Version: 2026-07-30 ยท v1.0
HarnessRouter Terms of Service
Scope: This is the main body of the HarnessRouter Terms of Service, the single clickwrap contract between Customer and us; together with any applicable Data Processing Addendum and any applicable Order Form, it forms the Agreement accepted through a single clickwrap.
These Terms of Service ("Terms") govern your access to and use of HarnessRouter, the multi-harness AI aggregation and routing services described in these Terms (the "Services"). HarnessRouter is currently provided by Lumentree Corporation, a California corporation, which is the party you contract with under these Terms ("we," "us," or "our"). We may transfer these Terms and the operation of HarnessRouter to an Affiliate or successor as permitted in Section 23; if the entity that provides HarnessRouter changes, we will identify the new entity under Section 23.6.
Please read these Terms carefully. Section 19 (Disclaimers), Section 21 (Limitation of Liability), and Section 24 (Governing Law and Dispute Resolution) contain important limitations on our liability, a binding individual arbitration requirement, a class action waiver, and a 30-day opt-out right. These provisions affect your legal rights.
1. Acceptance, Eligibility and Customer Scope
1.1 Acceptance. You accept this Agreement by taking the affirmative action presented at the acceptance page, such as checking an unchecked box or selecting a clearly labeled acceptance control, against the Agreement version and manifest then presented. That recorded affirmative acceptance, and not the mere creation of an account or Workspace or the access to or use of the Services, is the event that forms this Agreement, as further described in Section 2.3. When you accept this Agreement, it applies to and governs all of your access to and use of the Services, including access and use that occurred before the date of your acceptance, and any dispute arising out of or relating to that prior access or use, unless a separate written agreement between you and us governed that access or use, in which case that agreement continues to govern the period it covers; access or use is not itself acceptance. If you do not agree, you may not access or use the Services. Continued use of the Services after a properly noticed update takes effect under Section 23.2 has only the prospective effect that Section provides; it is not the mechanism by which you originally accept this Agreement.
1.2 Who the Customer is. "Customer" means the individual who accepts this Agreement on their own behalf, or, where an individual accepts on behalf of an organization, that organization. HarnessRouter is available to individuals, independent developers, hobbyists, and organizations; use is not restricted to businesses. The Services are designed, marketed, and offered primarily as developer and professional tools for building and operating software. This does not exclude personal use; where an individual uses the Services as a consumer, Sections 1.5, 20.4, 24, and 25 apply as written.
1.3 Authority. If you accept this Agreement on behalf of an organization, you represent and warrant that you are authorized to bind that organization, and "Customer," "you," and "your" refer to that organization.
1.4 Age. Each account holder, Workspace Administrator, purchaser, and Authorized User must be at least the age of majority in their place of residence and in any event at least 18 years old. This minimum age applies to the HarnessRouter account holder, not to the end users of a Customer Application. If a Customer Application is directed to, or knowingly used by, minors, Customer is responsible for complying with all applicable children's- and minors'-privacy and consumer-protection laws (such as COPPA and, where applicable, the UK Age-Appropriate Design Code and Article 8 GDPR), obtaining any required parental or guardian consent, and implementing age-appropriate safeguards. HarnessRouter is a general-audience developer service, is not directed to children, and does not knowingly collect personal information from children; Customer must not route a child's personal data to the Services except as permitted by applicable law and with the required consents. Child-safety and prohibited-content rules are included in Sections 4 and 11 and the applicable Provider-route restrictions disclosed for a route.
1.5 Non-waivable rights preserved. Nothing in this Agreement waives or limits a right or remedy that applicable law does not permit to be waived or limited. Where an individual using the Services qualifies as a consumer under mandatory consumer-protection law, non-waivable rights (for example, concerning automatic renewal, cancellation, or refunds) continue to apply notwithstanding that the Services are developer tools. Additional terms for such an individual resident in the EEA, UK, or Switzerland are in Section 25.
2. Definitions, Agreement Composition and Order of Precedence
2.1 Defined terms. Capitalized terms have the meanings given where they are defined in this Agreement. The following core terms apply throughout:
- Customer, Authorized User, Workspace Administrator, and End User have the meanings given in this Agreement for the corresponding roles. "Authorized User" means an employee, contractor, or agent that Customer permits to use its account or Workspace. "End User" means an end user of a Customer Application, who is not a party to this Agreement unless they separately register with us. We do not use "User" alone to mean an Authorized User, End User, or website visitor.
- Workspace means the tenant container within an Organization on which acceptance of this Agreement, Authorized User membership, feature enablement, budgets, and administrative scope depend, and through which Customer organizes and administers its use of the Services.
- Workspace Administrator means a person who administers a Workspace on Customer's behalf โ configuring members, permissions, budgets, and features, and managing and gating the consents required to enable data-sharing routes โ as further described in Section 3.2 and referenced in the Privacy Policy. A Workspace Administrator is not a separate party to this Agreement except as stated in Section 3.2.
- Customer Application means an application, product, or service that Customer builds, operates, or offers using the Services, including for its End Users, as referenced in Sections 1.4, 6, 7, 20, and 22.
- Route means the Provider, Model, and Region path selected to execute a given Run, as further described in Section 9.
- Provider means an independent third-party AI, model, cloud, or infrastructure provider (for example, a model or hosting provider) whose services may be reached through the Services.
- Model means an AI model made available through the Services and identified in the Services or in a route-specific disclosure.
- Region means a data-processing or service region made available through the Services and identified in the Services or in a route-specific disclosure.
- Customer Content means the inputs, files, datasets, code, configurations, prompts, and other materials that Customer or its Authorized Users provide to or through the Services.
- Output means the text, structured results, generated code, files, and other materials returned by the Services in response to Customer Content.
- Run means a single execution attempt; Session means the technical identifier for a series of interactions; Task means a user-visible objective; Harness means a reusable Agent configuration; Artifact means a generated file or file group and its manifest.
- Agent means an automated or AI-driven process that Customer configures or authorizes to take actions through the Services.
- Registry means our dynamic factual disclosure and evidence record of available Providers, Models, Regions, data policies, data modes, Provider Terms and version, route status, and restricted-party screening, disclosed where offered in the Services or in a route-specific disclosure. It is referenced by the Agreement but is not itself a contract document and does not by itself amend the Agreement or impose a new material obligation; a new material recipient, data practice, fee, indemnity, arbitration, or use restriction still requires the applicable Agreement update, route acceptance, Provider-native acceptance, or blocking.
- Affiliate means, with respect to a party, any entity that directly or indirectly controls, is controlled by, or is under common control with that party, where "control" means ownership of more than fifty percent (50%) of the voting interests or the power to direct the management and policies of the entity.
- Successor means a person or entity that acquires a party's business, the relevant business unit, or all or substantially all of the assets used in connection with this Agreement, by merger, reorganization, change of control, or sale of assets, and that assumes the obligations transferred to it.
- restricted party means a person or entity that is the target of applicable sanctions or export-control restrictions, that is owned or controlled by or acting on behalf of such a person, or that is listed on an applicable government restricted-party, denied-party, or sanctioned-party list.
- direct competitor means an entity that, as a substantial part of its business, offers a product or service that is materially and directly competitive with the Services.
- Documentation means the then-current product and developer documentation we make available (for example, at the Documentation URL referenced in the Agreement).
- Order Form means an ordering document signed by both parties that references this Agreement.
- Enterprise MSA means an Enterprise Master Services Agreement or equivalent negotiated master services agreement signed by both parties that expressly governs Customer's enterprise use of the Services.
- Gate means a legal, sanctions, upstream, payment, tax, age, Region, identity, or use-case eligibility checkpoint applied to registration, a route, a feature, or a payment, as described in Section 22 and the applicable route-specific disclosure.
- Minimum End User Terms has the meaning given in Section 6.2, which is the only place this term is defined.
2.2 The Agreement. These Terms of Service, any applicable Data Processing Addendum, and any applicable Order Form collectively form the "Agreement" between Customer and us. The Agreement manifest presented when Customer accepts these Terms identifies the contract documents then incorporated. The Privacy Policy, Subprocessor List, and Security and Vulnerability Disclosure Policy are notices or public procedures and do not form part of the Agreement unless a signed Order Form expressly says otherwise.
