Legal
Terms of Service
These Terms govern the Tethra website and distributed software. The Apache License 2.0 separately governs use, modification, and distribution of Tethra's licensed source code.
1. Acceptance of Terms
By accessing usetethra.com, downloading a Tethra build, or using the Tethra desktop application or CLI (collectively, the "Service"), you agree to these Terms of Service ("Terms") and acknowledge the Privacy Policy. These Terms are an agreement between you and Tethra ("Tethra," "we," "us," or "our"), based in Atlanta, Georgia, United States.
If you do not agree, do not use the website or our distributed builds. Your rights to source code already received under the Apache License 2.0 are governed by that license and are not revoked merely because you stop using the Service.
2. Eligibility and authority
You must be at least 18 years old, or the age of legal majority where you live, to accept these Terms. If you use Tethra for an employer, client, or other organization, you represent that you are authorized to bind that organization, and "you" includes that organization.
3. Description of the Service
Tethra is local-first developer software that can help users:
- Create and manage a locally stored credential vault;
- Associate API credentials, providers, and projects;
- Scan selected repositories, configuration, env files, and git history for possible credential exposure;
- Observe sanitized API-request metadata through a local gateway or process runner;
- Review provider metadata, permissions, usage, cost estimates, pricing, budgets, and activity where supported;
- Configure alerts, documentation watches, webhooks, destinations, synchronization plans, backups, temporary access, and credential rotation workflows.
Feature availability varies by platform, provider, provider permission, configuration, and software version. A listed provider or capability does not imply endorsement, guaranteed compatibility, or continued availability.
3.1 Tethra for Teams and waitlist
Tethra for Teams is a coming-soon concept, not a generally available product or an offer to sell. Joining the waitlist does not guarantee access, timing, features, pricing, support, compatibility, or a commercial relationship, and creates no purchase or payment obligation. We may change, delay, or discontinue the planned offering.
Every waitlist field—name, email address, phone number, and company—is optional. By submitting, you ask us to record the information you choose to provide and represent that you may provide it. If you provide an email address or phone number, you request personal follow-up about Tethra for Teams. The form does not authorize automated marketing calls or texts; any campaign requiring separate consent will use a separate consent request. The Privacy Policy explains processing, retention, and deletion.
4. Open-source software license
Tethra source code identified as licensed under the Apache License, Version 2.0 is provided under that license. The Apache License governs your rights to use, reproduce, modify, and distribute that code and its covered derivative works, including its notice, attribution, patent, and warranty terms.
These Terms do not reduce rights granted by an applicable open-source license. If these Terms conflict with the Apache License regarding licensed source code, the Apache License controls for that code. Separate third-party components may have their own licenses, which you must follow.
5. No Tethra accounts, subscriptions, or payment processing
The current Service does not require a Tethra account, charge a subscription, process payments, or offer paid cloud storage. There is therefore no billing, automatic renewal, trial, payout, or refund program. Any future paid offering will be presented with separate pricing and applicable commercial terms before a charge. Fees charged by API providers, hosting providers, destination services, network operators, or other third parties remain your responsibility.
7. Vault, passwords, local data, and backups
You are responsible for your master password, device security, operating-system account, full-disk encryption, local data directory, exports, and backups. Tethra does not operate a password-recovery service and cannot retrieve a forgotten master password or decrypt a vault for you.
Credential values are designed to be encrypted locally, while some operational metadata must remain unencrypted in the local database for product and locked-state workflows. Filesystem paths, project and credential names, provider relationships, timestamps, usage/activity records, and other metadata may therefore be visible to someone who can access your device or data directory. Review the Privacy Policy and security documentation before deciding what to store.
Backups may preserve older credentials or passwords and may not be automatically deleted when you remove a current record. Store backups securely, test restoration with synthetic data where practical, and retain independent recovery procedures for critical provider accounts. Uninstalling the app may leave the data directory, CLI, gateway service, exports, or backups in place.
8. Provider operations and outbound network actions
Some features send requests directly from your device to a provider, documentation site, webhook, secret destination, API origin, or other endpoint you configure. Depending on the operation, a request may include an API credential, administrative credential, account or project identifier, secret value, provider-specific parameters, or API request data necessary to perform the action.
Validation does not prove a key is safe, properly scoped, owned by you, or accepted for every API. Metadata and usage information may be incomplete or delayed. Revocation and rotation can be irreversible, can break production systems, can produce downtime, and may not be recoverable through Tethra. Dry-run or preview output is informational and cannot model every dependency, race, permission, provider behavior, or external change.
You authorize these outbound connections when you initiate or enable the corresponding feature. Tethra does not operate an intermediary provider proxy and is not responsible for third-party receipt, processing, cost, rate limits, suspension, compromise, or retention.
