# Third-party notices

Everything under `play/` is written here from published rules, with the anchor
each engine was verified against recorded in its own header. **One file is not
ours, and it carries obligations.** This document exists so those obligations are
discoverable without reading a 1.5 MB minified file.

⚠️ **This is a record of what we ship and where its source lives. It is not legal
advice, and nobody with a law degree has reviewed it.**

---

## Stockfish — GNU General Public License v3

**File:** `play/stockfish-worker.js` (≈1.5 MB)
**Used by:** `play/chess-review.html`, loaded as a Web Worker by
`play/chess-review.js` (`new Worker('stockfish-worker.js')`). It is the engine
behind the unlimited free game review — the feature that exists because
chess.com metered theirs.

**Copyright:** T. Romstad, M. Costalba, J. Kiiski, G. Linscott and other
contributors.
**Multi-variant support:** Daniel Dugovic and contributors.
**Compiled to JavaScript and WebAssembly by:** Niklas Fiekas, using Emscripten
and Binaryen.

**Licence:** GNU General Public License, version 3 —
<https://www.gnu.org/licenses/gpl-3.0.html>

### Corresponding source

GPLv3 §6 requires that anyone we convey the binary to can get the source it was
built from. We serve this file to every visitor of `chess-review.html`, so that
obligation is live, and these are the directions:

| what | where |
|---|---|
| the JavaScript/WebAssembly build we actually serve | <https://github.com/niklasf/stockfish.js> |
| the multi-variant Stockfish fork it was compiled from | <https://github.com/ddugovic/Stockfish> |
| upstream Stockfish | <https://github.com/official-stockfish/Stockfish> |

🔴 **This was pointing at the wrong project until 2026-08-03.** The footer of
`chess-review.html` linked to `nmrugg/stockfish.js` — a different, also popular
JS port by a different author, and **not** the build we serve. The file's own
header has said `niklasf/stockfish.js` since the day it was added. A source link
that resolves to somebody else's project is the right gesture aimed at the wrong
target: it looks like compliance in a page footer and does not give the reader
the corresponding source. Corrected in both places.

### What we did not do to it

We have not modified the engine. The file is the upstream build, byte for byte,
with its `/*! ... */` header intact — the notice most likely to be lost is the
one a minifier or a copy-paste strips, and it is still there.

### Why this does not make the rest of the site GPL

The engine runs as a **separate Web Worker** and communicates over `postMessage`
using UCI text. Our code and Stockfish share no address space, no linkage and no
build step; the same arrangement is how lichess ships this build. That is the
generally accepted reading, **it is a reading, and if `chess-review` ever becomes
commercially load-bearing it deserves twenty minutes of actual legal advice
rather than this paragraph.**

---

## Third-party code we load but do not host

Neither is redistributed by us — the browser fetches them from the vendor.

| what | from | licence |
|---|---|---|
| `@supabase/supabase-js` v2 | cdn.jsdelivr.net | MIT |
| Google Analytics (`gtag.js`) | googletagmanager.com | Google's terms |

## Data and word lists

- `data/lexicon-enable1.txt` — the ENABLE word list, public domain. Cross-checked
  against `github.com/dolph/dictionary`; the copies in the wild disagree, and
  `play/lexicon-engine.js` records which disagreements and why.

---

## The Open Source Arcade — games that are not ours

Everything under `arcade/` is **somebody else's game**, published by its author
under a licence that permits redistribution, and copied here so it stays
playable. None of these authors submitted their game to us and none of them are
affiliated with EveryGameMade — the licence is the whole of the permission.
That distinction matters enough to spell out, because the community arcade under
`ai/g/` works the opposite way: those games arrive through the upload form and
their pages say "hosted with their permission." These do not, and their pages
say what is actually true instead.

Each game ships three files: `game.txt` (the author's HTML, byte-for-byte as
published, served as `.txt` so it can never execute same-origin by direct
navigation), `index.html` (our wrapper), and `LICENSE.txt` (the author's licence,
verbatim). Every wrapper page names the author, the licence and the source repo,
and links its own `LICENSE.txt`.