2.3 One acceptance; frozen manifest. Customer accepts the Agreement once. Each acceptance freezes the Agreement version and a manifest of the versions of all documents then incorporated, together with the Provider Terms bindings identified for the applicable default routes. Acceptance is not recorded as a bare "terms accepted" flag.
2.4 Use restrictions and AI/agent safety. The use restrictions in Sections 4, 10, 11, 17, and 22 are part of these Terms and apply to Customer's and its Authorized Users' use of the Services. Customer must ensure that its Customer Applications and End Users comply with these restrictions and applicable Provider-route restrictions to the extent Customer controls, or is legally responsible for, that downstream use.
2.5 Feature-specific terms. Customer accepts the Agreement once when creating its account or Workspace. If we later offer a feature that requires additional terms, those terms apply only after they are presented and added under Section 23.2, and only if and when Customer or an authorized Workspace Administrator accesses, enables, purchases, or uses that feature. Activating or using a covered feature confirms Customer's instruction to enable that feature and does not create a separate agreement with us unless we expressly state otherwise.
2.6 Data Processing Addendum. If we process Customer Personal Data on Customer's behalf, the version of our Data Processing Addendum identified by the Agreement manifest, as validly updated under the Agreement, is incorporated into and applies under the Agreement without a separate signature, unless the parties execute a different DPA. The DPA applies where we process Customer Personal Data on a Customer's behalf as a processor or service provider, including for organizations and for individuals who use the Services for commercial or professional purposes; it does not apply to purely personal or household consumer use, or to our own controller processing described in the Privacy Policy.
2.7 Third-Party Terms. Certain routes or features require Customer to comply with or directly accept terms of a Third-Party Provider. Customer authorizes us to present or facilitate those terms, but acceptance of this Agreement does not eliminate any separate acceptance, verification, or disclosure that the Third-Party Provider or applicable law requires before that route or feature is enabled. Third-Party Terms bind Customer to the relevant third party; they are not promises by us and do not expand our warranties, indemnities, refunds, service levels, or liability.
2.8 Order of precedence. In case of conflict, the following order controls: (a) an amendment signed by both parties that expressly identifies the term it modifies; (b) an Order Form signed by both parties, only as to pricing, quantity, term, support scope, and the matters it expressly overrides; (c) an Enterprise MSA; (d) the Data Processing Addendum, only as to Personal Data processing (with mandatory clauses of any official Standard Contractual Clauses or UK Addendum prevailing only as to the transfers they cover); and (e) these Terms of Service. The Subprocessor List, route-specific disclosures, Documentation, and marketing materials are factual disclosures and records and do not by themselves amend the Agreement or impose a new material obligation merely because they are referenced or linked; a new material recipient, data practice, fee, indemnity, arbitration, or use restriction still requires the applicable Agreement update, route acceptance, Provider-native acceptance, or blocking. Section 25 (Additional Terms for Consumers in the EEA, UK, and Switzerland) is a point-specific mandatory-consumer overlay within these Terms; it controls only the specific conflict between a non-waivable mandatory consumer law and a provision of this Agreement for a consumer within its scope, and it does not displace the order of precedence in this Section, including the priority of the Data Processing Addendum as to Personal Data processing.
2.9 No open-ended incorporation. The Agreement includes only these Terms and the contract documents expressly incorporated by reference in these Terms โ including the Data Processing Addendum as Section 2.6 provides โ as identified in the version manifest recorded at acceptance, each accessible through the Legal Hub. No provision incorporates future or unspecified policies into the Agreement automatically.
3. Accounts, Workspaces and Administration
3.1 Object model. The Services are organized as Organization, Workspace, Harness, and Task/Session, with results, files, and traces.
3.2 Administration. A Workspace Administrator may configure members, permissions, budgets, and features that the Agreement already covers, acting for Customer. A Workspace Administrator is not a separate party to this Agreement unless that person is also the Customer, and may not bypass payment, third-party acceptance, or any legally required consent, and may not give, on behalf of an End User, a consent that law does not permit to be given by an agent.
3.3 Responsibility for members. Customer is responsible for its invitations, role assignments, and the acts and omissions of its Authorized Users, and for maintaining accurate account information.
3.4 Credentials and API Keys. Customer is responsible for safeguarding account credentials and API Keys and for all activity under its account. Customer must not share, sell, or transfer account login credentials, and must keep each set of credentials restricted to the individual authorized to hold it. Customer will promptly notify us at the notice address in Section 23.1 on becoming aware of any suspected loss, theft, compromise, or unauthorized use of its account or credentials. API Keys must be kept server-side, must not be exposed in browsers, client-side code, prompts, files, traces, or public repositories, and must be handled as described in the Documentation. We provide reasonable security controls but do not guarantee that any account cannot be compromised. Customer is responsible for all use of, and activity under, its account and credentials, except to the extent the activity results solely from our own breach of our security obligations. This responsibility is in addition to, and not diminished by, the prompt-notice duty above.
4. Service License and Restrictions
4.1 License. Subject to this Agreement, we grant Customer a limited, revocable, non-exclusive, non-transferable, non-sublicensable right to access and use the Services, the API, the SDK, the CLI, AGENTS.md integration, and the Documentation, solely for Customer's internal use and permitted Customer Applications, within the scope currently described in the Documentation.
4.2 Reservation. This is a license to use the Services only. It does not transfer any ownership of, or other right in, the Services, the platform software, or our intellectual property.
4.3 Restrictions. Customer must not, and must not permit any Authorized User to, and must ensure its End Users and Customer Applications do not (to the extent they could reach the Services): (a) copy, modify, translate, or create derivative works of the Services except as expressly permitted; (b) reverse engineer, decompile, or attempt to derive source code or underlying models, except to the extent applicable law prohibits this restriction; (c) circumvent or exceed rate limits, quotas, metering, seat limits, or access controls; (d) resell, sublicense, or provide the bare Services to third parties without material added value (meaning substantial independent functionality beyond mere resale, relabeling, or thin wrapping of the Services); (e) copy the Services to build a competing service, or use the Services or Output to train or develop a competing AI model; or (f) use the Services in violation of Sections 10, 11, 17, 22, applicable Provider-route restrictions, or applicable law. This Section is independent of, and survives alongside, the intellectual property provisions in Section 14.
5. Service Scope, Changes and Availability
5.1 Scope. The Services consist of the features currently described in the Documentation. HarnessRouter is a multi-Harness aggregation and routing layer that normalizes Tasks, Runs, Sessions, streaming, files, Artifacts, and renderer contracts through a backend API.
5.2 Changes and deprecation. We may add, change, deprecate, remove, re-route, or restrict Providers, Models, routes, Regions, and data modes, and may change, add, deprecate, or discontinue features, quotas, renderers, and Beta functionality, at any time. Provider, Model, route, Region, and data-mode availability is dynamic; the Providers currently available, their data-retention and training policies, applicable Provider Terms and version, supported Regions, data modes, and route status are disclosed as a factual disclosure in the Services or in a route-specific disclosure, which does not by itself amend the Agreement. Where a change would send Customer Personal Data to a new Subprocessor, the Subprocessor notice-and-objection process in the DPA applies. We do not guarantee that any particular Provider, Model, capacity, or feature remains available.
5.3 Beta and non-production. Demo Replay, Beta, and preview features are provided on an "as available" basis, may change or be withdrawn at any time, and must not be used for production, high-risk, or reliance-based decisions. Demo Replay does not create a real Run, call paid Runtime, or draw down a Usage balance.
5.4 No default service level. The Services are provided without a service level agreement. Any service level, uptime, support response, or capacity commitment applies only if and to the extent set out in a signed Order Form. Community channels are not private support or a service level commitment.
6. Customer Applications and End Users
6.1 Customer responsibility. Customer is responsible for its Customer Applications, including their architecture, front end and back end, security, business logic, End User experience, and lawful operation, and for its relationships with its End Users. We do not become the seller, publisher, or merchant of record of a Customer Application by providing infrastructure or routing, except where the payment architecture and applicable law provide otherwise.
