Terms of service
The agreement between you and Ackee: what the service is, what you are responsible for in your own cloud account, what it costs, and what each of us can and cannot hold the other to.
The agreement
These are the terms of service for Ackee — the sites at ackee.dev, app.ackee.dev and docs.ackee.dev, the deployment manager, the API, and the Ackee mobile apps when they ship — provided by Ackee, a service operated from the United States by its developer ("Ackee", "we", "us"). They are a contract between you and us.
You accept them by creating an account, including through Continue with GitHub. Both account screens link to these documents before account creation. Agreement to the privacy policy does not waive your privacy rights or replace separately required consent. Section 17 explains when v0.3.0 applies to existing accounts. If you use Ackee on behalf of a company or another organisation, you are telling us you have the authority to bind it, and "you" in these terms means that organisation too. The privacy policy is part of this agreement and says what we do with your data.
Ackee is in preview. Section 10 says what that means; in short, it works, it is under active development, and it will change.
Who can use Ackee
- You must be at least eighteen years old and able to enter into a binding contract. Ackee deploys production infrastructure that costs money; it is not for children, and we do not knowingly let anyone under thirteen create an account.
- You must not be a person, or act for an organisation, that United States law prohibits us from dealing with — on a sanctions list, or in a country subject to a comprehensive embargo. Ackee is software subject to US export law, and you agree to follow it.
- You must not have been removed from Ackee before for breaking these terms.
Your account
You need an account with a verified email address to deploy. You are responsible for protecting its credentials, activity you authorise and reasonable steps to prevent misuse. Notify us promptly of suspected compromise. We strongly recommend two-factor authentication, which every account can enable; GitHub’s own second factor and any enabled Ackee factors apply to their respective sign-in steps.
Your account page shows every device signed in and lets you sign any of them out. If you see one you do not recognise, revoke it and change your password, which signs every device out at once. Then tell us.
Personal API tokens and apps connected through Ackee OAuth are separate from browser sessions. Signing out does not disconnect them. Review and revoke them under Account → API tokens and Account → Connected apps, protect tokens from disclosure, and remove connections you no longer trust or need. A password reset also revokes personal API tokens and connected-app tokens; it does not revoke credentials issued by your cloud provider.
We may suspend an account that we reasonably believe is compromised, is being used to attack someone, or is breaking these terms, and we will tell you when we do unless the law or the safety of others stops us.
Teams and project-specific roles control shared access across a project’s environments. Members can see membership emails and roles; authorised collaborators can view configuration, logs and outputs and perform operations through shared connections without seeing the stored secret. Review access before inviting someone. Only invite people you are entitled to contact and grant permissions you are entitled to give.
Work contributed to another organisation may remain under its control after you leave. Deleting the account recorded as an organisation’s billing account can delete that organisation and its shared work. Coordinate deletion with collaborators first.
What Ackee does
Ackee is a visual infrastructure editor with templates, existing-resource references, projects and environments, team collaboration, a command console and OpenTofu plan/apply/destroy operations. Supported repository connections can trigger deployments and builds from pushes or build notifications. Some Google Cloud workloads build source through Cloud Build and Artifact Registry; configured GitHub Actions workflows can build images separately. Feature support differs by cloud, node and configuration. Automatic apply, when enabled, authorises a run without separate approval of each plan.
Your cloud provider hosts your deployed resources and bills for them. Execution can occur on an Ackee worker or, when configured, in AWS Fargate, Google Cloud Build or Azure Container Apps in your account. Durable state is supported in configured AWS S3 and Google Cloud Storage buckets and Azure Blob Storage; unsupported or development configurations may retain worker-local state that does not survive replacement. Review state settings and warnings before relying on a deployment.
Ackee also provides an MCP endpoint for compatible AI assistants and other clients, and personal API tokens for scripts and automation. These interfaces can read and change permitted projects, edit graphs, request plans and approve infrastructure operations. Account verification, project roles and plan limits still apply.
We may change, add to or remove features, and we will try to give notice before removing something people rely on. We do not promise that any feature, node or cloud will be supported forever.
Your cloud account, your charges, your resources
This is the section that matters most, because it is where Ackee differs from a service that hosts your things for you.
- The cloud account is yours. You must have the right to use it and to grant Ackee the access you grant. Your agreement with the cloud provider governs that account; ours does not.
- Cloud provider charges are yours. Resources, builds, storage and network usage are billed in your account. A deployment plan is not a complete statement of those charges. Check your provider's pricing and console as well as the plan.
