End-User License Agreement
Effective: August 29, 2026 (version 2026-08-29)
Summary
# Summary
A plain-English outline of what this Agreement says. The numbered sections below are the actual licence terms — they control if there is ever a conflict.
- This Agreement is your **licence to use Fresh Jots**. Fresh Jots is a hosted service: you get a limited, personal right to use it under your plan, not a copy of the software you own. It sits alongside the [Terms of Service](/terms) (account, billing, acceptable use) and the [Privacy Policy](/privacy) (personal data); the per-tier capacity, rate, and size limits that bound your licence are published, and kept current, at [/limits](/limits) as Schedule A.
- **Your notes are yours.** We don't claim ownership, sell them, or train AI on them; we only access them to run the Service. That promise is about *our* systems, though — if you connect an outside AI client or tool yourself (see below), you're the one sending your notes to that third party, at your own risk and under their terms. Keep your own backups — you can ask for a full export at any time, and we email you a one-time signed download link when the archive is ready.
- **Encrypted notes are yours to hold.** You can client-encrypt a note on your own device before sending it and store only the ciphertext; we never receive your key, so we can't read, search, or decrypt those notes — and can't recover them if you lose your key. Keep your key backed up somewhere safe and separate.
- **Notarization (Dev and Team) proves a note hasn't changed.** If you notarize a plain-text note, we hash it and anchor a daily fingerprint to the Bitcoin blockchain, so you — or anyone you give the proof to — can show it existed by a certain time and is unaltered. It proves integrity, not truth (not that the content is accurate, or untouched before we saw it), and it depends on outside networks (OpenTimestamps and Bitcoin), so we don't guarantee a proof anchors, confirms, stays retrievable, or is accepted as evidence — you rely on it at your own risk. The one-way hashes and the public anchor reveal nothing about your content and are kept even after you delete a note.
- **Your licence is scoped to your tier.** Free, Personal, Dev, and Team each carry different note, storage, API, and rate-limit ceilings. Going around the controls that enforce those limits — or sharing one account between several people — is outside the scope of your licence.
- **What you may not do:** copy, resell, or reverse-engineer the software; circumvent your plan's limits or rate caps; scrape outside the documented API; probe security without permission; or use Fresh Jots, its features, or any data you observe from it to build a competing product.
- **Credentials are yours to safeguard.** You may hold up to four kinds of credential, and you're responsible for all traffic any of them authenticate: general **API tokens** (Dev and Team) under your active-token cap; a system-issued **14-day trial API token** if you signed up in code mode; one append-only **browser-extension token** bound to a single note, available to every active subscriber and revoked automatically when your subscription lapses; and a per-note **inbound-webhook URL** at `/h/<token>` where the unguessable path is itself the credential.
- **Team workspaces** (the Team tier) are a single licence held by the **owner**, who is the contracting party for the whole workspace. The owner grants each accepted member a personal sub-licence to use the workspace; accepted members must comply with this Agreement and the Terms of Service, and the owner is responsible for what members do under team credentials. Invitations expire after 14 days, an individual can hold at most one accepted membership at a time, and owners and admins can read the 90-day team audit log.
- **Public share links and outbound alert destinations** are yours to control. You decide which notes to share or where to send your team's overdue-note alerts; you can revoke a share link at any time, and you're responsible for what you share and for any third-party endpoint you point us at.
- **Connecting AI clients and other apps** — through the **MCP endpoint** at `/mcp` or an OAuth connection — is your choice and your responsibility. A connected tool can read, write, and even delete your notes within the scope you grant it, so grant only the access it needs and revoke it when you're done. When that tool is or relies on an AI provider, your notes leave Fresh Jots and that provider's own terms govern what happens to them; we don't control or vet those third parties and aren't responsible for them.
- The Service is provided **"as is"**, and our liability is limited as set out in the Terms of Service. Your mandatory consumer-protection rights are unaffected.
- We may **update this Agreement.** Material changes come with at least 14 days' notice and a request to re-accept; on the effective date, signing in to the browser surface bounces you through a one-click re-acceptance gate, and the acceptance is recorded on your account for audit.
# End-User License Agreement
This End-User License Agreement (the "Agreement" or "EULA") is a binding legal agreement between you ("you" or the "Licensee") and Privately owned ("we", "us", or the "Licensor") governing your access to and use of the Fresh Jots software and hosted note-taking service (together, the "Service"). It is the licence layer of our legal documents: the [Terms of Service](/terms) govern your account, billing, and acceptable use; the [Privacy Policy](/privacy) governs how we handle personal data; this Agreement governs the grant, scope, and restrictions of your right to use the Service. Where these documents overlap, the order of precedence in the Terms of Service controls, and this Agreement controls for matters of licence grant, permitted use, and restrictions.