6.2 Minimum End User Terms (canonical definition). "Minimum End User Terms" means the minimum terms that Customer must put in place with, and make binding on, its End Users, comprising, as applicable to the relevant context: End User terms of service; a privacy notice; any AI-use notice and consents required by law; refund, delivery, and support terms; and a clear identification of the seller or operator. This is the only definition of Minimum End User Terms in the Agreement; a future Service Schedule, if any, may reference this definition and narrow it to a particular context but does not redefine it.
6.3 Consents and compliance. Customer is responsible for obtaining any consents, providing any notices, and meeting any consumer, sector, and regulatory requirements that apply to its Customer Applications and End Users. Customer must not represent us as performing to its End Users. Where a Customer Application has End Users, Customer will implement and maintain the Minimum End User Terms with those End Users.
7. Customer Content, Input, Files and Datasets
7.1 Ownership. As between the parties, Customer retains all right, title, and interest in Customer Content. Customer grants us a limited, non-exclusive license to host, process, transmit, display, and otherwise use Customer Content solely as needed to provide, secure, and lawfully operate the Services, including transmitting Customer Content to the Provider, Model, and Region selected for a Run. We acquire no ownership of Customer Content.
7.2 Customer warranties. Customer represents and warrants that it owns or has the necessary rights, consents, and legal bases for Customer Content and its processing through the Services, and is responsible for classifying, minimizing, and where appropriate de-identifying Customer Content, and for selecting permitted data paths.
7.3 Model training (our models). We do not use Customer Content to train our AI models unless Customer affirmatively opts in. This commitment applies to Customer Content in any form: de-identifying, aggregating, or deriving data from Customer Content does not create a right to use that content, or anything derived from its substance, to train our AI models, and the aggregated and de-identified data described in Section 7.6 may not be used to reconstruct or train on the substance of Customer Content. This commitment is limited to our own use of Customer Content to train models. It is distinct from, and does not restrict, internal processing such as abuse detection, safety classification, security monitoring, service operation, debugging, and legal compliance, which are not "training" for purposes of this Section.
7.4 No whole-chain training warranty. Whether an upstream Provider trains on, retains, or logs data is governed by that Provider's own policies. We disclose the applicable configuration per route in the Services or in a route-specific disclosure, and do not warrant "never train" or "zero retention" across the whole chain. A route that shares data with a model Provider is enabled only after the required Workspace Administrator disclosure and authorization is obtained.
7.5 Minimization and deletion. Customer must not submit data categories that this Agreement prohibits (see Section 11) and remains responsible for minimizing Personal Data. Deletion and retention are handled under Section 18, the Privacy Policy, and, where the DPA applies, the DPA.
7.6 Aggregated and de-identified data. We may create aggregated, statistical, and de-identified data from the operation and use of the Services, including usage volumes, Run, Session, and token counts, Model, Provider, Region, and Harness metrics, and our own observed operational measurements of latency, error rates, throughput, availability, and performance from traffic we actually serve. Data qualifies under this Section only when it is aggregated or de-identified so that it does not identify, and cannot reasonably be used to identify, Customer, any Authorized User, End User, or other individual. We apply reasonable measures against re-identification, including publishing a metric only at a level of aggregation drawn from a sufficient number of distinct sources that no single Customer, Authorized User, End User, or non-public Harness, Customer Application, or configuration is identifiable from it. Once data so qualifies, it is no longer Customer Content, Personal Data, or Customer Confidential Information; we own it and may use, retain, and disclose it, including publicly (for example, as usage statistics, rankings, or trends), for any lawful business purpose, including operating, securing, analyzing, improving, and marketing the Services. We will not attempt to re-identify such data, except as required by law or as necessary to test whether our de-identification measures satisfy applicable law, and will not publish the substance of Customer Content, Customer's identity, or a Customer's non-public Harness, Customer Application, or configuration. The aggregated and de-identified data under this Section consists of usage, operational, and metadata measurements; it does not include the substance of Customer Content or Output. Any public comparative benchmark that identifies a named Provider or Model is additionally subject to applicable Provider Terms and law. This Section does not permit us to use Customer Content โ whether in original, de-identified, aggregated, or derived form โ to train our AI models; such training is permitted only under the opt-in in Section 7.3. The aggregated and de-identified operational, usage, performance, and route- and task-type metadata described in this Section โ which does not include the substance of Customer Content or Output โ may be used to build, train, and operate routing, recommendation, benchmarking, and model- and harness-suitability analytics (including which harness and model perform best for a given task type) and to publish rankings and trends; the training prohibition in Section 7.3 and this Section applies to training our AI models on the substance of Customer Content or Output, not to operational metrics or metadata.
8. Output, Artifacts and Generated Code
8.1 Allocation of rights. To the extent we can and lawfully may do so, and subject to the rights actually available from and enforceable against the applicable upstream, we do not assert ownership of Output as against Customer. We make no promise of rights in Output wider than what we receive from and can enforce against every applicable upstream. As between Customer and us, Customer holds whatever rights in Output the applicable Provider's terms grant, and those Provider Terms identified for the applicable route govern Output ownership.
8.2 No warranty as to Output. Output may be inaccurate, incomplete, out of date, non-unique, insecure, or infringing, and may not be fit for a particular purpose. Similar inputs may produce Output also provided to others.
8.3 Human review required. Customer is responsible for reviewing Output for accuracy, security, intellectual property, licensing, and legal compliance before using, publishing, deploying, merging, transacting on, or making decisions based on it. Sandboxing, scanning, approval, and renderer isolation are risk-reduction measures, not guarantees.
9. AI Providers, Models, Regions and Third-Party Services
9.1 Routing. For each Run, the Services route to a Provider, Model, and Region and record the actual path, including any fallback and its reason. Customer or its Workspace policy selects the Model within the range the tenant policy permits; the backend validates eligibility. We do not present a platform selection as a Customer instruction, and are designed not to silently fall back to a non-compliant route.
9.2 Provider Terms โ two-layer flow-down. Provider Terms apply on a two-layer basis and are not incorporated by any single catch-all statement:
(a) We write into our own documents only (i) mandatory text or flow-down that law or a contracting upstream requires, together with the verification, gating, suspension, and liability boundaries we need to enforce; and (ii) the strict intersection of the limitations common to all default routes.
(b) Route-specific limitations apply through the Provider Terms and route-specific disclosures identified for the applicable route. We do not transcribe Provider text into the Agreement. For default routes accepted at clickwrap (Class 1), the applicable Provider Terms bindings are drawn to Customer's attention by a conspicuous, accessible link at acceptance and are frozen in the Agreement manifest. Where a route carries material special limitations, creates material obligations not covered by the existing manifest, or an upstream requires Customer or an Administrator to accept identified Model or Provider Terms (Class 2), the required assent of an authorized person is obtained before enablement. Where a Provider must establish the relationship or control the consent flow directly (Class 3), that flow governs. A route may be blocked (Class 4). On a material adverse change, a route is reclassified and re-assented or disabled; terms at unknown, unlocatable, or arbitrary future URLs are not incorporated.
9.3 Managed credentials and future customer-directed provider accounts. Managed credentials do not make Customer a contracting party of a Provider. If we later make a customer-directed Provider account configuration available, Customer's direct agreement with that Provider will govern that Provider relationship, and Customer will be responsible for its Provider fees, quotas, and data settings.
9.4 Third-party services. Providers, Models, Tools, connectors, payment processors, and other third parties are independent. We do not guarantee their continued availability, capacity, pricing, model behavior, or policies, and a change, limitation, or discontinuation required by law, a Provider, or a payment or regional rule is not a breach of any availability, model, or timing commitment. We make no representation or warranty regarding any Provider's, Model's, or other third party's data handling, retention, training, security, availability, or intellectual-property practices. Customer's access to or use of any Provider, Model, Tool, connector, or other third party through the Services is subject to that third party's own terms and policies, and we are not responsible or liable for their acts or omissions.
10. Tools, MCP, Skills, Connectors and Agent Actions
10.1 Customer authorization. Customer authorizes and configures any Tool, MCP server, Skill, or connector it enables, and is responsible for reviewing their source, licenses, permissions, credentials, and data access, and for applying least privilege.
