Ninebloomninebloom
Ninebloom — Legal

Licence

Effective 16 September 2026 · Proprietary · Third-party notices included

Ninebloom’s platform, website and services are proprietary. Third-party open-source components listed on /attribution remain under their own licences.

1. Proprietary Licence — Ninebloom

Copyright (c) 2026 Ninebloom Pvt Ltd. All rights reserved.

This repository and its contents (including source code, designs, images, documentation, and configuration) are proprietary and confidential.

No part of this repository may be reproduced, distributed, transmitted, publicly displayed, modified, reverse-engineered, or used to create derivative works without prior written permission from Ninebloom Pvt Ltd, except as explicitly permitted under applicable third-party open-source licences for dependencies listed in THIRD_PARTY_NOTICES.md (which remain governed by their respective licences).

Third-party open-source components are NOT covered by this proprietary licence; they are licensed separately under their own terms (see THIRD_PARTY_NOTICES.md, client/THIRD_PARTY_NOTICES.md, landing/THIRD_PARTY_NOTICES.md, server/THIRD_PARTY_NOTICES.md).

If you have been granted access to this repository, your use is governed by your agreement with Ninebloom. Unauthorized copying or disclosure is prohibited.

For licensing inquiries: legal@ninebloom.co

2. Third-Party Open-Source Notices

Ninebloom uses the following permissive open-source SDKs dynamically via npm/pip. They are not covered by the proprietary licence above.

Client & Landing (npm)

  • MIT / ISC @radix-ui/*, @tanstack/*, tailwindcss, lucide-react (ISC), thesvg (MIT), qrcode, recharts, sonner, cmdk, embla-carousel — see THIRD_PARTY_NOTICES.md
  • CC0-1.0 simple-icons (landing brand marquees) — paths are public domain, trademarks remain with brands
  • SIL OFL 1.1 Manrope, Instrument Serif via Google Fonts — openfontlicense.org
  • Cloudflare Turnstile https://challenges.cloudflare.com — Cloudflare Terms, CSP allow-listed

Server (pip · 109 packages pinned in uv.lock)

  • Apache-2.0 / BSD / MIT boto3/botocore, cryptography, fastapi/starlette, supabase, openai, langchain*
  • LGPL-3.0-only fpdf2, psycopg* — used as unmodified wheels, §4; source via upstream
  • GPL-2.0 (transitive) pyphen via weasyprint — SaaS use is not distribution; distributing a Docker image requires GPL compliance or rebuild without pyphen
  • CC BY-SA 4.0 MaxMind GeoLite2 City DB — not vendored; fetched via GEOIP_DB_PATH

Full SBOM: THIRD_PARTY_NOTICES.md in root / client / landing / server, regeneratable via npx license-checker --production and pip-licenses. Raw files:/THIRD_PARTY_NOTICES.md, /LICENSE

See full attribution for images, icons & fonts →

3. How to comply when you distribute a bundle

  • Retain MIT/ISC/Apache-2.0/BSD licence texts (included in bundle via THIRD_PARTY_NOTICES).
  • For LGPL (fpdf2, psycopg): if you modify the library itself, publish modified source under LGPL-3.0.
  • For OFL fonts: retain OFL.txt if you self-host WOFF2.
  • For Unsplash photos hotlinked from images.unsplash.com — commercial use allowed, no attribution required; do not relicense as more restrictive.

Contact

Legal & licensing: legal@ninebloom.co · Privacy: privacy@ninebloom.co

See also: Terms · Privacy · Attribution