1. Introduction and Acceptance
1.1 The Agreement
These Terms of Service (the "Terms") form a legally binding agreement between SmartVibe AI, a business established in Nashik, Maharashtra, India ("SmartVibe", "we", "us", "our"), and the individual or legal entity that accesses or uses the Services ("you", "your", "Customer"). If you are entering into these Terms on behalf of a company, organisation or other legal entity, you represent that you have the authority to bind that entity, and "you" refers to that entity.
The "Services" means the SmartVibe platform made available at smartvibe.dev and its subdomains, including the Browser IDE, Live Preview, AI code generation and agentic build features, project storage, the GitHub and Supabase integrations, the SmartVibe API, associated documentation, and any successor or additional services we make generally available under these Terms.
1.2 How you accept these Terms
You accept these Terms by (a) clicking or tapping any button or checkbox indicating acceptance, (b) creating an Account, (c) accessing or using any part of the Services, or (d) executing an Order Form or Enterprise Agreement that references these Terms. If you do not agree to these Terms, you must not access or use the Services.
1.3 Documents incorporated by reference
The following documents are incorporated into and form part of these Terms. By accepting these Terms you also accept each of them:
-
the Privacy Policy, describing how we process personal data;
-
the Acceptable Use Policy ("AUP"), describing conduct and content that is prohibited on the Services;
-
the Cookie Policy, describing our use of cookies and similar technologies;
-
the Data Processing Addendum ("DPA"), which applies where we process personal data as a processor or data processor on your behalf;
-
the Service Level Agreement ("SLA"), which applies to paid plans as specified in that document;
-
the DMCA and Copyright Policy, describing how to report claimed infringement; and
-
any Order Form, Enterprise Agreement, plan description or product documentation that expressly references these Terms.
1.4 Order of precedence
In the event of a conflict or inconsistency, the following order of precedence applies, with the earlier prevailing to the extent of the conflict: (1) a signed Enterprise Agreement or Order Form; (2) the DPA; (3) the SLA; (4) these Terms; (5) the AUP, Privacy Policy, Cookie Policy and DMCA Policy; (6) any other documentation. Notwithstanding the foregoing, the DPA prevails over all other documents in respect of the processing of personal data, and the AUP prevails in respect of prohibited conduct.
1.5 Changes to these Terms
We may modify these Terms from time to time. For changes that materially reduce your rights or materially increase your obligations, we will provide at least thirty (30) days' advance notice by email to the address associated with your Account and by posting a notice within the Services. Other changes take effect when posted. The "Effective Date" at the head of these Terms indicates when they were last revised, and we will maintain an archive of prior versions. Your continued use of the Services after the effective date of a change constitutes acceptance of the revised Terms. If you do not accept a change, you must stop using the Services and may terminate your subscription in accordance with Section 18, in which case we will refund any pre-paid fees covering the remainder of the then-current subscription term on a pro-rata basis, excluding consumed Credits.
For customers under an Enterprise Agreement, changes to these Terms do not apply during the then-current subscription term unless required by law, and will apply on renewal.
2. Definitions
In these Terms, capitalised terms have the meanings given below or where first defined.
| Term | Meaning |
| Account | The registered user or organisation account through which the Services are accessed, including all Workspaces and Projects associated with it. |
| Agentic Build | The feature by which the Services autonomously plan and execute multi-step development tasks — creating and editing files, installing dependencies, running commands in a Sandbox and applying changes to a Project — in response to your instructions. |
| AI Output | Any content produced by the Services in response to a Prompt, including Generated Code, explanations, file structures, configuration, schema definitions, test cases, commit messages and documentation. |
| Browser IDE | The in-browser development environment forming part of the Services, including the code editor, file tree, terminal emulator, package management interface and associated tooling. |
| Credits | The prepaid or plan-allocated units of account that are consumed when you use AI features, as further described in Section 4. |
| Customer Content | All data, code, text, files, prompts, database contents, images, configuration, credentials and other material that you or your Authorised Users upload to, create within, generate using, or transmit through the Services. AI Output constitutes Customer Content once delivered to you, subject to Section 7. |
| Documentation | The technical and user documentation for the Services that we make generally available at docs.smartvibe.dev or within the Services. |
| Enterprise Agreement | A separately executed written agreement between you and SmartVibe governing an Enterprise plan, including any Order Form, statement of work or addendum forming part of it. |
| Generated Code | Software source code, configuration files, schema, scripts and related build artefacts comprised within AI Output. |
| Integration | A connection between the Services and a third-party service, including the GitHub, Supabase, Google and payment processor integrations described in Section 8. |
| Live Preview | The feature that renders a running instance of a Project at a SmartVibe-provisioned preview URL so that it can be viewed and tested in a browser. |
| Model Provider | A third party that provides the foundation or reasoning models used to deliver AI features, as listed in the Privacy Policy sub-processor schedule. |
| Project | A discrete application, repository or codebase created or managed within the Services, together with its files, history, settings and associated resources. |
| Prompt | Any instruction, query, file, image, schema, error message, repository context or other input you submit to an AI feature of the Services. |
| Sandbox | The isolated, ephemeral compute environment in which a Project is built, executed and previewed. |
| Authorised User | An individual whom you permit to use the Services under your Account, including your employees, contractors and agents, and for whom a seat has been allocated where seats apply. |
| Workspace | A container within an Account that groups Projects, members, roles and billing settings. |
3. Eligibility, Accounts and Authorised Users
3.1 Age and capacity
The Services are intended solely for persons who are at least eighteen (18) years of age and who have the legal capacity to enter into a binding contract. The Services are not directed to children, we do not knowingly collect personal data from children, and we will terminate any Account we determine to be held by a person under 18. If you believe a child has provided personal data to us, please contact support@smartvibe.dev so that we may delete it.
3.2 Registration information
You must provide accurate, current and complete registration information and keep it up to date. You may register using an email address and password or through a supported identity provider such as Google (see Section 8.4). You must not register an Account using a false identity, an email address you are not authorised to use, or on behalf of a person or entity without authority.
3.3 Account security
You are responsible for safeguarding your credentials, API keys, personal access tokens and integration authorisations, and for all activity that occurs under your Account, whether or not authorised by you. You must (a) use a strong, unique password, (b) enable multi-factor authentication where offered, (c) not share credentials between individuals, and (d) notify us immediately at support@smartvibe.dev on becoming aware of any unauthorised access, credential compromise or suspicious activity. We may, but are not obliged to, require a password reset, revoke sessions or suspend an Account where we reasonably believe it has been compromised.
We are not liable for any loss arising from unauthorised use of your Account where that use results from your failure to comply with this Section 3.3.
3.4 Authorised Users and seats
Where your plan is licensed on a per-seat basis, each seat entitles one named individual to use the Services. Seats may be reassigned when an individual ceases to require access, but must not be shared, rotated between individuals to circumvent seat limits, or used concurrently by more than one person. You are responsible for (a) ensuring each Authorised User complies with these Terms and the AUP, (b) the acts and omissions of your Authorised Users as if they were your own, and (c) promptly deactivating access for individuals who leave your organisation.
3.5 Roles and administrative control
Workspace administrators may add and remove members, change roles, transfer Project ownership, access Projects within the Workspace, export or delete Workspace data, and configure security settings. If you access the Services using an email address belonging to a domain controlled by an organisation, that organisation may be permitted to claim the Account and assume administrative control over it, including access to Projects within it. You acknowledge this and, where relevant, should use a personal Account for personal Projects.
3.6 Service accounts and automation
You may create service accounts or machine credentials for automation, subject to the API terms in Section 9 and any plan limits. Automated access must be attributable to a specific Account and must not be used to evade rate limits, seat limits or Credit consumption.
4. Plans, Credits, Fees and Billing
4.1 Plans
We offer the Services under Free, Pro, Business and Enterprise plans. The features, quotas, Credit allocations, concurrency limits, storage limits, support levels and prices applicable to each plan are described on our pricing page and in the Documentation, and may differ between plans. We may introduce, modify, rename or discontinue plans; where a plan is discontinued, existing subscribers will be permitted to complete the then-current subscription term or migrate to a comparable plan.