By creating an account, clicking to accept, or otherwise accessing or using the Service, you confirm that you have read, understood, and agree to be bound by this Agreement. If you do not agree, do not access or use the Service. You must be at least 16 years old and have the legal capacity to enter into this Agreement; if you use the Service on behalf of an organisation, you represent that you are authorised to bind that organisation, and "you" includes that organisation. You further represent and warrant that you are not located in, ordinarily resident in, or organised under the laws of, and are not a national of, any country or territory subject to comprehensive trade sanctions or embargoes administered by the United Nations, the European Union, the United States, the United Kingdom, or the Republic of North Macedonia; that you are not identified on any restricted-party, denied-persons, or specially-designated-nationals list maintained by any of those authorities; and that you will not use the Service, or make it available to any person, in violation of any applicable export-control, sanctions, or dual-use regulation. These representations are continuing and are made each time you access or use the Service.
## 1. Definitions
- **Service** — the Fresh Jots hosted application, its software, web interface, REST API, remote Model Context Protocol (MCP) endpoint, OAuth 2.1 authorisation endpoints, inbound-webhook ingestion endpoints, browser extension, command-line interface, documentation, and related features, as we make them available from time to time.
- **Software** — the object and source code, interfaces, and underlying technology that make up the Service, whether executed on our servers or delivered to your browser as client-side code.
- **Your Content** — the notes, titles, folders, attachments, comments, and other material you create, upload, or store in the Service. Your Content is yours; this Agreement does not transfer ownership of Your Content to us. The licence you grant us to operate the Service on Your Content is set out in the Terms of Service.
- **Encrypted Note** — a plain-text note whose body you encrypt on your own device, with a key we never receive, before you send it to the Service. We store and return the resulting ciphertext exactly as sent, without the ability to read, search, index, or decrypt it. Marking a note as "client-encrypted" is your own declaration for how the Service should treat the note, not a fact we verify; the confidentiality of an Encrypted Note comes from your encryption, not from the marker.
- **Notarization** — an optional tamper-evidence feature, available on the Dev and Team Tiers, that computes a one-way cryptographic hash (SHA-256) of each note event — each entry of an append-only log as we receive it, and a once-a-day snapshot of a note you edit — combines each day's hashes across accounts into a single Merkle tree, and commits that tree's root to the public Bitcoin blockchain through the third-party OpenTimestamps calendar network. Notarization operates on hashes, not on the readable text of Your Content; for an Encrypted Note it hashes only the ciphertext we receive.
- **Notarization Proof** — the cryptographic evidence Notarization produces for a note: the note's per-event hash chain, the Merkle path linking it to a daily root, and the OpenTimestamps/Bitcoin timestamp, which together let you (or anyone you give the proof to) demonstrate that the note existed by a certain time and has not changed since. A Notarization Proof is derived from one-way hashes and carries none of your identity.
- **API Token** — a bearer credential you generate to authenticate requests to the REST API. Where this Agreement refers to "API Token" without qualification, it means a general-purpose bearer token issued from your profile.
- **Trial API Token** — a system-issued, time-bounded API Token granted on signup when you choose the developer onboarding mode; it expires 14 days after issuance and is then deleted automatically.
- **Extension Token** — a single, append-only API Token bound to one note, intended for the Fresh Jots browser extension, as described in Section 5.
- **Ingest Token** — the unguessable per-note URL component used by the inbound-webhook endpoint at `/h/<token>`, as described in Section 5.
- **MCP Endpoint** — the remote Model Context Protocol endpoint at `/mcp` through which AI clients, assistants, and agents can read, create, append to, edit, move, and delete your notes and folders, authenticated either with an API Token or with the OAuth access token of a Connected Application, and subject in each case to the scope of the credential used and to Schedule A, as described in Section 5.
- **Connected Application** — any third-party application, AI client or assistant, agent, coding tool, or other service that you authorise to access your account or Team Workspace through the REST API, the MCP Endpoint, or our OAuth 2.1 authorisation flow, whether by configuring it with an API Token or by completing an OAuth authorisation, as described in Section 5.
