Legal
Terms of Service
Agent Vault lets software agents spend your money and sign in as you. These terms set out what we provide, what we do not promise, and — importantly — what you remain responsible for when an agent acts on your behalf.
1. The agreement
These terms are a contract between you and [LEGAL ENTITY NAME], registered at [REGISTERED ADDRESS] (“we”, “us”), the operator of Agent Vault, a product of Self.xyz. By creating an account or using the service you agree to them. If you do not agree, do not use the service.
Our Privacy Policy forms part of this agreement and describes what we do with your data. Where the two documents describe the same behaviour, they are intended to agree; if they conflict, the Privacy Policy governs how data is handled.
If you are agreeing on behalf of a company, you confirm you are authorised to bind it, and “you” means that company.
2. Preview status
Agent Vault is a preview. It is under active development, parts of it are incomplete, and it is offered for evaluation. Concretely, and without limiting the disclaimers in §12:
- Our card vault account is an evaluation tenant, not a production plan (§6).
- Some data-lifecycle behaviour does not yet match what these terms and our Privacy Policy intend, and each gap is flagged in place below rather than glossed over.
- We may change, suspend, or discontinue any part of the service, including your access to it, at any time and without notice.
Do not store cards, credentials, or identity data you rely on, and do not use the service for purchases you cannot afford to have go wrong.
3. What the service does
You store payment cards, postal addresses, identity details, and site logins in Agent Vault. You then issue an API key to an AI agent. That key can be restricted to specific cards and logins, and a card placed behind an agent card can be bounded by spending limits, merchant allowlists, and approval requirements. API-key scope, allowlists and approval requirements are not applied by default: a key created without them reaches every card and login on your account, and identity details and addresses cannot be restricted per key at all. Spending limits are — the first funding card you add through the dashboard is given an agent card carrying starter caps of $75 per transaction, $200 per week and $500 per month, plus $100 per day on plans that allow a daily cap. Those are defaults, not a ceiling we enforce for you: you can change or remove them, and a card you add another way may have none. §12 of the Privacy Policy sets out which control covers which value.
When your agent shops or signs in, it fills forms with mock tokens — placeholder values that carry no secret. Our checkout proxy runs the actual browser and substitutes your real values into the page at the last moment, after our backend has authorised that specific use. Your card number, security code and password are never returned to the agent through our API, and are redacted from screenshots and error text. That is a narrower promise than “the agent never has them”, and deliberately so: your agent controls the session. The keyboard route out is closed, though — once a real value has been substituted into a session, the proxy refuses every clipboard-capable chord, so a value the agent cannot read cannot be copied out with a shortcut either. §4 of the Privacy Policy describes the path and the guard (issue #252).
The browser runs on our infrastructure, but by default its network traffic is relayed back out through the machine running your agent, so merchants see your IP address rather than ours. This is deliberate — a datacenter IP blocks many checkouts — and it is switchable. The default prefersthe relay rather than requiring it, and an attested checkout reaches the merchant from our datacenter instead, so that path shows our address even on default settings. Pass tunnel: true to make the relay mandatory. See §4 of the Privacy Policy.
Where a site raises a challenge the agent cannot pass, the session can be handed to you: a live view of the proxy’s browser is streamed to you and your input is relayed back so you can complete the step. That view is reached through an emailed link, and the link itself is the credential — it does not require you to be signed in, and it stays usable until the handoff expires or settles rather than being spent on first use, so treat it like a password reset email (see §7 of the Privacy Policy). Where a purchase needs a card security code, we prompt you for it at that moment.
We are not a payment processor, a bank, or a money transmitter. We do not hold, move, or settle funds. Purchases are made directly between you and the merchant with your own payment card; we automate the filling of their form.
4. Eligibility and your account
- You must be at least 18 and legally able to enter into this contract.
- You must give accurate account information and keep it current. You are responsible for everything done under your account.
- Your API keys are credentials. Anyone holding one can direct spending within its scope and limits. Keep them secret, scope them narrowly, and revoke them immediately if exposed — you can do this from the dashboard at any time.
- Tell us promptly at [support@…] if you suspect unauthorised access.
5. You are responsible for your agent
This is the most important clause in this document.
- An action taken by your agent, with your key, within the limits you set, is your action. Purchases it makes are real purchases on your real card, and you owe the merchant for them. Sign-ins it performs are your sign-ins.