The Free plan is provided without charge, without any service level commitment, with reduced quotas, and may be modified, limited or withdrawn at any time. Resources allocated to Free plan Accounts may be reclaimed after a period of inactivity notified to you in advance.
4.2 Credits
AI features consume Credits. The number of Credits consumed by a given operation depends on factors including the model selected, the size of the Prompt and context supplied, the length and complexity of the AI Output, the number of tool-use or agentic steps performed, and any retries. Credit consumption is metered by us and displayed in your Account. Our records of consumption are determinative absent manifest error.
-
Credits included with a subscription plan are allocated at the start of each billing period and, unless expressly stated otherwise for your plan, do not roll over to the next period.
-
Credits purchased separately as a top-up ("Top-up Credits") do not expire while your Account remains active and in good standing, and are consumed only after plan Credits for the period are exhausted.
-
Credits have no cash value, are not a stored-value or prepaid payment instrument, are not redeemable for money, and may not be sold, transferred, assigned or exchanged except between Workspaces within the same Account where we make that feature available.
-
Consumed Credits are non-refundable, including where the AI Output is unsatisfactory, incorrect, incomplete or not used by you, save where the Credits were consumed as a direct result of a defect in the Services that we acknowledge.
-
Where an operation fails as a result of an error attributable to us, we will use reasonable efforts to reverse the associated Credit consumption. You may raise a Credit adjustment request within fourteen (14) days of the relevant operation.
We may adjust the Credit cost of operations to reflect changes in Model Provider pricing or infrastructure costs. We will give at least thirty (30) days' notice of an increase in the Credit cost of an existing operation, and such changes will not affect Top-up Credits already purchased for a period of thirty days following the notice.
4.3 Fees, currency and taxes
You agree to pay all fees for the plan and any add-ons you select, in the currency presented at checkout. Fees are exclusive of taxes. You are responsible for all applicable taxes, duties and levies, including Goods and Services Tax (GST) in India, value added tax, sales tax and equivalent charges, other than taxes on our net income. Where we are required to collect such taxes, they will be added to the amount charged. If you are exempt from a tax or are required to withhold tax, you must provide valid documentation before invoicing; where withholding is required, you will gross up the payment so that we receive the full invoiced amount.
4.4 Subscription term, renewal and cancellation
Paid subscriptions are billed in advance on a monthly or annual basis, as selected. Subscriptions renew automatically for successive periods of the same length unless cancelled before the end of the then-current period. You may cancel at any time from your Account billing settings; cancellation takes effect at the end of the current billing period and you retain access until then. We do not provide refunds for partial periods except as set out in Section 4.7 or as required by law.
4.5 Upgrades, downgrades and proration
Upgrades take effect immediately and are charged pro-rata for the remainder of the current billing period, with the corresponding Credit allocation adjusted accordingly. Downgrades take effect at the start of the next billing period. On downgrade, features, quotas and Credit allocations reduce to those of the lower plan, and Projects or data exceeding the lower plan's limits may become read-only until you reduce usage. It is your responsibility to export data before a downgrade takes effect.
4.6 Payment processors, failed payments and suspension
Payments are processed by third-party payment processors, currently Stripe and Razorpay. We do not receive or store your full payment card number. Your use of a payment processor is subject to that processor's own terms and privacy policy, and you authorise us and the processor to charge your selected payment method on a recurring basis until cancelled.
If a payment fails, we will attempt to collect using the retry schedule of the relevant processor and will notify you. If payment remains outstanding seven (7) days after the due date, we may downgrade your Account to the Free plan or suspend access to paid features. If it remains outstanding thirty (30) days after the due date, we may suspend the Account, and after a further thirty (30) days may terminate it and delete Customer Content in accordance with Section 18.5. Amounts overdue by more than thirty days may bear interest at 1.5% per month or the maximum rate permitted by applicable law, whichever is lower, together with reasonable costs of collection.
4.7 Refund policy
You may request a refund of the fee for a subscription period by contacting support@smartvibe.dev within seven (7) days of the charge. Requests are reviewed individually and a refund will be granted where no Credits from that period have been consumed and the Services have not been substantially used. Where Credits have been partially consumed, we may at our discretion issue a partial refund proportionate to unconsumed Credits, or a Credit adjustment. Top-up Credit purchases are refundable within seven (7) days only to the extent unconsumed.
Refunds are not available for (a) consumed Credits, (b) periods already elapsed, (c) Accounts terminated for breach of these Terms or the AUP, or (d) dissatisfaction with AI Output where the Services performed as described. Approved refunds are issued to the original payment method within ten (10) business days of approval, subject to processor timelines. Nothing in this Section limits any non-excludable statutory right you may have, including under the Consumer Protection Act, 2019 (India) or, if you are a consumer in the European Economic Area or the United Kingdom, your statutory withdrawal rights.
4.8 Price changes
We may change our prices. We will give at least thirty (30) days' notice before a price change takes effect for your plan, and the new price will apply from your next renewal. If you do not accept the change, you may cancel before renewal.
4.9 Chargebacks
If you initiate a chargeback or payment dispute without first contacting us to seek resolution, we may suspend your Account pending resolution and may recover the disputed amount together with any processor fees. We ask that you contact support@smartvibe.dev first; most billing issues are resolved within two business days.
5. Browser IDE, Sandboxes and Live Preview
5.1 What we provide
The Browser IDE provides an editor, file system, terminal emulator, dependency management and build tooling that execute against a Sandbox provisioned by us. Live Preview renders your Project from that Sandbox at a preview URL so it can be viewed in a browser. These features are provided for development, prototyping, evaluation and testing purposes.
5.2 Sandboxes are ephemeral
Sandboxes are transient compute environments. They may be suspended, reset, migrated between hosts, or destroyed and recreated at any time, including after a period of inactivity, on a build error, on redeployment, during maintenance, or where resource limits are exceeded. Data written only to a Sandbox filesystem and not committed to a persisted Project, a connected repository or an external database may be irretrievably lost. We do not warrant the durability of Sandbox state and do not maintain backups of Sandbox filesystems.
Persisted Project files stored in our platform storage are subject to the backup arrangements described in Section 14 and the SLA. You remain responsible for maintaining your own copies of anything you cannot afford to lose, including by connecting a Git repository under Section 8.2.
5.3 Resource limits and fair use
Sandboxes are subject to limits on CPU, memory, disk, process count, execution duration, concurrent Sandboxes, network egress and build minutes, as described in the Documentation for your plan. We may throttle, queue, pause or terminate workloads that exceed those limits or that, in our reasonable judgement, degrade the Services for other customers. You must not use the Sandbox environment as general-purpose compute, and in particular must not:
-
run cryptocurrency mining, proof-of-work, distributed computing or similar workloads;
-
operate persistent servers, bots, relays, proxies, VPNs, tunnels or file-sharing endpoints;
-
run load generators, scanners or traffic against systems you do not own or are not authorised to test;
-
attempt to escape the Sandbox, access the host, other tenants' data, our internal metadata endpoints or our orchestration control plane;
-
use the Sandbox to circumvent geographic restrictions or to anonymise the origin of network traffic; or
-
store or process data unrelated to the development of a Project.
5.4 Live Preview URLs are not private and not production hosting
Unless you have expressly enabled an access control feature that we make available, preview URLs are unauthenticated and accessible to anyone who has the link. Preview URLs may be discoverable, may be indexed by third parties if linked publicly, and may be shared onward by recipients. Accordingly you must not place in a Live Preview, or in any Project intended to be previewed, any production credentials, personal data of real individuals, payment card data, health information, trade secrets or other confidential or regulated information.
Live Preview is not a production hosting service. It carries no uptime commitment, no capacity guarantee, no custom domain, no persistent IP address, no content delivery network guarantees and no protection against traffic surges. Preview URLs may change or be revoked. You must not (a) use Live Preview to serve a live application to end users or customers, (b) direct commercial traffic to a preview URL, (c) rely on a preview URL in any product, marketing material or filing, or (d) use Live Preview to distribute files or media at scale. Applications intended for production use must be exported and deployed to a hosting provider of your choosing.
