Terms of Service
Last updated: [date]
These Terms of Service ("Terms") are a binding agreement between you ("you," "your," or "Customer") and [Spondeo, Inc.] ("Spondeo," "we," "us," or "our") governing your access to and use of the Spondeo website, the consumer affiliation-proof-link service, the Spondeo developer API, SDKs, MCP server, documentation, and related services (together, the "Service").
By creating an account, generating an API key, or otherwise using the Service, you agree to these Terms. If you are using the Service on behalf of an organization, you represent that you are authorized to bind that organization, and "you" refers to that organization.
If you do not agree to these Terms, do not use the Service.
1. The Service
Spondeo is a privacy-preserving affiliation-verification platform. It lets:
- a consumer prove that they control an organization email and, from that, mint reusable,
minimal-disclosure proof links that show only a status/tier (e.g. "verified student at an accredited university"); and
- a developer call the Spondeo API (e.g.
POST /v1/verify) to confirm that a user holds such a
verified affiliation, receiving in response only a tier/status enum and a pairwise identifier.
The Service is designed so that it does not receive or store a person's name, school name, employer name, email address, or date of birth. See our Privacy Policy for details on what is and is not processed.
2. Honest scope and the nature of a "proof" — please read
This is the most important thing to understand about the Service, and it is a disclaimer, not a warranty.
- Spondeo verifies control of an email address at an organization's domain at a point in time, and
maps that domain to an institution tier plus a self-asserted status (such as "student" or "employee"). Where supported, it may also indicate overlays such as "accredited US university."
- **Email-domain control is not registrar-, HR-, or government-backed enrollment or employment
verification.** Spondeo does not contact a registrar, an HR system, or any system of record, and does not verify a person's identity, name, current enrollment, current employment, eligibility, or any other fact about a person.
- A Spondeo proof is NOT a guarantee of any fact about a person. It is evidence that, at the time of
verification, someone demonstrated control of an email at a given category of organization. Email accounts can be shared, retained after a person leaves an institution, or otherwise not reflect a person's current status. Every proof is labeled "verified via email-domain control" so that it is never mistaken for identity-of-record or for a legally authoritative credential.
- You are responsible for deciding whether email-domain control is sufficient for your use case. Do
not rely on the Service where law, regulation, or your own risk tolerance requires registrar-, HR-, or government-backed verification of a person.
3. Accounts and eligibility
- You must provide accurate account information (an email address) and keep it current.
- You are responsible for all activity under your account and for safeguarding your API keys (including
sk_test_ and sk_live_ keys). Treat live keys as secrets; do not embed them in client-side code or public repositories. Notify us promptly at [contact@…] if you suspect a key is compromised; you may revoke and rotate keys at any time from your account.
- The Service is not directed to children. You may not use the Service if you are under 13, and the
consumer verification flow is intended for users aged 13 and over. See the Privacy Policy.
4. Acceptable use
You agree not to, and not to permit any third party to:
- use the Service to verify or gate access to anything unlawful, or in violation of any applicable law,
regulation, or third-party rights;
- attempt to deanonymize users, correlate pairwise identifiers across audiences, or otherwise defeat
the privacy properties of the Service;
- submit forged, stolen, or fraudulently obtained credentials or presentations, or attempt to obtain a
proof for an affiliation you do not hold;
- probe, scan, or test the vulnerability of the Service, or breach or circumvent any authentication,
rate-limiting, quota, or security measure, except under a separate written authorization from us;
- use the Service to build a competing affiliation-verification database, or to scrape, harvest, or
enumerate organizations, domains, or users;
- exceed, evade, or manipulate the usage quotas or metering associated with your plan (for example, by
splitting usage across accounts to avoid overage); or
- interfere with or disrupt the integrity or performance of the Service.
You are responsible for the conduct of your end users to the extent you integrate the Service into your own product, and for providing your end users any notices and obtaining any consents required by law for the verification you perform.
5. API terms, quotas, rate limits, and fair use
- Your use of the API is subject to the quotas and rate limits of your plan, described at
/pricing and in docs/launch/pricing.md. We may apply per-key and per-account rate limits and monthly verification quotas.
- On the free tier, usage hard-stops when the included quota is exhausted (the API returns an
HTTP 429 and directs you to /pricing). On paid tiers, usage above the included amount is billed as metered overage at the rates for your plan.
- We may throttle, suspend, or limit access, and revoke API keys, if we reasonably believe your use
threatens the security, integrity, availability, or lawful operation of the Service, violates these Terms, or constitutes abuse or fraud. Where practical and lawful, we will give notice; for active security or abuse threats we may act first and notify after.
- We may change, deprecate, or version API endpoints. We will use commercially reasonable efforts to
give advance notice of breaking changes via the changelog and/or email to account holders.
6. Fees, payment, taxes, and metering
- Current plans, included verifications, and overage rates are described at /pricing. The consumer
proof-link path is free.
- Paid plans are billed in advance on a recurring basis (monthly or annual) through our payment
processor. Metered overage (on paid tiers) is billed in arrears based on successful verifications, metered per account. Unsuccessful verifications are not billed.
- All fees are stated exclusive of taxes. You are responsible for any sales, use, VAT, GST, or similar
taxes, except taxes on our net income. You authorize us and our payment processor to charge your payment method for all fees and applicable taxes.
