Last updated: August 8, 2026
This Customer Agreement (the “Agreement”) is between Waffer, Inc., a Delaware corporation doing business as “Teaflask” (“Teaflask”, “we”, “us”), and the customer accepting it (“Customer”, “you”). BY (A) CLICKING A BOX OR CHECKBOX INDICATING ACCEPTANCE, (B) CREATING AN ACCOUNT THROUGH A SCREEN THAT REFERENCES THIS AGREEMENT, OR (C) USING THE SERVICE, YOU AGREE TO BE BOUND BY THIS AGREEMENT. If you accept on behalf of a company or other legal entity, you represent that you have authority to bind that entity, and “Customer” refers to it. If you do not agree, do not use the Service. If Customer and Teaflask have signed a separate written agreement covering the Service (such as an enterprise master services agreement), that agreement — not this one — governs Customer’s use to the extent of any conflict, including when Customer’s users later accept this Agreement through the signup flow.
1. Definitions
- “Service” means the products, sites, applications, APIs, and code Teaflask makes available to Customer — including any surfaces Teaflask powers inside Customer Properties or hosts on Customer’s behalf — as described in our documentation and any order form, and as they evolve over time.
- “Teaflask Code” means software code Teaflask provides for deployment on or use with Customer Properties, in whatever form.
- “Customer Properties” means the websites, applications, and other products owned or operated by (or for the benefit of) Customer in which Customer deploys the Service.
- “Visitors” means end users of and visitors to Customer Properties who interact with the Service, whether or not identified by Customer.
- “Customer Data” means data submitted to or collected by the Service by or for Customer, including content and systems Customer connects, content Customer creates in the Service, Visitor conversations, and information the Service reads from Customer Properties.
- “Outputs” means content and information the Service generates for Customer or its Visitors.
- “Actions” means operations the Service performs against systems Customer connects or directs it to act upon — Customer’s own or third parties’ — at the direction of Customer or its Visitors, under Customer’s configured policies.
2. The Service
The Service lets Customer offer AI agents, grounded in the content and systems Customer connects, that converse with Customer and its Visitors, generate Outputs, and perform Actions. Subject to this Agreement, Teaflask grants Customer a non-exclusive, non-transferable right during the term to access and use the Service, and to deploy the Teaflask Code on Customer Properties, for Customer’s business purposes. What the Service does and how it behaves is described in our documentation, which we keep current as the Service evolves.
We may improve or modify the Service, provided we do not materially reduce its general functionality during a paid subscription period. We may update the Teaflask Code remotely, and will not change deployed Teaflask Code in ways that break Customer Properties without notice.
3. Accounts and organizations
Customer is responsible for its users’ accounts, for keeping credentials and API keys confidential, and for all activity under its organization. Customer will notify us promptly at security@teaflask.com of any suspected unauthorized access. The Service is for business use; each user must be at least 18 years old.
4. Customer responsibilities and governance
The Service acts only through capabilities Customer connects and under policies Customer configures. Customer — not Teaflask — decides which Actions exist, which run autonomously, and which require human approval. Customer is responsible for:
- having all rights necessary for the content, systems, and data it connects to the Service, and ensuring that connecting them does not violate any law or agreement;
- reviewing what the Service prepares on Customer’s behalf and configuring its policies (including approval requirements) appropriately for the sensitivity of each capability before enabling it for Visitors;
- the consequences of Actions executed against connected systems as configured — an Action the Service performs under Customer’s policies is Customer’s action for the purposes of Customer’s relationship with its Visitors and third parties;
- its Customer Properties, products, and services, and its own terms and policies with its Visitors.
5. Visitor data and required disclosures
For personal data of Visitors processed through the Service, Customer is the controller (or an intermediate processor) and Teaflask is Customer’s processor or service provider. Our Privacy Policy describes our practices; a data processing addendum is available on request at privacy@teaflask.com and, once executed, is incorporated into this Agreement.