- Approving a plan authorises Ackee to apply it. Enabling automatic apply authorises runs from configured repository or workflow events without separate approval of each plan. Destroy operations can remove databases and their contents. A plan describes intended changes, not a guarantee of success or rollback. Preparation, service enablement and builds can occur before plan approval as described below.
- Ackee acts within the access you grant for the connected features described in these terms and the privacy policy. Use the least privilege suitable for your workflow and revoke access at the provider when needed.
- Protect your state. When durable cloud state is configured, it lives in your account's bucket or Azure storage container. Deleting or altering that state can prevent safe reconciliation. Ackee checks for unexpected state loss in supported flows, but an acknowledgement does not recover missing state or guarantee that resources will not be duplicated or left unmanaged. Worker-local state has the limitations in section 4.
- Deleting your Ackee account, or a project, deletes the drawing and the history on our side and leaves your cloud account exactly as it is. Resources keep running and keep costing money until you destroy them — from Ackee, before you delete, or by hand afterwards.
- Ackee generates infrastructure configuration that you are responsible for. Whether a particular graph is secure, resilient, compliant with a standard, or right for your workload is your judgement to make, not ours.
Connecting credentials also authorises the connection tests, readiness checks, supported discovery and import, Google API enablement and Azure resource-provider registration needed for requested features, state and runner preparation and builds described in the privacy policy. Some checks occur when you open an environment; deployment preparation can also enable required services before plan approval.
Builds, runner preparation, storage and network transfer may incur provider charges before an infrastructure plan is approved, or even if a deployment fails or is cancelled. Estimates are not spending caps. A failed or cancelled run can leave partially changed resources; cancellation is not a guaranteed rollback.
Existing-resource references do not manage the referenced resource as a newly created node, but other nodes or operations can still affect related permissions and services. Review the complete plan. Deleting Ackee records does not remove staged source archives, images, state buckets or provider logs.
Credentials and connected services
When you approve an app on Ackee's consent screen or give a personal API token to a client, you authorise it to access permitted account content and submit operations on your behalf within the access you grant. The current MCP OAuth permission covers both reading and changing projects accessible to your account; it is not limited to a single project or to read-only use. Personal API tokens also allow permitted API routes beyond MCP, while sensitive account, billing and credential-management routes require a signed-in session. Use only clients you trust with that access.
An authorised client can submit the approval that applies a plan, including a planned teardown. The MCP plan and destroy tools stop for approval, but the same client can call the approval tool; Ackee does not require a separate human click in the editor for that call. Review proposed changes and configure your client's confirmation controls before allowing deployment actions. Agent-generated configuration and explanations can be wrong, and a client's confirmation interface is governed by that client.
You are responsible for activity you authorise through connected clients and for the resulting cloud charges, subject to applicable law and the limits in these terms. Connecting a client does not enlarge your rights to another person's or organisation's content. Make sure you have authority to share the returned information with that client and any model provider it uses. Its terms and privacy practices apply to its own processing; the additional restrictions on Google API data in the privacy policy continue to apply. Registration with Ackee is not an endorsement of a client.
When you connect GitHub, Google or a cloud provider, you authorise Ackee to use that connection as the privacy policy describes, and you can withdraw the authorisation at any time by disconnecting it in Ackee or revoking Ackee at the provider. Ackee stores what you connect encrypted and uses it only for the purpose you connected it.
Those services are not ours. Your use of GitHub, Google, AWS, Azure and Stripe is governed by their terms, and we are not responsible for what they do, for their outages, or for a change in their APIs that stops a feature of Ackee from working. We will fix what we can when they change.
For a supported source build you authorise Ackee to fetch the selected repository archive, stage it in your cloud, execute the selected Dockerfile in the configured build environment and publish the image. Ensure you have rights to repository content and dependencies, and review code that runs with your build permissions.
Disconnecting a stored connection may not stop a running job, revoke an already issued token or remove a separate project/node connection. Revoke access at the provider when needed.
Revoke an Ackee-connected app or personal API token in its account controls to stop subsequent access through it. This does not undo completed changes, cancel a deployment already applying, or delete copies a client has already received. Manage those copies with the client and its provider.
Your content
You retain your rights in the graphs, configuration, names and other content you put into Ackee, including through an agent, and Ackee claims no ownership of the OpenTofu configuration it compiles for you. You grant us a worldwide, non-exclusive, royalty-free licence to store, copy, process, compile, build, transmit and display that content solely to provide and secure the service, including sharing it with authorised collaborators, configured build providers and clients you connect. This permission lasts while the content is held for those purposes, including limited retention described in the privacy policy. Third-party code, dependencies and client-generated material remain subject to any applicable rights and licences; using Ackee does not establish ownership or exclusivity in material generated by an AI system. This licence does not authorise training general-purpose AI models on your content. We claim no other right in it.
