Last updated: Aug 24, 2026 · Effective: Sep 23, 2026

Terms of Use

These terms govern the Clusy platform: your account, the AI agent, the cloud sandboxes your code runs in, paid plans, and anything you publish. Please read sections 8 to 10 in particular. They explain that the agent executes code on your behalf, that your content is sent to third party AI providers in several countries, and what that means for you.

1.Who we are and how to reach us

Clusy is operated by Clusy Inc., a corporation incorporated in the State of Delaware, United States, with its registered address at 2093 Philadelphia Pike, Suite #3740, Claymont, DE 19703, United States. In these Terms, “Clusy”, “we”, “us” and “our” mean Clusy Inc.

General and account support
support@clusy.io
Legal notices and these Terms
legal@clusy.io
Privacy and data protection
privacy@clusy.io
Security and vulnerability reports
security@clusy.io, and our security page

Notices to you may be sent to the email address on your account or shown inside the product. Notices to us must be sent to legal@clusy.io and are effective when we acknowledge receipt.

2.These Terms and how the agreement is formed

These Terms of Use (the “Terms”) are a binding agreement between you and Clusy governing your access to and use of the Services. They replace all previous versions, including the version dated June 28, 2026, which described an invite only waitlist and pilot programme rather than the paid product Clusy operates today.

You enter into this agreement when you create an account, or when you continue to use the Services after these Terms take effect. You create an account by choosing a sign in method and then either entering the six digit code we email you, or authenticating with Google or GitHub. We may ask you to complete a bot check. The sign in screen tells you, before you continue, that continuing means you accept these Terms and our Privacy Policy. You can correct input errors before submitting at each step. This agreement is concluded in English, and we make it available on this page in a form you can save and print.

If you enter into these Terms on behalf of an organisation, you represent that you are authorised to bind that organisation, and “you” means that organisation. If you are using Clusy as an individual, that representation does not apply to you.

If you are a consumer, section 30 sets out terms that apply to you and that prevail over anything else in these Terms that conflicts with them. Nothing in these Terms limits rights you have under mandatory law that cannot be limited by agreement.

3.Definitions

Services
The clusy.io website, documentation and blog; the Clusy web application and accounts; projects, notebooks and branches; the AI agent and the code it writes; execution of code in cloud sandboxes, including GPU sandboxes and sandboxes with internet access; publishing, share links and the Clusy Hub; connected third party integrations; the programmatic interfaces the application uses and any Clusy API key you are issued; free, subscription, usage based and credit funded offerings; the meeting booking flow at clusy.io/meet; and support and related communications.
Agent
The AI system in the Services that reads your project context, generates text and code, calls tools, and executes code in a Sandbox on your behalf.
Sandbox
The cloud compute environment in which your code and the Agent’s code run. Sandboxes are operated for us by third party providers and are described in section 10.
Input
Everything submitted to the Agent or the Services by you or on your behalf. This expressly includes material the Agent retrieves rather than material you type: files it reads, datasets it downloads, web pages it fetches, tool results, terminal output, and the contents of repositories and data warehouses you connect.
Output
Content the Agent generates in response to Input, including text, code, analyses and files.
Customer Content
Input and Output together, plus your notebooks, cells, uploaded files, chat history and Sandbox filesystem contents.
Published Content
Customer Content you choose to publish through a share link, the Hub, or an export to a connected third party service.
Connected Account
A third party account or service you link to Clusy, such as GitHub, Hugging Face, Kaggle, Databricks, Snowflake or a Model Context Protocol (MCP) server.
BYOK Credentials
An API key for a supported model provider, currently Anthropic and OpenAI, that you supply so that model usage runs on your own account with that provider.
Paired Machine
A computer you pair with Clusy so that a turn runs on the Claude Code or Codex CLI installed there, under your own subscription with that provider.
Model Provider
A third party that operates or hosts the AI models the Services use, listed in our Privacy Policy.
Consumer
An individual using the Services wholly or mainly outside their trade, business, craft or profession.

4.Eligibility and your account

You must be at least 18 years old to use the Services. The Services give you an internet connected Linux environment driven by an autonomous agent that runs code without asking you to approve each action, so we do not make them available to minors. This applies to the free plan as well as to paid plans. We do not knowingly permit anyone under 18 to hold an account. If you believe an account belongs to someone under 18, contact support@clusy.io and we will investigate and close it.

You are responsible for everything that happens under your account, and for keeping your access secure, however your access is established. That includes your email inbox, your Google or GitHub identity if you sign in with one, any Clusy API key you create, and any device you pair. Tell us at security@clusy.io as soon as you suspect unauthorised access.

Accounts are for one person. You can give other people access to a project you own, and section 10 explains what they then share with you, but you may not share, sell, rent or transfer the account itself or any API key. Do not create multiple accounts to work around plan allowances, free tier limits, promotional pricing or an enforcement decision. Doing so is a breach of these Terms.

