These terms govern your company’s use of Roar AI Cloud — the AI gateway, the app hosting platform, the console, the documentation, and every API and interface we provide alongside them. We call all of it the service. Where these terms say you, they mean the company that holds the account, not the individual reading this page.
By creating an account, accepting an invitation to one, or calling the API with a key issued to your account, you agree to these terms. If you do not agree to them, do not use the service.
How we handle personal data is set out separately in our Privacy Policy, which forms part of this agreement.
01Who this agreement is between
The service is operated by [LEGAL: full registered legal entity name], of [LEGAL: registered address] (“Roar AI”, “we”, “us”). The agreement is between that entity and the company whose account is in question.
The service is sold to organisations, not to consumers. The person who opens an account confirms they are authorised to bind their company to these terms. If a separate signed order form or agreement exists between us and your company, it takes precedence over anything on this page that conflicts with it.
02Accounts and eligibility
Access is invite-only. An account exists because we created it or because we approved a request for one, and a requested account has no access until an operator approves it. We may decline a request without giving a reason.
Each account has an owner — the person responsible for billing and for who else can get in. You are responsible for keeping your account’s details accurate, for the security of the credentials issued to your people, and for everything done through your account, whether or not you intended it.
API keys are the account’s credentials. We store only a hash of each key, so we cannot recover one for you — a lost key is replaced, not retrieved. Keys must not be shared outside your company, committed to a public repository, or embedded in software you distribute to people outside your organisation. Tell us promptly at [LEGAL: security contact email] if you believe a key or an account has been compromised, and revoke the key from the console yourself in the meantime.
Account holders and users must be at least [LEGAL: minimum age for account holders] years old.
03Your people and their access
The service is designed so your company administers itself. An owner can invite colleagues, place them in projects, and set what each of them may do — including who can read stored request content and who can see spend. Those choices are yours to make and yours to review.
Everyone you invite is your responsibility. You must make sure they use the service in line with these terms and with your own internal policies, and you must remove access when someone leaves. We act on the permissions your account has configured; we do not second-guess them.
04Acceptable use
You may not use the service, or allow anyone using your account to use it, to:
- break any law that applies to you or to us, or infringe anyone’s intellectual property or privacy rights;
- produce or distribute material that sexually exploits children, incites violence, harasses or defames a person, or is designed to deceive people about who is speaking to them;
- build or operate anything that attacks other systems — malware, credential harvesting, phishing, denial of service, unsolicited bulk messaging, or the scanning and probing of networks you do not own;
- attempt to reach data, accounts or infrastructure that are not yours; probe, reverse-engineer or circumvent the platform’s security, rate limits, spend controls or tenancy boundaries;
- resell the gateway as a general-purpose inference API to the public, or otherwise present the service as your own product to parties outside your organisation, unless we have agreed to that in writing;
- deliberately degrade the platform for other customers — for example by generating load intended to exhaust a shared resource rather than to serve your own users.
Some models are served by third parties whose own acceptable-use rules apply on top of this section. See section 8.
We do not routinely monitor the content of your requests or the code you deploy, and nothing in this section obliges us to. Where we do become aware of a breach, section 12 applies.
05Your content, and who owns it
Your content stays yours. The prompts, files and data you send to the gateway, the source code you deploy, and the data your applications and databases hold are your property. We claim no ownership of any of it, and we acquire no licence to it beyond what is needed to operate the service for you — routing your requests, running your applications, storing your data, backing it up, and providing support when you ask for it.
You are responsible for having the right to send us what you send us, including where it contains someone else’s personal data or confidential information.
Some content is retained for a limited period so the platform can show you what happened — request and response bodies, usage records, and your applications’ traffic logs. Retention windows, encryption, and the controls you have over them, including turning content logging off, are described in the Privacy Policy.
Our side. The platform itself — the console, the gateway, the deployment tooling, our documentation and everything we build — remains ours. These terms grant you the right to use it, not to copy it.
06Model output
Model output can be wrong. Language models produce text that is plausible before it is correct. Output may be inaccurate, out of date, biased, or entirely invented, and the same prompt can produce different answers on different occasions. This is a property of the technology, not a fault in the service.
