Terms of Service

Effective Date: August 14, 2026 · Last Updated: August 14, 2026

1. Agreement and Order of Precedence

These Terms of Service (“Terms”) govern access to and use of SuperPenguin and related websites, dashboards, desktop applications, software development kits, APIs, documentation, integrations, AI-assisted features, and support services (collectively, the “Services”) provided by Carrot Labs AI, Inc.(“Carrot Labs,” “we,” “us,” or “our”).

By creating an account, accepting an Order, connecting a device or integration, or otherwise accessing or using the Services, you agree to these Terms. If you use the Services for a company or other entity, you represent that you have authority to bind that entity, and “Customer” and “you” mean that entity. If you do not agree, do not use the Services.

An ordering document, statement of work, or other written order accepted by both parties is an “Order.” If an Order conflicts with these Terms, the Order controls for that Order. A data processing addendum (“DPA”) executed by the parties controls over these Terms solely for its subject matter.

2. Definitions

  • “Authorized User” means an employee, contractor, or other individual Customer permits to use the Services under its account.
  • “Customer Data”means data, content, records, credentials, and other information submitted to, imported into, or collected by the Services at Customer's or an Authorized User's direction.
  • “Documentation” means our published technical and usage documentation for the Services.
  • “Organization Administrator” means an Authorized User whom Customer permits to manage its workspace, users, settings, integrations, access, or billing.
  • “Service Data” means diagnostic, operational, usage, and performance information generated by the operation of the Services. Service Data does not include prompt text, source file contents, or raw model responses.

3. Eligibility and Authority

You must be at least 18 years old, or the age of legal majority where you live, to create an account. Authorized Users may use an account provisioned by their employer or another organization if legally permitted to do so. You represent that information you provide is accurate and that you are not prohibited from using the Services under applicable law.

4. Accounts, Workspaces, and Administrators

Each Authorized User must use an individual account and keep credentials, API keys, and device authorization codes secure. Customer is responsible for activity under its accounts, for maintaining an accurate list of Authorized Users, and for promptly revoking access when it is no longer authorized. Please notify us promptly of suspected unauthorized access.

Organization Administrators may manage workspace membership, permissions, provider connections, billing, data controls, and access to organization-level analytics. Depending on the Customer's settings and plan, administrators and other authorized viewers may see data associated with individual Authorized Users, including usage, costs, coding activity, and pull-request attribution.

Customer is responsible for providing all notices and obtaining all rights, permissions, and consents needed to invite Authorized Users, configure organization policies, and process workplace or employee data through the Services. Customer must comply with applicable privacy, employment, labor, monitoring, and communications laws. Customer must not use estimates generated by the Services as the sole basis for hiring, termination, compensation, promotion, or other consequential employment decisions.

5. Access to the Services and Software License

Subject to these Terms and any applicable Order, we grant Customer a limited, non-exclusive, non-transferable, non-sublicensable right during the applicable subscription term to access and use the Services for Customer's internal business purposes. Customer may permit its Authorized Users to do so within purchased plan limits.

We grant Customer a limited, revocable, non-exclusive, non-transferable, non-sublicensable license to install and use SuperPenguin desktop software and SDKs solely with the Services and in accordance with the Documentation. Software may download or notify users about updates. Open-source components are governed by their applicable licenses, which control if they conflict with this paragraph.

6. Customer Responsibilities and Acceptable Use

Customer is responsible for its Customer Data, Authorized Users, systems, and decisions made using the Services. Customer will use the Services only in accordance with applicable law, these Terms, the Documentation, and any applicable Order.

Customer and Authorized Users must not:

  • Access or use the Services for an unlawful, fraudulent, or unauthorized purpose, or to violate another person's rights.
  • Upload malicious code; probe, scan, or test vulnerabilities without written permission; or disrupt the integrity, availability, or performance of the Services.
  • Attempt to gain unauthorized access to the Services or another customer's accounts, systems, or data.
  • Reverse engineer, decompile, disassemble, or seek to discover non-public source code or underlying components, except to the extent a restriction is prohibited by law or an applicable open-source license.
  • Copy, resell, sublicense, or provide the Services to third parties as a standalone product without our written permission.
  • Circumvent plan limits, usage controls, or security measures, or use automated means to access the Services in a manner not authorized by the Documentation.
  • Submit data to the Services unless Customer has the rights and permissions needed for us and our subprocessors to process it as described in these Terms.

