treg terms privacy support docs
Legal

Treg Terms of Service

Last updated: 22 July 2026 Effective: 22 July 2026

The short version

  • What this is. Treg holds your API keys and OAuth connections server-side and lets your teammates and AI agents use them through a revocable token — without the key ever landing on a machine.
  • Your credentials stay yours. We store them encrypted, use them only to make the calls you or your team ask for, and never sell or mine them.
  • You are responsible for what you connect. Only upload credentials you have the right to use, and follow the terms of whatever upstream API sits behind them.
  • Free, and offered as-is. The hosted service is in early access with no uptime promise. Don't make it the only copy of anything you can't lose.
  • Self-hosting is separate. If you run your own registry, the source license governs — not this document.

This summary is for orientation only. The numbered sections below are the actual agreement.

01Who we are, and what these terms cover

Treg (also called tools-registry) is operated by Superdesign ("we", "us"). These Terms of Service (the "Terms") are a binding agreement between us and you — the person or organization using the service ("you").

They cover the hosted service we run at treg.superdesign.dev: the web dashboard, the API, the call proxy, the treg CLI when pointed at our servers, and everything reachable from them (together, the "Service").

They do not cover self-hosted instances. If you install treg on your own infrastructure, your relationship with us is governed by the source license alone. We have no access to your data and take on no obligations for that deployment.

By creating an account, signing in, or making a call through the Service, you accept these Terms. If you are accepting on behalf of a company, you confirm you're authorized to bind it.

02Your account

You sign in with an email address, either by one-time code or through a supported identity provider. You must be at least 16 years old and give a real, working address — invite links and sign-in codes go there, so a wrong address is a security problem, not a typo.

03Teams, roles, and who controls what

Every account gets a personal team, and you can create or join others. Within a team:

If you join a team you don't own, the team's owner effectively controls that workspace: they can revoke your access, see your call history in it, and delete shared content. Choose your teams accordingly.

04Credentials, and what we do with them

The point of the Service is holding credentials so you don't have to hand them out. Concretely:

Your obligations. You must have the right to store and use every credential you add, and the authority to grant your teammates and agents access through it. You are responsible for the calls made with your credentials — including calls made by AI agents you've pointed at the Service. An agent acting under your token is you, as far as these Terms are concerned.

Treat treg as a working vault, not a system of record. Keep your own copy of any credential you can't re-issue, and revoke upstream if you ever suspect compromise — revoking at the source is always faster and more complete than anything we can do for you.

05Upstream APIs and connected accounts

When you connect an account (Google Search Console, Google Analytics, Google Business Profile, Google Ads, YouTube, LinkedIn, Slack, X, or any API you register yourself), calls made through the Service are subject to that provider's terms as well as these. We are not a party to your relationship with them.

06Skills and content you upload

Skills, tool definitions, and their companion files are yours. You keep all rights in them; you grant us only the limited licence needed to store them, show them to the teammates you've shared them with, and run them when you ask us to. We don't use your skill content to train models.

You're responsible for what you put in them. Don't upload content you don't have the rights to, and don't put secrets in a skill's text — that's what the vault is for, and skill text is visible to every member of the team it lives in.

07Acceptable use

Don't use the Service to:

We apply per-member daily call caps, egress restrictions, and sandboxing to protect the Service. Circumventing them is a breach of these Terms.

08Early access, availability, and changes

The Service is in early access. It's free today, it changes often, and features can be added, altered, or withdrawn. We may change or discontinue the Service, and we'll make a reasonable effort to give notice before anything that would cause you to lose data.

There is no uptime commitment and no support commitment. We aim to be reliable and we answer email, but nothing here is an SLA.

If we introduce paid plans, we'll say so clearly in advance and no charge will apply to you without your explicit agreement.

09Suspension, termination, and deletion

You can leave at any time: delete a team from the dashboard, or email us to delete your account entirely. Deleting a team destroys its stored credentials, tools, and skills.

We may suspend or terminate an account or team — with notice where practical, immediately where necessary — if it breaches these Terms, endangers the Service or other users, or if we're required to by law. If we terminate you without cause, we'll give you a reasonable chance to export your content first.

On termination, your right to use the Service ends. Sections 04 (your obligations), 10, 12, 13, and 14 survive.

10No warranty

THE SERVICE IS PROVIDED "AS IS" AND "AS AVAILABLE", WITHOUT WARRANTIES OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, AND NON-INFRINGEMENT. We do not warrant that the Service will be uninterrupted, error-free, or secure against every attack, or that any call made through it will succeed.

Nothing in these Terms excludes liability that cannot lawfully be excluded, including for fraud or for death or personal injury caused by negligence.

11Open source and self-hosting

treg's source is public under the tools-registry License (Apache 2.0 plus additional terms). You may run your own registry for your own organization — that's expressly encouraged. You may not offer treg to third parties as a hosted, managed, or embedded service without our prior written authorization. The source licence, not these Terms, governs your use of the code itself.

12Limitation of liability

To the maximum extent permitted by law, neither party is liable for indirect, incidental, special, consequential, or punitive damages, or for lost profits, revenue, goodwill, or data, however caused.

Our total aggregate liability arising out of or relating to the Service is limited to the greater of (a) the amount you paid us for the Service in the twelve months before the claim, or (b) US$100. While the Service is free, that means US$100.

13Indemnity

You'll defend and indemnify us against claims, losses, and costs arising from your use of the Service in breach of these Terms — in particular, claims that you stored or used a credential you weren't entitled to use, or that calls you made violated an upstream provider's terms.

14Governing law and disputes

These Terms are governed by the laws of the State of Delaware, USA, without regard to its conflict-of-laws rules. The state and federal courts located in Delaware have exclusive jurisdiction, and both parties consent to venue there. If you're a consumer, this doesn't deprive you of the protection of mandatory laws in your country of residence.

15Changes to these Terms

We may update these Terms. If a change is material we'll notify account holders by email or an in-app notice before it takes effect, and the "last updated" date at the top always reflects the current version. Continuing to use the Service after a change means you accept it; if you don't, stop using the Service and delete your account.

16Contact

Questions about these Terms, or anything else: jason@superdesign.dev. Security reports are welcome and taken seriously — see SECURITY.md.


See also the Privacy Policy, which explains what data we hold and why.