<!-- ARCADE-TABLE:BEGIN (generated by tools/vendor_arcade.py -- do not hand-edit) -->
| Directory | Game | Copyright | Licence | Source |
|---|---|---|---|---|
| [`arcade/afterglow/`](arcade/afterglow/) | AFTERGLOW | 2026 David Linacre | MIT License | [DLinacre/afterglow](https://github.com/DLinacre/afterglow) |
| [`arcade/anime-dash/`](arcade/anime-dash/) | Anime Dash | 2026 Muthu Sivasubramanian | MIT License | [smuthu7/anime-dash](https://github.com/smuthu7/anime-dash) |
| [`arcade/clownword-desert/`](arcade/clownword-desert/) | ClownWord Desert | 2026 Richmack | MIT License | [iamrichmack111/clownword-desert](https://github.com/iamrichmack111/clownword-desert) |
| [`arcade/ink-rider/`](arcade/ink-rider/) | INK RIDER III | 2026 jimdo-png | MIT License | [jimdo-png/ink-rider](https://github.com/jimdo-png/ink-rider) |
| [`arcade/little-sky-pilot/`](arcade/little-sky-pilot/) | Little Sky Pilot | 2026 Brian A. Robinson | MIT License | [brobin09/PlaneGame](https://github.com/brobin09/PlaneGame) |
| [`arcade/perf-and-postmark/`](arcade/perf-and-postmark/) | Perf & Postmark - learn philately by playing | 2026 peterdsouza247 | MIT License | [peterdsouza247/postmark](https://github.com/peterdsouza247/postmark) |
| [`arcade/petrichor/`](arcade/petrichor/) | Petrichor | 2026 MeatPopSci1972 | MIT License | [MeatPopSci1972/petrichor](https://github.com/MeatPopSci1972/petrichor) |
| [`arcade/pulsefield/`](arcade/pulsefield/) | Pulsefield | 2026 jenschristianschroder | MIT License | [jenschristianschroder/pulsefield](https://github.com/jenschristianschroder/pulsefield) |
| [`arcade/seal-vault/`](arcade/seal-vault/) | SEAL VAULT | 2026 royalgames0 | MIT License | [royalgames0/SealVault](https://github.com/royalgames0/SealVault) |
| [`arcade/snake-touch-edition/`](arcade/snake-touch-edition/) | Snake — Touch Edition | 2026 Snake Game contributors | MIT License | [satish8288/snake-game](https://github.com/satish8288/snake-game) |
| [`arcade/solar-system/`](arcade/solar-system/) | Solar System | 2026 Noah DeMar | MIT License | [noahdemar/game_solar_system](https://github.com/noahdemar/game_solar_system) |
| [`arcade/speed-racing/`](arcade/speed-racing/) | 极速狂飙 (Speed Racing) | 2026 SW DAI | MIT License | [SWDAI916/Road_Game](https://github.com/SWDAI916/Road_Game) |
| [`arcade/stupid-cjp/`](arcade/stupid-cjp/) | Stupid CJP | *(licence leaves the holder line unfilled — author Kushagra (anshdwivedi922-oss))* | Apache License 2.0 | [anshdwivedi922-oss/CJP-](https://github.com/anshdwivedi922-oss/CJP-) |
| [`arcade/tank-battle/`](arcade/tank-battle/) | 坦克大战 (Tank Battle) | 2026 Michael-Rudalx | MIT License | [Michael-Rudalx/tank-battle](https://github.com/Michael-Rudalx/tank-battle) |
| [`arcade/ward-13/`](arcade/ward-13/) | WARD 13 — Anomaly Protocol | 2026 Negru Gabriel | MIT License | [Negru-Gabriel/WARD-13-Anomaly-Protocol](https://github.com/Negru-Gabriel/WARD-13-Anomaly-Protocol) |
| [`arcade/welcome-to-klang/`](arcade/welcome-to-klang/) | Welcome to Klang | *(licence leaves the holder line unfilled — author SkylineClhS)* | Apache License 2.0 | [SkylineClhS/WelcomeToKlang](https://github.com/SkylineClhS/WelcomeToKlang) |
<!-- ARCADE-TABLE:END -->

**Both licences here require the copyright notice and licence text to travel with
the code.** That is what `LICENSE.txt` in each directory is for; do not delete it
when moving these around. The Apache-2.0 game additionally requires that
modifications be stated — **we have not modified any of these files.**

**No game file was edited.** The wrapper injects a small in-memory `localStorage`
shim into the frame at runtime, because a sandbox with no `allow-same-origin`
gives the frame an opaque origin where touching `window.localStorage` throws and
takes the game down with it. Shimming from the wrapper rather than patching the
game is what keeps `game.txt` byte-identical to what the author published. The
visible cost is that progress does not persist between visits, and each game page
says so.

**Why these ones.** They were picked from 301 games created on GitHub in one week
(2026-07-29 to 08-04) on evidence, not vibes: each carries a permissive licence,
contains **no third-party media assets at all** — no art, no audio, no fonts,
nothing but code that draws itself — and was opened and looked at in this site's
own sandboxed wrapper before it got a page. That media property is why the licence
covers the whole work and this notice can be short. Games with unattributed art, a
soundtrack of unknown origin, or a trademarked title were left out.

🔴 **"It loaded" was the wrong test, and it passed a dead game.** The first pass
qualified games by loading the author's GitHub Pages site and seeing a page. One
candidate (`CelynXT/tank-battle`) rendered its scoreboard, its legend and its
controls around a **black rectangle**, throwing `Cannot read properties of
undefined` out of its render loop 194 times in the seconds it took to look — on
the author's own site, not just ours. A game that is broken at the source looks
exactly like a working one to a check that only asks whether the document
rendered. Every game listed above was opened in the wrapper and *looked at*.
The 28 rejects and the reason for each are in
`tools/arcade_rejects_2026-08-06.json`, because a silent drop is indistinguishable
from never having looked.

⚠️ Same caveat as the rest of this file: it is a record of what we ship and where
it came from, not legal advice, and nobody with a law degree has reviewed it.

---

## Our own code

**This repository has no `LICENSE` file, which means our own work is "all rights
reserved" by default.** That is stated here rather than left to be inferred,
because a repo with no licence is routinely mistaken for a permissive one — the
same mistake in reverse is the reason this file exists. Nothing here grants
anyone a licence to our engines, art or copy.

**The rules of a game are not copyrightable**, which is what makes the queue in
`GOAL_EVERY_GAME.md` buildable at all: euchre, cribbage, carrom and the rest are
implemented from published rules, against published anchors, with no third-party
code involved. Names are a different matter — trademarked titles (UNO,
Rummikub, Cluedo, Yahtzee, Scrabble, Monopoly) are why those games are either
absent from the queue or shipped under our own names (LEXEME, MOGUL, QUINT,
OVERRUN, CLASP, HOMESTRETCH, OUTPOST).