Customer acknowledges that the Teaflask Code stores namespaced identifiers in browser storage on Visitors’ devices (and sets no cookies), as described in our Cookie & Storage Policy, which is incorporated by reference; this storage is necessary to provide the Service. Customer will: (a) include in each Customer Property’s privacy disclosures its use of Teaflask and how Visitor data is used and shared; (b) provide Visitors with any information about storage and access of information on their devices required by applicable law; and (c) as between Customer and Teaflask, be solely responsible for obtaining any consents, clearances, and approvals from Visitors required by applicable law.
Anonymous Visitor conversations are retained for the fixed idle period stated in our Privacy Policy and then deleted. Customer can request deletion of Visitor data sooner at any time.
6. AI provisions
6.1 Nature of outputs
The Service is built on machine-learning models, whose outputs are probabilistic. Outputs may be incorrect, incomplete, misleading, or not reflective of recent events, and must not be relied upon as a sole source of truth without independent verification. The Service is not human and is not a substitute for human oversight. Outputs may not be unique, and similar outputs may be generated for others. Customer will not remove, and will pass on to its Visitors where Outputs are presented to them, notice that factual assertions in Outputs should not be relied upon without independently checking their accuracy.
6.2 AI identity disclosure
The Service presents itself to Visitors as an AI assistant. Customer will not configure, describe, or present the Service in a way that states or implies Visitors are interacting with a human, and will not represent Outputs as human-generated.
6.3 Ownership of outputs
As between the parties, Customer retains all rights in Customer Data, and Teaflask assigns to Customer all of Teaflask’s right, title, and interest, if any, in and to Outputs. Teaflask retains all rights in the Service itself.
6.4 No training on your data
TEAFLASK WILL NOT USE CUSTOMER DATA OR OUTPUTS TO TRAIN AI MODELS, AND OUR AGREEMENTS WITH THE THIRD-PARTY MODEL PROVIDERS THAT POWER THE SERVICE PROHIBIT THEM FROM USING CUSTOMER DATA OR OUTPUTS TO TRAIN THEIR MODELS, IN EACH CASE UNLESS CUSTOMER EXPLICITLY AGREES OTHERWISE. Model providers process Customer Data as subprocessors solely to provide the Service. Our Privacy Policy describes our subprocessors by category; the named list, with change notice and objection rights, is available to Customer through our data processing addendum and trust center.
6.5 Bring your own key
Where Customer supplies its own model-provider API key, Customer is responsible for that key, for its provider account and the fees it incurs, and for complying with that provider’s terms; Customer’s provider agreement — not ours — governs that provider’s handling of data sent under Customer’s key. We store supplied keys encrypted and use them solely to provide the Service to Customer.
7. Acceptable use
Customer will not, and will not permit its users or Visitors to:
- use the Service to violate any law, infringe anyone’s rights, or generate or distribute content that is unlawful, deceptive, or harmful;
- attempt to manipulate an agent into bypassing its configured governance controls, executing unauthorized Actions, or revealing its instructions or other organizations’ data — including through prompt injection or jailbreaking — or probe, disrupt, overload, or gain unauthorized access to the Service or its infrastructure (coordinated security research is welcome via security@teaflask.com);
- resell, white-label, or provide the Service to third parties except by deploying it in Customer Properties as intended;
- reverse engineer the Service or use it to build a competing product, or use Outputs to train competing AI models;
- deploy the Service in Customer Properties that are directed at, or likely to be primarily accessed by, individuals under 18;
- configure the Service to solicit or process government identification numbers, full payment card numbers, or protected health information, unless expressly agreed with us in writing (the Teaflask Code always redacts password, payment card, and one-time-code fields it encounters on pages);
- use the Service for decisions that produce legal or similarly significant effects on individuals — including in medical, legal, financial, insurance, employment, or housing contexts — without review by a qualified professional before the decision or advice takes effect, and required disclosure that AI was used.
The Service is built on third-party foundation models, and use of the Service must also comply with the usage policies of the model providers behind it. We identify those providers, and their applicable policies, in our trust center and on request at legal@teaflask.com. We may update these acceptable-use requirements to the extent our providers require it, and will post material updates per Section 17.