- AI agents are non-deterministic. Yours may buy the wrong item, the wrong quantity, from the wrong merchant, at the wrong price, or at the wrong time. It may be manipulated by content on a page it visits into doing something you did not intend. The controls we provide — per-card spending limits, merchant allowlists, approval prompts, scoped and revocable keys — exist to bound that risk. They reduce it; they do not remove it. Set limits you can afford to lose.
- Know what “pause” actually pauses. An agent card’s merchant allowlist, pause control, and approval threshold apply to card and security-code fills. Its spending limits apply to card-number fills only — a checkout that asks for the security code alone can still be stopped by a pause, an allowlist or an approval, but it is not counted against your limits. None of them stop an agent resolving a saved password, a one-time code, an identity field, or an address. If you need to stop an agent completely, revoke its API key — that halts every kind of resolution at once, with one exception: a challenge handoff already sitting open on your phone is not cancelled by the revocation, so do not complete one after revoking (issue #212). A security-code request is not an exception — the card is re-authorised after you enter the code and before it is released, so revocation stops it. Closing the pause gap is tracked as issue #181.
- You are responsible for reviewing your activity feed and for disputing incorrect charges with the merchant or your card issuer. We are not a party to those transactions and cannot reverse them.
- You confirm that you own, or are authorised to use, every card, address, identity detail, and login you store, and that you may lawfully authorise an automated agent to use them.
6. Card vault and stored credentials
Card numbers you add are stored with Basis Theory, a PCI-DSS Level 1 certified tokenization vault; of the number we hold only a token reference. We do keep the card’s metadata ourselves — last four digits, brand, expiry month and year, cardholder name, and which billing address it uses — so the dashboard can show you the card and a checkout can fill those fields. Security codes are not stored — you are prompted for one per purchase. Site passwords and one-time-code seeds are stored, encrypted at rest.
Those statements describe what the system does with data you add now. Records left by the designs that preceded the vault, the live-security-code flow, and the current credential encryption are still being purged and re-keyed, and §5 and §6 of the Privacy Policy set out exactly what that means. Read them rather than this summary if the detail matters to you.
Evaluation status. Our account with Basis Theory is currently an evaluation tenant, not a production plan. Basis Theory’s PCI-DSS Level 1 certification belongs to Basis Theory and describes their vault. It is not a certification of Agent Vault. We hold no PCI, SOC 2, or ISO certification and make no such claim about ourselves.
Where your card number is revealed. To type your card into a merchant’s checkout, our proxy retrieves the number from the vault and holds it in memory — not only for that fill, but for the rest of that agent session, so it can blank the value out of screenshots and error messages. It is never written down. That is what happens wherever card filling works at all today; a deployment not configured to fill cards refuses before any number is retrieved. Our software also carries a second, attested checkout path that would move the reveal into an isolated enclave so that not even we can see it — but that enclave is not deployed, every attested checkout is refused before a card is handed over, and we do not claim that protection. See §5 of the Privacy Policy.
Many sites’ terms restrict credential sharing and automated access. Storing a login and authorising an agent to use it is your decision, and you are responsible for whether it is permitted by that site — see §10.
7. Acceptable use
You will not, and will not configure an agent to:
- Store or use a card, address, identity detail, or login that is not yours or that you are not authorised to use.
- Make a purchase you do not intend to pay for, or commit payment fraud of any kind.
- Buy or attempt to buy anything unlawful where you or the merchant are located, or anything you are barred from purchasing.
- Use the service in breach of sanctions or export-control laws, or from a sanctioned jurisdiction.
- Automate access to a site in a way that breaches that site’s terms, or use the service to scalp, hoard, or circumvent purchase limits, queues, or anti-bot protections where doing so breaches those terms.
- Attempt to extract a stored secret through any channel other than an authorised fill — including by prompting an agent to reveal it, by exploiting a merchant page to echo it back, or by attacking the proxy.
- Probe, scan, overload, or interfere with the service or its infrastructure, or bypass any limit, quota, or authorisation check.
- Reverse engineer, resell, or provide the service to third parties as your own, except as the applicable open-source licences permit.
- Use the service to harass, defraud, or harm anyone.
We may investigate suspected breaches and take action under §15, including revoking keys or suspending an account, without notice where the risk warrants it.
8. Plans, payment, and cancellation
Plans
Agent Vault offers a free plan and paid plans. As at the date of this draft: Free ($0), Plus ($10 per month), and Pro ($20 per month). Current prices and what each tier includes are shown on our pricing page and prevail over this summary.
Billing
- Paid plans are billed monthly in advance through Stripe. By subscribing you authorise recurring charges to your payment method until you cancel.
