---
title: "Terms of Service"
description: "These Terms of Service are the contract between you and Caveman Labs, Inc., a Delaware corporation, for using Caveman Cloud (the hosted gateway, dashboard and control API) and the caveman.so website. "
canonical: https://caveman.so/terms
last-updated: 2026-10-08
status: "in effect"
version: "2026-10-08.1"
effective: "October 8, 2026"
publisher: "Caveman Labs, Inc."
contact: "contact@caveman.so"
---

# Terms of Service

These Terms of Service are the contract between you and Caveman Labs, Inc., a Delaware corporation, for using Caveman Cloud (the hosted gateway, dashboard and control API) and the caveman.so website. They cover plans and fees, your data and how we may use it, AI output, the open-source tools, liability and how disputes are resolved. Questions go to [contact@caveman.so](mailto:contact@caveman.so).

## Summary

The full text below governs. This is the short version.

- These Terms are a contract between you (or the organisation you act for) and Caveman Labs, Inc. for Caveman Cloud (the hosted gateway, dashboard and control API) and the Website.
- The Free plan is for one person; Pay-as-you-go adds a card, members and usage above the free allowances; Enterprise is a signed contract.
- You bring your own Model Provider keys and agreements. You can pass keys with each request or store them with us, encrypted. We add no markup to tokens and do not resell them.
- You own your Customer Data. We keep it until you delete it, and you can set a deletion window. Replay of your stored traffic to Model Providers is on by default for each project, and you can turn it off.
- Product Data Sharing, which lets us use your traffic to improve Caveman's own models, is a condition of the Free plan. On Pay-as-you-go it is off unless an Admin turns it on or the Workspace kept an earlier setting from the former Indie or Team plans. On Enterprise it is never on.
- Paid usage is billed monthly per product, above the free allowances, up to billing limits you set. No fee is ever calculated from a savings figure.
- AI features can be wrong. Savings figures are labelled measured, inferred or verified, and none of them is a guarantee.
- The Open-Source Tools are governed by their own licences.
- Warranties are limited and liability is capped. Delaware law governs, but mandatory consumer and data-protection law where you are still applies.

## 1. Acceptance and eligibility

### Who the contract is between

These Terms of Service (the "Terms") are an agreement between Caveman Labs, Inc. ("Caveman", "we" or "us") and the organisation or individual that accepts them ("Customer" or "you"). "You" includes the Users of your Workspace, for whom you are responsible.

### How these Terms are formed

You accept these Terms in any of these ways:

- by accepting them in the dashboard. When a Workspace first uses the dashboard, and again whenever we publish a new version of these Terms, the dashboard asks an Admin to accept the current version on behalf of the Workspace, and we record that acceptance. Other members see a notice;
- by signing or accepting an Order Form that refers to these Terms; or
- by using the Services after these Terms have been presented to you.

If you do not agree to these Terms, do not use the Services.

### Eligibility

The Services are for business and professional use. To use them you must:

- be at least 18 years old;
- have authority to bind the organisation on whose behalf you accept these Terms;
- not be barred from receiving the Services under the laws of the United States, the European Union, the United Kingdom or any other applicable jurisdiction, including sanctions and export-control laws (see section 24).

If you use the Free plan as an individual, you are treated as acting for business or professional purposes. Where the law of your country nonetheless gives you mandatory consumer rights, nothing in these Terms takes them away.

## 2. Definitions

In these Terms:

- **"Acceptable Use Policy"** means the policy at [/legal/acceptable-use](/legal/acceptable-use).
- **"Account Data"** means information we hold to run your account, such as User names and emails, authentication and session records, security and audit logs, billing details and support correspondence. Our [Privacy Policy](/privacy) covers it.
- **"Admin"** means a User with the owner or admin role in a Workspace.
- **"Affiliate"** means an entity that controls, is controlled by, or is under common control with a party, where "control" means owning more than 50% of the voting interests.
- **"Agreement"** means these Terms, any Order Form, the Data Processing Agreement where it applies, the Acceptable Use Policy, and any other document these Terms incorporate by reference.
- **"Beta Features"** means features we label as alpha, beta, preview, early access, experimental or similar.
- **"Caveman Cloud"** or the **"Services"** means the hosted service we operate, including the LLM gateway at `api.caveman.so`, the dashboard at `app.caveman.so`, the control API, and related features and Documentation. The Services do not include the Open-Source Tools or a Self-Hosted Deployment.
- **"Customer Data"** means data that you or your Users submit to the Services or that the Services generate from your traffic for you, including Payloads, Usage Metadata and Output. Customer Data does not include Account Data.
- **"Data governance"** means the page in the dashboard where Admins manage retention, Product Data Sharing and deletion for a Workspace.
- **"Data Processing Agreement"** or **"DPA"** means the agreement at [/legal/dpa](/legal/dpa).
- **"Documentation"** means the documentation we publish at docs.caveman.so or otherwise provide for the Services.
- **"Model Provider"** means a third-party provider of AI models (for example a large language model API) that you choose to reach through the Services.
- **"Open-Source Tools"** means software and models we publish under an open-source or other public licence, including the `caveman` CLI, the local Proxy and Engine, the Caveman skill, hooks, SDKs, middleware, Caveman Mode, Browse, Caveman Code, cavemem and CaveGemma.
- **"Order Form"** means an ordering document, quote or online checkout for the Services that you and Caveman accept and that refers to these Terms.
- **"Output"** means content returned to you through the Services, including responses from Model Providers and content produced by AI features of the Services.
- **"Payloads"** means the bodies of requests you send through the gateway and of the responses returned to you, such as prompts, messages, tool calls and completions, and the same kinds of content in traces and logs you import.
- **"Plan"** means the Free, Pay-as-you-go or Enterprise plan, or any other plan, that applies to your Workspace. "Paid Plan" means any Plan other than Free.
- **"Product Data Sharing"** means the setting, described in section 7, under which Payloads and Usage Metadata may be used to improve Caveman's own models.
- **"Provider Key"** means an API key, role or other credential you use to access a Model Provider.
- **"Replay"** means the feature, described in section 9, that sends a project's stored Payloads to Model Providers to compare models, build and test changes, and judge results.
- **"Self-Hosted Deployment"** means Caveman Cloud software that you run in your own environment, such as your own Kubernetes cluster or virtual private cloud.
- **"Usage Metadata"** means data about your requests rather than their content, such as model, provider, token counts, cost, latency, status, salted hashes of Payloads, tags, the member user ID, a hashed client user ID, session ID and routing decisions.
- **"User"** means a person you or an Admin authorise to use the Services under your Workspace, such as an employee or contractor.
- **"Website"** means caveman.so and docs.caveman.so.
- **"Workspace"** means your organisation's space in Caveman Cloud, with its own projects, settings, members and data.