You agree to give us accurate account and billing information and to keep it up to date.

5.What the Services are

Clusy is an agent native notebook for data science and machine learning research. You create projects and notebooks, write or generate code, and run that code in a cloud Sandbox. The Agent can read your project, write and edit cells, install packages, read and write files, run terminal commands, browse the internet from the Sandbox, and act on your Connected Accounts within the permissions you grant.

Plans differ in the models you can reach, the usage allowance included, Sandbox memory and concurrency, GPU access, saved kernel state storage, and how long a paused Sandbox is kept before it is released. The current plans and prices, and the plan limits on storage, memory, GPUs and concurrent Sandboxes, are on our pricing page, which forms part of these Terms. Other operational limits, including maximum execution time, Sandbox lifetime and the hourly ceiling on model calls, are enforced in the product and are described in our documentation. We describe how billing works in sections 6 and 7 rather than repeating the numbers here, so that the two never disagree.

Availability. We do not offer a service level agreement or an uptime commitment on any plan. We aim to keep the Services available and publish incidents at status.clusy.io, but the Services may be unavailable during maintenance, during provider outages outside our control, and during deployments. Some deployments interrupt work that is in progress.

Where we label a feature preview, beta or experimental, it is provided for evaluation, may change or be withdrawn without notice, and should not be relied on for work you cannot afford to lose. We may also change or withdraw an unlabelled feature under section 28. Your mandatory statutory rights still apply either way.

6.Plans, fees, usage and credits

Plans and prices

Plans are billed monthly in US dollars through Stripe. Current prices are on the pricing page. We do not currently offer annual plans or free trials. The amount shown at checkout is the amount charged. Where we become required to collect sales tax, VAT or GST, we will show it before you pay.

Payments. Stripe Inc. is our payment processor. Card details are entered on Stripe hosted pages and are handled by Stripe. We never receive or store your full card number. Your use of Stripe is also subject to Stripe’s own terms.

Usage allowance

Each plan, including the free plan, includes a monthly usage allowance. Usage of models and metered compute draws down that allowance. Your remaining allowance is shown in the product as a percentage. The allowance period is a rolling 30 day cycle anchored to the date you signed up, and it is re anchored when your plan changes or your subscription status changes. It is not a calendar month.

What happens when the allowance runs out depends on your plan:

  • On the free plan, all agent work stops until your next cycle begins. There is no unmetered floor on the free plan: the Auto model and the CPU Sandbox both draw down the free allowance, so once it is spent no new run will start.
  • On a paid plan, the Services keep working. Your account continues on the unmetered default model and a CPU Sandbox, which do not draw down the allowance, unless you have enabled pay as you go.

On a paid plan, a run that starts within your allowance is allowed to finish even if it exhausts the allowance part way through, and there is no per run spend cap other than the pay as you go cap described below. On the free plan a run is capped at your remaining allowance plus a small margin so it can finish the step it is on, and it stops when it reaches that ceiling.

Pay as you go

Pay as you go lets usage continue past your allowance on a paid plan. It is off by default and you must turn it on and set a monthly spend cap. We will not charge you above the cap that was in force at the time the usage happened. If you lower your cap during a cycle, usage you had already authorised under the higher cap is still billed, and the lower cap applies from then on. Overage is not charged in real time: it is totalled after your 30 day cycle closes and billed on a separate invoice, charged automatically to your payment method. An overage invoice that would come to less than fifty US cents is waived. Cycles are billed against the plan, setting and cap that applied at the time of each item of usage, and once a cycle has closed and the short billing window has passed we do not go back and bill it.

Credits

We may grant credits to your account, for example as a promotion, a goodwill gesture or a sponsorship. Credits are granted by us and cannot be purchased. They have no cash value, are not refundable or transferable, and are applied automatically. We will tell you at the time if a credit expires.

Storage and other limits

Each plan includes an amount of saved kernel state storage. It is a fixed limit rather than a metered charge: we do not charge a per gigabyte fee and we do not bill you for going over it. If you reach the limit we may stop you creating new saved state until you free some up. Plans also carry limits on Sandbox memory, on how many Sandboxes you can run at once, and on how many model calls you can make per hour. Model usage under BYOK Credentials or through a paired local machine is billed to you by that provider and is not metered by us. Sandbox usage is still ours: on a paid plan a GPU Sandbox draws down your allowance and a CPU Sandbox does not, and on the free plan all Sandbox usage draws down the allowance.

Failed payments

If a payment fails, we do not cut off your access immediately. Your subscription is marked past due and your plan continues while Stripe retries the payment over roughly three weeks. If the payment ultimately fails, your subscription ends and your account moves to the free plan. We do not delete your work because a payment failed.

