diff --git a/docs/specs/hosted.md b/docs/specs/hosted.md
index 9d52e4b1c..1eceeca64 100644
--- a/docs/specs/hosted.md
+++ b/docs/specs/hosted.md
@@ -51,6 +51,16 @@ Source of truth: `hosted/server/providers.js`; `authPolicy` / `providerBindings`
Source of truth: `App` in `hosted/src/App.tsx`; `restoreTheme` in `hosted/src/main.tsx`.
+## Terms acceptance
+
+Continuing past the sign-in notice is how an account agrees to the Hosted terms (`website/src/pages/Terms.tsx` -> "The service").
+
+- **Must show the notice beside every sign-in method**, naming `TERMS_VERSION` and linking the terms and privacy policy without leaving the page.
+- **`TERMS_VERSION` is the policy pages' revision date** and changes with every terms revision.
+- **Must record each account's first acceptance of each version**, after a sign-in that continued past the notice,, current version only.
+
+Source of truth: `termsRoutes` in `hosted/server/terms.ts`; `TERMS_VERSION` in `hosted/server/policy-constants.ts`.
+
## Managed voice
An admin-only test slice: Dormouse desktop exchanges a pasted voice token for ElevenLabs speech. The account Worker serves the token routes; the voice Worker serves speak.
@@ -81,7 +91,7 @@ Errors are JSON `{ message }`. Cookie routes answer 401 without a login and 403
**Must delete ElevenLabs speech history, which keeps each generation's text, from the production voice Worker only**: one pass shortly after each successful speak, and a Cron Trigger every 5 minutes for what that missed. No retention bound is guaranteed (rationale).
-- **Must use an ElevenLabs account dedicated to Dormouse voice.** A sweep deletes the whole account's history.
+- **Must use an ElevenLabs service account dedicated to Dormouse voice, with history access isolated from other workspace usage.** A sweep deletes every history item visible to its key (rationale).
- **Never touch the database or any binding but `ELEVENLABS_API_KEY` in a sweep**, so an idle deployment lets Postgres suspend. Without the key nothing runs; development and previews never sweep.
- **Must fail the cron invocation when its pass cannot list or any delete fails; the after-speech pass only logs** (rationale).
diff --git a/docs/specs/hosted.rationale.md b/docs/specs/hosted.rationale.md
index e9b641dac..576606902 100644
--- a/docs/specs/hosted.rationale.md
+++ b/docs/specs/hosted.rationale.md
@@ -4,8 +4,8 @@
History sweep (sources checked 2026-09-22):
-- ElevenLabs stores every text-to-speech generation, including its text, in the account's speech history. Turning that off per request (`enable_logging=false`, zero-retention mode) is available to enterprise accounts only, so deletion is the remaining control. The history API filters only by voice or model, not by "items this Worker created", so a sweep of a shared account would delete unrelated history.
-- Deleting the item straight after the speech call fails: the operator observed (2026-09) that the history item does not exist yet. The after-speech pass therefore waits about 10 s, and the cron pass catches anything that was still not listed. Spoken text usually leaves ElevenLabs about 10 s after the call, otherwise within the 5-minute interval plus ElevenLabs' indexing delay.
+- ElevenLabs stores every text-to-speech generation, including its text, in the account's speech history. Turning that off per request (`enable_logging=false`, zero-retention mode) is available to enterprise accounts only, so deletion is the remaining control. The sweep has no per-application filter, so every history item visible to its key is eligible for deletion. On 2026-10-07 the operator confirmed testing that the dedicated Dormouse service account isolates its history from other usage in the same workspace. This is operator verification, not a claim that every service-account sharing configuration has the same isolation.
+- Deleting the item straight after the speech call fails: the operator observed (2026-09) that the history item does not exist yet. The after-speech pass therefore waits about 10 s, and the cron pass catches anything that was still not listed. Successful deletion removes visible speech history; ElevenLabs' retention documentation allows residual debugging or moderation records and backups, so these schedules do not establish when every provider copy disappears.
- `ctx.waitUntil()` extends an HTTP invocation for at most 30 s after the response is sent (https://developers.cloudflare.com/workers/runtime-apis/context/), so a 10 s wait plus one short pass has margin. Every 5 minutes is the backstop because the after-speech pass handles the common case.
- Workers limits (https://developers.cloudflare.com/workers/platform/limits/, checked 2026-09-22): 50 subrequests per invocation on Free, and six connections may await response headers at once. The per-pass caps fit the Free limit, so the sweep does not depend on the account's plan; a test pins the arithmetic.
- Endpoints: https://elevenlabs.io/docs/api-reference/history/list and https://elevenlabs.io/docs/api-reference/history/delete.
diff --git a/docs/specs/pricing.md b/docs/specs/pricing.md
index 8af6c39cd..6fda2f97c 100644
--- a/docs/specs/pricing.md
+++ b/docs/specs/pricing.md
@@ -11,7 +11,7 @@
**Settings is the front door.** The spoken-alarm row's managed-voice link and the playground tutorial land on `/hosted#voice`, and the plan cards sit within one screen of that anchor. `#remote-control` and `#voice` keep resolving as section ids.
-**Content, in order:** the plan cards, directly under the title and anchored `#pricing`; what a member gets, as prose; "Self-hosting stays free"; and a short FAQ — refunds and cancellation, the founding lock, who appears in the founders row, what happens if Hosted shuts down, and that team pricing goes by email to `teams@dormouse.sh`.
+**Content, in order:** the plan cards, directly under the title and anchored `#pricing`; what a member gets, as prose; "Self-hosting stays free"; and a short FAQ — refunds and cancellation, the founding lock, who appears in the founders row, what happens if Hosted shuts down, and that team pricing goes by email to `support@dormouse.sh`.
**Prices, inclusions, and the FAQ are prerendered text**, and the page emits `Product` / `Offer` JSON-LD carrying one `Offer` per paid plan at its current price, so an assistant fetching the page can quote it. **Offers stay `PreOrder` while checkout is unbuilt.**
@@ -46,7 +46,7 @@ Seats left in the open cohort and the founders row load after hydration from one
### Published prices
-Prices in USD, and the merchant of record adds or includes tax by jurisdiction.
+Prices in USD; DiffPlug adds or includes applicable tax by jurisdiction.
| Plan | Price | Cadence |
|---|---|---|
@@ -78,8 +78,8 @@ Team and enterprise tiers are never sold through this page. A free hosted tier i
What each plan grants once checkout can sell it; [Published prices](#published-prices) is the ladder as the page prints it today.
- **Founding grants the Individual plan plus a founding badge**; monthly and yearly grant the plan alone.
-- **A founding lock survives every later price change** and ends only when the subscription lapses; a lapsed founder re-subscribes at list.
-- **Cohorts close by count, never by date.** The count is completed purchases at the billing provider; a refund returns the seat to its cohort.
+- **Must lock the founding base yearly price in USD while the subscription remains active**, excluding applicable taxes; a lapsed founder re-subscribes at list. **Must preserve the lock through billing-provider migrations and failures caused by DiffPlug**, allowing payment restoration.
+- **Cohorts close by count, never by date.** The count is completed purchases at the billing provider; a full refund or finally reversed payment returns the seat to its cohort.
- **When a cohort closes the price rises one step and the counter resets to 100.**
- **Founding closes only when the ladder reaches list.** Founding means bought at launch pricing; the hosted Relay shipping does not close it.
