Correct the UDP hole punching default and document TCP hole punching, WebRTC, and relay fallback delay across all 12 languages. Note that WebRTC requires RustDesk Server Pro 1.8.7.
Analytics.astro rendered <GoogleAnalytics> whenever config.yaml carried a
measurement id, so gtag ran and the _ga cookies were set on the first page
view, before the banner was answered and whatever the visitor went on to
choose. The analytics service in the consent config was never wired up to
anything -- its onAccept was a `// TODO: load ga4` -- so consent decided
nothing either way. The privacy policy says the opposite, that cookies are
used on the basis of consent given through the banner.
Analytics.astro now only defines window.loadGoogleAnalytics, and the ga4
service calls it from onAccept, so Google is first contacted after the visitor
accepts. Rejecting leaves the loader uncalled, and the library erases the _ga
cookies it already matches.
CookieConsent.astro skipped run() once its own localStorage flag was set,
which meant the library was not initialised on any later visit -- with the
loader moved behind consent that would have left analytics permanently dead
instead of permanently on, since re-applying a stored consent is what calls
onAccept. It now runs on every page load and lets the library decide whether
to show the banner.
Consent could also not be withdrawn: the preferences modal had no trigger
anywhere on the site, and the privacy policy offered browser settings instead,
which is not a withdrawal mechanism and is not as easy as giving consent was.
The footer now links to the modal and the policy points at it.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EZ49AbZJYfm8NTp5yDPMab
Section 9 still named The Cayman Islands although the contracting entity
has been Purslane Tech Pte. Ltd. for some time, so the choice of law no
longer matched the company it was chosen for.
Changing it surfaced the rest. The Terms defined "Software" circularly and
then forbade modifying, translating and reverse engineering it, which
contradicts the AGPL the client and Server OSS are released under; Section 2
is now split so the license restrictions fall away for those parts while the
conduct restrictions -- which is where the anti-fraud rules live -- apply
however the software was obtained. Termination was immediate on any breach
however small, with no refund and an order to destroy copies that the AGPL
does not permit us to give. The warranty disclaimer was unqualified, the
liability clause had no cap to fall back on and no carve-out for liability
that cannot be excluded, and there was no effective date, so nothing recorded
which version a customer had accepted.
The Privacy Policy stopped at section 3 (d) and was missing every mandatory
disclosure under GDPR Articles 13 and 14: who the controller is and how to
reach them, who the data is shared with, where it goes, how long it is kept,
what rights the data subject has, and where to complain. It also pointed at
an "Article 4" that does not exist.
Termination, the change mechanism and the one-way jurisdiction clause follow
what AnyDesk and TeamViewer do, so the position is no weaker than theirs. The
liability cap matches Splashtop's. Payment and renewal terms are still absent
and are left for later.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EZ49AbZJYfm8NTp5yDPMab