5.5 Third-party packages and dependencies
The Browser IDE lets you install packages from third-party registries such as npm, PyPI and similar sources. Those packages are supplied by their respective publishers, not by us. We do not review, audit, vet or endorse them and we accept no responsibility for their content, security, licensing or behaviour, including where a package is malicious, abandoned, vulnerable, or subject to licence terms incompatible with your intended use. Installation and use of any package is at your own risk and is governed by that package's licence. You are responsible for dependency review, licence compliance and vulnerability management in your Projects.
5.6 Command execution
You may execute commands within a Sandbox, and the Agentic Build feature may do so on your instruction. You are responsible for all commands executed under your Account, including those proposed by an AI feature and accepted or auto-approved by you. Commands may make irreversible changes to Project files, connected repositories and connected databases. We strongly recommend reviewing proposed commands and destructive operations before approval, maintaining version control, and not granting write access to production systems. Where you enable automatic approval of agent actions, you do so at your own risk and accept responsibility for the resulting changes.
5.7 Beta and preview features
Features designated as alpha, beta, preview, experimental or "labs" are provided for evaluation only, may be incomplete or unstable, may change or be withdrawn without notice, are excluded from the SLA and from any support commitment, and are provided "as is" without any warranty. We may collect additional telemetry from beta features to improve them, as described in the Privacy Policy. Do not use beta features for anything important.
6. AI Services and AI Output
6.1 How AI features operate
AI features generate AI Output by submitting your Prompt, together with context we assemble (which may include Project files, file structure, dependency manifests, database schema, error output, prior messages in the session and retrieved documentation), to one or more foundation models operated by us or by a Model Provider. The models generate output probabilistically. They do not verify facts, do not execute or test code unless a tool step is invoked, and have no knowledge of your legal, regulatory, security or commercial requirements.
6.2 AI Output is non-deterministic and may be wrong
You acknowledge and agree that AI Output:
-
may be inaccurate, incomplete, insecure, inefficient, non-functional, outdated or misleading, and may contain logical errors, security vulnerabilities, race conditions, injection flaws, insecure defaults, hard-coded secrets, deprecated APIs or dependencies with known vulnerabilities;
-
may fabricate package names, API endpoints, function signatures, configuration options, citations, standards or documentation that do not exist;
-
is non-deterministic — the same Prompt may produce materially different output on different occasions, and we do not warrant reproducibility;
-
may not be unique: other users submitting similar Prompts may receive similar or identical output, and we make no representation that AI Output is original, novel or unencumbered;
-
may resemble or reproduce material from third-party sources, including code subject to open-source or proprietary licences, patents or trade secrets;
-
may not comply with any applicable law, regulation, accessibility requirement, industry standard, security framework or contractual obligation binding on you; and
-
does not constitute legal, financial, medical, tax, security, engineering, architectural or other professional advice, and must not be relied on as such.
6.3 Your obligation to review, test and verify
You are solely responsible for evaluating AI Output before relying on it. You must not deploy Generated Code to a production environment, to systems handling personal data or funds, or to any environment where failure could cause harm, without competent human review and testing. At minimum, before production use you should conduct code review by a qualified person, functional and regression testing, security review including dependency and secret scanning, licence compliance review, and validation against your own regulatory obligations. Any decision to use AI Output is yours, and the consequences of that decision — including for the correctness, security, licensing, performance and legal compliance of the resulting application — rest with you.
6.4 High-risk and prohibited uses
You must not use the Services, and must not use AI Output, in connection with:
-
the operation of safety-critical systems, including medical devices, clinical decision-making, diagnosis or treatment, life support, aviation, maritime or rail control, autonomous vehicles, nuclear facilities, industrial control of hazardous processes, weapons systems, or emergency response infrastructure;
-
automated decision-making that produces legal effects for, or otherwise significantly affects, individuals — including credit, insurance, housing, employment, education admission, benefits eligibility or criminal justice determinations — without meaningful human review and any assessment required by applicable law;
-
biometric identification or categorisation, emotion inference, social scoring, or predictive policing;
-
any use that would constitute a prohibited practice under the EU Artificial Intelligence Act or an equivalent restriction under applicable law; or
-
any use prohibited by the AUP.
If you deploy an application built with the Services in a manner that engages obligations under the EU Artificial Intelligence Act or comparable legislation, you act as the provider or deployer of that application and are responsible for those obligations. SmartVibe is a general-purpose development tool and does not assume the role of provider or deployer of your application.
6.5 Disclosure and transparency obligations
You are responsible for any disclosure obligations that apply to you in respect of AI involvement in your products, including obligations to inform end users that they are interacting with an AI system or with AI-generated content. Where you distribute or publish material containing AI Output, you are responsible for any labelling required by applicable law or by the platform on which you publish.
6.6 Model selection, changes and availability
We select the models used to deliver AI features and may add, change, upgrade, downgrade, substitute or retire models at any time, including replacing a Model Provider. Model behaviour, output quality, latency, context length and Credit cost may change as a result. We do not guarantee the continued availability of any specific model, model version or Model Provider. Where a model is retired and this materially changes the Services for you, we will use reasonable efforts to give advance notice.
6.7 Rate limits and abuse controls
AI features are subject to rate limits, concurrency limits and context-size limits per plan. We may apply automated abuse controls, including content filtering, refusal of Prompts, throttling and temporary blocks, where we reasonably suspect a violation of the AUP or an attempt to extract model weights, system prompts or training data, to jailbreak safety controls, or to use the Services to develop a competing model.
6.8 Training on your data
We do not use your Prompts, Customer Content, Generated Code, Projects or uploaded files to train foundation models by default. We contract with Model Providers on terms that prohibit them from using data submitted through our accounts to train their models, and we seek zero-retention or short-retention arrangements where offered. Where you expressly opt in — for example by submitting a specific conversation for quality improvement or participating in a research programme — we will use the data only for the purposes described at the point of opt-in, and you may withdraw the opt-in at any time in respect of future use.
We may use aggregated and de-identified metrics that do not identify you or reveal Customer Content (for example, error rates, latency, feature adoption counts and Credit consumption patterns) to operate, secure and improve the Services. We may retain Prompts and AI Output for a limited period for the purposes of delivering the Services, debugging, billing verification, abuse detection and legal compliance, as described in the Privacy Policy.
6.9 Feedback
If you submit feedback, ratings, bug reports or suggestions, you grant us a perpetual, irrevocable, worldwide, royalty-free, sublicensable licence to use them for any purpose without obligation or attribution. Feedback is provided voluntarily and is not your Confidential Information. Please do not include Customer Content or personal data in feedback submissions unless necessary; where a bug report requires a reproduction case, we will handle it in accordance with the Privacy Policy and DPA.
7. Intellectual Property and Ownership of AI-Generated Code
7.1 SmartVibe intellectual property
As between the parties, SmartVibe and its licensors own all right, title and interest in and to the Services, including the platform software, Browser IDE, orchestration and agent systems, prompt engineering, model routing logic, Sandbox infrastructure, user interfaces, designs, APIs, Documentation, and all trade marks, service marks, logos, trade names and other brand features, together with all intellectual property rights in them. No rights are granted to you other than the limited licence in Section 7.2. All rights not expressly granted are reserved.
7.2 Licence to use the Services
Subject to your compliance with these Terms and payment of applicable fees, we grant you a limited, non-exclusive, non-transferable, non-sublicensable, revocable licence to access and use the Services during the subscription term for your internal business or personal development purposes. You must not: (a) copy, modify, translate or create derivative works of the Services; (b) reverse engineer, decompile or disassemble any part of the Services, or attempt to derive source code, model weights, system prompts or training data, except to the extent such restriction is prohibited by applicable law; (c) rent, lease, lend, sell, sublicense, resell or provide the Services to third parties as a service bureau or on a white-label basis, except as expressly permitted under an Enterprise Agreement; (d) remove or obscure proprietary notices; (e) use the Services to build, train or improve a competing product, model or service; (f) access the Services to conduct competitive benchmarking or publish performance results without our prior written consent; or (g) circumvent technical limitations, usage quotas, metering or access controls.
