# Early access terms of service

> The draft terms for using AgentGate during early access: the service, your account, your visitors' data, sub-processors, availability, fees, suspension and termination, liability, changes and contact.

> [!IMPORTANT]
> **Draft for review:** these terms are not in force until [LEGAL ENTITY NAME] publishes them; placeholders in [brackets] must be filled in. This draft was written without legal advice. [LEGAL ENTITY NAME] must review it, with a lawyer where needed, before it applies to anyone.

## 1. Who these terms are between

These terms are between **[LEGAL ENTITY NAME]**, [LEGAL ENTITY ADDRESS] ("we", "us") and the organisation or person that requests access to, or uses, AgentGate ("you"). If you use AgentGate for an organisation, you confirm that you may accept these terms for it.

You accept these terms when you request access, when you create or join an account, or when you use the service. The [Acceptable use policy](/docs/acceptable-use) and the [Privacy notice](/docs/privacy) are part of these terms.

## 2. The service

AgentGate is bot and agent protection for forms and APIs. It has four parts:

- the **browser check widget**, a script on your pages that runs an invisible check and hands your form a single-use token;
- **siteverify**, the `POST /v1/siteverify` call your server makes to validate that token;
- the **gateway**, which checks requests before your app sees them (nginx `auth_request` or Go / Node middleware);
- the **console**, where you add sites, copy keys, manage members and API tokens and read every decision.

We run AgentGate for you: it is a hosted service on our servers (section 6 says where). There is no fee during early access unless agreed in writing per site (section 8), and your visitors' data is processed by us for you (section 5).

AgentGate is in **early access**. Features may change, be renamed or be removed; the [changelog](/changelog) and the [roadmap](/roadmap) say what is available today. Every new site starts in [monitor mode](/docs/monitor-and-enforce), which blocks no one.

## 3. Your account

- **Access is by request.** We review every request and email an invitation. We may decline a request without giving a reason.
- **The owner is responsible for the account**: for every member and their role (owner, admin, member, read-only), for every site's backend secrets, for every API token, and for everything done with them. Keep secrets and tokens confidential, rotate them if you suspect they have leaked, and tell us at [SUPPORT EMAIL].
- **Two-factor authentication is recommended.** Every user can turn on an authenticator app (TOTP) with recovery codes in their profile, and an owner can require it for every member of the account.
- **Protect only what is yours.** Add only sites and APIs that you operate or are authorised to protect.
- **Limits apply.** By default an account has 5 sites, 3 live backend secrets per site, 10 members and 25 live API tokens (the [API reference](/docs/api-reference) has the details). Ask us if you need more.
- Keep your contact email current: it is where we send notices under these terms.

## 4. Acceptable use

Use AgentGate only as the [Acceptable use policy](/docs/acceptable-use) allows. In short: do not attack or probe systems with it, do not build evasion tooling from it, do not put it in front of abuse, do not break the law, do not deliberately exceed limits, do not resell it without our agreement, and do not use it to exclude people because of who they are or to remove the check's accessible alternatives.

## 5. Customer data and privacy

**Your visitors' data.** For the personal data of the people who use your protected pages, **you are the controller** and we process it for you, on your instructions as set out in these terms and in the console's settings. You must have a lawful basis for the processing, tell your visitors that AgentGate is in use (your privacy notice can link to [ours](/docs/privacy), which says exactly what the script collects), and answer their access and deletion requests. We help you find their records: they are pseudonymous, so we locate them by site and time.

**What we process.** How a visitor interacts (timings of key presses, not which keys; pointer movement; scrolling), browser environment facts, request metadata including the IP address, and the results of the proofs. The script never collects the contents of form fields, and the gateway check never sees request bodies. Decisions are stored under a pseudonymous identifier (a keyed hash scoped to one site), and full IP addresses are not written to application audit logs or traces.

**How long.** These are the retention periods the hosted service applies:

| Data | Kept for |
| --- | --- |
| Detailed decision events | **7 days** |
| Daily aggregate counts (the analytics) | **90 days** |
| Interaction feature vectors, only for sites that have opted in; never message text or raw event traces | 30 days by default; deleted when the site opts out |
| Account data (names, emails, company, site configuration, audit log) | For the life of the account, then **30 days** after deletion (section 9) |

**What we use it for.** To decide whether a request comes from a person, a declared agent or undeclared automation; to enforce rate limits; to investigate abuse; and, for sites that have opted in, to improve detection. Not for advertising, not for profiling people across sites, and we do not sell it.

If you need a data processing agreement, ask [SUPPORT EMAIL].

## 6. Sub-processors

These providers handle data for the hosted pilot:

| Provider | What for | What they handle |
| --- | --- | --- |
| Hetzner Online GmbH, Germany (Nuremberg, eu-central) | Runs the hosted service: one server, in one region today | Everything in section 5. The database and the key store live on that server; backups are encrypted before they leave it |
| Resend (`smtp.resend.com`) | Email delivery | Invitations, password resets, member invites and notices: the recipient's address, the message and when it was sent |

The public threat-intelligence feeds and agent key directories the server downloads are not sub-processors: no data about you or your visitors is sent to them. We tell account owners by email before we add a sub-processor.