- **Team Workspace** — a multi-seat workspace created when an account purchases a Team-tier subscription, sharing notes, folders, API tokens, alerts, and an audit log among its accepted members.
- **Team Owner**, **Team Admin**, **Team Member** — the three roles a person can hold within a Team Workspace, as described in Section 6.
- **Schedule A** — the service limits published at [/limits](/limits), which are incorporated into this Agreement by reference and set the per-tier capacity, rate, and size limits that bound your licence.
- **Tier** — the plan under which you use the Service (Free, Personal, Dev, or Team), each carrying the entitlements and limits described on our pricing page and in Schedule A.
- **Usage Statistics** — aggregated, de-identified statistics we derive about how the Service is used (for example, total note counts, request volumes, or error rates), measured from technical and operational logs and never from the contents of Your Content. Usage Statistics do not identify you or any other user.
## 2. Licence grant
Subject to your continuous compliance with this Agreement and the Terms of Service, and to any limits applicable to your Tier, we grant you a limited, non-exclusive, non-transferable, non-sublicensable, revocable licence to access and use the Service for your own personal note-taking or your organisation's internal business purposes, for the duration of your account. The Service is provided to you as a hosted, software-as-a-service offering; we do not sell, deliver, or assign any copy of the Software to you, and no title to or ownership of the Software passes to you under this Agreement.
This licence extends to the client-side code the Service delivers to your browser, to the browser-extension client we distribute, and to the open-source command-line wrapper we publish at `/cli`, in each case solely to the extent necessary to run the Service as intended. Any rights not expressly granted in this Agreement are reserved to us and our licensors, and no rights are granted by implication, estoppel, course of dealing, or otherwise.
## 3. Scope of the licence and your Tier
Your licence is scoped to the Tier under which your account operates. The note-count, storage, per-note size, API-token, and rate limits that apply to your Tier are set out in Schedule A and may differ between Tiers. Exceeding, or attempting to exceed, the limits of your Tier — or circumventing the controls that enforce them — is outside the scope of this licence. If you downgrade or your subscription lapses, your licence narrows to the entitlements of the Tier you are then on; continued read-only access to Your Content for up to twelve months after your last payment, and the data-retention rules that follow, are governed by the Terms of Service.
The licence is granted per account. You are responsible for all activity under your account and under any credential issued from it. One account is for one person; sharing a single account among multiple people is outside the scope of this licence, and the Team Tier exists for multi-person use.
## 4. Your Content
As between you and us, you retain all right, title, and interest in Your Content. We claim no ownership of it, we do not sell it, we do not use it to train artificial-intelligence models, and we access it only as needed to operate, secure, back up, and support the Service, or as required by law. Separately from Your Content, we may derive and use Usage Statistics for any lawful business purpose, including to operate, secure, analyse, and improve the Service; as between you and us, Usage Statistics are owned by us. The limited licence you grant us to store and process Your Content for those purposes, and the handling of Your Content after your subscription ends, are described in the Terms of Service and the Privacy Policy. You are solely responsible for the lawfulness of Your Content and for keeping your own copies; the export tools in the Service let you do so at any time. Full-account exports are produced asynchronously by a background worker and delivered as a one-time signed download link emailed to the address on your account; you are responsible for keeping that mailbox secure for the link's validity window. Where you mark a note as client-encrypted — an "Encrypted Note", as defined in Section 1 — we store only the ciphertext you send and cannot read, search, index, or decrypt it; encrypting a note in this way does not otherwise change your or our rights and obligations under this Agreement.
Where you enable Notarization for a note (Dev and Team Tiers), we compute and retain one-way cryptographic hashes of the note and its events, combine them into a daily Merkle root, and commit that root to the public Bitcoin blockchain, so that you can later prove the note existed by a certain time and has not changed since. Those hashes and the Bitcoin anchor are irreversible fingerprints from which Your Content cannot be reconstructed, and they carry none of your identity. Because a Notarization Proof must stay verifiable independently of us, and because each day's proof is a single Merkle tree shared across accounts, the hashes and the anchor are retained as an integrity ledger even after the underlying note is deleted; the note's own content — including any copy we store so a proof can be reproduced — is removed when you delete the note or close your account, as described in the Privacy Policy, leaving only the irreversible fingerprint and the public anchor. The Bitcoin anchor, once written, is public and permanent and cannot be recalled by anyone, including us.
