Legal document
Pipefork Terms of Service
1. Agreement
These Terms of Service ("Terms") govern access to and use of Pipefork, including the website, dashboard, API builder, API runtime, API key management, request logs, documentation, support channels, and related services (the "Service").
By creating an account, accessing the Service, or using any Pipefork API runtime, you agree to these Terms. If you use the Service on behalf of a company, customer, employer, or other organization, you represent that you have authority to bind that organization to these Terms.
If you do not agree to these Terms, you must not use the Service.
2. Intended Use
Pipefork is intended for professional, development, integration, business, and commercial use. The Service is not intended for consumer, household, medical, emergency, life-critical, safety-critical, financial trading, nuclear, aviation, or other high-risk use cases.
You may use the Service only for professional, business, development, or commercial purposes. You must not use the Service primarily for personal, household, or consumer purposes.
You must not use Pipefork where failure, delay, incorrect output, downtime, or data loss could reasonably lead to death, personal injury, severe financial loss, critical infrastructure disruption, or material legal harm.
3. Service Description
Pipefork allows users to build, compose, transform, secure, deploy, and operate API facades from the browser. The Service may include API projects, endpoint definitions, upstream HTTP requests, response mapping, API keys, environments, deployment metadata, request logs, usage counters, generated API documentation, and runtime execution.
Pipefork may call third-party or customer-configured upstream APIs based on your configuration. You are responsible for ensuring that you have the right to access, process, transmit, transform, and expose any data or systems connected to Pipefork.
4. Account and Workspace Responsibility
You are responsible for:
- maintaining the confidentiality of your login credentials;
- managing users invited to your workspace;
- protecting API keys, secrets, credentials, and tokens;
- all activity occurring under your account, workspace, API keys, or published APIs;
- ensuring that your API definitions, upstream connections, and published APIs comply with applicable law and third-party terms.
You must notify Pipefork promptly if you suspect unauthorized access or credential compromise.
5. Customer Content
"Customer Content" means API definitions, endpoint paths, mapping rules, upstream configuration, test data, request and response payloads, logs, secrets metadata, generated documentation, and other content you submit to or process through the Service.
You retain ownership of Customer Content. You grant Pipefork a limited, non-exclusive right to host, process, transmit, store, display, secure, back up, and otherwise use Customer Content only as necessary to provide, maintain, protect, troubleshoot, and improve the Service.
You are solely responsible for Customer Content and for the APIs you build, expose, test, publish, or operate through Pipefork.
6. Secrets, Credentials, and API Keys
Pipefork may allow you to store or reference external API credentials, tokens, headers, API keys, and other secrets.
You must not intentionally expose secrets in endpoint responses, generated documentation, public URLs, browser-visible data, logs, client-side code, or other locations where unauthorized parties may access them.
Pipefork will use reasonable technical measures to protect secrets. You remain responsible for rotating credentials, limiting upstream permissions, revoking compromised keys, and validating that your API configuration does not disclose confidential information.
7. Acceptable Use
You must not use the Service to:
- violate applicable law or third-party rights;
- access systems, APIs, data, or networks without authorization;
- transmit malware, phishing content, spam, abusive traffic, or deceptive content;
- overload, disrupt, scan, attack, bypass, reverse engineer, or interfere with the Service;
- publish APIs that facilitate unlawful surveillance, fraud, credential theft, data scraping, or unauthorized data extraction;
- bypass usage limits, security controls, rate limits, plan limits, or billing controls;
- upload or process special categories of personal data, criminal offence data, health data, payment card data, national identification numbers, children's data, or other highly sensitive data unless Pipefork has expressly approved that use in writing and you have a lawful basis and appropriate safeguards;
- use Pipefork as a general-purpose proxy for unlawful, abusive, or deceptive activity.
Pipefork may suspend or restrict accounts, workspaces, API keys, endpoints, runtime traffic, or access to features if Pipefork reasonably believes that use violates these Terms, creates security risk, creates legal risk, or may harm Pipefork, users, upstream providers, or third parties.
8. External APIs and Third-Party Services
Pipefork is not responsible for third-party APIs, upstream systems, external services, data sources, authentication providers, cloud providers, payment processors, networks, or other third-party infrastructure.
You are responsible for complying with the terms, rate limits, privacy requirements, licensing restrictions, and security requirements of any third-party API or service you connect to Pipefork.
