Terms of Service
Last updated: June 12, 2026
These Terms of Service (the "Terms") are a binding agreement between DeployMill ("DeployMill," "we," "us") and the person or organization using the DeployMill service ("you," "Customer"). They govern your use of the DeployMill website at https://deploymill.com, the dashboard at /account, the MCP tool surface, the REST API, the documentation at /docs, and the apps and resources you deploy through any of them (collectively, the "Service").
By creating an account, connecting an AI agent to the Service, or otherwise using the Service, you accept these Terms. If you are accepting on behalf of a company or other legal entity, you represent that you have authority to bind that entity, and "you" means that entity. If you don't agree to these Terms, don't use the Service.
One thing worth saying plainly before the legal language starts: DeployMill is built so that an autonomous AI agent can operate your account (create repositories, deploy containers to production, manage domains, databases, and secrets) on your behalf. That is the product working as intended, and it has a consequence these Terms repeat several times: you are responsible for what your connected agent does with your credentials. We build guardrails (isolated previews, health-gated deploys with auto-rollback, an audit trail, a secret hand-off the agent never sees), but the agent acts as you.
1. Definitions
- "Agent" means any AI system, MCP client, or automated tool (e.g. Claude,
Codex, or any other Model Context Protocol client) that you connect to the Service and authorize to act on your account.
- "Customer Content" means everything you (or your Agent, or your deployed
apps' end users) put into the Service: source code, container images built from it, database contents, objects in storage, environment variables and secret values, deployed app content, and logs your apps emit.
- "Organization" (or "workspace") means a tenant within the Service that
owns apps, secrets, domains, and other resources, and to which members are invited with roles.
- "Order" means a plan selection, subscription, or other purchase made
through the Service, including a free plan.
- "Documentation" means the public docs served at
/docsand as MCPresources.
- "AUP" means the Acceptable Use Policy,
which is part of these Terms.
2. Eligibility and account registration
You must be at least 18 years old (or the age of majority where you live) and capable of forming a binding contract to use the Service. The Service is offered to businesses and individual developers. It is not directed at children.
When you register (via Google or GitHub sign-in, email, or enterprise SSO) you agree to provide accurate information and keep it current. You are responsible for all activity under your account, whether performed by you, your team members, or your connected Agent. Authentication uses OAuth 2.0 with PKCE. Access tokens issued to an Agent carry the full authority you grant them at consent time. Treat them like passwords, because functionally they are.
If you believe your account or an Agent's token has been compromised, revoke the token and contact [email protected] immediately.
3. Description of the Service
DeployMill is a control plane for shipping web apps. Through MCP tools, the REST API, and the dashboard, the Service lets you (or your Agent) create and import source repositories, build and deploy containers, spin up isolated preview environments, attach custom domains with TLS, provision managed databases and object storage, manage environment variables and secrets, view logs and health, and roll back deployments.
Three architectural facts matter for these Terms:
- Your apps run on our infrastructure. Customer apps run as containers on
DeployMill's self-operated Kubernetes infrastructure with per-Organization tenant isolation. Deployed apps are served under subdomains of
deploymill.appunless you attach a custom domain. - An Agent operates the account on your behalf. When you connect an Agent
and grant it access, actions it takes (deploying, deleting, changing environment variables, modifying DNS routing for your apps) are your actions under these Terms. The Service maintains an audit trail attributing actions to the credential that performed them, and it provides safety mechanisms (preview isolation, health-gated rollouts with automatic rollback, dry-runnable reconcile plans), but it does not review or approve your Agent's decisions. You should.
- Secret values bypass the Agent. Secret values are entered by a human
through a single-use browser link and are never returned to an Agent or echoed into a transcript. They are stored encrypted (AES-256-GCM) and injected server-side into your apps' runtime environment. This design only protects you if you actually use it. Pasting a secret into an Agent chat instead of the hand-off link defeats it, and that's on you.
We may improve, modify, or discontinue features over time (see Section 16).
4. Organizations, teams, roles, and seats
Resources in the Service belong to an Organization. The Organization's owner and administrators control membership, roles, invitations, SSO configuration, and billing.
- Members act for the Organization. Each member's actions (and their
connected Agents' actions) bind the Organization within the scope of the member's role.
- You manage your own access. Granting someone (or some Agent) a role is
your decision. We honor the roles you configure. Remove members and revoke Agent tokens promptly when access should end.
- Fees. Paid plans are priced on usage (the hours your apps are awake)
above a monthly minimum, as described at the time of purchase. Seats are free and unlimited. You're responsible for all fees and usage attributable to your Organization.