Words such as "including" and "for example" mean "including without limitation".

## 3. The Services

### Sign-up and Plans

Where sign-up is open, anyone who meets section 1 can sign up, with an email address and password, Google or GitHub. While Caveman Cloud is in private development, we may limit sign-up to people we invite. Your first sign-in that does not come from an invitation creates a personal Workspace on the Free plan. A Free Workspace is for one person; adding members needs a Paid Plan. We may decline or close a sign-up that we reasonably believe is automated, abusive or in breach of section 24. Features, allowances, limits and Plans will change, and some features in the Documentation may not yet be available to your Workspace.

### What we provide

Subject to these Terms, we grant you a non-exclusive, non-transferable, non-sublicensable right during the term to access and use the Services for your internal business purposes, including to power your own products and services for your own customers.

Unless an Order Form says otherwise, we provide support by email at [contact@caveman.so](mailto:contact@caveman.so) on a reasonable-efforts basis, and we do not commit to any uptime level or service-level agreement.

### Beta Features

We may offer Beta Features. They are optional. They may be incomplete, may change or be withdrawn without notice, and may be less reliable or secure than generally available features. Beta Features are provided "as is", with no warranty, indemnity or support commitment, and the warranty for paid Services in section 21 does not apply to them. Section 7 (Product Data Sharing) applies to Beta Features in the same way as to the rest of the Services.

### Changes to the Services

We may add, change or remove features. If we remove or materially reduce a core feature of a paid Plan you have bought, we will give you at least 30 days' notice where practical, and if the change materially harms you, you may terminate that Plan for a pro rata refund of prepaid fees. We will not make changes that materially weaken the security of the Services during a paid term.

### Deployments in your cloud account

A dedicated Enterprise deployment operated by Caveman in your cloud account, or a Self-Hosted Deployment operated by you where separately agreed, is governed by its separate written agreement (an Order Form or enterprise licence). These Terms apply to that deployment only to the extent that agreement expressly incorporates them. The deployment agreement identifies the account and region, who operates it, Caveman's permitted access, and retention, backup and deletion responsibilities.

The deployment stores request content and operational telemetry in its configured storage to provide platform features. Customer-account deployment does not mean zero data retention. Customer content from Enterprise deployments is not used to improve Caveman's models. Your configured model providers and integrations still receive the data needed for their services.

Where Caveman provides Caveman Cloud source code to you, it is licensed under the Business Source License 1.1 for non-production use; production use requires a commercial licence. Installation licence verification is offline. Separate CLI usage telemetry is on by default and can be disabled as described in the Privacy Policy; support messages and other information you send to Caveman are also covered there. Using Caveman's hosted gateway or hosted routing remains use of the hosted Services.

### The Website

You may browse the Website and use its content for your own information. Its content is general information and may be out of date. Our [Privacy Policy](/privacy) covers waitlist sign-ups, and the Acceptable Use Policy applies to your use of the Website.

## 4. Accounts and Workspaces

### Admins and Users

Admins control a Workspace. They can invite and remove Users on a Paid Plan, assign roles, manage settings, set retention windows, turn payload storage, Replay and Product Data Sharing on or off where your Plan allows it, and connect AI assistants and integrations. The Workspace owner can delete Workspace data. You are responsible for the actions of your Admins and other Users in the Services and for their compliance with these Terms.

### Credentials and security

You must give accurate account information and keep it up to date. Each User must have their own login, and credentials may not be shared between people. You are responsible for keeping credentials secure, including passwords, passkeys, multi-factor authentication devices, session tokens, Caveman API keys and Provider Keys. We recommend that every User turns on multi-factor authentication or a passkey. You must tell us promptly at [contact@caveman.so](mailto:contact@caveman.so) if you believe an account, credential or Workspace has been compromised. We are not responsible for loss caused by credentials that were disclosed, shared or stolen from your side, unless the loss was caused by our breach of these Terms.

## 5. Model Providers and BYOK

### Your own keys and agreements

Caveman Cloud is "bring your own key" (BYOK). You choose the Model Providers your traffic reaches and you use your own Provider Keys. Each request is forwarded to the Model Provider you select under your own agreement with that provider. You are responsible for:

- having a valid agreement and account with each Model Provider you use;
- complying with that provider's terms, usage policies and rate limits;
- paying the provider's charges. We add no markup to tokens, we do not resell them and we do not pay Model Provider charges on your behalf.

### Model Providers are not sub-processors

Model Providers are not Caveman's sub-processors or subcontractors. A Model Provider receiving your data through the Services acts under its agreement with you, as your processor or as an independent controller. We are not responsible for a Model Provider's acts or omissions, availability, outputs, prices or data handling.