10.2 Agent actions. Where an Agent, acting under Customer's configuration and authorization, performs an external action, such as sending, deleting, paying, publishing, or deploying, that action is attributed to Customer as its own. We may make approval or sandbox controls available but do not guarantee that we will intercept every erroneous or malicious action. Customer is responsible for configuring approvals and for monitoring and finally confirming business or production actions.
10.3 Third-party components and side effects. Third-party components and external systems are independent. Customer is responsible for external side effects, third-party contracts, and system consequences of the actions it authorizes.
11. Sensitive Information, Secrets and Restricted Data
11.1 Data classification policy. The Services apply a four-tier policy of ordinary, restricted, prohibited, and Secrets data. Customer is responsible for identifying, classifying, minimizing, de-identifying, and lawfully handling the data it submits, and for selecting appropriate data paths.
11.2 Prohibited and restricted categories. Customer must not submit data that the Services are not approved to process. Unless we expressly approve a specific written data path in advance, Customer must not submit protected health information, full payment-card or PCI sensitive authentication data, government identifiers, children's data, biometric templates, government secrets, export-controlled technical data, highly sensitive credentials, or other regulated or high-risk sensitive data into prompts, files, traces, source code, or other general-purpose fields. Customer must not submit children's data except as permitted by applicable law and with the required consents under Section 1.4.
11.3 Secrets. API Keys, OAuth tokens, MCP credentials, private keys, and database administration credentials must not be placed in prompts, files, traces, or source code. They may be provided only through a documented secrets channel if one is expressly made available for that purpose; otherwise Customer must not submit them to the Services.
11.4 Our obligations preserved. We remain responsible for truthfully disclosing data paths, implementing our DPA and security obligations, protecting the Secrets within our control, and taking reasonable isolation, deletion, notice, or legally required retention measures for data that has entered our control, including where Customer has mis-sent data. A Customer's mis-transmission does not relieve us of the obligations we have actually assumed.
12. Subscriptions, Fees, Credits and Taxes
12.1 Prices, plans, Credits, and checkout. Subscriptions, fees, usage charges, Credits, taxes, renewal, cancellation, and refunds are governed by this Section 12, the Pricing page, the disclosures presented at checkout, and any applicable Order Form. These Terms do not statically list current plan prices, included Credits, usage rates, promotional amounts, or other variable commercial quantities. The then-current Pricing page states the generally available plan prices, included Credits, any applicable usage rates, and any promotional Credits, and checkout or an Order Form states the transaction-specific price, currency, renewal timing, cancellation method, and any Credit expiry for the purchase. If the Pricing page and checkout or an Order Form conflict for a specific purchase, the checkout disclosure or Order Form controls that transaction. "Credits" are the usage units we make available for the Services. Promotional Credits are Credits we provide without a separate purchase, including free Credits issued at signup or through a promotion. Credits that Customer separately purchases (such as top-up Credits) are prepaid usage allowances for the Services. Credits are not money or a cash equivalent, and are not a wallet, deposit, stored-value or bank account, or a property right; they have no monetary value outside the Services and are not transferable or redeemable for cash except where required by law. All purchases of Credits are final. Except as required by applicable law or for our verified billing error, purchased Credits are non-refundable. Pricing and checkout disclosures do not override these Terms on liability, dispute resolution, data use, indemnity, or other non-commercial terms.
12.2 Money flow. At this time, the only money flow governed by this Agreement is the subscription and usage fees Customer pays to us. HarnessRouter does not currently provide third-party seller payouts or customer payment collection for applications built by Customer.
12.3 Authorization and disclosure. Where a plan involves a recurring charge, the actual price, currency, renewal date and frequency, cancellation method, and any Credit expiry are disclosed conspicuously near the charge control, and the applicable authorization for the transaction and any automatic renewal is obtained at that point, as required by applicable law.
12.4 Taxes. Customer is responsible for taxes lawfully imposed on its purchases, and may provide exemption, reverse-charge, or withholding documentation. We remain responsible for our own income tax and for collection, invoicing, and reporting obligations that law imposes directly on us, which are not transferred to Customer.
12.5 Refund remedy on no-fault termination. Where we terminate or permanently discontinue a paid Service without Customer's fault, a no-fault-termination refund remedy applies for Customer's benefit. Unless applicable law requires otherwise, the remedy is a pro-rata refund or credit of prepaid, unused fixed Subscription Fees (as defined in Section 21.3) for the affected paid Service, calculated based on the unused portion of the then-current subscription period after the effective termination or discontinuation date. Included Credits, consumed Credits, separately purchased Credits (including top-up Credits), Promotional Credits, usage charges, pass-through third-party costs, taxes, and payment-processing amounts are not refunded except where required by law or where the charge resulted from our verified billing error.
13. Services Not Currently Offered
13.1 Not currently offered. Certain features and services are not currently offered. If we later offer one and it requires additional terms, those terms are added under Section 23.2 with any required notice and re-acceptance, apply prospectively only, and apply only when Customer enables the feature. A future Service Schedule, if any, is not incorporated by the clickwrap and is not part of the Agreement manifest unless it is presented and accepted as part of that manifest or otherwise validly added under Section 23.2.
14. Intellectual Property and Feedback
14.1 Our IP. As between the parties, we and our licensors own the Services, the platform software, the HarnessRouter name and marks, and all related intellectual property. No rights are granted except the limited license in Section 4.
14.2 Customer IP. Customer retains its background intellectual property and its Customer Content, subject to the limited license in Section 7.
14.3 Feedback. If Customer provides suggestions or feedback, Customer grants us a non-exclusive, worldwide, royalty-free, perpetual, and irrevocable license to use, reproduce, adapt, and incorporate it to operate, develop, secure, and improve our products, services, and business, including through our Affiliates, successors, and persons acting on our behalf, without obligation or attribution. This does not grant rights in Customer Content, Customer's marks, or Customer's Confidential Information merely because they accompany the feedback.
14.4 Third-party and open-source components. Third-party and open-source components remain subject to their own licenses, and applicable open-source and third-party notices are made available in the Documentation or on request.
15. Privacy, Data Processing and Security
15.1 Roles. We act as a controller or business for the data we process for our own account, such as account, billing, security, anti-abuse, and marketing data, and as a processor or service provider when we process Customer Personal Data on Customer's behalf under the DPA. The Privacy Policy describes our processing as a controller or business; it is a notice and does not create a general consent that waives statutory rights.
15.2 DPA. Where we process Customer Personal Data on Customer's behalf, the DPA applies as provided in Section 2.6. Customer remains responsible for its own legal basis, notices, and instructions.
15.3 Security. We implement technical and organizational measures appropriate to the nature of the Services but do not warrant absolute security or that we will prevent every attack or detect every mis-transmission of sensitive data. We respond to security incidents as required by applicable law. These measures include, as appropriate, encryption of data in transit and at rest, access controls and per-tenant isolation, logging, and incident response, as further described in the technical and organizational measures in the DPA (Annex 2) at https://harnessrouter.ai/legal/dpa. Vulnerability reporting and incident-handling procedures are described in the Security and Vulnerability Disclosure Policy at https://harnessrouter.ai/legal/security.
16. Confidentiality
16.1 Definition. "Confidential Information" means non-public information that one party (the discloser) makes available to the other (the recipient) in connection with this Agreement, whether or not marked, that is identified as confidential or that a reasonable person would understand to be confidential given its nature or the circumstances of disclosure. It includes Customer Content; non-public pricing, roadmap, and product plans; security, architecture, and technical measures; and non-public account, usage, and business information. The exceptions in Section 16.3 apply.
16.2 Mutual obligation. Each party will protect the other's Confidential Information with at least reasonable care and use it only to perform under this Agreement. A recipient may disclose Confidential Information only to its personnel, Affiliates, advisers, contractors, and subprocessors who need it to perform under this Agreement and who are bound by confidentiality obligations at least as protective as this Section; the recipient remains responsible for their compliance.
16.3 Exceptions. Confidential Information does not include information that is or becomes public through no breach, was known without duty of confidence, is independently developed, or is rightfully received from a third party.