- **Checkout honors the price it opened at.** Concurrent checkouts may oversell a cohort by a few seats; the overage is the customer's, and the next cohort still opens at a full 100.
@@ -102,19 +102,19 @@ What each plan grants once checkout can sell it; [Published prices](#published-p
### Checkout and entitlement
-- **Stripe Managed Payments runs checkout, subscriptions, and the customer portal as merchant of record, through `@pgstencil/stripe`**, so tax is Stripe's. Dormouse never stores card data. A founding lock is a per-cohort Price; cohort counts come from the billing provider's completed subscriptions.
+- **Must use Stripe Billing, Stripe-hosted Checkout, and its customer portal through `@pgstencil/stripe`; DiffPlug is the seller and merchant of record**, responsible for refunds and applicable tax registration, collection, filing, and remittance. **Never receive or store full card numbers in Dormouse.** A founding lock is a per-cohort Price; cohort counts come from the billing provider's completed subscriptions.
- **Checkout starts from a Hosted account**: a buy button lands on the account origin, which asks for sign-in first, so the subscription belongs to an account from its first event.
- **Founding checkout offers the founders-row opt-in, unticked**; the account can withdraw it at any time.
- **The success page asks the four Van Westendorp questions**, optional and unsent until answered: too expensive to consider, too cheap to trust, expensive but would consider, a bargain. Their answers inform later list changes.
- **The entitlement is the account's subscription, read on the server on every voice and Relay request.** No licence, no offline verification, and no grace past what the subscription grants; a lapsed member's voices fall back to the system voice and its Burrows to `not-entitled`.
- **A desktop signs in from Settings by device code**, the flow Burrow enrollment already runs (`docs/specs/hosted.md` -> "Burrow enrollment"). The approval mints a desktop credential the host keeps and never hands a webview. Sign-in is the only account surface in the free client.
-- **One account covers every machine the member uses.** No device count, no seat count, no activation limit.
-- **A refund or chargeback ends the subscription**, so the next request is refused, and the seat returns to its cohort.
+- **Must license one individual, including work use, without a per-device charge.** **Must disclose material enrollment and usage limits before purchase**, including the managed Relay's enrollment cap (`docs/specs/hosted.md` -> "Burrow enrollment").
+- **A full refund or a finally reversed payment ends the subscription**, so the next request is refused. A partial refund or billing correction never ends it, and an open dispute only suspends it ("Paid-launch requirements").
### Managed voice
- **Dormouse operates the endpoint and holds the vendor key** (ElevenLabs). A request carries the desktop credential, a voice id, and the text; the response is audio.
-- **What leaves the machine is exactly the sanitized spoken label and the voice id** — the `toSpokenText` output in `lib/src/lib/alert-speech.ts`, never terminal content, never a notification body, never a Session id. **Disclose this in the enable flow before the first request**, honoring the promise the Hosted page makes.
+- **Must send only the shortened displayed label, voice id, and authentication credential in the voice request**, never the terminal screen or output stream, notification body, or Session id. **Must disclose before enabling managed voice that labels can come from program-supplied titles, command labels, or directory names and that secret filtering is heuristic**, not a guarantee of confidentiality. Connection metadata remains visible to the serving infrastructure.
- **Cache clips by voice and text on the client** and regenerate only when the label changes; a cache hit makes no request. **Fair use is a daily request cap per member**; past it, the system voice speaks.
- **The system voice is the fallback**, for offline, unentitled, endpoint error, or cap: same delivery rules, same cut-off on attend, never silence because the service failed. Delivery identity, queueing, and cut-off stay owned by `docs/specs/alert.md` -> "Spoken alarms".
- **One voice per Pane.** The member default applies everywhere; a per-Pane override is persisted with the pane's settings and follows the Session through minimize and restore. Doors and headers show nothing new.
@@ -123,11 +123,31 @@ What each plan grants once checkout can sell it; [Published prices](#published-p
### Renewal, cancellation, refund
- **Every plan auto-renews; cancel any time; access runs to period end.**
-- **30-day refund on every plan.** A refund revokes.
+- **Must offer a full refund within 30 days of the first Hosted payment or any yearly renewal**, including collected tax; monthly renewals, plan changes, and resubscriptions do not restart this voluntary first-payment guarantee. **Must preserve mandatory legal remedies.** A full refund revokes.
- **A failed founding renewal gets 30 days of grace before the lock is lost.**
- **A subscription is personal and non-transferable.**
- **No trial**: the 30-day refund is the trial.
+### Paid-launch requirements
+
+Part of **hosted-sales**; these remain unimplemented launch gates, not claims about the current account service.
+
+EEA/UK representative appointment is excluded from the internal release gate by operator decision; applicable legal obligations remain unchanged (rationale).
+
+- **Must obtain affirmative agreement to versioned terms and express consent to automatic renewal before charging**, disclosing price, taxes, interval, refund conditions, cancellation, and material limits beside the purchase action; retain the accepted version, offered limits, and consent evidence and send a durable confirmation.
+- **Must provide direct online cancellation and a support cancellation path when account access is lost.** **Must cancel future renewals as part of account closure**, explaining remaining access and refund eligibility before completing closure; verification cannot require account recovery.
+- **Must send jurisdiction-required renewal, annual, and price-change notices with cancellation instructions.** For California consumers, annual-term renewal notices are 15–45 days before renewal and fee-change notices 7–30 days before effectiveness; annual reminders also apply to monthly plans (rationale).
+- **Must route subscription notices to the maintained billing email**, including provider-only accounts without a sign-in email; use the account contact email for other notices, or show them at sign-in when none exists. **Must record notice delivery or presentation before starting a notice period**, and provide any additional legally required notice or consent process.
+- **Never end a subscription solely for a partial refund or billing correction.** **Must distinguish payment-dispute suspension from termination**: notify the customer, restore remaining access and the prior founding price if suspension was mistaken or payment is restored, and preserve refund and dispute rights; final reversal may end the affected access and renewals.
+- **Must refund unused prepaid service, including corresponding collected tax, on permanent discontinuation or termination unrelated to customer breach**, and offer the same remedy for a material service reduction or rejected material terms change during a prepaid term. **Must give at least 30 days' advance notice of discontinuation, material reductions, or material terms changes**, except urgent legal or security requirements; no retroactive terms changes for disputes.
+- **Must verify the permitted sales territories and tax setup before accepting payment**, and confirm refund, cancellation, failed-payment, and founder-lock behavior against the published offer. Stripe Billing does not transfer the seller's tax obligations.
+- **Must support worldwide sales only where lawful, including EEA and UK consumer rights**: disclose the statutory withdrawal right and model form before purchase and in the confirmation, accept an unambiguous notice without account recovery, and refund withdrawal payments within 14 days without a use deduction or waiver for immediate access. The voluntary guarantee is additional (rationale).
+- **Must provide a prominent online withdrawal function on the account billing page throughout the statutory withdrawal period**, distinct from cancelling renewal; allow the consumer to identify the contract, confirm submission, and receive a durable acknowledgement with the statement and its date and time. **Must disclose its location before purchase and in the confirmation** (rationale).
+- **Must complete the EEA and UK provider privacy arrangements before launch**: execute applicable processor agreements, document provider transfer safeguards and assessments, and publish the applicable contacts and means to obtain the safeguards. **Never claim a transfer certification, contract, or representative that has not been verified** (rationale).