If you think a charge is wrong, please contact support@clusy.io first. We would rather fix it than have it go to a card dispute. We may suspend paid features while a disputed balance is outstanding, and we may close accounts used for repeated fraudulent disputes. Nothing here affects your right to dispute a charge with your card issuer or your statutory rights.

7.Auto renewal, plan changes, cancellation and refunds

Your subscription renews automatically. A paid plan is a monthly recurring subscription. It renews once a month on your billing date at the then current price for your plan, and it keeps renewing until you cancel it. You can cancel at any time in Settings, then Billing, where your renewal date is shown. Your billing date and your 30 day usage allowance cycle are set separately and will usually fall on different days.

Changing plans

  • Upgrades take effect immediately and are prorated. Stripe charges the prorated difference for the rest of the current period straight away.
  • Downgrades take effect at the end of your current billing period. Nothing is due at the time you downgrade, you keep your current plan until the period ends, and downgrades are not prorated or refunded.

Cancelling

You can cancel a subscription at any time online, from Settings, then Billing, in the same place you subscribed. We will show you what you will lose and ask you to confirm. Cancellation takes effect at the end of the billing period you have already paid for. You keep your plan and its features until then, the subscription does not renew, and your account moves to the free plan afterwards. We do not refund or prorate the remainder of a period you have already paid for. If you have trouble cancelling for any reason, email support@clusy.io and we will cancel it for you.

Cancelling a subscription does not delete your account or your work. To delete your account and data, see section 27.

Refunds

Except where these Terms say otherwise or the law requires otherwise, fees are non refundable and we do not prorate partial periods. We may issue a refund or a credit at our discretion, for example where a fault on our side made the Services unusable. This does not affect your statutory rights, including the consumer rights described in section 30.

Price changes

We may change our prices. If we increase the price of a plan you are on, we will tell you by email at least 30 days before it applies to you, and the new price will apply from your next renewal after that notice. You can cancel before it takes effect. Price changes are never applied retroactively.

8.The AI agent, and what it can and cannot do

You are working with an AI system, and it runs code by itself. The Agent reads your prompts, chat history, notebook contents and connected data, generates code, and then executes that code in a cloud Sandbox without asking you to approve each action.

You authorise the Agent to act for you

When you use the Agent, you authorise it to create, edit and delete cells and files, install software, run terminal commands, make network requests from the Sandbox, and use your Connected Accounts within the permissions you granted. Actions the Agent takes at your direction are treated as your actions under these Terms, including under the Acceptable Use section. You are responsible for what you ask it to do and for what it does in your project as a result.

Controls you have

You can stop a run in progress, steer it while it is running, and use plan mode, which has the Agent propose a plan for you to review before it creates, edits, deletes or runs notebook cells. Plan mode does not stop the Agent from reading your project or from searching and fetching material while it plans. Outside plan mode, the Agent does not ask you to approve most of what it does. A few actions do pause for approval, including sending a project file to our document parsing provider, and any tool on a connected MCP server, which requires your approval per tool before the Agent may call it. We describe these controls as they are: they let you interrupt and direct the Agent, and they do not guarantee that it will never take an action you did not want.

Output can be wrong

Output is generated by statistical models. It can be inaccurate, incomplete, out of date, biased, or entirely fabricated, including citations, statistics, dataset descriptions, API signatures and code that looks correct and is not. Treat Output as a draft to verify, not as a source of truth. You are responsible for reviewing and testing anything you rely on or ship.

Not professional advice, and not for high risk use

The Services are general purpose research tooling. They do not provide medical, clinical, diagnostic, legal, financial, or safety engineering advice. Do not use them as a medical device or for clinical decision making, and do not use them in circumstances where an error could lead to death, personal injury, or severe environmental or property damage. We have not designed, validated or documented the Services for those uses. If you deploy the Services into a regulated or safety critical setting, you do so as the party responsible for that system.

Prompt injection

The Agent reads content from your files, datasets, connected systems, MCP servers and the public internet. That content can contain instructions designed to manipulate the Agent into acting against your interests, for example exfiltrating data or running unwanted commands. We design against this and we cannot prevent it. Do not give the Agent access to credentials, repositories or systems whose misuse you could not tolerate.

Destructive and costly actions

The Agent can overwrite and delete files, environments and repository contents, and some of that is irreversible. Keep your own backups of anything you cannot lose. The Agent can also start work that costs money, including GPU compute, metered model usage, and charges on your own Connected Accounts and BYOK provider accounts. Those charges are yours. Pay as you go is off by default and capped, as described in section 6, and you can stop a run at any time. Note that stopping a run does not shut down your Sandbox: Sandbox compute is metered on the Sandbox’s running time and continues until it is paused or reclaimed, so close a GPU Sandbox you are finished with rather than only stopping the run.

Marking

The Agent identifies itself as an AI system in chat, and its messages are shown as the Agent’s rather than yours. We record whether a notebook cell was written by you or by the Agent. Where we display or export an indication that content was AI generated, do not remove, alter or falsify it, and do not present Output as human authored where that would mislead someone.