You decide what to do with what a model returns, and you are responsible for that decision. Review output before you act on it, and do not rely on it unreviewed for medical, legal, financial, safety or employment decisions, or for anything else where being wrong causes harm. We make no representation that output is accurate, complete, fit for a particular purpose, or free of third-party rights.
Output is not guaranteed to be unique — a model may return substantially similar text to two different customers.
The platform offers configurable guardrails, including detection and redaction of sensitive strings before a request leaves for an external provider. These are a control you configure, not a guarantee: pattern-based detection misses things, and you should not treat it as a substitute for keeping sensitive data out of a prompt in the first place.
07Applications you deploy
App hosting runs code you supply. You connect a source repository, we build it and run it on our infrastructure, and we give it a URL and, where you ask for one, a database. Everything about that code remains yours: what it does, whether it is secure, what it collects from the people who visit it, what licences it depends on, and whether it complies with the law wherever its users are.
You are the operator of your application, and we are the platform under it. We do not review your code, and running it is not an endorsement of it. If your application processes personal data, you are the party responsible to those people for it.
We may stop a hosted application, or the traffic reaching it, without prior notice where it is unlawful, where it is causing harm to others, where it breaches section 4, or where it is destabilising the shared infrastructure it runs on. We will tell you why as soon as we reasonably can, and we will restore it once the cause is resolved. Stopping an application does not delete it or its data.
Resource limits apply to hosted applications, and the platform enforces them. Applications are not exempt from the acceptable-use rules in section 4 simply because the code is yours.
08Third-party model providers
The gateway reaches models that we serve and models served for us by third-party providers. We choose which route serves each model, and that choice is part of what you are buying — it is what makes a model behave consistently from one call to the next.
Where a request is served by a third-party provider, that provider’s own usage policies apply to it in addition to these terms, and we may pass on restrictions they impose. We do not control their availability, their pricing, their model versions, or their decision to withdraw a model. A model can be deprecated, changed, or removed by the party that makes it, and we may have to withdraw or replace it at short notice as a result.
We may change how a model is served — including which provider serves it — without notice, provided the model you asked for is the model that answers.
09Where the service runs
Applications and their databases run on infrastructure we operate in the market they are placed in. Where your account is configured for in-region processing or in-region storage, we place your workloads accordingly.
During a declared incident, data may be recovered in another region so the service can be restored. We do not continuously replicate customer data across borders outside of that. If a stricter residency arrangement is required for your organisation, it has to be agreed with us in writing — it is not something the standard terms provide.
We use third-party infrastructure providers to operate parts of the platform. We remain responsible to you for the service under these terms regardless of who supplies the underlying capacity.
10Fees, credits and budgets
The service is prepaid. You buy credit in advance and usage draws it down. There is no subscription and no minimum commitment; you are charged for what you use.
Rates. Each model has a per-million-unit rate. For models we publish on our pricing page, the published rate is the rate you pay, and it changes only when we republish it — a provider’s cost moving underneath does not reprice you mid-cycle. Models that are not published are billed at our cost plus a standard markup and can move with that cost. We may change published rates on [LEGAL: notice period for changes to published rates] notice; a change never applies to usage already incurred.
Metering. Usage is measured by the platform and recorded against your account. Our records of usage are the basis for what is charged. If you think a charge is wrong, tell us within [LEGAL: window for disputing a charge] and we will investigate.
Currency and taxes. Credit is denominated and charged in US dollars. The console can present your balance and spend in another currency for convenience; that conversion is a display, not the amount charged. Amounts are exclusive of taxes and duties, and [LEGAL: applicable taxes, VAT/GST treatment and withholding] is your responsibility unless we state otherwise.
Budgets and caps. You can set spend limits on a key, a project, or the whole account, and choose whether a limit warns you or blocks. A hard limit blocks requests once it is reached, and the tightest applicable limit is the one that applies. These are your controls; configuring them is your responsibility, and we are not liable for spend incurred within limits you set or chose not to set.
Running out. When your balance reaches zero, gateway requests are refused. Hosted applications keep running for a short grace period and are then stopped — not deleted, and databases are not stopped. Topping up restores service. We will alert you before you reach that point, using the contact details on your account, but the responsibility for keeping the account funded is yours.
Refunds. Purchased credit is for use on the service and is not transferable between accounts. [LEGAL: refund policy and whether credit expires].