7. Customer Data and Service Data

As between the parties, Customer retains its rights in Customer Data. Customer grants us and our subprocessors a worldwide, non-exclusive license to host, copy, transmit, process, display, and otherwise use Customer Data only as necessary to provide, maintain, secure, and support the Services; comply with law; and carry out Customer's documented instructions.

We may collect and use Service Data to operate, secure, support, and improve the Services and to produce analytics. We may also create and use aggregated or de-identified information that does not reasonably identify Customer or an Authorized User. We will not use Customer Data to train a general-purpose machine-learning model unless Customer expressly opts in.

Customer is responsible for the legality, quality, and accuracy of Customer Data and for maintaining appropriate backups of data it requires. Data access, export, retention, and deletion are subject to the functionality of the Services, the Privacy Policy, any applicable DPA, and legal retention obligations.

8. Desktop and AI Coding Data

8.1 Desktop Synchronization

When an Authorized User connects SuperPenguin Desktop to a Customer workspace, the application periodically reads supported coding-tool and local repository records on that device and synchronizes eligible data while the user remains signed in. Signing out stops new synchronization from that device.

Baseline synchronization may include account, organization, and device identifiers; session or conversation identifiers and timestamps; model, mode, tool, provider-route, token, request, context-window, usage, and cost-estimate data; repository, workspace, branch, and file-path metadata; commit and pull-request metadata; code hashes; aggregate line, character, edit, and tool-call counts; environment configuration names and token estimates; and synchronization or error information.

Baseline synchronization does not include source file contents, raw model responses, or raw tool output. Prompt text is not uploaded by Desktop by default, and prompt-derived session titles are not retained by the Services by default. Some metadata, such as a file path, repository name, or branch name, may nevertheless contain text selected by an Authorized User or their organization.

8.2 Individual Prompt and Analysis Controls

An Authorized User may separately enable encrypted prompt storage. When enabled, SuperPenguin uploads prompt text after applying best-effort redaction and stores it encrypted to support features such as work-context and pull-request matching. Because automated redaction cannot identify every secret or item of personal information, Authorized Users should not include sensitive information in prompts unless authorized to do so. Disabling prompt storage deletes prompt text stored for that user, subject to limited backup and legal-retention exceptions.

Semantic matching and remote semantic analysis are separate controls and are off by default. If remote semantic analysis is enabled, eligible matching inputs may be sent to a hosted model provider. Available controls may vary by coding tool, plan, and feature version.

8.3 Organization Policies and Usage-Limit Sharing

Depending on the Customer's plan, an Organization Administrator may allow each member to choose whether to share company-account usage-limit summaries or may require that sharing as an organization policy. An affected Authorized User will be shown a notice and asked to acknowledge a required-sharing policy before the relevant upload begins.

Usage-limit sharing is designed to transmit current utilization percentages, reset times, and reporting status, not provider credentials, prompt text, source code, or raw model responses. When a provider account combines personal and business activity, the provider's reported quota may not allow SuperPenguin to separate those categories.

9. SDKs, APIs, and Optional Content Capture

API keys issued by SuperPenguin are for Customer's authorized use only. Customer must protect them, rotate or revoke compromised keys, and is responsible for requests made with its keys. We may revoke or limit a key that is compromised, misused, or threatens the Services.

By default, SuperPenguin SDK telemetry is intended to collect request-level cost and operational metadata, such as token counts, model, provider, latency, and Customer-supplied attribution tags, rather than prompt or response content or provider API keys.

Certain plans may offer a separate organization-controlled option to capture sampled text prompts and outcomes for analysis. If Customer enables that feature, eligible content is transmitted after supported filtering and best-effort redaction and is encrypted at rest. Customer is responsible for configuring the feature appropriately and for providing notices and obtaining permissions from its end users. Desktop prompt controls described in Section 8 are separate from this SDK content-capture option.