You are responsible for your content: for having the right to use it, for what it does when deployed, and for keeping secrets out of it. Ackee routes the passwords it generates through your cloud's secret service, but a secret you paste into a field is stored with the graph and may surface in a log. Use a reference to a secret instead.
If you give us feedback or a suggestion, we may use it without owing you anything for it.
You must have the authority and any notices or consents needed to submit other people’s personal information. Arrange any legally required data-processing agreement or additional safeguards before submitting that data.
Acceptable use
You agree not to use Ackee to:
- Deploy into a cloud account, or connect a repository or credential, that you do not have the right to use.
- Attack, probe, overload or gain unauthorised access to Ackee, to any other user, or to anyone else — including by deploying infrastructure whose purpose is to do so.
- Break the law, infringe anyone's rights, or distribute malware or anything else harmful.
- Evade plan limits, share one paid account among many organisations, or resell access to Ackee.
- Reverse-engineer the service beyond what the law allows, scrape it, or interfere with its operation. The compiled OpenTofu is yours to read, keep and run without us; the service itself is not yours to copy.
- Impersonate anyone, or misrepresent who you are acting for.
We may suspend or end an account that breaks these rules, and we may remove content that does. We are not obliged to police content and take no responsibility for it by not doing so.
Plans, fees and billing
- The free plan costs nothing and has the limits shown on your account page. Paid plans cost the monthly price shown, in US dollars, at the moment you choose them, and are billed in advance each month.
- A paid plan renews automatically at the end of each monthly period, at the same price, until you cancel. You will be told this, and asked to confirm it separately, on the checkout page before you are first charged.
- Where a plan allows usage beyond its included limits — additional projects, additional deploys — the extra is charged at the per-unit rate shown on your account page and at checkout, and billed at the end of the period in which it was used.
- MCP tool-call allotments reset each UTC calendar month, separately from the subscription renewal date: 1,000 calls on Free, 10,000 on Starter, 50,000 on Pro and 250,000 on Business. Free refuses further calls at its allotment. On paid plans, additional calls continue and incur US $1 for each block of 1,000 additional calls started, where metered billing is configured and the charges have been disclosed and authorised. The first call in a block incurs the full block charge. For example, one call beyond the allowance starts a $1 block; 1,001 additional calls start two blocks costing $2.
- Recognised MCP tool calls that reach tool execution count even when the tool returns an error, including failed operations, repeated status checks and retries. Requests rejected before tool execution, including an exhausted free allotment, do not count. MCP usage is attributed to the calling account; deployment and cloud-provider charges are separate and may also apply to the same action. Review usage in Billing and your client's automation settings. A policy update alone does not authorise previously undisclosed charges or retroactive overage billing.
- You can cancel at any time from the Manage billing button on your account page, which opens the billing portal; complete the cancellation confirmation there. Contact us if the controls are unavailable. Cancellation takes effect at the end of the current period, you keep the plan until then, and renewal stops. Previously incurred fees or metered usage may still be payable.
- Fees are not refundable for the unused part of a period, except where the law where you live requires a refund, in which case that law applies. If we make a mistake in billing you, tell us and we will put it right.
- Payment is taken by Stripe, on Stripe's pages, under Stripe's terms. We do not see your card. Payment failures can restrict paid features according to subscription status and plan limits. Your cloud resources are not destroyed by a downgrade or failed payment.
- Prices may change. A price change applies to you only from the start of a period beginning at least 14 days after we have emailed you about it, so you always have a chance to cancel first.
- Prices exclude taxes. Where we are required to collect a tax on the fee, it is added at checkout and shown before you pay.
Project limits count parent projects, with environments belonging to those projects. Deployment usage counts runs under the displayed allowance; free deployment allowances may be lifetime limits and paid allowances follow the billing period. Overage applies only where enabled and at the disclosed rate.
Personal and team billing records are separate. A stored seat count does not itself create a seat charge; disclosed and accepted pricing governs. Leaving a team, deleting a project or disconnecting a cloud account does not cancel a subscription. Creating a free account does not authorise paid recurring charges.
Where billing is labelled simulated, upgrades are for preview/testing and do not charge a payment method. They do not authorise future real charges. Mandatory cancellation, withdrawal and refund rights remain unaffected.
