Terms of Service for brnrd.dev

Version 2026-07-24. These terms are an agreement between you and HugiMuni SAS about the
hosted service at brnrd.dev. They are a draft pending review by French counsel; where a
statement below is a reading rather than a settled position, it says so.

1. What these terms govern — and what they do not

These terms govern brnrd.dev: the website, the account, the dashboard, and the relay
that carries messages between a chat or forge gate and a daemon you run. That is the
whole of what HugiMuni SAS operates and the whole of what you are agreeing to here.

They do not govern the brnrd engine — the program you install and run on your own
machine. That is open-source software licensed to you under its own licence (MIT for the
daemon core, AGPLv3 for the backend and dashboard components), it costs nothing, and it
needs no account here. Your rights to it come from that licence, not from this page, and
nothing on this page adds a condition to it.

An installation that never runs brnrd account connect sends us nothing. If that
describes you, you are not a party to these terms, and you do not need to read further.

2. Who we are

The service is operated by HugiMuni SAS, a société par actions simplifiée incorporated
in France, and its legal successors. Its full company and publication details —
registered office, share capital, SIREN/RCS registration, VAT number, publication
director, and hosting provider — belong in a separate legal notice (mentions légales)
which is not yet published.

3. Your account and eligibility

You sign in with a GitHub account. You are responsible for that account's security and
for anything done through your brnrd.dev session. You must be old enough to enter a
contract where you live, and you must not use the service if we have previously
terminated your access.

If you accept these terms on behalf of a company or other organisation, you confirm you
are authorised to bind it, and "you" in these terms means that organisation.

4. Beta status: the service may change or end

brnrd.dev is in beta. Features may be added, changed, throttled, or withdrawn; the
service may be interrupted for maintenance or to protect it, its infrastructure, other
users, or connected third-party services. We may end the beta, or the service, at any
time. We will give reasonable notice of a change that materially reduces what a paying
subscriber has already paid for, and section 10 governs what happens to money in that
case.

We do not promise any level of availability, response time, or data durability. The
durable copies of your work are the ones on your own machine and in your own
repositories.

5. Where the agent actually runs

This is the most important thing to understand about the service, and it is a
description of the product before it is a disclaimer.

The agent runs on your machine, as your user, with your credentials, against your real
repository, on your network — and it runs with its approval prompts deliberately
bypassed, because unattended work is the point of the product. It calls the model
provider under your own subscription, from your machine. brnrd.dev calls no model
provider: there is no model-provider client in the backend at all. What brnrd.dev does
is relay a message to your daemon and relay the reply back, and — if you turned it on —
mirror pages your agent wrote so the dashboard can render them.

Two consequences follow, and we would rather state them than have you discover them.
First, anything the agent does, it does with your authority: it can write files, run
shell commands, install dependencies, make network calls, and push to your forge, and a
mistake it makes is a mistake made on your system. Second, any text the service ingests
— an issue body, a review comment, a chat message — reaches the agent's prompt as
potential instruction. Whoever you authorise to trigger a run can, in practice, instruct
your agent. Authorise people as carefully as you would grant shell access.

We publish the full execution and trust model, including what each execution environment
does and does not isolate and which gaps are still open, in SECURITY.md. It is part of
how you should evaluate this service. It names, in particular, that worktree and docker
are not security boundaries.

6. Acceptable use, and what you instruct the agent to do

You must not use brnrd.dev to:

break the law, or infringe anyone's rights;

access systems, accounts, repositories, or data you are not authorised to access;

develop or distribute malware, credential harvesters, or tooling whose purpose is
unauthorised access;

attack, overload, probe, or circumvent the service's controls, quotas, authorisation
checks, or billing;

resell or provide the hosted service to third parties as if it were your own service;

process personal data through the service in a way that breaks the law applying to you
as its controller.

You are responsible for what you instruct the agent to do, for what the people you
authorise instruct it to do, and for what it does as a result. That responsibility does
not shift to us because an agent, rather than your hands, carried out the instruction.

An agent produces output that can be wrong, insecure, or subtly incorrect while looking
correct. You must review its output before you merge it, deploy it, publish it, run it
in production, or otherwise rely on it. We may suspend an account that is breaking this
section, immediately where the breach is causing harm.

7. Your content stays yours

Your code, prompts, messages, repositories, and everything your agent writes remain
yours. We claim no ownership of any of it, and nothing here transfers any intellectual
property to us.

To run the service we have to hold copies of some of it for a while: a message has to be
stored to be relayed, and a page has to be copied to brnrd.dev to be rendered in your
dashboard. So you grant us a non-exclusive, worldwide, royalty-free licence to host,
copy, transmit, and display your content solely to operate the features you have
enabled, and only for as long as we hold that copy. That is the whole grant. It ends
when the copy does.

For the avoidance of doubt, it is not a licence to use your content to train or
fine-tune any model, to build datasets, to publish or market it, or to sublicense it to
anyone other than the providers we need to run the service (hosting, payments, GitHub,
and the chat gate you chose to connect). brnrd.dev sends no part of your content to a
model provider, because the service makes no model calls at all — the model calls happen
on your machine, under your own account with that provider, under their terms.

What the mirror contains, and for how long, is set out on the hosted-execution page.
Read it before you enable publishing: it is measured, and it is more than people assume.

8. Our intellectual property

The brnrd source code is licensed to you under the open-source licences that ship with
it, and those licences govern what you may do with the code. The name "brnrd", the name
"HugiMuni", and the site's branding are not covered by those licences and remain ours;
use them to refer to the project, not to suggest we endorse or operate something we do
not.

