Website and App Launch Legal Checklist: IP, Terms, Privacy, and Compliance

By ·

This checklist takes a website or mobile app from naming to the post-launch docket in ten phases and roughly 110 concrete actions, each one a filing, a document, a configuration change, or a record you will have to produce in litigation two years later. It covers brand clearance and the domain and handle sweep; contractor and employee IP assignments plus the software bill of materials and the AGPL decision; assent-screen design to the Berman and Meyer specification, with the per-user evidence record that decides arbitration motions; the script inventory, the data map, the privacy notice, consent tooling that actually blocks tags before consent, and vendor data processing agreements; the six-dollar DMCA designated-agent registration and the repeat-infringer workflow behind it; claim substantiation, the FTC Endorsement Guides and the Reviews Rule, and the ROSCA subscription flow; a WCAG 2.1 Level AA audit; a vulnerability disclosure policy and a two-track incident runbook; the copyright, design patent, and Statement of Use filing calendar; and the monitoring, docketing, and enforcement program you leave behind. Every phase carries the governing rule, the fee, the trap, and a worked example — Brindle Labs, Inc. shipping NINEBAR on 15 April 2025 — so you can see what finished looks like. Deadlines are consolidated in a single table, and a Common Mistakes section collects the failures that recur across launches.

IP and Technology > Internet | Checklist | Published 28 February 2025 - Updated 18 October 2025 | Casey Scott McKay - marksy.us

Summary. Ten phases, roughly 110 actions, from the first knockout search to the docket you hand over after launch. Brand and domain; ownership and open source; terms and assent design; privacy and data; DMCA and platform exposure; advertising and claims; accessibility; security; IP filings; post-launch monitoring. Each item states the move, and where it matters, the rule that requires it, the fee, and the specific way teams get it wrong. One worked example — Brindle Labs, Inc. shipping NINEBAR on 15 April 2025 — runs through every phase, with dollar figures and dates, so you can tell a finished item from a checked box. The deadlines are consolidated in one table at the end. The doctrine is in the companion article; the sequencing, model clauses, and cost ranges are in the companion guide.

Keywords: website launch checklist · app launch legal checklist · trademark clearance · intent-to-use application · contractor ip assignment · open source license audit · clickwrap assent design · terms of service · privacy policy data map · global privacy control · dmca designated agent · repeat infringer policy · wcag 2.1 aa accessibility · rosca subscription disclosure · ftc endorsement guides · copyright group registration · vulnerability disclosure policy · incident response plan · trademark watch service · launch docket


What this checklist is for, who should use it, and what to have open

What it is. A pre-ship gate for a consumer or business website or mobile app. Every item is either a filing, a signed document, a configuration change, or a record you will have to produce in a deposition. Work it top to bottom and you will finish the job.

Who should use it. Founders and product leads shipping a first version; in-house counsel at a company that has outgrown terms it copied in 2021; and outside counsel running a launch as a fixed-scope matter. It assumes a US-incorporated company, mostly US users with some EU or UK traffic, at least one contractor, and at least one place in the product where a user can type something into a box.

What this is not. It is not the doctrine. Why browsewrap loses, why the § 512 conditions bite, and what Feist Publications, Inc. v. Rural Telephone Service Co., 499 U.S. 340 (1991), leaves you in a database are covered in The Legal Layers of a Website. The model clauses, decision trees, and cost ranges — including the belt-and-braces grant for authors in civil-law countries and the ROSCA pre-billing block — are in Launching a Website or App Without Legal Debt. This is the operational distillation of both.

Have these open before you start.

The worked example. Brindle Labs, Inc., a Delaware corporation, shipped NINEBAR — a brew-log and subscription app — on 15 April 2025. Every phase below closes with what Brindle actually did, what it cost, and what it filed. Total legal and filing spend across the whole launch: $38,400, of which $21,000 was a domain.