- Your card details for the subscription are entered on Stripe’s hosted pages and are handled by Stripe under their terms. We never see them.
- Changing tier mid-cycle is prorated: Stripe adjusts the charge for the remainder of the period.
- Prices are stated exclusive of any applicable sales tax, VAT, or GST. How such tax is charged and by whom: [TAX TREATMENT].
- We may change prices. We will give notice before a change applies to your next renewal — [NOTICE PERIOD FOR PRICE CHANGES].
Cancellation and refunds
- You can cancel at any time. Where the dashboard’s Billing page can open Stripe’s billing portal, cancel there; the portal shows when the cancellation takes effect and whether you keep paid features until the end of the period you have paid for, and it is authoritative over this summary.
- If that button is not available, email us and we will cancel for you. The portal requires a billing-portal configuration that our checkout flow does not, so a deployment can take your subscription while the Billing page still shows “billing management is coming soon”. In that state there is no in-product way to cancel, and the right to cancel does not depend on our having shipped the button: [support@…] reaches us, and we will action it and refund anything billed after your request.
- Fees already paid are not refunded except where the law requires it, or where [REFUND POLICY] provides otherwise.
Deleting your account does not cancel your subscription. Account deletion does not tell Stripe anything, so an active subscription keeps billing your payment method — and because deletion removes your account, it also removes the in-product route to Stripe’s billing portal, which is the only cancellation control the product itself offers.
Cancel your subscription first, and confirm it is cancelled, before deleting your account. If you have already deleted an account with an active subscription, contact [support@…] and we will cancel it and refund any amount billed after the deletion. We are stating this as a warning rather than as a promise that closure ends billing, because today it does not.
Non-payment
If a charge fails we may downgrade or suspend paid features. Free-plan limits then apply, which may cause agent requests exceeding those limits to be refused.
9. Closing your account
You may close your account at any time. What closure does — and, just as importantly, what it does not do — is set out in §10 of the Privacy Policy. In summary:
- Closure deletes your cards’ records, logins, addresses, agent cards, pending prompts, webhook logs, and push subscriptions, and revokes every API key so no agent can resolve another real value.
- Closure is not an emergency stop. It does not tear down a proxy session that is already running. Revoking the keys stops that session obtaining any further real value — a card, a code, a password, an identity field, or an address — from the moment it lands. But the browser it already has stays up until the session ends by itself or hits its one-hour ceiling, and in that window it can still navigate, click, and submit whatever was already typed into the page. So a purchase already in flight may still complete. A security-code or challenge prompt already open when you close the accountis cancelled: closure deletes those requests, so the link stops working even if it is already in your inbox — but only one that is still pending. A challenge handoff whose viewer has already attached keeps running: deletion removes the request record, which stops any new attach or reconnect, while the viewer already connected goes on driving that browser through the live session until it ends. What closure does not undo is a prompt you already completed — a code you supplied a moment earlier is with the merchant, not with us, and the proxy also keeps it in that session’s memory until the session ends so it can redact it from screenshots and error text (§5, §6, issue #212). If you need an agent stopped, stop the agent first; closure locks it out of anything new, but it is not a way to halt something already under way.
- Closure retains transaction history, agent session records with their events and their receipt screenshots (until the 30-day session purge reaches them), notification history, revoked API key records, and your registry contributions — a submitted recipe is a contribution to a shared registry, so closing your account does not withdraw it.
Closure does not currently remove your card number from the vault. The instruction to destroy the vaulted card needs a delete-only vault key that is not set on any deployment, so it is skipped every time. We delete our reference; the card remains stored at Basis Theory until removed by hand. Email [privacy@…] to have it destroyed.
Closure does not cancel a paid subscription. See §8.
There is no button for account closure or data export in the dashboard, and no support tooling behind them either — both are self-service functions that authenticate as you, so fulfilling an emailed request means an operator doing it by hand. Email [privacy@…] and we will honour it within 30 days; see §11 of the Privacy Policy for what that covers.
10. Third-party sites and services
The service directs a browser to sites we do not control. Your relationship with any merchant or site is between you and them, governed by their terms and their privacy policy. We are not a party to it, we do not endorse them, and we are not responsible for their goods, services, pricing, availability, or conduct.
That includes the merchant’s payment processor. Many checkouts embed card fields hosted by a provider such as Stripe or Adyen, and your card number, expiry and security code go to that provider rather than to the merchant’s own servers. The merchant chooses them, not us, and their handling of your card is governed by their terms — see §4 of the Privacy Policy.