### How Provider Keys are handled

You can pass a Provider Key with each request or store it in Caveman Cloud. Stored keys are encrypted with envelope encryption using a dedicated cloud key management (KMS) key. The gateway uses a stored key when a request carries none, and features such as routing through Caveman Cloud, model comparisons, Replay and agent runs use your stored keys. If you connect Amazon Bedrock on hosted Caveman Cloud, you give us a Bedrock API key or AWS access keys, which we store encrypted like other stored keys. Those requests run in, and are billed to, your AWS account. Hosted Caveman Cloud does not assume a role in your AWS account. You may revoke or rotate a Provider Key with the Model Provider, or delete it from Caveman Cloud, at any time.

Model Providers can change or withdraw their models and APIs without notice to us. We do not guarantee that any particular Model Provider or model will remain reachable through the Services.

## 6. Customer Data

### Ownership

As between you and Caveman, you own your Customer Data, including Output, to the extent any rights exist in it. We do not acquire any rights in Customer Data except the limited rights in this section and in section 7.

### Licence to Caveman

You grant Caveman and its sub-processors a worldwide, non-exclusive, royalty-free licence to host, copy, transmit, process and display Customer Data only as needed to:

- provide, maintain, secure and support the Services for you;
- prevent abuse, investigate security incidents and enforce the Acceptable Use Policy;
- comply with law; and
- do anything else you instruct or authorise, including through your settings.

This licence ends when the Customer Data is deleted under section 20. Use for model improvement is covered only by section 7.

### Your responsibilities

You are responsible for your Customer Data and for how you use the Services to process it. You confirm that:

- you have all rights, licences, notices and consents needed to send Customer Data through the Services and to let us process it under the Agreement;
- your Customer Data and its processing through the Services do not infringe anyone's rights or break any law or the Acceptable Use Policy; and
- you have configured your Workspace, including retention, redaction and Product Data Sharing, in a way that fits your legal obligations.

You must not send protected health information under HIPAA or payment card data under PCI DSS on any Plan unless an Order Form allows it. Section 7 adds limits that apply where Product Data Sharing applies.

### Retention controls

Our [Privacy Policy](/privacy) and [Data use summary](/data-use) give the full detail. In outline:

- We keep Customer Data, including Usage Metadata, Payloads, compression originals, imported content and agent artifacts, until you delete it, on every Plan. Admins can set a window, from 1 to 36,500 days, after which it is deleted automatically. By default no window is set. Agent artifacts are kept only while artifact storage is on. It is on for Workspaces that start on Free, and it stays on when they add a card or move to Enterprise. It is off for Workspaces created directly on Pay-as-you-go or Enterprise, including customer-owned installs. An Admin can turn it on or off on every plan.
- Payloads are stored by default. They are redacted where the redaction pipeline applies and encrypted with AES-256-GCM envelope encryption under data keys scoped to your Workspace. Compression originals are exact copies and are not redacted. On a Paid Plan, Admins can turn payload storage off.
- Redacted prompt snippets and embeddings used for traffic analysis and the semantic cache are kept for at most 90 days (semantic-cache samples at most 30 days), and never longer than your window.
- Cached responses are kept for 5 minutes by default and never longer than 24 hours.
- The request header `x-cave-retention: metadata` or `x-cave-retention: zdr` can only tighten retention. Zero data retention (`zdr`) turns off payload storage, compression originals, caching and Replay for that request.

## 7. Product Data Sharing

### What it is

Product Data Sharing lets Caveman use Payloads and Usage Metadata from your Workspace to improve Caveman's own models and services. "Caveman's own models" means Caveman's routing, compression, caching and optimisation models and the evaluations we use to build and test them.

### When it applies

- **Free plan.** Product Data Sharing is a condition of the Free plan, and the Free plan is offered in part in exchange for it (see the Notice of financial incentive in our [Privacy Policy](/privacy)). You agree to it on a separate screen at sign-up. It covers what reaches Caveman Cloud from your Workspace, including recorded requests with their Payloads and, for projects that opt in to router learning, sampled routing-request text. It stays on while the Workspace is on Free. To stop it, add a card to move to Pay-as-you-go, or stop using the Workspace.
- **Pay-as-you-go.** Product Data Sharing is off by default for new Pay-as-you-go Workspaces. It applies if an Admin turns it on in Data governance, and an Admin can turn it off at any time. A Workspace that moves from Free to Pay-as-you-go stops sharing from that moment. Workspaces moved from the former Indie or Team plans kept their earlier setting, which may be on, until an Admin turns it off.
- **Enterprise.** Product Data Sharing never applies and cannot be turned on.

Turning Product Data Sharing off stops new collection for this purpose and deletes the stored copies kept only for it. Training sets already built from that data are not rebuilt with it and are deleted when they expire, at most 365 days after they were built. If your Workspace returns to Free after a failed payment, it keeps its existing setting, and sharing turns back on only if an Owner or Admin turns it on. Deleting Workspace data in Data governance also purges data held under Product Data Sharing. Improvements already made to models, and aggregated or de-identified data, cannot be undone.

### Our commitments

When Product Data Sharing applies:

- we never sell the data;
- we never share it with other customers;
- we never use it to train a third party's general-purpose model;
- we redact Payloads before capture where our redaction pipeline applies;
- data used under Product Data Sharing is kept only while sharing applies to it, and never longer than your own retention window;
- per-request zero data retention (`x-cave-retention: zdr`) still prevents payload storage for that request.

### Our role

For the purpose of improving Caveman's own models, Caveman acts as an independent controller of any personal data in that data, not as your processor. The DPA does not apply to that use. Our [Privacy Policy](/privacy) describes it. If an individual objects to this use, we exclude data we can link to that person (such as their email, member ID or client user ID) from Product Data Sharing, whatever the Plan.

