-weight: 600;
  font-display: swap;
}

Then search the whole codebase for fonts.googleapis.com, fonts.gstatic.com and use.typekit.net. The app is usually clean. The marketing site, the blog template and the waitlist page someone built in an afternoon usually are not. Check the live pages with the network tab open too, because a third party widget can pull in fonts on its own.

3. Keep session replay off until you have consent and masking

FullStory, Hotjar, Microsoft Clarity, LogRocket and similar tools record what people do on your pages: every click, every scroll and, unless you stop them, what they type. In the US these scripts have become a steady target of class actions under California's wiretapping law, CIPA, on the theory that a third party is listening to a conversation between you and your visitor without consent. Courts have gone both ways, and that uncertainty is exactly what you do not want to test with your own company.

My default is off. If you need replay to debug a funnel, turn it on only after consent, mask every input by default, and exclude password, payment and health fields completely. Each tool has an attribute for it: data-hj-suppress in Hotjar, data-clarity-mask in Clarity, data-private in LogRocket. Then watch a recording of yourself signing up and make sure you cannot read anything you typed.

Chat widgets deserve the same look. Some can show your team what a visitor is typing before they press send. Find that setting and turn it off.

4. Put an unsubscribe link and a postal address in every marketing email

The US CAN-SPAM Act applies to every commercial email, including the "we just launched" message to your waitlist. Two requirements catch founders. Every message needs a working way to opt out, and you have 10 business days to honor it. Every message also needs a valid physical postal address: a street address, a PO box registered with the Postal Service, or a private mailbox registered with a commercial mail receiving agency. The FTC can fine more than $50,000 per email.

Gmail and Yahoo add a practical layer. Since 2024, anyone sending more than 5,000 messages a day to Gmail accounts must support one click unsubscribe through the List-Unsubscribe headers from RFC 8058, and process it within two days. Most email platforms add them for you. Check that yours does:

List-Unsubscribe: <https://example.com/unsubscribe?u=abc123>
List-Unsubscribe-Post: List-Unsubscribe=One-Click

The emails people miss live outside the main newsletter tool: the drip sequence someone set up in a different app, the follow up to everyone who signed up on launch day, the note sent from a personal inbox to a few hundred addresses. Every one of those is a commercial email.

5. Put the full price next to the subscribe button

This is the one with the most enforcement behind it. The FTC's click to cancel rule was struck down by the Eighth Circuit in July 2025 on procedural grounds, and in March 2026 the FTC started a new rulemaking. None of that made subscriptions a safe area. The FTC still enforces the Restore Online Shoppers' Confidence Act, and California's automatic renewal law, amended for contracts from July 1, 2025, already asks for most of what the federal rule tried to.

Next to the pay or subscribe button, show:

  • the price, and the price after the trial if there is one
  • how often you charge
  • that it renews until canceled
  • how to cancel

Put it right beside the button, where the eye already is. A line in the terms does not count. Then make canceling as easy as signing up. If people subscribed online, they cancel online, in a few clicks, without a phone call or a chat with a retention bot. California requires a prominent "click to cancel" link if you want to show a discount before letting someone go.

Last, keep a record of the consent: what the checkout screen said, the price, the time and the account. California asks you to keep it for three years, or one year after the contract ends if that is longer. A row in your database with the version of the checkout copy is enough to start.

6. Register a DMCA agent if people can upload

If users can put content on your service, such as images, audio, files in a chat or posts in a community, the DMCA safe harbor protects you from liability for what they upload. It comes with a condition. You have to designate an agent with the US Copyright Office, publish the agent's contact details on your site, and renew the designation every three years. It costs $6. If the designation lapses, you risk losing the safe harbor.

Register, add a copyright page with the agent's name, address, phone and email, and put the renewal date in your calendar. The Copyright Office sends reminders at 90, 60, 30 and 7 days, to whatever address you gave it three years earlier.

If every piece of content in your app comes from you, skip this one.

7. Link your privacy policy and terms wherever users can reach them

Apple's App Review Guidelines require a privacy policy link in two places: the App Store Connect metadata and inside the app, easy to find. Google Play asks for the same. The policy has to say what you collect, who you share it with, including analytics and advertising SDKs, and how someone can delete their data. Put the terms next to it on the signup screen, in settings and in the website footer.

8. Ask before you set analytics cookies for EU visitors

Under the EU's ePrivacy rules, storing or reading anything on a visitor's device that is not strictly necessary needs consent first. Analytics and advertising cookies are not strictly necessary. For visitors in the EU and the UK, that means a banner with a real choice, where declining takes as little effort as accepting, and no analytics script running until they say yes. If your analytics tool has a consent mode, connect it to the banner. If it does not, load the script after the click.

9. Ask for tracking permission on iOS

If your iOS app links user data with data from other companies' apps or websites for advertising, or shares it with a data broker, Apple calls that tracking, and you need the App Tracking Transparency prompt first. You cannot lock features behind a yes. Many attribution and ad SDKs track by default, so read their settings before you submit the build.

What it all costs

Add it up: one question on the signup screen, a folder of fonts, a script removed, an email footer, four lines next to a button, a $6 form, two links and two permission prompts. An afternoon, maybe two.

I now do this pass in the same week I write the store description, because both belong to the same part of the product: the part nobody looks at until something goes wrong. Users rarely notice any of it. Regulators, and the lawyers who send demand letters in bulk, notice all of it.

← All posts