Legal · Terms

Terms of service.

The agreement between you (Customer) and CloakAPI AS (Provider) governing use of the gateway, portal, desktop client, receipt-verifier, and supporting APIs.

Version 2.2 · Published 2026-10-05 · Effective 2026-10-05 for new accounts and 2026-11-04 for accounts established before that date (30 days' notice, section 3) · Governing law: Norway

1. Acceptance & scope

By creating a CloakAPI account or sending a request through the gateway, you agree to these Terms. Enterprise customers with a counter-signed Master Service Agreement are governed by that MSA; these Terms back-fill anything the MSA does not address.

These Terms govern the CloakAPI developer platform only: the gateway at api.cloakapi.io, official client SDKs, the local MCP server, cloak-proxy, the desktop client, the browser extension, the web chat and portal at app.cloakapi.io, the receipt-verifier, and the documentation at docs.cloakapi.io.

Products this document covers (the CloakAPI platform). The REST API at api.cloakapi.io; official client SDKs (Go, Java, .NET, PHP, Ruby, Python, Rust); the local MCP server (Model Context Protocol); the local proxy (cloak-proxy); the desktop application for Windows; the browser extension for Chrome; and the web chat and developer portal at app.cloakapi.io. Chat and portal are offered principally as a developer console. Individuals may use them. Usage on those surfaces is billed against the customer's CloakAPI prepaid balance at the platform markup rates published at cloakapi.io/pricing (15 % pooled keys, 5 % BYOK, 5 % complete-local), not as a separate consumer subscription.

Products this document does not cover. The first-party end-user applications published under their own names and hostnames — including cloak-cv, cloak-write, cloak-convert, cloak-docs, cloak-meet, cloak-post, cloak-scan, cloak-sheets, cloak-translate, cloak-redact, and cloakup — are separate products. Each has its own price, published on that application's /pricing page. Those prices are not the platform SLA and are not interchangeable. Where an application relays through the platform, that relay is processed under this document in CloakAPI's capacity as platform operator; the application's end user is not the platform Controller unless they also hold a CloakAPI developer account. See Consumer application terms.

Fees for the platform are the markup rates at /pricing (machine-readable docs/pricing/price-book.json). End-user applications listed in the Consumer application terms are billed on those applications' own pricing pages and are not governed by the platform fee schedule below except to the extent an application, acting as a platform customer, consumes prepaid markup.

2. Customer responsibilities

3. Provider responsibilities

4. Fees & billing

The price book is published at /pricing and machine-readably at docs/pricing/price-book.json. CloakAPI charges a markup on the underlying provider cost: 15% for CloakAPI keys (pooled provider keys), 5% for BYOK (bring your own provider keys), 5% for Complete-local (self-hosted / desktop model).

Rate changes. We may change our markup rates and fees at any time. A change takes effect for prepaid pay-as-you-go usage on the next call made after the change is published (each call is billed at the markup in effect when the call is made, per that call's receipt), and for established accounts after 30 days' advance notice under §3. Your continued use of the Service after a change takes effect constitutes acceptance of the revised rates.

Pricing accuracy. The per-model provider prices we display — in the portal, the AI model selector, and the price book — are based on each provider's own published pricing, which we track on a best-effort basis. A displayed price may occasionally be out of date or incorrect, and some providers use dynamic, variable, or individually negotiated pricing that we can only stipulate or estimate in advance. We reserve the right to correct any displayed or quoted price. The authoritative amount charged for any individual call is the amount recorded on that call's receipt, which reflects the actual provider cost plus the applicable markup at the time of the call.

Prepaid balance accounts are debited per call. Postpaid invoiced accounts settle monthly, net-30. Disputes must be raised within 60 days of invoice date.

Taxes: prices exclude VAT. Norwegian VAT is added where applicable. Reverse charge applies for B2B EU customers with a valid VAT ID.

5. Intellectual property

You retain all rights to your prompts, responses, and any data you process through the Service. We retain all rights to the Service software, the receipt-chain protocol implementation, the detector library, and the brand. The OpenReceipt spec is licensed under CC-BY 4.0.

6. Confidentiality

Each party will protect the other party's confidential information with the same care it gives its own (and not less than reasonable). Account data, support communications, and contract terms are confidential. The receipt chain itself is public by design (the value of the spec depends on it).

7. Warranties & disclaimers

We warrant that the Service performs materially as documented. EXCEPT FOR THIS, THE SERVICE IS PROVIDED “AS IS” WITHOUT IMPLIED WARRANTIES, INCLUDING MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, AND NON-INFRINGEMENT.

7a. Scope of privacy protection — what CloakAPI does NOT protect against

CloakAPI tokenises detected personal data before it reaches the AI provider — a real but bounded guarantee. Being explicit about its limits is part of the product. The following are out of scope; evaluate them against your own threat model. The full technical threat model is public at docs.cloakapi.io/security/threat-model.

7b. Known limitations

Personal-data detection runs on the client device and is best-effort and probabilistic. It can miss personal data, and it can incorrectly flag ordinary text. Results can vary by data type, language or script, and formatting, including punctuation, spacing, line breaks, and address layout. The service does not perform server-side PII detection or tokenisation of user content. Review the content your client displays before sending; detection does not guarantee that every personal-data value will be found or removed. Where this site describes personal data as replaced or removed before content leaves your device, it refers to the values the detector finds; it does not promise that all personal data is found.

Measured examples

These measurements describe the listed test material. They are not an estimate of the share of all requests that contain missed data, and they do not guarantee results for other content, routes, or versions.

File and image content

Handling of file and image content differs between clients and file types. Review of the prepared content before sending has only been tested for plain-text files, in test builds of two clients (the browser extension and CloakAPI Convert); it has not been tested for other file types, images or routes, or for every released build, and not every client shows the prepared content before sending. The browser extension's test of PDF files used a fixed synthetic substitute, so extraction, review and sending of real PDF and image content have not been tested end to end. Some clients, such as the browser extension, can let you choose to send a file unchanged when it cannot be processed; in that case the original file goes to the AI provider you chose. Check what your client shows before you send, and do not send files or images you are not prepared to share with the provider.

8. Liability cap

Each party's aggregate liability under these Terms is capped at the fees paid to CloakAPI in the 12 months preceding the incident. Neither party is liable for indirect, incidental, consequential, or lost-profit damages. The cap does not apply to (a) breach of confidentiality, (b) gross negligence or wilful misconduct, or (c) IP-infringement indemnification.

9. Indemnification

We will defend you against third-party claims that the Service, used as documented, infringes their IP. You will defend us against claims arising from your use of the Service in violation of these Terms or applicable law.

10. Termination

Either party may terminate for material breach with 30 days' written notice and a cure period. You may close your account at any time from the portal. We will delete your account residuals within 30 days, retaining only what bookkeeping, tax and audit obligations require — invoices and financial records for the Bokføringsloven statutory minimum of 5 years (plus any legal-hold), pseudonymised.

11. Governing law & venue

These Terms are governed by Norwegian law. Disputes are resolved in Oslo District Court (Oslo tingrett), subject to any consumer-protection rights you have under your country of residence.

12. Contact

Legal: legal@cloakapi.io · Privacy/DPO: dpo@cloakapi.io · Security: security@cloakapi.io

Related documents