10. Third-Party Services and Integrations

The Services may connect with AI providers, cloud platforms, source-control and coding tools, notification services, payment processors, analytics services, and other third-party products selected or authorized by Customer (“Third-Party Services”). Customer authorizes us to access and process the data and perform the actions reasonably necessary to provide each enabled integration.

Customer represents that it is authorized to provide credentials and retrieve data from each Third-Party Service it connects. Credentials retained by SuperPenguin are encrypted at rest and used to provide and maintain the requested integration. Customer may disconnect an integration through available settings; disconnecting stops future access by that connection but does not automatically delete data already imported into SuperPenguin.

Third-Party Services are governed by their own terms and privacy policies. We do not control and are not responsible for their availability, security, changes, data accuracy, or fees. Features that depend on a Third-Party Service may be unavailable if that service changes, suspends, or terminates access.

11. AI-Assisted Features and Analytics

Some features use hosted machine-learning models to answer questions, analyze permitted inputs, or generate recommendations. When an Authorized User uses such a feature, we may send their input, relevant conversation history, and limited account or organization context to a model provider acting on our behalf.

Model outputs, cost estimates, forecasts, AI-versus-human classifications, pull-request matches, attribution results, optimization recommendations, provider-limit reports, and other analytics may be incomplete, delayed, or inaccurate. They are provided for informational purposes and may differ from provider invoices, source-control records, or actual activity. Customer is responsible for independently validating information used for financial, employment, legal, operational, or other consequential decisions.

Customer retains its rights in inputs. Subject to applicable law and third-party rights, Customer may use outputs generated for it. We do not represent that an output is unique or that it does not resemble output provided to another customer.

12. Orders, Fees, and Payment

12.1 Plans and Fees

Customer will pay the fees stated at checkout or in an Order. Fees may be based on a fixed subscription, seats, managed spend, usage, a percentage of managed spend, or a combination of these measures. Our records and the calculation method stated in the applicable Order or plan description determine billable usage, subject to correction of documented errors.

12.2 Billing and Taxes

Customer authorizes us and our payment processor to charge the selected payment method for amounts due. Invoiced amounts are due within the period stated in the Order. Fees are exclusive of taxes, duties, and similar governmental assessments, and Customer is responsible for them except taxes based on our net income. Customer will provide valid tax-exemption documentation when applicable.

12.3 Renewal, Cancellation, and Pricing Changes

Unless an Order states otherwise, paid subscriptions renew for successive periods equal to the initial subscription period until canceled before renewal. Cancellation takes effect at the end of the then-current paid period. Except where these Terms, an Order, or applicable law provides otherwise, fees are non-cancelable and non-refundable and unused time is not credited.

We may change online plan pricing by providing at least 30 days' notice, with the change taking effect at the next renewal. Pricing in an Order changes only as stated in that Order or at renewal after notice.

12.4 Trials and Plan Limits

Trials and promotional access may be modified or ended as stated when offered. Unless otherwise stated, a trial does not automatically convert to a paid plan. When a trial expires, historical dashboards may remain available while new imports, synchronization, or configuration changes are paused. Plans may include feature, seat, spend, retention, or usage limits.

12.5 Late Payment

If an undisputed amount is overdue, we may suspend paid features after providing notice and a reasonable opportunity to pay. Late amounts may accrue interest at the lesser of 1.5% per month or the maximum rate permitted by law, plus reasonable collection costs. Customer must raise a good-faith billing dispute before the due date or within 30 days after the applicable charge, whichever is later.

13. Confidentiality

“Confidential Information” means non-public information disclosed by one party (“Discloser”) to the other (“Recipient”) that is identified as confidential or reasonably should be understood to be confidential. Customer Data is Customer's Confidential Information. Our non-public technology, security information, pricing, and product plans are our Confidential Information.