11Availability and support
We do not offer an availability percentage, and these terms contain no uptime guarantee or service level agreement. An uptime figure is a claim about a measured history, and we would rather offer none than one we cannot stand behind. If your organisation needs a contractual service level, it has to be agreed with us separately in writing.
What we do commit to is the practice underneath: backups are encrypted, held off the machine that made them, and restore-tested; the gateway fails over between markets; and a lost machine is recovered rather than reconstructed by hand. Our current measured recovery figures are available on request.
Support is during business hours in one market’s working day. There is no 24/7 rota and no out-of-hours response commitment. We may perform maintenance that interrupts the service, and will give reasonable notice where the work is planned.
We may change, add to, or withdraw features. Where a change removes something you rely on, we will give reasonable notice.
12Suspension
We may suspend an account, a key, a project or a hosted application where:
- these terms are being breached, in particular section 4;
- the account’s balance is exhausted, as described in section 10;
- use is harming the platform, other customers, or a third party;
- we are required to by law, or by a provider whose model or infrastructure is involved; or
- we reasonably believe an account has been compromised.
Suspension takes effect immediately and closes access to the console, the gateway and the API. We will tell you why, and we will lift it once the cause is resolved. Where the circumstances allow, we will raise the problem with you before suspending rather than after.
13Termination
You may stop using the service and close your account at any time. Because the account is prepaid and may be running applications, closing it requires that hosted applications and databases have been removed and that the balance has been settled — the platform enforces both.
We may terminate this agreement on [LEGAL: termination notice period] notice, or immediately where you are in material breach of these terms, where an account has been suspended and the cause has not been resolved, or where we are required to by law.
On termination, access ends and we will delete your data in the ordinary course of our retention schedule. You are responsible for exporting anything you want to keep before your account closes — ask us and we will help while the account is still open. Sections 5, 14, 15, 16 and 18 survive termination.
14Disclaimers
The service is provided as is and as available. To the fullest extent permitted by law, we disclaim all warranties, express or implied, including implied warranties of merchantability, fitness for a particular purpose, non-infringement, and any warranty arising from a course of dealing.
We do not warrant that the service will be uninterrupted or error-free, that any particular model will remain available, that defects will be corrected, or that output produced by a model will be accurate or suitable for your purpose. We do not warrant the code you deploy, and we are not responsible for its behaviour.
Nothing in these terms excludes or limits liability that cannot lawfully be excluded or limited.
15Limitation of liability
To the fullest extent permitted by law, neither party is liable for indirect, incidental, special or consequential loss, or for loss of profit, revenue, goodwill, anticipated savings, business opportunity, or data — whether or not the possibility of that loss was known.
Our total aggregate liability arising out of or relating to this agreement is limited to [LEGAL: liability cap — amount or formula, e.g. fees paid in the preceding twelve months].
These limits apply to all claims taken together, whether in contract, tort, or otherwise, and they reflect the allocation of risk between us at the prices charged.
16Indemnity
You will indemnify us against claims, losses and reasonable costs arising from your content, from applications you deploy and the way they are operated, from your use of model output, from your breach of these terms or of any law, and from claims brought by the people who use the applications you host with us.
We will notify you promptly of any such claim, and you may take conduct of its defence provided you do not settle it in a way that admits fault on our part or imposes an obligation on us without our consent.
17Changes, and general terms
We may update these terms — because the service changes, or because the law does. When we make a material change we will give [LEGAL: notice period for changes to these terms] notice by email to the account owner and by updating the date at the top of this page. Continuing to use the service after a change takes effect means you accept it. If you do not accept it, close your account before it takes effect.
If a provision of these terms is held unenforceable, the rest continues to apply. A failure to enforce a term is not a waiver of it. You may not assign this agreement without our consent; we may assign it to a successor to our business.
18Governing law and contact
These terms are governed by the laws of [LEGAL: governing law jurisdiction], and the courts of [LEGAL: courts or dispute-resolution venue] have exclusive jurisdiction over any dispute arising from them.
Before starting formal proceedings, both parties will try in good faith to resolve the dispute by talking to each other. Most things are settled that way.
Questions about these terms, and formal legal notices, go to [LEGAL: contact email for legal notices]. For anything else — a question about your account, a rate, or something that is not working — the fastest route is to talk to us. We are in Colombo.
Last updated 21 August 2026.