Our undertaking not to sell Your Content, not to share it with third parties for their own purposes, and not to use it to train artificial-intelligence models describes how *we* handle Your Content on our own systems. It does not, and cannot, govern what happens to Your Content once you yourself send it elsewhere — in particular, where you authorise a Connected Application or use the MCP Endpoint to route Your Content to a third party (including a third-party AI or large-language-model provider). That onward transmission is made at your direction and is governed by Section 5 and by the third party's own terms, not by this undertaking.
Where Your Content includes personal data of other people and you use the Service to process it, you act as the controller of that personal data and we act as your processor in respect of it. If you are subject to the General Data Protection Regulation, the UK GDPR, or a comparable law that requires a written processor agreement, a Data Processing Agreement satisfying Article 28(3) of the General Data Protection Regulation is available on request from the contact address in Section 21. Once executed by both parties, that Data Processing Agreement supplements this Agreement, the Terms of Service, and the Privacy Policy, and controls over them to the extent of any conflict with respect to the processing of that personal data; the absence of an executed Data Processing Agreement does not waive any obligation either party owes under applicable data-protection law.
## 5. API access, the MCP Endpoint, Connected Applications, and other machine credentials
On Tiers that include API access, we grant you a licence to use the documented REST API at [/docs](/docs) and the remote MCP Endpoint at `/mcp` in accordance with this Agreement and Schedule A. Machine access to the Service is authenticated by the credentials described in this Section, whether presented directly by you, by a tool you configure, or by a Connected Application you authorise. Each credential is licensed to you on the same terms as the licence in Section 2, and the restrictions in Section 8 apply to each in full.
- **API Tokens.** API access is authenticated with bearer API Tokens you generate from your profile or, for a Team Workspace, from the team's API-tokens page. The number of active tokens, their default and maximum expiry, the per-token rate limits, and the request and payload size limits are set out in Schedule A. Treat every API Token like a password: do not share it, embed it in client-side code you distribute, or commit it to a public repository. Anyone holding a token can act as your account (or, for a team-scoped token, as the workspace) up to the API's rate and capacity limits, and you are responsible for all traffic authenticated by your tokens, whether issued by you, by an integration you authorised, or by a third party who obtained your token.
- **Trial API Tokens.** If you onboard in code mode, we may issue you a single, system-generated Trial API Token, valid for 14 days from issuance and authorised against the same REST API surface as a regular API Token within the rate limits of the Dev Tier. A Trial API Token is provisioned and revoked by us; it is not granted under your Tier's API allowance, it does not carry over to a paid Tier, and it is deleted automatically on expiry. Your responsibility for traffic authenticated by a Trial API Token is the same as for any other API Token.
- **Extension Tokens.** Independent of the Tier-based API-token allowances, every active subscriber — the Personal Tier included — may hold one append-only Extension Token bound to a single note, for use with the Fresh Jots browser extension. An Extension Token may only append to the one note it is bound to: it cannot read, modify, or delete that note, and it cannot reach any other note or endpoint. It is counted and rate-limited separately from your other API Tokens under Schedule A, and it is revoked automatically when your subscription lapses.
- **Inbound-webhook Ingest Tokens.** On Tiers that include API access, you may enable per-note inbound webhook ingestion: each eligible note exposes an unguessable URL of the form `/h/<token>` to which external systems can POST plain-text payloads that we then append to that one note. The unguessable token component **is** the credential — there is no separate header authentication — so anyone in possession of the URL can append to the destination note within Schedule A's payload-size and rate limits. You are responsible for distributing the URL only to senders you authorise, for the content they post, and for rotating the URL (by enabling a new token on the note) if you believe it has been disclosed.
- **The MCP Endpoint and Connected Applications.** On Tiers that include API access, you may connect AI clients, assistants, agents, and other tools to your account (or, for a Team Workspace, to the workspace) through the remote MCP Endpoint at `/mcp` or our OAuth 2.1 authorisation flow. The MCP Endpoint exposes operations to list, read, create, append to, edit, move, and **delete** notes and folders, bounded by the scope of the credential used: a Connected Application authorised by OAuth, or configured with an API Token, can act with the access that credential carries, and a read-only or single-note-scoped token limits it accordingly. Deletions performed through the MCP Endpoint act on your live data and may be irreversible. Authorising a Connected Application, and choosing the scope you grant it, is **your** act and your responsibility: you are responsible for the Connected Application's behaviour, for everything it does under the access you grant, and for granting it no more access than it needs. We do not control, endorse, vet, or guarantee any Connected Application, and we are not responsible for its availability, security, conduct, or the consequences of the access you grant it. You should review a Connected Application's own terms and privacy policy before connecting it, and you may withdraw its access at any time through the OAuth authorisation controls we provide or, for token-based access, by revoking the token.