Recipient will use Confidential Information only to exercise its rights and perform its obligations under the agreement and will protect it using at least reasonable care. Recipient may disclose it only to personnel, professional advisers, and subprocessors who need to know it and are bound by confidentiality obligations at least as protective as these Terms.

Confidential Information excludes information that Recipient can demonstrate was lawfully known without restriction, becomes public without breach, is received lawfully from a third party, or is independently developed without use of the Confidential Information. Recipient may disclose information when legally required, provided it gives advance notice when legally permitted and reasonable assistance at Discloser's expense.

14. Privacy, Security, and Data Processing

Our Privacy Policy explains how we collect, use, and disclose personal information. We maintain administrative, technical, and organizational safeguards designed to protect Customer Data, as described in our Security Policy. No method of storage or transmission is completely secure, and we cannot guarantee absolute security.

If we process personal data on Customer's behalf and applicable law requires a data processing agreement, the parties will enter into a DPA. We may use subprocessors to provide the Services and remain responsible for their performance to the extent required by the applicable DPA or law. We will notify Customer of a confirmed breach of Customer Data as required by applicable law and any applicable DPA.

15. Intellectual Property and Feedback

The Services, Documentation, branding, and underlying technology are owned by Carrot Labs and its licensors and are protected by intellectual-property laws. Except for the limited rights expressly granted in these Terms, neither party grants the other any rights by implication, estoppel, or otherwise.

If Customer or an Authorized User gives us feedback or suggestions, we may use them without restriction or obligation, provided we do not identify Customer publicly as the source without permission.

16. Service Changes, Availability, and Beta Features

We may improve or change the Services over time. We will not materially reduce the core functionality of a paid Service during a committed Order term without reasonable notice, except when needed to address law, security, abuse, or a Third-Party Service change. We do not guarantee uninterrupted or error-free operation or that every feature will remain available.

Preview, beta, evaluation, and experimental features may be incomplete, change without notice, and be discontinued at any time. They are provided as-is, may be subject to additional limits, and should not be used for production-critical purposes.

17. Warranties and Disclaimers

We warrant that paid Services will perform in all material respects in accordance with the applicable Documentation. If Customer reports a reproducible breach of this warranty, we will use commercially reasonable efforts to correct it. If we cannot do so within a reasonable period, Customer may terminate the affected paid Service and receive a prorated refund of prepaid, unused fees for the terminated portion. This is Customer's exclusive remedy for breach of this warranty.

EXCEPT FOR THE EXPRESS WARRANTY ABOVE AND TO THE MAXIMUM EXTENT PERMITTED BY LAW, THE SERVICES ARE PROVIDED “AS IS” AND “AS AVAILABLE.” CARROT LABS DISCLAIMS ALL IMPLIED OR STATUTORY WARRANTIES, INCLUDING MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, NON-INFRINGEMENT, ACCURACY, AND ANY WARRANTY ARISING FROM COURSE OF DEALING OR USAGE OF TRADE.

18. Indemnification

18.1 By Customer

Customer will defend Carrot Labs and its affiliates, officers, directors, and personnel against a third-party claim arising from Customer Data; Customer's or an Authorized User's unlawful use of the Services; or Customer's breach of Sections 4 or 6, and will pay resulting damages, settlements, and reasonable attorneys' fees.

18.2 By Carrot Labs

We will defend a Customer purchasing paid Services against a third-party claim that Customer's authorized use of the Services infringes a United States patent, copyright, or trademark, and will pay resulting damages, settlements, and reasonable attorneys' fees. We have no obligation for claims caused by Customer Data, Third-Party Services, unauthorized modifications or combinations, continued use after notice, or use contrary to the Documentation.

If such a claim may prevent use of the Services, we may obtain the right to continue use, modify or replace the affected Service, or terminate it and refund prepaid, unused fees for the terminated portion.

18.3 Process

The indemnified party must promptly notify the indemnifying party and provide reasonable cooperation. The indemnifying party controls the defense and settlement, but may not settle a claim in a manner that admits fault by or imposes non-monetary obligations on the indemnified party without its consent, not to be unreasonably withheld.