7.3 Your ownership of Customer Content
You retain all right, title and interest in and to your Customer Content, including any pre-existing code, designs, data and materials you bring to the Services and any intellectual property rights in them. Nothing in these Terms transfers ownership of Customer Content to us.
7.4 Limited licence you grant to us
You grant us a worldwide, non-exclusive, royalty-free licence to host, store, copy, transmit, cache, index, display, execute, adapt (for formatting and technical purposes) and create backups of Customer Content, and to submit Prompts and associated context to Model Providers, solely to the extent necessary to provide, secure, support and maintain the Services for you and to comply with law. This licence terminates when the relevant Customer Content is deleted from the Services, except for (a) copies retained in routine backups until they expire in the ordinary course, and (b) copies we are required to retain by law. This licence does not permit us to use Customer Content to train foundation models except as set out in Section 6.8.
7.5 Ownership of AI Output and Generated Code
To the maximum extent permitted by applicable law, SmartVibe assigns to you all right, title and interest that it may have in and to the AI Output generated for you in response to your Prompts, including Generated Code, and waives any moral rights it may hold in that AI Output. Where such assignment is not legally effective, we grant you instead a perpetual, irrevocable, worldwide, royalty-free, fully paid-up, sublicensable and transferable licence to use, reproduce, modify, adapt, publish, distribute, sublicense, sell and commercially exploit that AI Output for any lawful purpose, including in closed-source, proprietary or commercial products.
This assignment and licence are conditional on your compliance with these Terms and, in respect of paid features, on payment of applicable fees. We do not assert ownership of, and will not claim royalties on, applications you build using the Services.
7.6 Important limitations on ownership of AI Output
You acknowledge that our assignment in Section 7.5 conveys only such rights as we hold, and that the following limitations apply. These limitations are fundamental to the bargain between us:
-
Copyright may not subsist in AI Output. Under the copyright laws of several jurisdictions — including India, where the Copyright Act, 1957 contemplates a human author, and the United States, where the Copyright Office has taken the position that material generated without sufficient human authorship is not registrable — output generated autonomously by a machine may not attract copyright protection at all, or may attract protection only in respect of your own creative contribution, selection, arrangement and subsequent modification. We do not represent or warrant that AI Output is protectable by copyright, that you can register or enforce copyright in it, or that you can prevent others from using identical output.
-
AI Output is not exclusive. Because the same or similar Prompts may be submitted by many users, AI Output substantially similar or identical to yours may be generated for and used by others. We may generate similar output for other customers and are not restricted from doing so.
-
Third-party rights may subsist in AI Output. AI Output may incorporate or resemble material in which third parties hold copyright, patent, trade mark, database or trade secret rights, including code subject to copyleft licences such as the GPL or AGPL whose conditions could, if applicable, affect how you may distribute your application. You are responsible for licence and clearance review of AI Output before distribution, including scanning for licence-encumbered code and third-party trade marks. We do not provide, and expressly disclaim, any warranty of non-infringement or of clear title in respect of AI Output.
-
No indemnity for AI Output. Except where expressly agreed in an Enterprise Agreement, we provide no indemnity in respect of any claim that AI Output, or your use of it, infringes or misappropriates the rights of a third party. Section 21 governs indemnification.
7.7 Templates, starter kits and platform components
Where the Services provide templates, starter kits, boilerplate, component libraries, snippets or sample code that are pre-authored by us rather than generated for you, those materials remain our property and are licensed to you under a perpetual, worldwide, royalty-free, non-exclusive licence to use, modify and distribute them as incorporated into your Projects. That licence does not permit you to distribute the materials on a standalone basis, to publish them as a competing template library, or to use our trade marks. Third-party templates or components made available through the Services are licensed under their own terms, which will be identified.
7.8 Open-source components in the Services
The Services incorporate open-source software. A list of such components and their licences is available in the Documentation. Nothing in these Terms restricts your rights under an applicable open-source licence, and to the extent an open-source licence conflicts with these Terms in respect of that component, the open-source licence prevails for that component.
7.9 Trade marks and publicity
"SmartVibe", the SmartVibe logo and related marks are our trade marks. You may state factually that you use the Services and may use our name and logo in unmodified form for that purpose in accordance with any brand guidelines we publish; you must not use our marks in a way that suggests endorsement, partnership or affiliation, in a product or domain name, or in a manner likely to cause confusion.
We may identify you as a customer and use your name and logo in our customer lists, website and marketing materials. You may opt out at any time by writing to support@smartvibe.dev, and we will cease such use within thirty (30) days in respect of future materials. We will not publish a case study, quotation or usage details about you without your prior written approval.
8. Third-Party Integrations
8.1 General
The Services offer optional Integrations with third-party services. Integrations are provided for convenience. Third-party services are not part of the Services, are not controlled by us, and are governed by their own terms and privacy policies. By enabling an Integration you authorise us to exchange data with that service to the extent necessary to provide the Integration, and you represent that you have the right to grant the access you grant. We are not responsible or liable for any third-party service, including its availability, security, accuracy, data handling, pricing, changes or discontinuation, or for any loss arising from your use of it. Your relationship with each third-party provider is directly between you and that provider.
We may add, modify, deprecate or remove an Integration at any time, including where a third party changes its API, terms or availability. Where we deprecate an Integration, we will use reasonable efforts to give at least thirty (30) days' notice.
8.2 GitHub integration
The GitHub Integration allows you to authenticate through GitHub, import repositories, and read from and write to repositories you authorise. When you connect GitHub you grant us, through GitHub's OAuth or GitHub App authorisation flow, the scopes shown to you at the point of authorisation. Depending on the scopes granted, we may:
-
read repository metadata, branches, file contents, commit history and issues in authorised repositories;
-
create branches, commits, files, pull requests and tags, and push to authorised repositories;
-
read your GitHub account identity and, where authorised, organisation membership; and
-
trigger or read the status of workflows where you enable that feature.
You are responsible for the scopes you grant and for restricting authorisation to the repositories you intend. We recommend granting repository-scoped rather than account-wide access, and using a GitHub App installation limited to selected repositories. Commits and other changes made through the Integration are attributed to your GitHub identity and are your responsibility, including where initiated by an AI agent on your instruction. Write operations may overwrite, delete or rewrite history in a connected repository; you are responsible for branch protection rules, review requirements and backups. You may revoke access at any time in your GitHub settings or from your SmartVibe Account; revocation does not delete data already synchronised, which is governed by Section 18.5. We are not responsible for GitHub Actions minutes, storage or other charges you incur with GitHub, nor for any breach of your organisation's policies resulting from an authorisation you grant.
8.3 Supabase integration
The Supabase Integration allows you to connect an existing Supabase project or, where supported, to provision one, and to have the Services read schema, generate and apply migrations, generate queries and configure authentication and storage. When you connect Supabase, you may authorise the Services to hold or use project credentials, including anonymous keys, service role keys, connection strings or personal access tokens.
-
Service role keys and database credentials confer privileged access and bypass row-level security. You are responsible for deciding whether to supply them, for scoping them as narrowly as your use permits, and for rotating them promptly if the Integration is disconnected or if you suspect compromise. We store integration credentials encrypted at rest and use them only to perform operations you request.
-
Migrations and schema changes may be destructive. Operations generated by AI features and applied on your instruction may drop tables or columns, alter constraints, delete rows or otherwise cause irreversible data loss. You must review migrations before applying them, apply them to a non-production branch or environment first, and maintain independent backups. We are not liable for data loss in your Supabase project.
-
Row-level security and authorisation are your responsibility. AI Output may generate policies, roles and queries, but you are responsible for verifying that access controls correctly restrict access to your data before any production use. A misconfigured policy can expose all rows in a table publicly.
-
Data residency, backups and availability of your Supabase project are determined by your Supabase configuration and plan, not by us. Your contractual relationship for that project is with Supabase, and Supabase's terms, security posture, pricing and data processing terms apply to data you store there. Where personal data is stored in your Supabase project, you are the controller and Supabase is your processor; our DPA covers only data processed within the Services.