16.4 Compelled disclosure. A party may disclose Confidential Information to the extent required by law or legal process, giving reasonable prior notice where lawful.
16.5 Necessary operational disclosure. Disclosure of Customer Content or configuration to the Provider, Model, or subprocessor necessary to provide the Services is permitted under this Agreement and the DPA and is not an unlimited license to disclose.
16.6 Return or destruction. On the discloser's written request or on termination of this Agreement, the recipient will return or destroy the discloser's Confidential Information in its possession, except copies retained to meet a legal or regulatory obligation, held in routine backups or archives that are isolated from active use and expire on the ordinary cycle, or as permitted under this Agreement or the DPA. Confidential Information retained under this Section remains subject to this Section for as long as it is kept.
17. Suspension
17.1 Grounds. We may suspend, limit, or remove content or access, in whole or in part, for security, a violation of Sections 4, 10, 11, or 22, applicable Provider-route restrictions, or applicable law, sanctions or trade-control reasons, non-payment, a third-party or upstream requirement, or a capacity or fraud risk.
17.2 Notice and restoration. We will provide notice and a path to appeal or restoration where doing so is feasible and lawful and would not impede an investigation or breach a legal or third-party requirement. We do not promise advance notice in every case. Suspension does not relieve Customer of fees already due.
18. Term, Termination, Export and Deletion
18.1 Term. This Agreement applies while Customer has an account or uses the Services.
18.2 Cancellation and termination. Customer may cancel through the cancellation method made available in the account, checkout, billing portal, or Documentation. We may terminate or suspend for the grounds in Section 17 or for material breach. Termination does not by itself waive fees already incurred, refund or chargeback obligations, tax obligations, or surviving obligations. Where we terminate or permanently discontinue a paid Service without Customer's fault, the no-fault-termination refund remedy in Section 12.5 applies.
18.3 Export and deletion. We provide feasible export and deletion consistent with our published retention policy and the DPA, subject to backup cycles and to fraud, security, financial, and legally required retention. We do not guarantee indefinite recoverability. Export is available as described in the Documentation at https://harnessrouter.ai/docs. Following account deletion or termination, we delete Customer Content from our active production systems in accordance with the retention section of the Privacy Policy and the DPA, subject to the exceptions stated there.
18.4 Survival. Provisions that by their nature should survive termination survive, including Sections 2 (Definitions), 4 (as to restrictions), 6.2, 7.1, 8, 11.4, 12 (as to amounts due), 14, 16, 19, 20, 21, 22, 23, 24, and 25, together with any accrued payment, tax, refund, chargeback, and indemnity obligations, and any other provisions that by their nature should survive. Any defined term used by a provision that survives continues to have its defined meaning for that purpose.
19. Disclaimers
Covered Parties. For Sections 19 and 21, the "Covered Parties" are we, our Affiliates, and our and their licensors, suppliers, service providers, officers, directors, employees, contractors, agents, successors, and assigns; the disclaimers, exclusions, limitations, and cap in these Sections apply to the Covered Parties collectively.
19.1 AS IS / AS AVAILABLE. EXCEPT AS EXPRESSLY STATED IN THIS AGREEMENT, THE SERVICES, INCLUDING BETA, DEMO REPLAY, OUTPUT, ARTIFACTS, THIRD-PARTY SERVICES, AND GENERATED CONTENT, ARE PROVIDED "AS IS" AND "AS AVAILABLE," WITH ALL FAULTS.
19.2 No implied warranties. TO THE FULLEST EXTENT PERMITTED BY LAW, THE COVERED PARTIES DISCLAIM ALL WARRANTIES, EXPRESS, IMPLIED, STATUTORY, OR OTHERWISE, INCLUDING MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, QUIET ENJOYMENT, NON-INFRINGEMENT, AND ANY WARRANTY ARISING FROM COURSE OF DEALING, USAGE, TRADE, OR PERFORMANCE. The Covered Parties do not warrant that the Services, Output, or Artifacts will meet Customer's requirements, or be accurate, complete, current, original, unique, uninterrupted, secure, error-free, or free of viruses or other harmful components, or that defects will be corrected. We do not warrant that any Provider, Model, Tool, connector, payment processor, or other third party will remain available.
19.3 Risk-reduction measures. Sandboxing, scanning, approval flows, renderer isolation, and security controls reduce but do not eliminate risk and are not a guarantee of protection.
19.4 Statutory limits. This Section applies only to the extent permitted by applicable law and does not exclude a warranty or right that law does not permit to be excluded, and does not disclaim any service level, security commitment, or obligation that we cannot lawfully exclude. Some jurisdictions do not allow the disclaimer of implied warranties or the exclusion of certain statutory rights, so some of the disclaimers in this Section may not apply to Customer. Nothing in this Section excludes any warranty, right, or remedy that applicable law does not permit to be excluded.
20. Indemnification
20.1 Customer indemnity. Customer will defend, indemnify, and hold us harmless from third-party claims to the extent caused by, and having a causal connection with: (a) Customer Content, Customer Applications, or Customer's marks or domains infringing or violating third-party intellectual property, privacy, or other rights; (b) Customer's lack of rights, notices, consents, or legal basis, or its submission of restricted or prohibited data; (c) the unlawful use of, or violation of Sections 4, 10, 11, or 22, applicable Provider Terms, or applicable Provider-route restrictions in connection with, the Services by Customer, an Authorized User, or an End User; (d) Tools, MCP servers, Skills, connectors, third-party accounts, and Agent actions Customer authorized; (e) Customer's use, external publication, external deployment, sale outside the Services, or decisions based on Output; and (f) a claim by an End User arising out of a Customer Application, Customer's products or services, or Customer's relationship with that End User, except to the extent the claim results from our breach of this Agreement. This indemnity covers defined third-party claims with the required causal connection and is not an indemnity for any and all matters arising from use. Any indemnity specific to a service that we do not currently offer is not part of this Agreement and applies only if and when that service is offered under Section 13.
20.2 Procedure. We will give Customer prompt notice and reasonable control of the defense, and will reasonably cooperate; we may participate with our own counsel. Customer may not, without our consent, agree to a settlement that admits our fault, imposes a continuing obligation on us, or restricts our business.
20.3 Our indemnity (limited). The self-serve Agreement does not provide a broad indemnity from us. Any defense obligation of ours, if provided, is set out only in a signed Order Form or Enterprise MSA, is limited to claims that our unmodified service directly infringes a third party's registered intellectual property, and excludes claims arising from Customer Content, Output, third-party models or components, open-source software, Customer instructions or combinations, use not in accordance with the Documentation, continued use of a version after notice to stop, or claims Customer could avoid by updating, replacing, or ceasing use. The sole remedy is to procure the right to continue use, modify or replace the affected service, or terminate the affected part and refund prepaid unused fees. We provide no broad non-infringement indemnity for AI Output.
20.4 Consumer scope of Customer indemnity. For an individual Customer using the Services solely for personal, family, or household purposes, the indemnity in Section 20.1 is limited to third-party claims to the extent caused by that Customer's own unlawful conduct, infringement or violation of a third party's intellectual property, privacy, or other rights, submission of restricted or prohibited data, or breach of Sections 4, 10, 11, or 22. The full indemnity in Section 20.1(a)โ(f) applies to a Customer using the Services for business, organizational, or commercial purposes, including through Authorized Users or End Users. This Section does not limit any other remedy available to us.
21. Limitation of Liability
21.1 Exclusion of indirect damages. TO THE FULLEST EXTENT PERMITTED BY LAW, NEITHER PARTY, AND NONE OF THE COVERED PARTIES, IS LIABLE FOR LOST PROFITS, REVENUE, GOODWILL, BUSINESS OPPORTUNITY, ANTICIPATED SAVINGS, DATA, USE, OR SUBSTITUTE SERVICES, OR FOR ANY INDIRECT, INCIDENTAL, SPECIAL, PUNITIVE, EXEMPLARY, OR CONSEQUENTIAL DAMAGES, ON ANY THEORY, EVEN IF ADVISED OF THE POSSIBILITY. The exclusion of data-loss damages is consistent with, and does not override, the export, retention, and backup obligations expressly stated in this Agreement.