- **Third-party AI clients and your Content.** When the Connected Application you authorise is, relies on, or forwards Your Content to a third-party artificial-intelligence or large-language-model provider (for example, an AI assistant or coding tool), connecting it causes Your Content to be transmitted out of the Service to that third party. That transmission happens **at your direction and at your own risk.** Once Your Content reaches the third party, what is done with it — including whether it is logged, retained, used to train models, or shared further — is governed by that third party's terms and privacy policy, not by this Agreement and not by our undertaking in Section 4, which binds only our own systems and cannot bind a third party you choose to connect. You are responsible for satisfying yourself that any such transmission is lawful, that you have the right to make it, and that the third party's handling of Your Content is acceptable to you before you connect it; this is especially important if Your Content includes personal data of others, confidential information, or material you are under a duty to protect. We are not responsible for, and disclaim all liability for, the acts, omissions, security, or data practices of any third-party AI provider or other Connected Application you authorise.
- **Team-alert outbound destinations and signing secrets.** A Team Owner or Admin may configure the workspace to deliver overdue-note alerts to an external endpoint (e.g. a chat webhook) and may set a shared signing secret used to HMAC-sign the outbound payload so the receiver can authenticate the request. You are responsible for the endpoint's behaviour, for keeping the signing secret confidential, for ensuring the destination uses TLS, and for any third-party terms applicable to the receiving service. We are not responsible for the availability of, the conduct of, or the consequences of delivery to any third-party endpoint you designate.
- **Revocation.** You may revoke any token, rotate any ingest URL, or withdraw a Connected Application's authorisation from your profile (or the team's settings, for team credentials) at any time. We may also revoke a token or ingest URL, withdraw a Connected Application's access, or revoke all credentials for an account or workspace, on reasonable notice — or immediately where required to protect the Service or other users — if its use threatens the integrity, security, or availability of the Service or appears to circumvent rate, capacity, or billing controls.
- **Changes to the API and the MCP Endpoint.** The REST API, the MCP Endpoint, the OAuth authorisation flow, and the ingestion endpoints are part of the Service and may evolve. The MCP Endpoint and OAuth connection flow are newer, still-evolving parts of the Service, and are offered on an "as is" and "as available" basis; we may change, restrict, or withdraw them, or any operation they expose, including with limited notice where reasonable. If we remove or materially change an endpoint, we will give the notice described in the Terms of Service.
## 6. Team Workspaces
The Team Tier creates a Team Workspace operated under a single licence held by the Team Owner — the account that purchased the subscription. The Owner is the contracting party for the workspace, is responsible for the workspace's compliance with this Agreement and the Terms of Service, and is the party against whom Workspace-level capacity, billing, and audit-log obligations run.
- **Sub-licences to members.** Subject to the seat cap recorded on the Team's subscription, the Owner may invite individual users to join the workspace as Team Admins or Team Members. By inviting a person and by accepting an invitation, both parties agree that the accepted member receives a personal, non-transferable, non-sublicensable sub-licence under this Agreement and the Terms of Service to access the workspace in their assigned role. Each accepted member must hold their own Fresh Jots account, comply with this Agreement in their own right, and use only their own credentials.
- **Roles and capabilities.** Team Owner, Team Admin, and Team Member each have the capabilities described in the in-product documentation at [/team](/team). Team Admins may issue and revoke team-scoped API tokens and read the team audit log; Team Members may read and write team notes and team folders but cannot manage seats, billing, tokens, or the audit log. The Owner and Admins are responsible for assigning appropriate roles.
- **Invitations.** Workspace invitations are issued by email and expire 14 days after they are sent. An individual may hold at most one accepted team membership at any time; accepting a new invitation requires leaving any other team you are currently a member of.
- **Owner responsibility for member conduct.** The Owner is responsible for ensuring that each accepted member complies with this Agreement and the Terms of Service, and for the use of any team-scoped credential issued from the workspace, whether issued by the Owner, an Admin, or used by any member. Where a member's conduct breaches this Agreement, we may revoke that member's access to the workspace, suspend or revoke the workspace's licence, and look to the Owner under Section 17 (Indemnification).
