FTTHelper — Content Rights Inventory

Reproduced verbatim from docs/legal/content-rights-inventory.md in the FTTHelper source tree. Back to Licenses and Attribution.

> **Last updated:** 2026-06-16
> **Owner:** R21 Digital (R21 Media Group LLC)
> **Purpose:** Forward-looking decision table for "can we use X?" — what content we *can* draw from to build FTTHelper, by category, with the verdict, license, attribution, and any action items.
> **Companion docs:** [`LICENSE.md`](../../LICENSE.md) (the *attribution* doc — what we already ship), [`docs/superpowers/plans/2026-06-14-dnd-rag-corpus.md`](../superpowers/plans/2026-06-14-dnd-rag-corpus.md) (RAG corpus), [`docs/superpowers/plans/2026-06-14-igarus-v1-distillation.md`](../superpowers/plans/2026-06-14-igarus-v1-distillation.md) (Igarus LoRA dataset).

---

How to use this doc

This is a **decision table**, not a catalog. The unit of decision is one row. The verdict is the only field that matters when you're about to ship content — the rest is *why*.

Verdict legend

| Verdict | Meaning | When to use it |
|---|---|---|
| ✅ **Use freely** | License is permissive (OGL-1.0a, CC-BY-4.0, CC-BY-3.0, ORC, public domain, our own). Required attribution is the only constraint. | Default verdict. Ship. |
| ⚠️ **Use with care** | License is restrictive (no-derivs, share-alike, attribution-non-commercial, or pending ToS update). | Talk to Carlos before shipping. |
| ❌ **Never use** | All-rights-reserved, on the Product Identity exclusion list, or platform ToS forbids training/redistribution. | Don't even use as inspiration. Don't paraphrase. |
| 🚧 **Pending** | The source is fine in principle, but a legal gate (e.g. ToS training-rights clause) must be in place first. | Don't ship until the gate is closed. |

The 4-question gate (use before adding any new source)

Before you add a new row, walk the gate:

1. **Is the source in the OGL / CC-BY / ORC / public-domain family?** → ✅ Use with attribution.
2. **Is the source on the Product Identity exclusion list (§D below)?** → ❌ Never.
3. **Is the content user-generated, and do we want to train on it?** → 🚧 Add a ToS training-rights clause first.
4. **Is the content from a scraping-against-ToS source** (D&D Beyond, Fandom, scraped D&D-art portfolios)? → ❌ Never.

If the answer is "I don't know" — default to ❌ and ask Carlos.

---

§A — Game-rule text (compendium data)

What fills our `/compendium/*` pages (monsters, items, spells, rules). **Already populated and live.**