21.2 Aggregate liability cap. TO THE FULLEST EXTENT PERMITTED BY LAW, THE TOTAL AGGREGATE LIABILITY OF THE COVERED PARTIES ARISING OUT OF OR RELATING TO THE SERVICES, THIS AGREEMENT, OR ANY SERIES OF RELATED FACTS, WHETHER BASED ON CONTRACT, TORT INCLUDING NEGLIGENCE, STRICT LIABILITY, STATUTORY DUTY, MISREPRESENTATION, RESTITUTION, INDEMNITY, WARRANTY, OR ANY OTHER LEGAL OR EQUITABLE THEORY, WILL NOT EXCEED THE GREATER OF (A) USD 100 OR (B) THE TOTAL AMOUNTS CUSTOMER ACTUALLY PAID TO US FOR THE SERVICES IN THE SIX (6) MONTHS BEFORE THE FIRST EVENT GIVING RISE TO THE CLAIM. For this Section, "amounts paid" means amounts Customer actually paid to us for the Services in the applicable period, and excludes taxes and any amount that was or is refunded, credited or charged back, disputed, reversed, or obtained through fraud or abuse. For a Customer with no such amounts paid in the applicable period, including free, Demo, and Beta accounts, the amount is USD 100.
21.3 Meaning of Subscription Fee; exclusions. "Subscription Fee" means only the fixed periodic fee for access to the current plan. It does not include, whether or not consumed, settled, or passed through: usage charges; Promotional Credits; model, Provider, Tool, MCP, cloud, storage, or other third-party or pass-through amounts; payment-processing fees; taxes; and any amount payable to a third party. The defined term "Subscription Fee" is used for the refund and service-credit remedies in Sections 21.9 and 12.5; the liability-cap base is the amounts-paid measure in Section 21.2.
21.4 Single aggregation. All claims of a Customer arising from the same or related facts, events, failures, or conduct are aggregated across these Terms, any Order Form, the DPA, and that Customer's Authorized Users, End Users, Runs, and Models into a single cap, and are not multiplied per claim, per event characterization, per user, per Run, or per document. This Section aggregates the claims of a single Customer and its own users and does not merge the separate liabilities we owe to different Customers under their respective agreements into one cap.
21.5 Amounts that are not capped damages. The cap and the exclusion of damages do not limit debts, restitution, or funds. Customer's payment, tax, refund, chargeback, and third-party pass-through obligations are amounts due, restitution, or funds responsibility, not ordinary damages subject to the cap. Likewise, our obligations to reverse an erroneous charge, to return an unused balance owed under law or contract, and to return funds we actually hold that belong to Customer or a third party are treated as account corrections or return obligations, not as damages.
21.6 Reciprocal base cap. The base cap for ordinary contractual direct damages applies reciprocally to both parties, without affecting the amounts described in Section 21.5, which remain due in full.
21.7 Indemnification and third-party-claim obligations are outside the cap. The cap in Section 21.2 and the reciprocal base cap in Section 21.6 do not limit: (a) either party's indemnification, defense, and hold-harmless obligations under Section 20, except that our limited indemnity remains subject to the sole-remedy limit in Section 20.3; (b) Customer's obligations under Sections 22.2 and 22.3 (sanctions and trade controls), subject to Sections 22.4 and 22.5; and (c) Customer's liability for infringement or misappropriation of a third party's intellectual property, violation of Sections 4, 10, 11, or 22, submission of restricted or prohibited data, or unlawful use of the Services. Section 20.4 (consumer scope of the Customer indemnity) and Section 21.8 (matters that cannot lawfully be limited, including Section 25 for Consumers) continue to apply, so this Section does not enlarge any obligation that non-waivable law or Section 20.4 limits.
21.8 Statutory carve-outs. The cap and the exclusions apply only to the extent liability may lawfully be limited. To the extent liability cannot lawfully be limited, this Section does not apply to it. This preserves, without enlarging, matters that applicable law does not permit to be limited, which may include fraud, willful injury, a violation of law (California Civil Code Section 1668), non-waivable consumer rights (including California Civil Code Section 1751), liability that cannot be released for gross negligence (City of Santa Barbara v. Superior Court), and non-waivable public injunctive relief (McGill v. Citibank). We do not voluntarily enlarge these carve-outs beyond what law requires or what we have expressly approved in writing. Some jurisdictions do not allow the exclusion or limitation of certain damages or liabilities, so some of the exclusions and limitations in this Section may not apply to Customer; this Section applies only to the fullest extent permitted by applicable law. For a consumer resident in the EEA, UK, or Switzerland, this Section is subject to Section 25.
21.9 Retained operative remedies. Notwithstanding the aggregate liability limitation in this Section, for a failure of the Services to conform to this Agreement we will, at our election, provide one or more of the following as Customer's remedy for that failure: (a) re-performance or repair of the affected Service; (b) replacement of the affected Service; (c) a reasonable service credit; or (d) termination of the affected Service and a pro-rata refund of prepaid, unused fixed Subscription Fees, applying the no-fault-termination refund remedy in Section 12.5. Ledger reversal of verified billing errors, and any remedy that cannot lawfully be limited, are preserved and are not affected by this Section.
21.10 Claim period. A claim arising under this Agreement must be brought within one year of the event giving rise to the claim or its reasonable discovery, to the extent enforceable under applicable law and subject to any mandatory-law minimum that cannot be shortened.
21.11 Enterprise. A different cap applies only if set out in a signed Order Form or Enterprise MSA. Any higher security or privacy super-cap applies only to expressly defined events and does not extend to Customer's own unlawful data handling or to third-party systems.
21.12 Essential purpose; basis of the bargain. Each limitation of liability, disclaimer of warranties, exclusion of damages, and limited remedy in this Agreement allocates risk between the parties, forms an essential basis of the bargain, and is severable and independent of the others; where any of them cannot lawfully be limited, it is inapplicable only to the extent necessary, and the remaining cap and exclusions continue to apply to all other matters. To the fullest extent permitted by law, they apply on every theory of liability, even if Customer has been advised of the possibility of damages, even if damages were foreseeable, and even if any limited or exclusive remedy in this Agreement (including Section 21.9) fails of its essential purpose. Nothing in this Section applies to liability that cannot lawfully be limited under Section 21.8.
22. Trade Controls, Sanctions and Regional Eligibility
22.1 Dynamic, feature-level eligibility. The Services use dynamic, feature-level eligibility. Registration, account access, each Provider, Model, and fallback route, payment, Credits, data Region, and Customer Application End User access are each subject to a Gate โ the intersection of applicable legal, sanctions, upstream, tax, data, and product controls. Where a single path is ineligible, only that path is closed; where law requires a hard denial, or circumvention occurs, or all affected paths are unavailable, the affected use is closed. Country and feature status is disclosed as a dynamic factual disclosure in the Services or in a route-specific disclosure and is not written into these Terms. Permitted and restricted regions and restricted-party screening are disclosed where required by applicable law of the regions where the Services are offered, and are not published as a static country list in these Terms.
22.2 Customer representations and undertakings. Customer represents, warrants, and covenants, on acceptance and throughout use, that:
(a) Customer and its known beneficial owners and controllers are not a restricted party and are not located, organized, or ordinarily resident in a region prohibited by applicable law or by the applicable Service rules, and Customer does not use the Services for or on behalf of a restricted party;
(b) Customer is responsible for the continued eligibility of the access region, identity, and use of its Authorized Users, Customer Applications, and End Users, and will immediately stop the affected use and notify us if any entity, ownership, control, address, use region, or eligibility changes;
(c) Customer will not use a VPN, proxy, re-routing, or a false or borrowed address, identity, payment method, tax information, account, or API Key to hide origin or to circumvent a country, party, Provider, Model, payment, or KYC restriction; ordinary corporate VPN use is not itself a violation but must not be used to circumvent;
(d) Customer will not export, re-export, transfer, or provide access to a prohibited party, region, or end use, and will obtain any required license, approval, notification, or registration; and
(e) Customer will promptly provide and update identity, ownership, control, address, use, End User, and license evidence on reasonable request, and a refusal, delay, or material inconsistency may trigger a restriction.