- **Audit log and visibility.** Every team-scope write — to notes, folders, comments, memberships, tokens, and alerts — is recorded in the workspace audit log, including the actor, action, timestamp, and request metadata. Owners and Admins may read the audit log for the retention window set out in Schedule A (currently 90 days). By accepting a workspace invitation, a member acknowledges that their team-scope actions are visible to the Owner and Admins through that log; the log is operational metadata about workspace activity, not personal data of the workspace itself, and is governed by the Privacy Policy.
- **Workspace-wide caps.** The note, storage, API-token, and rate limits of the Team Tier apply across the workspace as a whole, not per member. Members compete for the same workspace pool; allocation between members is the Owner's and Admins' responsibility.
- **End of membership.** A membership ends when the member leaves the workspace, when an Owner or Admin removes them, when the workspace's subscription ends or is downgraded below the relevant seat, or on termination of this Agreement as to the workspace. On end of membership, the member's right to access the workspace stops; their personal account, and any non-team Content they hold, are unaffected.
## 7. Public share links
The Service lets you make an individual note publicly readable through an unguessable share URL. When you enable a share link, you grant us permission to store and serve that note to anyone who has the link, for as long as the link is active. You are solely responsible for what you choose to share and for the consequences of distributing a share URL, including any onward sharing by recipients. You may revoke a share link at any time, after which we will stop serving the note at that URL, though copies others already made or cached are outside our control. We may disable a share link that violates this Agreement, the Terms of Service, or applicable law.
## 8. Restrictions
The licence in this Agreement is conditioned on your compliance with the following restrictions. You will not, and will not permit any third party (including, for a Team Workspace, any Team Admin or Team Member) to:
- copy, reproduce, modify, translate, or create derivative works of the Software or the Service, except for the client-side execution expressly contemplated in Section 2;
- reverse engineer, decompile, disassemble, or otherwise attempt to derive the source code, underlying structure, or algorithms of the Software, except to the limited extent this restriction is prohibited by applicable mandatory law;
- rent, lease, lend, sell, sublicense, assign, distribute, host, or otherwise make the Service available to any third party, or operate it as a service bureau for the benefit of third parties, except for the in-Workspace sub-licences expressly contemplated on the Team Tier (Section 6);
- circumvent, disable, or interfere with any limit, rate cap, billing control, licensing mechanism, authentication, signature verification, or other access control, including the per-Tier limits in Schedule A and the workspace-wide caps in Section 6;
- access the Service by any automated means other than the documented API, the MCP Endpoint, and the inbound-webhook endpoints within their published limits, or scrape, harvest, or bulk-extract content except through your own account's export tools;
- use an Ingest Token or a public share URL as a covert distribution channel for content addressed to the wider public, or in any way that exceeds the per-note rate and size limits in Schedule A;
- probe, scan, or test the vulnerability of the Service, or breach or circumvent any security or authentication measure, without our prior written authorisation;
- use the Service, or any of its components, features, telemetry, or observable behaviour, to build, train, evaluate, or improve a competing product or service, or to extract benchmark or comparative data for the same purpose;
- remove, obscure, or alter any proprietary notice, label, attribution, or signature on or in the Service or in payloads it produces;
- forge, tamper with, alter, or misrepresent a Notarization Proof, or use Notarization to deceive any person about the existence, timing, integrity, or authorship of any content;
- use our trademarks, logos, or brand features except as permitted in Section 10;
- use the Service in violation of applicable law, including export-control, sanctions, data-protection, and intellectual-property law, or to store or transmit content you do not have the right to store or transmit; or
- use the Service in a way that the Terms of Service prohibit under its acceptable-use rules.
Each restriction in this Section is a condition of, and a material term of, the licence; a breach of any of them terminates the licence granted in Section 2 with respect to the conduct in breach, in addition to any other remedy available to us.
## 9. Ownership and reservation of rights
The Service, the Software, and all related intellectual property — including their design, structure, organisation, source and object code, interfaces, documentation, trademarks, logos, and all copies and derivative works — are and remain the exclusive property of us and our licensors, and are protected by copyright, trademark, trade-secret, and other intellectual-property laws. This Agreement grants you only the limited licence expressly described, and does not transfer any ownership interest. Aside from that licence, we reserve all rights in and to the Service and the Software.
## 10. Trademarks
"Fresh Jots", the Fresh Jots logo, and our other names, marks, and brand features are our trademarks. This Agreement does not grant you any right to use them, and you will not use them in a way that is likely to cause confusion, imply endorsement or affiliation, or disparage us or the Service, without our prior written permission. Any goodwill arising from use of our marks inures solely to our benefit.