9.Model providers, where your content goes, and BYOK

Your content is sent to third party AI companies to produce a response. When you use the Agent, we transmit your prompt, your chat history, notebook context including cell code and text, excerpts of files the Agent reads, tool results, execution output and error traces, images where your selected model supports them, and profile and connection details including your display name and your IP address, to a Model Provider.

For a chat turn, the model you select normally determines which company receives your content. Two things qualify that. Some product features, including titles and tags, inline code completion and project memory, use providers we choose regardless of your selection. And if the provider for your selected model fails part way through a turn, we retry that turn on a different provider so your work is not lost.

Some Model Providers are outside the United States, including in mainland China and Singapore. We name every Model Provider and the models routed to it, and, where we can determine it, the country or region in which it processes content, in the AI and model providers section of our Privacy Policy. Read it before putting sensitive material into the Services.

Training

Because a single sweeping statement would not be true across every route, we state our position in parts:

  • Clusy does not train or fine tune models on your Customer Content. We operate no training, fine tuning or distillation pipeline that draws on customer notebooks, prompts, chat or outputs, and our evaluation suites run on synthetic and public benchmark data rather than customer data.
  • What each Model Provider may do with what we send is governed by our contract with that provider, and it is not uniform. We do not send a no training or zero retention instruction to every provider on every request, and we do not make a single promise on behalf of companies we do not control. If this matters to your work, use BYOK with a provider whose terms you control, or ask us at privacy@clusy.io about a specific model.
  • Content you publish is different. Published Content is world readable, and we allow AI crawlers to index our public pages, so published notebooks may be collected and used by third parties for model training. See section 13.
  • Human review is described in the Privacy Policy, including the limited circumstances in which our staff can access account data or content.

Changes to the model roster

We add, update, replace and retire models regularly, because providers deprecate them, change their terms, or because a better model becomes available. We may do so without notice. If we remove a model that your plan specifically offered and the change materially reduces what you are paying for, we will give you advance notice and you may cancel and receive a prorated refund of the unused part of the period.

Bring your own key

If you supply BYOK Credentials, requests run against your own account with that provider, under your own agreement with them. That provider’s retention, human review and training practices apply, and our commitments in this section do not extend to them. We use your key only to run your own requests. We check it with the provider when you add it and reject it if the provider says it is invalid; if the provider cannot be reached at that moment we store it and it will fail on first use instead. You can remove it at any time, which deletes the stored key immediately, and a working copy held in memory by the service that runs your turns clears within about a day. You remain responsible for what that provider charges you.

Your use of the Services is also subject to the acceptable use policies of the Model Providers whose models you use. We may act on those policies, and a provider may require us to restrict or suspend an account.

10.Sandboxes and code execution

Code runs in a Sandbox operated for us by third party providers, not on your own machine and not on hardware we own. CPU sandboxes run on E2B and GPU sandboxes run on Modal. Your code, notebook files, uploaded data and workspace contents are sent into those providers’ infrastructure to run.

  • Sandboxes are not permanent. A CPU Sandbox that goes idle is normally paused rather than destroyed: the provider keeps a suspended copy of its memory and filesystem so you can resume where you left off. A Sandbox that is destroyed loses everything inside it.
  • Durability comes from copying your work out, and that happens at session boundaries, not after every cell you run. We copy workspace files, saved kernel state and the package environment to storage when a project is paused, when you publish a share and when the runtime changes. Work done after the last copy can be lost if a Sandbox is destroyed unexpectedly, so keep your own backups of anything critical.
  • A single execution started by the Agent is capped at six hours of wall clock time. A cell you run yourself is bounded instead by the life of the Sandbox.
  • One Sandbox serves a project, not a person. Everyone with edit access to a project shares the same Sandbox and the same filesystem.
  • Sandboxes have broad internet access. Your code runs as an unprivileged account that owns the Sandbox filesystem, so you can install arbitrary packages, but you do not have root inside the Sandbox.

Monitoring, and your consent to it

You consent to us monitoring, logging and inspecting activity in the Services for security and policy purposes. Your chat messages and the inputs to tools the Agent runs are checked by an automated rule based detector, and account and execution activity generates security signals. That check runs alongside your work rather than gating it: it does not block, cancel or alter what you are doing. Section 17 explains what we do with the results, and the Privacy Policy explains what is recorded.

Your responsibility for your Sandbox

Sandboxes reach the public internet, and we barely restrict that. On CPU Sandboxes we block inbound public traffic and deny outbound connections to a small fixed list, covering private and cloud metadata address ranges and a couple of addresses recovered from a past abuse incident. Everything else on the internet remains reachable, and GPU Sandboxes carry no outbound restriction at all. You are therefore responsible for all network traffic originating from your Sandbox, including traffic that third parties see as coming from Clusy or from our providers’ infrastructure. Do not place irreplaceable data or production credentials in a Sandbox.

