Terms of Service
Last Updated: August 6, 2026 · Effective Date: August 6, 2026
These Terms of Service (the “Terms”) are a binding agreement between Alter Labs, Inc., a Delaware corporation with its principal place of business at 169 Madison Ave, STE 15836, New York, NY 10016 (“Alter,” “we,” “us,” or “our”), and the individual or entity that creates a Customer account or accepts an Order (“Customer,” “you,” or “your”).
You accept these Terms when an account holder, or an Authorized User whose contracting authority has been confirmed, creates the Customer account, accepts an Order, or clicks “I agree” on the Customer’s behalf. That individual represents that they have authority to bind the Customer. An Authorized User who lacks contracting authority does not bind the Customer merely by installing an SDK or CLI or by using the Service operationally; once the Customer has validly accepted the Agreement, however, every Authorized User’s use on the Customer’s behalf remains subject to the Agreement. If the Customer has not validly accepted these Terms, do not create or administer its account or use the Service on its behalf.
These Terms incorporate by reference our Privacy Policy, our Cookie Notice, our Acceptable Use Policy (attached as Schedule A), and, where applicable, our Data Processing Agreement (collectively, the “Agreement”). An order form, online checkout, statement of work, or other ordering document that references these Terms (an “Order”) also forms part of the Agreement. Detailed data-processing terms — including sub-processor lists, international-transfer mechanisms, and audit rights — are addressed exclusively in the Data Processing Agreement and the Privacy Policy, not in these Terms.
1. Definitions
1.1 “Service” means Alter’s hosted credential-authorization platform for AI agents, including the OAuth credential vault, managed-secret storage, credential-brokering and token-refresh APIs, the developer portal, the Alter Wallet, the embeddable Alter Connect widget, the Alter SDKs and CLI, and related documentation and websites.
1.2 “Documentation” means the usage guides and technical materials Alter makes available for the Service.
1.3 “Customer Application” means the application, agent, or service that you build and that integrates with the Service.
1.4 “End User” means an individual or entity that interacts with a Customer Application and, through it, authorizes a Connected Account or whose data is processed via the Service.
1.5 “Connected Account” means a third-party account (e.g., a Google, Slack, GitHub, or other provider account) that an End User or you authorize the Customer Application to access through the Service.
1.6 “Credentials” means OAuth access and refresh tokens, API keys, managed secrets, and other authentication material stored or brokered through the Service. OAuth application client credentials used to configure a Provider integration are “Provider Configuration,” not Credentials under this definition.
1.7 “Grant” means an authorization record linking a principal (an End User, agent, or system identity) to a Connected Account and a defined set of permissions or scopes.
1.8 “Agent” means an automated or AI-driven process that acts through the Customer Application and, subject to a Grant, on a Connected Account via the Service.
1.9 “Customer Data” means data you or your End Users submit to or process through the Service, including Credentials, Grants, configuration, and End User identifiers. As between the parties, Customer Data is yours.
1.10 “Provider” means a third-party platform that issues Credentials or exposes APIs accessed through the Service (e.g., an OAuth or API provider).
1.11 “Authorized User” means your employee, contractor, service provider, or other individual whom you authorize to administer or use the Service on your behalf. An End User is not an Authorized User solely because the End User authorizes a Connected Account.
1.12 “Usage Data” means technical, operational, and statistical data about the configuration, performance, security, and use of the Service, excluding Customer Data.
2. The Service
2.1 License. Subject to the Agreement and payment of applicable fees, Alter grants you a non-exclusive, non-transferable, non-sublicensable right to access and use the Service during the Term for your internal business purposes and to operate your Customer Application.
2.2 What the Service does, and does not do. The Service is a technical intermediary that stores Credentials securely, refreshes tokens, enforces Grants and policies, brokers authorized calls to Providers, and records audit logs. Alter does not establish your relationship with any Provider or End User, does not own the underlying Provider accounts, and does not control the data a Provider returns. You retain ownership of and responsibility for your own OAuth applications and Provider relationships, except where a development integration expressly identifies an Alter-managed shared OAuth application. Shared applications remain subject to Section 7.3.