- Disputes inside your Organization (e.g. between members, or between you
and a departed contractor) are yours to resolve. We will follow lawful instructions from the Organization's owner of record.
5. Acceptable use
Your use of the Service must comply with the Acceptable Use Policy. In short: no illegal content, no malware or phishing, no attacking third parties or other tenants, no crypto mining or resource abuse, no spam, and absolute zero tolerance for CSAM. The AUP applies equally to actions taken by your Agent. Wiring an Agent to do something the AUP prohibits is the same as doing it yourself.
We may suspend or remove apps and content, and suspend or terminate accounts, for AUP violations as described in Section 10 and in the AUP's enforcement section.
6. Customer Content and ownership
You own your stuff. As between you and DeployMill, you retain all rights, title, and interest in Customer Content. These Terms transfer no ownership of your code, data, or deployed applications to us.
You grant us a license to run it. You grant DeployMill a worldwide, non-exclusive, royalty-free license to host, store, copy, build, execute, transmit, display, and otherwise process Customer Content solely as needed to provide, secure, and support the Service. For example: pulling your source to build a container, running that container, storing your database, serving your app to its visitors, creating copy-on-write database branches for previews, and writing secrets into your containers' runtime environment. This license ends when the content is deleted from the Service, subject to the windows described in our data retention & deletion policy and residual copies in backups.
You are responsible for your content. You represent that you have all rights necessary to deploy your Customer Content through the Service, and that doing so doesn't violate law or third-party rights. Apps you deploy are yours: you are the operator of record for their content, their handling of their end users' data, and their compliance obligations. DeployMill is your hosting and deployment layer, not a co-publisher.
Feedback. If you send us suggestions or feedback, we may use it without restriction or obligation.
7. Third-party services and subprocessors
The Service uses third-party providers for parts of the default managed stack (for example GitHub for source, Cloudflare R2 for object storage, and optional managed-database backends). The current list, with what data each receives and why, is maintained at Subprocessors. That page is the source of truth and we keep it updated as backends change.
Some features connect to accounts you control with third parties (e.g. your GitHub account, your DNS provider for custom domains). Your use of those services is governed by their terms, and you're responsible for maintaining the access the Service needs (e.g. keeping a GitHub App installation in place).
8. Fees, billing, plans, and taxes
- Plans. The Service offers free and paid plans. Features, quotas, and
resource limits per plan are described at the point of purchase or in the Documentation. We may change plan pricing and packaging prospectively with reasonable notice. Changes take effect at your next renewal.
- Free plans are provided as-is, may carry usage limits we enforce
automatically, and may be modified or withdrawn. We'll give reasonable notice before materially reducing a free plan you're actively using.
- Payment. Paid plans are billed in advance on the subscription cycle you
select (and in arrears for any usage-based components). You authorize us and our payment processor to charge your payment method. Fees are non-refundable except where these Terms or applicable law require otherwise.
- Late payment / non-payment. If payment fails, we'll notify you and
retry. Continued non-payment may lead to suspension of paid features and, ultimately, termination under Section 10, including stopping running apps. We're not in the business of surprise shutdowns. We are in the business of not running infrastructure for free indefinitely.
- Taxes. Fees exclude taxes. You're responsible for applicable sales,
use, VAT, GST, and similar taxes, excluding taxes on our net income.
- Overage and abuse pricing. Usage that exceeds plan quotas may be
throttled, blocked, or billed as overage as described in your plan.
9. Trials, betas, and pre-release features
We may offer trials, beta features, or early-access functionality (anything labeled alpha, beta, preview, or experimental). These are provided "as is," without any warranty or commitment, may change or vanish without notice, may be subject to additional terms, and are excluded from any SLA commitments. Don't bet production-critical workloads on a feature we've labeled experimental.
10. Suspension and termination
Your right to leave. You can stop using the Service and delete your account at any time. Deleting your account or Organization deletes your apps and data per the data retention & deletion policy.
Our right to suspend. We may suspend some or all of the Service for your account (including stopping running apps and disabling domains) if, in our reasonable judgment: (a) you materially breach these Terms or the AUP; (b) your apps or Agent activity pose a security, legal, or operational risk to the Service, other tenants, or third parties (e.g. an app that's actively attacking someone, mining cryptocurrency, or serving malware); (c) payment is overdue past the notice period; or (d) we're required to by law. Where practical we'll notify you and give you a chance to cure first. For severe cases (CSAM, active attacks, legal demands) we will act immediately and notify you after, as the AUP describes.