11.Your content, and the permission you give us

You keep ownership of your Customer Content. We claim no ownership of your notebooks, code, data or results.

To run the Services, you grant us a non exclusive, worldwide, royalty free licence to host, store, copy, transmit, process, execute and display your Customer Content, and to sublicense those rights to the infrastructure, storage, Sandbox, model, tooling, communication and monitoring providers we use to deliver, secure and support the Services, including the third party services the Agent calls at your direction. The licence also covers recording and reviewing your content and activity by automated means for security and policy compliance, as described in sections 10 and 17. For Published Content, the licence additionally covers publicly displaying it and letting others view, download and fork it, as described in section 13.

This licence exists so we can operate the Services and it ends when you delete the content or your account, except that copies others already made of Published Content, and routine backup and security records, survive for the periods described in the Privacy Policy. This licence does not permit us to train models on your content.

What you promise about your content

You represent and warrant that, for all Customer Content you submit:

  • you have all rights, licences, consents and permissions needed for it to be submitted, stored, executed and transmitted to the Model Providers and Sandbox providers described in these Terms;
  • it does not infringe anyone’s intellectual property, privacy or other rights, and does not breach any law, licence, contract or duty of confidentiality; and
  • you comply with the licence terms of any dataset, model weights or third party code you use in the Services.

Data you must not put into Clusy

Unless we have signed a separate written agreement covering it, do not upload or generate in the Services:

  • special category personal data under the GDPR, including health, biometric, genetic, racial or ethnic origin, political, religious, trade union or sexual orientation data;
  • protected health information subject to HIPAA. We do not sign business associate agreements;
  • payment card numbers or other cardholder data;
  • government issued identification numbers or financial account credentials of other people;
  • technical data controlled under ITAR, or technology controlled under the Export Administration Regulations beyond EAR99; or
  • classified or export restricted material.

Personal data about other people

If you put personal data about other people into the Services, you are the controller of that data and we process it for you. You are responsible for having a lawful basis, for giving those people the notices they are entitled to, and for meeting any additional conditions that apply to the categories of data involved. If you need a data processing agreement, email privacy@clusy.io.

12.Output

As between you and Clusy, we assign to you all right, title and interest we may have in the Output generated for you, to the extent permitted by law. You are responsible for the Output you use.

  • Output may not be protectable. Material generated by an AI system without sufficient human creative contribution may not attract copyright. We make no representation that Output is protectable, and you are responsible for identifying AI generated portions in any registration or filing.
  • Output is not unique. Other users may receive the same or similar Output from the same or similar prompts. Nothing here stops us or anyone else generating or using similar material.
  • We do not warrant that Output is non infringing. Generated code can reproduce material from training data, including code under copyleft or attribution licences. If you ship agent written code in a proprietary product, review it. We do not provide an intellectual property indemnity for Output.

13.Publishing, share links and the Hub

You can publish a notebook from Clusy itself in two ways, and you should understand what each one does before you use it. You can also export or publish to a connected third party service such as GitHub, Hugging Face or Kaggle, which is covered in section 14.

  • An unlisted share link creates a snapshot at a secret URL. Anyone who has the link can open it without logging in, and can download it as a notebook file. It is not listed anywhere, and the short link we give you asks search engines not to index it, but the viewer page it opens carries no such request and the link is the only protection. Treat it as public.
  • A Hub listing publishes the notebook to our public gallery. It is world readable, searchable within the Hub, and submitted to search engines. Our public pages also permit AI crawlers, including those that collect data for model training, so a Hub listing may be ingested by third party AI systems.

A share is a frozen snapshot at the moment you create it. It contains your cells, their code and text, and, if you leave outputs on, the execution results including any images and tables. It does not include your chat history with the Agent. It does include the public parts of your profile, which are your display name and avatar, so viewers can see who published it.

Forking. If you allow forking, any signed in user can copy your published notebook into their own project. A fork is an independent copy that belongs to them.

Unpublishing is not retroactive. Revoking a share stops new access immediately and permanently: the link stops working and cannot be reactivated. It does not reach copies that already exist. Forks other people have made stay in their projects, downloaded files stay downloaded, and search engine or third party caches may persist for a time we do not control.

You are responsible for what you publish, including any personal data or third party material in it. Where you publish personal data about someone else, you are the controller of it. If you need something taken down, see section 18.

14.Connected accounts, MCP servers and paired devices

You can connect third party services, including GitHub, Hugging Face, Kaggle, Databricks and Snowflake, and you can register external MCP servers. When you do, you authorise us and the Agent to access those services on your behalf within the permissions you grant.