+- **Must recheck ElevenLabs' training opt-out or contractual no-training protection and the applicable processing agreement before enabling paid voices**, and keep the public disclosure consistent with the verified practice. History deletion alone is not evidence of either protection (rationale).
+- **Must obtain acceptance of the managed-voice customer provisions before granting paid voice access**, archive the incorporated provider requirements with the accepted terms, preserve mandatory consumer rights, and relay relevant provider notices. **Must apply the terms' age and government-use restrictions to managed voices** and verify the permitted voice selection. **Must obtain ElevenLabs' written approval before marketing that names it**; the Terms and Privacy policy name it because the provider requirements and disclosure law need them to. Provider requirement changes follow the published notice, renewed-agreement, service-reduction, and refund process (rationale).
+- **Must complete the privacy notice from verified practices before paid launch**: purposes and applicable legal bases, retention periods or criteria, survey linkage, provider roles, and applicable international-transfer safeguards; describe unshipped practices conditionally. **Must archive previous policies and record actual publication and applicability dates.** **Must apply the replacement terms to new accounts on acceptance and to existing accounts on the notified date at least 30 days after notice**, unless expressly accepted sooner; obtain renewed agreement where required, preserve previous terms until then, and never backdate replacement to the revision date (rationale).
+
### Open questions
- A free hosted tier, no card. It is the only way a stock binary can try Pocket, since the shipped bundle reaches only `*.dormouse.sh` (`docs/specs/relay.md` -> "Relay origin").
diff --git a/docs/specs/pricing.rationale.md b/docs/specs/pricing.rationale.md
new file mode 100644
index 000000000..9b41f6854
--- /dev/null
+++ b/docs/specs/pricing.rationale.md
@@ -0,0 +1,15 @@
+# Pricing rationale
+
+## Paid-launch requirements
+
+- The September 29 account terms promised reasonable advance notice of material changes. The October 8 revision adds a liability cap, business indemnity, and forum clause, so publication is distinguished from acceptance and the notified transition for existing accounts. Its 30-day transition is the chosen contractual process, not a claim that every jurisdiction requires that exact period. Subscription notices use the checkout/billing email because provider-only accounts can lack a sign-in email; an undisplayed account notice is not treated as delivered.
+- California notice windows were checked against the [Attorney General's September 2025 guidance](https://oag.ca.gov/node/608083) on 2026-10-07. The applicable sales jurisdictions need review before launch; a generic promise of enough time to cancel does not configure the required notices.
+- ElevenLabs' [retention documentation](https://elevenlabs.io/docs/eleven-api/resources/zero-retention-mode) and [model-training guidance](https://elevenlabs.io/docs/help-center/legal/is-my-data-used-to-improve-eleven-labs-ai-models), checked 2026-10-07, distinguish visible history deletion from residual records, backups, and training settings. On 2026-10-07 the workspace training opt-out was saved in the system browser and verified off after a full reload. The Dormouse Hosted service-account key was restricted to Text to Speech and History write, with a 10,000-credit refresh-period limit and leak auto-disable enabled. The operator separately confirmed history isolation. These facts do not establish zero retention or retroactively undo training; section 4(i) of the [provider terms](https://elevenlabs.io/terms-of-use) makes the opt-out prospective after processing.
+- The worldwide launch decision includes EEA and UK consumers. The [EU distance-selling guidance](https://europa.eu/youreurope/business/selling-in-eu/selling-goods-services/ecommerce-distance-selling/index_en.htm) distinguishes statutory withdrawal disclosures and reimbursement timing from a voluntary refund promise. No use deduction or waiver is needed to support the offered full-refund policy (reviewed 2026-10-07).
+- [Directive 2023/2673](https://eur-lex.europa.eu/eli/dir/2023/2673/oj/eng) added the Consumer Rights Directive's Article 11a online withdrawal function, with national measures applying from 2026-06-19. Despite the amending directive's financial-services title, this function also covers other distance contracts concluded through an online interface (reviewed 2026-10-07).
+- The [ICO's representative guidance](https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/international-transfers/receiving-personal-information-from-the-eea/) describes separate EEA and UK representation duties and the narrow occasional-processing exception; [its transfer guidance](https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/international-transfers/a-brief-guide-to-international-transfers/) distinguishes adequacy from other safeguards. Provider locations alone do not establish either arrangement (reviewed 2026-10-07).
+- On 2026-10-08 the operator declined to appoint EEA or UK representatives at this stage and accepted the resulting compliance risk. Appointment is therefore excluded from the internal launch gate; this records a business decision, not a legal exemption. The published privacy contact is DiffPlug's support address and does not purport to be a local representative.
+- The [OEM terms](https://elevenlabs.io/oem-terms), checked 2026-10-07, define eligible business customers as Scale, Business, Enterprise, or equivalent subscribers (1.D), but define end users by internal business operations (1.I). The [Grant program](https://elevenlabs.io/startup-grants) advertises Scale access for startups building and launching products, supporting plan eligibility. The operator elected to proceed without vendor negotiation and treat the personal/hobby-use wording as a known supplier-contract ambiguity; grant-expiry planning is outside this review. This decision does not amend ElevenLabs' agreement. Section 2.B also requires approval for government use and public statements about the supplier relationship; adding customer clauses does not supply such approval.
+- The [ElevenLabs DPA](https://elevenlabs.io/dpa), checked 2026-10-07, covers entity customers through the incorporated terms and includes EU SCCs and the UK Addendum. The workspace product-terms page showed no pending terms; that does not establish DiffPlug as the contracting customer or supply a consumer OEM exception.
+- The managed-voice section added on 2026-10-08 addresses OEM 3.A through scoped incorporation of provider use requirements, a processing permission, no-agency/partnership language, and third-party-beneficiary rights. The [Prohibited Use Policy](https://elevenlabs.io/use-policy) (17 August 2026 version, checked 2026-10-08) also restricts government use and model training with output. The section limits incorporation to voice use; DiffPlug's payment, refund, and dispute provisions remain its own. Provider updates follow the published consumer-protective changes process; a provider requirement incompatible with continued service can trigger the service-reduction remedy. Affirmative acceptance and archiving the incorporated versions remain implementation work.
+- The [Grants announcement](https://elevenlabs.io/blog/elevenlabs-grants) FAQ, checked 2026-10-08, asks a recipient to display the "ElevenLabs Grants" logo at the bottom of its website; the [program page](https://elevenlabs.io/startup-grants) states no other publicity term. That request is not the prior written approval OEM 2.B(d) requires for other public statements, and Terms of Use 5(c) reserves the ElevenLabs name and logos.
diff --git a/docs/specs/website-docs.md b/docs/specs/website-docs.md
index 7e6c56ee0..78244022d 100644
--- a/docs/specs/website-docs.md
+++ b/docs/specs/website-docs.md
@@ -136,7 +136,7 @@ Source of truth: `Hosted` in `website/src/pages/Hosted.tsx`; `HostingRequirement
## Hosted policies
-**Must prerender `/privacy` and `/terms` outside Docs navigation with standalone marketing chrome and an effective date.**
+**Must prerender `/privacy` and `/terms` outside Docs navigation with standalone marketing chrome and a last-updated date.** **Must distinguish the revision date from the policy's applicability conditions; draft policies remain marked as not yet effective.**
Source of truth: `HostedPolicyLayout` in `website/src/components/HostedPolicyLayout.tsx`.
diff --git a/hosted/README.md b/hosted/README.md
index d5e2935bf..175dad5ce 100644
--- a/hosted/README.md
+++ b/hosted/README.md
@@ -179,7 +179,7 @@ pnpm exec wrangler secret put ELEVENLABS_API_KEY --config wrangler.voice.jsonc
The voice Worker's first secret creates its stub, so set it before the first release that deploys `dormouse-voice`: preflight reads it there. Once that release is live, delete the copy the account Worker held before the split (`pnpm exec wrangler secret delete ELEVENLABS_API_KEY`); its mapper no longer reads it, but a secret should live only where it is used.