Pipefork does not guarantee availability, correctness, legality, compatibility, performance, or continued operation of third-party APIs.
9. Beta Services, Free Plans, and Experimental Features
These Terms and the Privacy Policy apply to private beta, public beta, free, preview, experimental, evaluation, trial, early access, and generally available use of the Service. Pipefork does not use separate Terms or a separate Privacy Policy solely because access is provided during a beta stage.
Private beta access may be invitation-only, limited to selected accounts or workspaces, subject to a cohort cap, and granted or withdrawn at Pipefork's discretion. Access invitations may be limited to named recipients or workspaces and may not be transferred or shared outside the permitted workspace. An invitation does not create a right to continued access, future features, a paid plan, or general availability.
The purpose of beta access is to evaluate the Service, identify defects and operational limits, and collect voluntary feedback. Beta participants should test their own configurations carefully and report material defects through the published support or feedback channel. Feedback is handled as described in Section 14.
Free, beta, preview, experimental, evaluation, trial, and early access functionality may be incomplete, contain defects, produce incorrect results, experience downtime, or cause data loss. Pipefork may add, change, limit, suspend, reset, or discontinue such functionality or access at any time, including to control security, abuse, support load, infrastructure cost, or operational risk.
Unless Pipefork expressly agrees otherwise in writing, beta and free services have no uptime commitment, support response commitment, performance commitment, service credit, or obligation to preserve a feature or configuration unchanged. There is no minimum service-data preservation or backup commitment beyond applicable law and the published Privacy Policy or Data Processing Addendum. Usage, workspace, API, deployment, runtime, AI, log-retention, and other limits may be lower or changed more frequently than for generally available paid services.
You must not use beta, free, evaluation, trial, or experimental services for production-critical, safety-critical, or other workloads where interruption, incorrect output, or data loss could cause material harm. You remain responsible for maintaining copies of your own configurations and data where appropriate and for having a safe fallback for systems that depend on the Service.
Participation in a beta does not obligate either party to enter into a paid relationship or require Pipefork to release any feature, roadmap item, integration, or commercial plan.
10. Paid Plans and Billing
Paid plans, usage limits, request quotas, log retention, billing periods, renewal rules, cancellation terms, and prices will be described at checkout or in the applicable plan documentation.
Payments may be processed by a third-party payment provider such as Stripe. You authorize Pipefork and its payment provider to charge applicable fees, taxes, and usage-based amounts.
Prices are exclusive of taxes unless stated otherwise at checkout. You are responsible for applicable taxes, duties, levies, and similar governmental charges, except for taxes based on Pipefork's income.
Paid subscriptions renew until canceled, unless checkout or plan documentation states otherwise. Cancellations, downgrades, and plan changes take effect according to the checkout flow, customer portal, or applicable plan documentation.
Request packs, credits, add-ons, and usage-based purchases are non-transferable and non-refundable unless required by law or expressly stated otherwise.
Unless required by law or expressly stated otherwise, fees are non-refundable.
Pipefork may suspend paid features if payment fails or if usage exceeds plan limits.
11. Availability, Changes, and Support
Pipefork aims to provide a useful and reliable Service, but does not guarantee uninterrupted, error-free, secure, or always-available operation.
Pipefork may modify, update, suspend, or discontinue parts of the Service. Pipefork will try to provide reasonable notice for material changes when practical.
Support availability depends on the plan and documentation then in effect.
12. Data Protection
For personal data that Pipefork processes as a controller, the Privacy Policy applies.
For personal data contained in Customer Content, API payloads, request logs, endpoint configurations, or upstream responses processed on your behalf, you are generally the controller and Pipefork acts as processor, unless otherwise agreed.
You instruct Pipefork to process such data only to provide, secure, maintain, troubleshoot, and improve the Service, and as otherwise required by law.
Pipefork may use subprocessors such as hosting providers, database providers, logging providers, email providers, analytics providers, payment processors, and infrastructure providers. Pipefork maintains a subprocessor registry and remains responsible for its subprocessors as required by applicable data protection law.
The Pipefork Data Processing Addendum applies where Pipefork processes Customer Content as a processor on behalf of Customer, unless the parties agree otherwise in writing.
13. Security
Pipefork will use reasonable technical and organizational measures designed to protect the Service and Customer Content.
However, no system is perfectly secure. You are responsible for configuring your APIs securely, limiting access, validating upstream data, protecting credentials, and avoiding unnecessary personal or sensitive data in logs and payloads.