22.3 Prohibited end use. Customer will not use the Services, software, technical data, Output, or a Customer Application for a military, nuclear, chemical, biological, missile, proliferation, sanctioned-transaction, or other prohibited end use, and is responsible for obtaining any required license.
22.4 Our reserved rights and retained obligations. We conduct risk-based screening under laws that apply directly to us and do not rely on Customer's representations alone. We may verify based on account, payment, and network signals; refuse registration, an invitation, a Run, a particular Provider or Model, or a payment; restrict, suspend, or terminate, requiring further evidence and withholding advance notice where notice would impede an investigation or breach a legal or third-party requirement; and block, freeze, refuse to transfer, or report funds where required by law. Unavailability, delay, or a path change caused by law, a Provider, or a payment-region rule is not a breach of any availability, model, or payment-timing commitment. This Section does not transfer our own sanctions, export, reporting, or freezing obligations to Customer, and Customer does not indemnify us for a fine or willful violation that law does not permit to be transferred.
22.5 To the extent lawful. Customer's indemnity for a breach of this Section applies only to the extent permitted by law and is subject to Section 20.
23. General Provisions
23.1 Notices. We may give notice through the account, in-product, or by email. Customer notices to us must be sent to the address we designate. Our contracting and notice entity is Lumentree Corporation, 201 Spear Street, Suite 1100, San Francisco, California 94105. Legal, privacy, billing, and security notices may be sent to contact@harnessrouter.ai. Copyright complaints may be sent to contact@harnessrouter.ai; where the U.S. DMCA applies, we handle notices and counter-notices in accordance with 17 U.S.C. ยง 512. By using the Services, Customer consents to receiving notices, agreements, disclosures, and other communications from us electronically, including by email and in-product notice, and agrees that electronic communications satisfy any legal requirement that a communication be in writing; to receive them, Customer needs a device with internet access and a current email address on the account, and Customer may withdraw this consent by closing the account.
23.2 Changes to the Agreement. We may update the Services, policies, and these Terms as follows. A non-material, clarifying, legal-compliance, security, or Provider-availability update takes effect prospectively on posting or notice, without a new clickwrap. A material adverse change is preceded by at least 30 days' prior notice by email or conspicuous in-product notice. For an existing paid subscription, a change to price, subscription period, or general commercial obligations takes effect at the next renewal term, unless Customer accepts earlier or a legal, safety, or Provider emergency requires otherwise. A legal, regulatory, security, abuse, sanctions, or Provider emergency change may take effect immediately to the extent necessary, with notice as soon as practicable. No update changes a dispute, event, accrued right, or liability that arose before the change takes effect, and a website update does not automatically override a signed Order Form. A material addition or change to the arbitration agreement or class action waiver is separately and conspicuously noticed and may be rejected within 30 days; if rejected, only the dispute-resolution provisions of this Agreement are pinned to the last version Customer accepted and are severed from later updates, while the remainder of the Agreement continues to update, and the first-acceptance 30-day opt-out in Section 24 remains available. Privacy notices are updated as law requires and a contractual continued-use mechanism does not replace a required statutory notice or consent; Documentation is not used to change price, the liability cap, indemnity, data use, or dispute rules.
23.3 Assignment by Customer. Customer may not assign or transfer this Agreement without our prior written consent, and any prohibited assignment is void to the extent permitted by law. However, an organizational Customer may assign this Agreement in its entirety, without our consent, to a Successor in a merger, reorganization, change of control, or sale of all or substantially all of its assets or of the business unit that uses the Services, provided that the Successor is not a direct competitor of ours or a restricted party, the Successor assumes all of Customer's obligations under this Agreement, and Customer gives us prompt written notice of the assignment. This exception does not apply to a Customer using the Services for personal, family, or household purposes.
23.4 Assignment and succession by us. We may assign, transfer, or delegate this Agreement, in whole or in part, to an Affiliate or Successor in connection with a reorganization, merger, change of control, financing, or transfer of the HarnessRouter business or related assets. Customer consents in advance to such permitted transfers and will execute any further instrument that applicable law reasonably requires. The assignee or successor assumes the transferred obligations. To the extent permitted by law, we are released from obligations arising after the effective transfer date once the successor assumes them. All liability caps, disclaimers, claim periods, and defenses continue to apply before and after the transfer. A permitted transfer does not, by itself, give Customer a right to refund, termination, or renegotiation, except where applicable law, an Order Form, or a resulting material adverse change requires. These Terms and the DPA share this same assignment mechanism.
23.5 Successor entity re-acceptance. Where a Workspace or Customer identity is transferred, an authorized representative of the receiving party must re-accept the then-current Agreement by clickwrap to complete the transfer.
23.6 Notice of new contracting entity. Where the contracting entity changes, we will notify Customer of the new legal entity and its contacts and will meet any applicable privacy-transparency, DPA, payment re-authorization, or DMCA designated-agent registration requirement, so that the change does not require re-executing this Agreement.
23.7 Force majeure. Neither party is liable for a delay or failure caused by an event beyond its reasonable control, except for payment obligations.
23.8 Entire agreement. This Agreement is the entire agreement between the parties on its subject matter and supersedes prior agreements on that subject matter.
23.9 Severability. If a provision is unenforceable, it is limited or severed to the minimum extent necessary and the remainder stays in effect.
23.10 No waiver. A failure to enforce a provision is not a waiver.
23.11 No agency; no third-party beneficiaries. The parties are independent contractors. This Agreement creates no agency, partnership, joint venture, or employment. Except as stated in this Section, it confers no third-party beneficiary rights. Each Provider is an intended third-party beneficiary of, and may enforce, only: (a) the provisions that require Customer to comply with the applicable Provider Terms and route-specific restrictions; (b) the disclaimers regarding Providers, Models, and Output (including Sections 8.2 and 19.2); and (c) the limitation of liability in Section 21, in each case solely as to that Provider, solely for the route whose Provider Terms are identified in the Services or in a route-specific disclosure, and solely to the extent those Provider Terms expressly require the Provider to be a third-party beneficiary. A Provider is not a party to, and is not an agent, partner, assignee, or successor of, us; this Section creates no warranty, indemnity, refund, service level, liability, arbitration right, assignment right, or other obligation on our part to any Provider or to Customer beyond what this Agreement already provides, and gives a Provider no rights under Section 20, Section 24, or the assignment and change provisions of this Section 23 except as strictly necessary to enforce clauses (a) through (c). This Section remains subject to non-waivable mandatory consumer law and Section 25. No other person is a third-party beneficiary of this Agreement.
23.12 Survival. Section 18.4 governs survival.
24. Governing Law and Dispute Resolution
Application of this Section. Except as Section 25.4 provides for consumers in the EEA, UK, or Switzerland, and then only to the extent that arbitration, the class-action waiver, California governing law, or the California forum is not permitted by non-waivable mandatory consumer law, this Section 24 applies to all Customers, including any business, enterprise, professional, or organizational user resident or established in the EEA, UK, or Switzerland.
24.1 Governing law. This Agreement is governed by the laws of the State of California, without regard to conflict-of-laws rules, and the United Nations Convention on Contracts for the International Sale of Goods does not apply.
24.2 Informal resolution. Before starting an arbitration, a party will send a written notice describing the dispute and will attempt in good faith to resolve it. The parties will engage in good-faith informal resolution for 45 days after the notice, during which the applicable limitations period is tolled for the dispute.
24.3 BINDING INDIVIDUAL ARBITRATION. EXCEPT FOR THE MATTERS IN SECTION 24.6, ANY DISPUTE NOT RESOLVED INFORMALLY WILL BE RESOLVED BY BINDING, INDIVIDUAL ARBITRATION, NOT IN COURT. The Federal Arbitration Act governs the interpretation and enforcement of this arbitration agreement. The arbitration is administered by National Arbitration and Mediation ("NAM") under its applicable commercial or consumer arbitration rules and fee schedule, with commercial disputes under the applicable commercial or streamlined rules and consumer disputes under the applicable consumer rules, in each case the NAM Rules then in effect and available at https://www.namadr.com. A material change to these arbitration provisions is governed by Section 23.2 rather than applied automatically. For clarity, the version-pinning available under Section 23.2 applies to the terms of these arbitration provisions in this Agreement; NAM's own procedural rules and fee schedule apply as then in effect when an arbitration is commenced. Coordinated or mass filings are administered under Section 24.10. The seat of arbitration is San Francisco, California.