| Phase | What it settles | Window | Blocks launch? | |---|---|---|---| | 1. Brand and domain | Whether you can keep the name | T-180 to T-150 | Yes | | 2. Ownership and open source | Whether you own what you built | T-150 to T-110 | Yes | | 3. Terms and assent design | Whether your contract exists | T-100 to T-90 | Yes | | 4. Privacy and data | Whether your disclosures are true | T-90 to T-75 | Yes | | 5. DMCA and platform | Whether you have the safe harbor | T-60 to T-45 | Yes, if users can post | | 6. Advertising and claims | Whether marketing can run | T-30 to T-14 | Yes | | 7. Accessibility | Your exposure to the most predictable demand letter | T-55 to T-10 | Risk call | | 8. Security | What happens when something goes wrong | T-21 to T-7 | Risk call | | 9. IP filings | What you own on paper | T-7 to T+90 | No | | 10. Post-launch monitoring | Whether any of it survives year two | T+1 onward | No |

Phase 7 sits where it does because remediation is the long pole: start the accessibility audit at T-55, in parallel with Phase 5, and expect to still be fixing focus indicators at T-10.


Phase 1 — Brand and domain (T-180 to T-150)

NINEBAR, Phase 1. BREWNOTE died in an afternoon against a live Class 9 registration for BREWNOTES covering software for tracking beverage preparation. CREMA was descriptive of a coffee product's subject matter. NINEBAR — nine bars is the standard pressure for espresso extraction — is suggestive, registrable without secondary meaning, and cleared against one Class 43 registration for bar services in Denver. Search $980, opinion $2,200, eleven days. ninebar.com cost $18,500 plus a 12% broker commission; five defensive domains cost $214 together; handles on six platforms took ninety minutes.


Phase 2 — Ownership and open source (T-150 to T-110)

NINEBAR, Phase 2. Nine contributors, seven of them contractors. Two had never signed anything; both signed before the next sprint, one for $0 and one for a $1,500 true-up. The Warsaw front-end author from the prior product got the belt-and-braces grant. The first SBOM run found an AGPL-3.0 charting library in the analytics service; the team replaced it in three engineer-days at T-118. Cost: $4,100 in counsel time, $0 in tooling.


Phase 3 — Terms and assent design (T-100 to T-90)

NINEBAR, Phase 3. The sign-up screen went from a footer link to notice above the button in 15px #1B1B1B with a blue underlined link, plus a separate unchecked box for the arbitration agreement. Engineering added an assent_events table with eight columns and a nightly export to cold storage. Two-person sign-off before every release. Cost: one engineer-week and $6,400 of drafting.


Phase 4 — Privacy and data (T-90 to T-75)

NINEBAR, Phase 4. The inventory found eleven tags; four were unknown to engineering, and one was a session-replay script left over from the prior product — the script that produced a $60,000 CIPA defense. Brindle removed it, self-hosted analytics, moved conversion tracking server-side with hashed identifiers, and cut the vendor list from eleven to five. The data map took nine days; the notice took four. That ratio is correct.


Phase 5 — DMCA and platform exposure (T-60 to T-45)

NINEBAR, Phase 5. Registration took twenty minutes. Legal name "Brindle Labs, Inc."; alternate names NINEBAR, ninebar.com, ninebar.app, Brindle Labs, and Brindle & Co.; agent "Copyright Agent, Brindle Labs, Inc."; dmca@ninebar.com routed to two people; $6 paid 12 February 2025; renewals docketed for 12 November 2027 and 12 January 2028. A test notice sent from a personal address on launch morning was acknowledged in eleven minutes.


Phase 6 — Advertising, claims, and the subscription flow (T-30 to T-14)

NINEBAR, Phase 6. Nineteen claims went into the matrix; three came out ("the fastest brew log," "used by most specialty roasters," and a savings claim) for want of substantiation. The pre-billing block above the card fields read: fourteen-day trial, $9.00 per month charged 29 April 2025, cancel in Settings → Subscription in two taps, no phone call. Cancellation took eleven seconds on an iPhone SE. Six influencer agreements carried the disclosure clause.


Phase 7 — Accessibility (audit T-55, remediation through T-10)

NINEBAR, Phase 7. Twenty-two templates, axe-core in CI from T-52. The automated scan found 340 issues across four rule families; the manual pass found the four that mattered, all in the checkout modal — a focus trap, an unlabeled card-number field, a 2.9:1 contrast ratio on the primary button, and a cancel control reachable only by mouse. Remediation ran six engineer-days and finished at T-9. Audit cost $7,800.