## 11. Third-party and open-source components
The Service incorporates third-party and open-source software, each licensed under its own terms. Nothing in this Agreement limits, supersedes, or modifies the rights and obligations you may have under those separate licences with respect to those components, and to the extent of any conflict between this Agreement and an open-source licence as applied to a given component, that open-source licence governs for that component. The Fresh Jots command-line client distributed at `/cli` is itself released under its own open-source licence and is licensed to you on those terms, independently of this Agreement. A list of material third-party components and their notices is available on request from the contact address below.
## 12. Feedback
If you choose to send us suggestions, ideas, bug reports, or other feedback about the Service, you grant us a perpetual, irrevocable, worldwide, royalty-free, transferable, and sublicensable licence to use, modify, and otherwise exploit that feedback for any purpose, without any obligation or compensation to you. You are not required to provide feedback, and any feedback you do provide is given voluntarily.
## 13. Updates and changes to the Service
The Service is delivered as software-as-a-service and evolves over time. We may add, change, suspend, or remove features, components, or the Software at any time, and we may release updates that are applied automatically without action by you. We are not obliged to maintain backward compatibility, except as expressly stated for the API in the Terms of Service. We will use reasonable efforts to avoid materially degrading the core note-taking functionality of a paid Tier during its paid term, but the specific features, interfaces, integrations, and ingestion endpoints available may change.
## 14. Term and termination of the licence
This Agreement and the licence it grants take effect when you first accept it and continue for as long as you have an account and comply with this Agreement and the Terms of Service. The licence ends immediately, without notice, if you materially breach this Agreement (including any restriction in Section 8); we may also suspend or terminate the licence as described in the Terms of Service, including for non-payment or account closure. For a Team Workspace, termination of the Owner's account terminates the workspace licence and each member's sub-licence under Section 6, subject to the wind-down process in the Terms of Service. On termination of the licence, your right to access and use the Service stops, although the Terms of Service govern the read-only access to, and export of, Your Content for a limited period after a paid subscription ends. The provisions that by their nature should survive — including Sections 4, 5 (your responsibility for credentials issued from your account and for Content you direct to any Connected Application or third party), 6 (Owner responsibility), 8, 9, 10, 12, and 15 through 20 — survive termination.
## 15. Disclaimer of warranties
To the maximum extent permitted by law, the Service and the Software are provided "as is" and "as available", without warranty of any kind, whether express, implied, or statutory, including any implied warranties of merchantability, fitness for a particular purpose, title, accuracy, and non-infringement. We do not warrant that the Service will be uninterrupted, error-free, secure, or free of harmful components, or that it will meet your requirements, and you use it at your own risk. We do not warrant that overdue-note alerts, inbound webhook ingestions, outbound webhook deliveries, MCP Endpoint operations, or any other time-sensitive feature will be delivered or executed without delay, error, or omission, and you must not rely on such features as the sole safety net for any life-safety, financial, or legally significant deadline. Features we identify as new, experimental, or evolving — including the MCP Endpoint and the OAuth connection flow — are provided strictly "as is", may be incomplete or change without notice, and carry no warranty of any kind. We give no warranty in respect of any Connected Application or third-party AI provider you authorise, which are outside our control. You are responsible for maintaining your own backups of Your Content. For any Encrypted Note, because we never receive or hold your key, we cannot read, decrypt, recover, reset, reveal, or reconstruct its contents or your key; if you lose your key, the contents of that note are permanently and irretrievably lost, and this is an inherent consequence of the encryption you control, not a defect in or failure of the Service. For Notarization and any Notarization Proof (Dev and Team Tiers), we give no warranty that a proof will be generated, will anchor to or confirm on the Bitcoin blockchain, will do so within any particular time, will remain retrievable, will verify with any given tool, or will be accepted as evidence by any court, regulator, counterparty, or other person; anchoring and confirmation are performed by the public OpenTimestamps calendar network and the Bitcoin network, which we neither operate nor control. A Notarization Proof attests only that content was not altered after we received and hashed it — it does not establish the truth, accuracy, lawfulness, authorship, or authenticity of the content, or that the content was not altered before it reached us. Notarization is not legal advice and is not a substitute for your own records; you rely on any Notarization Proof at your own risk, and we have no obligation to preserve, reproduce, defend, interpret, or testify to any proof. Nothing in this Section excludes or limits any warranty or right that cannot be excluded or limited under mandatory law applicable to you, including consumer-protection law.
