# Third-party notices and reuse boundaries

Original Clinical Figure Library adapters, synthetic examples and teaching text: **Copyright 2026 Jaime Yan**, under the Jaime Yan Personal Noncommercial Attribution License 1.0. Retain the author, LICENSE, NOTICE and CITATION files. The original license does not restrict rights granted by third parties.

No third-party implementation source, dataset or example image is vendored by this extension. Packages are separately installed dependencies; this repository invokes their public APIs. Source snippets inspected for research are retained only in ignored internal evidence, with pinned URLs and hashes in the public research catalog. They must not be included in a source bundle.

| Component | Use | Upstream rights / source |
|---|---|---|
| Python / R | External language runtimes | [Python PSF license](https://docs.python.org/3/license.html); [R licensing](https://www.r-project.org/Licenses/) |
| NumPy / pandas | External arrays and tabular preparation | BSD-3-Clause; [NumPy](https://numpy.org/doc/stable/license.html), [pandas](https://pandas.pydata.org/docs/getting_started/overview.html#license) |
| SciPy | External `stats.ecdf` and t quantiles | BSD-3-Clause; [license](https://github.com/scipy/scipy/blob/main/LICENSE.txt) |
| Matplotlib | External native Figure and exports | PSF-based; [license](https://matplotlib.org/stable/project/license.html) |
| ggplot2 | External native ggplot and exports | MIT + upstream LICENSE; pinned DESCRIPTION/LICENSE in research catalog |
| jsonlite | External R JSON serialization | MIT; installed package metadata, no code copied |
| Seaborn | Benchmark only; not required by template API | BSD-family upstream license text pinned in research catalog |
| statsmodels 0.14.6 | External OLS implementation for adjusted-domain adapter; also ECDF benchmark | BSD-3-Clause; installed source/license hashes and upstream copyright evidence recorded in research catalog. No upstream code copied or binaries redistributed. |
| pypdf / Playwright | Local PDF/browser verification only | BSD-3-Clause / Apache-2.0; not shipped as runtime JS or vendored source |
| PyMuPDF | Optional local PDF rasterization check only; existing installation, no source/binary redistribution | AGPL or commercial licensing; [official licensing](https://pymupdf.readthedocs.io/en/latest/about.html). Not a deployed service or template runtime dependency. Reusers must evaluate their own distribution and execution context. |
| DejaVu Sans | Installed font used by Python; PDF embeds glyph subset | [DejaVu license](https://dejavu-fonts.github.io/License.html), based on Bitstream Vera; preserve embedded font notices and font redistribution terms. No standalone font file copied. |

R exports use installed Arial/Arial Bold via Cairo; the actual installed OS/2 fsType flags were inspected and equal 8 (editable embedding). See the [Microsoft document-embedding rules](https://learn.microsoft.com/en-us/typography/fonts/font-faq). No standalone Windows font is distributed or served as a web font. Generated PDFs contain subsets, and R SVGs contain glyph outlines. Consequently R SVG text is not directly editable as text; the native ggplot object and PDF preserve the editable workflow. Browser pages reuse the existing site's locally hosted fonts and notices. The source bundle excludes dependency binaries and font files.

GPL/LGPL candidates, including forestly, ggdist, ggridges, qcc, dagitty and survival, retain their original rights. Their source is not combined or relicensed here. A future adoption must review exact files, linking and distribution, preserve notices, and may require separate external dependencies or a different distribution boundary. We do not assert that every conceivable combination is compatible with the custom noncommercial license.

Credit the actual versions of SciPy, Matplotlib, ggplot2, R and Python in reproducible work. For the original adapter, figures, synthetic data and teaching material, cite **Jaime Yan, Clinical Figure Library**, with the commit used. Upstream attribution does not replace the required Jaime Yan citation; the Jaime Yan license does not claim ownership of upstream code or user-supplied data.
