Terms of service

Effective 23 July 2026. These terms govern your access to and use of foro.sh (the “service”), operated by DJH Tech, a sole proprietorship registered in the Netherlands (KvK 98346709, VAT NL005326176B46, Tweede Boerhaavestraat 55E, 1091 AL Amsterdam) — “we” and “us” in what follows. The service builds MCP servers from Git repositories you connect or project archives you upload and runs them on EU-hosted infrastructure at a stable https://<slug>.foro.sh URL. By creating an account, connecting a repository, or otherwise using the service, you agree to these terms. If you use the service on behalf of an organisation, you confirm you have authority to bind that organisation, and “you” includes it.

Our processing of personal data is described in the privacy policy, which forms part of your agreement with us for that purpose.

Eligibility and accounts

You must be able to form a binding contract under applicable law and must not be prohibited from using the service under applicable sanctions or export-control rules. You are responsible for your account credentials, for activity under your account and workspaces, and for keeping contact details accurate. Do not share sign-in credentials; invite teammates through workspace seats where your plan allows it. Notify us promptly at [email protected] if you suspect unauthorised access.

The service

When you connect a repository (or upload a project archive), we fetch or receive the code, validate configuration such as your pyproject.toml or package.json, build an image, and run a container for your project. We assign an immutable slug used for the public URL, container name, routing, and log paths. Secrets you store are encrypted at rest and injected only into your own container. Live and persisted logs and request metrics are provided so you can operate your server, as described in the privacy policy.

The service is in an early-access phase. Features, supported runtimes, and operational behaviour may change. We may restart, reschedule, or rebuild deployments for maintenance, capacity, security, or platform updates. Custom domains, auto-deploy, seats, retention, and other capabilities depend on your plan and on what we have shipped.

Third-party services you connect — Git providers, LLM endpoints for dashboard chat, custom domains’ DNS, and anything your MCP server calls — are governed by those providers’ terms. We are not responsible for their availability, policies, or charges.

Plans, quotas, and capacity

The service is offered on Free, Starter, Team, and Enterprise tiers. Each plan has its own server (project), seat, feature, and retention limits. Current base limits enforced in the product are: Free — 1 server, 1 seat, 24-hour metrics and log retention; Starter — 3 servers, 1 seat, 7-day retention; Team — 10 servers, 10 seats, 30-day retention; Enterprise — custom limits (with a base of 10 servers and 10 seats until overrides are set) and 90-day retention. Platform-wide live container capacity is also capped regardless of plan; when that ceiling is reached, new or restarted deployments may be refused until capacity frees up.

Paid plans may currently be granted manually or arranged through a demo or sales path; self-serve checkout is not yet the general path. We may change plan definitions, prices (when billed), and limits as the service evolves; material changes affecting existing customers are announced before they take effect. Downgrades do not forcibly delete running servers above the new limit, but you may be unable to create, start, or add seats until you are within the new limits.

Your content and responsibilities

You retain all rights to the code, configuration, secrets, archives, and other materials you provide (“your content”). You grant us a limited, worldwide, non-exclusive licence to fetch, copy, build, store, transmit, and run your content solely to provide and secure the service, including backups and logs as described in the privacy policy. That licence ends when your content is deleted from the service, subject to residual copies in rolling backups that expire on the schedule in the privacy policy.

You are solely responsible for your content and for everything your deployments do: tools they expose, data they process, outbound calls they make, and compliance with law and with third-party licences and terms. You must have the rights needed to deploy the code and to grant us the licence above. Do not store secrets you are not authorised to use. foro.sh is a deployment target, not a source-of-truth backup — keep your code in your own repository.

Acceptable use

You may use foro.sh to build, deploy, and operate MCP servers for lawful purposes within your plan limits. You must not use the service — or allow anyone else to use your account, workspace, or deployments — to do any of the following.

Illegal or harmful activity. Violate applicable law; infringe intellectual property, privacy, publicity, or other rights; traffic in stolen data or credentials; commit fraud, scams, or identity theft; or distribute, host, or link to child sexual abuse material or other illegal content.

Attacks and abuse. Create, distribute, or operate malware, ransomware, spyware, botnets, command-and-control infrastructure, phishing, or social-engineering kits; scan, probe, or attack systems you do not own or have explicit authorisation to test; conduct or amplify denial-of-service attacks; or use deployments as open proxies, anonymous relays, or egress for third-party abuse.

Platform integrity. Attempt to escape or weaken the container sandbox; access, alter, or exfiltrate data belonging to other customers or to foro.sh; interfere with other deployments or shared infrastructure; circumvent plan quotas, rate limits, authentication, billing, or access controls; or reverse-engineer the platform in order to defeat those controls.

Resource abuse. Mine cryptocurrency or run similar proof-of-work workloads; consume CPU, memory, disk, network, or build capacity far beyond ordinary use of your plan in a way that degrades the service for others; or use the platform primarily as bulk storage, a CDN, or a general-purpose VPS unrelated to running an MCP server.

Spam and product misuse. Send unsolicited bulk messages or automated outreach; harvest or scrape personal data without a lawful basis; impersonate foro.sh, another person, or another organisation; or resell, sublicense, or white-label the service except as expressly authorised in writing (for example under an Enterprise agreement).

High-risk and regulated misuse. Use deployments to process payments, store special-category or otherwise highly regulated personal data, or operate in a highly regulated sector in a way that would make foro.sh a regulated intermediary, without a prior written agreement covering that use. You must not use the service if you are prohibited from receiving it under applicable sanctions or export-control rules.

Good-faith security research reported to [email protected] (or a published security contact, if we designate one) is not a violation when it avoids harm to customers, data, and availability, and follows any published disclosure guidelines.

We may investigate suspected violations. Depending on severity, we may warn you, stop or remove deployments, throttle or reset resources, require remedial action, or suspend or terminate the account. We give notice where practicable; for activity that is illegal, poses an immediate security risk, or harms other customers, we may act without prior notice.

Our intellectual property

The service, including its software, design, documentation, and branding, is owned by us or our licensors. These terms do not grant you any right to use foro.sh marks except as needed to refer accurately to the service. Feedback you submit may be used freely to improve the service without obligation to you.

No warranty, no SLA

The service is provided “as is” and “as available.” To the fullest extent permitted by law, we disclaim all warranties, whether express, implied, or statutory, including merchantability, fitness for a particular purpose, and non-infringement. There is no uptime, latency, or support SLA on Free, Starter, or Team unless we agree otherwise in a separate written Enterprise agreement. We do not warrant that deployments will be uninterrupted, error-free, or secure against every threat, or that your MCP server will behave correctly for every client.

Liability

To the extent permitted by law, our liability for damages arising from the use of the service is limited to intent and gross negligence, and to foreseeable, typical damages in case of breach of an essential contractual obligation. Mandatory statutory liability — including for injury to life, body, or health, and liability under product liability law where applicable — is unaffected. We are not liable for losses caused by your content, your deployments, your misconfiguration, third-party services you choose, or force majeure events outside our reasonable control.

You will defend and indemnify us against claims, damages, and reasonable costs arising from your content, your use of the service in breach of these terms, or your violation of law or third-party rights, except to the extent caused by our intent or gross negligence.

Suspension and termination

You may stop using the service and delete your account at any time from the dashboard. Deletion removes your deployments and data as described in the privacy policy and is unrecoverable once completed.

We may suspend or terminate access immediately for material breach of these terms (including acceptable use), for legal or security risk, or for non-payment when billing applies. We may also discontinue the service or your access to it with at least 30 days’ notice when we wind down early access or a plan tier. Provisions that by nature should survive — including ownership, licence wind-down, disclaimers, liability limits, indemnity, and governing law — survive termination.

Changes

We may update these terms as the service evolves. We will change the effective date above and announce material changes to signed-in users before they take effect. Continued use after the effective date of an update constitutes acceptance. If you do not agree, stop using the service and delete your account before the change takes effect.

General

These terms are the entire agreement between you and us regarding the service, and supersede prior understandings on the same subject. If a provision is held unenforceable, the remainder stays in effect. Our failure to enforce a provision is not a waiver. You may not assign these terms without our consent; we may assign them in connection with a reorganisation, merger, or sale of assets. These terms are governed by the law of the Netherlands, without regard to conflict-of-law rules that would choose another jurisdiction. The courts of Amsterdam have exclusive jurisdiction, subject to mandatory consumer protections where they apply.

Questions about these terms: [email protected]. Privacy and data-subject requests: [email protected].