-Create `ELEVENLABS_API_KEY` in an ElevenLabs account dedicated to Dormouse voice — the Worker deletes that account's entire speech history on a schedule, so never point it at a shared account. Restrict the key to text-to-speech plus speech-history access, and set a spending limit in the ElevenLabs console. How the Worker uses the key is `docs/specs/hosted.md` -> "Managed voice".
+Create `ELEVENLABS_API_KEY` for an ElevenLabs service account dedicated to Dormouse voice, with history access isolated from other workspace usage — the Worker deletes every speech-history item its key can see on a schedule. Restrict the key to text-to-speech plus speech-history access, and set a spending limit in the ElevenLabs console. How the Worker uses the key is `docs/specs/hosted.md` -> "Managed voice".
Generate a fresh cryptographically random `AUTH_SECRET`, and separately `RELAY_ENROLL_SECRET`, each with at least 32 bytes of entropy in your secret manager. Rotating `RELAY_ENROLL_SECRET` only voids enrollments in progress. Client IDs are public but may be stored through the same prompts as `GITHUB_CLIENT_ID`, `GOOGLE_CLIENT_ID`, `MICROSOFT_CLIENT_ID`, and `APPLE_CLIENT_ID`. The first secret can create the initial Worker stub; it does not activate account service. Set all required secrets before release; deployment preserves the ones already there.
diff --git a/hosted/server/account-app.ts b/hosted/server/account-app.ts
index c5a02bee8..876b4b467 100644
--- a/hosted/server/account-app.ts
+++ b/hosted/server/account-app.ts
@@ -3,14 +3,15 @@ import type { AccountEnv } from "./bindings";
import { accountRules } from "./headers";
import { relayAccountRoutes, type RelayAccountHost } from "./relay-account";
import { relayRoom } from "./relay-room-contract";
+import { termsRoutes } from "./terms";
import { voiceTokenRoutes } from "./voice";
import { workerApp } from "./worker-app";
/**
* The account Worker (`hosted.dormouse.sh`): auth, providers, readiness,
- * voice-token minting, the Relay's account routes, and the frontend. The
- * production and preview entries differ only in `fetchAuth`'s mail and in
- * `bindings`.
+ * terms acceptance, voice-token minting, the Relay's account routes, and the
+ * frontend. The production and preview entries differ only in `fetchAuth`'s
+ * mail and in `bindings`.
*/
export function accountApp(
fetchAuth: (
@@ -40,6 +41,7 @@ export function accountApp(
approveLimit: c.env.RELAY_APPROVE_LIMIT,
closeBurrow: (userId, burrowId) => relayRoom(c.env.RELAY_ROOM, userId).closeBurrow(burrowId),
});
+ termsRoutes(app, host);
voiceTokenRoutes(app, host);
relayAccountRoutes(app, host);
},
diff --git a/hosted/server/account-gate.ts b/hosted/server/account-gate.ts
index d1ec0308f..e3392fdfa 100644
--- a/hosted/server/account-gate.ts
+++ b/hosted/server/account-gate.ts
@@ -39,6 +39,20 @@ export interface AccountLogin {
export function cookieAdmin(
host: (c: Context) => AccountHost,
refuse: (c: Context) => Response,
+): MiddlewareHandler<{ Variables: { login: AccountLogin } }> {
+ return cookieGate(host, refuse);
+}
+
+/** {@link cookieAdmin}'s gate for a route any signed-in account may use. */
+export function cookieLogin(
+ host: (c: Context) => AccountHost,
+): MiddlewareHandler<{ Variables: { login: AccountLogin } }> {
+ return cookieGate(host);
+}
+
+function cookieGate(
+ host: (c: Context) => AccountHost,
+ refuse?: (c: Context) => Response,
): MiddlewareHandler<{ Variables: { login: AccountLogin } }> {
return async (c, next) => {
const origin = new URL(c.req.url).origin;
@@ -61,7 +75,7 @@ export function cookieAdmin(
session?: { createdAt?: unknown };
} | null;
if (!session?.user) return c.json({ message: "Sign in first." }, 401);
- if (!isAdmin(session.user)) return refuse(c);
+ if (refuse && !isAdmin(session.user)) return refuse(c);
c.set("login", {
userId: session.user.id,
createdAt: session.session?.createdAt,
diff --git a/hosted/server/dormouse-migrations/005_terms_acceptances.sql b/hosted/server/dormouse-migrations/005_terms_acceptances.sql
new file mode 100644
index 000000000..3d39e690a
--- /dev/null
+++ b/hosted/server/dormouse-migrations/005_terms_acceptances.sql
@@ -0,0 +1,12 @@
+-- Up Migration
+-- Each version of the Hosted terms an account agreed to by continuing past the
+-- sign-in notice (docs/specs/hosted.md -> "Terms acceptance"), first time only.
+CREATE TABLE dormouse_terms_acceptances (
+ "userId" text NOT NULL REFERENCES "user" (id) ON DELETE CASCADE,
+ version text NOT NULL,
+ "acceptedAt" timestamptz NOT NULL DEFAULT now(),
+ PRIMARY KEY ("userId", version)
+);
+
+-- Down Migration
+DROP TABLE dormouse_terms_acceptances;
diff --git a/hosted/server/policy-constants.ts b/hosted/server/policy-constants.ts
index 54cdb70af..75de72e66 100644
--- a/hosted/server/policy-constants.ts
+++ b/hosted/server/policy-constants.ts
@@ -20,3 +20,10 @@ export const RECENT_LOGIN_WINDOW = `${LOGIN_FRESH_AGE_MS / 60_000} minutes`;
// How long an enrollment's device code lives (the relay mints it) and how long
// an approval waits for its poll (the account writes it).
export const ENROLLMENT_TTL_MS = 10 * 60 * 1000;
+
+// The Hosted terms version the sign-in notice names and an account accepts by
+// continuing: the revision date both policy pages print
+// (`website/src/components/HostedPolicyLayout.tsx`), which
+// `hosted/server/tests/policy.test.ts` pins this to. A new version is a new
+// acceptance row, never an edit of an old one.
+export const TERMS_VERSION = "2026-10-08";
diff --git a/hosted/server/terms.ts b/hosted/server/terms.ts
new file mode 100644
index 000000000..0a2d7e0c6
--- /dev/null
+++ b/hosted/server/terms.ts
@@ -0,0 +1,30 @@
+// Rules: docs/specs/hosted.md -> "Terms acceptance".
+import type { Context, Hono } from "hono";
+import { accountQuery, cookieLogin, type AccountHost } from "./account-gate";
+import { TERMS_VERSION } from "./policy-constants";
+
+/**
+ * Registers the account's POST /api/terms/acceptance, which records that the
+ * signed-in account continued past the sign-in notice naming `version`; call
+ * before any /api/* catch-all. Only the current version is recorded, so a
+ * notice a stale page showed never stands in for the one in force.
