Legal
Terms of Service
Agreement
These Terms of Service (“Terms”) govern access to and use of Candler at candler.dev and related applications, APIs, and services (the “Service”). By creating an account or using the Service, you agree to these Terms.
Use of Candler is also subject to the Acceptable Use Policy at https://candler.dev/acceptable-use, which is incorporated into these Terms by reference. Privacy practices are described in the Privacy Policy at https://candler.dev/privacy.
Eligibility and account responsibility
You must be at least 16 years old, or the minimum age of digital consent in your country if higher, to create an account. If you use the Service on behalf of an organization, you represent that you have authority to bind that organization.
You are responsible for your account, the accuracy of registration information, and all activity that occurs under your credentials. You must keep your password, recovery codes, authenticator devices, and session devices under your control. Notify us promptly at the contact below if you believe your account has been compromised.
Candler does not guarantee that unauthorized access to your devices, email inbox, or reused passwords can be prevented. Secure login is a shared responsibility.
Candler Vault
Vault lets you store project secrets such as API keys and environment variables. Secret values are stored as ciphertext using AES-256-GCM. Candler does not keep a plaintext value column for Vault secrets.
You are responsible for the secrets you store, for classifying them correctly, and for rotating them if a device, account, or integration is compromised. Reveal and copy of Vault values may require additional authentication (step-up). Metadata about secrets (names, environment, timestamps, and similar) may be processed unencrypted so the workspace can function.
Authenticator
Candler Authenticator stores TOTP seeds so you can generate one-time codes. Seeds are stored encrypted at rest with AES-256-GCM. Generated codes are produced on demand and are not stored as a historical code log.
Authenticator is a convenience aligned with standard TOTP. It is not a substitute for keeping backup factors. Losing access to Candler and to your other factors may lock you out of third-party accounts that depend on those seeds.
Recovery Codes
Recovery code sets you store in Candler are encrypted at rest with AES-256-GCM. Recovery codes generated for your Candler login are shown once when created. Candler stores only what is required to verify and consume them.
You must store recovery codes in a place you control. Candler cannot reconstruct a discarded one-time recovery code for you.
Candler Cloud, backups, and Restore to Device
Candler Cloud stores files you upload in private object storage. Access is authorized by the Service using short-lived signed requests. Cloud buckets are not public. Storage quotas are enforced server-side and currently include 10 GB on Free, 50 GB on Candler Pro, 500 GB on Pro + Cloud 500, and 1 TB on Pro + Cloud 1 TB. Quotas and plan names may change.
Restore to Device packages selected Cloud content for download to a machine you control. Restores can fail, be canceled, or be incomplete. You remain responsible for verifying restored files before relying on them.
Candler does not guarantee that backups are complete, continuous, or free from corruption, and does not guarantee that Cloud objects cannot be lost. You should maintain independent backups of irreplaceable data.
Subscriptions, plans, and cancellation
Paid plans are billed through Stripe. Current published launch prices are Candler Pro at US$18 per month, Pro + Cloud 500 at US$29 per month, and Pro + Cloud 1 TB at US$39 per month, plus a Free plan with limited Cloud storage. Prices, entitlements, and taxes may change.
Unless required by law or stated at checkout, fees are non-refundable. Canceling stops future renewal charges; you generally retain access through the end of the paid period. Failed payments may result in suspension or reversion to Free entitlements.
You authorize Candler and Stripe to store billing metadata necessary to operate subscriptions, invoices, and customer portals. Candler does not store full payment-card numbers on its own servers.
Third-party services and integrations
Candler is designed to bridge tools you already use, including GitHub, Vercel, Supabase, Stripe, Cloudflare, and others. Those providers have their own terms. Candler does not replace them and is not responsible for their availability, data handling, or billing.
You are responsible for the credentials, webhooks, and authorizations you connect. Revoke access in the third-party product if you stop using the integration.
Candler Agent
Candler Agent can help inspect workspace metadata and propose actions you authorize. Agent traffic may be processed by model providers such as OpenAI when the feature is enabled. Prompts and tool payloads are filtered for common secret patterns, and Agent is designed not to receive raw Vault secret values as a matter of product architecture. Filtering is not perfect.
You must review Agent output before acting on it. You remain responsible for actions you approve, including any effect on third-party systems. Do not instruct Agent to attack systems, steal credentials, or otherwise violate the Acceptable Use Policy.
Your content and license to operate the Service
You retain ownership of content you submit, including project metadata, files, conversation text, and configuration. You grant Candler a worldwide, non-exclusive license to host, transmit, encrypt, back up, display, and otherwise process that content solely as needed to provide and secure the Service.
You represent that you have the rights needed to submit the content and that it does not violate law or third-party rights.
Prohibited use
You may not use the Service in violation of the Acceptable Use Policy, including illegal activity, malware distribution, unauthorized access, phishing, infrastructure abuse, or attempts to disrupt Candler or third-party systems.
Availability, beta features, and security limitations
Candler is provided as a developing product. Features may be offered in beta, change, or be withdrawn. We do not warrant uninterrupted or error-free operation.
Candler uses encryption, tenant isolation, access controls, and logging as described on the Security page, but no internet service is absolutely secure. Candler does not guarantee that data cannot be lost, accessed without authorization, or affected by defects, provider outages, or your own device security.
Suspension and termination
We may suspend or terminate access if you violate these Terms, if required by law, or if needed to protect the Service or other users. You may stop using the Service and close your account by contacting hello@candler.dev.
After termination, we may delete or restrict access to content in accordance with the Privacy Policy and operational backups. You should export anything you need before you leave.
Disclaimers
THE SERVICE IS PROVIDED “AS IS” AND “AS AVAILABLE.” TO THE MAXIMUM EXTENT PERMITTED BY LAW, CANDLER DISCLAIMS WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, AND NON-INFRINGEMENT, AND ANY WARRANTY THAT THE SERVICE WILL BE SECURE, ERROR-FREE, OR FREE OF DATA LOSS.
Limitation of liability
TO THE MAXIMUM EXTENT PERMITTED BY LAW, CANDLER AND ITS OPERATORS WILL NOT BE LIABLE FOR INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, EXEMPLARY, OR PUNITIVE DAMAGES, OR FOR LOST PROFITS, REVENUE, DATA, OR GOODWILL, EVEN IF ADVISED OF THE POSSIBILITY.
TO THE MAXIMUM EXTENT PERMITTED BY LAW, TOTAL LIABILITY ARISING OUT OF THE SERVICE WILL NOT EXCEED THE GREATER OF THE AMOUNTS YOU PAID TO CANDLER FOR THE SERVICE IN THE THREE MONTHS BEFORE THE CLAIM OR ONE HUNDRED U.S. DOLLARS (US$100).
Indemnity
You will defend and indemnify Candler and its operators against claims arising from your content, your use of the Service, your integrations, or your violation of these Terms or applicable law.
Changes to these Terms
We may update these Terms. The version identifier and effective date appear on this page. Material changes that require a new agreement will be presented in the product for acceptance before continued use of the workspace. Continued use after an informational update that does not require re-consent constitutes acceptance of the revised Terms where permitted by law.
Governing law and disputes
The operating jurisdiction for Candler is not yet finalized for public launch. Until a later revision names a governing law and venue, the parties will attempt to resolve disputes in good faith. Nothing in this section limits non-waivable consumer protections that apply to you.
Contact
Questions about these Terms: legal@candler.dev or hello@candler.dev.