Terms of service
What you are agreeing to, what we are agreeing to, and what happens to your
work if either of us stops. Written to describe what the software actually does rather than
to be unreadable — where a clause below makes a promise, there is a mechanism behind it and
we have said which.
Draft, and not yet reviewed by counsel. Placeholders marked
[ ] are facts about the company rather than about the product, and are
filled in before these take effect — ask us where that stands.
1. Who these are between
These terms are between [legal entity name and registration number] of
[registered address] ("we", "us") and the organisation whose administrator
accepted them ("you"). They are accepted when an account is created, and they apply to
everyone that account admits.
An organisation is the unit that holds the work, the billing and the
people. The person who signs up does not own the data; the organisation does. That is why
an administrator can be replaced without anything moving.
2. What you are buying
A licence to use the software for as long as you pay for it, for your own engineering
programmes. Not a transfer of anything: we keep the software, you keep your data, and
neither of us acquires rights in the other's.
Editors are charged, viewers are not. An editor is somebody who changes
the programme. A viewer reads, comments and keeps their own tasks, and is free, always,
however many of them there are. Editors are counted per programme, per month, and the rate
is graduated: the first twenty-five editors cost $100 each, the twenty-sixth to
seventy-fifth cost $75 each, and every one after that costs $50. Crossing a boundary does
not reprice the editors below it.
A programme whose monthly bill is more than $30,000 is invoiced rather than charged to a
card.
What is on the pricing page is included in that rate. Cost and earned
value, risk, the connectors and the assistant are not priced separately, and a bill that moved
with seats and with capabilities is one nobody could predict. If we ever sell a capability
separately we will say so on the pricing page before we sell it, and it will not change what
an existing subscription includes for the term you have paid for.
3. The trial, and the charge at the end of it
Ninety days, the whole product, for your whole organisation. We take a card at the start
and it is not charged during the trial, with one exception in section 4.
We email an administrator seven days before the first charge. This is
not a courtesy and it is not best-effort: the billing does not run without it. If the
reminder does not reach anybody — a bounced address, a mail outage, an organisation whose
only administrator never confirmed theirs — the trial is extended rather than the card
charged, and it keeps being extended until the reminder gets through. A charge you were not
warned about is one we would rather not take at all.
Cancel at any time, in one click, from Settings. Cancel before the
ninety days are up and you are never charged anything for the subscription. There is no
call to make, no retention offer, and no notice period.
After the trial the subscription renews monthly until you cancel. Cancelling takes effect
at the end of the period you have paid for.
4. The assistant, and why it is billed separately
The assistant runs on a third-party language model, and that model charges us per token.
We pass that through at cost, with no markup, and it is billed from your
first day rather than after the trial — the trial is free of our charges, not of somebody
else's.
You can see the model, the tokens, the rate and the total for every period in Settings,
and you can set a monthly ceiling above which the assistant stops answering. Pointing the
assistant at your own API key, so that we charge nothing for inference at all, is planned and
not yet available in the hosted service.
Rates change when our provider's published rates change. We read the
published rate card daily and apply what it says in both directions, so a reduction reaches
you without waiting for us. We tell you in the product and by email when a rate moves.
A change applies only to questions asked after it. Every answer records
the rate it was priced at, so a change never re-prices anything you have already been
invoiced for, and never alters an invoice that has already been issued.
If our provider's rates rose sharply enough that passing them through would materially
change what you pay, we would rather talk to you than apply it — see section 9.
5. Your data
It is yours. We hold it to run the service, and we count what is in each
programme — numbers, never names — to see how much the product is used. We do not sell it, we
do not use it to train models, and we do not use one customer's data to improve what another
customer sees. A feature that would share patterns across customers is planned, and would be
off unless you turned it on; the privacy policy says what it would
share.
What we hold at rest is limited, and here is the exact limit.
Programme content is encrypted in your browser before it is stored, with a key derived per
organisation, so what we hold at rest is ciphertext and a wrapped key. That
protects a stored copy, not against us: for your members' browsers to read the programme, our
service unwraps the key and hands it to them, and our connector for AI agents decrypts on our
server what an agent asks for. We do not look at your content, but we are not technically
unable to. Content saved before encryption was introduced is stored unencrypted. The
privacy policy has the detail.
Asking the assistant a question is the exception, and it is not a small one.
When you ask, your browser decrypts the part of the programme the question is about and sends
it, in the clear, through our service to the model provider. It is not stored — we keep the
cost, the model and a digest of what was sent, never the question or the answer — but it
passes through us, and for those seconds we could read it. Nothing else works: a model cannot
answer a question about a programme it cannot see. If that is not acceptable for a given
programme, do not use the assistant on it. Pointing it at your own model, where we would not be
in the path at all, is planned.
Some things are necessarily in the clear because the database has to look them up:
programme names and descriptions, the email addresses of people you invite, and anything you
type into a feedback form. Branch names and content saved before encryption was introduced are
also in the clear. Section 6 says what happens to those on deletion.