Termination. Either party may terminate for the other's material breach not cured within 30 days of written notice. We may also terminate free accounts that have been inactive for an extended period, with notice.
Effect of termination, read this part. When your account or Organization is terminated, running apps are stopped, domains are detached, and Customer Content becomes scheduled for deletion under the windows in the data retention & deletion policy. During that window you can export your data (your source lives in your own GitHub repositories already, which helps). After the window, deletion is permanent. Sections of these Terms that by their nature should survive (ownership, payment obligations accrued, disclaimers, liability limits, indemnities, confidentiality, governing law) survive termination.
11. Customer responsibilities and security
You agree to:
- Protect credentials. Keep your account credentials, API keys, and Agent
OAuth tokens confidential. Revoke tokens for Agents and tools you no longer use. An Agent token in the wrong hands can deploy to your production. Scope and guard it accordingly.
- Use the secret hand-off for secrets. Enter secret values only through
the single-use browser hand-off, never by pasting them into an Agent conversation, a repository, or an environment variable set via an Agent.
- Supervise your Agent. Review what your Agent deploys, especially to
production. Use previews and the dry-run/plan tools before applying changes. The audit trail exists so you can check what happened. Checking it is your job.
- Deploy lawfully. Do not deploy unlawful content or use the Service in
violation of the AUP, export-control and sanctions laws, or other applicable law.
- Secure your own apps. You're responsible for your apps' application-level
security (their auth, their handling of their users' data, their dependencies). We isolate tenants and secure the platform. We don't audit your code.
- Maintain your own backups of anything irreplaceable beyond what the
Service's retention windows provide, to the extent your plan doesn't include managed backups you've verified meet your needs.
12. Privacy
Our collection and use of personal data is described in the Privacy Policy. Where you deploy apps that process personal data of your own end users, you are the controller (or equivalent) for that data and DeployMill processes it on your behalf. A Data Processing Agreement is available and forms part of these Terms where required.
13. Service levels and support
Availability commitments for paid plans, and the remedies for missing them, are described in the SLA. Free plans carry no SLA. Support is available at [email protected] and through the dashboard at /account/support. Response targets, where offered, are described in your plan. Our security posture is documented at Trust & Security.
14. Warranties and disclaimers
We warrant that we will provide the Service with reasonable skill and care.
Otherwise, the Service is provided "AS IS" and "AS AVAILABLE." To the maximum extent permitted by law, DeployMill disclaims all other warranties, express or implied, including merchantability, fitness for a particular purpose, title, non-infringement, and any warranty that the Service will be uninterrupted, error-free, or secure.
A specific, honest disclaimer about AI agents. The Service is designed to let an autonomous Agent take real actions, including deploying to production, modifying configuration, and deleting resources. AI agents make mistakes: they can misread instructions, deploy the wrong thing, overwrite configuration, or take actions you didn't anticipate. The guardrails we build (preview isolation, health gates with auto-rollback, dry-run plans, the audit trail, secrets the agent can't read) reduce the blast radius. They do not make Agent behavior our responsibility. DeployMill does not warrant, control, or review the decisions of any Agent you connect, and you are solely responsible for reviewing and supervising what your Agent does with your account. Actions taken by your Agent are deemed your actions for every purpose under these Terms, including the liability and indemnity sections below.
Some jurisdictions don't allow certain warranty disclaimers. In those places, the above applies to the fullest extent permitted.
15. Limitation of liability
To the maximum extent permitted by law:
- No indirect damages. Neither party is liable for indirect, incidental,
special, consequential, or punitive damages, or for lost profits, lost revenue, lost data, or business interruption, even if advised of the possibility.
- Cap. Each party's total aggregate liability arising out of or relating
to these Terms is limited to the greater of (a) the amounts you paid DeployMill for the Service in the 12 months before the event giving rise to liability, or (b) USD $100.
- Exclusions from the cap. The cap doesn't apply to your payment
obligations, your indemnification obligations, your breach of Section 5 (acceptable use), or either party's liability that cannot be limited under applicable law (e.g. fraud, willful misconduct, death or personal injury caused by negligence).
- Agent actions. For the avoidance of doubt, DeployMill has no liability
for the consequences of actions initiated by your connected Agent, including deployments, deletions, and configuration changes it performs with the authority you granted it.
These limits reflect the deal: the Service is priced for self-serve infrastructure, not for insuring your production outcomes.