8.4 Google and other identity providers
You may sign in using Google or another supported identity provider. We receive the identifiers and profile fields you authorise, typically your email address, name, profile picture and provider account identifier, and use them to create and authenticate your Account. We do not receive your password. If you revoke our access at the provider, or if your provider account is suspended or deleted, you may lose access to your Account; we recommend setting a password or adding a secondary authentication method. Our use of data received from Google APIs adheres to Google API Services User Data Policy, including the Limited Use requirements.
8.5 Model Providers and other sub-processors
AI features are delivered using models operated by us or by Model Providers, and the Services rely on infrastructure, storage, email, analytics, error-monitoring and support sub-processors. A current list of sub-processors, their locations and their functions is maintained in the Privacy Policy and the DPA. We remain responsible to you for the performance of our sub-processors in respect of the Services, on the terms set out in the DPA and subject to Section 20.
8.6 Credentials you supply
Where you supply third-party credentials, API keys, tokens or connection strings to the Services (whether for an Integration or within Customer Content), you represent that you are authorised to do so and that doing so does not breach any agreement binding on you. We store such secrets encrypted at rest and restrict internal access, but you should supply the least-privileged credential capable of performing the task, must not embed production secrets in Projects that will be previewed, and must rotate credentials on disconnection or suspected compromise. We disclaim liability for consequences arising from credentials that you scope too broadly or expose within your own Project code.
9. API and Developer Terms
9.1 Access and keys
Where your plan includes API access, we issue API keys enabling programmatic use of the Services. API keys are confidential, are issued to your Account, and must not be shared, published, embedded in client-side code or mobile applications, or committed to a repository. You are responsible for all use of the Services under your API keys. You must rotate keys promptly on suspected compromise and may revoke keys from your Account at any time. We may rotate or revoke keys where we reasonably believe they have been compromised or misused.
9.2 Quotas and rate limits
API use is subject to per-minute, per-hour and per-month rate limits, concurrency limits, payload size limits and Credit consumption as described in the Documentation for your plan. Exceeding a limit may result in throttling, queuing or rejected requests with an error response. You must implement exponential backoff with jitter, must honour Retry-After headers, and must not retry aggressively on error. We may adjust limits to protect the stability of the Services, with notice where practicable. The Free plan carries no service level commitment for API access.
9.3 Restrictions on API use
In addition to the restrictions in Sections 7.2 and 10, you must not use the API to:
-
resell, redistribute or expose the Services (or any material part of them) to third parties as a substantially similar or competing product, or as an undifferentiated pass-through of our AI features;
-
generate synthetic data, distil, extract or replicate model behaviour for the purpose of training or fine-tuning any machine learning model;
-
extract, discover or publish system prompts, model identities, internal tooling, orchestration logic or other non-public elements of the Services;
-
scrape, crawl or systematically harvest content or metadata from the Services other than through documented endpoints;
-
circumvent metering, quotas, seat limits or Credit accounting, including by rotating keys, accounts, IP addresses or payment methods;
-
operate a shared or multi-tenant service on a single Account in a manner that attributes the usage of many end users to one seat, except as expressly permitted by your plan or Enterprise Agreement; or
-
perform load testing, penetration testing, fuzzing or vulnerability scanning against the Services without our prior written consent, save as permitted under our responsible disclosure programme.
9.4 Caching and storage of responses
You may cache and store API responses within your own systems for your own use. You must not build or publish a corpus, dataset or index of AI Output for redistribution, model training or resale.
9.5 Versioning and deprecation
The API is versioned. We may release new versions and deprecate old ones. We will use reasonable efforts to give at least ninety (90) days' notice before removing or making a backwards-incompatible change to a generally available API endpoint or field, other than where a shorter period is necessary to address a security vulnerability, legal requirement or a change imposed by a Model Provider or other third party. Endpoints marked experimental or beta may change at any time. Additive changes — new fields, new endpoints, new enum values — are not treated as backwards-incompatible, and your integration should tolerate them.
9.6 Suspension of API access
We may suspend or throttle API access immediately where we reasonably believe it is causing or is likely to cause degradation to the Services, security risk, legal exposure, or where it violates these Terms or the AUP. Where practicable we will notify you and work with you to restore access.
10. Acceptable Use
Your use of the Services is subject to the Acceptable Use Policy, which forms part of these Terms. Without limiting the AUP, you must not use the Services to develop, host, generate or distribute malware, ransomware, exploit kits, credential harvesting or phishing infrastructure, spam tooling, child sexual abuse material, non-consensual intimate imagery, content that sexualises minors, unlawful surveillance or stalkerware, or content that infringes third-party rights or violates applicable law. You must not attempt to defeat the security of the Services or of any third party, and must not use the Services in violation of applicable export control or sanctions laws.
We may investigate suspected violations, and may remove or disable access to Customer Content, restrict features, suspend or terminate Accounts, and report conduct to law enforcement or other authorities where we reasonably believe it is required or appropriate. Where a violation is not severe and does not create ongoing risk, we will normally notify you and provide an opportunity to remedy before taking action against your Account.
11. Customer Content and Your Responsibilities
11.1 Your warranties
You represent and warrant that (a) you own or have all necessary rights, licences, consents and permissions in Customer Content and in any third-party material you submit to the Services, (b) Customer Content and its processing by us in accordance with these Terms will not infringe or misappropriate the rights of any third party or violate applicable law, (c) where Customer Content includes personal data, you have a lawful basis for its processing and have provided all required notices and obtained all required consents, and (d) you will not submit Customer Content in violation of the AUP.
11.2 Restricted data
Unless expressly agreed in writing in an Enterprise Agreement together with any additional terms we require, you must not upload to or process within the Services: payment card data subject to PCI DSS; protected health information subject to HIPAA or comparable health privacy laws; government-issued identity numbers other than as necessary for billing; biometric identifiers; children's personal data; classified or export-controlled technical data; or special category personal data within the meaning of Article 9 of the GDPR. Live Preview and Sandboxes must not be used with any of the foregoing under any circumstances. If you do so in breach of this Section, you do so at your own risk and remain responsible for the consequences.
11.3 Backups are your responsibility
While we maintain platform-level backups of persisted data as described in Section 14 and the SLA, those backups exist for disaster recovery of the Services as a whole and are not a substitute for your own backups. We do not guarantee point-in-time restoration of an individual Project, file or record, and we are not obliged to restore Customer Content that you or your Authorised Users delete or overwrite. You should maintain independent copies of anything material, including by connecting version control.
11.4 Export control and sanctions
You represent that you are not located in, ordinarily resident in, or organised under the laws of a country or territory subject to comprehensive economic sanctions administered by India, the United Nations, the United States, the European Union or the United Kingdom, and that you are not a person or entity designated on any applicable restricted party list, nor owned or controlled by such a person. You must not use or export the Services in violation of applicable export control or sanctions laws, or for any prohibited end use, including nuclear, chemical, biological weapons or missile technology applications.
12. Enterprise Licensing
This Section 12 applies only where you have entered into an Enterprise Agreement or an Order Form for an Enterprise plan. Where a term of the Enterprise Agreement conflicts with this Section, the Enterprise Agreement prevails.
12.1 Order Forms and scope
Enterprise entitlements are set out in an Order Form specifying the plan, number of seats or usage entitlement, Credit allocation, deployment model, subscription term, fees, payment terms, support tier and any agreed service levels. Each Order Form incorporates these Terms and forms a separate agreement in respect of the entitlements described in it.
12.2 Deployment models
Enterprise plans may be delivered in one or more of the following configurations, as specified in the Order Form: (a) multi-tenant — the standard shared platform, with enterprise administration features; (b) dedicated — logically isolated compute and storage within our infrastructure, with configurable region; (c) customer-managed cloud — deployment into a cloud account or virtual private cloud that you control; or (d) self-hosted — installation on infrastructure you operate. Configurations (c) and (d) are subject to the additional licence terms in Section 12.3 and to any technical prerequisites we specify.
