Many people are asking AI models to take the Javascript code from my website, remove all ads from it, and they publish such a "new product" on Github for everyone to download.
There exist tens of such repositories on Github. I want my website to be the only source of a stable version of my program Photopea. I even received emails from people complaining about something in Photopea, and it took several emails to figure out that they are not using Photopea.com (so it ruins my reputation a little).
I reported it to Github on the 4th of September 2026: https://www.photopea.com/g/XKoqqIGv
Today, a month later, I received this response:
Thank you for submitting a DMCA takedown notice. We've reviewed the information you've provided, and based on the facts presented to us, we're unable to confirm a violation of 17 U.S. Code § 1201.
What do you think I could do? Do you think I should look for a lawyer to deal with it outside the digital world? I really doubt that a real person ever looked at my report, and they probably send this response automatically to 99% of people.
Second, I am sorry this is happening to you.
Third, based on GitHub's reply, specifically
> we're unable to confirm a violation of 17 U.S. Code § 1201
they took your submission as 17 U.S. Code § 1201 takedown notice. Maybe you specifically stated this. Maybe it was implied. This is likely not what you want and GitHub's response is likely correct. The reason for this is that § 1201 prohibits circumventing a technological measure. The JS you host on your public site, even if obfuscated, very likely does not qualify for this protection. Another detail - the reason it took long (a month later according to your post) is that after the youtube-dl fiasco, they committed to manual review, legal and technical, of every 1201 takedown notice [0].
Fourth, if you believe these copies are sufficiently reproducing your copyrighted work, what you likely want to do is file a standard copyright infringement 17 U.S Code § 512(c) takedown notice. This still goes through the same DMCA report flow but it should result in a less stringent review process and a faster response.
Fifth and finally, consider asking your favorite LLM to get more context around these laws. Good luck!
[0] https://github.blog/news-insights/policy-news-and-insights/s...
Honestly, I was a hoping that giving attention to this problem here at HN might lead to someone from Github actually noticing my problem and looking into it.
I think I will try solving it with a lawyer. But it would be really cool if I could spend my days writing code instead of dealing with lawyers and stuff.
I think anybody in any line of work or life would like that. It's however unlikely to never run into an issue where a lawyer is really needed, so don't hesitate when you realize you need one.
If you don't, don't.
It's that simple. Be an adult, make a choice and live with it.
ETA: I dispute the implication that "honest" software is a category that necessarily excludes all ad-supported software, but that's a side story.
As an aside, I thought that "cracked" software meant software that has had the copy protection or other access control bypassed or removed, not the alteration of the software functionality itself. If your software was actually cracked then you may have some fairly heavy law in your favor. For better or worse, bypassing access controls (even weak or simple access controls) gets special legal attention.
Less than 7 figures (~1 million) per year -- not per month -- based on previous comment from 2021: https://news.ycombinator.com/item?id=26769141
As for DMCA filings, we publish all of them here: https://github.com/github/dmca
I see two from Photopea, one from 2022 (https://github.com/github/dmca/blob/d97814f268e07e62aabe8b5c...) and one from 2024 (https://github.com/github/dmca/blob/d97814f268e07e62aabe8b5c...) - could you point to the recent filing?
I work at GH, but am not involved in DMCA filings, and can in no way answer or judge this case, but potentially follow up internally.
Github did take down this https://github.com/spooknik/Photopea-Appimage and other repos in the past, but now, I feel like I talk to a robot. I am happy to hear that they have real employee! :D
OP, I’m sorry this is happening to you. It must be incredibly frustrating to have people ripping off something you’ve worked on for many years and pass it off as their own work. I would be furious in your position.
I wish I could do something directly to help you but the best I can offer is to echo the best advice others have already given you: it’s time to get a lawyer. That is the one guaranteed route to get GitHub to sit up and take the action they should already have taken on your behalf.
I think we're also going to see the strategy to be to remove the processing and magic sauce from the client and move it to the server where it can't be decompiled and rebuilt with AI.
Also if it could recreate it that would be fine, because it would be doing so without having access to the source.
SaaS killed Open Source with it, two decades ago.
Hire a copyright lawyer.
Start going after the people that run this as a service, for both copyright and trademark infringement (you have a trademark for photopea right?).
You had commented on the photocraft post prior, so if it's that, then it's a bit muddled. It's a LLM based re-implementation and not a copy of the code made open. So the argument would be weaker there, and you'd really need specific code samples to make a case of copyright infringement. Photocraft not "piracy" as is normally understood, which is the exact same binary, optionally with the license protection removed.
https://github.com/martinwoodward
before starting heavy artillery with lawyers.
(Martin also often posts on HN).
Did they actually republish you code or were they just creating wrappers that download/cache the code from your website to run locally?
Hope you manage to get it sorted but I have no idea how that would go down at this point. I’m sure at least one of them could claim they copied it off the other ones and then you’re shit out of luck.
