Legal
Terms of Service
The agreement between you and Caterfli: what the service does, who is responsible for changes agents make in your own systems, and how either side can end it.
- Version
- 1.0
- Effective
- Last updated
This is a working starting point provided with the software. It is not
legal advice. Have a qualified adviser review it against your
jurisdiction and business before you rely on it.
1. Who these terms are between
These terms are between you (the "Customer") and the operator of this Caterfli installation (the "Provider", "we"). By creating an account or using a workspace you accept them. If you accept on behalf of a company, you confirm you are authorised to bind it.
2. What the service does
Caterfli connects to software you already run — APIs, OpenAPI documents, MCP servers and MySQL or PostgreSQL databases — and lets AI agents operate that software on your behalf, within limits you configure.
You decide which systems are connected, which capabilities each agent may use, and which actions require a human decision before they run.
Agents can be reached from the web dashboard and, where your plan includes them, from Telegram, Slack, WhatsApp and email. A message arriving through one of those channels is handled by the same runtime, with the same permission and approval checks, as one typed in the dashboard.
3. Your account
You may sign in with a password, or with Google or GitHub where the operator of this installation has enabled them. Signing in with a third party means that provider vouches for your identity; your relationship with them is governed by their own terms.
You are responsible for keeping sign-in credentials confidential, for all activity under your workspace, and for removing access promptly when someone leaves your team. Tell us without delay if you believe an account has been compromised.
You must be old enough to form a binding contract in your jurisdiction.
4. Your systems and your credentials
When you connect a system you give us credentials for it. You confirm that you are entitled to grant that access.
Grant each connection the least privilege it needs. The platform's own restrictions — permissions, approval gates, query validation — are a second line of defence, not a substitute for correctly scoped database and API credentials. An agent can never do more than the credential you supplied allows.
5. Automated action, and your responsibility for it
Agents act on instructions from your team, planned by an AI model. The platform validates every proposed action before it runs, and pauses destructive work for human approval by default.
An AI model is not deterministic. It can misread a request, choose the wrong record, or act on an ambiguous instruction, and no amount of checking on our side turns it into something that cannot be wrong.
You remain responsible for the outcome of actions carried out in your workspace, including actions a member of your team approved. Configure approval requirements to match the risk you are prepared to accept.
6. Changes and deletions in the software you connect
This section matters more than any other on this page, so it is stated plainly.
When you connect your own software, agents write to it directly. That includes creating records, changing records, and deleting records.
**We are not responsible for any data or information that is changed, overwritten, lost or deleted in software you connected to this platform.** That applies however the change came about — an agent acting on an instruction from your team, an action a colleague approved, a model choosing the wrong record, a misconfigured connection, or a credential granted more access than it needed. The data is yours, the system it lives in is yours, and responsibility for what happens in it remains yours.
What we do provide is a set of safeguards, and it is worth being precise about what each one is and is not:
- Destructive operations require human approval by default, and you can
require it for anything else.
- Updates and deletes are refused unless they carry a filter, and a
single operation cannot exceed a row limit you set.
- Where your schema records deletions rather than performing them
(deleted_at, is_deleted and similar), a delete marks the row instead of removing it.
- Every create, update and delete an agent makes is recorded, so you can
see afterwards what was changed and who asked for it.
These reduce the chance of an unwanted change and make one easier to find afterwards. **None of them is a backup, and none of them can undo anything.** The record of a change is a record, not a copy of the data it changed.
Keeping your own backups of any system you connect, and being able to restore them, remains entirely your responsibility. If a system holds data you cannot afford to lose, connect it with a read-only credential until you are satisfied with how your agents behave.
7. Acceptable use
You must not use the service to:
- break any law, or infringe anyone's rights
- access systems you are not authorised to access
- attempt to defeat the platform's permission, approval or isolation
controls, or to reach another customer's data
- send unlawful, abusive or deliberately misleading content through a
connected channel
- resell or provide the service to a third party unless we have agreed
in writing
8. Plans, payment and renewal
Paid plans are billed in advance for the period you choose. Charges are exclusive of tax unless stated otherwise. Subscriptions renew automatically until cancelled.
Moving to a larger plan takes effect immediately. You are charged the new plan's price less a credit for the part of the current period you have paid for and not yet used, worked out by time.
Moving to a smaller plan takes effect when the period you have already paid for ends. It cannot be brought forward, because you have paid for the plan you are on until that date.
You may cancel at any time; cancellation takes effect at the end of the period you have already paid for, and access continues until then.
Except where the law requires otherwise, payments already made are not refundable for a period that has begun.
9. If a payment fails
We will attempt to collect again and tell you. There is a grace period during which the workspace keeps working normally.
If payment is still outstanding after the grace period, paid features are restricted — but your data is not deleted. Connections, agents, execution history and audit records are preserved, and paying restores access.
10. Usage allowances
Each plan includes an allowance of AI usage per billing period, measured in model tokens, along with limits on agents, connections, executions and other resources. Your current usage and what remains are shown in the dashboard.
When the AI allowance for a period is spent, **features that need an AI model stop working** until the period resets or you move to a larger plan. Agents will not run and chat will not answer. We email the people who own or administer the workspace when this happens.
Nothing is deleted when an allowance runs out, and everything that does not need a model continues to work.
11. The history we keep, and for how long
The record of what your agents changed in your connected systems is kept for a period set by your plan, after which older entries are deleted automatically. The period that applies to you is shown alongside the history itself.
Moving to a larger plan keeps more history from that point onwards. It does not restore entries that have already been removed, and no entry can be recovered once it has been. If you need a record kept beyond your plan's period, take your own copy of it before then.
12. Availability
We aim for high availability but do not promise uninterrupted service unless a separate written agreement says otherwise. Maintenance, third-party outages and failures in systems you have connected can all affect what agents can do.
AI models are supplied by third parties. Their availability, their limits and their behaviour are outside our control.
13. Your data
You keep all rights in the data in your workspace. We process it to provide the service, as described in the Privacy Policy.
You may export your data while your account is active. After closure we retain it only for the period stated in the Privacy Policy, then delete it.
14. Suspension
We may suspend a workspace that is being used in breach of these terms, that is causing harm to the platform or to others, or where payment is long overdue. Except in urgent cases we will give notice and an opportunity to put things right first.
15. Liability
Nothing here excludes liability that cannot lawfully be excluded, including for death or personal injury caused by negligence, or for fraud.
Subject to that, neither side is liable for indirect or consequential loss, and our total liability in any twelve-month period is limited to the amount you paid for the service in that period.
For the avoidance of doubt, and without limiting section 6, this includes loss of or damage to data held in systems you connected to the platform, and the cost of restoring it.
16. Changes to these terms
We may update these terms. Material changes will be announced before they take effect, and the version and effective date at the top of this page will change. Continuing to use the service after that date means you accept the revised terms.
The version you agreed to when you signed up is retained, and remains available on request.
17. Ending the agreement
You may close your account at any time. We may end the agreement on reasonable notice, or immediately for a serious or repeated breach.
On termination, access stops and data is handled as described in the Privacy Policy.
18. Contact
Questions about these terms should go to the contact address published on our contact page.