Legal
Terms of Service
Agent Vault lets software agents spend your money and sign in as you. These terms set out what we provide, what we do not promise, and, importantly, what you remain responsible for when an agent acts on your behalf.
1. The agreement
These terms are a contract between you and SocialConnect Labs, Inc. dba Self Labs, a Delaware corporation(“we”, “us”), the operator of Agent Vault, a product of Self.xyz. By creating an account or using the service you agree to them. If you do not agree, do not use the service.
Our Privacy Policy forms part of this agreement and describes what we do with your data. Where the two documents describe the same behaviour, they are intended to agree; if they conflict, the Privacy Policy governs how data is handled.
If you are agreeing on behalf of a company, you confirm you are authorised to bind it, and “you” means that company.
2. What the service does
You store payment cards, postal addresses, identity details, and site logins in Agent Vault. You then issue an API key to an AI agent. That key can be restricted to specific cards and logins, and a card placed behind an agent card can be bounded by spending limits, merchant allowlists, and approval requirements. API-key scope, allowlists and approval requirements are not applied by default: a key created without them reaches every card and login on your account, and identity details and addresses cannot be restricted per key at all. Spending limits are, the first funding card you add through the dashboard is given an agent card carrying starter caps of $75 per transaction, $200 per week and $500 per month, plus $100 per day on plans that allow a daily cap. Those are defaults, not a ceiling we enforce for you: you can change or remove them, and a card you add another way may have none. §12 of the Privacy Policy sets out which control covers which value.
A key can also be granted one further power: creating a login, which is off unless you switch it on, per key. With it, your agent can sign you up for an account on a site and save the result to your vault without asking you first. The password is generated in our backend and is never shown to your agent, and never shown to you, the agent receives only a mock token and the dashboard has no reveal button. That is the point of it: a password neither of you has read is one neither of you can be tricked into repeating. If you want a password you can type yourself, reset it on the site and save the new one here. A key with this power may also complete a site’s two-factor setup, in which case the agent tells our proxy where on the page the site printed the setup key, never what it says. These writes are capped per day, emailed to you as they happen, and listed in your activity feed.
When your agent shops or signs in, it fills forms with mock tokens, placeholder values that carry no secret. Our checkout proxy runs the actual browser and substitutes your real values into the page at the last moment, after our backend has authorised that specific use. Your card number, security code and password are never returned to the agent through our API, and are redacted from screenshots and error text. That is a narrower promise than “the agent never has them”, and deliberately so: your agent controls the session. The keyboard route out is closed, though, once a real value has been substituted into a session, the proxy refuses every clipboard-capable chord, so a value the agent cannot read cannot be copied out with a shortcut either. §4 of the Privacy Policy describes the path and the guard (issue #252).
The browser runs on our infrastructure, but by default its network traffic is relayed back out through the machine running your agent, so merchants see your IP address rather than ours. This is deliberate, a datacenter IP blocks many checkouts, and it is switchable. The default prefersthe relay rather than requiring it, and an attested checkout reaches the merchant from our datacenter instead, so that path shows our address even on default settings. Pass tunnel: true to make the relay mandatory. See §4 of the Privacy Policy.
Where a site raises a challenge the agent cannot pass, the session can be handed to you: a live view of the proxy’s browser is streamed to you and your input is relayed back so you can complete the step. That view is reached through an emailed link, and the link itself is the credential, it does not require you to be signed in, and it stays usable until the handoff expires or settles rather than being spent on first use, so treat it like a password reset email (see §7 of the Privacy Policy). Where a purchase needs a card security code, we prompt you for it at that moment.
We are not a payment processor, a bank, or a money transmitter. We do not hold, move, or settle funds. Purchases are made directly between you and the merchant with your own payment card; we automate the filling of their form.
3. Eligibility and your account
- You must be at least 18 and legally able to enter into this contract.
- You must give accurate account information and keep it current. You are responsible for everything done under your account.
- Your API keys are credentials. Anyone holding one can direct spending within its scope and limits. Keep them secret, scope them narrowly, and revoke them immediately if exposed, you can do this from the dashboard at any time.
