Terms of Use
The agreement that governs use of Hooldur - for the people who audit their apps with it, and for anyone visiting our website.
Version 0.1 · Effective 23 August 2026 · Last updated 23 August 2026
These terms govern access to and use of Hooldur. Like our Privacy Policy, they are written to be checked: every claim below describes how the product actually works today. Where something is not yet established, these terms say so rather than papering over it.
Contact: [email protected]
1. Who we are, and who you are
Hooldur is an AI-staffed IT department for apps built with AI tools, published and operated by the Hooldur Team. Today the service is one thing: a free, read-only audit. You connect the GitHub repository of an app you built - and, if you choose, its Supabase project and its domain - our agents read them and produce a graded, plain-English report, and you fix what you choose to and run it again.
There are two ways you might be reading this:
- You have, or are creating, a Hooldur account. Signing in binds you to these terms. If you are doing it in the course of your employment, or for someone else's app, the agreement is also with your employer or principal, and you confirm to us that you are authorised to connect what you connect on their behalf. An account comes with a workspace we call an organization; today it has one member, and that is you.
- You are visiting our website. Acceptable use, Our intellectual property, Disclaimers, Liability, Governing law and disputes, Changes to these terms, and Contact apply to you.
2. The service
We provide the audit described above, free of charge, and we keep improving it - features will change, and we will tell you when something that matters to you does. We may also change or withdraw the free audit; if we do, we will give notice, and your data follows the closure process in Suspension and termination rather than disappearing.
Paid tiers - scheduled audits, monitoring, and an operated service with a human behind it - are described on our website as what we are asking people about, not as what exists. Nothing you use today becomes chargeable without your agreement, and these terms change before any of that does.
We apply operational limits to keep the service stable and to protect every customer on it: one audit at a time per app, one completed audit per app per rolling day, seven completed audits per organization per rolling week, and rate limits on sign-in. These are protective, not a way to withhold something you have paid for - there is nothing you have paid for - and the product tells you when a limit applies and when it clears.
3. Accounts and eligibility
To use Hooldur you must be at least 18, or the age of legal majority where you live if that is higher, and you must have the legal capacity to enter into these terms.
Sign-in is by a one-time link sent by email, or with GitHub, Google, or Microsoft. There are no passwords, so there is no password for you to protect - but your email account and sign-in providers now control access to Hooldur, and to everything you have connected to it, and you are responsible for keeping them secure.
You agree to keep your account information accurate. Tell us promptly at [email protected] if you believe your account has been accessed without authorisation.
4. Your app, and what we do with it
The material an audit reads - your repository and its history, the metadata of your database, and what your domain shows a visitor - belongs to you (or your licensors), and so do the findings we produce from it.
The licence we take. To run the service we need permission to clone and read that material, to send it to the model hosts that do the reading, to store what the audit produces, and to show it back to you. That is the whole of the licence: it lasts as long as the app is connected, it is limited to running the audits you ask for, and it grants us nothing else. Our Privacy Policy describes each of those steps, and names the model hosts.
We do not train AI models on your content, and our inference routing requires zero data retention and no training from the hosts that serve it. The Privacy Policy states the precise scope of that guarantee and its limits, and it is the controlling description.
When we look at your content ourselves. Beyond the automated processing above, we will not access your repository, your findings, or anything else an audit read except:
- to provide, maintain and repair the service;
- to investigate or resolve a technical or security problem;
- to answer a support request from you, so far as answering it requires;
- where the law requires it, on the terms described in the Privacy Policy; or
- where you have asked us to.
Your responsibilities. You are responsible for having the right to connect what you connect: the repository, the database, and the domain must be yours, or you must be authorised to have them audited. If a repository or database contains other people's personal data, you are responsible for being allowed to show it to us - we read it only as part of the audit, on your instructions, and the Privacy Policy says how it is handled.
Data protection. Where we handle personal data on your behalf in that way we act as your processor, and the Privacy Policy sets out how. We have not yet published a separate data processing agreement; if you need one, write to [email protected] and we will tell you where that work stands. We would rather say that than point you at a document that does not exist.
5. Connected services
An audit reads through access you grant, and the access is narrow by construction:
- GitHub, through a GitHub App you install that asks for read access to code and metadata and nothing else. Each audit mints a token that expires in an hour and is never stored.