### Cross-customer practice evidence

Cross-customer practice evidence is a separate, project-level opt-in that is off by default and does not follow from Product Data Sharing or your Plan. If a project opts in, only derived before/after metrics, window sizes and a practice ID contribute to aggregate rankings, never prompts, responses, diffs, repository content or organisation identity. Enterprise Workspaces and Workspaces without a known Plan cannot opt in. Revocation applies to the next rollup.

### Your obligations

When Product Data Sharing applies, you confirm that you have the right to share the data with Caveman for this purpose, including any notices to and consents from individuals that the law requires. You must not send special categories of personal data, criminal-offence data or children's personal data through a Workspace where Product Data Sharing applies (always the case on the Free plan).

## 8. Usage Metadata and aggregated data

We use Usage Metadata to provide the Services, including to meter usage, enforce limits, calculate cost and savings, detect abuse and give support.

We may also create aggregated, de-identified statistics, such as total request volumes or error rates by Model Provider, to operate, secure, plan capacity for and report on the Services. Aggregated statistics do not identify you, any User or any individual, and they do not contain Payloads. Unless Product Data Sharing applies, we do not use Usage Metadata or aggregated statistics derived from it to train Caveman's models. We will not attempt to re-identify de-identified data.

## 9. AI features and Output

### AI features

Some features use AI models, for example Ask, briefs, judges, model comparisons and agent runs. On Caveman Cloud they run on your own Provider Keys. By configuring a Provider Key for an AI feature, leaving Replay on for a project, or starting an agent run, you instruct Caveman to send the relevant Customer Data to that Model Provider. At the date of this version, Caveman does not send Customer Data to a model provider under its own account on the Services. Before it does, it will add that provider to the sub-processor list with the notice the DPA requires. We will make it clear in the product when you are interacting with an AI feature or viewing content it generated.

### Replay and work Caveman starts

Replay is on by default for each project. With Replay on, Caveman Cloud may, on its own initiative, send a project's redacted stored Payloads to your Model Providers on your stored keys to look for a cheaper or better setup, build and test changes, and judge the results. This uses your Provider Keys, so your Model Providers will charge you for it. Admins can turn Replay off for each project, and per-request zero data retention excludes a request from it.

If you connect a repository, Caveman's agents may copy its code and history, read your recorded traffic, write tests and open pull requests in that repository. They do not merge pull requests; you decide what to merge.

### Output can be wrong

AI models produce output by probability. Output may be inaccurate, incomplete, offensive, out of date or similar to content produced for others. You must review Output, including any code, pull request, configuration change or recommendation, before you rely on it or put it into production, and you are responsible for what you do with it.

### No professional advice

Output is not legal, financial, medical, tax or other professional advice. Do not use the Services as the sole basis for decisions that produce legal or similarly significant effects on individuals. Caveman does not use the Services to make such decisions about individuals.

### Your own AI systems

If you use the Services to build or operate AI systems for your own users, you are responsible for complying with the laws that apply to those systems, including any duty to tell people that they are interacting with an AI system or viewing AI-generated content.

## 10. Savings figures

The Services show figures about cost and savings. We keep three labels separate:

- **Measured:** figures taken from observed traffic and provider usage.
- **Inferred:** estimates of what a change would save, or would have saved, based on models, catalogues and assumptions.
- **Verified:** savings supported by provider-causal evidence. Only that evidence enters the verified-savings ledger.

Savings figures are informational. Prices come from catalogues that can be incomplete or out of date, and your Model Provider's invoice is the authority on what you were charged. We do not guarantee that you will save any amount. No fee is calculated from a savings figure unless an Order Form expressly says so.

## 11. Acceptable use

You must comply with the [Acceptable Use Policy](/legal/acceptable-use), which forms part of these Terms. Among other things, it prohibits reselling or white-labelling the Services without a written agreement with us, attacking the Services or other tenants, circumventing limits or governance controls, and reverse engineering the Services except as an open-source licence or mandatory law permits.

## 12. Open-Source Tools

The Open-Source Tools are licensed to you under their own licences, which you can read in each repository:

- the `caveman` CLI, local Proxy and Engine, Caveman skill, hooks, SDKs, middleware, the cavemem bundled with the CLI, Caveman Mode and Browse: Apache License 2.0;
- Caveman Code and the standalone cavemem package: MIT License;
- releases published before these licences applied keep the licence they shipped with, for example the MIT License or the Business Source License 1.1;
- CaveGemma model weights: the Gemma Terms of Use, because they are derived from Google's Gemma models.

Those licences govern your use, copying, modification and distribution of that software. Nothing in these Terms limits any right granted by those licences, and these Terms do not impose extra obligations on your use of it. Products we have not released under an open-source licence, such as Pebble, are not Open-Source Tools.

These Terms apply when an Open-Source Tool connects to Caveman Cloud, for example when you sign in from the CLI, when it syncs (which it does automatically once you are signed in) or when you use managed gateway mode. Data it sends to Caveman Cloud on your behalf is Customer Data. Our [Privacy Policy](/privacy) explains CLI telemetry, how to turn it off, and how Caveman Mode handles data.

## 13. Integrations and third-party services

You may connect the Services to third-party services, such as GitHub, a Google account for sign-in or your own OpenID Connect identity provider. Those services are provided by third parties under their own terms. We do not control them and are not responsible for them. By connecting one, you authorise us to exchange data with it as needed to provide the integration.

### GitHub integration

The GitHub integration is optional. On Caveman Cloud you install Caveman's GitHub App on the repositories you choose. It has read access to repository metadata and write access to repository contents and pull requests, and GitHub notifies us when the App is installed or changed and when its pull requests change. The integration can copy repository content and history and open pull requests, and repository-contributor features read commit author names and email addresses. You are responsible for having the right to let us process that data, including contributors' personal data, and for reviewing pull requests before you merge them. You can uninstall the App in GitHub at any time.