9. Local gateway and runtime observability
Tethra's gateway is intended to bind to loopback and forward configured API traffic from local applications. Its observability features are intended to retain sanitized metadata rather than authorization headers, bodies, raw query secrets, or credential values. Nevertheless, software defects, unusual protocols, unsafe configuration, malicious local processes, provider changes, or sensitive data embedded in paths could cause unintended collection or disclosure.
You are responsible for reviewing routes and environment-file changes, restricting local access, testing with non-production credentials, and confirming that interception or monitoring is permitted. Do not expose the gateway to an untrusted network. Locking the vault does not necessarily stop an independently running gateway; use the gateway controls to stop or uninstall it when required.
10. Product analytics and privacy
Limited measurement analytics is on by default for U.S. users and opt-in elsewhere, subject to prior choices and Global Privacy Control. When enabled, Tethra sends only finite allowlisted events, broad screen or page categories, and numeric totals of locally managed projects and credential records. It is not intended to send vault contents, secrets, free-form fields, project or credential names, file paths, provider names, or request content. You may turn it off at any time without losing core functionality.
The Privacy Policy describes identifiers, event categories, hosting data, third-party processing, retention, and rights. You agree not to use analytics debugging, modification, or instrumentation to insert another person's personal information or confidential data into Tethra analytics events.
11. Acceptable use
You may not use the Service to:
- Access, scan, intercept, monitor, test, copy, modify, disable, revoke, or rotate a credential, repository, device, account, API, or system without authorization;
- Commit credential theft, unauthorized access, fraud, surveillance, harassment, extortion, data exfiltration, malware delivery, or another unlawful act;
- Bypass access controls, usage limits, rate limits, security measures, or provider restrictions;
- Disrupt or burden Tethra hosting, a provider, a destination, or another person's systems;
- Use webhooks, API requests, notifications, or integrations to send spam, unlawful content, or harmful payloads;
- Misrepresent affiliation with Tethra or use Tethra marks to imply endorsement;
- Publish real credentials, private source code, personal information, or confidential logs in issues or test materials.
Security research involving systems you own or have written authorization to test is permitted subject to law, provider rules, applicable open-source licenses, and responsible disclosure. This clause does not restrict rights that applicable law or an open-source license expressly protects.
12. Third-party services, data, and terms
Tethra can interoperate with third-party providers, documentation, repositories, webhooks, destinations, package managers, source hosts, and APIs. Those services are not controlled by Tethra. Their terms, privacy policies, licenses, acceptable-use rules, rate limits, data-location rules, and charges apply to your use.
Provider names, pricing, permissions, endpoints, manifests, documentation, and metadata may change without notice or contain errors. Tethra is not endorsed by or affiliated with a third party merely because an integration or link appears. You must independently verify current provider documentation and operational impact.
13. Open-source contributions and feedback
Contributions submitted to a Tethra repository are governed by the repository's license, contribution files, and any contributor agreement presented at submission. Unless clearly stated otherwise, you represent that you have the right to submit the contribution and license it under the repository's applicable Apache 2.0 terms.
Do not submit employer-confidential code, third-party code without compatible rights, real secrets, personal data, or material subject to restrictions you cannot satisfy. General product feedback may be used without restriction or compensation, but this does not grant us ownership of your confidential information or separately licensed code.
14. Intellectual property and marks
Open-source code remains subject to its applicable license. Tethra and its contributors retain rights not granted under those licenses, including rights in names, logos, trademarks, website presentation, and separately identified content. The Apache License does not grant permission to use trade names, trademarks, service marks, or product names except for reasonable and customary description of origin and reproduction of required notices.
You retain rights in original data and configuration you create. Processing local information through Tethra does not transfer ownership of it to us. You are responsible for ensuring you have rights to content and data you process.
15. Availability, updates, and changes
We may update, patch, redesign, suspend, or discontinue the website, distributed builds, integrations, or features at any time. Open-source forks may continue independently under their licenses. We do not promise a maintenance period, support level, compatibility window, provider integration, data migration, or uninterrupted hosting.
Updates may change database schemas, behavior, security controls, provider calls, or system requirements. Back up data, review release notes and source changes, and test in a non-production environment before relying on an update.
16. Security-tool limitations and no compliance guarantee
The current macOS alpha is for Apple Silicon, signed with an Apple Developer ID, and notarized by Apple. The Windows x64 alpha is currently unsigned and may trigger Microsoft SmartScreen. Signing and notarization do not guarantee that software is free of defects or suitable for your use. Verify the published checksum, review the source and release notes, and evaluate the build in a non-production environment before entrusting it with sensitive credentials.
Tethra can miss exposed credentials, report false positives, misattribute activity, estimate usage or cost incorrectly, rely on stale provider data, fail to observe traffic, or fail during synchronization or rotation. Detection is not proof of compromise, and the absence of a finding is not proof of safety.