| Source | License | Verdict | What we use it for | Required attribution | Action items |
|---|---|---|---|---|---|
| WotC SRD 5.1 | CC-BY-4.0 + OGL-1.0a | ✅ | Monsters, items, spells, rules text | "© Wizards of the Coast LLC, used under CC-BY-4.0 / OGL-1.0a." | Done — see LICENSE.md §2.1 |
| WotC SRD 5.2 | CC-BY-4.0 | ✅ | Updated 2024 rules text | Same as 5.1 | Done — see LICENSE.md §2.1 |
| 5e Core Rules (pre-SRD OGL) | OGL-1.0a | ✅ | Subset of SRD under original OGL | Same as 5.1 | Done — see LICENSE.md §2.1 |
| Open5e API aggregation | OGL-1.0a | ✅ | Already populated; the de facto Compendium source | Per-source attribution on every detail page | Done — `scripts/seed-*.mjs` + `/compendium/[slug]` |
| D&D 5e API (`dnd5eapi.co`) | OGL-1.0a / CC-BY | ✅ | Supplement Open5e; cross-check entries | Per-source attribution on every detail page | Done — linked from `/licenses` |
| Kobold Press — Tome of Beasts (1/2/3/2023) | OGL-1.0a | ✅ | Monster expansions | "© Open Design LLC / Kobold Press. OGL-1.0a." | Done — see LICENSE.md §2.2 |
| Kobold Press — Creature Codex | OGL-1.0a | ✅ | Monster expansions | Same | Done — see LICENSE.md §2.2 |
| Kobold Press — Tome of Heroes | OGL-1.0a | ✅ | Items, spells | Same | Done — see LICENSE.md §2.2 |
| Kobold Press — Deep Magic (5e + Extended) | OGL-1.0a | ✅ | Spells | Same | Done — see LICENSE.md §2.2 |
| Kobold Press — Warlock Archives | OGL-1.0a | ✅ | Spells | Same | Done — see LICENSE.md §2.2 |
| Kobold Press — Compilation | OGL-1.0a | ✅ | Spells | Same | Done — see LICENSE.md §2.2 |
| Kobold Press — Black Flag SRD | ORC + OGL-1.0a | ✅ | Monsters (dual-licensed) | "© Open Design LLC / Kobold Press. Licensed under ORC and OGL-1.0a." | Done — see LICENSE.md §2.2 |
| EN Publishing — Level Up A5e (Core + Monstrous Menagerie) | OGL-1.0a | ✅ | Items, spells, monsters | "© EN Publishing. OGL-1.0a." | Done — see LICENSE.md §2.3 |
| Mage Hand Press — Vault of Magic | OGL-1.0a | ✅ | Magic items | "© Mage Hand Press. OGL-1.0a." | Done — see LICENSE.md §2.4 |
| Darrington / Green Ronin — Tal'Dorei Reborn | OGL-1.0a | ✅ | Monsters, magic items (mechanics only) | "© Green Ronin Publishing LLC / Darrington Press. OGL-1.0a." | Done — see LICENSE.md §2.5 |

---

§B — World lore & setting prose

The *narrative* content that brings a setting to life — gazetteers, adventure modules, novelizations. **Mechanics are OGL; narrative is not.**

| Source | License | Verdict | What we use it for | Required attribution | Action items |
|---|---|---|---|---|---|
| Forgotten Realms (WotC) | All-rights-reserved | ❌ | Nothing — no lore, no names, no geography | n/a | Hard ban. Even "inspired by" fan content is a slippery slope. |
| Greyhawk (WotC) | All-rights-reserved | ❌ | Nothing | n/a | Hard ban. |
| Eberron (WotC) | All-rights-reserved | ❌ | Nothing | n/a | Hard ban. |
| Ravenloft / Dragonlance / Dark Sun (WotC) | All-rights-reserved | ❌ | Nothing | n/a | Hard ban. |
| Tal'Dorei (Green Ronin / Darrington) | All-rights-reserved (Product Identity separate from OGL mechanics) | ❌ | Mechanics only (per §A) — no setting prose, no named NPCs/factions | n/a | Hard ban on the setting; the *mechanics* are fine, the lore isn't. |
| Wildemount (WotC) | All-rights-reserved | ❌ | Nothing | n/a | Hard ban. |
| Strixhaven / Theros / Ravnica (WotC) | All-rights-reserved | ❌ | Nothing | n/a | Hard ban. |
| Exandria (Critical Role) | All-rights-reserved | ❌ | Nothing — same as Tal'Dorei | n/a | Hard ban. |
| Pathfinder / Golarion (Paizo) | All-rights-reserved | ❌ | Nothing | n/a | Hard ban. (Different publisher; even more isolated than WotC settings.) |
| DMs Guild / D&D Beyond community content | Varies; often all-rights with limited-use license | ❌ | Nothing | n/a | Hard ban — third-party published content; even with a license, it's not broad enough for our use. |
| dandwiki.com | CC-BY-SA (copyleft) | ❌ | Nothing | n/a | CC-BY-SA is copyleft — derivative works must be shared under the same license. We can't ship CC-BY-SA in a proprietary product. |
| Fandom wikis (Forgotten Realms, etc.) | All-rights-reserved | ❌ | Nothing | n/a | Hard ban. (WotC PI again, plus Fandom ToS forbids scraping.) |
| Adventure modules (WotC, Paizo, etc.) | All-rights-reserved | ❌ | Nothing | n/a | Hard ban — full adventures are PI, not just settings. |

