# Licenses and attribution obligations Nuvolari redistributes third-party data. Every obligation below is binding: the Sources screen in the app must satisfy all of them, and none of them may be dropped to save screen space. ## Summary | Data | License | Mandatory credit | Notes | |---|---|---|---| | Radar-DPC rasters | CC BY-SA | "Radar-DPC" | **Share-alike propagates to our frames** | | ARPA Piemonte data | CC BY 4.0, commercial OK | "Fonte: Arpa Piemonte - www.arpa.piemonte.it" | Radar volumes: licence not repeated on their page, access by email | | ARPA Piemonte alerts | CC BY 4.0 (site notice) | as above, + link to the official bulletin | Levels republished verbatim | | OpenStreetMap data | ODbL | "© OpenStreetMap contributors" | Must stay visible on the map | | OpenMapTiles schema | BSD 3-Clause | "© OpenMapTiles" | Must stay visible on the map | | OpenFreeMap service | MIT | "OpenFreeMap" — optional | Listed on the Sources screen | | Istat municipality boundaries | CC BY 4.0 | "Istat" | Bundled municipality list, commercial use permitted | ## Share-alike is the constraint that shapes the backend The Radar-DPC rasters are **CC BY-SA**. The PNG frames the worker produces — cropped, reprojected, colourised — are a derived product, so they inherit CC BY-SA. Practical consequences: - The published frames and `manifest.json` are CC BY-SA and must be labelled as such. - We cannot relicense them, and we cannot restrict their reuse. - The share-alike obligation covers the **data**, not the app's source code or UI. The manifest carries its own `attribution` string for exactly this reason: the credit travels with the frames rather than being remembered at render time, and the app displays whatever the publisher of those frames says to display. ## ARPA Piemonte: CC BY 4.0, stated in the legal notice ARPA's legal notice at releases environmental and open data under **CC BY 4.0**, explicitly permitting commercial use, and requires the credit *"Fonte: Arpa Piemonte - www.arpa.piemonte.it"*. Logos, institutional emblems, registered trademarks and third-party content are excluded. Both ARPA REST APIs — `api_realtime` and Meteoweb — link that notice from their OpenAPI `description`, so anything served by them is covered without further correspondence. The **radar volumes** are the one gap: their open-data page says only *gratuiti* and does not repeat the licence, and the real-time access link is issued by email. Ask ARPA to confirm both in the same message. Until then the radar adapter stays disabled — see [data-sources.md](data-sources.md) section 2. The credit string ARPA asks for is the full *"Fonte: Arpa Piemonte - www.arpa.piemonte.it"*, not the bare name currently in the region config. Adopt the full form the moment any ARPA-sourced data is actually displayed. ## Where the credits live, and why that is enough The OpenFreeMap style JSON has no `attribution` field, so MapLibre displays nothing on its own. The app therefore renders the credits itself, on the **Sources screen**, reached from the settings button on the map. There is deliberately no permanent credit line over the map. The [OSMF attribution guidelines](https://osmfoundation.org/wiki/Licence/Attribution_Guidelines) allow this for a browsable map: attribution may be collapsed or dismissed provided that *"the user must still be able to find the licence information if they look for it, for example from an '(i)' button in the corner of the map or an 'About' option in a menu"*. The route is map → settings → **Fonti e licenze**, two taps and clearly labelled, and MapLibre's own `(i)` control sits in the map's top-right corner as well. **This is a licence obligation, not a layout preference.** Do not bury the Sources entry deeper, and do not remove its subtitle saying what it contains. A test in `settings_screen_test.dart` asserts the entry exists and opens the screen, so removing it fails the build rather than shipping quietly. The Sources screen lists every credit the region config declares, **plus** the credit the radar manifest carries for the frames currently on screen — that one is set by whoever published the frames and is not in the config, so it would otherwise have been lost when the on-map bar was removed. ## Advertising, and why it still matters here The app currently carries **no advertising**, so it is not a commercial product today. Ads are a plausible future, though, and a source adopted now on non-commercial terms would have to be ripped out then. Prefer sources that permit commercial use. This is why **Open-Meteo's free tier** and **Blitzortung** remain listed as excluded even though the features that would have used them are out of scope: both are non-commercial-only, and neither should be reached for on the grounds that there are no ads at the moment. ## Naming and independence The app must never appear to be an official ARPA or Protezione Civile product: - no ARPA/DPC logos, coats of arms or institutional branding; - never the word "ufficiale" applied to the app itself (the *bulletin* is official — the *app* is not); - the Sources screen carries an explicit disclaimer that Nuvolari is an independent app, not affiliated with, endorsed by, or operated by ARPA Piemonte or the Dipartimento della Protezione Civile; - for civil-protection purposes the official channels always prevail, and the app says so next to every alert.