2.3 SDKs and CLI. Alter’s SDKs and CLI are part of the Service and provided under the license in Section 2.1 (or under any open-source license accompanying a specific package, which controls for that package). You must keep them reasonably up to date.
2.4 Changes to the Service. The Service is under active development. We may add, change, or discontinue features. We will not make a material reduction to the core functionality of a paid tier during a paid term without notice. Beta, preview, and early-access features are provided “as is,” may change or be withdrawn, and are excluded from any service commitments.
2.5 Service levels, availability, and support. Alter will use commercially reasonable efforts, consistent with its general business practices, to make the Service available and to perform maintenance in a manner that minimizes disruption. Alter will use commercially reasonable efforts to perform scheduled maintenance during off-peak hours and to provide advance notice of maintenance it reasonably expects to materially affect availability, and to respond to and resolve support requests in a timely manner consistent with the severity of the issue, through its designated support channel during standard business hours. The parties may agree in an Order to specific service levels, including a target availability percentage, service credits, and response or resolution times; where service credits are agreed, those credits are your sole and exclusive remedy for the corresponding failure. Except as expressly set forth in an Order, Alter does not commit to any specific availability percentage, service credit, or response or resolution time.
2.6 Free plans, trials, and previews. Free, evaluation, trial, beta, preview, experimental, and early-access offerings may be suspended or discontinued at any time and may contain errors or incomplete features. Unless an Order expressly says otherwise, they are provided without support, service levels, warranties, or indemnification to the maximum extent permitted by law.
2.7 End Users. An End User does not become a Customer or accept these Terms merely by using Wallet or Connect to review, grant, manage, or revoke authorization for a Customer Application. Your terms govern the End User’s relationship with the Customer Application. Alter’s Privacy Policy explains Alter’s processing, and the Acceptable Use Policy applies to conduct on Alter-operated surfaces.
3. Accounts and registration
3.1 Registration. Alter provides first-party email-and-password authentication and may also permit sign-in through supported third-party identity providers, as described in the Privacy Policy. Alter Wallet uses an identity provider selected by the applicable Customer. You must provide accurate information and keep it current.
3.2 Account security. You are responsible for safeguarding your account credentials, Personal Access Tokens, API keys, and HMAC signing material, and for all activity under your account. Notify us promptly at security@alterauth.com of any unauthorized use.
3.3 Eligibility. You must be at least 18 years old and capable of forming a binding contract. The Service is for business use and is not directed to children.
3.4 Authorized Users. You are responsible for selecting and administering your Authorized Users, assigning least-privilege access, promptly removing access that is no longer needed, and ensuring their compliance with the Agreement. An Authorized User’s act or omission in connection with your account is treated as your act or omission.
4. Customer obligations regarding Connected Accounts, End Users, and Providers
This Section is central to the Service and your use of it.
4.1 End User authorization and notice. You are solely responsible for your relationship with your End Users. Before an End User authorizes a Connected Account through the Service, you must (a) provide your own legally adequate privacy notice and terms to that End User, (b) obtain all consents required for your Customer Application and its Agents to access, store, and act on the Connected Account and its data, and (c) accurately describe to the End User what your Customer Application and Agents will do.
4.2 Provider terms. You must comply with the terms, policies, and developer agreements of every Provider you connect (for example, the Google API Services User Data Policy and equivalent provider requirements), including any limits on scopes, data use, retention, and re-sharing. You are responsible for maintaining your own Provider/OAuth application registrations and credentials, except for an expressly identified Alter-managed shared OAuth application.
4.3 Lawful basis and scope. You will request only the scopes and data your Customer Application genuinely needs, and use Credentials, Grants, and Connected-Account data only for the purposes the End User authorized and only as permitted by the relevant Provider.
4.4 Your Agents and delegated authority. You are responsible for the actions your Customer Application and its Agents take through the Service, including actions taken on a Connected Account under a Grant and actions delegated from one Agent to another. You must configure Grants, scopes, expiry, policies, approval requirements, and revocation controls appropriate for the risk of the action. You must not allow one principal to use another principal’s authorization or allow an Agent to bypass a required human approval. The Service enforces the authority and policies you configure; it does not independently determine whether the business purpose of each authorized call is appropriate.