14. Intellectual Property
Pipefork and its software, design, documentation, trademarks, logos, and technology are owned by Pipefork or its licensors.
These Terms do not transfer ownership of Pipefork technology to you. You receive only a limited, revocable, non-exclusive, non-transferable right to use the Service according to these Terms.
Feedback, suggestions, or ideas you provide may be used by Pipefork without restriction or obligation to compensate you.
15. Confidentiality
Non-public information disclosed through the Service, including security information, product roadmap details, private beta features, credentials, and workspace data, must be treated as confidential unless it is already public or independently known.
16. Termination, Deletion, and Retention
You may stop using the Service at any time. You may request account deletion according to the Privacy Policy and applicable law.
Pipefork may suspend or terminate access if you breach these Terms, create risk, fail to pay fees, violate law, or misuse the Service.
After termination, your access may stop immediately. Pipefork may delete Customer Content after a reasonable retention period unless legally required to retain it.
Data deletion and retention are handled as described in the Privacy Policy, Data Processing Addendum, and applicable plan documentation. Backups, logs, billing records, audit records, and security records may be retained for a limited period where necessary for security, legal, billing, abuse prevention, dispute handling, or operational reasons.
17. Disclaimers
To the maximum extent permitted by law, the Service is provided "as is" and "as available".
Pipefork disclaims all warranties, whether express, implied, statutory, or otherwise, including warranties of merchantability, fitness for a particular purpose, non-infringement, availability, accuracy, security, and error-free operation.
Pipefork does not warrant that APIs created with the Service will be correct, secure, lawful, compliant, available, performant, or suitable for your intended use.
18. Limitation of Liability
To the maximum extent permitted by law, Pipefork and its owners, directors, employees, contractors, and affiliates will not be liable for:
- indirect, incidental, special, consequential, exemplary, or punitive damages;
- lost profits, lost revenue, lost business, lost savings, or loss of goodwill;
- loss, corruption, exposure, or unavailability of data;
- downtime, latency, failed API calls, incorrect API responses, or upstream API failures;
- unauthorized access caused by your configuration, credentials, API keys, or third-party services;
- claims arising from Customer Content, your APIs, your users, or your third-party integrations.
For business, professional, development, and commercial users, and to the maximum extent permitted by law, Pipefork's total aggregate liability for all claims relating to the Service will not exceed the amounts paid by you to Pipefork for the Service during the 12 months before the event giving rise to the claim.
If you use only a free, beta, preview, evaluation, or trial plan and have not paid Pipefork any fees during that period, Pipefork will have no monetary liability to you for that free use of the Service, except to the extent liability cannot be excluded or limited under applicable law.
Nothing in these Terms excludes or limits liability where such exclusion or limitation is not permitted by applicable law, including mandatory consumer rights, intentional misconduct, gross negligence, or mandatory data protection liability.
19. Indemnity
If you use the Service on behalf of a business, organization, employer, customer, client, or for professional, development, integration, business, or commercial purposes, you agree to defend, indemnify, and hold harmless Pipefork and its owners, directors, employees, contractors, and affiliates from claims, damages, losses, liabilities, costs, and expenses arising from:
- your Customer Content;
- APIs you create, publish, or operate;
- your use of upstream APIs or third-party services;
- your violation of law or third-party rights;
- your breach of these Terms;
- your users' use of APIs created through Pipefork.
This Section applies only to the extent permitted by applicable law and does not limit mandatory consumer, data protection, or other non-excludable rights.
20. Changes to These Terms
Pipefork may update these Terms from time to time for valid reasons, including legal, security, billing, operational, technical, product, provider, or abuse-prevention reasons.
If changes are material, Pipefork will take reasonable steps to notify you, such as by email, dashboard notice, or requiring acceptance at next login. If a material change negatively affects your rights or use of the Service, Pipefork will provide reasonable notice where practical.
If required by applicable law, or if your paid plan documentation gives you that right, you may stop using the Service or cancel your paid plan before a material change takes effect.
Continued use of the Service after updated Terms become effective means you accept the updated Terms.
21. Governing Law and Disputes
These Terms are governed by the laws of Finland, excluding conflict of law rules.
Unless mandatory law provides otherwise, disputes will be resolved in the competent courts of Finland.
22. Contact
Questions about these Terms may be sent to:
support@pipefork.com