+ */
+export function termsRoutes(
+ app: Hono
Terminal traffic is end-to-end encrypted between your computer and your phone,
@@ -596,34 +600,40 @@ export default function Hosted() {
DiffPlug LLC operates Dormouse Hosted at hosted.dormouse.sh. This policy covers its account service and related support. Contact us at support@diffplug.com about privacy or your account.
-The current service lets you create an account and manage sign-in methods. Creating an account does not upload your terminal contents, commands, files, or audio. Managed remote control and hosted voice are not available yet; we will explain their data handling before offering them.
+DiffPlug LLC operates Dormouse Hosted and is the controller of the personal information described here: the account service at hosted.dormouse.sh, the managed Relay and Pocket at relay.dormouse.sh, and managed voices at voice.dormouse.sh. This policy covers those services, the paid subscription that unlocks them, and related support. Contact us at support@dormouse.sh about privacy or your account.
+Our business address is DiffPlug LLC, 447 Sutter St Ste 405, San Francisco, CA 94108, United States.
+Dormouse itself runs on your computer and sends no usage telemetry. An update check fetches a version file from dormouse.sh without sending terminal contents or a Hosted account identifier. Automatic update checks run only if enabled. "Check now" makes a request when you click it. Creating an account does not upload your terminal contents, commands, files, or audio.
+This website, dormouse.sh, is served by Cloudflare, which processes visitors’ IP addresses and request information to deliver it. The site currently loads fonts from Google Fonts, so Google receives your IP address and browser information when you visit.
This policy does not describe a Relay you operate yourself or third-party services you choose to open. Those services have their own operators and policies.
+Hosted is not directed to children under 13, and we do not knowingly collect their personal information. If you believe a child under 13 has given us personal information, contact us and we will delete it.
> }, - { id: "information", title: "Information we handle", body: <> + { id: "information", title: "Account and sign-in", body: <>When you use email sign-in, we process your email address, its verification status, sign-in requests, and one-time verification codes. We store a protected representation of each code to verify it.
If you choose Google, GitHub, Microsoft, or Apple sign-in, we receive the provider’s account identifier and the identity information it supplies, which may include your name, email address, verification status, and profile-image URL. Apple may supply a private relay address. We use the provider identifier to recognize you even when your email changes. We do not request access to your mail, documents, repositories, or contacts.
-We keep account and connected-provider records, creation and update times, and browser login records. Login records can include your IP address and browser information. We also process cookies, temporary sign-in state, and abuse-prevention records. Our infrastructure providers process connection and operational information to deliver and secure the service.
+We keep account and connected-provider records, creation and update times, browser login records, and which version of the terms you agreed to and when. Login records can include your IP address and browser information. We also process cookies, temporary sign-in state, and abuse-prevention records.
+When you sign in a copy of Dormouse to your account, we store only a hash of the credential that copy keeps, never the credential itself, with when it was created, last used, and revoked.
If you contact support, we receive your message and anything you choose to include. Please do not send passwords, API keys, or terminal contents that contain secrets.
> }, + { id: "subscription", title: "Your subscription", body: <> +You buy Hosted subscriptions from DiffPlug LLC. We use Stripe Billing, Stripe-hosted Checkout, and Stripe’s customer portal to process payments and manage subscriptions. Stripe collects payment details, billing addresses, and applicable tax information. It processes information on our behalf and for its own purposes, such as fraud prevention and legal compliance, as described in Stripe’s privacy policy. Dormouse does not receive or store your full card number.
+We receive subscription and billing information from Stripe: customer and subscription identifiers linked to your account, the billing email, the plan and price (including a founding cohort, if any), status, billing-period dates, cancellation status, and billing-event records. Stripe’s dashboard and billing records may also make your billing address, tax information, invoices, and limited payment-method details, such as card brand and last four digits, available to us for support, accounting, refunds, and disputes.
+If you buy a founding plan and tick the box to appear in the founders row, we show your account name and profile picture on the Hosted page. The box starts unticked, and you can untick it at any time. We serve those pictures from our own site, so a visitor’s browser never asks your sign-in provider for them. Everyone else counts only toward the total.
+After checkout we may ask four optional questions about price. Nothing is sent unless you answer, and we use the answers only to set future prices.
+ > }, + { id: "voice", title: "Managed voices", body: <> +When managed voices are on, Dormouse sends voice.dormouse.sh a shortened version of the terminal’s displayed label, the selected voice identifier, and your authentication credential. The label can include a program-supplied terminal title, a command label, or a directory name. We remove punctuation and some patterns that resemble secrets, but this filtering cannot reliably remove all confidential information. Avoid sensitive labels when using managed voices.
+The voice request does not upload the terminal’s screen or output stream, a notification body, or a session identifier. Dormouse explains the label disclosure before the first managed-voice request. Cached clips play locally; generating a clip that is not in the cache makes a new request.
+We forward the label and voice id to ElevenLabs, which turns them into speech. We do not log the label. We keep a count of your requests per day to apply the fair-use limit.
+ElevenLabs keeps generated text and audio in its speech history. We use a dedicated service account within our ElevenLabs workspace and automatically delete its history, normally within minutes. This is not zero-retention processing: deletion requests can fail, and deleting visible history does not necessarily erase debugging or moderation records. ElevenLabs documents that deleted data can remain in backups for up to 30 days. See its retention documentation. We cannot guarantee when every provider copy is erased.
+We have turned off model-training data use in the ElevenLabs workspace that contains Dormouse’s service account. This is separate from history deletion. ElevenLabs’ terms state that the opt-out takes effect after they process it and does not undo earlier uses of data or materials resulting from those uses. The opt-out does not eliminate the retention described above.
+ > }, + { id: "remote-control", title: "Remote control and Pocket", body: <> +The managed Relay connects Dormouse on your computers to Pocket on your phone. Terminal traffic and push notification contents are end-to-end encrypted between your devices, so the Relay carries them without being able to read them.
+We store the computers you enroll (an identifier, a hash of each one’s Relay credential, and when it enrolled), the passkeys you register for Pocket (each one’s public key and the label you gave it), hashes of Pocket sign-in sessions, and short-lived sign-in and pairing challenges. If you turn on push notifications, we store each phone’s push subscription: the address your phone’s browser vendor gave it, the keys that seal notifications to it, and when it subscribed.
+While it carries a connection, the Relay also sees connection metadata: IP addresses, which of your computers are online, which devices talk to which, and the timing and size of encrypted traffic. Once a session switches to a direct connection between your devices, the Relay sees only that the session exists. The trust model lists this in full.
+A one-time connection link needs no account. Its rendezvous forwards the encrypted handshake between your phone and computer without reading or storing it.
+ > }, { id: "use", title: "How we use it", body: <> -We use this information to create and recognize your account, verify sign-in, connect methods you explicitly select, send requested sign-in codes, prevent abuse, troubleshoot failures, and answer support requests. We discard provider access, refresh, and identity tokens after identity verification rather than storing them in your account.
-We do not sell Hosted account information, use it for targeted advertising, or use it to train general-purpose AI models. Signing in does not subscribe you to a newsletter. The account site uses necessary authentication and security cookies and does not load marketing analytics.
+We use this information to create and recognize your account, verify sign-in, connect methods you explicitly select, send requested sign-in codes, check on each request that your subscription is active, deliver the features you pay for, apply fair-use limits, prevent abuse, troubleshoot failures, and answer support requests. We discard provider access, refresh, and identity tokens after identity verification rather than storing them in your account.