## 16. Limitation of liability
The limitation of liability, including the exclusion of indirect, incidental, special, consequential, and similar damages and the monetary cap on our aggregate liability, is set out in the Terms of Service and applies to this Agreement and to your use of the Service as if restated here. Nothing in this Agreement or the Terms of Service excludes or limits liability that cannot be excluded or limited under mandatory law, and your mandatory consumer-protection rights are unaffected.
## 17. Indemnification
You will defend, indemnify, and hold us and our officers, employees, and agents harmless from and against any claims, damages, liabilities, costs, and expenses (including reasonable legal fees) arising out of or related to your breach of this Agreement, your misuse of the Service, Your Content, your use of API Tokens, Trial API Tokens, Extension Tokens, Ingest Tokens, the MCP Endpoint, or share links, your authorisation of any Connected Application and the transmission of Your Content to any third party you direct, the conduct of any Team Member or Team Admin in a Team Workspace you own, or your violation of law or of the rights of a third party, on the terms and subject to the conditions set out in the Terms of Service.
## 18. Equitable remedies
You acknowledge that a breach or threatened breach of the licence restrictions in Section 8, of the ownership and trademark provisions in Sections 9 and 10, or of the confidentiality of the Software, would cause us irreparable harm for which monetary damages would be an inadequate remedy. In such a case we are entitled to seek injunctive or other equitable relief to enforce this Agreement, in addition to any other remedy available at law, without the need to post a bond or prove actual damages, to the extent permitted by applicable law.
## 19. Changes to this Agreement
We may update this Agreement from time to time. Each version is identified by a date shown at the top of this page, and past versions remain available at [/eula/versions](/eula/versions) for your reference. If a change is material — for example, a change to the licence grant, to the restrictions in Section 8, to the Team Workspace rules in Section 6, or to a term that materially reduces the rights granted to you — we will notify you by email or through the Service at least 14 days before it takes effect, unless a shorter period is needed for legal or security reasons, and we will ask you to accept the updated Agreement. On the effective date of an updated Agreement, the first browser request you make to the Service after signing in will route you through a one-click re-acceptance gate before you can continue, and your acceptance (including the version accepted, the time, and request metadata) is recorded on your account for audit. Non-material changes (typographical fixes, clarifications, and reorganisation that does not change rights or obligations) take effect on publication. Your continued use of the Service after the effective date of an updated Agreement means you accept it; if you do not agree, you may stop using the Service and close your account before the new version takes effect.
## 20. Governing law, entire agreement, and general
This Agreement is governed by the law of North Macedonia, with the courts of Skopje having exclusive venue, and the governing-law, dispute-resolution, and consumer-forum provisions of the Terms of Service apply to it. In particular, before either party begins any formal proceeding arising out of this Agreement or the Service, the party raising the dispute must first give written notice and the parties must attempt to resolve the matter amicably and in good faith for 60 days, with optional non-binding mediation thereafter, as set out in the Terms of Service; that required first step does not apply to, and does not delay, an application for urgent injunctive or other equitable relief, a claim to protect intellectual property, a claim that may be brought in a small-claims court, or any right you cannot waive under mandatory consumer law, and it does not remove your access to a court. This Agreement, together with the Terms of Service, the Privacy Policy, and Schedule A, forms the entire agreement between you and us regarding the licence to use the Service and supersedes any prior agreement on that subject. In case of conflict, the order of precedence in the Terms of Service applies, and this Agreement controls for matters of licence grant, permitted use, and restrictions. If any provision of this Agreement is held unenforceable, the remaining provisions remain in effect and the unenforceable provision will be modified to the minimum extent necessary to be enforceable while preserving its intent. Our failure to enforce a provision is not a waiver of it. You may not assign this Agreement without our written consent; we may assign it in connection with a merger, acquisition, reorganisation, or sale of all or substantially all of our assets. For a Team Workspace, the Owner may not assign the workspace licence except through an ownership-transfer flow we provide; sub-licences to members are personal to each member and may not be assigned. Section headings are for convenience only, and the English-language version of this Agreement controls.
## 21. Contact
Questions about this Agreement may be sent to [support@freshjots.com](mailto:support@freshjots.com), or [arsphy@yahoo.com](mailto:arsphy@yahoo.com). The service limits referenced throughout this Agreement are published, and kept current, at [/limits](/limits).