I've seen people on Reddit writing things like, "Come on, what's the big deal? AI can write any code now." I disagree. There are hundreds of thousands of lines of code here, very complex code, which even AI wouldn't be able to write on the first try or in a single day. So this person stole this code from Photopea and built a product on top of it.
You will never sue your way out of this. Piracy will always exist. GitHub will respond to a legal notice but whack a mole is the game and legal notices cost money
The solution in the WP community at the time was variations of the plugin as a loss leader to get revenue with support or to leverage community visibility into larger contracts for work or hosting the platform for others.
If your business model depends on your code being a secret, JavaScript is not a good play. The business model needs to enhance what the code offers since it’s basically a commodity now
But wow, how do you stand a chance in stopping anyone when your code is all there freely available in the browser
Because it is trained on code of people like Ivan
https://www.reddit.com/r/Bard/comments/1wxmqpt/ive_created_o...
Headspace updated it's privacy policy info recently, which got me to have it checked with an LLM. And it turns out that what you're doing on $100 per year meditation app is still being sold to anyone willing to pay. Using headspace lost it's charm. I wonder if Andy ever agreed to this.
If you have one of these, it’s possible that GitHub would honour it if you go via a lawyer.
(I only noticed because your site is not blocked in the UK but most of the templates are.)
So you are going to have to prove their code is a copy of yours, not just a copy of the functionality.
In Google vs Oracle, APIs also aren’t necessarily copyright able:
“So long as the specific code used to implement a method is different, anyone is free under the Copyright Act to write his or her own code to carry out exactly the same function or specification of any methods used in the Java API. It does not matter that the declaration or method header lines are identical”
To sum it up; get a lawyer.
Right now, the settled law is that such an LLM reproduction is 100% legal.
If you really want to protect your software in the years to come, you might have to seriously consider starting some sort of popular political movement to address this issue in copyright law.
Current models can already do a full reproduction of anything with source code available (e.g. JavaScript...), and there's already been some poor-quality Photoshop knockoffs.
Where did you hear that? Because it is 100% untrue and is the opposite of current legal guidance from reputable legal expert
How so? Interfaces are not copyrightable, but that it not the same as dissecting a js bundle and copying the implementations. Are we sure these LLM are keeping sanitary habits there?
several courts have ruled Ai output is not copyrightable, I am unaware of any co-authored cases
But, the use of LLMs is not disqualifying. To qualify for copyright protection your work simply must have a sufficient degree of human authorship.
However this is just about protection, not infringement.
If you use an LLM to generate something and that LLM just happens to output something that another human wrote, you may be liable for copyright infringement.
Or perhaps the people should admit that copyright, an artificial construct which is not rooted in natural property, was inherently broken and is not (or at least no longer is) a net benefit to the society and simply adapt around it.
I’m personally waiting for LLMs to get so good that I can make music and movies based on my favorite ones. I probably could never release it to the public, but being able to make it and enjoy it myself would be amazing.
Modifying/modding/remixing software was simply not as feasible as music, but LLMs made it possible.
Copyright, patents and IP are the evolution of our (Western) way of converting research into a form of financial investment.
And a big church could employ lots of them, and thereby stimulate the economy. It seems that the Baroque Era and churches crammed to the rafters with art, may be an artifact of a very good job market for those architects, craftsmen and artists!
Yeah... you could copy some sheet music and share it around, but it still required skilled musicians to perform, play and sing it. And nobody was taking photos or uploading JPEGs of your art and sculpture, so it was fairly locked-in that people needed to visit, and see it in context. So it stood to reason that you could probably reconstruct Noah's Ark from the fragments of True Cross that were circulating around Europe... and how many fingers did your favorite saint really have?
Copyright-free church economics have sort of fallen apart since then. However, museums, arena concerts, theaters and the rest, they have all taken pages from the Church playbooks. The fact that a church can still draw in hundreds for a show with great production values, every week or daily, seems dull and unremarkable now, but a good rock concert or museum collection can evoke the same "goin' to church" fervor in people who like that kind of stuff.
I have agents maintaining several patches to my main tools, not forking, not sharing (some have no interest), personal adjustments
There is basically zero pushback to generated code. All the crazy Minecraft in GTA type mods that came out in the last couple weeks are obviously vibe coded but no one cares because they play good and surprisingly bug free.
If he put in AI visuals as in generated textures then it's different, because that's way more visible and gets labeled as slop immediately. There's also the (accurate imo) perception that AI is taking artists jobs against their will but coders adopted it on their own and benefit from it, so using it for code is ethical from a labor rights POV.
Photopea creator weighs in on Photosuite project
https://news.ycombinator.com/item?id=49972730
Sorry GitHub, that's not for you to determine, as you are not a US judge. They should never have replied like this IMO and this behavior opens them up to liability for not properly handling DMCA procedures.