+Every request to Hosted carries your IP address and connection information, which we and our infrastructure providers use to deliver the request, secure the service, and limit request rates. Rate-limit records we store hold a keyed hash of the address, not the address itself, and are kept only briefly.
+DiffPlug does not sell Hosted information, use it for targeted advertising, or use it to train AI models. The managed-voice section describes ElevenLabs’ separate processing. Signing in or subscribing does not subscribe you to a newsletter. The account site uses necessary authentication and security cookies and does not load marketing analytics.
+To see whether Hosted is working, we may keep aggregate daily counts on our own servers — for example, checkouts per plan, sign-ins per method, and voice requests answered or over the limit — with no per-person analytics. A count row carries no account id, email address, IP address, browser information, or text. Links to the Hosted page from Dormouse or this site may carry a short label naming where you came from (such as the voice setting or the tutorial), which may be counted, in the same aggregate way, if you check out. There are no analytics scripts or tracking cookies. Because we do not track you across sites or sell your information, browser Do Not Track and Global Privacy Control signals have nothing further to turn off, and we do not change our practices in response to them.
+ > }, + { id: "legal-bases", title: "Our legal bases", body: <> +Where the EU or UK GDPR applies, our legal basis depends on the purpose:
+We need account and billing information to provide the corresponding services; without it we cannot create the account or fulfill the purchase. Public founder attribution and survey answers are optional.
> }, { id: "providers", title: "Who processes the information", body: <> -Cloudflare runs the account website and API. Neon stores the account database. Postmark delivers sign-in emails and processes their recipients, contents, and delivery records. GitHub stores encrypted database-backup artifacts. These providers process information needed to provide their services to us.
+Cloudflare runs the account, Relay, and voice services. Neon stores the database. Postmark delivers sign-in emails and processes their recipients, contents, and delivery records. GitHub stores encrypted database-backup artifacts. Stripe processes payments and manages billing. ElevenLabs generates managed voices from spoken labels. These providers process information needed to provide their services; Stripe’s and ElevenLabs’ additional processing is described above.
+Push notifications travel through the push service your phone’s browser uses — Apple, Google, Mozilla, or Microsoft — which sees that a sealed notification was sent, not what it says.
A sign-in provider you choose learns that you are authenticating with Dormouse and handles that interaction under its own policy. Our email and support providers also process messages you send us. Authorized DiffPlug personnel may access information to operate the service or respond to your request.
We may disclose information when legally required, to investigate abuse, or to protect people and the service. If a business transfer affects your information, we will notify you of material changes to how it is handled.
> }, { id: "retention", title: "Storage, retention, and security", body: <> -We operate from the United States and use providers that may process information in other countries. The production account database is hosted in the United States.
-We retain account information while you maintain an account and as needed for support, security, and legal obligations. A sign-in code expires after ten minutes and a browser login expires after 24 hours; expiry does not mean every related database or delivery-log record is immediately erased. Backup copies remain until their retention periods end.
+We operate from the United States and use providers that may process information in other countries. The production database is hosted in the United States.
+We retain account information while you maintain an account. Account-linked daily voice counters currently remain until account deletion. Sign-in codes, browser logins, Relay sessions, and pairing challenges are short-lived; expiry does not mean every related database or delivery-log record is immediately erased. Removing a computer from your account deletes its Relay records and push subscriptions. Our encrypted deployment-backup artifacts in GitHub are configured to expire after 30 days; providers’ own backups follow their retention arrangements.
+Support and security records are retained for the time needed to resolve the request or incident and any related dispute, or to meet a legal preservation obligation. We assess the record’s purpose, whether the issue remains open, and applicable legal deadlines. Deleting an account does not immediately remove copies in backups or records we must keep for these purposes.
+We keep subscription and billing-event records after a subscription ends, and after account deletion, for as long as accounting, tax, and dispute obligations require. Stripe keeps its own payment records under its policy.
We protect information with encrypted connections, access controls, and encrypted backup artifacts. No service can guarantee absolute security. Our security documentation describes the current boundaries and limitations.
> }, { id: "choices", title: "Your choices and requests", body: <>You choose which sign-in providers to use. Connecting another provider requires a recent login and an explicit action in your account. Logging out ends the current browser’s login; it does not log out your other devices. You can also remove Dormouse’s authorization in a provider’s settings, but that alone does not delete your Dormouse account.
-Contact support@diffplug.com to request access, correction, export, or deletion of account information, or to raise a privacy concern. We may need to verify your identity before acting. We handle requests according to applicable law, including any rights to object, restrict processing, or complain to a data-protection authority. Account deletion is handled through support; there is no self-service deletion control yet.
+You can turn managed voices or push notifications off in Dormouse at any time, remove an enrolled computer from your account, leave the founders row, and cancel your subscription from the billing portal.
+Contact support@dormouse.sh to request access, correction, export, or deletion of account information, or to raise a privacy concern. We may need to verify your identity before acting. We handle requests according to applicable law, including any rights to object, restrict processing, or complain to a data-protection authority. Account deletion is handled through support; there is no self-service deletion control yet.
+If the EU or UK GDPR applies, you may request access, correction, erasure, restriction, or portability where the relevant conditions apply, and object to processing based on legitimate interests because of your particular situation. You may withdraw consent without affecting prior lawful processing. We respond without undue delay, normally within one month; if the law permits more time for a complex request, we will explain the extension within that month. You may complain to your local data-protection authority in the EEA or the UK Information Commissioner, without first contacting us.
> }, { id: "updates", title: "Changes to this policy", body: <>We will update this page when our practices change and identify the effective date. We will provide notice before materially expanding how we use account information, and obtain consent when required.
@@ -46,5 +89,5 @@ export const PRIVACY_SECTIONS: PolicySection[] = [ ]; export default function Privacy() { - returnThese terms govern the Dormouse Hosted account service operated by DiffPlug LLC at hosted.dormouse.sh. By creating or using a Hosted account after these terms take effect, you agree to them. You must be legally able to enter this agreement. If you act for an organization, you must have authority to bind it.
-The current service provides accounts and sign-in management. Managed remote control, hosted voice, subscriptions, pricing, and launch dates are not promised by creating an account. Any paid service will have its own offer and payment terms before you buy it.
+These terms govern Dormouse Hosted, provided and sold by DiffPlug LLC: the account service at hosted.dormouse.sh and the paid subscription that adds managed voices and the managed Relay for Pocket. You must be legally able to enter this agreement. If you act for an organization, you must have authority to bind it. The subscription provisions apply to purchases made when paid subscriptions become available.
+You agree to this version by continuing past the sign-in notice that names it; for a new account, it takes effect then. For an existing account, it replaces your previous terms on the effective date stated in the notice we give you, at least 30 days after that notice, unless you expressly agree to this version sooner. We obtain renewed agreement where required by law. Until then, your previous terms continue to apply. Publication alone does not replace your existing agreement, and this version does not apply retroactively to disputes.
+The Hosted page describes what a subscription includes, what it costs, and its current usage limits. If it conflicts with these terms, these terms control. An account alone is free and grants no paid features.
The Dormouse software and self-hosted components remain subject to their own software licenses. These terms do not change those licenses or require a Hosted account to use local terminals.