- Supabase, either through an authorisation that asks for read scopes only and cannot run SQL, or through a read-only database role you create with a statement we give you. We check the role when you paste its connection string, and refuse one that could read the rows of any table.
- Your domain, from the outside, as a visitor would - no credential at all.
By connecting a service you authorise us to read it in that way to run audits, and you confirm you are entitled to grant that access. You can withdraw it at any time: disconnect the service, delete the app, or close your account. Deleting an app revokes the Supabase authorisation at Supabase; closing your account also uninstalls the GitHub App. A read-only database role lives in your database, so dropping it is yours to do, and we show you the statement. Credentials we hold are encrypted as described in the Privacy Policy.
Hooldur sends email only to you - a sign-in link, a note when an audit finishes or fails, and a confirmation link if you close your account. We send nothing on your behalf to anyone else.
6. Acceptable use
You agree not to:
- connect a repository, database, or domain you do not own or are not authorised to have audited;
- use the service to break the law;
- probe, scan, or test the vulnerability of the service, or circumvent its security or its organization isolation, except with our prior written agreement;
- access or attempt to access another customer's data;
- interrupt or burden the service deliberately, including by evading its limits;
- resell or white-label the service without an agreement with us; or
- misrepresent who you are or who you act for.
We may investigate suspected violations and take the actions described in Suspension and termination.
7. The audit, and what it is not
Hooldur's agents read your app and propose findings - each with a severity, a fix, and an effort estimate - and a grade is derived from the worst of them. Every output is a suggestion to you: nothing the AI produces changes anything in your app, and no AI output takes effect against anyone without a person deciding to use it.
AI output can be wrong, incomplete, or out of date. You are responsible for reviewing a finding before you act on it, and for the changes you make to your own app. We do not warrant the accuracy of any finding, and we do not warrant that a clean audit means a secure app: the audit runs a stated set of checks against what it can reach, the report says what it could not check, and the absence of a finding is not a certification. A report describes weaknesses in a live application, so treat it as the sensitive document it is.
Read-only. The audit never writes, deploys, or deletes anything in your repository, your database, or your domain. The only changes we make on a connected account are to our own access - minting a token to read, or revoking our authorisation when you ask us to.
8. Price
The audit is free. There is no card to enter, no plan to choose, and nothing that renews. When a report is ready we ask what you would expect this to cost and what you would want it to do; that is research, not an order - nothing is charged, and no card is taken.
If we introduce paid tiers, their prices will be published where you would sign up for them, and these terms will say so first.
9. Suspension and termination
You can leave at any time. You can delete an app, which removes its audits and findings and destroys the keys they were encrypted under, or close your account from your profile, which does that for every app, uninstalls the GitHub App, and deletes your account. Closure is confirmed by a link we email you and takes effect immediately - no grace period, and no restore path - as described in the Privacy Policy, which also says what little survives.
We can restrict, suspend or terminate an account for material breach of these terms, or for use that creates a security or legal risk to us, to other customers, or to anyone else. We will give notice where practicable, and we prefer the narrowest step that resolves the problem - a restriction over a suspension, a suspension over termination. On termination the closure process above applies, and data is never deleted merely because an account was restricted.
Either of us can end this if the other stops trading - becomes insolvent, cannot pay its debts as they fall due, or has a liquidator, receiver or administrator appointed - by written notice. If that is us, the closure process above still applies.
10. Our intellectual property
The Hooldur platform - its software, the checks it runs and the way they are written, its design, and its name - is ours, along with everything in it that did not come from you. These terms grant you a limited, non-exclusive, non-transferable, revocable right to use the service for your own apps, and nothing more. In particular you may not:
- copy, modify, or create derivative works of the service;
- reverse engineer, decompile, or disassemble it, except so far as the law says you may despite this restriction;
- sell, rent, lease, sublicense, or otherwise make it available to a third party, or use it to operate a service for someone else, without an agreement with us; or
- remove or obscure any proprietary notice in it.
The findings and reports produced about your app are yours to use for that app. Our name and logo may not be used without our written permission.
If you send us feedback or suggestions - including your answers to the questions the product asks - we may use them without obligation to you; we will never claim your app or your findings as our own because of it.
11. Third-party providers
The service is built on third-party providers, and they are listed in the Privacy Policy. Those providers are ours to manage: we are responsible for how our product uses them.