- Tell us promptly at legal@self.xyz if you suspect unauthorised access.
4. You are responsible for your agent
This is the most important clause in this document.
- An action taken by your agent, with your key, within the limits you set, is your action. Purchases it makes are real purchases on your real card, and you owe the merchant for them. Sign-ins it performs are your sign-ins.
- An account your agent opens is your account. If you let a key create logins (§2), the agreement your agent enters into with that site is yours, its terms, its charges, and its cancellation policy. It signs up under whatever email address you gave it, and the site will treat whoever controls that mailbox as the account holder, so give an agent an address you own and can read. We do not read the site’s terms for you and cannot tell you whether it permits an automated signup at all (§9).
- AI agents are non-deterministic. Yours may buy the wrong item, the wrong quantity, from the wrong merchant, at the wrong price, or at the wrong time. It may be manipulated by content on a page it visits into doing something you did not intend. We give you controls to bound that risk: per-card spending limits, merchant allowlists, approval prompts, and keys that are scoped and revocable. They reduce it; they do not remove it. Set limits you can afford to lose.
- Know what “pause” actually pauses. An agent card’s merchant allowlist, pause control, and approval threshold apply to card and security-code fills. Its spending limits apply to card-number fills only, a checkout that asks for the security code alone can still be stopped by a pause, an allowlist or an approval, but it is not counted against your limits. None of them stop an agent resolving a saved password, a one-time code, an identity field, or an address. If you need to stop an agent completely, revoke its API key, that halts every kind of resolution at once, with one exception: a challenge handoff already open on your phone and still connected keeps driving the paused session, so do not complete one after revoking (issue #212). A link you have not opened yet, and an open page whose connection drops and tries to reconnect, are both refused. A security-code request is not an exception, the card is re-authorised after you enter the code and before it is released, so revocation stops it. Closing the pause gap is tracked as issue #181.
- You are responsible for reviewing your activity feed and for disputing incorrect charges with the merchant or your card issuer. We are not a party to those transactions and cannot reverse them.
- You confirm that you own, or are authorised to use, every card, address, identity detail, and login you store or let an agent create for you, and that you may lawfully authorise an automated agent to use them.
5. Card vault and stored credentials
Card numbers you add are stored with Basis Theory, a PCI-DSS Level 1 certified tokenization vault; of the number we hold only a token reference. We do keep the card’s metadata ourselves, last four digits, brand, expiry month and year, cardholder name, and which billing address it uses, so the dashboard can show you the card and a checkout can fill those fields. Security codes are not stored, you are prompted for one per purchase. Site passwords and one-time-code seeds are stored, encrypted at rest.
Those statements describe what the system does with data you add now. Records left by the designs that preceded the vault, the live-security-code flow, and the current credential encryption are still being purged and re-keyed, and §5 and §6 of the Privacy Policy set out exactly what that means. Read them rather than this summary if the detail matters to you.
Evaluation status. Our account with Basis Theory is currently an evaluation tenant, not a production plan, so a card added here is stored in their test tenant. Use test cards only.
Whose certification is whose. Basis Theory’s PCI-DSS Level 1 certification belongs to Basis Theory and describes their vault. It is not a certification of Agent Vault. We hold no PCI, SOC 2 or ISO certification and make no such claim about ourselves.
Where your card number is revealed. To type your card into a merchant’s checkout, our proxy retrieves the number from the vault and holds it in memory, not only for that fill, but for the rest of that agent session, so it can blank the value out of screenshots and error messages. It is never written down. That is what happens wherever card filling works at all today; a deployment not configured to fill cards refuses before any number is retrieved. The proxy runs on Confidential GKE nodes, so that memory is encrypted in use by the processor. Our software also carries a second, attested checkout path that would move the reveal into an isolated enclave so that not even we can see it, but that enclave is not deployed: every attested checkout is refused before a card is handed over, and we do not claim that protection. See §5 of the Privacy Policy.
Logins your agent created. A login opened by an agent under §2 is stored exactly like one you added, with one difference: we cannot show you its password. It was generated in the backend and written straight into encrypted storage without ever being rendered, so there is no path in the product that displays it, to you or to anyone here. We are not withholding it; we do not have a way to read it out. The rest of the record, the site, the username, and whether a one-time-code seed is attached, you can see and edit like any other. Deleting it deletes our copy and nothing more, closing the account is something you do with the site.