24.4 CLASS ACTION WAIVER. THE PARTIES WILL BRING CLAIMS ONLY IN AN INDIVIDUAL CAPACITY, AND NOT AS A PLAINTIFF OR CLASS MEMBER IN ANY CLASS, COLLECTIVE, OR REPRESENTATIVE PROCEEDING. The arbitrator may not preside over any class, collective, or representative proceeding or award class, collective, or representative relief; Section 24.7 preserves non-waivable public injunctive relief in court. Coordinated administration of mass filings under Section 24.10 is not a class, collective, or representative proceeding, does not consolidate the claims into a single claim, and does not make one claimant's result binding on another claimant.
24.5 30-DAY OPT-OUT. Customer may opt out of the arbitration agreement, the class action waiver, and the coordinated-filing provisions in Sections 24.3, 24.4, and 24.10 by sending notice within 30 days after first accepting this Agreement. Notice of opt-out must be sent to contact@harnessrouter.ai, or by mail to the notice address in Section 23.1, and must identify Customer's account and state Customer's intent to opt out. Opting out does not affect any other part of this Agreement. This opt-out is separate from the arbitration-update rejection right in Section 23.2.
24.6 Court exceptions. The following are not subject to arbitration and may be brought in court: (a) a claim in small claims court that qualifies; (b) a request for temporary or equitable relief to protect intellectual property, Confidential Information, account or platform security, or against unauthorized access; (c) a matter a regulator may lawfully hear; and (d) confirmation or enforcement of an arbitration award and any non-arbitrable matter. Any such court proceeding will be brought in the state courts located in San Francisco County, California, or in the United States District Court for the Northern District of California.
24.7 Public injunctive relief. Nothing in this Section waives a party's right to seek public injunctive relief that applicable law does not permit to be waived (McGill v. Citibank). To the extent a claim for public injunctive relief is asserted and cannot be waived or sent to arbitration, it may be brought in the courts identified in Section 24.6, and the remainder of this Section continues to apply to all other claims.
24.8 Jury trial. A valid arbitration waives a jury trial for the matters sent to arbitration. This Agreement does not rely on a standalone predispute contractual jury-trial waiver as an independent protection.
24.9 Severability of this Section. If the class action waiver in Section 24.4 is found unenforceable as to a particular claim, that claim is severed and may proceed in the courts in Section 24.6, and the remainder of this Section, including individual arbitration of all other claims, continues to apply. If the coordinated-filing provisions in Section 24.10 are found unenforceable as to a particular claimant or batch, that claimant's or batch's demands proceed as individual arbitrations under this Section, without invalidating the coordinated administration of other batches or the remainder of this Section. If any other part of this Section is unenforceable, it is severed to the minimum extent necessary. Where any provision of this Section is found unenforceable as to a particular person, claim, remedy, jurisdiction, or consumer status (including as to a consumer within the scope of Section 25), that unenforceability is severed only as to that person, claim, remedy, jurisdiction, or status, and does not invalidate or impair the arbitration agreement, the class-action waiver, the governing-law provision, or the forum provision as to any other Customer, including any business, enterprise, professional, or organizational user resident or established in the EEA, UK, or Switzerland.
24.10 Coordinated or mass filings. If 25 or more arbitration demands raising the same or substantially similar claims are submitted by or with the coordination or assistance of the same or coordinated counsel within a 90-day period, those demands are administered as a coordinated mass proceeding under NAM's Mass Filing Supplemental Rules and fee schedule, rather than as concurrent separate cases. Coordinated administration under this Section does not create a class, collective, or representative proceeding, does not make one claimant's result binding on any other claimant, and preserves each claimant's right to an individualized determination of its own demand and to all remedies otherwise available to that claimant. Regardless of the administrator's procedures, each claimant retains the right to an individual arbitrator, an individual hearing, and an individual award on the merits of its own demand, and no bellwether, test-case, or precedent procedure may make the outcome of one claimant's demand binding on any other claimant without that claimant's consent. The batching, sequencing, and fee provisions are those of NAM's Mass Filing Supplemental Rules then in effect when the demands are commenced and available at https://www.namadr.com; consistent with Section 24.3, the version-pinning under Section 23.2 applies to the terms of these arbitration provisions in this Agreement and not to NAM's own procedural rules. For a Customer using the Services for personal, family, or household purposes, we will bear the portion of NAM's fees that applicable California law or NAM's Consumer Rules require the business to bear, and the claimant's filing fee will not exceed the then-current filing fee for a claim in the Superior Court of California. The applicable limitations period is tolled for each demand while it awaits administration in the queue. If a demand has not been assigned a merits arbitrator within 120 days of its proper filing (excluding delay the claimant causes or the parties jointly request), the claimant may elect to withdraw that demand and proceed in the courts identified in Section 24.6 or in small claims court. If NAM declines to administer the demands on a mass or batch basis, the demands proceed as individual arbitrations under this Section. Nothing in this Section limits a claimant's choice of counsel or requires claimants to share counsel. This Section applies equally to Customer and to us and does not waive any claim.
25. Additional Terms for Consumers in the EEA, UK, and Switzerland
25.1 Who this Section covers. This Section applies only to an individual resident in the European Economic Area (EEA), the United Kingdom, or Switzerland who uses the Services wholly or mainly outside that individual's trade, business, craft, or profession (a "Consumer"). It does not apply to any organization, to anyone who accepts this Agreement on behalf of an organization, or to any individual who uses the Services for trade, business, or professional purposes; every such Customer โ including one resident or established in the EEA, UK, or Switzerland โ remains governed by the general terms of this Agreement, including Sections 21 and 24. A lowercase "consumer" elsewhere in this Agreement refers more broadly to any individual protected under an applicable mandatory consumer-protection law and does not by itself bring that individual within this Section. Only to the extent a non-waivable mandatory rule applicable to a Consumer conflicts with a provision of this Agreement does that rule control, and then for that conflict only; all other provisions remain in full force.
25.2 Your statutory rights. Nothing in this Agreement excludes, limits, or otherwise affects any right or remedy that the mandatory consumer-protection law of a Consumer's country of habitual residence grants and does not permit to be waived โ including the non-waivable rights preserved by Section 1.5 and Section 21.8, the legal guarantee of conformity for digital content and digital services under applicable EEA consumer law, and, for a Consumer resident in the United Kingdom, the statutory rights and remedies for digital content under the Consumer Rights Act 2015.
25.3 Right of withdrawal. A Consumer resident in the EEA or the United Kingdom who enters into a distance contract for a paid Service generally has the right to withdraw from that contract within 14 days without giving any reason. Mandatory Swiss law does not provide this withdrawal right, and this Agreement does not add one for a Consumer resident in Switzerland. Where the right applies, checkout or account disclosures identify the immediate-performance consent, acknowledgment, contract confirmation, pro-rata charge for Services already performed, refund timing and method, and any other mechanics required by applicable law.
25.4 Dispute resolution and governing law for Consumers. Section 24 โ including binding individual arbitration, the class-action waiver, California governing law and forum, and the coordinated-filing provisions โ applies to a Consumer only to the extent permitted by the mandatory law described in Section 25.2. To any extent it is not permitted: (a) the Consumer keeps the protection of the mandatory consumer-protection rules, and any more protective governing law, of the Consumer's country of habitual residence; (b) the Consumer may bring proceedings in, and may be sued only in, the courts that such mandatory law makes available, including the courts of the Consumer's place of residence; and (c) the Consumer may use any dispute-resolution entity or consumer authority that such law makes available. This Section disapplies the corresponding provisions of Section 24 only for that Consumer and only to the extent required; Section 24 otherwise remains in full force for that Consumer and for every other Customer.