Proper DMCA 512(h) notices (assuming OP's was proper) require the host (github) to remove or disable the content first without even attempting to verify the claims.
Then the repo owner has a chance to challenge the notice. If they choose to do, they're basically required to publicly doxx themselves first, by nature of just going through the motions of the judicial court system.
If there was no challenge after a set period of time, then the content stays down.
If there was a challenge, it stays down until a court decides what happens next.
two sides to the coin, we'll hear about how some evil corporation used their influence to have a legitimate project DMCA'd and HN will have the opposite reaction on that day
something like "jury duty" from the community seems an interesting idea for a middle path, if we want better systems, we'll all need to contribute a little to making it so
Meanwhile AI refuses to touch photos that contain anything that remotely looks like Mickey Mouse.
Shit was never on the Common Folk's side.
Use a trademark.
Something else is needed. If the code is basically open, then there is no technical protection. Remove tens of those repos - hundreds might appear.
Second, the trademark will help you against the masqueraders, those copying your tool and the Photopea brandmark. That will help with customers complaining about some other modified product. It will not help in case you find someone copying your codebase and putting it out in the open under a different name. For that, you'll need a copyright.
Doing both of these might be expensive but gives you complete legal standing. Companies will have no choice but to take down the copies.
My reply is that you now own a customer list, brandname and trademark, and that is about it.
I would imagine they all converge on common features and core implementation foundation
Because if the javascript source matches the source in the repo, then they copied it
This day in age, we need to verify ourselves
Can you show us an example? How did you verify?
I wanted to discuss the behaviour of Github without giving these "projects" even more attention.
I would think a github link would be easy to provide, sus that it hasn't been
If you want to make proprietary software that's cool, but client-side JavaScript was a terrible choice. The cat is out of the bag.
There's a reason software for which you purchase a license key generally doesn't give you source code outside rock-solid legal agreements.
Because what I see is essentially "they're storing stolen property" but the burden of proof is on the author to prove it was, indeed, stolen.
I imagine the bar for that is pretty high otherwise anyone could weaponize DMCA to target their competitors' repositories.
That's not what OP alleges - they are saying people are redistributing modified versions of OP's copyrighted code. DMCA is an appropriate measure in such a situation, but it's unclear why OP's DMCA takedown was rejected by GitHub. Without more detail, it's hard to comment further
https://reclaimthenet.org/kiwi-farms-dmca-subpoena-anonymous...
That is an extremely disingenuous and bad faith interpretation of what OP has said and I think you know it. You want to be edgy? Go comment on Reddit.
OP is rightly frustrated that their copyrighted work, that they’ve been working on full time for over a decade, is simply being ripped off by people and GitHub refuses to do anything about it.
Shifting blame to GitHub is absolutely idiotic.
Try removing locks from your doors in a high crime area (which is what the Internet is) then being indignant when the police can't stop all the criminals stealing your property.
I would not fork or re-release proprietary code. I would ask my LLM to write a very rigorous end to end test suite for your tool, delete all the code, then have a clean context LLM re-write the code to pass all the same tests. Then I could publish it under an open license.
Ads are a cancer, and it is a matter of weeks before someone does the above where you have zero recourse.
I suggest open sourcing the code properly without ads yourself before someone does it for you. If you do that someone might donate to you instead of paying for the tokens to clone your work.
Software is no longer a moat and DMCA means nothing anymore.
The real engineering work that will always be paid for is identifying problems and testing solutions to see what solves the problems.
The substrate in which we use to do that will change, but the job will endure.
Those that just do what they are told however, yeah they are SOL unfortunately.
Creative problem solving is the only skill that will matter anymore.
If security is a solved problem then anyone that wants to teach themselves enough can move to trying to solve disease, until disease is solved, then we all move on to building enough robots to mass produce enough food to solve world hunger and shelter... and once the needs of everyone on earth are solved at an ever cheaper price until it is free... then I guess we do whatever we want.
Capitalism is just a bootloader to get us there.
It's not. The economic landscape is also entirely different from before as well.
Rip me off if you can. :)
> take the Javascript code from my website, remove all ads from it
I would assume that this might be one of the reasons why people are modifying and repackaging your product. I would suggest to remove that incentive. So that the people will have no reason to repackage your product because it has annoying features. And so that they could use it directly and be happy about it.
I think that the differentiating factor must be something else than the software product feature. Because that can easily be copied or recreated.
It can be e.g. the customer support where customers will be listened to and will have their suggestions and requests implemented as features.
No one implied that the author should offer their product for free. I merely suggested that they need to focus on other aspect of their product rather than the mechanical software parts because they can no longer be the differentiating factor. Precisely because they could easily be recreated or copied.
Wonder how many even built a popular free product supported by ads?
It's quite difficult and you need to provide even more value than a paid product (if that makes sense) for users to come back constantly.
There is nothing new now with people copying software. It's just that much MORE of the masses have access to this now than before.
And thus thieves multiply exponentially.