Many sites’ terms restrict credential sharing and automated access. Storing a login, letting an agent open one, and authorising an agent to use it are your decisions, and you are responsible for whether each is permitted by that site. See §9.
6. Acceptable use
You will not, and will not configure an agent to:
- Store or use a card, address, identity detail, or login that is not yours or that you are not authorised to use.
- Make a purchase you do not intend to pay for, or commit payment fraud of any kind.
- Buy or attempt to buy anything unlawful where you or the merchant are located, or anything you are barred from purchasing.
- Use the service in breach of sanctions or export-control laws, or from a sanctioned jurisdiction.
- Automate access to a site in a way that breaches that site’s terms, or use the service to scalp, hoard, or circumvent purchase limits, queues, or anti-bot protections where doing so breaches those terms.
- Attempt to extract a stored secret through any channel other than an authorised fill, including by prompting an agent to reveal it, by exploiting a merchant page to echo it back, or by attacking the proxy.
- Probe, scan, overload, or interfere with the service or its infrastructure, or bypass any limit, quota, or authorisation check.
- Reverse engineer, resell, or provide the service to third parties as your own, except as the applicable open-source licences permit.
- Use the service to harass, defraud, or harm anyone.
We may investigate suspected breaches and take action under §14, including revoking keys or suspending an account, without notice where the risk warrants it.
7. Plans, payment, and cancellation
Plans
Agent Vault offers a free plan and paid plans. As at the effective date above: Free ($0), Plus ($10 per month), and Pro ($20 per month). Current prices and what each tier includes are shown on our pricing page and prevail over this summary.
Billing
- Paid plans are billed monthly in advance through Stripe. By subscribing you authorise recurring charges to your payment method until you cancel.
- Your card details for the subscription are entered on Stripe’s hosted pages and are handled by Stripe under their terms. We never see them.
- Changing tier mid-cycle is prorated: Stripe adjusts the charge for the remainder of the period.
- Prices are stated exclusive of any applicable sales tax, VAT, or GST. We do not currently calculate or collect any such tax at checkout, the amount you are charged is the listed price, and any tax due on the transaction is your own responsibility. If we begin collecting tax, it will be shown before you confirm and we will update these terms first.
- We may change prices. We will give you at least 30 days’ notice by email before a change applies to your next renewal, and the new price takes effect only from that renewal. If you do not want the new price, cancel before it starts.
Cancellation and refunds
- You can cancel at any time. Where the dashboard’s Billing page can open Stripe’s billing portal, cancel there; the portal shows when the cancellation takes effect and whether you keep paid features until the end of the period you have paid for, and it is authoritative over this summary.
- If that button is not available, email us and we will cancel for you. The portal requires a billing-portal configuration that our checkout flow does not, so a deployment can take your subscription while the Billing page still shows “billing management is coming soon”. In that state there is no in-product way to cancel, and the right to cancel does not depend on our having shipped the button: legal@self.xyz reaches us, and we will action it and refund anything billed after your request.
- Fees already paid are not refunded, and cancelling part-way through a period does not produce a partial refund for the unused remainder, except where the law requires otherwise, where we have billed you in error, or where we bill you after you asked us to cancel. In each of those cases we refund the amount in question.
Deleting your account cancels your subscription. The deletion lists your live subscriptions at Stripe and cancels them before it erases anything, and it refuses to delete the account at all unless it can confirm they are gone. So a deletion that goes through has ended the billing it could see.
One gap survives that, and we would rather name it than round the sentence up. A subscription can begin between the last check and the erasure committing; what catches one that does is the deletion of your Stripe customer, which the erasure schedules and which cancels whatever is on that customer. If that job exhausts its retries, such a subscription can outlive the account. If anything is billed after your account is gone, email legal@self.xyz and we will cancel it and refund what was charged.
A deletion that does not go through keeps your account and your data, but the wind-down runs before the erasure, so a cancellation that had already taken effect at Stripe stays in effect. The error tells you what had landed before it stopped.