4.5 Acceptable use. Your use of the Service must at all times comply with the Acceptable Use Policy attached as Schedule A, which is incorporated into these Terms.
4.6 Compliance with law. You will comply with all laws applicable to your use of the Service and your Customer Data, including data-protection, export-control, and anti-corruption laws.
4.7 Technical restrictions. Except to the extent a restriction is prohibited by law, you must not (a) copy, modify, or create derivative works of the Service; (b) reverse engineer or attempt to discover its non-public source code, algorithms, or security mechanisms; (c) resell, sublicense, or provide the Service as a standalone service bureau; (d) circumvent access, approval, usage, or billing controls; (e) access the Service to build a competing product or conduct competitive benchmarking for publication without our written consent; or (f) remove proprietary notices. This Section does not restrict use of a package under an open-source license that expressly permits the activity.
4.8 Restricted data and regulated workloads. Documented Provider operations may transmit ordinary business, accounting, customer, invoice, and payment records between you and the selected Provider. Unless an executed Order or addendum expressly permits it, however, you must not use Customer-configurable storage, diagnostic payload capture, free-form fields, or support channels to persist protected health information regulated by HIPAA, raw payment-card data subject to PCI DSS, government identification numbers, consumer online-banking usernames or passwords, bank account or routing numbers, or special-category personal data. You must not enable diagnostic payload capture for a workload likely to contain those records unless the Agreement expressly authorizes it. Alter does not act as a HIPAA business associate unless the parties have executed a business associate agreement.
4.9 Review and intervention. You are responsible for determining when an Agent’s action requires human review and for supervising high-impact, destructive, financial, legal, or otherwise consequential actions. You must promptly suspend an Agent, revoke a Grant, or rotate a Credential if you know or reasonably suspect that its authority, instructions, or authentication material has been compromised or is no longer valid.
5. Fees and payment
5.1 Fees. Paid plans, usage allowances, and overage rates are described on our pricing page or in an applicable Order. Billing is processed by our payment processor (Stripe).
5.2 Usage-based charges. A completed Provider request executed through Alter’s proxy counts as one metered API call. Management, grant-list, identity-resolution, and reporting calls do not consume that allowance. Usage measured by the Service is the authoritative record absent manifest error; contact support to dispute an incorrect measurement.
5.3 Payment. Fees are due in advance for the stated period and, unless stated otherwise, are non-refundable except as required by law or expressly provided in the Agreement. You authorize us and our payment processor to charge your payment method for all amounts due.
5.4 Taxes. Fees are exclusive of taxes. You are responsible for all applicable taxes, duties, and similar governmental assessments, other than taxes on Alter’s net income. If Alter is required to collect or remit such taxes, they will be invoiced to you unless you provide a valid exemption certificate.
5.5 Auto-renewal. Paid subscriptions renew automatically for successive periods at the then-current rate unless cancelled before the renewal date, as described at sign-up or on the pricing page. You may cancel renewal at any time through the developer portal. Where an automatic-renewal, continuous-service, or similar law applies, Alter will provide the pre-purchase disclosures, obtain the consent, and send the renewal and cancellation reminders that the applicable law requires.
5.6 Late or failed payment. We may suspend the Service for non-payment after reasonable notice.
5.7 Orders and purchase orders. An Order may contain additional commercial terms. A purchase order or similar customer form is for administrative convenience only and does not add to or modify the Agreement unless Alter expressly agrees in writing.
5.8 Price changes. Fees are fixed during the then-current paid term. Alter may set the fees for any renewal term by prior notice, using commercially reasonable efforts to provide that notice before the renewal date; your sole remedy for a renewal-term price you do not accept is to decline to renew. This Section does not apply to usage above an agreed allowance or to a change you request.
6. Intellectual property
6.1 Alter IP. Alter and its licensors own all right, title, and interest in the Service, including all software, APIs, and Documentation, and all related intellectual property rights. Except for the rights expressly granted, no rights are granted to you.
6.2 Customer Data. As between the parties, you own Customer Data. You grant Alter a worldwide, non-exclusive, non-sublicensable (except to sub-processors engaged under the DPA) license to host, process, transmit, and display Customer Data, and to access and use Credentials and Grants, solely to provide, secure, and support the Service and as otherwise permitted by the Agreement (including the DPA) or required by law.