---

§C — Named characters, factions, and deities

**The single most common content-licensing mistake: lifting a named character.** Even changing the spelling doesn't work — it's the *identity* that's protected.

| Source | License | Verdict | What we use it for | Required attribution | Action items |
|---|---|---|---|---|---|
| Drizzt Do'Urden, Mordenkainen, Tasha, Strahd, Elminster, Volo, Minsc (WotC) | All-rights-reserved (Product Identity) | ❌ | Nothing | n/a | Hard ban — explicit PI list in LICENSE.md §2.1 |
| The Forgotten Realms deities (Mystra, Bane, Bhaal, Shar, etc.) | All-rights-reserved (Product Identity) | ❌ | Nothing | n/a | Hard ban. Use generic "god of magic" / "god of murder" wording, not deity names. |
| Pathfinder iconic characters (Valeros, Seelah, etc.) | All-rights-reserved | ❌ | Nothing | n/a | Hard ban. |
| Critical Role PCs (Vox Machina, Mighty Nein, Bell's Hells) | All-rights-reserved | ❌ | Nothing | n/a | Hard ban — even fan-art-style use is risky. |
| Open5e-republished named NPCs (where license applies) | OGL-1.0a (when re-published under OGL) | ✅ | Only what's re-published under OGL, with attribution | Per Open5e entry | Use Open5e's published versions; never invent a name that "feels like" one of these. |
| FTTHelper "The Loremaster" curator NPCs | Proprietary (R21 Digital) | ✅ | All `seed-npcs.mjs` outputs | n/a (we own it) | Maintain `seed-npcs.mjs` — see Thread 2 in 2026-06-16 RAG Foundation Sprint. |

The "Renamed but recognizable" test

If you changed a WotC PI name by one letter and a player would still recognize who it's *supposed* to be (e.g. "Drizzit" → "Drizzt"), it's still PI in spirit. Default to ❌. The two seeded renames this session — Korrg the Cleaver → **Tormund Ironhide** and Whisper → **Sariel Wren** — are safe because they're genuinely *new* characters with no recognizable source.

---

§D — Monster lore (non-PI)

OGL *mechanics* (stat blocks, CR, traits) are licensed. The narrative flavor text for monsters in published books is often *Product Identity*, not OGL. **The SRD/Open5e descriptions are clean; in-book descriptions are not.**

| Source | License | Verdict | What we use it for | Required attribution | Action items |
|---|---|---|---|---|---|
| **Product Identity monsters (hard ban list — see LICENSE.md §2.1):** Beholder, Mind Flayer / Illithid, Displacer Beast, Githyanki, Githzerai, Carrion Crawler, Gauth, Kuo-toa, Slaad, Umber Hulk | All-rights-reserved (WotC PI) | ❌ | Nothing — even via paraphrase | n/a | **Never seed these. Never let users upload art of them. (Consider a content-filter on user uploads — open question.)** |
| Owlbear, Goblin, Orc, Hobgoblin, Bugbear, Kobold, Lizardfolk, Dragon (generic), Troll, Ogre, Skeleton, Zombie, Mummy, Banshee, Wyvern, Manticore, Sphinx (generic), Harpy, Medusa, Minotaur, Vampire (generic), Werewolf (generic), Demon (generic), Devil (generic) | OGL-1.0a (mechanics + SRD description) | ✅ | Stat blocks, SRD descriptions | Per Open5e entry, link to source | Use Open5e / SRD descriptions. Don't paste the WotC MM flavor text — paraphrase if you need longer flavor. |
| Drow | OGL-1.0a (mechanics) — but the *Lolth-sworn Drow* archetype is heavily tied to FR/PI | ⚠️ | Stat block only — never invoke FR setting, Lolth, or the Underdark-as-Forgotten-Realms framing | n/a | Allowed in stat-block context; do not put Drow NPCs in our Codex with FR-locked flavor. (Project rule: no Drow in the seeded Codex.) |
| Custom / Open5e-original monsters | OGL-1.0a | ✅ | Anything published under Open5e | Per Open5e entry | Use as-is. |
| Beholder variants (Death Kiss, Gazer, etc. — *not* the base Beholder) | OGL-1.0a (in Kobold ToB, EN A5e, etc.) | ⚠️ | Allowed only when the *source* is OGL | Per source | Track the source; the variant's body must come from an OGL document, not invented. |