The case it refuses is a subscription that starts during the deletion, which a Stripe billing-portal tab you still have open can do. You are told the account was not deleted and that trying again will cancel the new subscription too. If you ever find an amount billed after an account of yours was deleted, contact legal@self.xyz and we will cancel it and refund that amount.
Non-payment
If a charge fails we may downgrade or suspend paid features. Free-plan limits then apply, which may cause agent requests exceeding those limits to be refused.
8. Closing your account
You may close your account at any time. §10 of the Privacy Policy sets out what closure does, and just as importantly what it does not do. In summary:
- Closure deletes your cards’ records, logins, addresses, agent cards, every approval, security-code and challenge prompt (settled ones as much as pending), webhook logs, and push subscriptions, and revokes every API key so no agent can resolve another real value.
- Closure is not an emergency stop. It does not tear down a proxy session that is already running. Revoking the keys stops that session obtaining any further real value, a card, a code, a password, an identity field, or an address, from the moment it lands. But the browser it already has stays up until the session ends by itself or hits its one-hour ceiling, and in that window it can still navigate, click, and submit whatever was already typed into the page. So a purchase already in flight may still complete. A security-code or challenge prompt already open when you close the accountis cancelled: closure deletes those requests, so the link stops working even if it is already in your inbox, but only one that is still pending. A challenge handoff whose viewer has already attached keeps running: deletion removes the request record, which stops any new attach or reconnect, while the viewer already connected goes on driving that browser through the live session until it ends. What closure does not undo is a prompt you already completed, a code you supplied a moment earlier is with the merchant, not with us, and the proxy also keeps it in that session’s memory until the session ends so it can redact it from screenshots and error text (§4, §5, issue #212). If you need an agent stopped, stop the agent first; closure locks it out of anything new, but it is not a way to halt something already under way.
- Closure erases transaction history, agent session records with their events and their receipt screenshots, notification history and revoked API key records. Some of that happens as you close the account and the rest in a background sweep. We do not put a completion time on the sweep: it works in bounded passes and a large account takes more of them, and a run that stalls is picked up by a daily retry rather than by a deadline.
- What closure keeps is a contribution that reached the registry: the recipe stays, because the registry is shared and public, with the submitter id rewritten away and the maintainer note you wrote alongside it removed. A contribution that never reached the registry is deleted with everything else. See Privacy §10 for the detail.
We cannot confirm that closure removes your card number from the vault. The instruction to destroy the vaulted card goes to Basis Theory directly, but it needs a delete-only vault key, and we have not provisioned one, so no deployment holds a working key today. Without it, every attempt stops at the check for it, retries, and gives up. We delete our reference; treat the card as still stored at Basis Theory until removed by hand. Email legal@self.xyz to have it destroyed.
Closure cancels a paid subscription, and refuses to proceed if it cannot confirm the cancellation. See §7.
There is no button for account closure or data export in the dashboard, and no support tooling behind them either, both are self-service functions that authenticate as you, so fulfilling an emailed request means an operator doing it by hand. Email legal@self.xyz and we will honour it within 30 days; see §11 of the Privacy Policy for what that covers.
9. Third-party sites and services
The service directs a browser to sites we do not control. Your relationship with any merchant or site is between you and them, governed by their terms and their privacy policy. We are not a party to it, we do not endorse them, and we are not responsible for their goods, services, pricing, availability, or conduct.
That includes the merchant’s payment processor. Many checkouts embed card fields hosted by a provider such as Stripe or Adyen, and your card number, expiry and security code go to that provider rather than to the merchant’s own servers. The merchant chooses them, not us, and their handling of your card is governed by their terms. See §4 of the Privacy Policy.
You are responsible for complying with the terms of every site your agent touches. Many sites restrict automated access, account sharing, or credential sharing. If a site prohibits what you are asking your agent to do, do not ask it. Your account there may be suspended or closed as a result, and that is between you and them.
We rely on the sub-processors listed in §8 of the Privacy Policy. Their availability affects ours; an outage at any of them may make part or all of the service unavailable.