12.3 Self-hosted and customer-managed licence
Where the Order Form provides for self-hosted or customer-managed deployment, we grant you a non-exclusive, non-transferable, non-sublicensable licence, for the subscription term and within the licensed entitlement, to install and operate the SmartVibe software solely for your internal business purposes and solely for the number of seats or units licensed. You must not (a) exceed the licensed entitlement, (b) provide access to third parties other than your Authorised Users and contractors acting for your benefit and bound by equivalent obligations, (c) modify, decompile or reverse engineer the software except as permitted by law, (d) remove or interfere with licence keys, entitlement checks or telemetry required for licence verification, or (e) operate the software after expiry or termination of the subscription term. You are responsible for the infrastructure, network, availability, patching and security of a self-hosted deployment, and the SLA does not apply to it. We will provide updates and security patches during the subscription term; you must apply security patches within the period we specify.
12.4 Usage verification
We may verify your compliance with licensed entitlements through platform telemetry or, for self-hosted deployments, by requesting a self-certification of usage no more than once in any twelve-month period. Where verification shows usage in excess of entitlement, you will pay for the excess from the date it began at the rates in the Order Form, or, if none, at our then-current list price. We will treat any information obtained through verification as your Confidential Information and will not use it for any other purpose.
12.5 Administration, identity and access management
Enterprise plans include an administration console providing, as specified in the Documentation: single sign-on via SAML 2.0 or OIDC; SCIM user provisioning and de-provisioning; role-based access control and custom roles; enforced multi-factor authentication; session and IP controls; audit logs of administrative and security-relevant events, exportable and retained for the period stated in the Order Form; domain capture; retention and deletion policy configuration; and controls governing whether Authorised Users may enable specific Integrations or AI features.
12.6 Security assurance
We will, on request and no more than once in any twelve-month period, provide Enterprise customers with (a) our then-current security documentation and completed security questionnaire, (b) a summary report of our most recent independent penetration test, and (c) copies of available third-party audit reports or certifications. These materials are our Confidential Information. Where you require an audit right beyond the foregoing, it will be as agreed in the Enterprise Agreement or the DPA. You may conduct a penetration test of your own Enterprise environment subject to our prior written approval of scope, timing and rules of engagement.
12.7 Support and service levels
Enterprise plans include the support tier stated in the Order Form, which may provide a named technical contact, prioritised response targets, an escalation path, a private support channel and onboarding assistance. Uptime commitments and service credits are as set out in the SLA and any Order Form variation.
12.8 Data protection for Enterprise customers
The DPA applies automatically. On request we will execute a countersigned copy, EU Standard Contractual Clauses, the UK International Data Transfer Addendum, and, where applicable, additional terms addressing India's Digital Personal Data Protection Act, 2023. We will agree in the DPA or Order Form the region in which Customer Content is stored, any restriction on sub-processor locations, breach notification timelines and deletion timelines.
12.9 Confidentiality, term and renewal
Enterprise Agreements include mutual confidentiality obligations as set out in Section 16. Enterprise subscriptions run for the term stated in the Order Form and renew as stated in it; where the Order Form is silent, the subscription renews for successive periods of the same length unless either party gives written notice of non-renewal at least sixty (60) days before the end of the then-current term. Fees for a renewal term may increase by no more than the greater of eight per cent (8%) or the increase in the applicable consumer price index over the preceding term, unless otherwise agreed.
12.10 Professional services
Where we agree to provide implementation, migration, integration, training or custom development services, those services will be described in a statement of work specifying scope, deliverables, assumptions, acceptance criteria, fees and timelines. Unless the statement of work provides otherwise, deliverables specifically created for you are assigned to you on payment in full, excluding our pre-existing materials, tools, know-how and generally applicable components, which remain ours and are licensed to you for use with the deliverables.
13. Service Levels and Support
Availability commitments, the method for calculating monthly uptime, exclusions, service credits and support response targets are set out in the Service Level Agreement. In summary: paid plans are subject to a monthly uptime commitment for the core platform, with service credits as the sole and exclusive remedy for failure to meet it; the Free plan, Live Preview, Sandboxes, beta features, third-party services and Integrations are excluded from the uptime commitment. Support is provided in English by email to support@smartvibe.dev and, where your plan includes it, through in-product channels. Nothing in the SLA extends our liability beyond Section 20.
14. Security Commitments
We maintain a written information security programme with technical and organisational measures appropriate to the nature of the Services and the risk to Customer Content, described more fully in Annex II to the DPA. Those measures include, as at the Effective Date:
-
Encryption — TLS 1.2 or higher for data in transit, with HSTS enforced; AES-256 or equivalent for data at rest, including Project storage, database contents, backups and integration secrets, which are additionally encrypted with keys held in a managed key management service.
-
Access control — role-based access on the principle of least privilege, mandatory multi-factor authentication for personnel with production access, unique named accounts, just-in-time and time-bound elevation for privileged operations, quarterly access reviews, and revocation on role change or departure.
-
Tenant isolation — logical separation of customer data, isolated Sandbox execution with resource and network constraints, and authorisation checks on every data access path.
-
Secure development — peer code review, protected branches, static analysis and dependency scanning in the build pipeline, secret scanning, infrastructure as code with change review, and separation of development, staging and production environments.
-
Vulnerability management — continuous dependency monitoring, regular scanning of infrastructure and application, independent penetration testing at least annually, and remediation targets of 7 days for critical, 30 days for high, and 90 days for medium severity findings, measured from validated triage.
-
Logging and monitoring — centralised, integrity-protected logging of authentication, administrative and security-relevant events, automated alerting on anomalous activity, and retention of security logs for at least twelve (12) months.
-
Incident response — a documented incident response plan, tested at least annually, with defined severity levels, escalation, containment, forensic preservation and post-incident review. Where we become aware of a personal data breach affecting Customer Content, we will notify you without undue delay and in any event within seventy-two (72) hours of becoming aware, with the information described in the DPA.
-
Resilience — automated encrypted backups of persisted Project data and platform databases with a target recovery point objective of 24 hours and recovery time objective of 8 hours for the core platform, backup restoration tested periodically, and infrastructure distributed across availability zones. Sandbox filesystems are not backed up.
-
Personnel — background checks where lawful, confidentiality undertakings, and security and privacy training at onboarding and annually thereafter.
-
Sub-processor diligence — security assessment before engagement, contractual obligations no less protective than those in the DPA, and periodic review.
Security is a shared responsibility. We secure the platform; you are responsible for the security of your Account and credentials, the configuration of your Projects and connected services, the access you grant through Integrations, the review of Generated Code for vulnerabilities, and the security of any application you deploy. We may update our security measures provided that we do not materially reduce the overall level of protection during a subscription term.
14.1 Responsible disclosure
We welcome reports of suspected vulnerabilities at security@smartvibe.dev. If you research in good faith, act only against your own Account, avoid privacy violations, service degradation and data destruction, do not exfiltrate data beyond the minimum needed to demonstrate the issue, and give us a reasonable period to remediate before disclosure, we will not pursue legal action against you in respect of that research and will treat your report as authorised for the purposes of these Terms. Automated scanning of production without prior written consent is not covered.
15. Privacy and Data Protection
Our processing of personal data is described in the Privacy Policy. Where we process personal data contained in Customer Content on your behalf and on your instructions, we do so as a processor (or, under India's Digital Personal Data Protection Act, 2023, as a data processor) and the DPA applies and forms part of these Terms. Where you determine the purposes and means of processing personal data of your end users within an application you build, you are the controller or data fiduciary in respect of that processing and are responsible for the corresponding obligations, including notice, lawful basis or consent, data subject rights and, where required, appointment of a data protection officer and registration with a supervisory authority.
16. Confidentiality
"Confidential Information" means non-public information disclosed by one party ("Discloser") to the other ("Recipient") that is designated as confidential or would reasonably be understood to be confidential in the circumstances, including Customer Content, non-public product roadmaps, security documentation, pricing not publicly listed, and the terms of any Order Form. Confidential Information does not include information that (a) is or becomes public other than through breach, (b) the Recipient held without obligation of confidence before disclosure, (c) the Recipient develops independently without use of the Discloser's Confidential Information, or (d) the Recipient lawfully receives from a third party without restriction.
