# Licensing state [Polska wersja](LICENSES.pl.md) RADBOX firmware, original product code, site, documentation and project records are licensed under Apache-2.0 unless a file carries a different SPDX identifier; see `LICENSE` and `NOTICE`. Core2 Foundation uses the same default. Copyright 2026 Tomasz Fiedoruk, https://fiedoruk.pl/. The repository remains private during development and a public GitHub release is optional. Apache-2.0 permits binary distribution and does not by itself require publication of the owner's original source. Redistribution must follow the Apache-2.0 `LICENSE` and `NOTICE` obligations. The staged low-friction handoff contains the exact factory firmware, browser manifest, hashes, Apache `LICENSE`/`NOTICE` and dependency materials. M5Unified and M5GFX are MIT. Arduino-ESP32 contains LGPL-2.1 and component-specific licences, so the exact release still needs the required source/build materials, third-party notices and SBOM. Full path: `docs/90-apache-2-licensing.en.md`. The generated BLE Signature Pack contains assigned-number facts derived from Nordic Semiconductor's Bluetooth Numbers Database under its BSD-3-Clause licence. The retained attribution is in `NOTICE`; the exact provenance and import policy are documented in `docs/92-ble-signature-pack.en.md`. `tools/capture-device-screen.mjs` is adapted from the owner-controlled Open Radio repository's tool of the same name. The checked local Open Radio source is GPLv3, not GPLv2 or MIT. The derived standalone tool is therefore marked `GPL-3.0-only` and distributed with `LICENSE-GPL-3.0`; it is not linked into the Apache-2.0 firmware. This is an intentional mixed-licence repository, not a claim that GPL code became Apache-2.0.