The "looks like Beholder" problem

A floating sphere with a central eye and eyestalks that shoots rays is *visually* a Beholder. Even if you call it "The Watcher of the Glade," the design is PI in spirit. Same goes for Mind Flayer head-shape, Displacer Beast's displaced-image silhouette, etc. For NPC art in our Codex, default to **humanoid or generic-monster silhouettes** unless the lore you want to invoke is unambiguously OGL (e.g. a goblin chief is fine; a mind flayer cult leader is not).

---

§E — Art & illustration

| Source | License | Verdict | What we use it for | Required attribution | Action items |
|---|---|---|---|---|---|
| Compendium art bundled in Open5e / 5e-API | OGL-1.0a / CC-BY (varies per entry) | ✅ | Compendium detail pages, with credit per entry | Per entry, link to source | Already done — `seed-compendium.mjs` writes per-row attribution. |
| NPC Codex portraits (fal.ai-generated, "The Loremaster" account) | Proprietary (R21 Digital) | ✅ | NPC Codex cover art | n/a (we own it) | `seed-npcs.mjs` — keep using fal (premium) or CF flux-schnell (free fallback). |
| DiegoV gallery (Cloudflare Workers AI, FLUX/SDXL) | Proprietary (R21 Digital — original generations) | ✅ | Demo / landing / showcase | n/a | `seed-diegov.mjs` — keep. |
| **User-generated art** | License = per the upload's license grant in our ToS | 🚧 | Art hub, profile galleries, "summon" outputs | Per the ToS grant (default: user's, with our display license) | **🚧 ToS training-rights clause required** before we use user art for Igarus LoRA training, RAG, or any derivative pipeline. |
| **WotC book art** (Player's Handbook, Monster Manual illustrations, etc.) | All-rights-reserved | ❌ | Nothing | n/a | Hard ban — even fan recreations are a risk. |
| **D&D Beyond / community art** | All-rights (typically) | ❌ | Nothing | n/a | Hard ban. |
| **Stock photo libraries** (Unsplash, Pexels, Pixabay) | Per-stock license (most are CC0 / "free for commercial") | ⚠️ | Marketing visuals only — never for in-game content | Per-stock | OK for landing/marketing; do not mix with compendium/NPC art. |
| **game-icons.net** | CC-BY 3.0 | ✅ | UI icons (per LICENSE.md §3) | "Icons by game-icons.net under CC-BY 3.0" | Done — see LICENSE.md §3. |

Igarus LoRA training — what goes in, what doesn't

The Igarus flywheel (see `2026-06-14-igarus-v1-distillation.md`) trains a FLUX-dev LoRA on FTTHelper's house art + synthetic premium-model generations. **The data sources must be:**

- ✅ Our own NPC portraits (R21 Digital proprietary)
- ✅ Our own user art (once the ToS training clause is live)
- ✅ Synthetic generations on SRD/Open5e-derived prompt seeds (clean prompt → clean generation)
- ❌ **NEVER** scrapes of D&D art from D&D Beyond, Fandom, ArtStation, Pinterest, Google Images, or artist portfolios — even for "personal" LoRA training, the redistribution surface is too broad and the ToS exposure is too high (Stability AI / Midjourgen lawsuit precedent).

