Superposition one plan, from requirement to decision Request access

Terms of service

What you are agreeing to, what we are agreeing to, and what happens to your work if either of us stops. Written to describe what the software actually does rather than to be unreadable — where a clause below makes a promise, there is a mechanism behind it and we have said which.

Draft, and not yet reviewed by counsel. Placeholders marked [ ] are facts about the company rather than about the product, and are filled in before these take effect — ask us where that stands.

1. Who these are between

These terms are between [legal entity name and registration number] of [registered address] ("we", "us") and the organisation whose administrator accepted them ("you"). They are accepted when an account is created, and they apply to everyone that account admits.

An organisation is the unit that holds the work, the billing and the people. The person who signs up does not own the data; the organisation does. That is why an administrator can be replaced without anything moving.

2. What you are buying

A licence to use the software for as long as you pay for it, for your own engineering programmes. Not a transfer of anything: we keep the software, you keep your data, and neither of us acquires rights in the other's.

Editors are charged, viewers are not. An editor is somebody who changes the programme. A viewer reads, comments and keeps their own tasks, and is free, always, however many of them there are. Editors are counted per programme, per month, and the rate is graduated: the first twenty-five editors cost $100 each, the twenty-sixth to seventy-fifth cost $75 each, and every one after that costs $50. Crossing a boundary does not reprice the editors below it.

A programme whose monthly bill is more than $30,000 is invoiced rather than charged to a card.

What is on the pricing page is included in that rate. Cost and earned value, risk, the connectors and the assistant are not priced separately, and a bill that moved with seats and with capabilities is one nobody could predict. If we ever sell a capability separately we will say so on the pricing page before we sell it, and it will not change what an existing subscription includes for the term you have paid for.

3. The trial, and the charge at the end of it

Ninety days, the whole product, for your whole organisation. We take a card at the start and it is not charged during the trial, with one exception in section 4.

We email an administrator seven days before the first charge. This is not a courtesy and it is not best-effort: the billing does not run without it. If the reminder does not reach anybody — a bounced address, a mail outage, an organisation whose only administrator never confirmed theirs — the trial is extended rather than the card charged, and it keeps being extended until the reminder gets through. A charge you were not warned about is one we would rather not take at all.

Cancel at any time, in one click, from Settings. Cancel before the ninety days are up and you are never charged anything for the subscription. There is no call to make, no retention offer, and no notice period.

After the trial the subscription renews monthly until you cancel. Cancelling takes effect at the end of the period you have paid for.

4. The assistant, and why it is billed separately

The assistant runs on a third-party language model, and that model charges us per token. We pass that through at cost, with no markup, and it is billed from your first day rather than after the trial — the trial is free of our charges, not of somebody else's.

You can see the model, the tokens, the rate and the total for every period in Settings, and you can set a monthly ceiling above which the assistant stops answering. Pointing the assistant at your own API key, so that we charge nothing for inference at all, is planned and not yet available in the hosted service.

Rates change when our provider's published rates change. We read the published rate card daily and apply what it says in both directions, so a reduction reaches you without waiting for us. We tell you in the product and by email when a rate moves. A change applies only to questions asked after it. Every answer records the rate it was priced at, so a change never re-prices anything you have already been invoiced for, and never alters an invoice that has already been issued.

If our provider's rates rose sharply enough that passing them through would materially change what you pay, we would rather talk to you than apply it — see section 9.

5. Your data

It is yours. We hold it to run the service, and we count what is in each programme — numbers, never names — to see how much the product is used. We do not sell it, we do not use it to train models, and we do not use one customer's data to improve what another customer sees. A feature that would share patterns across customers is planned, and would be off unless you turned it on; the privacy policy says what it would share.

What we hold at rest is limited, and here is the exact limit. Programme content is encrypted in your browser before it is stored, with a key derived per organisation, so what we hold at rest is ciphertext and a wrapped key. That protects a stored copy, not against us: for your members' browsers to read the programme, our service unwraps the key and hands it to them, and our connector for AI agents decrypts on our server what an agent asks for. We do not look at your content, but we are not technically unable to. Content saved before encryption was introduced is stored unencrypted. The privacy policy has the detail.

Asking the assistant a question is the exception, and it is not a small one. When you ask, your browser decrypts the part of the programme the question is about and sends it, in the clear, through our service to the model provider. It is not stored — we keep the cost, the model and a digest of what was sent, never the question or the answer — but it passes through us, and for those seconds we could read it. Nothing else works: a model cannot answer a question about a programme it cannot see. If that is not acceptable for a given programme, do not use the assistant on it. Pointing it at your own model, where we would not be in the path at all, is planned.