## 14. Fees and payment

### Plans and the Free plan

Your Plan determines the features, allowances and limits available to your Workspace. The current products, units, allowances and prices are those shown in the dashboard's billing page when you incur the usage.

- **Free** costs nothing and needs no card. When a product reaches its monthly allowance, the gateway keeps forwarding your requests but stops recording them, no new agent run starts, and routing hands back to your local setup, until the next month or until you add a card. The Free plan is subject to Product Data Sharing as described in section 7. We may change or discontinue the Free plan with at least 30 days' notice.
- **Pay-as-you-go** needs a card on file. It includes the same monthly allowances as Free, then charges for each product's usage above its allowance at graduated per-unit prices. Optional packages add features for a flat monthly fee.
- **Enterprise** is priced in an Order Form and is not metered by the Services unless the Order Form says so.

### Billing limits

On Pay-as-you-go, each product has a billing limit in US dollars, which you can change. We email Workspace owners and Admins when a product reaches 80% and 100% of its limit. When a product reaches its limit, or its allowance on Free, we stop charging for it for the rest of the billing period. Gateway requests are still forwarded to your Model Providers but are no longer recorded, and other products pause until the next billing period or until you raise the limit. Model Provider charges are not Caveman fees and are not covered by billing limits.

### Invoicing and payment

Usage fees are charged monthly in arrears, and package fees monthly in advance, unless your Order Form says otherwise. You authorise us and our payment processor, Stripe, to charge your card when fees are due. Order Form invoices are payable within 30 days of the invoice date. If a card payment fails and is not fixed within the grace period set in our billing system, currently seven days, the Workspace returns to the Free plan: existing members keep their access and their traffic keeps flowing, but nobody new can be added until a card is back.

No fee, credit, rebate or discount is calculated from a savings figure, unless an Order Form for an Enterprise Plan expressly says so.

### Taxes

Fees do not include taxes. You are responsible for all sales, use, value added, goods and services, withholding and similar taxes on the fees, except taxes on Caveman's net income. Where a reverse-charge mechanism applies, you account for the tax.

### Late payment

For fees invoiced under an Order Form, we may charge interest on overdue undisputed amounts at 1% per month or the highest lawful rate, whichever is lower, and if an amount is more than 15 days overdue, we may suspend paid features after at least 10 days' notice by email. If you dispute an invoice in good faith, tell us before the due date and pay the undisputed part.

### Refunds and price changes

Fees are non-refundable, except where these Terms or your Order Form say otherwise or where the law requires a refund.

We may change our prices. We give at least 60 days' notice of a price rise by email to Workspace owners, and the new price applies from the first monthly billing period that starts after the notice period. If you do not agree, you may leave Pay-as-you-go or cancel a package before then. Prices fixed in an Order Form apply for the term of that Order Form.

## 15. Confidentiality

### What is confidential

"Confidential Information" means non-public information that one party (the "Discloser") discloses to the other (the "Recipient") under the Agreement that is marked confidential or that a reasonable person would understand to be confidential. Your Customer Data is your Confidential Information. Non-public parts of the Services, Order Form pricing and our security information are ours.

Confidential Information does not include information that the Recipient can show: is or becomes public without its fault; it already lawfully knew without a duty of confidence; it lawfully receives from a third party without a duty of confidence; or it develops independently without using the Discloser's information.

### Obligations

The Recipient will use Confidential Information only to perform the Agreement or exercise its rights under it, and will protect it with at least reasonable care. It may share Confidential Information only with its and its Affiliates' employees, contractors, sub-processors and advisers who need to know it and are bound by equivalent confidentiality duties. It may disclose Confidential Information where the law or a court requires, after giving the Discloser prompt notice where lawful.

Caveman's use of Customer Data under section 7 (Product Data Sharing), when that section applies, is not a breach of this section. Our commitments in section 7 still apply to that data.

These obligations last for the term and five years after it, and for trade secrets and Customer Data for as long as the information remains a trade secret or is held by the Recipient.

## 16. Privacy and data protection

Our [Privacy Policy](/privacy) explains how we handle personal data as a controller, including Account Data and data used under Product Data Sharing.

Where Caveman processes personal data in Customer Data on your behalf, and the EU General Data Protection Regulation, the UK GDPR, the California Consumer Privacy Act or a similar law applies, the [Data Processing Agreement](/legal/dpa) forms part of these Terms and governs that processing. In that case you are the controller (or business) and Caveman is your processor (or service provider).

We use sub-processors to provide the Services. Our current list is at [/legal/subprocessors](/legal/subprocessors). We will give at least 30 days' notice before adding or replacing a sub-processor, and you may object as the DPA describes. Model Providers you choose are not on that list because they are not our sub-processors (see section 5).

We host Caveman Cloud on Google Cloud in the europe-west4 region in the Netherlands. Some of our vendors, including Cloudflare, process data on global networks, and Caveman staff may access data from outside the European Economic Area. Where personal data is transferred outside the EEA, the UK or Switzerland, we rely on the EU Standard Contractual Clauses (Module 1 for data we receive as an independent controller, such as Account Data and data used under Product Data Sharing; Modules 2 and 3 for data we process for you), the UK Addendum, the Swiss amendments or another lawful transfer mechanism.

If we are required to appoint a representative in the EU or UK under Article 27 GDPR / UK GDPR, we will list their details here.

## 17. Security

We maintain reasonable technical and organisational measures designed to protect the Services and Customer Data against unauthorised access, loss and disclosure. The security section of our [Privacy Policy](/privacy) describes them. Unless an Order Form says otherwise, we do not commit to any third-party security certification or audit report.

If we become aware of a breach of security that leads to unauthorised access to, or the accidental or unlawful destruction, loss or disclosure of, your Customer Data, we will notify you without undue delay and, where feasible, within 72 hours of becoming aware, and give you the information you reasonably need. The DPA sets out the timing and content of notices for personal data.

