Terms of Use
These Terms are the agreement that governs the GrayPass website and the GrayPass platform: the SDK, the API, the hosted console, and the non-production sandbox.
Contents and legal documents
Acceptance
These Terms of Service (the "Terms") are a binding agreement between you and GrayPass, Inc. ("GrayPass," "we," "us," or "our"). They govern your access to and use of the GrayPass website, the GrayPass SDK, the GrayPass API, the hosted console, the non-production sandbox, and any related documentation and services (together, the "Services").
If you have a separate written agreement with us, including an order form or an evaluation agreement, that agreement controls for its subject matter and these Terms govern everything it does not address.
By accessing or using the Services, creating an account, or obtaining an API key, you accept these Terms. If you are using the Services on behalf of a company or other legal entity, you represent that you have authority to bind that entity, and "you" refers to that entity. If you do not agree to these Terms, do not use the Services.
The services
GrayPass operates one platform. The SDK reads interaction timing signals in the end user's browser and reduces them to derived features on the device. The API maintains Brainprint templates, evaluates policy, and returns authorization decisions with typed assurance to your systems. The hosted console provides keys, policy, and operational visibility.
The non-production sandbox and any demonstration environments are provided for evaluation and integration work. They are not production authorization systems, and you must not rely on them to protect production assets or sensitive information.
We may modify, suspend, or discontinue any part of the Services as they evolve. Where a change materially reduces the functionality of a paid Service, we will use reasonable efforts to give advance notice.
Accounts and API keys
You are responsible for the accuracy of the information associated with your account and for everything that happens under your API keys.
- Secret keys must be kept confidential, stored server-side, and rotated if you suspect exposure.
- Short-lived ct_ browser credentials may ship to the authenticated browser subject they name. Secret sk_ credentials and unsupported pk_ keys must not ship in client code.
- You must notify us promptly at tools@graypass.org if you become aware of unauthorized use of your keys or account.
We may suspend keys that show signs of compromise, abuse, or usage patterns that put the Services or other customers at risk. Where practical, we will contact you before or promptly after doing so.
Acceptable use
You agree not to misuse the Services. In particular, you will not:
- probe, scan, or test the vulnerability of the Services except through coordinated disclosure arranged by contacting us;
- interfere with service availability, including load testing without written permission;
- attempt to re-identify, reverse engineer, or reconstruct raw behavioral data from Brainprint templates or any other artifact of the Services;
- use the Services to authenticate or surveil individuals without a lawful basis and any legally required notice and consent;
- use the Services to infer emotion, personality, health, or any trait unrelated to control of an account or authorization of an action;
- use the Services in violation of applicable law, including biometric privacy, data protection, export control, and sanctions laws;
- resell, sublicense, or white-label the Services without a written agreement with us.
If you integrate the SDK into your product, you are responsible for presenting your end users with any notices and obtaining any consents required in your jurisdictions, including those described in our BIPA policy and GDPR documentation.
Privacy and behavioral data
Our handling of personal data is described in the Privacy Policy, the Data Privacy document, the BIPA policy, and the GDPR page. Those documents are part of how we deliver the Services, and we will not weaken the commitments in them retroactively for data already collected.
In short: the SDK reads interaction timings, not content; raw behavioral streams are not persisted; what we store is a Brainprint template, a revocable, tenant-scoped artifact; and deletion is available on request.
Fees and payment
GrayPass is sold through a time-boxed paid evaluation or an annual agreement. Paid usage is governed by the evaluation agreement or order form agreed between you and us. No public price list applies.
The service counts assured actions and active Brainprint months. Your contract names which meter is billed. Sandbox activity is not metered, and billing state never changes an authorization decision.
You are responsible for applicable taxes other than taxes on our income. If you believe an invoice is incorrect, contact us within thirty (30) days of the invoice date and we will work with you in good faith to resolve it.
Intellectual property
GrayPass and its licensors own the Services, including the SDK, API, models, documentation, site content, and branding. We grant you a limited, non-exclusive, non-transferable, revocable license to use the SDK and API as documented, solely to integrate the Services into your products while these Terms are in effect.
You own your applications and your data. You grant us the rights in your data that are necessary to operate the Services, consistent with the privacy documents referenced in Section V.
Feedback
If you send us feedback, ideas, or suggestions, you grant us a perpetual, irrevocable, worldwide, royalty-free license to use them without restriction or obligation to you.
Disclaimers
THE SERVICES ARE PROVIDED "AS IS" AND "AS AVAILABLE." TO THE MAXIMUM EXTENT PERMITTED BY LAW, WE DISCLAIM ALL WARRANTIES, EXPRESS OR IMPLIED, INCLUDING MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, AND NON-INFRINGEMENT.
Assurance is probabilistic by nature. We return typed claim statuses with coverage, freshness, reason codes, and limitations so that your policy layer can decide what to do with uncertainty. Calibrated confidence is not emitted until a real-human calibration exists.
We publish no availability target, recovery objective, latency figure, or continuous-engine accuracy figure because none has been measured externally for the canonical build.
Measures that raise the bar against replay, automation, and operator substitution are described as raising the bar, not as immunity. No security product eliminates every technique, no behavioral signal is reliable on a fully compromised device, and we do not represent that the Services are.
Limitation of liability
TO THE MAXIMUM EXTENT PERMITTED BY LAW, NEITHER PARTY WILL BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES, OR ANY LOSS OF PROFITS, REVENUE, DATA, OR GOODWILL, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.
EXCEPT FOR YOUR PAYMENT OBLIGATIONS, YOUR INDEMNIFICATION OBLIGATIONS, OR EITHER PARTY'S WILLFUL MISCONDUCT, EACH PARTY'S TOTAL LIABILITY ARISING OUT OF OR RELATING TO THESE TERMS IS LIMITED TO THE GREATER OF (A) THE AMOUNTS YOU PAID US FOR THE SERVICES IN THE TWELVE (12) MONTHS BEFORE THE EVENT GIVING RISE TO LIABILITY AND (B) ONE HUNDRED U.S. DOLLARS (US$100).
Indemnification
You will defend and indemnify GrayPass against third-party claims arising from (a) your applications and services, (b) your use of the Services in violation of these Terms or applicable law, or (c) your failure to provide legally required notices to, or obtain legally required consents from, your end users.
Term and termination
These Terms apply for as long as you use the Services. You may stop using the Services at any time. We may suspend or terminate access for material breach that remains uncured fifteen (15) days after notice, or immediately for breaches involving abuse, security, or law.
Upon termination, your license to the SDK and API ends and outstanding fees become due. Sections that by their nature should survive (including IV, V, VII, IX, X, XI, and XIV) survive termination. Data deletion on termination is handled as described in the Data Privacy document.
Changes to these terms
We may update these Terms as the Services evolve. If a change is material, we will post the updated Terms here with a new effective date and, for account holders, make reasonable efforts to notify you by email. Continued use of the Services after the effective date constitutes acceptance of the updated Terms.
Governing law and contact
These Terms are governed by the laws of the State of Delaware, USA, excluding its conflict-of-laws rules. The parties will first attempt in good faith to resolve any dispute informally; unresolved disputes will be brought exclusively in the state or federal courts located in Delaware, and both parties consent to their jurisdiction.
Questions about these Terms: tools@graypass.org. Legal notices to GrayPass must be sent to the same address with the subject "Legal notice."