6.3 Feedback. If you voluntarily give us suggestions or feedback that do not contain Customer Data or Confidential Information, you grant Alter a perpetual, irrevocable, royalty-free license to use that feedback without restriction. This license does not transfer ownership of Customer Data, Credentials, source code, or Confidential Information.
6.4 Aggregated/de-identified data. Alter may generate and use aggregated or de-identified data that does not identify you, any End User, or any individual to operate, analyze, and improve the Service. Alter will not disclose Customer Data, Credentials, or the contents of Connected Accounts as part of this, and will maintain de-identified data in de-identified form and not attempt to re-identify it except to test whether its de-identification controls are effective or as otherwise permitted by law.
6.5 No model training on your data. Alter will not use Customer Data, Credentials, the contents of Connected Accounts, or the inputs or outputs of your Customer Application or Agents to train, fine-tune, or otherwise develop any machine-learning or artificial-intelligence model. Information that Alter has irreversibly de-identified so that it no longer relates to any identifiable individual or to Customer, and operational telemetry that does not contain Customer Data, are not Customer Data and are outside this commitment; Alter may use such information to provide, secure, and improve the Service.
7. Third-party Providers and services
7.1 The Service interoperates with Providers and other third-party services that you choose to connect. Those are governed by their own terms and privacy policies. Alter is not responsible for, and does not warrant, any Provider or third-party service, including changes to or discontinuation of their APIs, scopes, or availability, which may affect the Service.
7.2 If you enable a Provider, customer-selected identity provider, third-party application, or other integration, you direct Alter to exchange the information necessary to operate that integration. You are responsible for its configuration and for any separate agreement with that third party. Alter may suspend an integration if necessary to protect the Service or comply with the third party’s requirements.
7.3 Alter-managed shared OAuth applications. Where a Provider integration is expressly identified as managed by Alter, Alter maintains that OAuth application and its Provider registration. Shared applications are intended only for the documented plans and workloads, remain subject to Provider quotas and policies, and may be suspended if the Provider requires it or the shared application threatens other customers. Alter may require migration to Customer-managed Provider credentials for production scale, policy compliance, or continuity. You remain responsible for your application, End User notices, requested scopes, and use of Provider data.
8. Confidentiality
8.1 Confidential Information means non-public information disclosed by a party that is designated confidential or that reasonably should be understood to be confidential, including the Service’s non-public features, security architecture, and pricing. The receiving party will use Confidential Information only to perform under the Agreement, protect it with reasonable care, and not disclose it except to representatives bound by confidentiality obligations. These obligations do not apply to information that is public through no fault of the receiving party, independently developed, or rightfully received from a third party, and do not prevent disclosures required by law (with notice where permitted). Before a legally compelled disclosure, the receiving party will, where permitted, give prompt notice and reasonable cooperation so the disclosing party may seek protection, and will disclose only the required portion. On request or termination, the receiving party will return or destroy Confidential Information except for protected backup copies and information it must retain by law. Confidentiality obligations survive for five years after disclosure or termination, whichever is later; trade-secret duties survive while the information remains a trade secret.
9. Data protection and security
9.1 Privacy. Alter’s handling of personal data is described in the Privacy Policy, and its use of browser storage and similar technologies is described in the Cookie Notice. The Privacy Policy controls over these Terms for Alter’s processing of personal information.
9.2 Processor terms. To the extent Alter processes personal data on your behalf as a processor (for example, End User identifiers and Connected-Account data), that processing is governed by the Data Processing Agreement, which is incorporated into the Agreement where applicable and controls over these Terms for the processing of Customer Personal Data.
9.3 Security. Alter implements technical and organizational measures designed to protect Credentials and Customer Data, including encryption of Credentials at rest in a dedicated secrets vault (the application database stores opaque vault references and non-secret metadata), encryption of Provider Configuration client secrets under keys held outside the database, a zero-trust authorization model, and audit logging. No method of transmission or storage is perfectly secure, and you are responsible for securing your own systems, account, and End User relationships. On your written request and subject to confidentiality, Alter will make available its then-current information-security overview, any available independent third-party audit reports (such as a SOC 2 report, once issued), and a completed security questionnaire.