Some things are necessarily in the clear because the database has to look them up: programme names and descriptions, the email addresses of people you invite, and anything you type into a feedback form. Branch names and content saved before encryption was introduced are also in the clear. Section 6 says what happens to those on deletion.

Crash reports carry no prose. When something breaks, what we receive is a closed vocabulary — an error's class, the failing request's method and table, stack frames as file, line and column — and never a message, because a message interpolates and would carry your data out in a payload nobody reviewed. A report you write yourself carries what you write and any screenshots you attach, and you see all of it before it is sent.

6. Deletion

You can ask us to destroy your organisation's data at any time, and we will. The product records which members your administrators have appointed as key custodians, and we act on an instruction from one of them.

That instruction is placed from the product's settings, and the ability to place one is switched off until you ask us to switch it on. We turn it on after talking to you, because this is the one thing here that nobody can undo afterwards — not you and not us — and that conversation is what catches the wrong person making the call. Until then, and afterwards if you would rather not have the button at all, email us and we will do the same thing by hand.

Placing an order shows what would be destroyed before the decision rather than after it, asks for the organisation's name typed out, and asks why. Nothing is destroyed for seven days. Every key custodian and administrator is emailed straight away with the reason given, the date it would happen, and who ordered it, and any key custodian can cancel it up to that date. We are told at the same time and by the same mechanism.

Deletion destroys the key, and then deletes what the key did not cover. Destroying the encryption key makes the encrypted content unrecoverable — including copies in backups, which an ordinary delete cannot reach. The key is held by a third-party key management service and its destruction is an act that service performs and records, so it is not a claim we make about our own database. The programmes, their history, and the things that had to stay readable to the database are then deleted outright.

What survives is that the organisation existed, not what it did. We keep the organisation, its members and their roles, its billing records, the record of its key, and the record of the deletion itself, which is what proves it was done. The history of changes goes with the programmes. Problem reports sent from the organisation or by its current members go too, with what anybody wrote in them and their screenshots, except copies we have downloaded to read, which we delete by hand when asked. One sent while nobody was signed in carries no organisation, and is deleted after twelve months, its screenshots after ninety days.

Honest limits: a backup taken this morning still holds a programme's name, and any content saved before encryption was introduced, until that backup expires, and deletion is per organisation rather than per person. If you need per-person erasure, tell us before you sign, because today we cannot do it.

7. Who else touches it

We use these subprocessors, and we will tell you before adding one that handles your content:

Superposition is not FedRAMP authorised, and neither are Supabase or Vercel, which hold your data. If that matters to you, say so before you sign rather than after.

8. What we do not claim

We are not certified against SOC 2, ISO 27001 or FedRAMP. We say so here, on the trust page, and on every call, and we will keep saying so until it stops being true.

The software is provided as it is. We do not warrant that it is free of defects or that it will be available without interruption, and nothing it computes is a substitute for your own engineering judgement. Do not rely on a number this product produces for a decision with a safety consequence without checking it. Every derived figure carries its provenance precisely so that it can be checked.

[Limitation of liability — to be drafted by counsel.] This is the clause most likely to be read carefully by your legal team and the one we least want to get wrong by copying somebody else's.

9. Changing these terms, and changing the price

We will give you [notice period] before a change to these terms or to your subscription price takes effect, and it takes effect at your next renewal rather than mid-period. If you do not accept it, cancel before that date and you are not charged the new amount.

Passthrough inference rates are the exception and are described in section 4: they move with our provider's published rates and are applied when they do, because holding an old rate would mean either absorbing a rise or withholding a reduction from you.

10. Stopping

Nothing is deleted because you stopped paying. Cancelled, expired, or a card that did not work — your programme stays readable and stays exportable, in full, in the formats it always did. Editing is what stops, not access. Three months of real work must never become a choice between paying us and losing it.

We will not hold your data hostage to get you to pay, and we will not delete it to save storage. If you want it out, export it; if you want it gone, section 6.

We may suspend an account that is being used to break the law or to attack the service. We will tell you why, and your data stays exportable while we sort it out.

If we discontinue the service we will give you [notice period] and an export of everything before it stops.

11. The rest

These terms are governed by the law of [jurisdiction], and [dispute resolution — to be drafted by counsel].

If a clause turns out to be unenforceable, the rest stands. Neither of us waives anything by not enforcing it immediately. These terms, together with the pricing page, are the whole of what is agreed.

Questions about any of this go to contact, and we would rather answer them before you sign than after.

Ninety days, when your turn comes

A card up front, nothing charged until the trial ends except what the assistant costs to run, and a reminder a week before. Cancel in one click.