The Recipient will use Confidential Information only to perform under these Terms, will protect it with no less than reasonable care and no less care than it applies to its own confidential information, and will limit disclosure to its personnel, affiliates, advisers and sub-processors who need to know and are bound by equivalent obligations. The Recipient may disclose Confidential Information where required by law or by a court or regulator, provided that, where legally permitted, it gives prompt notice and reasonable cooperation so the Discloser may seek protective relief. Obligations under this Section continue for three (3) years after disclosure, and indefinitely in respect of trade secrets and Customer Content.
17. Suspension
We may suspend your Account, a Workspace, a Project, a Sandbox, an Integration or API access, in whole or in part, with notice where practicable and immediately where not, if: (a) we reasonably believe there is a material violation of these Terms or the AUP; (b) there is a security risk to the Services, to us or to a third party; (c) your use is causing or is likely to cause material degradation to the Services; (d) payment is overdue as described in Section 4.6; (e) we are required to do so by law or by a competent authority; or (f) we reasonably believe your use exposes us to legal liability. We will limit any suspension in scope and duration to what is reasonably necessary, and will restore access promptly once the cause is resolved. Suspension for cause does not relieve you of the obligation to pay fees for the suspended period.
18. Term, Termination and Effect
18.1 Term
These Terms apply from your first access to the Services and continue until your Account is terminated in accordance with this Section or, for Enterprise customers, until expiry or termination of all Order Forms.
18.2 Termination by you
You may stop using the Services at any time, cancel a subscription as described in Section 4.4, and delete your Account from your Account settings. You may terminate for our material breach if we fail to cure within thirty (30) days of your written notice describing the breach, in which case we will refund pre-paid fees for the unused remainder of the subscription term, excluding consumed Credits.
18.3 Termination by us
We may terminate these Terms and your Account: (a) immediately, for a material breach of these Terms or the AUP that is not capable of cure or that creates a risk of harm, including fraud, unlawful use, or conduct described in the AUP as grounds for immediate termination; (b) on thirty (30) days' notice for any other material breach not cured within that period; (c) on thirty (30) days' notice where you are on the Free plan, for any reason or none; (d) where payment remains overdue as described in Section 4.6; (e) immediately if you become insolvent, enter administration, liquidation or an equivalent proceeding, or make an assignment for the benefit of creditors; or (f) on sixty (60) days' notice if we discontinue the Services generally, in which case we will refund pre-paid fees for the unused remainder of the subscription term.
18.4 Effect of termination
On termination or expiry: (a) your right to access the Services ceases; (b) all outstanding fees become immediately payable; (c) each party will, on request, return or destroy the other's Confidential Information, subject to legal retention requirements; and (d) unconsumed Credits are forfeited without compensation, save where termination was by you for our material breach or by us under Section 18.3(f).
18.5 Data export and deletion
Except where termination results from a violation involving unlawful content or where retention is required by law, we will retain your persisted Customer Content in a state permitting export for thirty (30) days following termination, during which you may request an export in a structured, commonly used, machine-readable format. After that period we will delete Customer Content from active systems within a further thirty (30) days, and from backups as those backups expire in the ordinary course, which will not exceed ninety (90) days from deletion from active systems. Data held in your own connected repositories or databases is not affected by termination and remains under your control. Enterprise customers may agree different export and deletion timelines in an Order Form or the DPA. We may retain a minimal record of the Account (identifier, plan, billing history and abuse records) for as long as necessary for tax, accounting, legal and abuse-prevention purposes, as described in the Privacy Policy.
18.6 Survival
Sections 1.4, 2, 4 (in respect of accrued amounts), 6.2, 6.9, 7, 9.4, 11, 16, 18.4–18.6, 19, 20, 21, 23, 24 and 26 survive termination, together with any other provision that by its nature should survive.
19. Disclaimers of Warranties
To the maximum extent permitted by applicable law, the Services, AI Output, Sandboxes, Live Preview, Integrations, templates, Documentation and support are provided "as is" and "as available", with all faults and without warranty of any kind. We expressly disclaim all warranties, conditions, representations and terms, whether express, implied, statutory or otherwise, including any implied warranty or condition of merchantability, satisfactory quality, fitness for a particular purpose, title, non-infringement, quiet enjoyment, accuracy, or arising from a course of dealing or usage of trade.
Without limiting the foregoing, we do not warrant that: (a) the Services will be uninterrupted, timely, secure or error-free; (b) defects will be corrected; (c) the Services or any file, Sandbox or Integration is free of viruses, malicious code or vulnerabilities; (d) AI Output will be accurate, complete, functional, secure, original, non-infringing, reproducible, unique to you, or fit for any purpose; (e) any result will be obtained from use of the Services; (f) data stored in a Sandbox or rendered in a Live Preview will persist or remain private; or (g) any third-party service or Integration will remain available or perform as described. Any advice or information, whether oral or written, obtained from us or through the Services does not create any warranty not expressly stated in these Terms.
Some jurisdictions do not allow the exclusion of certain warranties or of implied statutory rights. Nothing in these Terms excludes or limits any right or remedy that cannot lawfully be excluded or limited, including rights under the Consumer Protection Act, 2019 (India) or mandatory consumer protection law applicable to you, and this Section applies only to the maximum extent permitted by the law applicable to you.
20. Limitation of Liability
20.1 Exclusion of indirect losses
To the maximum extent permitted by law, neither party will be liable to the other for any indirect, incidental, special, consequential, exemplary or punitive damages, or for any loss of profits, revenue, anticipated savings, goodwill, reputation, business opportunity, or for loss, corruption or inaccuracy of data or code, or the cost of procuring substitute services, in each case however caused and whether arising in contract, tort (including negligence), breach of statutory duty or otherwise, even if advised of the possibility of such loss.
20.2 Aggregate cap
To the maximum extent permitted by law, our total aggregate liability arising out of or relating to these Terms and the Services, whether in contract, tort or otherwise, will not exceed the greater of (a) the total fees actually paid by you to us for the Services in the twelve (12) months immediately preceding the first event giving rise to the liability, and (b) INR 10,000 (ten thousand Indian Rupees). Where you use the Services on the Free plan, our total aggregate liability will not exceed INR 10,000. Multiple claims will not enlarge this cap.
20.3 AI Output
For the avoidance of doubt and to the maximum extent permitted by law, we will have no liability arising from or relating to AI Output, including any liability for its accuracy, security, licensing, originality, infringement of third-party rights, performance, or for any decision taken or application deployed in reliance on it, or for any loss resulting from a command, migration or repository operation executed by an AI feature on your instruction. This allocation of risk reflects the nature of generative technology and your obligation to review under Section 6.3, and is a material inducement for us to provide the Services at the stated prices.
20.4 Exclusions from the cap
Nothing in these Terms limits or excludes either party's liability for: (a) death or personal injury caused by negligence; (b) fraud or fraudulent misrepresentation; (c) your obligation to pay fees due; (d) your indemnification obligations under Section 21.1; (e) a party's wilful misconduct; or (f) any liability that cannot lawfully be limited or excluded.
20.5 Basis of the bargain
The disclaimers in Section 19 and the limitations in this Section 20 form an essential basis of the agreement between us and apply even if a limited remedy fails of its essential purpose. If applicable law does not permit a limitation set out here, that limitation applies to the greatest extent permitted.
21. Indemnification
21.1 Your indemnity
You will defend, indemnify and hold harmless SmartVibe, its owners, personnel and agents from and against any third-party claim, demand, proceeding or investigation, and all resulting losses, damages, liabilities, settlements, fines, penalties and reasonable legal costs, arising out of or relating to: (a) Customer Content, including any claim that it infringes or misappropriates third-party rights or violates law; (b) your Prompts or your use of AI Output, including in any application you deploy; (c) your breach of these Terms, the AUP or applicable law; (d) your violation of the rights of a third party, including any data subject or end user of your application; (e) your configuration of, or the access you grant through, any Integration, including operations performed on a connected repository or database; or (f) any claim by an Authorised User or your end users relating to an application you build using the Services.