9.4 Security incidents. Whether or not the DPA applies, Alter will notify an affected Customer without undue delay after becoming aware of unauthorized access to, acquisition of, or material loss, alteration, disclosure, or destruction of its Customer Data. Alter will provide reasonably available information about the incident and reasonable cooperation with the Customer’s investigation and legally required notifications. The DPA controls if it requires earlier notice, additional information, or additional assistance. You must promptly provide information and cooperation reasonably needed to investigate a suspected compromise arising from your account, Customer Application, Authorized Users, or Agents.
10. Warranties and disclaimer
10.1 Mutual. Each party warrants that it has the authority to enter into the Agreement.
10.2 Service warranty. Alter warrants that, during a paid subscription term, the Service will perform materially in accordance with the Documentation. Alter will use commercially reasonable efforts to correct a reported non-conformity at no additional charge, and if Alter does not do so within a reasonable time after written notice describing the non-conformity, you may terminate the affected subscription and receive a pro-rata refund of prepaid, unused fees for the remainder of the terminated period. To the maximum extent permitted by law, this is your exclusive remedy and Alter’s entire liability for breach of this warranty, unless the non-conformity also constitutes a material breach that you terminate under Section 13.3. This warranty does not apply to free plans, trials, previews, or beta features (Section 2.6), or to non-conformities caused by use of the Service not in accordance with the Agreement or the Documentation.
10.3 Disclaimer. EXCEPT AS EXPRESSLY STATED IN THE AGREEMENT, THE SERVICE AND ALL RELATED MATERIALS ARE PROVIDED “AS IS” AND “AS AVAILABLE,” AND ALTER DISCLAIMS ALL WARRANTIES, EXPRESS OR IMPLIED, INCLUDING MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, AND NON-INFRINGEMENT. ALTER DOES NOT WARRANT THAT THE SERVICE WILL BE UNINTERRUPTED, TIMELY, ERROR-FREE, OR SECURE, OR THAT IT WILL PRESERVE ACCESS TO ANY PROVIDER OR CONNECTED ACCOUNT.
11. Limitation of liability
11.1 Exclusion of indirect damages. TO THE MAXIMUM EXTENT PERMITTED BY LAW, NEITHER PARTY WILL BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR EXEMPLARY DAMAGES, OR FOR LOST PROFITS, REVENUE, GOODWILL, OR DATA, ARISING OUT OF OR RELATING TO THE AGREEMENT, EVEN IF ADVISED OF THE POSSIBILITY.
11.2 General cap. TO THE MAXIMUM EXTENT PERMITTED BY LAW, EXCEPT AS PROVIDED IN SECTION 11.3, EACH PARTY’S TOTAL AGGREGATE LIABILITY ARISING OUT OF OR RELATING TO THE AGREEMENT WILL NOT EXCEED THE GREATER OF (A) THE AMOUNTS YOU PAID TO ALTER FOR THE SERVICE IN THE TWELVE (12) MONTHS BEFORE THE EVENT GIVING RISE TO THE LIABILITY, OR (B) ONE HUNDRED U.S. DOLLARS ($100).
11.3 Super-cap and exceptions. Each party’s aggregate liability for its indemnification obligations and for breach of its confidentiality obligations will not exceed two (2) times the amount of the general cap in Section 11.2. The limitations in this Section do not apply to (a) your payment obligations or (b) a party’s fraud, willful misconduct, or gross negligence, in each case to the extent these exceptions are enforceable under applicable law. The DPA separately preserves mandatory Data Subject and Standard Contractual Clause liability.
11.4 Basis of the bargain. These limitations are an essential basis of the bargain between the parties.
12. Indemnification
12.1 By you. You will defend, indemnify, and hold harmless Alter and its officers, directors, and employees from and against any third-party claim, and any resulting losses, to the extent caused by (a) Customer Data infringing a third party’s rights, (b) your Customer Application or Agents violating law or the Agreement, (c) your unauthorized use of a Connected Account or Provider, (d) your material breach of Section 4 or the Acceptable Use Policy, or (e) your failure to obtain required End User consents.