  • Grant the narrowest permissions that will do the job. Connecting a repository means we clone it server side, including private repositories. Connecting a data warehouse means the Agent can run queries against it with your credentials and bring the results into your notebook.
  • Publishing to a connected service sends what you select. Notebook publishes to Hugging Face and Kaggle include execution outputs embedded in the notebook file.
  • MCP servers you register are third party services we do not control. Tool calls send arguments to them and bring their responses back into your session. Each tool requires your approval before the Agent may call it. You are responsible for the servers you connect and for any credentials you configure on them.
  • Disconnecting an integration removes the stored credential from Clusy. For most integrations that is all it does, and the credential stays valid at the provider until you revoke it there, so revoke it there too if that matters to you. GitHub is the exception: we also ask GitHub to invalidate the token.

How we store these credentials, and which are encrypted, is described in the Privacy Policy.

15.Acceptable use

These rules apply to everything you do in the Services, and to everything the Agent does at your direction. We run compute with internet access, so this section is specific rather than generic.

Do not use the Services to

  • break the law, or infringe anyone’s intellectual property, privacy, publicity or other rights;
  • mine cryptocurrency or run other work whose main purpose is to consume compute for value transfer;
  • operate a proxy, VPN, tunnel or exit node, or otherwise relay third party network traffic through a Sandbox;
  • build, host or operate command and control infrastructure, malware, ransomware, botnets, credential stealers, phishing pages or fraud panels;
  • scan, probe, stress test or attack any network or system you are not authorised to test, or take part in denial of service activity;
  • send spam or bulk unsolicited messages, or harvest contact details for that purpose;
  • circumvent our billing, allowances, rate limits, plan gating or enforcement, including by creating multiple accounts or automating signups;
  • reverse engineer, decompile, or attempt to extract our source code, model weights, prompts or configuration, except where that restriction is unenforceable under mandatory law;
  • resell, sublicense or provide the Services to third parties as your own service, or use the Services to build a competing product by copying them;
  • generate or distribute material that sexually exploits or endangers children, incites violence or terrorism, promotes self harm, or harasses or defames a person;
  • generate content designed to deceive people about its origin, including impersonating a real person or organisation, or producing fabricated records, reviews or credentials;
  • attempt to identify individuals from data in a way they have not consented to, or infer sensitive characteristics about people for the purpose of targeting or discriminating against them; or
  • interfere with the Services, other users’ work, or the integrity of the platform, including by bypassing Sandbox isolation, escalating privileges outside your Sandbox, or accessing another account’s data.

Automated access

Use our APIs within their documented limits and with your own API key. Do not scrape the Services, and do not use automation to create accounts or consume allowances beyond what a person would.

16.Security research

We welcome good faith security research and we will not pursue legal action against you for it, provided you follow our disclosure process. Report findings to security@clusy.io and see our security page and security.txt.

Good faith means: test only against your own account and your own projects, do not access, modify or retain another person’s data, do not degrade the Services for others, do not exfiltrate data beyond the minimum needed to demonstrate a finding, and give us a reasonable opportunity to fix an issue before disclosing it. Testing outside those bounds is not covered by this section and is a breach of section 15.

17.Monitoring, suspension, termination and appeals

We use automated systems and human review to detect breaches of these Terms. Automated checks examine code before it runs, network activity from Sandboxes, and account and usage signals, and they produce alerts.

What we may do

If we reasonably believe you have breached these Terms, or to protect the Services, other users or third parties, we may:

  • stop a run in progress or restrict a Sandbox;
  • remove or disable access to specific content, including a published share;
  • restrict features, rate limit an account, or require additional verification;
  • suspend the account; or
  • terminate the account.

We aim to take the least restrictive action that addresses the problem, and to act proportionately. Where the law allows and it is safe to do so, we will give you notice before we act, and otherwise promptly afterwards. We may act without prior notice where there is a risk of harm to people, to the Services or to third parties, where we are legally required to, or where notice would defeat the purpose of the action.

What we will tell you

If we suspend or terminate your account, we will tell you the reason. We will not disclose the internal detail of our detection systems, because publishing it would let it be evaded, but you will get enough to understand the decision and to contest it. If you want to know whether an automated rule was involved in your case, ask in your appeal and we will tell you.

Appeals

You can appeal. A suspended account can reach the appeal form in the product, where you can put your case in your own words. A person, not an automated system, reviews appeals. We will consider your appeal and tell you the outcome. If we got it wrong, we will lift the suspension. Suspension is reversible and does not delete your work.

If we terminate your account for a serious breach, we may retain a record of the enforcement decision to stop the same person re registering. This is described in the Privacy Policy.

You can leave at any time

You can stop using the Services, cancel a subscription, or delete your account at any time. See sections 7 and 27. While an account is suspended those controls are not reachable, so email support@clusy.io to cancel billing or to ask us to delete the account, and we will do it for you.

19.Legal requests and law enforcement

We may access, preserve and disclose your information and Customer Content where we reasonably believe it is necessary to comply with a law, regulation, legal process or enforceable governmental request, to enforce these Terms including investigating potential breaches, to detect or address fraud or security issues, or to protect against harm to the rights, property or safety of Clusy, our users or the public.