Tethra is not a substitute for a managed secrets platform, identity and access management, provider audit logs, endpoint protection, code review, penetration testing, incident response, legal advice, regulatory assessment, or an organization's security program. Use of Tethra does not by itself establish compliance with SOC 2, ISO 27001, PCI DSS, HIPAA, GDPR, CCPA, NIST, or any other framework or law.
17. Disclaimers
To the maximum extent permitted by law, the Service and distributed builds are provided "as is" and "as available," with all faults and without warranties of any kind, express, implied, statutory, or otherwise, including warranties of merchantability, fitness for a particular purpose, title, non-infringement, accuracy, quiet enjoyment, security, and availability. Tethra does not warrant that the Service will detect every secret, remain error-free, protect against every attack, preserve data, work with every provider, prevent cost or downtime, or meet your requirements.
The warranty disclaimer in the Apache License 2.0 also applies to code provided under that license. Some jurisdictions do not allow certain disclaimers, so some of the above may not apply to you. Mandatory consumer rights remain unaffected.
18. Limitation of liability
To the maximum extent permitted by law, Tethra and its contributors, maintainers, licensors, and agents will not be liable for indirect, incidental, special, exemplary, consequential, or punitive damages, or for lost profits, revenue, business, goodwill, credentials, data, API access, production availability, or security, arising from or related to the Service, even if advised of the possibility.
To the maximum extent permitted by law, aggregate liability for all claims relating to the Service will not exceed the greater of one hundred US dollars (US $100) or the amount you paid directly to Tethra for the Service during the twelve months before the event giving rise to liability.
These limits do not apply to liability that applicable law does not permit us to exclude or limit. The Apache License's limitation provisions separately apply to Apache-licensed code.
19. Indemnification
To the extent permitted by law, you will defend, indemnify, and hold harmless Tethra and its contributors, maintainers, licensors, and agents from third-party claims, damages, liabilities, penalties, judgments, and reasonable costs arising from your unauthorized or unlawful use of the Service; your credentials, data, configurations, provider actions, scans, monitoring, destinations, or gateway traffic; your violation of these Terms, law, contract, or third-party rights; or content you submit publicly. This obligation does not apply to the extent a claim results from our own willful misconduct or where prohibited by law.
20. Export controls and sanctions
You must comply with applicable United States and international export-control, import, and sanctions laws. You may not use, export, re-export, transfer, or provide the Service in violation of those laws, including to prohibited persons, entities, destinations, or prohibited end uses. You represent that you are not barred from receiving the Service under applicable law.
21. Suspension and termination
You may stop using the Service at any time. We may restrict access to Tethra-operated hosting or downloads for abuse, security risk, legal requirements, or violation of these Terms. Termination does not automatically delete local vaults, backups, installed CLI files, or gateway services, and it does not terminate rights to source code already granted under an applicable open-source license.
Provisions that by nature should survive remain effective, including license terms, intellectual property, disclaimers, liability limits, indemnification, dispute provisions, and general terms.
22. Governing law and disputes
Before filing a formal claim, you agree to contact us and attempt in good faith to resolve the dispute informally for 30 days. These Terms are governed by the laws of the State of Georgia, United States, without regard to conflict-of-laws rules. Subject to mandatory consumer law, state and federal courts located in Fulton County, Georgia will have exclusive jurisdiction.
If you are a consumer outside the United States, this section does not deprive you of non-waivable protections or a right to bring a claim in your home courts where applicable law provides it. These Terms do not require arbitration and do not waive any right that cannot lawfully be waived.
23. Changes to these Terms
We may revise these Terms by posting an updated version and changing the "Last updated" date. Material changes apply prospectively after the date stated or any notice period required by law. Continued use of Tethra-operated services after revised Terms take effect constitutes acceptance; if you disagree, stop using those services. Open-source license rights already granted remain governed by the applicable license.
24. General terms
These Terms, the Privacy Policy, and applicable open-source licenses are the complete agreement concerning their subject matter and supersede prior statements. If a provision is unenforceable, it will be limited to the minimum extent necessary and the remainder will continue. Failure to enforce a provision is not a waiver. You may not assign these Terms without our consent; we may assign them in connection with a reorganization, asset transfer, or operation of the Service. No partnership, employment, fiduciary, franchise, or agency relationship is created.
We are not liable for delay or failure caused by events beyond reasonable control, including disasters, war, labor disputes, internet or power outages, provider failures, government action, or supply-chain incidents. Headings are for convenience. "Including" means "including without limitation." Electronic notices and records satisfy written-form requirements where lawful.
25. Contact
Questions about these Terms may be sent to:
Email: unleeshedstudios@gmail.com