You are responsible for complying with the terms of every site your agent touches. Many sites restrict automated access, account sharing, or credential sharing. If a site prohibits what you are asking your agent to do, do not ask it. Your account there may be suspended or closed as a result, and that is between you and them.
We rely on the sub-processors listed in §8 of the Privacy Policy. Their availability affects ours; an outage at any of them may make part or all of the service unavailable.
11. Intellectual property and feedback
We and our licensors own the service, its software, and its branding, except for the components published under open-source licences, which are governed by those licences. You get a limited, non-exclusive, non-transferable, revocable right to use the service under these terms. Nothing here transfers ownership.
Your data stays yours. You grant us only the licence needed to operate the service for you: to store your data, and to transmit your stored values into the forms your agent is authorised to fill. We do not use your vault data to train models and do not sell it.
If you send us feedback or suggestions, we may use them without restriction or obligation to you.
12. Disclaimers
The service is provided “as is” and “as available”, without warranty of any kind. To the fullest extent permitted by law we disclaim all warranties, express or implied, including merchantability, fitness for a particular purpose, title, and non-infringement.
We specifically do not warrant that:
- the service will be uninterrupted, timely, secure, or error-free;
- an agent will act correctly, buy the right thing, respect your intent, or resist manipulation by content on a page it visits;
- a checkout or sign-in will succeed on any given site, or continue to work as that site changes;
- spending limits, allowlists, or approvals will catch every unwanted action;
- stored data will be free from loss, or that our security measures cannot be defeated.
Nothing in these terms excludes liability that cannot lawfully be excluded, including for death or personal injury caused by negligence, or for fraud. Some jurisdictions do not allow the exclusion of implied warranties, so parts of this section may not apply to you.
13. Limitation of liability
To the fullest extent permitted by law, and except for liability that cannot lawfully be limited:
- We are not liable for indirect, incidental, special, consequential, exemplary, or punitive damages, or for lost profits, lost revenue, lost data, or loss of goodwill, however caused.
- We are not liable for purchases made by your agent, for goods or services obtained through the service, or for the acts or omissions of any merchant, site, or sub-processor.
- Our total aggregate liability arising out of or relating to the service is limited to the greater of (a) the fees you paid us in the [LIABILITY CAP PERIOD, e.g. 12 months] before the event giving rise to the claim, and (b) [MINIMUM CAP AMOUNT].
These limits apply even if a remedy fails of its essential purpose, and they reflect an agreed allocation of risk for a preview service offered at these prices.
14. Indemnity
You will indemnify and hold us harmless against claims, damages, losses, and reasonable costs arising from your use of the service, from anything your agent does with your keys, from your breach of these terms or of any third-party site’s terms, or from your infringement of anyone’s rights. We will notify you of any such claim and you may control its defence, provided any settlement releases us fully and imposes no obligation on us.
15. Suspension and termination
You may stop using the service and close your account at any time (§9). We may suspend or terminate your access, revoke API keys, or remove content if you breach these terms, if we reasonably suspect fraud or unlawful use, if required by law or by a provider, or if we discontinue the service.
Where the circumstances allow, we will give notice and an opportunity to fix the problem first. On termination your right to use the service ends; sections that by their nature should survive — §5, §11, §12, §13, §14, §17 — do survive.
16. Changes
We may change these terms as the service changes. For material changes we will update the effective date at the top and notify account holders by email or in the dashboard before they take effect. Continuing to use the service after that means you accept the new terms; if you do not, stop using the service and close your account.
This document is a draft pending legal review and is not yet in force.
17. Governing law and disputes
These terms are governed by the laws of [GOVERNING LAW], without regard to its conflict-of-laws rules. The courts of [COURTS / VENUE] have exclusive jurisdiction over any dispute, and both parties submit to that jurisdiction.
Any mandatory arbitration, class-action waiver, or informal dispute-resolution step: [DISPUTE RESOLUTION TERMS].
If you are a consumer, nothing here deprives you of the protection of mandatory provisions of the law of the country where you live, or of your right to bring proceedings there.
If a provision of these terms is held unenforceable, the rest remains in force. Our failure to enforce a provision is not a waiver of it. You may not assign this agreement without our consent; we may assign it in connection with a merger, acquisition, or sale of assets. These terms, with the Privacy Policy, are the entire agreement between us about the service.
18. Contact
General and billing support: [support@…]
Privacy and data protection: [privacy@…]
Postal: [LEGAL ENTITY NAME], [REGISTERED ADDRESS]