You are responsible for the security of your own systems and for configuring the Services' security and governance settings to suit your needs.

## 18. Intellectual property and feedback

### Caveman's rights

Caveman and its licensors own the Services, the Documentation, Caveman's models, and all improvements and derivative works of them, including all intellectual property rights in them. Except for the rights expressly granted in these Terms, and your rights under the open-source licences described in section 12, no rights are granted to you. "Caveman" and our logos are trademarks of Caveman or its licensors. You may not use them without permission, except to refer to our products accurately.

### Feedback

If you give us suggestions, ideas or other feedback about the Services, we may use it without restriction or payment to you. Feedback does not include your Customer Data, and giving feedback does not give us any right in your Customer Data.

## 19. Suspension

We may suspend or limit your access to all or part of the Services if we reasonably believe that:

- your use poses a security risk to the Services, to a Model Provider or to another customer;
- you or your Users are in material breach of the Acceptable Use Policy;
- your use is unlawful or exposes Caveman to legal liability;
- an amount is overdue as described in section 14; or
- a law, court, regulator or Model Provider requires it.

We will limit any suspension to what is reasonably necessary. Where practical and lawful, we will give you notice, the reason and a chance to fix the problem first. For urgent risks we may suspend first and tell you afterwards. We will restore access promptly once the cause is resolved. Fees that are due remain payable.

## 20. Term, termination and data

### Term

These Terms apply from acceptance until all Order Forms and subscriptions have ended and you stop using the Services.

### Termination by you

You may stop using the Services at any time. You can delete your Workspace data in Data governance. To close your account or Workspace, write to [contact@caveman.so](mailto:contact@caveman.so). If you leave Pay-as-you-go, we charge usage up to the end of the current billing period and any package fee already paid for it, and nothing after. Except where these Terms provide for a refund, you are not entitled to one for an early cancellation.

### Termination by Caveman

We may terminate the Free plan, or your access to the Services while you use only the Free plan, with at least 30 days' notice. We may terminate a paid subscription for convenience with at least 30 days' notice, in which case we will refund prepaid fees for the unused part of the term.

### Termination for cause

Either party may terminate the Agreement, or an affected Order Form, by notice if the other party materially breaches it and does not cure the breach within 30 days after receiving notice describing it. Either party may also terminate by notice if the other becomes insolvent, makes a general assignment for the benefit of creditors, or becomes subject to bankruptcy, administration or similar proceedings that are not dismissed within 60 days. We may terminate immediately by notice for a serious or repeated breach of the Acceptable Use Policy or of section 24.

If you terminate for our uncured material breach, we will refund prepaid fees for the unused part of the term.

### Effect of termination

When the Agreement or an Order Form ends, your right to use the affected Services ends and you must pay all fees due up to the end date. Export and deletion work as described below.

### Data export

You can export Customer Data during the term and for 30 days after the Agreement ends (longer where the switching rules below apply). Export means the export tools in the Services plus reasonable assistance from us on request. The export tools document the formats and structures of the data they produce.

### Deletion

Workspace data deletion requested in Data governance is carried out 30 days after the request and also purges data held under Product Data Sharing, although improvements already made to models, and aggregated or de-identified data, cannot be undone. A daily process removes data whose retention window has expired. We delete remaining Customer Data within 30 days after the export period ends. Copies in database backups, point-in-time recovery logs and object versions roll off within about 35 days after deletion. Rows deleted from our analytics database by a retention window can stay on disk, and in backups taken in that time, for up to about two months in total. If an Admin lengthens or removes the window after rows were deleted, those rows can stay on disk until the database merges them or the Workspace is deleted. We may keep data where the law requires it, and we keep Account Data as our Privacy Policy describes.

### Switching providers (EU Data Act)

This subsection applies to the extent that Regulation (EU) 2023/2854 (the "Data Act") applies to your use of the Services.

- **Request.** You may ask to switch to another provider of data processing services or to your own infrastructure, or to have your exportable data erased. You give notice by writing to [contact@caveman.so](mailto:contact@caveman.so). The notice period is no more than two months.
- **Transition.** After the notice period, a transitional period of 30 days begins. During it, we continue to provide the Services, give you reasonable help with the switch, and export your exportable data and digital assets. If a 30-day transition is technically unfeasible, we will tell you within 14 working days of your request, explain why, and propose an alternative period of no more than seven months, during which the Services continue. You may extend the transitional period once, by a period you consider more appropriate for your purposes.
- **Exportable data.** Exportable data means the input and output data that you or your Users generated through your use of the Services, including Usage Metadata, stored Payloads, imported content, Output, and your Workspace configuration such as projects, routing and gateway settings, budgets and labels. It excludes Caveman's software, models, Documentation and other assets protected by Caveman's intellectual property rights or trade secrets, and Caveman's own security and operational data.
- **Retrieval and erasure.** You may retrieve your exportable data for at least 30 days after the transitional period ends. After that, and once the switch is complete, we erase your exportable data and digital assets.
- **End of contract.** The affected Agreement ends when the switch is completed, or at the end of the notice period if you only asked for erasure. We will confirm this to you.
- **Charges.** We will not impose switching or data egress charges except where and to the extent the Data Act permits them, and any such charges will not exceed our costs directly linked to the switch.

Nothing in this subsection limits rights you have under the Data Act.

## 21. Warranties and disclaimers

### Mutual warranties

Each party warrants that it has the power and authority to enter into the Agreement, and that it will comply with the laws that apply to its performance under the Agreement.