8. Customer data
Customer owns Customer Data. Customer grants Teaflask a non-exclusive, worldwide, royalty-free license to host, process, transmit, and display Customer Data for the sole purpose of providing and securing the Service for Customer and as otherwise required by law. Teaflask may use aggregated, de-identified technical and usage data that does not identify Customer, its users, or Visitors, and does not reveal Customer Data content, to operate, secure, and improve the Service.
9. Confidentiality
Each party may receive non-public information from the other that is marked confidential or that reasonably should be understood as confidential — for Customer this includes Customer Data; for Teaflask, non-public product and security information. The receiving party will use such information only to perform under this Agreement, protect it with at least reasonable care, and not disclose it except to employees, affiliates, and contractors bound by comparable obligations. These obligations do not apply to information that is or becomes public without breach, was known before disclosure, is independently developed, or is rightfully received from a third party, and disclosure is permitted where required by law with reasonable notice where lawful. These obligations survive for three years after termination, and for Customer Data, for as long as we hold it.
10. Fees and billing
Free features are provided free of charge. Paid features are billed at the prices and on the terms presented at purchase or in an order form, processed by our payment provider. Where charges recur or are usage-based, the amount or the way it is determined, the billing timing, and the way to cancel are disclosed before you first pay, and you can cancel at any time in the dashboard, effective at the end of the current billing period. Fees are in U.S. dollars, exclusive of taxes (which Customer is responsible for, other than taxes on our income), and non-refundable except as expressly stated or required by law. We will give at least 30 days’ notice before a price increase takes effect for Customer.
11. Security
Teaflask maintains administrative, technical, and organizational safeguards appropriate to the nature of the data it processes, as described in the Privacy Policy. We will notify Customer without undue delay after confirming a breach of security affecting Customer Data, and will provide information reasonably required for Customer’s own legal obligations. Service status is published at status.teaflask.com; service-level commitments, where offered, are set out in the applicable order form.
12. Suspension
We may suspend or limit the Service (in whole or for specific capabilities) where reasonably necessary to: address a security risk or operational threat; respond to Customer’s material breach of Section 7 (Acceptable use); comply with law; or comply with an enforcement action of a model provider whose policies apply to Customer’s use. We will use reasonable efforts to notify Customer promptly, limit the suspension to what is necessary, and restore the Service once the cause is resolved.
13. Term and termination
This Agreement runs from acceptance until terminated. Customer may terminate at any time by deleting its organization or closing its account; either party may terminate for material breach uncured 30 days after written notice, and we may terminate free accounts with 30 days’ notice. On termination, Customer’s access ends and, except where law requires retention, termination is Customer’s instruction to us to delete Customer Data, which we will complete within a commercially reasonable period; Customer may export its data before termination and may request reasonable assistance within 30 days after. Sections that by their nature should survive (including 6.3, 6.4, 9, and 14 through 18) survive termination.
14. Warranties and disclaimers
Each party warrants that it has the right to enter into this Agreement. EXCEPT AS EXPRESSLY STATED IN THIS AGREEMENT, THE SERVICE AND ALL OUTPUTS ARE PROVIDED “AS IS” AND “AS AVAILABLE,” AND EACH PARTY DISCLAIMS ALL OTHER WARRANTIES, EXPRESS OR IMPLIED, INCLUDING MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, AND NON-INFRINGEMENT. WITHOUT LIMITING THE FOREGOING, TEAFLASK DOES NOT WARRANT THAT OUTPUTS ARE ACCURATE, COMPLETE, RELIABLE, FREE FROM BIAS OR ERROR, OR FIT FOR ANY PARTICULAR USE, THAT OUTPUTS WILL NOT INCORPORATE THIRD-PARTY DATA OR INFRINGE THIRD-PARTY RIGHTS, OR THAT THE SERVICE WILL BE UNINTERRUPTED OR ERROR-FREE.