12.2 By Alter. Alter will defend you against any third-party claim alleging that the Service, as provided by Alter and used in accordance with the Agreement, infringes that third party’s intellectual property rights, and will pay resulting damages finally awarded or agreed in settlement. Alter has no obligation for claims arising from Customer Data, a Connected Account, a Provider, your modifications, use of the Service not in accordance with the Agreement, the combination or use of the Service with products, data, or services not provided by Alter where the claim would have been avoided but for that combination, or open-source components used in accordance with their own licenses. If such a claim is likely, Alter may obtain the right to continue use, modify or replace the affected Service with a substantially equivalent non-infringing alternative, or terminate the affected Service and refund prepaid fees for the unused period.
12.3 Procedure. The indemnified party will give prompt notice, reasonable cooperation, and control of the defense to the indemnifying party (subject to the indemnified party’s right to participate with its own counsel). A notice delay relieves the indemnifying party only to the extent materially prejudiced. The indemnifying party may not settle a claim in a way that admits fault by, imposes non-monetary obligations on, or fails to unconditionally release the indemnified party without that party’s consent, not to be unreasonably withheld.
13. Term, suspension, and termination
13.1 Term. The Agreement starts when you first accept it and continues until all accounts and subscriptions are terminated.
13.2 Termination for convenience. You may stop using the Service and close your account at any time. Termination does not entitle you to a refund except as stated in the Agreement (including Sections 5, 10.2, 12.2, and 13.3) or required by law.
13.3 Termination for cause. Either party may terminate the Agreement if the other materially breaches and fails to cure within thirty (30) days of notice (or immediately for a breach incapable of cure). If you terminate under this Section for Alter’s uncured material breach, Alter will refund the prepaid fees that cover the remainder of the terminated period after the effective date of termination.
13.4 Suspension. We may suspend your access immediately if we reasonably believe your use (a) poses a security risk, (b) violates the Acceptable Use Policy or law, (c) may harm Alter, other customers, End Users, or Providers, or (d) is overdue on payment. We will use reasonable efforts to give notice where practicable, limit a suspension to the affected account, Agent, Grant, integration, or feature where reasonably possible, and evaluate restoration after the issue is resolved.
13.5 Effect of termination. On termination, your right to use the Service ends. Whether or not the DPA applies, at your choice Alter will return Customer Data made available through the Service’s documented export features or delete the Customer Data and active copies under Alter’s control without undue delay and no later than sixty (60) days after termination, unless applicable law requires continued retention. Data retained by law or under a documented legal hold will remain protected and used only for that purpose. Independently generated, privacy-minimized security evidence may remain under the Privacy Policy for a documented security or legal-claims period after Customer-submitted identity fields are deleted or irreversibly de-identified. Backup and immutable-ledger copies are put beyond ordinary use and deleted when their verified rotation or finite lock expires. The DPA controls if it imposes stronger return, deletion, timing, or backup requirements.
Credentials are deleted from the active vault when the associated resource is deleted by immediately blocking access and requesting permanent deletion from the production secrets service without a recovery window. The provider may require a short asynchronous interval to complete physical deletion, during which the Credentials remain inaccessible and must not be read, refreshed, or used. You are responsible for revoking, exporting, or migrating Grants and Credentials before termination. During the Term, and before termination takes effect, you may export Customer Data made available through the Service’s documented export features. After termination, Alter has no obligation to preserve access except as required by the DPA or an Order.
13.6 Survival. Sections that by their nature should survive (including 1, 6, 8, 10–12, 13.5–13.6, 14, and 15) survive termination.
14. Governing law and dispute resolution
14.1 Governing law. The Agreement is governed by the laws of the State of New York, excluding its conflict-of-laws rules.
14.2 Informal resolution. Before filing a claim, the parties will attempt to resolve the dispute informally by contacting legal@alterauth.com; if unresolved within thirty (30) days, either party may proceed as provided below.
14.3 Exclusive jurisdiction. Subject to Sections 14.2 and 14.5, the parties submit to the exclusive jurisdiction of the state and federal courts located in New York County (Borough of Manhattan), New York, for any dispute arising out of or relating to the Agreement, and each party waives any objection to venue or inconvenient forum in those courts. Nothing in this Section prevents a party from seeking injunctive or other equitable relief in those courts to protect its intellectual property or Confidential Information.
