Terms of Service
Draft. Fields in brackets are placeholders; a lawyer reviews this before the first paying customer.
These terms are a contract between [company legal name], [CNPJ], [address] ("Kuuhaku", "we") and the organisation that creates an account ("you", the "Customer"). By creating an account or using the service you accept them. If you accept on behalf of a company, you confirm you are allowed to.
Contents
1. The service
Kuuhaku reads the source repositories you point it at and produces a map of how they connect: routes, calls between services, queues, models, dependencies and the people behind the commits. The result is kept as a website your team uses. The scanner runs on our servers with a read-only key you add to your code host, or on your own machines through the command-line tool, which sends us only the resulting graph.
We describe what the scanner reads and does not read on the security page. That page is part of these terms.
2. Accounts and teams
- An account belongs to a person; an organisation ("team") belongs to its owners. Owners manage billing and members; the roles and what each may do are listed in the product.
- You keep your credentials secret and tell us at security@kuuhaku.dev if you think they were exposed. Actions taken with your credentials count as yours until you tell us.
- You give the scanner access only to repositories you are allowed to share with a processor. Adding a key to a repository you do not control is a breach of these terms.
3. Acceptable use
You may not use the service to break the law, to scan code you have no right to, to probe or overload our systems, to resell the service as your own, or to build a competing product from it. We may suspend an account that does, after telling you unless the law or the safety of other customers forbids it.
4. Your data
- Yours stays yours. Your repositories, the graphs we build from them, the decisions your team records and the text you write in Kuuhaku are your data. You grant us the license needed to process them for the sole purpose of providing the service.
- What we keep. The graph (route paths, names of services, models, queues, hosts and environment keys, dependency names and versions, commit counts and author names, and three-line code excerpts around the items left for review), the decisions and text your team enters, and account data. We do not keep your source code beyond those excerpts: a clone made for a scan is deleted when the scan ends. We never store the values of environment variables or credentials found in code.
- Where. Hosting location and the processors we use are listed in the privacy policy.
- Export and deletion. You can export your graph at any time and delete a workspace or the whole organisation from the product. Deletion removes imports, declarations and keys within 30 days, except where the law requires us to keep billing records.
- Aggregate statistics that cannot identify you or your code (for example, how many repositories the average customer connects) may be used to improve the service.
5. Our software
The service, the scanner, the website and their documentation are ours or our licensors'. The command-line tool is provided under its own license file. You may not copy, modify or reverse engineer the service beyond what that license or the law allows.
6. Plans, trial and payment
- Plans, limits and prices are shown on the pricing page and in your billing settings. Prices exclude taxes unless stated.
- Paid plans may start with a free trial of the length shown at checkout. At its end the plan is charged unless cancelled before.
- Subscriptions renew automatically each billing period until cancelled. Cancellation takes effect at the end of the period already paid; no partial refunds, except where the law grants a right of withdrawal.
- If a payment fails we tell you and retry; after [14] days the organisation drops to the free plan and data beyond the free limits is kept for 30 more days before deletion.
- We may change prices with at least 30 days' notice; the change applies at your next renewal.
- Payments are processed by Stripe; we do not see or store card numbers.
7. Availability and support
We aim at a monthly availability of [99.5%] for paid plans, measured on the API and the web application, excluding announced maintenance. Support is by email at support@kuuhaku.dev with a first answer within [two business days] for paid plans. Nothing here promises that a scan finds every connection in your code; the product shows how it knows what it knows, and what it could not read.
8. Confidentiality
We treat your graphs, decisions and account data as confidential: we access them only to provide the service, to fix a problem you reported, or when the law requires, and our staff access is logged and visible to you in the product. You treat non-public information about the service the same way.
9. Warranties and liability
The service is provided as is. To the extent the law allows, we disclaim implied warranties, and our total liability for any claim arising from the service is limited to the amount you paid us in the twelve months before the event. We are not liable for indirect damages, lost profits or data you could have backed up and did not. Nothing limits liability for fraud, wilful misconduct, or where the law does not allow a limit.
10. Termination
You may close your organisation at any time from the settings. We may terminate for a breach not cured within 15 days of notice, or immediately for serious misuse. On termination we delete your data as described in section 4 and, on request within 30 days, provide an export.
11. Changes to these terms
We may update these terms. Material changes are announced by email and in the product at least 30 days before they apply; continuing to use the service after that date is acceptance. The current version is always at this address, with its date.
12. Law and disputes
These terms are governed by the laws of Brazil. Disputes go to the courts of [city, state], Brazil, unless mandatory consumer law gives you another forum. Before any claim, both sides try to resolve the matter by email for 30 days.
Contact: [legal email].