15. Indemnification
By Teaflask. We will defend Customer against any third-party claim that the Service, used as permitted under this Agreement, infringes that third party’s intellectual property rights, and will indemnify the resulting damages finally awarded or agreed in settlement. This does not apply to claims arising from Customer Data, from combination with products or data not provided by us, or from use in violation of this Agreement. If the Service is subject to such a claim, we may modify it, procure the necessary rights, or terminate the affected portion with a prorated refund of prepaid fees.
By Customer. Customer will defend Teaflask against any third-party claim arising from Customer Data (including claims that it infringes or misappropriates third-party rights), from Customer Properties or Customer’s products and services, from Actions executed against connected systems under Customer’s configured policies, or from Customer’s breach of Section 5 or Section 7, and will indemnify the resulting damages finally awarded or agreed in settlement.
The indemnifying party’s obligations are conditioned on prompt notice, sole control of defense and settlement (no settlement admitting the other party’s fault without its consent), and reasonable cooperation.
16. Limitation of liability
TO THE MAXIMUM EXTENT PERMITTED BY LAW, NEITHER PARTY WILL BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, EXEMPLARY, OR PUNITIVE DAMAGES, OR ANY LOSS OF PROFITS, REVENUES, DATA, OR GOODWILL, EVEN IF ADVISED OF THE POSSIBILITY. EXCEPT FOR A PARTY’S INDEMNIFICATION OBLIGATIONS UNDER SECTION 15, ITS BREACH OF SECTION 9 (CONFIDENTIALITY), ITS GROSS NEGLIGENCE, FRAUD, OR WILLFUL MISCONDUCT, OR CUSTOMER’S PAYMENT OBLIGATIONS, EACH PARTY’S TOTAL CUMULATIVE LIABILITY ARISING OUT OF OR RELATING TO THIS AGREEMENT WILL NOT EXCEED THE GREATER OF (A) THE FEES PAID OR PAYABLE BY CUSTOMER FOR THE SERVICE IN THE 12 MONTHS BEFORE THE EVENT GIVING RISE TO LIABILITY AND (B) ONE HUNDRED U.S. DOLLARS ($100).
The disclaimers, exclusions, and limitations in Sections 14 through 16 form an essential basis of the bargain between the parties, and apply regardless of the theory of liability and even if a limited remedy fails of its essential purpose.
17. Changes to this Agreement
We may update this Agreement from time to time. For material changes, we will give at least 30 days’ notice before they take effect — by email to the account owner, in the dashboard, or both — and post the updated version, with its effective date, at this address. Continued use of the Service after the effective date constitutes acceptance; if Customer does not agree, its remedy is to terminate under Section 13 before the change takes effect. Non-material changes (such as clarifications) take effect on posting.
18. General
- Governing law and venue. This Agreement is governed by the laws of the State of Delaware, without regard to its conflict of laws rules and excluding the United Nations Convention on Contracts for the International Sale of Goods. The state and federal courts located in Delaware have exclusive jurisdiction, and each party consents to their jurisdiction and waives objections to venue.
- Entire agreement; order of precedence. This Agreement (with the policies it incorporates and any order form) is the entire agreement about the Service and supersedes prior discussions. Terms on a Customer purchase order or vendor form have no effect, even if acknowledged. If an order form conflicts with this Agreement, the order form controls for that order.
- Assignment. Neither party may assign this Agreement without the other’s consent, except to an affiliate or in connection with a merger, acquisition, or sale of substantially all assets, with notice.
- Notices. Legal notices to Teaflask go to legal@teaflask.com; notices to Customer go to the account owner’s email.
- Publicity. We may identify Customer by name and logo as a customer; Customer may opt out by emailing legal@teaflask.com.
- Miscellaneous. If a provision is unenforceable, the rest remains in effect. A waiver must be in writing. The parties are independent contractors. Neither party is liable for delay or failure caused by events beyond its reasonable control. Each party will comply with applicable export laws.
19. Contact
Questions about this Agreement: legal@teaflask.com. Waffer, Inc., 2261 Market Street, STE 86804, San Francisco, CA 94114.