Phase 8 — Security, disclosure, and the incident plan (T-21 to T-7)

NINEBAR, Phase 8. The VDP went live at T-19; the first researcher email arrived at T-4 reporting an IDOR in the shared-recipe endpoint, was acknowledged in three hours, and was fixed in two days. Counsel and a forensics firm signed two-track engagement letters at T-14. Cyber and tech E&O bound at $4,200 for the year.


Phase 9 — IP filings (T-7 to T+90)

NINEBAR, Phase 9. ITU filed 14 November 2024 in Classes 9 and 42, $700 base with ID Manual wording and no surcharges. Launch-day specimens captured 15 April 2025 at 09:12 Pacific and saved to Matter 2024-114. Source code registered 3 June 2025 with the first-and-last-ten-pages deposit; twenty-eight blog posts group-registered 9 July 2025 for $65, six days inside the § 412 window. One design patent application on the brew-timer screen filed 8 April 2025, a week before disclosure.


Phase 10 — Post-launch monitoring (T+1 onward)

NINEBAR, Phase 10. The watch service flagged a Class 42 application for NINE BAR LABS in week seven. Brindle filed a thirty-day extension of time to oppose, wrote to the applicant, and settled on an amended identification and a consent agreement for $3,200 — roughly a tenth of what an opposition would have cost.


Common Mistakes


Deadlines at a Glance

| Deadline | Authority | Clock | Consequence of missing | |---|---|---|---| | Copyright registration for statutory damages and fees | 17 U.S.C. § 412 | 3 months from first publication | Actual damages only; usually near zero | | Right to file suit at all | Fourth Estate, 586 U.S. 296 | Register must act on the application | Complaint dismissed or stayed | | DMCA counter-notice restoration | 17 U.S.C. § 512(g)(2)(B)-(C) | Not less than 10 nor more than 14 business days | Loss of the § 512(g) shield; user claim | | DMCA designated agent renewal | 37 C.F.R. § 201.38 | Every 3 years; amendment restarts it | Safe harbor lapses silently | | Design patent / patent statutory bar | 35 U.S.C. § 102(a)-(b) | 1 year from first disclosure, offer, or public use | Rights barred outright | | Office action response | 37 C.F.R. § 2.62(a) | 3 months, one 3-month extension for $125 | Abandonment | | Extension of time to oppose | 37 C.F.R. § 2.102 | 30 days from publication, extendable | Opposition window closes | | Statement of Use | 15 U.S.C. § 1051(d) | 6 months from Notice of Allowance; five extensions; 36-month cap | Application dies; priority lost | | Section 8 declaration | 15 U.S.C. § 1058 | Years 5-6, with a 6-month grace period | Cancellation | | Sections 8 and 9 renewal | 15 U.S.C. §§ 1058-1059 | Years 9-10, then every 10 years | Registration expires | | Section 15 incontestability | 15 U.S.C. § 1065 | Any time after 5 years of continuous use | Forgoes incontestability | | Privacy notice refresh | Cal. Civ. Code § 1798.130(a)(5) | Every 12 months | Statutory violation; deception exposure | | Consumer rights request response | Cal. Civ. Code § 1798.130(a)(2) | 45 days, one 45-day extension on notice | Enforcement action | | Data subject request response | GDPR art. 12(3) | 1 month, extendable by 2 further months | Supervisory authority complaint | | Breach notification, EU | GDPR art. 33 | 72 hours from awareness | Article 83 fine exposure | | Breach notification, US states | State statutes | Commonly 30 days outer limit; AG notice above thresholds | Penalties; multistate investigation | | CAN-SPAM opt-out | 15 U.S.C. § 7704(a)(4) | Honored within 10 business days | Per-message penalties | | Data Privacy Framework re-certification | DPF program rules | Annually | Removed from the list; transfers unsupported |


Related Documents

Articles

Guides

Checklists

Toolkits

Templates & Forms

Across the Wider Corpus

The library now covers the platform, data, and privacy layers in depth. These sit outside this document's immediate subject and bear on it directly — the regimes an online product meets once it has users, data, and a terms page.


This document is general information about the law, not legal advice, and does not create an attorney-client relationship. Trademark and copyright outcomes turn on specific facts. Marksy is not a law firm.

Read this article on Marksy