### Caveman's warranty for paid Services

We warrant that paid Services will be provided with reasonable skill and care and will perform materially as described in the Documentation during the paid term. If they do not and you tell us within 30 days, we will use reasonable efforts to correct the problem. If we cannot do so within a reasonable time, either party may terminate the affected paid Plan and we will refund prepaid fees for the unused part of the term. This is your sole remedy for breach of this warranty. It does not apply to the Free plan, Beta Features, Open-Source Tools, Model Providers, third-party services, or problems caused by your misuse or modification.

### Your warranties

You warrant that you have the rights described in sections 6 and 7 and that your use of the Services complies with the Agreement and with the terms of each Model Provider you use.

### Disclaimers

Except as expressly stated in these Terms, and to the maximum extent the law allows, the Services, Output, savings figures, the Free plan, Beta Features and the Website are provided "as is" and "as available", and Caveman disclaims all other warranties, express, implied or statutory, including merchantability, fitness for a particular purpose, title, non-infringement and accuracy. We do not warrant that the Services will be uninterrupted or error-free, that Output will be accurate, or that you will achieve any saving.

## 22. Indemnification

### Indemnity by Caveman

Caveman will defend you against any claim brought by a third party alleging that your use of the paid Services in accordance with the Agreement infringes or misappropriates that third party's patent, copyright, trademark or trade secret, and will pay the damages, costs and reasonable legal fees finally awarded against you, or agreed in a settlement we approve, for that claim.

We have no obligation for claims arising from: Customer Data or Output; Model Providers or third-party services; Open-Source Tools; the Free plan or Beta Features; combination of the Services with anything we did not provide, where the claim would not exist without it; modifications not made by us; use after we told you to stop because of a possible claim; or your breach of the Agreement.

If the Services are, or we think are likely to be, subject to such a claim, we may at our option and expense get you the right to keep using them, modify them so they no longer infringe without materially reducing functionality, or, if neither is commercially reasonable, terminate the affected Services and refund prepaid fees for the unused part of the term. This subsection states our entire liability and your exclusive remedy for third-party intellectual property claims.

### Indemnity by Customer

You will defend Caveman and its Affiliates, officers, employees and contractors against any claim brought by a third party arising from:

- your breach of your obligations in section 6 (Your responsibilities) or section 7 (Your obligations), including a failure to have the rights, notices or consents those sections require;
- your or your Users' use of the Services in breach of the Acceptable Use Policy or the law; or
- any dispute between you and a Model Provider,

and you will pay the damages, costs and reasonable legal fees finally awarded against us, or agreed in a settlement you approve, for that claim.

### Procedure

The defended party must promptly notify the defending party of the claim (a delay reduces the obligation only to the extent it causes prejudice), give it sole control of the defence and settlement, and cooperate reasonably at its expense. The defending party may not settle in a way that admits fault for, or imposes an obligation on, the defended party without that party's written consent, not to be unreasonably withheld. The defended party may take part with its own counsel at its own cost.

## 23. Limitation of liability

### Excluded damages

To the maximum extent the law allows, neither party is liable to the other for any indirect, incidental, special, consequential, exemplary or punitive damages, or for any loss of profits, revenue, business, goodwill or anticipated savings, loss or corruption of data, or cost of substitute services, arising out of or in connection with the Agreement, however caused and on any theory of liability, even if it was advised of the possibility. The exclusion of loss or corruption of data does not apply to loss caused by Caveman's breach of section 17 (Security) or the DPA.

### Cap

To the maximum extent the law allows, each party's total liability arising out of or in connection with the Agreement is limited to the greater of (a) the fees paid and payable by you to Caveman under the Agreement in the 12 months immediately before the event giving rise to the claim, and (b) USD 100.

### Higher cap for data protection

For Caveman's breach of section 15 (Confidentiality), section 17 (Security) or the DPA, Caveman's total liability is instead limited to the greater of (a) two times the amount of the cap above and (b) USD 25,000.

### Exceptions

The exclusions and caps above do not apply to:

- liability for fraud or fraudulent misrepresentation;
- liability for gross negligence or wilful misconduct, where the applicable law does not allow it to be limited;
- a party's obligations under section 22 (Indemnification);
- your obligation to pay fees; or
- your breach of the Acceptable Use Policy.

### Mandatory law

Nothing in the Agreement excludes or limits any liability that cannot be excluded or limited under applicable law, such as liability for death or personal injury caused by negligence. Where the law limits how far liability may be excluded, our liability is limited to the fullest extent the law allows.

## 24. Export controls, sanctions and anti-corruption

### Export controls and sanctions

The Services and Open-Source Tools are subject to export-control and sanctions laws, including the US Export Administration Regulations, US Office of Foreign Assets Control sanctions, and EU and UK export-control and sanctions law. You confirm that neither you nor any User is located in, organised under the laws of, or ordinarily resident in a country or region subject to comprehensive sanctions, and that none of you is named on, or owned or controlled by a party named on, a restricted-party or sanctions list. You will not access, use, export or re-export the Services in breach of these laws, including for any prohibited end use. Model Providers may impose their own geographic restrictions.

### Anti-corruption

Neither party will offer, give, request or accept any bribe or improper payment in connection with the Agreement, and each party will comply with applicable anti-corruption laws, including the US Foreign Corrupt Practices Act and the UK Bribery Act 2010.

## 25. US government end users

The Services and Documentation are "commercial products", "commercial computer software" and "commercial computer software documentation" as those terms are used in the Federal Acquisition Regulation (FAR 2.101 and 12.212) and the Defense Federal Acquisition Regulation Supplement (DFARS 227.7202). US government end users receive only the rights granted to all other customers under these Terms.

## 26. Governing law and disputes

### Governing law

The Agreement and any dispute arising out of or in connection with it are governed by the laws of the State of Delaware, USA, without regard to its conflict-of-laws rules. The United Nations Convention on Contracts for the International Sale of Goods does not apply.

### Courts

Each party agrees to the exclusive jurisdiction of the state and federal courts located in Wilmington, Delaware for any such dispute.