---

§F — Iconography & UI

| Source | License | Verdict | Action items |
|---|---|---|---|
| game-icons.net | CC-BY 3.0 | ✅ | Done — LICENSE.md §3 |
| Lucide / Heroicons / Phosphor | MIT / MIT / MIT | ✅ | Open-source icons — fine for UI; no attribution required (appreciated). |
| Emoji (system-rendered) | n/a (per Unicode, system-font) | ✅ | Use freely. |
| Custom R21 icons | Proprietary (R21 Digital) | ✅ | Use freely. |
| D&D-style symbols (Amber, Sigil of the Nine Hells, etc.) | Mixed — many are PI | ❌ | Don't use a sigil as a faction logo unless the source is OGL. |

---

§G — System mechanics (rules)

| Source | License | Verdict | Notes |
|---|---|---|---|
| SRD 5.1 / 5.2 mechanics | CC-BY-4.0 / OGL-1.0a | ✅ | All dice, classes, spells, conditions. |
| OGL-1.0a mechanics | OGL-1.0a | ✅ | Same as above. |
| Homebrew rules (FTTHelper's own) | Proprietary (R21 Digital) | ✅ | Any custom systems we build — our IP. |
| Pathfinder 2e mechanics | All-rights (Paizo's ORC) | ❌ | Different system; only OK if we add Paizo's ORC and respect its terms (currently not on roadmap). |
| OSR systems (Old-School Essentials, Basic Fantasy, etc.) | OGL / CC | ✅ if OGL | Allowed under same attribution as D&D 5e. |

---

§H — AI-generated content (our pipeline)

| Source | License | Verdict | What we use it for | Action items |
|---|---|---|---|---|
| fal.ai generations (FLUX 1.1 pro, FLUX.2 pro, etc.) | Per fal.ai ToS — output rights transferred to caller for paid tiers | ✅ | Premium art, "Summon Studio" outputs | Per fal commercial terms. |
| Cloudflare Workers AI (FLUX.1-schnell, SDXL-lightning) | Per CF ToS — generally permissive for paid accounts | ✅ | Free-tier art, "Igarus" default rung | Confirm CF ToS annually. |
| Google Gemini (Nano Banana 2, image gen) | Per Google ToS | ⚠️ | Pending review of Google's commercial-use terms for image gen | Action: Carlos to review Google ToS before turning this rung on for the public. |
| xAI Grok Imagine | Per xAI ToS | ⚠️ | Same as Gemini — paid rung only after ToS review | Same. |
| OpenAI GPT Image 1.5 / 2 | Per OpenAI ToS — usage policy requires disclosure | ⚠️ | Paid rungs; **must surface "AI-generated" disclosure on the art card** | Action: Add the disclosure in the art-card component if not already there. (Verify in Thread 4 audit.) |
| A LoRA *trained* on scraped D&D art | n/a (illegal in our pipeline) | ❌ | Nothing — even locally, the redistribution surface (we ship the model on fal) is too broad | Hard ban. Distillation-from-own-art is the path. |
| User art used as LoRA training data (without ToS) | n/a | ❌ | Nothing until the ToS training clause is in place | 🚧 Gate on ToS. |

---

§I — User-generated content (UGC)

The widest legal surface. **🚧 We need a ToS training-rights clause before we use any user content for Igarus training, RAG, or model fine-tuning.**

| Content type | Default license (per draft ToS) | Verdict | Notes |
|---|---|---|---|
| **User art** (uploaded or generated via Summon) | User owns; grants R21 a non-exclusive display license | ✅ to display, 🚧 to train on | ToS update needed for the train-on part. |
| **User-created worlds / NPCs / lore** | User owns; grants R21 a non-exclusive display + improvement license | ✅ to display, 🚧 to ground RAG | Same gate. |
| **User prompts** (the `final_prompt` field we save) | User owns; grants R21 a non-exclusive use license | ✅ to display (in their own profile), 🚧 to use as LoRA training captions | Same gate. |
| **User names / handles** | User owns; we display in public | ✅ | Standard. |
| **User email / payment data** | User owns; we don't display, don't share | ✅ | Privacy policy covers. |
| **Public Codex NPCs the user derives from a public-Loremaster NPC** | User owns the *derivation*; the base NPC stays Loremaster's | ✅ | Standard "derivative work" framing. |

ToS update — required before the next sprint

The clause we need (paraphrased — actual wording goes in the legal review):

> "By using FTTHelper, you grant R21 Digital a non-exclusive, royalty-free, worldwide license to use your user-generated content (art, prompts, world entities, and metadata) for the purposes of operating, improving, and developing FTTHelper, including but not limited to: displaying your content, training machine-learning models on the platform, and aggregating anonymized insights. You retain ownership. You may revoke the train-on portion at any time by deleting the relevant content."