The services you connect - GitHub, Supabase, and wherever your domain is hosted - are different. They are governed by their own terms, what Hooldur can do with them is limited by what you grant and what those services permit, and we are not responsible for the service itself - only for how our product uses it.
12. Disclaimers
The service is provided as is and as available. To the fullest extent the law allows, we disclaim all warranties that are not written into these terms, express or implied - including the implied warranties of merchantability, fitness for a particular purpose, title, and non-infringement.
We work to keep the service reliable and secure - the Privacy Policy describes the measures - but we do not promise it will be uninterrupted or error-free, and we do not offer a contractual uptime commitment. We would rather say that plainly than imply a service level we have not built the machinery to guarantee. The audit is an early product offered for free, partly as research into what to build next, and it may change or be withdrawn as described in The service.
13. Liability
Neither of us is liable to the other for indirect or consequential loss - lost profits, loss of goodwill, or loss of data you could have kept a copy of - arising from these terms.
Beyond that: you have paid us nothing, and a free audit is not a commitment on your side, so to the fullest extent the law allows we are not liable for loss arising out of your use of the service. Where the law does not allow that exclusion, our liability is limited to the least the law permits us to limit it to. If we ever charge for something, these terms will say what we owe you then.
One thing sits outside those limits: your obligation under Indemnity. It is not a limit on what we owe you, so it does not belong under one.
Nothing in these terms excludes or limits liability that cannot lawfully be excluded or limited - including for fraud, or for death or personal injury caused by negligence. That includes the Australian Consumer Law where it applies; where it permits us to limit our liability for services, our liability is limited to supplying them again or paying the cost of having them supplied again.
14. Indemnity
If a third party brings a claim against us because of something you connected to the service without the right to, or because of your use of the service in breach of these terms, you will defend us against that claim and cover the losses that result. We will tell you promptly about any such claim and let you control the defence, at your expense, and we will not settle it without your agreement.
15. Governing law and disputes
Before anything formal, write to [email protected]. We will try to resolve the matter with you directly, and most things end there. Neither of us gives anything up by trying.
These terms are governed by the laws in force in Queensland, Australia, without reference to conflict of laws principles. You and we submit to the exclusive jurisdiction of the courts of Queensland, Australia, and of the courts that hear appeals from them.
16. General
Notices. We give notice to you by email to your account address, and for changes to these terms by posting here as described below. An email notice takes effect one business day after we send it, unless we get a delivery failure back within that day - so keep an address that works. Notices to us go to [email protected], and take effect on the same terms.
Assignment. You may not transfer these terms or your account without our written consent. We may transfer them to an acquirer of our business or assets, on notice to you; the Privacy Policy describes what happens to personal data if that occurs.
Entire agreement. These terms and the Privacy Policy are the whole agreement between us about the service, and replace anything said before. Where you have signed a separate written agreement with us, that agreement prevails over these terms to the extent they conflict.
Confidentiality. Each of us will protect non-public information the other shares in the course of the relationship, and use it only for the purposes of the relationship. Your repository and your findings are governed by Your app, and what we do with it, and by the Privacy Policy, not by this paragraph.
Publicity. Neither of us will use the other's name or logo publicly without permission. If you give permission and later withdraw it, we will stop.
Waiver. If either of us does not enforce a right straight away, that is not a waiver of it.
Severability. If any part of these terms is unenforceable, the rest stays in force.
Survival. The sections that are meant to outlast the agreement do - Your app, and what we do with it, Our intellectual property, Disclaimers, Liability, Indemnity, Governing law and disputes, and this one.
Force majeure. Neither of us is liable for a failure to perform caused by something outside our reasonable control.
No third-party beneficiaries. These terms give rights to you and to us, and to nobody else.
Sanctions. You confirm you are not a person, and are not in a place, that we are legally prohibited from providing the service to, and that you will comply with applicable export control and sanctions law.
17. Changes to these terms
We will update this page when the terms change and record every change below. Material changes will be communicated to account holders directly, in advance, rather than left for you to notice. Continued use of the service after a change takes effect is acceptance of the changed terms.
18. Contact
Questions about these terms go to [email protected].
| Version | Date | Change |
|---|---|---|
| 0.1 | 2026-08-23 | Initial Terms of Use. |