> }, { id: "account", title: "Your account", body: <>Use an email address or provider account you are authorized to use. Protect those accounts and your devices, and tell us if you believe someone is using your Hosted account without permission.
-You are responsible for activity you authorize through your account. Provider sign-in depends on the provider’s availability and policies. Keep access to at least one connected sign-in method: account merging, automatic recovery, and a sign-out-everywhere control are not available. Connecting a provider is an explicit account action; matching email addresses alone do not merge accounts.
+You are responsible for activity you authorize through your account. Provider sign-in depends on the provider’s availability and policies. Keep access to at least one connected sign-in method; we may be unable to restore an account you can no longer sign in to.
+We send subscription notices to the billing email you provide at checkout or later update for your subscription, and other account notices to your account’s contact email. Keep those addresses current; contact support if you need help updating them. If your account has no contact email, we show account notices when you sign in. Subject to applicable law, these methods satisfy written-notice requirements in these terms; they do not replace any additional notice or consent required by law.
Our privacy policy explains how we handle account information.
> }, + { id: "subscriptions", title: "Subscriptions and payment", body: <> +A subscription is billed monthly or yearly, at the price shown when you buy it, in US dollars. DiffPlug LLC is the seller and uses Stripe Billing and Stripe-hosted Checkout to process payments and manage subscriptions. We are responsible for the subscription, refunds, and applicable sales tax or VAT obligations. Checkout shows the total, including any applicable tax, before you authorize payment.
+Every plan renews automatically at the end of each period until you cancel. There is no free trial; the refund below takes its place.
+A subscription covers one individual, including that person’s work use, with no per-device charge. It may not be shared, resold, or transferred to another person. Device enrollment and usage limits are described below. For shared accounts, multiple users, or organization-level features, email support@dormouse.sh.
+If a renewal payment fails, the paid features stop until a payment succeeds. Dormouse keeps working in the meantime, with spoken alarms in your system voice. A partial refund or billing correction alone does not end your subscription.
+During a payment dispute or chargeback, we may temporarily suspend the paid access covered by the disputed payment while we investigate. We will notify you and provide a way to contact us. If the suspension was mistaken or the disputed payment is restored, we will restore any remaining paid access and the founding price you held before the suspension. If the subscription payment is finally reversed, we may end the access covered by that payment and stop future renewals. This does not limit your right to dispute a charge or any refund or remedy owed to you.
+ > }, + { id: "cancellation", title: "Cancellation and refunds", body: <> +You can cancel at any time from the billing portal in your account. Cancelling stops future renewals; you keep the paid features until the end of the period you already paid for. If you cannot sign in or use the portal, contact support@dormouse.sh to cancel. We may verify that you own the subscription, but do not require you to recover account access to cancel it.
+Ask within 30 days of your first Hosted subscription payment, or of any yearly renewal, and we will refund that payment in full, including tax we collected on it. Monthly renewals are not covered by this voluntary guarantee. Changing plans or cancelling and subscribing again does not restart the first-payment window. A full refund under this guarantee ends the subscription and its paid features straight away, and a founding refund returns the seat to its cohort. Email support@dormouse.sh to ask.
+This guarantee is in addition to the unused-period refunds below and any rights or remedies the law where you live gives you, including cancellation, withdrawal, and remedies for defective or undelivered services. Those rights are not limited to 30 days by these terms. We issue refunds to the original payment method where possible; your bank or payment provider controls when the credit appears.
+ > }, + { id: "withdrawal", title: "EEA and UK consumer withdrawal", body: <> +If you are a consumer in the European Economic Area or United Kingdom, you may withdraw from your initial Hosted subscription contract without giving a reason within 14 days after the contract is made. Send an unambiguous statement to support@dormouse.sh or by post to DiffPlug LLC, 447 Sutter St Ste 405, San Francisco, CA 94108, United States, before that period ends. We do not require a particular form, account access, or a reason.
+You can also use “Withdraw from contract” on your Hosted account’s billing page during the withdrawal period, then confirm your withdrawal. We will send you an acknowledgement on a durable medium, such as email, with your statement and the date and time it was submitted. Withdrawal ends the current contract; ordinary cancellation of renewal keeps access through the paid period.
+For that withdrawal, we will refund all payments received for the subscription, including collected tax, without undue delay and within 14 days after receiving your notice. We use the original payment method unless you expressly agree otherwise, and charge no refund fee. Access ends on withdrawal. Starting to use Hosted immediately does not waive this right, and we do not deduct a charge for use during this withdrawal period. Our separate 30-day guarantee and any longer statutory rights remain available.
+You may use this optional withdrawal form by email or post: “To DiffPlug LLC, 447 Sutter St Ste 405, San Francisco, CA 94108, United States; support@dormouse.sh: I give notice that I withdraw from my contract for Dormouse Hosted. Ordered on: ____. Name: ____. Address: ____. Date: ____. Signature, only if sent on paper: ____.” Your account email or order reference helps us locate the purchase, but is not a required formality for giving notice.
+ > }, + { id: "founding", title: "Founding prices", body: <> +A founding subscription is a yearly plan sold at a launch price, in cohorts of 100. When a cohort sells out the founding price rises, and founding closes when it reaches the list price.
+Your base yearly subscription price in US dollars is locked for as long as that subscription stays active. Applicable taxes may change. If a founding renewal payment fails, you have 30 days from the failed renewal to fix it and keep the locked price; this preserves the price, not paid access during nonpayment. After that, subscribing again is at the list price, as it is after you cancel and the paid period ends. A billing-provider migration or a payment failure caused by us does not forfeit your locked price; we will give you a reasonable opportunity to restore payment.
+A founding badge is cosmetic. It grants nothing beyond the plan itself.
+ > }, + { id: "fair-use", title: "Fair use", body: <> +Managed voices have a daily request limit, and the managed Relay limits how many copies of Dormouse an account can enroll. The Hosted page states the current limits. Past the voice limit, Dormouse speaks in your system voice until the limit resets. There is no per-device fee.
+We also limit connection attempts and requests to protect availability and prevent abuse, and may act immediately against abuse or security threats. Material reductions to the paid service remain subject to the notice and refund provisions below.
+ > }, + { id: "managed-voices", title: "Managed voices and ElevenLabs", body: <> +ElevenLabs supplies the speech generation used by managed voices. You must be at least 18 years old, or the age of legal majority where you live if higher, to use managed voices. Use them only through Dormouse, for its alarms. Do not extract, resell, sublicense, or redistribute the speech service or your credentials.
+For managed voices and the resulting audio, you must comply with the restrictions, obligations, and prohibitions concerning use in the ElevenLabs Terms of Service and Prohibited Use Policy, which are incorporated into this agreement for that purpose. This includes their restrictions on harmful or deceptive impersonation, infringement, abuse, bypassing safeguards, and using the service or its output to train AI models or develop competing products. Do not send protected health information subject to HIPAA through managed voices. Government entities, as defined in the Prohibited Use Policy, may not use managed voices without ElevenLabs’ prior written authorization; contact us before using them on behalf of such an entity.
+You must have the rights and permissions needed for the labels you send for speech generation. You grant DiffPlug, ElevenLabs, and ElevenLabs’ affiliates and subcontractors a non-exclusive right to process and use those labels and the resulting audio to provide and support managed voices, as described in our privacy policy. This permission does not transfer ownership of your content.