14.4 Jury-trial and class-action waivers. TO THE MAXIMUM EXTENT PERMITTED BY LAW, EACH PARTY WAIVES ANY RIGHT TO A TRIAL BY JURY, AND WAIVES ANY RIGHT TO BRING OR PARTICIPATE IN A CLASS, COLLECTIVE, OR REPRESENTATIVE ACTION, in any dispute arising out of or relating to the Agreement. Claims may be brought only in an individual capacity.
14.5 Arbitration. Except as set out in this Section 14.5, any dispute, claim, or controversy arising out of or relating to the Agreement or the Service that is not resolved under Section 14.2 will be resolved by final and binding arbitration administered by JAMS under its then-current applicable rules, and judgment on the award may be entered in any court of competent jurisdiction. The arbitration will be conducted on an individual basis only; the class, collective, and representative-action waiver in Section 14.4 applies in arbitration, and the arbitrator may not consolidate more than one person’s claims or preside over any class, collective, or representative proceeding. The arbitration will be seated in New York County (Borough of Manhattan), New York, and governed by the law specified in Section 14.1. Each party will bear its own arbitration costs and fees except as the JAMS rules require. This Section 14.5 does not apply to, and either party may bring in the courts identified in Section 14.3, (i) any claim that qualifies for small-claims court and (ii) any action seeking injunctive or other equitable relief to protect intellectual property rights or Confidential Information. Customers on Alter’s free tier, and individuals using the Service other than through a paid subscription, are not required to arbitrate under this Section 14.5 and instead remain subject to Sections 14.3 and 14.4 in the designated courts. You may opt out of this Section 14.5 by sending written notice to legal@alterauth.com within thirty (30) days after first accepting these Terms; opting out will not affect the other provisions of this Section 14.
15. General
15.1 Changes to these Terms. We may update these Terms from time to time. If a change is material, we will provide reasonable notice (e.g., by email or in-product) and require an explicit affirmative acceptance action by the account holder or an Authorized User whose contracting authority has been confirmed. Continued use alone, including continued use by a contracting representative, does not constitute acceptance of a material update. Ordinary operational use by another Authorized User never binds the Customer to an update. An Order may specify when updated Terms apply to a fixed subscription term.
15.2 Assignment. You may not assign the Agreement without Alter’s prior written consent, except to a successor in a merger or sale of substantially all assets that is not a competitor of Alter. Alter may assign the Agreement. Any prohibited assignment is void.
15.3 Force majeure. Neither party is liable for delay or failure due to causes beyond its reasonable control.
15.4 Notices. Legal notices to Alter must be sent to legal@alterauth.com and 169 Madison Ave, STE 15836, New York, NY 10016. We may give notice to you via the email on your account or in-product.
15.5 Independent contractors. The parties are independent contractors; the Agreement creates no partnership, agency, or joint venture.
15.6 Severability; waiver. If any provision is unenforceable, it will be modified to the minimum extent necessary and the rest remains in effect. A failure to enforce a provision is not a waiver.
15.7 Entire agreement; order of precedence. The Agreement is the entire agreement between the parties on its subject and supersedes all prior agreements. If its documents conflict: (a) the DPA, including its incorporated transfer terms, controls for Customer Personal Data; (b) the applicable Order controls for the ordered Service and commercial terms, but does not override the DPA unless it expressly amends the DPA and applicable law permits the amendment; (c) the Cookie Notice controls over these Terms for browser storage and similar technologies; (d) the Privacy Policy controls over these Terms for Alter’s controller processing; (e) these Terms control next; and (f) the Acceptable Use Policy (Schedule A) and Documentation follow. Each document controls only within the subject identified here.
15.8 Export and sanctions. You represent that you are not subject to applicable sanctions and will not use the Service in violation of export-control or sanctions laws.
15.9 No third-party beneficiaries. Except as expressly stated in the Agreement, it does not create rights for any third party.
15.10 Anti-corruption. Each party will comply with applicable anti-bribery and anti-corruption laws in connection with the Agreement.
