Terms of Service

The rules, in plain language

What we provide, what you are responsible for, and what happens when either side gets it wrong. Written to be read, not skimmed past.

Last updated 13 August 2026

1.The agreement

These terms are between you and [registered company name] (“we”, “us”), the operator of Neuctra Authix. They apply from the moment you create an account, and they cover the dashboard, the API, the SDKs and the documentation.

You must be at least 16 and able to enter a contract. If you are signing up for a company, you confirm you are allowed to bind it, and “you” means that company.

If you do not accept these terms, do not create an account. If we change them materially, we will email account holders before the change takes effect; continuing to use Neuctra Authix afterwards is acceptance.

2.What Neuctra Authix provides

A hosted API for authenticating your users and storing their data, plus SDKs and pre-built components for calling it. Concretely: sign-up and sign-in, email verification, password reset, session management, a unified server-only account API key, and a schemaless JSON store with search, pagination, versioning and batch writes.

What Neuctra Authix is not

It is not an identity provider for third-party logins (there is no OAuth, SAML or social sign-in), not a multi-factor authentication product for end users, and not a compliance solution. It offers no service level agreement, no guaranteed uptime, and no certified compliance with HIPAA, PCI-DSS, SOC 2 or ISO 27001.

Every feature is described honestly on the features page and in the documentation. If something is not listed there, it does not exist — do not build on a roadmap.

3.Your account and your keys

You are responsible for everything done with your credentials. In practice that responsibility is mostly about API keys, so it is worth being specific.

CredentialWhere it belongsIf it leaks
API key (ak_)Browsers, mobile apps, anywhere a user can see itLimited damage by design — it can only reach the signed-in user's own data
API key (ak_)Your server only. Never in client code, never in a public repositoryFull access to every user and record on your account. Revoke it immediately
Dashboard passwordYour password managerChange it — this also signs out every session everywhere
We cannot recover a lost key

API keys are stored as hashes. The plaintext is shown once, at creation, and is not retrievable afterwards by you or by us. If you lose one, create a new key and revoke the old one.

Tell us promptly at security@neuctra.com if you believe a credential has been compromised.

4.Your users' data, and who answers for it

When your users sign in through Neuctra Authix, you are the data controller and we are your processor. We store and process on your instructions. That split has consequences you should plan for:

  • Your users' requests come to you. Access, correction and deletion requests are yours to answer. We will not act on a request from someone we cannot authenticate as an account holder.
  • You need your own privacy policy telling your users that their data is processed by a third party.
  • You choose what gets stored. The data API takes any JSON. Do not put payment card numbers, government identifiers, health records or other special-category data into it — Neuctra Authix is not built for that, and doing so may breach the law where you operate.
  • You keep your own exports. Deletion in Neuctra Authix is immediate and permanent, and we do not offer per-account point-in-time restore.

5.Acceptable use

Do not use Neuctra Authix to:

  • Break the law, or help anyone else break it.
  • Store or distribute malware, phishing pages, or content designed to deceive people into giving up credentials.
  • Attack the service — load testing without written permission, probing for vulnerabilities outside a responsible disclosure to us, or attempting to reach another account's data.
  • Work around plan limits, whether by creating multiple accounts, sharing keys across organisations, or automating signups.
  • Resell Neuctra Authix as your own authentication product. Building a product that uses Neuctra Authix is fine and encouraged; reselling access to the API itself is not.
  • Store data you have no right to hold, or that you obtained without consent.

We may suspend an account that is actively harming the service or other customers, and will tell you why. For anything less urgent we will contact you first and give you a chance to fix it.

6.Plans, billing and limits

Prices and limits are on the pricing page. Paid plans are billed monthly in advance through Paddle, our payment provider and merchant of record — your contract for the payment itself is with them, and your card details never reach our servers.

  • Upgrades take effect once the payment is confirmed, with a fresh request quota from that moment.
  • Downgrades and cancellations are made through the billing portal and take effect at the end of the paid period. You keep the paid plan until then.
  • Failed payments suspend paid access until the payment succeeds. Your data is not deleted while a payment is being retried.
  • Exceeding a limit — request quota, storage, user count — causes API requests to be rejected with a clear error. Nothing is deleted and nothing is charged as overage.
  • Price changes are announced by email at least 30 days ahead and never apply to a period you have already paid for.

Refunds are covered separately in the Refund Policy. Taxes are handled by Paddle and may be added at checkout depending on where you are.

7.Availability and support

We aim for the service to be available continuously and we monitor it, but we do not offer a service level agreement or an uptime guarantee, and we may take the service down for maintenance. Plan for the possibility that the API is unreachable — cache what you can, fail gracefully, and do not make your critical path depend on a single request succeeding.

PlanSupportResponse
FreeDocumentation and communityNo commitment
StarterEmail supportBest effort, typically a few business days
Pro and ScalePriority email supportBest effort, ahead of other tiers

Support response times are goals, not contractual commitments. We will say so plainly if we cannot help with something.

8.Intellectual property

Yours stays yours. You own your applications, your users' data and everything you store through the API. We claim no licence over it beyond what is needed to run the service for you — storing it, transmitting it, backing it up, and showing it back to you.

Ours stays ours. The Neuctra Authix service, the dashboard, the API design, the documentation and the Neuctra name and logo belong to us. Our SDKs are published under their own licences, which govern their use.

If you send us feedback or a feature suggestion, we may act on it without owing you anything. This is not a claim over your ideas generally — it just means we do not want a bug report to create an obligation.

9.Warranties and liability

Read this section

Neuctra Authix is provided “as is” and “as available”, without warranties of any kind, express or implied, including merchantability, fitness for a particular purpose and non-infringement. We do not warrant that the service will be uninterrupted, error-free or secure against every attack.

To the fullest extent the law allows, we are not liable for indirect, incidental, special or consequential damages, nor for lost profits, lost revenue, lost business or lost or corrupted data.

Our total liability for any claim relating to Neuctra Authix is capped at the greater of the amount you paid us in the 12 months before the claim or USD 100. On a free account that cap is USD 100.

Nothing here limits liability that cannot lawfully be limited — including death or personal injury caused by negligence, and fraud. Some jurisdictions do not allow certain exclusions, so parts of this section may not apply to you.

10.Ending the agreement

  • You may close your account at any time, for any reason, from the dashboard. Export anything you want to keep first.
  • We may terminate for a material breach of these terms, for non-payment, or if we discontinue the service. Except for serious abuse, we will give you at least 30 days' notice and a reasonable chance to export your data.
  • On termination, access stops and your data is deleted after a short grace period. Sections covering intellectual property, liability and governing law survive.

11.Governing law and contact

These terms are governed by the laws of [jurisdiction], and the courts of [jurisdiction] have exclusive jurisdiction over any dispute — without affecting mandatory consumer protections in your own country.

Before starting a formal dispute, please write to us. Most problems are a misunderstanding and are resolved in a single email.

If any provision here is unenforceable, the rest stands. Not enforcing a term once does not waive it.

Legal notices: legal@neuctra.com · Security: security@neuctra.com · Everything else: contact us.

[registered company name], [registered address], [company registration number].