+DiffPlug is not ElevenLabs’ agent or partner and is not in a joint venture with ElevenLabs. You must not hold yourself out as ElevenLabs’ agent, partner, or joint venturer through your use of managed voices. ElevenLabs is an intended third-party beneficiary of these terms as they relate to managed voices and may enforce those provisions.
+DiffPlug provides support for your Hosted subscription. Your payments, cancellation, refunds, and disputes with DiffPlug remain governed by these Hosted terms. Nothing in this section reduces your mandatory consumer rights. We will notify you of material updates to the incorporated provider requirements through the changes process below, obtain renewed agreement where required, and pass on provider notices that affect your use. If a provider requirement prevents us from continuing managed voices under your agreed terms, the service-reduction and refund provisions below apply.
+ > }, { id: "acceptable-use", title: "Acceptable use", body: <>Do not use the service unlawfully, impersonate others, access accounts without authorization, send unwanted messages, interfere with other users, or bypass authentication, rate limits, or other security controls. Do not use the service to distribute malware or attack third parties.
+You may not use Hosted if you are on a U.S. sanctions list or in a country or region under comprehensive U.S. sanctions, or in violation of U.S. export laws.
Good-faith security reports are welcome through our security reporting process. Avoid accessing other people’s data or disrupting service while investigating an issue.
> }, { id: "availability", title: "Availability and account closure", body: <> -This is an early account service. We may change features, interrupt operation for maintenance, or discontinue it. We do not promise uninterrupted availability or a particular future feature.
-We may restrict or suspend an account to address abuse, a security issue, a legal requirement, or a material violation of these terms. Where practical, we will explain the reason and provide a way to contact us; urgent protective action may come first.
-You may stop using the service at any time. Contact support@diffplug.com to request account closure or to ask us to review a restriction. Information is retained or deleted as described in the privacy policy and as required by law.
+We may change features, interrupt operation for maintenance, or discontinue the service. We do not promise uninterrupted availability or a particular future feature. When managed voices are unavailable, Dormouse speaks in your system voice.
+We will give at least 30 days’ advance notice before we permanently discontinue Hosted, materially reduce your paid service during a prepaid term, or make a material change to these terms, unless an urgent legal or security requirement prevents it; in that case we will notify you as soon as reasonably possible.
+We refund the unused portion of your prepaid subscription, including the corresponding tax we collected, if we discontinue Hosted, if we end your paid access for a reason other than your material breach, or if, during a prepaid term, we materially reduce your paid service or materially change these terms and you choose to end your subscription instead of accepting the change. The refund runs from when paid access ends, and the 30-day guarantee does not limit it. Discontinuation also stops renewals. The Relay is source-available and its self-hosting guide is published if you want to operate your own Relay; self-hosting does not replace your refund.
+We may restrict, suspend, or terminate an account to address abuse, a security issue, a legal requirement, or a material breach of these terms. Where practical, we will explain the reason and provide a way to contact us; urgent protective action may come first.
+You may stop using the service at any time. Contact support@dormouse.sh to request account closure or to ask us to review a restriction. When we close your account, we also cancel future subscription renewals. Before completing your closure request, we will explain when paid access will end and any refund available to you; you can instead cancel renewal and keep access through the paid period. Information is retained or deleted as described in the privacy policy and as required by law.
> }, { id: "responsibility", title: "Warranties and responsibility", body: <> -To the extent permitted by law, the early account service is provided “as is” and “as available,” without implied warranties of merchantability, fitness for a particular purpose, or non-infringement.
-To the extent permitted by law, DiffPlug LLC is not responsible for indirect or consequential losses arising from use of the service. Nothing in these terms excludes responsibility or consumer rights that cannot lawfully be excluded. You remain responsible for keeping independent copies of information you need.
+Consumers retain their mandatory rights to services that conform to the contract and are provided with reasonable care and skill, and any applicable remedies such as correction, a price reduction, or a refund. The qualifications below apply only where the law permits them.
+To the extent permitted by law, the service is provided “as is” and “as available,” without implied warranties of merchantability, fitness for a particular purpose, or non-infringement.
+To the extent permitted by law, DiffPlug LLC is not liable for indirect or consequential losses arising from the service. Its total aggregate liability for all claims arising out of or relating to these terms or Hosted is limited to US$10 if you paid no Hosted subscription fees in the twelve months preceding the first event giving rise to the claims. If you paid any Hosted subscription fees in that period, the limit is the greater of US$100 and those fees. This is one aggregate limit, not a separate limit for each claim; cancelling after the event does not change which limit applies.
+The exclusions and limit do not reduce refunds owed under these terms, or exclude or limit liability for fraud, willful misconduct, gross negligence, death or personal injury caused by negligence, or any liability or consumer right that cannot lawfully be excluded or limited. You remain responsible for keeping independent copies of information you need.
+If you use Hosted for business purposes and are not a consumer, you will defend DiffPlug LLC against third-party claims alleging that content you supplied infringes another person’s rights or violates applicable law, or that your unlawful use of Hosted or material breach of these terms caused the third party harm. You will indemnify DiffPlug for reasonable defense costs and damages finally awarded, or settlements you approve, to the extent caused by that conduct. This obligation does not cover claims to the extent caused by DiffPlug’s or its providers’ breach, negligence, or misconduct, or by voices or other materials they supply independently of your content. Using provider-generated audio as permitted by these terms does not by itself trigger this obligation.
+We will promptly notify you of a claim, allow you to control its defense with reasonably qualified counsel, and provide reasonable cooperation at your expense. Delayed notice reduces your obligation to the extent it prejudices your defense. We may participate with our own counsel at our expense. Neither party may settle a covered claim without the other’s written consent, which must not be unreasonably withheld; you may not impose an admission, payment, or other obligation on DiffPlug without its express consent.
+ > }, + { id: "governing-law", title: "Governing law and general terms", body: <> +California law governs these terms. If you are a consumer, you also retain the protections of mandatory law in the country where you habitually reside, and you may bring proceedings in the courts where you live. Otherwise, the state and federal courts in San Francisco County, California have exclusive jurisdiction.
+These terms, including the requirements they incorporate, are the whole agreement between you and DiffPlug LLC about Hosted. You may not transfer them. DiffPlug LLC may assign them to a successor to the business that operates Hosted, who will be bound by them. Not enforcing a provision is not a waiver of it.
+Provisions that by their nature should outlast the agreement survive its end, including amounts owed, refunds, warranties and responsibility, and governing law. If a provision of these terms is unenforceable, the remaining provisions continue to apply to the extent permitted by law.
> }, { id: "changes", title: "Changes and contact", body: <> -We will identify the effective date of changes on this page and provide reasonable advance notice of material changes, except when an urgent security or legal need requires earlier action. If you do not agree to changed terms, you may stop using the service and request account closure.
-For questions about these terms, contact DiffPlug LLC at support@diffplug.com.
+We will identify the effective date of changes on this page and give notice of material changes as described in Availability and account closure, including the refund if you do not accept one. Changes do not apply retroactively to disputes. We will obtain renewed agreement where required by law.
+We may change monthly and yearly subscription prices only from a future renewal, after notice of the new price and how to cancel. We will give the notices required where you live, including applicable renewal reminders, annual reminders, and price-change notices. A price change never changes a founder’s locked base subscription price.
+For questions about these terms, contact DiffPlug LLC at support@dormouse.sh.
+Our business and postal address is DiffPlug LLC, 447 Sutter St Ste 405, San Francisco, CA 94108, United States.
> }, ]; export default function Terms() { - return