Crash reports carry no prose. When something breaks, what we receive is
a closed vocabulary — an error's class, the failing request's method and table, stack frames
as file, line and column — and never a message, because a message interpolates and would
carry your data out in a payload nobody reviewed. A report you write yourself carries what you
write and any screenshots you attach, and you see all of it before it is sent.
6. Deletion
You can ask us to destroy your organisation's data at any time, and we will. The product
records which members your administrators have appointed as key custodians, and we act on an
instruction from one of them.
That instruction is placed from the product's settings, and the ability to place one is
switched off until you ask us to switch it on. We turn it on after talking to you, because
this is the one thing here that nobody can undo afterwards — not you and not us — and that
conversation is what catches the wrong person making the call. Until then, and afterwards if
you would rather not have the button at all, email us and we will do the same thing by
hand.
Placing an order shows what would be destroyed before the decision rather than after it,
asks for the organisation's name typed out, and asks why. Nothing is destroyed for seven
days. Every key custodian and administrator is emailed straight away with the reason given,
the date it would happen, and who ordered it, and any key custodian can cancel it up to that
date.
We are told at the same time and by the same mechanism.
Deletion destroys the key, and then deletes what the key did not cover.
Destroying the encryption key makes the encrypted content unrecoverable — including copies in
backups, which an ordinary delete cannot reach. The key is held by a third-party key
management service and its destruction is an act that service performs and records, so it is
not a claim we make about our own database. The programmes, their history, and the things that
had to stay readable to the database are then deleted outright.
What survives is that the organisation existed, not what it did. We keep
the organisation, its members and their roles, its billing records, the record of its key, and
the record of the deletion itself, which is what proves it was done. The history of changes
goes with the programmes. Problem reports sent from the organisation or by its current
members go too, with what anybody wrote in them and their screenshots, except copies we have
downloaded to read, which we delete by hand when asked. One sent while nobody was signed in
carries no organisation, and is deleted after twelve months, its screenshots after ninety
days.
Honest limits: a backup taken this morning still holds a programme's name, and any content
saved before encryption was introduced, until that backup expires, and deletion is per
organisation rather than per person. If you need per-person erasure, tell us before you sign,
because today we cannot do it.
7. Who else touches it
We use these subprocessors, and we will tell you before adding one that handles your
content:
- Supabase — database, authentication and the functions that serve the
application.
- Vercel — serving the website and the application's front end, and
running the connector for AI agents, which handles decrypted content.
- Amazon Web Services — key management, which is what makes the
deletion above verifiable.
- Stripe — payments. We never see or store a card number; Stripe holds
it and we hold a reference.
- Resend — the emails we send you about your account.
- Anthropic — the hosted assistant, with only what you send it, and the
AI tools we use to triage problem reports you send us.
- GitHub — hosts our code and runs the build servers that fetch problem
reports for triage.
Superposition is not FedRAMP authorised, and neither are Supabase or Vercel, which hold
your data. If that matters to you, say so before you sign rather than after.
8. What we do not claim
We are not certified against SOC 2, ISO 27001 or FedRAMP. We say so here, on the
trust page, and on every call, and we will keep saying so until it stops
being true.
The software is provided as it is. We do not warrant that it is free of defects or that it
will be available without interruption, and nothing it computes is a substitute for your own
engineering judgement. Do not rely on a number this product produces for a decision
with a safety consequence without checking it. Every derived figure carries its
provenance precisely so that it can be checked.
[Limitation of liability — to be drafted by counsel.] This is the clause
most likely to be read carefully by your legal team and the one we least want to get wrong by
copying somebody else's.
9. Changing these terms, and changing the price
We will give you [notice period] before a change to these terms or to
your subscription price takes effect, and it takes effect at your next renewal rather than
mid-period. If you do not accept it, cancel before that date and you are not charged the new
amount.
Passthrough inference rates are the exception and are described in section 4: they move
with our provider's published rates and are applied when they do, because holding an old rate
would mean either absorbing a rise or withholding a reduction from you.
10. Stopping
Nothing is deleted because you stopped paying. Cancelled, expired, or a
card that did not work — your programme stays readable and stays exportable, in full, in the
formats it always did. Editing is what stops, not access. Three months of real work must
never become a choice between paying us and losing it.
We will not hold your data hostage to get you to pay, and we will not delete it to save
storage. If you want it out, export it; if you want it gone, section 6.
We may suspend an account that is being used to break the law or to attack the service. We
will tell you why, and your data stays exportable while we sort it out.
If we discontinue the service we will give you [notice period] and an
export of everything before it stops.
11. The rest
These terms are governed by the law of [jurisdiction], and
[dispute resolution — to be drafted by counsel].
If a clause turns out to be unenforceable, the rest stands. Neither of us waives anything
by not enforcing it immediately. These terms, together with the pricing page, are the whole
of what is agreed.
Questions about any of this go to contact, and we would rather
answer them before you sign than after.
Ninety days, when your turn comes
A card up front, nothing charged until the trial ends except what the assistant costs to
run, and a reminder a week before. Cancel in one click.