Terms of Service

    Version 1.1 · effective from 2026-08-22

    This document is a working draft awaiting legal review. Until that review is complete it does not constitute binding terms of service.

    1. Scope

    These terms govern the use of the Candy Lab platform, including the One House product, where AI agents build and maintain applications on the Client's behalf.

    Using the platform means accepting these terms. If you do not accept them, do not create an account and do not use the service.

    2. Definitions

    Provider — [registration details to be completed], contact: hello@candylab.io.

    Client — the person or entity using the platform under an account.

    Project — a unit of work in One House with an attached code repository, tasks and the history of agent work.

    Company repository — a repository in the Provider's git namespace, used when the Client has not connected a git account of their own.

    3. Account and registration

    An account is required. The Client provides accurate details and is responsible for keeping credentials confidential and for actions taken from the account.

    Accounts are personal. Sharing an account is at the Client's own risk.

    4. What the service does

    The platform provides AI agents that plan, write, test and deploy code within a Project, plus the interface used to run and approve that work.

    Agent output is produced automatically. The Client is responsible for reviewing code before production use, in particular for security, legal compliance and fitness for the intended purpose.

    5. Payments, renewals and refunds

    Prices are shown in the pricing section, inclusive of tax, in the currency selected with the plan. The price in force at the time of purchase applies.

    For subscriptions and token top-ups, the seller of record is Paddle.com Market Ltd, acting as Merchant of Record. Paddle issues the invoice, collects payment and accounts for the tax applicable in the customer's country. Payment complaints may be addressed to us or directly to Paddle.

    A subscription renews automatically for each following billing period until cancelled. Cancellation is available at any time in the panel and takes effect at the end of the paid period — access remains active until then and no further payment is taken.

    Token top-ups are one-off purchases. Tokens do not expire, but they cannot be exchanged for money and are not refundable once consumed.

    RIGHT OF WITHDRAWAL. Consumers, and sole traders treated as consumers, may withdraw within 14 days without giving a reason. This right does not apply where performance has begun with the customer's express consent after being informed that the right would be lost — we ask for that consent before the service or tokens are made available. No refund is due for tokens already consumed or for the portion of a subscription period actually used.

    REFUNDS BEYOND STATUTORY WITHDRAWAL. We consider these case by case, in particular where the service was unavailable through our fault for a significant part of a paid period. Send requests to the contact address in these Terms; we reply within 14 days. Refunds are made using the original payment method.

    6. Code repository

    Project code is stored in a git repository. The Client may connect their own git account (GitHub or GitLab), in which case the repository is created in their namespace and stays under their control.

    If the Client has not connected an account, the Provider creates a private repository in the company namespace so work can start. The Client is granted access to it where they hold an account with the git provider. The Client may connect their own account at any time and request a transfer of the repository.

    Credentials for the Client's repositories are stored encrypted and used only for operations performed within the Project.

    7. Code backup copy

    For Projects with the backup copy enabled, the Provider keeps a copy of the repository in its own infrastructure. The purpose is continuity: recovering the Project's work if access to the source repository is lost, revoked or the repository is deleted.

    The copy is private and available only to the people delivering the service. The Client may disable it in the Project settings; disabling it deletes the copy.

    The copy does not replace the Client's own backups and is not an archiving service.

    8. Rights to code and content

    Code and materials produced within a Project belong to the Client. The Provider acquires no rights to them beyond what is necessary to deliver the service (storage, processing, deployment, backup).

    The Client declares that materials supplied to a Project do not infringe third-party rights.

    The platform itself — its code, interface and starter libraries — remains the Provider's property.

    9. Processing by AI providers

    Delivering the service requires sending Project content — including code fragments, task descriptions and conversations — to external language-model providers. The list of providers is in the Privacy Policy.

    The Client should not place data in a Project whose disclosure to such providers would be unacceptable, in particular production passwords and access keys.

    10. Availability

    The Provider makes reasonable efforts to keep the platform running but does not guarantee continuity. Maintenance windows, outages and limits imposed by third-party providers are possible.

    11. Liability

    The Provider is liable for damage caused intentionally and within the limits set by mandatory law.

    The Provider is not liable for the consequences of using agent-produced code without review by the Client, nor for data loss occurring on the Client's git provider.

    12. Changes to these terms

    These terms carry a version number and an effective date. Material changes are announced before they take effect and require acceptance again.

    If the Client does not accept a new version, they may terminate the agreement at no additional cost.

    13. Termination and data deletion

    The Client may delete their account at any time. The Provider may suspend or delete an account for a material breach of these terms, after prior notice unless notice is impossible or pointless.

    After termination, company repositories for the Client's Projects are archived and backup copies deleted. The Client should download any code they wish to keep beforehand.

    14. Contact

    Questions and complaints: hello@candylab.io. We respond within 14 days.

    Version identifier: terms@1.1