Preview, beta and new features
Ackee is in preview, and these terms carry a version starting with 0 for that reason. While that is so, and for any feature we label beta, preview or experimental afterwards — new nodes, new clouds, the mobile apps — the feature may change or be withdrawn without notice, may have bugs, has no uptime commitment, and may in the worst case fail in a way that affects resources in your account. Use the plan view; it exists so that you can see what a feature is about to do before it does it. Section 13 applies with particular force to preview features.
Our intellectual property
The Ackee service, its design, its compiler, its documentation and its name are ours, protected by copyright and trademark law, and licensed to you only as these terms say. You may not use the Ackee name or marks without our written permission, except to say truthfully that you use Ackee.
OpenTofu is open-source software under its own licence, which governs your use of it. The configuration Ackee compiles from your graph is yours (section 7), and you may keep it, edit it and run it with OpenTofu yourself, whether or not you continue to use Ackee. That is the point.
Ending the agreement
You may end this agreement at any time by deleting your account: write to legal@ackee.dev from the account's address, or use the account deletion the app offers. Account deletion attempts to cancel the personal subscription before removing the account and its sessions and stored connections. It does not revoke provider credentials or guarantee cancellation of separate team or provider subscriptions. Cancel those through their billing controls and contact us if unavailable. Deletion can remove organisations tied to your billing account and their shared work; content in other organisations may remain, as the privacy policy describes. We will not delete an account while one of its deploys is still running; wait for it to finish, then ask again.
We may end this agreement, or suspend your access, if you materially break it and do not put it right within fourteen days of being told, or immediately if the breach is one that cannot be put right or that endangers others. We may also end the service as a whole, on at least thirty days' notice by email, in which case any prepaid fee for time after the end is refunded.
Ending the agreement does not touch your cloud account: resources Ackee deployed stay, and keep costing money, until you destroy them. Sections 5, 7, 11, 13, 14, 15 and 18 survive the end of the agreement.
Disclaimers
ACKEE IS PROVIDED "AS IS" AND "AS AVAILABLE". TO THE FULLEST EXTENT THE LAW ALLOWS, WE DISCLAIM ALL WARRANTIES, EXPRESS OR IMPLIED, INCLUDING WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE AND NON-INFRINGEMENT. WE DO NOT WARRANT THAT THE SERVICE WILL BE UNINTERRUPTED, ERROR-FREE OR SECURE, THAT A PLAN WILL APPLY WITHOUT ERROR, THAT INFRASTRUCTURE COMPILED FROM YOUR GRAPH WILL BE SECURE, COST-EFFICIENT, COMPLIANT WITH ANY STANDARD OR SUITABLE FOR YOUR PURPOSE, OR THAT ANY CLOUD PROVIDER WILL BEHAVE AS DOCUMENTED.
Some jurisdictions do not allow some of these disclaimers. Where the law where you live does not allow one, it does not apply to you, and the rest still do.
Limitation of liability
TO THE FULLEST EXTENT THE LAW ALLOWS, ACKEE WILL NOT BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL OR PUNITIVE DAMAGES, OR FOR ANY LOSS OF PROFIT, REVENUE, DATA OR GOODWILL, ARISING OUT OF OR RELATING TO THESE TERMS OR THE SERVICE, HOWEVER CAUSED AND UNDER ANY THEORY OF LIABILITY, EVEN IF WE WERE TOLD SUCH DAMAGES WERE POSSIBLE. WITHOUT LIMITING THAT, WE ARE NOT LIABLE FOR CHARGES FROM YOUR CLOUD PROVIDER; FOR RESOURCES CREATED, MODIFIED, REPLACED OR DESTROYED IN YOUR ACCOUNT BY A PLAN YOU APPROVED OR A PUSH YOU CONFIGURED TO APPLY; FOR DATA LOST WHEN SUCH A RESOURCE WAS DESTROYED OR REPLACED; FOR STATE YOU ALTERED OR DELETED; OR FOR THE ACTS, OUTAGES OR CHANGES OF A CLOUD PROVIDER, GITHUB, GOOGLE OR STRIPE.
OUR TOTAL LIABILITY TO YOU FOR ALL CLAIMS ARISING OUT OF OR RELATING TO THESE TERMS OR THE SERVICE WILL NOT EXCEED THE GREATER OF THE FEES YOU PAID US IN THE TWELVE MONTHS BEFORE THE EVENT GIVING RISE TO THE CLAIM AND FIFTY US DOLLARS.
Nothing in these terms limits liability that the law does not allow to be limited, including for death or personal injury caused by negligence, for fraud, or, where you are a consumer, any right the consumer law where you live gives you and does not let you waive.