## 7. Availability

**Early access means no SLA.** We run the hosted pilot on a best-effort basis: no uptime commitment, no service credits, and maintenance or upgrades may happen at short notice or none. We announce changes in the [changelog](/changelog).

**Decide what happens when AgentGate cannot be reached.** The widget alone enforces nothing; your server's siteverify call, or the gateway in front of your app, is the enforcement point. When AgentGate is down or unreachable:

- sites in **enforce** mode fail closed: the reference nginx configuration and the middleware adapters refuse the request with `503`;
- sites in **monitor** mode fail open: the request is allowed and recorded with reason `service_unavailable`, never silently.

Your integration decides which of these you want, and you are responsible for that choice. Read [When AgentGate is unreachable](/docs/siteverify#when-agentgate-is-unreachable) and [When AgentGate fails](/docs/monitor-and-enforce#when-agentgate-fails).

Backups and upgrades of the hosted service are our responsibility; there is nothing for you to run.

## 8. Fees

- There is **no fee during early access unless agreed in writing per site**. Where we agree a fee for a site, the written agreement says what it covers and when it is due.
- If we introduce fees for the hosted service, we will tell account owners by email at least [NOTICE PERIOD, e.g. 30 days] before they apply. You may end the pilot instead (section 9).
- AgentGate can answer an agent's request with a price (`402 Payment Required`, pay-per-crawl headers) and records accepted offers, but it does not collect or move money. Any payment between you and an agent operator is between the two of you.

## 9. Suspension and termination

**You can leave at any time.** An account owner can delete the account from the console or with `DELETE /v1/console/account`, once no site is in enforce mode (switch them to monitor first, so nothing keeps failing closed for a site that no longer exists). On deletion, sessions, API tokens and site credentials are revoked, the account's sites switch to monitor mode and stop issuing tokens, and the data is kept for **30 days** and then purged. Within those 30 days we can restore the account if you ask. Copy anything you need before you delete.

**We may suspend an account** if it breaks the acceptable use policy, if it appears to be compromised, if an agreed fee is not paid, or if the law requires it. Suspension mirrors what the product does: sign-in, the console and the API are closed (`403 account_suspended`), while the account's **sites keep protecting**: the widget still issues tokens and siteverify and the gateway still answer, so your visitors are not affected. Contact [SUPPORT EMAIL] to resolve a suspension.

**We may end an account** with at least [NOTICE PERIOD, e.g. 30 days'] notice by email, or at once for a serious breach of these terms. The same 30-day retention then applies.

## 10. Intellectual property

- **Your data stays yours**: your site configuration, your visitors' data and anything that passes through the gateway. You give us the rights we need to process it to run the service for you, and nothing more.
- **The service stays ours**: the software, the models and rules, the documentation, the name and the logo. These terms give you the right to use the service; they do not license the software itself.
- Feedback you give us may be used without obligation to you.
- Detection improvements built from opted-in feature vectors (which never contain content) belong to us.

## 11. What we do not promise

The service is provided **as is** during early access. AgentGate raises the cost of automation; it does not prove that anyone is human (see the [threat model](/docs/threat-model)). We do not promise that it stops every bot, that it never asks a person to complete the check, or that it fits any particular purpose. Detectors that have not been measured on real people ship in count mode. Test in monitor mode before you enforce. To the extent the law allows, we exclude every warranty that is not written here.

## 12. Liability

To the extent the law allows:

- neither of us is liable to the other for indirect or consequential loss, lost profits, lost data or lost business;
- our total liability under these terms is capped at **[LIABILITY CAP AMOUNT]** or, if greater, the fees you paid us in the 12 months before the claim;
- you are responsible for claims that arise from your sites, your content, or your breach of the acceptable use policy.

Nothing in these terms excludes liability that cannot be excluded by law, such as liability for fraud or for death or personal injury caused by negligence.

## 13. Changes to these terms

We may change these terms. We will email account owners at least [NOTICE PERIOD, e.g. 14 days] before a change takes effect and update the date at the top of this page. If you keep using the service after that date, the new terms apply; if you do not agree with them, delete your account before then.

## 14. Governing law

These terms are governed by the law of **[GOVERNING LAW / JURISDICTION]**, and its courts have jurisdiction over any dispute. Please write to [SUPPORT EMAIL] first: we would rather fix a problem than argue about it.

## 15. Contact

- Questions about these terms, your account or a data processing agreement: [SUPPORT EMAIL].
- Abuse of the service: [ABUSE EMAIL] (see [Reporting abuse](/docs/acceptable-use#4-reporting-abuse)).
- Security issues: `/.well-known/security.txt` and the [security testing brief](/hack).
- Post: [LEGAL ENTITY NAME], [LEGAL ENTITY ADDRESS].