21.2 Our indemnity
We will defend you against any third-party claim that your use of the Services as provided by us (excluding AI Output, Customer Content, Integrations and third-party components) in accordance with these Terms directly infringes that third party's copyright, trade mark or Indian patent, and will pay damages finally awarded or agreed in settlement, subject to Section 20.2. This indemnity does not apply to any claim arising from (i) AI Output, (ii) Customer Content or its combination with the Services, (iii) modification of the Services by anyone other than us, (iv) use of the Services other than in accordance with these Terms or the Documentation, (v) third-party services, Integrations, open-source components or packages you install, (vi) use of a superseded version where an update would have avoided the claim, or (vii) use on the Free plan or of a beta feature. This indemnity is available to Enterprise customers and, at our discretion, to Business plan customers; it is our sole liability and your sole remedy for third-party intellectual property claims.
21.3 Procedure
The indemnified party must (a) promptly notify the indemnifying party in writing of the claim, provided that a delay reduces the indemnity only to the extent of resulting prejudice, (b) give the indemnifying party sole control of the defence and settlement, provided that no settlement imposing a non-monetary obligation or admission on the indemnified party may be made without its consent, and (c) provide reasonable cooperation at the indemnifying party's expense. The indemnified party may participate with its own counsel at its own expense. Where a claim against us is indemnifiable, we may, at our option, modify the Services to make them non-infringing, procure a licence, or terminate the affected Services with a pro-rata refund of pre-paid fees.
22. Dispute Resolution
22.1 Informal resolution first
Before commencing formal proceedings, the parties will attempt to resolve any dispute informally. You agree to send a written notice of dispute to support@smartvibe.dev describing the dispute and the relief sought, and to allow thirty (30) days for good-faith discussions. This requirement does not prevent either party from seeking urgent injunctive relief.
22.2 Arbitration
Subject to Section 22.4, any dispute, controversy or claim arising out of or relating to these Terms or the Services that is not resolved informally will be referred to and finally resolved by arbitration under the Arbitration and Conciliation Act, 1996 of India. The arbitration will be conducted by a sole arbitrator appointed by agreement between the parties or, failing agreement within thirty (30) days, in accordance with that Act. The seat and venue of arbitration will be Nashik, Maharashtra, India, and the language will be English. The arbitrator may award any relief available in a court of competent jurisdiction, and the award will be final and binding. Each party bears its own costs unless the arbitrator determines otherwise.
22.3 No class or representative proceedings
To the extent permitted by applicable law, each party will bring claims only in its individual capacity and not as a claimant or class member in any purported class, collective, consolidated or representative proceeding, and the arbitrator may not consolidate claims of more than one person without the consent of all parties. If this Section 22.3 is held unenforceable in respect of a particular claim, that claim will be severed and heard in the courts identified in Section 23.
22.4 Exceptions
Either party may (a) seek interim, urgent or injunctive relief from a court of competent jurisdiction to protect its intellectual property, Confidential Information or the security of its systems, (b) bring a claim for unpaid fees in the courts identified in Section 23, and (c) bring a claim in a small claims or consumer forum where that forum has jurisdiction. If you are a consumer, nothing in this Section 22 deprives you of the right to bring proceedings before a consumer forum having jurisdiction under the Consumer Protection Act, 2019, or, where you are resident in the European Economic Area or the United Kingdom, before the courts of your place of residence where mandatory law so provides.
23. Governing Law and Jurisdiction
These Terms and any dispute arising out of them are governed by the laws of India, without regard to conflict-of-laws principles. Subject to Section 22, the courts at Nashik, Maharashtra, India have exclusive jurisdiction. The United Nations Convention on Contracts for the International Sale of Goods does not apply. Where mandatory law in your country of residence grants you the protection of that law or the jurisdiction of its courts, nothing in this Section removes that protection.
24. Compliance and Anti-Corruption
Each party will comply with all laws applicable to its performance under these Terms, including anti-bribery and anti-corruption laws such as the Prevention of Corruption Act, 1988, applicable anti-money-laundering laws, and applicable export control and sanctions laws. Neither party will offer or accept any improper payment or benefit in connection with these Terms. Each party will maintain accurate books and records sufficient to demonstrate compliance with this Section.
25. Intermediary Status and Grievance Redressal (India)
To the extent we act as an intermediary within the meaning of the Information Technology Act, 2000 and the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, we publish these Terms, the Privacy Policy and the AUP as our rules and regulations, and we have appointed a Grievance Officer to receive and address complaints concerning content or conduct on the Services. Complaints may be sent to the Grievance Officer at grievance@smartvibe.dev, and will be acknowledged within twenty-four (24) hours and disposed of within fifteen (15) days of receipt, save for complaints concerning non-consensual intimate imagery or content impersonating another person, which will be actioned within twenty-four (24) hours of a valid complaint. The Grievance Officer's name and contact details are published at smartvibe.dev/legal/grievance.
26. General Provisions
26.1 Notices
We may give notice to you by email to the address associated with your Account, by posting within the Services, or by posting on smartvibe.dev. You must give notice to us in writing at support@smartvibe.dev and, for legal notices, additionally to the postal address on the first page. Notices are deemed received on the day of sending if sent by email on a business day, and otherwise on the next business day. You are responsible for keeping your email address current.
26.2 Assignment
You may not assign or transfer these Terms or your Account without our prior written consent, except that you may assign them in full to a successor in connection with a merger, acquisition or sale of substantially all assets, on written notice to us. We may assign these Terms in connection with a merger, acquisition, reorganisation or sale of assets, or to an affiliate, on notice to you. Any purported assignment in breach of this Section is void.
26.3 Subcontracting and affiliates
We may perform our obligations through affiliates, contractors and sub-processors, and remain responsible for their performance to the extent set out in these Terms and the DPA.
26.4 Force majeure
Neither party is liable for any failure or delay in performance (other than a payment obligation) caused by an event beyond its reasonable control, including act of God, natural disaster, epidemic, war, terrorism, civil unrest, government action, change in law, labour dispute, failure of a telecommunications or internet backbone, widespread cloud infrastructure outage, or failure of a third-party service on which the Services depend. The affected party will notify the other and use reasonable efforts to mitigate. If a force majeure event continues for more than sixty (60) days, either party may terminate the affected subscription with a pro-rata refund of pre-paid unused fees.
26.5 Severability, waiver and remedies
If any provision is held invalid or unenforceable, it will be modified to the minimum extent necessary to make it enforceable or, if that is not possible, severed, and the remaining provisions continue in full force. A failure or delay in exercising a right is not a waiver of it, and a waiver is effective only if in writing. Except where these Terms state that a remedy is sole and exclusive, all rights and remedies are cumulative.
26.6 Entire agreement
These Terms, together with the documents incorporated by reference and any Order Form, constitute the entire agreement between the parties in respect of the Services and supersede all prior or contemporaneous proposals, discussions and agreements, whether written or oral. Neither party has relied on any statement not set out in these Terms, save in respect of fraudulent misrepresentation. Any purchase order, vendor portal terms or other document you issue is for administrative convenience only and its terms have no effect.
26.7 Relationship and third parties
The parties are independent contractors. Nothing creates a partnership, joint venture, agency, fiduciary or employment relationship. These Terms confer no rights on any third party, except that our affiliates and personnel may enforce Sections 19, 20 and 21.1.
26.8 Interpretation and language
Headings are for convenience only. "Including" means "including without limitation". References to a statute include its subordinate legislation and any successor. These Terms are drafted in English, and the English version prevails over any translation.
26.9 Electronic contracting
You consent to contract electronically. Records maintained by us in electronic form are admissible as evidence, and you agree not to contest the validity or enforceability of these Terms on the ground that they were accepted electronically.
27. Contact
SmartVibe AI
India
-
General and support: support@smartvibe.dev
-
Privacy and data protection: privacy@smartvibe.dev
-
Security and vulnerability reports: security@smartvibe.dev
-
Copyright and DMCA notices: copyright@smartvibe.dev
-
Abuse reports: abuse@smartvibe.dev
-
Grievance Officer (India): grievance@smartvibe.dev
-
Enterprise and licensing: enterprise@smartvibe.dev
By using SmartVibe, you confirm that you have read, understood and agree to be bound by these Terms of Service and the documents incorporated into them.