- Fees are non-refundable except as stated in our Refund & Cancellation Policy or as
required by law.
- We may change fees or plans on prospective notice; changes take effect at your next renewal.
7. Customer data and privacy
Our processing of personal data is governed by the Privacy Policy, which is incorporated into these Terms. As between the parties, you retain ownership of the inputs you submit; you grant us a limited license to process them solely to provide and secure the Service. The Service is deliberately built to minimize the personal data it handles (see the Privacy Policy and Section 2).
8. Intellectual property
We retain all right, title, and interest in the Service, including the software, APIs, SDKs, documentation, and trademarks. Subject to these Terms, we grant you a limited, non-exclusive, non-transferable, revocable license to access and use the Service and to use our SDKs as documented. The @spondeo/verify SDK and other published packages are licensed under their stated license terms. You retain ownership of your own application and content.
9. Third-party services
The Service relies on third-party providers (for example, email delivery, hosting, and payment processing) and uses vendored, openly licensed reference data to classify organization domains. We are not responsible for third-party services, and your use of them may be subject to their terms. See the Privacy Policy for our sub-processors.
10. Disclaimers — AS IS
THE SERVICE IS PROVIDED "AS IS" AND "AS AVAILABLE," WITHOUT WARRANTIES OF ANY KIND, WHETHER EXPRESS, IMPLIED, OR STATUTORY, INCLUDING ANY IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, AND NON-INFRINGEMENT.
WITHOUT LIMITING THE FOREGOING, WE DO NOT WARRANT THAT A VERIFICATION, PROOF, OR CLAIM IS ACCURATE, CURRENT, COMPLETE, OR A GUARANTEE OF ANY FACT ABOUT ANY PERSON. A PROOF REFLECTS DEMONSTRATED CONTROL OF AN ORGANIZATION EMAIL AT A POINT IN TIME — NOTHING MORE (SEE SECTION 2). YOU ASSUME ALL RISK OF RELYING ON ANY VERIFICATION RESULT. We do not warrant that the Service will be uninterrupted, error-free, or secure. Some jurisdictions do not allow the exclusion of certain warranties, so some of these exclusions may not apply to you.
11. Limitation of liability
TO THE MAXIMUM EXTENT PERMITTED BY LAW, NEITHER PARTY WILL BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, EXEMPLARY, OR PUNITIVE DAMAGES, OR FOR ANY LOSS OF PROFITS, REVENUE, DATA, GOODWILL, OR BUSINESS, ARISING OUT OF OR RELATED TO THESE TERMS OR THE SERVICE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.
OUR TOTAL AGGREGATE LIABILITY ARISING OUT OF OR RELATED TO THESE TERMS OR THE SERVICE WILL NOT EXCEED THE GREATER OF (A) THE AMOUNTS YOU PAID TO US FOR THE SERVICE IN THE TWELVE (12) MONTHS BEFORE THE EVENT GIVING RISE TO THE CLAIM, OR (B) ONE HUNDRED U.S. DOLLARS (US$100).
These limitations apply regardless of the theory of liability and even if a limited remedy fails of its essential purpose. Some jurisdictions do not allow certain limitations, so some of these may not apply to you.
12. Indemnification
You will defend, indemnify, and hold harmless Spondeo from and against any third-party claims, damages, liabilities, costs, and expenses (including reasonable legal fees) arising out of or related to your use of the Service in violation of these Terms or applicable law, including your reliance on a verification result and your handling of your end users' data.
13. Term, suspension, termination, and account deletion
- These Terms apply for as long as you use the Service.
- You may stop using the Service and delete your account at any time via the self-serve
/account/delete flow, which purges your account and its associated data. Cancellation of a paid plan is governed by the Refund & Cancellation Policy.
- We may suspend or terminate your access for breach of these Terms, non-payment, or to comply with law
or protect the Service or its users. We will provide notice where practical and lawful.
- Sections that by their nature should survive termination (including Sections 2, 6 (for accrued fees),
8, 10, 11, 12, and 15) survive.
14. Changes to these Terms
We may update these Terms from time to time. For material changes, we will provide reasonable advance notice (for example, by email to account holders and/or a notice on the site) before they take effect. Your continued use of the Service after the effective date constitutes acceptance. If you do not agree, stop using the Service and delete your account before the change takes effect.
15. Governing law and disputes
These Terms are governed by the laws of [jurisdiction], without regard to its conflict-of-laws rules. The parties submit to the exclusive jurisdiction of the courts located in [jurisdiction] for any dispute arising out of or relating to these Terms, except that either party may seek injunctive relief in any court of competent jurisdiction. To the extent permitted by law, any claim must be brought within one (1) year after it arises.
16. General
These Terms, together with the Privacy Policy and Refund & Cancellation Policy, are the entire agreement between you and us regarding the Service and supersede any prior agreements. If any provision is held unenforceable, the remaining provisions remain in effect. Our failure to enforce a provision is not a waiver. You may not assign these Terms without our consent; we may assign them in connection with a merger, acquisition, or sale of assets. Nothing in these Terms creates an agency, partnership, or joint venture.
17. Contact
Questions about these Terms: [contact@…], [Spondeo, Inc.], [address].