Where we are legally permitted, and where doing so would not risk harm or obstruct an investigation, we will make reasonable efforts to notify you of a legal request for your data before we respond, so that you can seek to challenge it.

20.Export controls and sanctions

The Services are subject to United States export control and sanctions laws, and to those of other jurisdictions where relevant. You represent that you are not located in, ordinarily resident in, or organised under the laws of, a country or territory subject to comprehensive US sanctions, and that you are not on any restricted party list including the US Specially Designated Nationals list, the Entity List or the Denied Persons List, and that you are not owned or controlled by such a party.

You agree not to use the Services, or export, re export or transfer Output, in violation of those laws, and not to use the Services for prohibited end uses, including nuclear, chemical or biological weapons or missile technology. We may block access from a jurisdiction or terminate an account to comply with these laws.

21.Confidentiality and feedback

If we give you information that is marked confidential, or that a reasonable person would understand to be confidential, such as unreleased features or non public technical detail, please do not share it while it remains non public, and use it only in connection with the Services. This obligation lasts three years and does not apply to information that is or becomes public without your fault, that you already had, that you receive from someone else without a duty of confidence, or that you develop independently.

This does not stop you talking about your own experience of Clusy. Nothing in these Terms restricts you from publishing an honest review or opinion of the Services, from describing a problem you had with them, from reporting a security issue under section 16, or from making a disclosure protected by law.

If you send us suggestions or feedback about the Services, you allow us to use it without restriction or payment, and without any obligation to you. You keep everything you already owned, and this does not give us any rights in your Customer Content or in your own products.

22.Privacy and data protection

Our Privacy Policy explains what personal data we collect, why, who we share it with, where it goes and how long we keep it. It forms part of these Terms and it is where the detail lives, including the list of subprocessors and the position on every Model Provider.

Where we process personal data on your behalf as your processor, and you need a written data processing agreement, email privacy@clusy.io and we will put one in place.

23.Third party services

The Services depend on third parties, and they also let you reach third parties of your choosing. These are different things.

  • Providers we use to deliver the Services, such as our cloud, Sandbox, payment and Model Providers, act for us. We choose them, and we remain responsible to you for the Services as described in these Terms. They are named in the Privacy Policy.
  • Services you connect or reach yourself, such as Connected Accounts, MCP servers, packages you install, and websites the Agent visits at your direction, are outside our control. Your use of them is governed by their terms, not ours, and we are not responsible for their content, availability, security or practices.

24.Disclaimers

To the maximum extent permitted by law, the Services are provided “as is” and “as available”, and we disclaim all warranties, whether express, implied or statutory, including implied warranties of merchantability, fitness for a particular purpose, title, non infringement, and any warranty arising from course of dealing or usage of trade.

We do not warrant that the Services will be uninterrupted, secure, timely or error free, that defects will be corrected, that a Sandbox will be available when you want one, or that Output will be accurate, complete or suitable for your purpose.

If you are a consumer, this section applies only to the extent the law allows. Mandatory consumer guarantees and statutory rights, including rights relating to digital content and services that are not as described or not of satisfactory quality, are not excluded. See section 30.

25.Limitation of liability

To the fullest extent permitted by law, neither party will be liable for indirect, incidental, special, consequential, exemplary or punitive damages, or for lost profits, lost revenue, lost business or lost goodwill, arising out of or relating to these Terms or the Services, even if advised of the possibility.

To the fullest extent permitted by law, our total aggregate liability for all claims arising out of or relating to these Terms or the Services in any 12 month period will not exceed the greater of one hundred US dollars (US$100) and the total amount you paid us for the Services in the 12 months before the event giving rise to the claim.

These limits do not apply to death or personal injury caused by negligence, fraud or fraudulent misrepresentation, gross negligence or wilful misconduct, our obligations under section 26 where we are the indemnifying party, or any liability that cannot lawfully be limited or excluded. If you are a consumer, section 30 applies.

Given what the Services do, please note specifically: you are responsible for keeping your own backups, for reviewing Output before you rely on it, and for the charges that agent initiated work can generate. The allocation of risk in this section is a fundamental basis of the bargain between us and is reflected in our pricing.

26.Indemnification

If you are using the Services for business purposes, you agree to defend, indemnify and hold harmless Clusy and its officers, directors, employees and agents from any third party claim, and any resulting damages, liabilities, losses and reasonable legal costs, arising out of your Customer Content, your Published Content, your use of the Services, or your breach of these Terms or of applicable law.

We will notify you promptly of any such claim, give you control of the defence, and cooperate reasonably at your expense. You may not settle a claim in a way that imposes any obligation or admission on us without our consent.

If you are a consumer, this section does not apply to you. You remain responsible for your own acts and omissions under general law.