Indemnification
You will defend, indemnify and hold harmless Ackee and its developer from any claim, loss, liability or expense, including reasonable legal fees, brought by a third party and arising from your content, your use of the service, what you deploy and run in your cloud account, your breach of these terms, or your breach of the law or of someone's rights. We will tell you promptly of any such claim and let you control its defence, provided you do not settle it in a way that admits fault on our part or binds us without our consent.
Copyright complaints
If you believe content on Ackee infringes your copyright, send a notice to legal@ackee.dev with your contact details, a description of the work and where on Ackee you found the copy, a statement made in good faith that the use is not authorised, a statement under penalty of perjury that you are the owner or act for the owner, and your signature. We will take the content down and tell the account that posted it, which may send a counter-notice. We may end the accounts of repeat infringers.
Changes to these terms
Version 0.3.0 is dated September 9, 2026 and applies to new accounts from publication. Substantive changes for earlier accounts take effect no sooner than 14 days after we email a summary. Publication alone does not establish that notice was sent or the period elapsed.
Future substantive revisions also receive at least 14 days’ advance email notice and a new version. Corrections that do not change rights or obligations can apply on publication. We obtain affirmative acceptance where required by law. Subject to those requirements, continued use after a notified change takes effect constitutes acceptance; you may stop using the service and end the agreement if you disagree.
Changes do not retroactively alter accrued claims or supply consent to new personal-data uses. The privacy policy governs its own notice and consent requirements. Prior wording is available on request.
Governing law and disputes
These terms are governed by the laws of the United States, without regard to conflict-of-law rules. Ackee is not yet a registered company; before version 1.0.0 of these terms we will name the state whose law applies and whose courts hear disputes, and that change will be announced like any other substantive change. Until then, any claim between you and us may be brought only in a court in the United States.
Before either of us starts a claim, we agree to try to resolve the dispute informally: write to legal@ackee.dev, or we will write to your account's address, and both of us will make a good-faith attempt to settle it within thirty days. If that fails, either of us may go to court. TO THE EXTENT THE LAW ALLOWS, EACH OF US WAIVES ANY RIGHT TO A JURY TRIAL, AND ANY CLAIM MUST BE BROUGHT IN YOUR OR OUR INDIVIDUAL CAPACITY AND NOT AS A CLASS OR REPRESENTATIVE ACTION. If you are a consumer in a jurisdiction whose law gives you the right to sue where you live, or under its own consumer law, nothing here takes that right away.
General
- These terms and the privacy policy are the entire agreement between you and us about Ackee, and replace any earlier one.
- If any part of these terms is found unenforceable, that part is limited to the minimum extent necessary and the rest stays in force.
- Our not enforcing a term is not a waiver of it.
- You may not assign this agreement without our written consent. We may assign it to a successor that takes over Ackee, and we will tell you when we do.
- Neither of us is liable for a failure caused by something beyond our reasonable control — a cloud provider outage, a network failure, a natural disaster, a change in the law — except that this does not excuse an obligation to pay.
- We may give you notice by email to your account's address or by a message in the service; you give us notice at legal@ackee.dev. By creating an account you agree to receive notices, including billing notices and invoices, electronically.
- Nothing in these terms creates a partnership, joint venture, employment or agency relationship between you and us, other than the limited authority to act in your cloud account that section 5 describes.
Contact
Questions about these terms go to legal@ackee.dev. That address reaches the developer who runs Ackee.
Version history
Every version of this document has a number. While Ackee is in preview the number starts with 0: a change to the middle digit (v0.2.0) means something you agree to, or something we collect, has changed; a change to the last digit (v0.1.1) means the wording changed but not the substance. Version 1.0.0 will be the text in force when Ackee leaves preview. This address shows the latest published version. The changes section explains when it applies to existing accounts; the history records what changed and when.
- v0.3.0September 9, 2026currentAdds connected-agent and API-token authority, approval and revocation limits, client data sharing, content rights and monthly MCP allotments with block-based overage charges. Updates Azure support. Existing-account advance notice and mandatory rights remain in place.
- v0.2.0September 6, 2026Updated account agreement, collaboration permissions, environments, discovery, source builds, automation, state risks, recurring and simulated billing, and deletion. Preserves advance notice for existing accounts.
- v0.1.0September 2, 2026First draft, written for the preview. Sets out the own-cloud-account model — your credentials, your charges, your state, your approval of every plan — alongside monthly plans with one-step cancellation, the preview disclaimer, and courts rather than arbitration for disputes.
Questions about this document go to legal@ackee.dev.