This is the gate for the Igarus flywheel and the RAG corpus. **Without it, both plans are parked.**

---

§J — Open5e aggregated content (the de facto corpus)

| Source | License | Verdict | Notes |
|---|---|---|---|
| Open5e API (any endpoint) | OGL-1.0a + per-publisher attribution | ✅ | The single source for `/compendium/*`. Per-entry attribution on every detail page. |
| Open5e original content | OGL-1.0a | ✅ | Same as above. |
| Open5e aggregated from WotC SRD | OGL-1.0a / CC-BY-4.0 | ✅ | Same. The Open5e chain makes the cross-licensing clean. |

---

§K — The "On the fence" list

Things we haven't decided on. The default is to **not ship** until the verdict moves to ✅.

| Item | License | Current verdict | Why it's pending |
|---|---|---|---|
| **Tavily / web search for NPC lore lookup** | Per Tavily ToS (we use it for R21 outreach) | ⚠️ | OK for *internal* research; never for *re-publishing* — we synthesize, we don't paste. |
| **Notion / Drive / ClickUp internal docs as prompt seed inspiration** | Internal — proprietary | ✅ | Fine for prompt engineering; never visible to users. |
| **Published bestiaries (Kobold ToB) PDF text** | OGL-1.0a | ✅ | Already attributed in LICENSE.md §2.2. |
| **Homebrew content uploaded by users** | Per ToS | 🚧 | Same ToS gate as user art. |
| **Critical Role fan-art of the Vox Machina cast** | All-rights (Darrington / CR) | ❌ | Hard ban — same as Tal'Dorei lore. |
| **Generic D&D-themed emojis / reactions** (custom set) | Proprietary if we make them; CC if we use an existing pack | ✅ / ⚠️ | Custom = fine; existing = check the pack's license. |
| **Real-world mythology** (Norse, Greek, etc.) | Public domain | ✅ | Free to use. (Gives "Tormund Ironhide" its flavor — Norse-coded, not Norse-pasted.) |
| **Our own Loremaster NPC designs** | Proprietary (R21 Digital) | ✅ | All `seed-npcs.mjs` outputs — including the Tormund Ironhide + Sariel Wren renames from the 6/16 sprint. |

---

The Product Identity exclusion list (consolidated from LICENSE.md §2.1)

For quick reference. **The default for any of these is ❌. Even paraphrases, even transformations.**

- **Creatures:** Beholder, Mind Flayer (and Illithid), Displacer Beast, Githyanki, Githzerai, Carrion Crawler, Gauth, Kuo-toa, Slaad, Umber Hulk
- **Named characters:** Drizzt Do'Urden, Mordenkainen, Tasha (and the rest of WotC's PI list — full list in `LICENSE.md` §2.1)
- **Settings:** Forgotten Realms, Greyhawk, Eberron, Ravenloft, Dragonlance, Dark Sun, Tal'Dorei, Wildemount, Strixhaven, Theros, Ravnica, Golarion

When in doubt → ask Carlos. When *still* in doubt → ❌.

---

Update log

| Date | Change | By |
|---|---|---|
| 2026-06-16 | First draft — Sections A–K, gate questions, PI exclusion list | Carlos + Claude (6/16 RAG Foundation Sprint) |
| _open_ | _Add per-section Action items as they're closed_ | _tbd_ |
| _open_ | _Add the ToS training-rights clause text once Carlos signs off_ | _tbd_ |

Back to Licenses and Attribution