### Mandatory law and injunctive relief

This section does not deprive you of the protection of mandatory consumer-protection or data-protection law of the country where you are based, or of your right to bring a claim or complaint where that law allows. Either party may seek injunctive or other equitable relief in any court of competent jurisdiction to protect its intellectual property, its Confidential Information or the security of the Services.

## 27. Changes to these Terms

These Terms are versioned. The version tag appears at the top of this page.

We may change these Terms. For a material change, we will give at least 30 days' advance notice by email to your Admins and by a notice on this page. When we publish a new version, the dashboard asks an Admin to accept it for the Workspace, and other members see a notice. Non-material changes, such as corrections, take effect when published. Where the law or security requires it, a change may take effect immediately, and we will tell you as soon as we reasonably can.

If you do not agree to a new version, stop using the Services. If you notify us before it takes effect, you may terminate a paid subscription and we will refund prepaid fees for the unused part of the term. Order Forms change only by written amendment accepted by both parties.

## 28. Publicity

We will not use your name, logo or trademarks to identify you as a customer without your prior permission, which an authorised person may give by email. You may withdraw permission at any time, and we will stop new uses within a reasonable time.

## 29. Illegal content and the Digital Services Act

### Point of contact

Our single point of contact for authorities of EU Member States, the European Commission and the European Board for Digital Services, and for recipients of our services, under Articles 11 and 12 of the EU Digital Services Act (Regulation (EU) 2022/2065), is [contact@caveman.so](mailto:contact@caveman.so). You can write to us in English or Dutch.

Caveman will designate a legal representative in the EU where Article 13 of the Digital Services Act requires it and publish the details here.

### Reporting illegal content

Anyone may tell us about content on or through our services that they believe is illegal by writing to [contact@caveman.so](mailto:contact@caveman.so). To help us act, a notice should include:

- a clear explanation of why you believe the content is illegal;
- where the content is, such as a URL, Workspace or request identifier, or other information that lets us find it;
- your name and email address, unless the notice concerns child sexual abuse material or another offence for which the law does not require this; and
- a statement that you believe in good faith that the information in the notice is accurate and complete.

We will confirm receipt, review the notice in a timely, diligent, non-arbitrary and objective manner, and tell you our decision and how you can seek redress. If we restrict a customer's content or account because it is illegal or breaches these Terms, we will give that customer a clear statement of reasons, unless the law prevents us or the content is high-volume deceptive commercial content. The customer may contest the decision by replying to our notice. If we suspect a criminal offence involving a threat to the life or safety of a person, we will inform the competent authorities.

## 30. General

### Force majeure

Neither party is liable for a delay or failure to perform caused by events beyond its reasonable control, such as natural disasters, war, epidemics, government action, failures of public networks or power, or outages at a Model Provider or infrastructure provider. This does not excuse your obligation to pay fees. If such an event prevents performance of a paid Service for more than 30 days, either party may terminate the affected Order Form by notice and we will refund prepaid fees for the unused part of the term.

### Assignment

Neither party may assign the Agreement without the other's prior written consent, not to be unreasonably withheld. Either party may, however, assign the Agreement in full with notice but without consent to an Affiliate or to a successor in a merger, acquisition, corporate reorganisation, change of control or sale of all or substantially all of its assets or of the relevant business, if the assignee is not a sanctioned party and agrees to be bound. Any other attempted assignment is void.

### Notices

We may send you notices by email to your Workspace owner or Admins, or in the dashboard. You must send notices to us by email to [contact@caveman.so](mailto:contact@caveman.so). Notices of breach, termination or legal claims to Caveman must also be sent to Caveman Labs, Inc., 1209 Orange Street, Corporation Trust Center, Wilmington, Delaware 19801, United States. An email notice is treated as received on the next business day after it is sent, unless the sender receives a delivery-failure message.

### Independent contractors

The parties are independent contractors. The Agreement does not create a partnership, franchise, joint venture, agency, fiduciary or employment relationship.

### No third-party beneficiaries

The Agreement does not give rights to anyone other than the parties, except that persons entitled to be defended under section 22 may rely on that section.

### Entire agreement and order of precedence

The Agreement is the entire agreement between the parties about its subject matter and replaces all prior agreements and understandings about it. Terms in a purchase order or other document you send are void, even if we accept or sign it. If documents conflict, this order of precedence applies. For the processing of personal data: (1) the Standard Contractual Clauses, where they apply, (2) an Order Form, only to the extent it expressly changes the DPA, (3) the DPA, (4) these Terms, (5) the Acceptable Use Policy, (6) other policies referred to in these Terms. For everything else: (1) an Order Form, (2) these Terms, (3) the Acceptable Use Policy, (4) other policies referred to in these Terms.

### Severability and waiver

If a provision is found unenforceable, it will be enforced to the maximum extent possible and the rest of the Agreement stays in effect. A delay in enforcing a provision is not a waiver, and waivers must be in writing.

### Survival

Sections that by their nature should survive termination survive it, including sections 2, 6 (Ownership and Your responsibilities), 7 (Our commitments and Our role), 8, 10, 14 (for amounts due), 15, 18, 20 (Effect of termination, Data export, Deletion and Switching providers), 21 (Disclaimers), 22, 23, 24, 26 and 30.

### Language

These Terms are written in English. If we provide a translation, the English version controls to the extent permitted by law.

### Electronic acceptance

Accepting these Terms electronically, including by clicking, in the dashboard or through an online Order Form, has the same effect as a handwritten signature.

## 31. Contact

Caveman Labs, Inc.

1209 Orange Street, Corporation Trust Center, Wilmington, Delaware 19801, United States

Email: [contact@caveman.so](mailto:contact@caveman.so)

To talk to us, you can also book a call at [cal.com/caveman/chat](https://cal.com/caveman/chat).
