You commented SUED. Here's the prompt that checks your app for all ten.

Paste it into Claude Code, Cursor or ChatGPT with your codebase or site attached. It inspects the real code, then reports PASS, FAIL or CAN'T TELL on each check, with the file and line as evidence and a concrete fix. It never claims legal certainty, because it can't give you any.

The audit prompt

You are auditing my app for ten common legal exposure points. You are not a lawyer and must never claim legal certainty. Inspect the actual code, config, templates, assets and live site I have given you. Do not guess from the README.

For each of the 10 checks below, report:
- Status: PASS, FAIL or CAN'T TELL
- Evidence: file path and line number (or URL and element) that shows why. If you can't find evidence either way, the status is CAN'T TELL, not PASS.
- Fix: one concrete change, with the code or copy if it is small.

CHECKS

1. Copyright images. Find every image, icon, font and video. Flag any that look scraped from Google, stock sites or other websites with no licence on file. Look for hotlinked third-party images, files with watermarks, and assets with no source or licence noted.

2. Cookie consent (GDPR). Find every cookie, tracker, analytics script, ad pixel and embedded third-party widget. Check whether a consent banner exists and whether non-essential cookies and scripts are blocked until the visitor opts in. Flag anything that fires on page load.

3. Email unsubscribe (CAN-SPAM). Find every email the app sends (newsletters, marketing, lifecycle). Check each one for a working one-click unsubscribe link and a physical postal address in the footer. Check that unsubscribe requests are actually honoured in the code.

4. California privacy (CCPA/CPRA). Check whether the app collects personal information from California residents and whether it sells or shares it (including via ad pixels and analytics). Look for a "Do not sell or share my personal information" link and a privacy policy that lists what is collected. Note that CCPA only applies to businesses over certain thresholds, so say if you can't tell whether I am covered.

5. Brand names in domains. Check my domain names, subdomains, app name, social handles and metadata for someone else's trademark or brand. Flag any that could suggest I am that brand or sell their product.

6. User uploads and DMCA. Check whether users can upload or post content (images, files, text, video). If so, check for a DMCA designated agent registered with the US Copyright Office, a published takedown process and contact details, and a repeat-infringer policy.

7. Breach response (GDPR Art. 33). Check whether the app stores EU residents' personal data. If so, check for a documented breach plan: who gets alerted, how a breach is detected (logging, alerts), and a process to notify the EU supervisory authority within 72 hours.

8. Face and biometric data (BIPA). Check for face login, face matching, face filters, voiceprints, fingerprints or any biometric feature, including through third-party SDKs. If found, check for written notice, written consent before collection, and a published retention and deletion policy, especially for Illinois users.

9. Training AI on user data. Check whether any user photos, text, files or behaviour are used to train, fine-tune or improve a model, yours or a vendor's. Check for explicit consent, a clear privacy policy statement, a way to opt out, and a way to delete data and any model trained on it.

10. Chatbot making things up. Find every AI chatbot or assistant that talks to customers. Check whether it is grounded in my real policies (refunds, pricing, shipping, terms) rather than answering from general knowledge, whether it shows a disclaimer, whether answers are logged, and whether there is a human escalation path.

RULES
- Never say "you are compliant" or "this is legal". Say what the code shows and what is missing.
- If a check does not apply (for example, no uploads), say so and explain why, with evidence.
- Do not edit any files yet. Report only.

OUTPUT
1. A table: check number, name, status.
2. The detail for each check, in order.
3. The top three fixes to do first, ranked by exposure and effort.
4. A list of everything you marked CAN'T TELL and what information you would need to settle it.

End with: "This is not legal advice. Have a lawyer review before you rely on it."

Run it, read the FAIL items first, then ask the AI to fix them one at a time. Here is what each check means.

1. Image grabbed off Google

Copyright statutory damages run up to $150,000 per work if the infringement is willful (17 U.S.C. 504(c)). "I found it on Google" is not a licence. Fix: use images you own, have licensed, or generated with AI, and keep the licence for each one.

GDPR fines go up to €20M or 4% of global turnover, whichever is higher (Art. 83). If EU visitors can load your site, it applies. Fix: add a consent banner that blocks non-essential cookies and scripts until the visitor opts in.

3. Newsletter with no unsubscribe link

CAN-SPAM penalties run up to $53,088 per email (2025 FTC figure, unchanged for 2026). Fix: a working one-click unsubscribe and your physical address in every marketing email.

4. Californians, no "Do not sell or share" link

CCPA fines are $2,663 per unintentional violation and $7,988 per intentional one (adjusted January 2025, in force through 2026). It only applies to businesses over the CCPA thresholds, so a tiny side project may be outside it. If you run ad pixels on a bigger site, check. Fix: add the "Do not sell or share my personal information" link and honour it.

5. Domain containing someone else's brand

Under the ACPA, statutory damages are $1,000 to $100,000 per domain. It needs bad-faith intent to profit from the mark, but a brand name in your domain looks bad in front of a judge. Fix: pick a domain that is yours.

6. Users can upload, no DMCA agent

Registering a DMCA designated agent costs $6 at the US Copyright Office. Without it you lose safe harbour for user uploads and face copyright statutory damages, up to $150,000 per work if willful. Fix: register the agent, publish a takedown page, remove infringing content when notified.

7. Breach not reported within 72 hours

GDPR Art. 33 requires you to tell the EU authority within 72 hours of becoming aware of a breach. Missing it can cost up to €10M or 2% of global turnover (Art. 83(4)). Fix: write a one-page breach plan before you need it, and set up alerts so you find out.

8. Face login or face features, Illinois users

BIPA damages are $1,000 per person for negligent violations and $5,000 for intentional ones, counted per person since the August 2024 amendment. Fix: written notice, written consent before you collect, and a published retention and deletion policy. Or drop the feature.

9. Training your AI on users' photos or data without consent

In FTC v Everalbum (2021), the company was ordered to delete the models it trained on users' photos. The fine print can be the least of it: you can lose the model itself. Fix: get explicit consent, say it in your privacy policy, and give users a way to opt out and delete.

10. Chatbot invents a policy

In Moffatt v Air Canada (2024 BCCRT 149), the airline was held liable for its chatbot's made-up bereavement refund policy and paid C$812.02. Your bot's words are your words. Fix: ground the bot in your real policies, add a disclaimer, and log its answers.

This is not legal advice. Talk to a lawyer before you rely on it.

Built something with this? DM me on Instagram and show me. I read every one.

I send one of these a week: an AI tool, what it does, and how to use it without writing code. Subscribe and the next one lands in your inbox.

PS. Want this done for your business site? That's what we do at optimax-ai.com.