16. Modifications to the Service and to these Terms
- To the Service. We continuously evolve the Service and may add, change,
or remove features. If we discontinue a material feature you're paying for, we'll give reasonable advance notice and, where a paid feature is removed mid-term, a pro-rata refund for the unused portion attributable to it.
- To these Terms. We may update these Terms from time to time. For
material changes we'll give at least 30 days' notice (by email or in-product notice) before they take effect. Non-material changes (clarifications, typos, new feature descriptions) may take effect on posting with an updated "Last updated" date. Continued use after the effective date constitutes acceptance. If you don't agree to a change, your remedy is to stop using the Service and, for paid plans, receive a pro-rata refund of prepaid fees for the remaining term.
17. Indemnification
By you. You will defend and indemnify DeployMill against third-party claims arising from: (a) Customer Content, including content deployed or actions taken by your Agent; (b) your apps and their treatment of their end users and their data; (c) your breach of these Terms or the AUP; or (d) your violation of law or third-party rights.
By us. We will defend and indemnify you against third-party claims that the Service itself (excluding Customer Content, third-party services, and combinations we didn't supply) infringes that party's intellectual property rights. If such a claim arises, we may modify the Service to be non-infringing, procure rights for you, or, if neither is commercially reasonable, terminate the affected portion and refund prepaid unused fees. This is your exclusive remedy for Service infringement claims.
Indemnification requires prompt notice, control of the defense by the indemnifying party, and reasonable cooperation by the indemnified party.
18. Intellectual property
DeployMill and its licensors own the Service, including the software, infrastructure, tool surface, Documentation, and the "DeployMill" and "DeployMill" names, logos, and marks. These Terms grant you a limited, non-exclusive, non-transferable right to use the Service during your subscription, and no other rights. Don't remove proprietary notices, resell the Service as your own without our agreement, or use our marks except to truthfully describe that your app runs on DeployMill. Open-source components included in the Service are licensed under their own terms.
19. Confidentiality
Each party may receive non-public information from the other that is marked or reasonably understood to be confidential ("Confidential Information"). Each party will protect the other's Confidential Information with at least reasonable care, use it only to perform under these Terms, and not disclose it except to employees, contractors, and advisors who need it and are bound by comparable obligations. Confidential Information excludes information that is or becomes public without breach, was already known, is independently developed, or is rightfully received from a third party. A party may disclose Confidential Information when legally compelled, with notice to the other party where lawful. Customer Content is treated as your Confidential Information. Our handling of it is further described in the Privacy Policy and Trust & Security.
20. Governing law and dispute resolution
These Terms are governed by the laws of the jurisdiction in which DeployMill is established, excluding its conflict-of-laws rules. The parties will first attempt in good faith to resolve any dispute informally by contacting each other (for us: [email protected]) and allowing 30 days for resolution. Failing that, disputes will be resolved exclusively in the courts of competent jurisdiction where DeployMill is established, and each party consents to their jurisdiction and venue. Each party waives any right to a jury trial to the extent permitted by law. Nothing in this section prevents either party from seeking injunctive relief for misuse of intellectual property or Confidential Information in any court of competent jurisdiction.
21. General
- Assignment. You may not assign these Terms without our written consent,
except to a successor in a merger, acquisition, or sale of substantially all assets (with notice). We may assign these Terms in connection with a corporate transaction. Any other attempted assignment is void.
- Force majeure. Neither party is liable for delay or failure caused by
events beyond its reasonable control (natural disasters, war, terrorism, labor disputes, internet or utility failures, governmental acts), provided it makes reasonable efforts to mitigate. This doesn't excuse payment obligations.
- Entire agreement. These Terms, together with the
AUP, Privacy Policy, DPA (where applicable), SLA, and your Orders, are the entire agreement between the parties about the Service and supersede prior agreements on the subject. Terms on your purchase order or vendor form don't apply, even if we sign it, unless we expressly agree in writing.
- Severability. If a provision is unenforceable, it will be modified to
the minimum extent necessary, and the rest remains in effect.
- No waiver. Failure to enforce a provision isn't a waiver of it.
- Independent contractors. The parties are independent contractors. These
Terms create no partnership, agency, or joint venture.
- Notices. Legal notices to us go to [email protected]. Notices to you
go to the email on your account. Keep it current.
- Export and sanctions. You may not use the Service in violation of
export-control or sanctions laws, and you represent that you are not on any restricted-party list and not located in an embargoed jurisdiction.
22. Contact
Questions about these Terms: [email protected]. Support: [email protected]. Abuse reports: [email protected] (see the Acceptable Use Policy). Privacy: [email protected] (see the Privacy Policy).