9. Personal data, and third parties

For your account, billing, and the security of the service, HugiMuni SAS decides why and
how personal data is processed. For the content you route through the service — message
bodies, mirrored pages, repository-derived text, which may contain other people's
personal data — you decide, and we process it on your behalf and on your instructions.

A privacy notice is in preparation and not yet published; a data-processing agreement
exists and is available to any Customer on request. Until the privacy notice is
published, the measured description of what the service holds and for how long is on the
hosted-execution page and in SECURITY.md, and you can ask us anything about it at the
address in section 16. To delete your account, use the "delete account" control in
dashboard settings — it asks you to re-type your GitHub login to confirm, then deletes
everything except the append-only billing ledger, which the deletion confirmation itself
states is retained and why (the data-processing agreement carries the same statement).
Anything the self-service control doesn't cover, write to the address in section 16.

The service relies on providers: our host, our payment processor, GitHub for sign-in and
forge access, and whichever chat gate you choose to connect. Your use of a connected
third-party service is governed by that service's own terms, and we are not responsible
for it.

10. Paid plans, Stripe, and refunds

Where a paid plan is offered, checkout runs through Stripe under Stripe's Managed
Payments, which means Stripe is the merchant of record — the seller for that
transaction. Stripe calculates and remits the applicable tax, issues the invoice, and
shows you the final price including tax before you pay. The terms Stripe presents at
checkout govern that sale. We do not describe here what Stripe undertakes to you; read
what Stripe shows you at checkout.

Subscriptions renew for successive periods until cancelled. You can cancel at any time
and the cancellation takes effect at the end of the period you have already paid for; we
do not pro-rate a part-used period.

Refunds. Outside your mandatory legal rights, fees already paid are non-refundable. We
will, however, refund the unused remainder of a period you have paid for if we terminate
your account without your being in breach, or if we end the service or withdraw a
feature you were paying for. If you think you were charged in error, write to us and we
will look at it. Consumers in the European Union have statutory withdrawal and
conformity rights that this paragraph does not reduce; where those rights apply, they
win.

11. Hosted execution

Running an agent on compute that HugiMuni SAS operates, rather than on your own machine,
is a separate feature with its own additional terms: the hosted-execution beta terms.
Those terms supplement these; they do not replace them, and where they say more about
hosted runs specifically, they apply. You are asked to accept them at the point you use
that feature — not when you sign in — and accepting them is not acceptance of anything
else.

12. No warranty

To the fullest extent the law allows, brnrd.dev is provided as is and as available, and
we disclaim all implied warranties, including any implied warranty of merchantability,
satisfactory quality, fitness for a particular purpose, or non-infringement.

In particular, we do not warrant that the service will be uninterrupted or error-free,
that agent output will be correct, safe, secure, or fit for your purpose, or that the
execution environments constitute a sandbox, a containment boundary, or a defence
against prompt injection, malicious code, supply-chain compromise, data loss, or a
third-party tool your run can reach. The trust and execution model states what each
control does and does not do; that document, not an assumption, is the description of
what you are getting.

Nothing in this section excludes a warranty or guarantee that the law does not let us
exclude. If you are a consumer, the legal guarantees you have under French and European
Union law — including the guarantee of conformity for digital content and services —
apply in full, and nothing above reduces them.

13. Limitation of liability

First, what is never limited. Nothing in these terms excludes or limits our liability
for death or personal injury caused by our negligence, for fraud or fraudulent
misrepresentation, for dol or faute lourde, or for any other liability that the law does
not permit us to exclude or limit. If you are a consumer, your mandatory rights under
French and European Union consumer law apply in full and this section does not reduce
them.

Second, indirect loss. Subject to the paragraph above, we are not liable for indirect or
consequential loss, loss of profit, loss of revenue, loss of business or goodwill, or
loss of or damage to data, however caused.

Third, the cap. Subject to the first paragraph, our total liability to you for all
claims arising in any twelve-month period is limited to the greater of the fees you paid
us for the service in that period and one hundred euros (EUR 100). If you are a consumer
and this cap is unenforceable against you, it does not apply to you, and our liability
to you is instead whatever the law provides.

Fourth, severability. Each of the paragraphs above, and each limitation within them, is
separate. If one is held unenforceable — in general, or against a particular user — it
is severed to the minimum extent needed and the remaining paragraphs continue to apply.

You keep the responsibilities described in sections 5 and 6: the agent runs with your
authority on your machine, and reviewing its output before you rely on it is your job,
not ours.

14. Suspension and termination

You can stop using brnrd.dev at any time: disconnect your repositories and stop signing
in, or delete your account outright from dashboard settings. Disconnecting your last
repository deletes the mirrored copy of your pages from our servers; deleting the
account does that and everything else described in section 9, immediately, without a
support request.

We may suspend or terminate your access if you breach these terms, if your use is
harming the service or another user, if we are required to by law, or if we discontinue
the service. Where the circumstances allow it, we will tell you first. Sections 6, 7, 8,
12, 13, 15, and 16 survive termination.

15. Changes to these terms

We may change these terms. The version and date at the top of this page always identify
the current text. For a change that materially affects your rights or obligations, we
will publish the new version here and show a notice in the dashboard at least thirty
days before it takes effect, and if you do not accept it you may cancel and stop using
the service; for a paid subscription, section 10's refund sentence applies. For other
changes, continuing to use the service after the new version is published means you
accept it.

16. Governing law, forum, and contact

These terms are governed by French law. Disputes go before the courts of France. If you
are a consumer resident in the European Union, this does not deprive you of the
protection of the mandatory law of your country of residence, and you may also bring
proceedings in the courts there.

Contact: security@hugimuni.fr. For a security issue, use that address and please report
it privately rather than in a public issue.