19. Limitation of Liability

TO THE MAXIMUM EXTENT PERMITTED BY LAW, NEITHER PARTY WILL BE LIABLE FOR INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, EXEMPLARY, OR PUNITIVE DAMAGES, OR FOR LOST PROFITS, REVENUE, BUSINESS OPPORTUNITIES, OR GOODWILL, ARISING OUT OF OR RELATED TO THE SERVICES, EVEN IF ADVISED THAT SUCH DAMAGES WERE POSSIBLE.

TO THE MAXIMUM EXTENT PERMITTED BY LAW, EACH PARTY'S TOTAL AGGREGATE LIABILITY ARISING OUT OF OR RELATED TO THE SERVICES WILL NOT EXCEED THE GREATER OF (A) THE FEES PAID OR PAYABLE BY CUSTOMER FOR THE SERVICES GIVING RISE TO THE CLAIM DURING THE 12 MONTHS BEFORE THE EVENT GIVING RISE TO LIABILITY OR (B) $100.

These limitations do not apply to Customer's payment obligations, a party's fraud or willful misconduct, or liability that cannot be limited by law. An Order may provide different liability terms.

20. Term, Suspension, and Termination

These Terms begin when Customer first accepts them or uses the Services and continue until all accounts and Orders governed by them end. Customer may stop using free Services at any time and may cancel a paid subscription as described in Section 12.

Either party may terminate for a material breach if the breach is not cured within 30 days after written notice. We may suspend affected access immediately if reasonably necessary to prevent a security threat, unlawful activity, material harm to the Services or another customer, or use prohibited by Section 6. When practicable, we will provide notice and limit the suspension to the affected portion of the Services. Overdue accounts are handled under Section 12.5.

We may discontinue a free Service with reasonable notice. We may terminate a paid Service for convenience only at the end of the then-current subscription term, unless we provide a prorated refund of prepaid, unused fees for the terminated portion.

Upon termination, Customer's rights to use the affected Services end. Customer should export required data using available functionality before termination. We will delete or retain Customer Data as described in the Privacy Policy, an applicable DPA, and applicable law. Sections that by their nature should survive termination will survive, including payment, confidentiality, intellectual property, disclaimers, indemnification, limitations of liability, and general terms.

21. Governing Law and Disputes

These Terms and any dispute arising from them are governed by the laws of the State of Delaware, without regard to conflict-of-laws rules. The state and federal courts located in Delaware have exclusive jurisdiction, and each party consents to their personal jurisdiction and venue. Either party may seek injunctive or other equitable relief in any court of competent jurisdiction to protect intellectual property, Confidential Information, or security.

22. Changes to These Terms

We may update these Terms from time to time. We will revise the “Last Updated” date and provide notice through the Services or by email for material changes. Unless a change is required sooner by law or to address an urgent security or abuse issue, a material change to a paid Customer's rights or obligations will take effect at its next renewal or 30 days after notice, whichever is later. Continued use after the effective date of updated Terms constitutes acceptance.

23. General Terms

Neither party may assign the agreement without the other party's consent, except to an affiliate or in connection with a merger, acquisition, corporate reorganization, or sale of substantially all relevant assets, provided the assignee assumes the assigning party's obligations. Customer may not assign to a direct competitor of Carrot Labs without our consent.

Neither party is liable for delay or failure caused by events beyond its reasonable control, except for payment obligations. The parties are independent contractors. These Terms create no partnership, franchise, joint venture, agency, fiduciary, or employment relationship and no third party is a beneficiary.

Customer will comply with applicable export-control, sanctions, and anti-corruption laws. Notices may be delivered electronically to the account email or through the Services. Legal notices to us must also be sent to the email in Section 24.

If a provision is unenforceable, it will be modified to the minimum extent necessary and the remaining provisions remain in effect. Failure to enforce a provision is not a waiver. Headings are for convenience only. These Terms, the applicable Orders and DPA, and documents expressly incorporated by them are the entire agreement concerning the Services and supersede prior agreements on that subject.

24. Contact Us

Questions or legal notices about these Terms may be sent to: