Agentknock · Full Disclosure
Service terms
Last updated ·
These terms govern your use of Agentknock's hosted services.
1. Operator and scope
Agentknock is operated by Full Disclosure, Business ID 3639691-6, at Taka-Niipperin tie 12, 02970 Espoo, Finland (“Full Disclosure”, “we”, “us”). These terms cover the hosted relay, optional cloud AI review and subscriptions provided by us.
The customer (“you”) may be an individual consumer or a business. If you act for an organisation, you must have authority to enter into this agreement for it. Consumer protections apply when you qualify as a consumer under applicable law. Sections 6 and 9 explain the rights that the limitations in these terms do not restrict.
For contractual enquiries, withdrawal requests and complaints, contact agentknock@fulldisclosure.fi. Include enough information to identify the matter, such as a relevant order reference. Do not send passwords, private keys or other secret values.
2. Software licences and hosted infrastructure
Agentknock lets you hold credentials on your phone and control their use by paired clients. The hosted relay connects those devices. Core features currently available without a subscription include local credential storage, pairing, manual approval and local approval settings. Paid access enables optional cloud AI review; buying access does not automatically enable AI for every credential or client.
Use compatible, updated devices and software, and the connectivity described in the service requirements. The current app and CLI workflow requires our deployed relay, including for manual approval and local approval settings. The phone must be available for credential delivery and signing, including uses approved automatically.
The app and CLI remain governed by their open-source licences; these terms do not reduce your rights under those licences. Source-code availability for any component does not include hosting or a commitment to operate or fund our deployment.
Core relay use is currently free. Hosting has ongoing costs, and free access has no minimum hosting period or lifetime entitlement. The free relay hosting provisions explain when access may change or end.
The data-processing agreement in section 13 forms part of these terms where we process personal data on your behalf. The privacy notice explains how personal data is handled, including cloud review context and retention.
3. Authorised use and security
Use the service only with credentials, systems and information that you are authorised to use. You are responsible for the instructions and access settings you choose, the clients you pair, and the permissions granted by your credentials. You must not use the service unlawfully or seek unauthorised access.
You must not overload the hosted service with excessive requests or traffic, interfere with its security or availability, or bypass its authentication, usage limits or other access controls. Do not evade a restriction by using other installations, devices, clients or identities. These restrictions govern use of our hosted infrastructure.
Protect your phone and paired computers, check pairing codes, and grant credentials only the permissions needed for their purpose. Maintain an independent way to recover access to the underlying services. We cannot reconstruct secret values or private keys lost from your devices.
An approval controls credential delivery or a signing operation. It does not confine the receiving program's later actions. Client-supplied command details may be incomplete or misleading, and Agentknock does not sandbox the command. A program that receives a credential may copy or disclose it. Revoking access in Agentknock does not invalidate a copy already obtained; revoke or rotate it with the service that accepts it. The security model explains these boundaries.
4. AI review and automated decisions
Selecting AI mode delegates eligible approval decisions to an AI model using the available context and your instructions. An AI approval can release credentials or permit signing without asking you to confirm that request. The model can also deny a request or refer it to you.
AI can make mistakes, including approving an unsafe or unintended operation and denying a legitimate one. It may misunderstand instructions, miss relevant facts or be influenced by misleading content. We do not guarantee that AI decisions or explanations will be accurate, complete or suitable for your intended use, or that the model will follow your instructions. An explanation is not proof that the decision is correct, and an approval is not a guarantee that a command is safe.
You are responsible for assessing whether AI review is appropriate for your use, choosing which credentials and clients may use it, and deciding where human review is needed. Consider the consequences of an incorrect decision and maintain appropriate safeguards, verification and monitoring, including access restrictions at the underlying service.
Where you require human authorisation, select Ask mode for the relevant secret and client and end temporary grants that bypass review. Changing a setting does not undo operations already authorised or retrieve credentials already delivered. If AI access is inactive or review fails, requests that remain eligible for approval fall back to manual review. Requests can also fail, expire or become unavailable.
These AI limitations do not reduce the mandatory rights and liability exceptions in sections 6 and 9.
5. Subscriptions and cancellation
The checkout shows the price, currency, billing period and any introductory offer before purchase; website prices are references. For app-store purchases, that store's applicable payment, subscription and refund rules also apply. Purchases are currently made through Google Play.
An automatically renewing subscription continues at the disclosed interval until cancelled. Manage or cancel renewal through the store where you subscribed. Ordinary cancellation stops future renewal, and access normally continues until the end of the paid period. Statutory withdrawal, termination and refund rights are separate and may end access earlier.
Uninstalling the app, resetting it, deleting an installation or asking us to delete personal data does not cancel subscription renewal. Ending AI access does not itself disable free features; their hosting limits still apply. See Plan and billing for the available controls.
Payments are non-refundable except where law or the applicable store's rules require a refund. For purchase or refund problems, use the store's process or contact us. Store procedures do not replace your statutory rights against us.
6. Mandatory consumer protections
You retain consumer rights that cannot be waived, including required service quality, updates, cancellation, refunds and compensation. The AI limitations, warranty exclusions and damages cap do not restrict those rights. The regional provisions below apply only where the identified law applies; they do not grant those protections worldwide.
Withdrawal under EEA or UK consumer law
Where EEA or UK consumer law applies to your distance contract for our hosted service, you normally have 14 days from concluding the contract to withdraw without giving a reason. Notify us of your decision to withdraw before that period expires, identifying the purchase. The following wording is optional:
To Full Disclosure, agentknock@fulldisclosure.fi: I withdraw from my contract for Agentknock's hosted service, ordered on [date], order reference [reference]. My name and address are [name and address]. Date: [date].
Starting the service does not by itself remove this right. If you expressly request performance during the withdrawal period, we may charge a proportionate amount for service already provided only when the legal conditions, including the required information, have been met. We do not treat activation of an ongoing subscription as full performance of that subscription.
We reimburse payments due following a valid withdrawal without undue delay and no later than 14 days after receiving it, using the original payment method unless you expressly agree otherwise, without a refund fee. Any lawful proportionate charge for service already supplied may be deducted. Longer periods or additional rights required by applicable law remain available.
Withdrawal or refund rights under another country's law apply under that law's conditions and time limits.
Mandatory remedies
Where EEA consumer law applies, you retain statutory rights to timely supply of a conforming digital service. Where UK consumer law applies, you retain statutory rights to services performed with reasonable care and skill and digital content meeting its required quality and description.
Applicable remedies for delay or defects may include correction, a price reduction, ending the contract or compensation. Report a problem to us so we can investigate.
7. Availability and support
We do not currently offer a service level agreement (SLA). We provide support responses and interruption notices required by law or applicable app-store rules. Any additional commitment to response or resolution times, an uptime percentage or service credits must be separately agreed in writing.
Maintenance, faults, security incidents and outages affecting networks, devices or providers can delay or prevent requests. We do not guarantee uninterrupted or error-free operation.
The support documentation explains reporting and troubleshooting. The absence of an SLA does not limit agreed service features or the mandatory rights in section 6.
8. Restrictions, suspension and ending the service
We may restrict hosted access for individual users, installations, clients, connections or requests. Measures may include rate or resource limits, rejecting requests, restricting features, and suspending or ending access. Limits may be enforced automatically, and we may apply restrictions manually. These measures apply to both free and paid users and are subject to the grounds and conditions below.
We may impose temporary restrictions where we have reasonable grounds to suspect abuse, fraud, unauthorised use, a compromised device, or a risk to the security, availability or lawful operation of the service. We may choose the form and scope of those restrictions as we consider appropriate to address the risk, without first confirming its cause or intent.
If delay would increase the risk of harm, disruption or unlawful activity, we may act immediately without advance warning or an opportunity to remedy the problem, subject to the protections below. Grounds for ending access include a material breach of these terms, repeated misuse, fraud, a serious or continuing security risk, or a legal requirement. We may also discontinue all or part of the hosted service under the conditions in this section.
All measures in this section, including restrictions on free access and service discontinuation, are subject to applicable law and app-store requirements. We will provide any required notice, explanation, opportunity to remedy a breach and refunds, including any required refund for unused prepaid access. Consumer restrictions must have grounds allowed by applicable consumer law. Any legal duties to act diligently, objectively and proportionately and respect affected rights also apply. These terms create no additional cancellation payment or refund entitlement.
Payment failure may suspend the affected paid feature; it does not by itself remove access to free features. We respect any statutory right to withhold payment or dispute a charge.
Free relay hosting
We may limit, change or discontinue free relay access for individual users or the service as a whole for operating costs, funding, capacity, security needs, changes to how we provide the service, or a decision to stop operating or funding the relay. We may set or change individual free-use limits for cost or capacity reasons even when use is not abusive. We do not undertake to keep paying for or maintaining infrastructure for free access.
These free-access provisions do not remove obligations to existing paid subscribers, including relay access needed to fulfil the subscription. Changes to the paid service follow section 11.
Ending hosted access does not revoke your open-source software licence. If the relay is no longer available, pairing, credential requests and signing through the current app and CLI cannot proceed through it. These terms do not include a replacement relay or migration service. Follow the data-deletion instructions if you want to remove an installation. Retention follows the privacy notice and applicable law.
9. Warranties and liability
Rights these limits do not affect. The exclusions and cap below do not restrict the mandatory consumer rights and remedies in section 6 or any liability the law requires us to retain, including for fraud, intentional or grossly negligent conduct, death or personal injury, or personal-data violations. Refunds required by law or the purchase rules in section 5 are outside these damages limits.
Warranty exclusions. Subject to the rights above and our express commitments in these terms, the hosted service is provided “as is” and “as available”. To the extent permitted by applicable law, we exclude other express, implied and statutory warranties, including warranties of merchantability, satisfactory quality, fitness for a particular purpose and non-infringement. This does not override binding descriptions of the service or statutory requirements for its supply and quality.
Excluded losses. Where the law permits, we are not liable for indirect, incidental, special or consequential damages, or for lost profits, revenue, business opportunities, goodwill, use, or lost or corrupted data, whether those losses are direct or indirect. We also exclude punitive and exemplary damages where permitted. These exclusions apply to claims arising out of or relating to the hosted service, including automated AI decisions.
Liability cap. Where the law permits, our total liability arising out of or relating to the hosted service will not exceed the greater of €100 or the fees you paid for the service giving rise to the claim during the 12 months before the first event giving rise to liability. The exclusions and cap apply regardless of whether a claim is based on contract, negligence or another legal ground, subject to the rights preserved above.
A prohibited exclusion or cap does not apply to your claim. You must take reasonable steps to avoid or limit loss, such as revoking compromised credentials, to the extent applicable law requires.
10. Business indemnity
This section applies only to business customers, not consumers. You must reimburse us for amounts finally awarded against us, settlements you approve in writing, and reasonable external legal costs defending third-party civil claims, only to the extent caused by your unlawful or unauthorised use of the hosted service or material breach of these terms. This excludes fines, amounts caused by our own breach, negligence or wilful misconduct, and liability that cannot lawfully be transferred to you.
We will notify you promptly, reasonably cooperate, and give you a reasonable opportunity to control the defence with counsel reasonably acceptable to us. Delayed notice reduces your responsibility only to the extent it materially harms the defence. Neither party may agree a settlement imposing payment, an admission or another obligation on the other without that party's written consent, which must not be unreasonably withheld.
The cap on our liability in section 9 does not limit this business indemnity. Ending hosted access does not remove obligations under this section arising from your earlier use of the service.
11. Changes to the service and terms
We may make changes needed to maintain conformity, security and legal compliance. Other changes to the service may be made for justified reasons, such as compatibility with supported platforms, replacement of a discontinued dependency or improvements to service functionality. Changes to these terms may also reflect those reasons, changes in law, or changes to the service's operating costs. Changes require a lawful basis and any required notice or consent; posting revised terms alone does not satisfy those requirements.
Subscription prices may change to reflect changes in service delivery costs, taxes, payment charges or currency exchange rates. We will provide the information, notice, consent process and cancellation rights required by applicable law or the applicable app store. Price changes do not increase charges for a period already paid for.
Changes under EEA consumer law
Where EEA consumer law applies to an ongoing digital service, changes beyond those needed to maintain conformity require a justified reason set out above, must not create an additional charge, and must be explained clearly. If a change has more than a minor adverse effect on your access to or use of the service, we will give reasonable advance notice in a form you can save, explaining the change, its timing and your rights.
Under those rules, you may end the contract without charge within 30 days after receiving the notice or the change taking effect, whichever is later, unless the adverse effect is minor or we let you keep the unchanged, conforming service at no extra cost. Any refund required by those rules remains available.
Notice under Finnish consumer law
Where Finnish consumer law applies, a permitted change adding consumer obligations or reducing consumer rights normally takes effect no earlier than one month after notice. A shorter period may apply where the law allows it, such as for a legislative change or an authority's decision. You retain the right to end an ongoing agreement because of a change, under the conditions that law provides. Other customers receive the notice and cancellation rights required by their applicable law and purchase rules.
12. Applicable law and disputes
For consumer contracts, these terms do not select a governing law. The applicable law is determined by the legal rules that decide which country's or state's law applies, including rules protecting consumers where they habitually live. For business customers, Finnish substantive law governs these terms. Nothing in this section excludes mandatory laws that apply regardless of a contractual choice of law.
Contact us so we can try to resolve a disagreement. Where eligible, consumers may seek assistance from Finnish Consumer Advisory Services and refer an eligible dispute to the Consumer Disputes Board. Disputes may be brought before a court with jurisdiction. These terms do not restrict mandatory rights to bring a claim or use other remedies.
13. Customer data processing
13.1 Roles and scope
This section is the data-processing agreement between you and Full Disclosure under Article 28 GDPR. It applies to free and paid hosted services where we process personal data on your behalf as a processor or subprocessor. You act as controller or, where you process data for another controller, as its authorised processor. We act as your processor or subprocessor, respectively. GDPR terms used here have their GDPR meanings.
“Customer personal data” means personal data in the encrypted messages, AI review inputs and outputs, and related delivery information that we process to carry out your instructions. It does not include data held only on your devices or records we process for our own administration, billing, security, website or correspondence purposes, as described in the privacy notice. Our role depends on the purpose of the particular processing.
You are responsible for the lawful basis and privacy information required by applicable law, and for authority to give your instructions, including authority from your controller where applicable.
13.2 Processing covered
- Subject matter and purpose
- Providing the customer's credential-access workflow: relaying exchanges between paired devices, delivering notifications, and producing requested AI approval decisions and explanations.
- Nature of processing
- Receiving, transmitting, temporarily storing and deleting encrypted messages and associated delivery information; where AI review is enabled, analysing readable review context and returning its result. Processing occurs as you and your authorised users use these features.
- Data and individuals concerned
- Device, client and request identifiers; names, usernames and contact details; credential descriptions and non-sensitive values; commands, paths, reasons, review instructions, SSH usernames, Git author and committer details, signing content and resulting decisions. Encrypted messages may contain further personal data that we cannot read. Individuals may include your users, employees, contractors, customers and other people whose information appears in submitted content. You determine the information submitted and must limit it to what your use requires.
- Duration
- For the provision of the selected services and until return or deletion under section 13.7. The service's routine retention and deletion schedules are described in section 8 of the privacy notice. These schedules do not authorise retaining customer personal data for an unrelated purpose.
13.3 Documented instructions
We will process customer personal data only on your documented instructions, including for international transfers. These terms and your use of the documented service controls instruct us to perform the processing above. You may give further written instructions through privacy@fulldisclosure.fi. If an instruction cannot be carried out within the service, we will inform you and resolve it with you before carrying out the affected processing. We will immediately inform you if, in our opinion, an instruction infringes the GDPR or other EU or Member State data-protection law, and suspend that instruction pending resolution.
If EU or Member State law requires processing otherwise than on your instructions, we will inform you of that requirement beforehand unless the law prohibits this on important public-interest grounds. We will not use customer personal data for advertising, model training or general product improvement. Instructions supplied to the AI model guide access decisions; they do not amend this agreement's processing purposes or safeguards. Section 4's limitations on model behaviour do not excuse a breach of our data-processing obligations.
13.4 Confidentiality and security
We will ensure that people authorised to process customer personal data are bound by contractual or statutory confidentiality obligations, and limit their access to what they need for the service. We will implement and maintain the technical and organisational measures required by Article 32 GDPR, taking account of the processing and its risks, including measures for confidentiality, integrity, availability, resilience, timely recovery and regular evaluation of their effectiveness.
The service uses encrypted network connections, authenticated device access and checks that requests belong to the relevant device or exchange. Paired-device message contents are end-to-end encrypted with keys unavailable to the relay. AI review is a separate readable processing path: stored credential fields marked sensitive and stored private keys are excluded, while submitted context can contain personal data. We do not retain review content in application logs or review databases after processing. Provider content logging and caching are disabled under the arrangements described in section 5 of the privacy notice, subject to the provider's stated zero-retention limitations. We maintain the documented cleanup and recovery-storage limits. Changes to security measures must not reduce the protection required for the agreed processing.
13.5 Subprocessors and transfers
You give general written authorisation for subprocessors used for the agreed processing. The current service providers are Cloudflare for hosting, relay storage and delivery, and the AI gateway; OpenAI through Cloudflare for AI review; and Google through Firebase for notification registrations and generic wake-up messages. Only the providers needed for the features you use receive the corresponding data. Providers used solely for our separate controller purposes are not subprocessors for this agreement.
We will make up-to-date information available to you about the subprocessors involved, including their legal names, addresses, contact details, processing activities and locations, and relevant downstream subprocessors. We will actively notify you in writing, including electronically, of intended additions or replacements at least 14 days before they process your customer personal data, providing the information needed to assess the change. Updating a web page alone is not that notice.
You may object on data-protection grounds before the notified change takes effect. We will work with you to resolve the objection. If no suitable arrangement is possible, we will stop the affected processing before using the new subprocessor for your data, and you may end the affected service. Applicable cancellation and refund rights remain available. We will impose the same data-protection obligations on our subprocessors by written contract and require corresponding protections through the processing chain. We remain fully responsible to you for performance of their data-protection obligations.
The agreed service uses providers with international operations, including processing outside the EEA and in the United States, as described in section 7 of the privacy notice and the applicable subprocessor record. Your instructions authorise those service transfers only with the safeguards required by Chapter V GDPR. We will provide information about the applicable transfer mechanisms and safeguards. Subprocessor authorisation does not itself replace a required transfer mechanism.
13.6 Rights, incidents and assistance
Taking account of the processing and the information available to us, we will assist you through appropriate technical and organisational measures, insofar as possible, with individual rights requests under Chapter III and your applicable obligations under Articles 32–36 GDPR, including security, breach notifications, data-protection impact assessments and prior consultation with supervisory authorities. This includes helping locate relevant records using available device, request or purchase identifiers, supplying information we hold, and carrying out appropriate correction, restriction or deletion instructions. Contact privacy@fulldisclosure.fi with the request and relevant identifiers. We will explain any technical limits and cooperate on an appropriate response; we cannot reconstruct content already discarded or decrypt your paired-device messages.
We will promptly forward requests concerning your customer personal data to you and will not answer them on your behalf without your instructions, unless required by law. We will notify you without undue delay after becoming aware of a personal data breach affecting customer personal data. We will provide available information about its nature, affected data and individuals, likely consequences, measures taken or proposed, and a contact for follow-up, with further information as it becomes available. We will cooperate in containing, investigating and remedying the breach. The responsible controller decides on notifications to individuals and authorities.
13.7 Return and deletion
At the end of the relevant processing services, we will, at your choice, return or delete customer personal data and delete remaining copies, unless EU or Member State law requires storage. Your initial instruction is deletion under the service's documented schedules; you may change that choice or request earlier deletion by contacting us before the data is removed. Return covers data still held by us or our subprocessors and does not require us to start retaining transient AI review content, recover already deleted data, or provide a migration service.
We will arrange a secure return of available data and explain its format and scope. After live deletion, recovery copies remain isolated from ordinary use and expire within the periods in section 8 of the privacy notice; any restored copy remains subject to the deletion instruction. Legally required copies remain protected and are used only for the required purpose. We will confirm completion on request. The obligations in this section continue for as long as we or our subprocessors retain customer personal data.
13.8 Compliance and priority
We will make available the information needed to demonstrate compliance with this agreement and Article 28 GDPR, and allow and contribute to audits, including inspections, by you or an auditor you appoint. Document review and remote checks may be used first where sufficient. Reasonable confidentiality, security and scheduling arrangements must protect other customers' data without preventing an effective audit, including where an incident or authority requires urgent access.
This section prevails over conflicting service terms concerning customer personal data. Service restrictions, the absence of an SLA and changes to the privacy notice do not excuse performance of these obligations. Section 9's liability provisions remain subject to mandatory data-protection law. Changes to the agreed processing require documented instructions or a binding amendment under section 11; publishing a revised notice alone does not amend your instructions. Nothing here restricts individuals' rights or supervisory authorities' powers.