16. Contact
Alter Labs, Inc. · General/legal: legal@alterauth.com · Security: security@alterauth.com · Support: support@alterauth.com · Address: 169 Madison Ave, STE 15836, New York, NY 10016
Schedule A — Acceptable Use Policy
This Acceptable Use Policy (the “AUP”) is incorporated into and forms part of the Terms of Service. Capitalized terms have the meanings given in the Terms. We may update this AUP from time to time; a material update follows the notice-and-acceptance treatment for a material update to the Terms, unless a fixed-term Order provides otherwise. Because the Service stores and brokers Credentials and lets AI agents act on Connected Accounts, misuse can cause real-world harm, and the rules below are taken seriously. Violating this AUP may result in suspension or termination under the Terms.
A1. Credential and access integrity
You must not: (a) store, broker, or use Credentials for any account you are not authorized to access, or beyond the authorization the account owner actually granted; (b) access, attempt to access, or act on a Connected Account without a valid Grant and the End User’s authorization; (c) use the Service to harvest, phish for, or otherwise obtain credentials, tokens, or authentication material under false pretenses; (d) request OAuth scopes or permissions broader than your Customer Application genuinely needs, or use granted scopes for purposes the End User did not authorize; (e) misrepresent your Customer Application’s identity or purpose to an End User or a Provider; (f) use Credentials or Connected-Account data in violation of the relevant Provider’s terms, developer policies, or data-use and re-sharing restrictions (including the Google API Services User Data Policy and equivalent provider requirements); or (g) retain or use Connected-Account data after a Grant is revoked or expires.
A2. Prohibited conduct
You must not use the Service to: (a) violate any law or regulation, or infringe anyone’s intellectual property, privacy, or other rights; (b) send spam or unsolicited messages, or engage in fraud, deceptive practices, or abusive automated activity through a Connected Account; (c) scrape, harvest, or collect data in violation of a Provider’s terms or applicable law; (d) store or transmit malware, ransomware, or other malicious code; (e) engage in activity that is harassing, defamatory, or that exploits or endangers minors, including child sexual exploitation, grooming, trafficking, or sextortion; (f) facilitate violence, terrorism, weapons development, human trafficking, or unlawful surveillance; (g) make or materially influence employment, housing, credit, insurance, healthcare, legal, benefits, or other consequential decisions without the notices, human review, appeal, testing, and legal authorization required for that use; (h) facilitate an AI practice prohibited by applicable law, impersonate a human in a deceptive manner, or conceal legally required disclosure that an automated agent is acting; or (i) store data you are not permitted to store, including special-category personal data except as expressly permitted by the Agreement and law.
A3. Platform and security integrity
You must not: (a) probe, scan, or test the vulnerability of the Service or breach or circumvent its authentication, authorization, rate-limiting, or security controls, except under an authorized program (see Section A5); (b) attempt to access another customer’s, organization’s, or End User’s data or resources; (c) use the Service to launch attacks against third parties, including denial-of-service or server-side request forgery, or to attempt to reach internal or restricted network resources; (d) interfere with or disrupt the integrity or performance of the Service or its infrastructure; (e) circumvent usage limits, metering, or billing, or share access in a way designed to evade fees; or (f) reverse engineer the Service except to the extent that restriction is prohibited by law.
A4. Fair use and automated access
Use the Service within the rate limits and usage allowances of your plan. Automated and high-volume access must use the official SDKs/CLI or documented APIs and respect published limits. We may throttle or suspend usage that threatens the stability or security of the Service or other customers.
A5. Security research and responsible disclosure
If you discover a vulnerability, report it to security@alterauth.com and give us a reasonable opportunity to remediate before public disclosure. Good-faith research must use only accounts and data the researcher owns or is authorized to test; it must not access, modify, or delete another person’s data, degrade the Service, use social engineering, or perform denial-of-service testing. Written authorization is required before testing anything outside those boundaries.
A6. Enforcement
We may investigate suspected violations and may remove content, disable Grants, throttle, suspend, or terminate access, and cooperate with law enforcement, as appropriate. Where practicable and not legally or operationally restricted, we will give notice. Serious violations, particularly those threatening security, Credentials, End Users, or Providers, may result in immediate suspension without prior notice. To report a violation of this AUP, contact abuse@alterauth.com (security issues: security@alterauth.com).