27.Term, termination, and what happens to your data

These Terms apply for as long as you use the Services or hold an account. You may stop at any time. You may delete your account in Settings, under Account.

Deleting your account deletes your projects, notebooks, cells, chat history, execution records and stored files, and cancels any active subscription. Some records survive deletion, including billing and tax records we are required to keep, records of enforcement decisions, and support tickets. The Privacy Policy sets out exactly what is deleted, what is retained, and for how long. Deletion is not reversible, so export anything you want to keep first.

Published Content that other people have already forked or downloaded is not affected by deleting your account, as explained in section 13.

We may terminate this agreement and close your account on 30 days’ notice, or immediately for a serious breach of these Terms or where required by law. If we close your account without cause, we will refund the unused portion of any prepaid period.

Sections that by their nature should survive will survive, including sections 11 to 13 as they relate to content already published, 18, 20, 21, 24, 25, 26, 29 and 31.

28.Changes to these Terms and to the Services

We may change these Terms. If a change is material, we will give you at least 30 days’ notice by email to the address on your account, or through the product, before it takes effect, and we will say what changed. Changes apply from the effective date onwards and never retroactively.

We will not use these Terms to expand how we use your existing content without asking you separately. If we ever want to use Customer Content for a materially different purpose, including model training, we will ask for your separate, affirmative agreement first, and it will apply only going forward.

If you do not accept a change, you may cancel and stop using the Services before it takes effect. Continuing to use the Services after the effective date means you accept the change.

We also change the Services themselves, and we may add, modify or discontinue features. If we discontinue a feature that is material to a plan you are paying for, we will give you reasonable notice and you may cancel and receive a prorated refund for the unused part of the period.

29.Disputes, governing law and venue

Please contact us at legal@clusy.io first. Most disputes can be resolved quickly that way, and we will try in good faith to resolve any dispute informally within 60 days.

These Terms are governed by the laws of the State of Delaware, United States, excluding its conflict of law rules and the UN Convention on Contracts for the International Sale of Goods. The state and federal courts located in the State of Delaware have jurisdiction over disputes arising out of or relating to these Terms, and you consent to their personal jurisdiction.

If you are a consumer, the paragraph above does not take away your rights. You keep the protection of the mandatory laws of the country where you live, and you may bring proceedings in the courts of that country. Nothing in these Terms limits your right to bring a claim in your local courts, to complain to your local consumer authority, or to use any alternative dispute resolution scheme available to you. If you are in California, nothing here waives rights under California consumer statutes that cannot be waived.

Any claim must be brought within one year after it arose, except where a longer period is required by law, which includes claims by consumers.

30.Consumer terms

This section applies if you are a consumer, and it prevails over anything else in these Terms that conflicts with it.

  • Your statutory rights are not affected. Nothing in these Terms excludes or limits our liability for death or personal injury caused by our negligence, for fraud, or for anything else that cannot lawfully be limited. Nothing excludes your rights in respect of digital content or services that are not as described, not of satisfactory quality, or not fit for a purpose you told us about.
  • Right to cancel within 14 days (EEA and UK). If you live in the EEA or the UK, you have 14 days from entering into a subscription to cancel it for any reason. To exercise it, tell us at support@clusy.io in a clear statement, or use the model cancellation form. We will refund you within 14 days using the same payment method you used. If you asked us to start straight away and you then cancel, we may charge you a proportionate amount for what you used before you cancelled.
  • Liability. Our liability to you is limited to loss that is a foreseeable result of our breach. We are not liable for loss you suffer in the course of a trade or business.
  • Indemnity and confidentiality. Section 26 does not apply to you, and the confidentiality obligation in section 21 applies only to information we actually mark or identify as confidential.
  • Law and courts. As set out in section 29, you keep the mandatory protections and the courts of the country where you live.

31.General

  • Entire agreement. These Terms, the Privacy Policy and the pricing page are the entire agreement between us about the Services, and replace any earlier agreement or understanding about them. This does not limit liability for fraudulent misrepresentation.
  • Severability. If a provision is held unenforceable, it is modified to the minimum extent needed to make it enforceable, or severed, and the rest remains in effect.
  • No waiver. If we do not enforce a provision, that is not a waiver of it.
  • Assignment. You may not assign these Terms without our written consent. We may assign them to an affiliate or in connection with a merger, acquisition or sale of assets, on notice to you.
  • Force majeure. Neither party is liable for a failure to perform caused by events beyond its reasonable control, other than payment obligations.
  • No third party rights. No one other than you and Clusy has rights under these Terms.
  • Relationship. These Terms do not create a partnership, joint venture, employment or agency relationship.

Need something more formal?

If your organisation needs a master services agreement, a data processing agreement, a security review or a custom schedule, email legal@clusy.io with your requirements and procurement timeline. For privacy specific requests, including data processing agreements, use privacy@clusy.io.