10. Intellectual property and feedback
We and our licensors own the service, its software, and its branding, except for the components published under open-source licences, which are governed by those licences. You get a limited, non-exclusive, non-transferable, revocable right to use the service under these terms. Nothing here transfers ownership.
Your data stays yours. You grant us only the licence needed to operate the service for you: to store your data, and to transmit your stored values into the forms your agent is authorised to fill. We do not use your vault data to train models and do not sell it.
A registry contribution is the exception, and it has to be. When your agent calls POST /v1/recipes, you grant us a non-exclusive, worldwide, royalty-free licence to send that recipe and the note you attach to it to Anthropic for screening. For the recipe — and for the note, where a maintainer approves it as the evidence for a verified claim — you also grant us and everyone who uses the registry a perpetual, irrevocable, worldwide, royalty-free licence to use, publish, edit, copy, adapt, merge, replace and redistribute it, alone or combined with other recipes. Nothing narrower would do: the entry is served publicly, other people copy it into their own systems, and we cannot reach what they took. You keep the copyright and you confirm the recipe is yours to send. The licence covers the recipe and its note and reaches nothing else in your vault. Closing your account does not withdraw it (§8), and neither does deleting the submission on our side. §2 of the Privacy Policy describes what happens to a submission at each stage.
If you send us feedback or suggestions, we may use them without restriction or obligation to you.
11. Disclaimers
The service is provided “as is” and “as available”, without warranty of any kind. To the fullest extent permitted by law we disclaim all warranties, express or implied, including merchantability, fitness for a particular purpose, title, and non-infringement.
We specifically do not warrant that:
- the service will be uninterrupted, timely, secure, or error-free;
- an agent will act correctly, buy the right thing, respect your intent, or resist manipulation by content on a page it visits;
- a checkout or sign-in will succeed on any given site, or continue to work as that site changes;
- spending limits, allowlists, or approvals will catch every unwanted action;
- stored data will be free from loss, or that our security measures cannot be defeated.
Nothing in these terms excludes liability that cannot lawfully be excluded, including for death or personal injury caused by negligence, or for fraud. Some jurisdictions do not allow the exclusion of implied warranties, so parts of this section may not apply to you.
12. Limitation of liability
To the fullest extent permitted by law, and except for liability that cannot lawfully be limited:
- We are not liable for indirect, incidental, special, consequential, exemplary, or punitive damages, or for lost profits, lost revenue, lost data, or loss of goodwill, however caused.
- We are not liable for purchases made by your agent, for goods or services obtained through the service, or for the acts or omissions of any merchant, site, or sub-processor.
- Our total aggregate liability arising out of or relating to the service is limited to the greater of (a) the fees you paid us in the 12 months before the event giving rise to the claim, and (b) USD 1,000.
These limits apply even if a remedy fails of its essential purpose, and they reflect an agreed allocation of risk for a service offered at these prices.
13. Indemnity
You will indemnify and hold us harmless against claims, damages, losses, and reasonable costs arising from your use of the service, from anything your agent does with your keys, from your breach of these terms or of any third-party site’s terms, or from your infringement of anyone’s rights. We will notify you of any such claim and you may control its defence, provided any settlement releases us fully and imposes no obligation on us.
14. Suspension and termination
You may stop using the service and close your account at any time (§8). We may suspend or terminate your access, revoke API keys, or remove content if you breach these terms, if we reasonably suspect fraud or unlawful use, if required by law or by a provider, or if we discontinue the service.
Where the circumstances allow, we will give notice and an opportunity to fix the problem first. On termination your right to use the service ends; sections that by their nature should survive, §4, §10, §11, §12, §13, §16, do survive.
15. Changes
We may change these terms as the service changes. For material changes we will update the effective date at the top and notify account holders by email or in the dashboard before they take effect. Continuing to use the service after that means you accept the new terms; if you do not, stop using the service and close your account.
This document is in force as of the effective date shown at the top.
16. Governing law and disputes
These terms are governed by the laws of the State of Delaware, without regard to its conflict-of-laws rules.
Binding arbitration. Any dispute, claim or controversy relating in any way to these terms or to your use of the service will be resolved by binding arbitration rather than in court, conducted under the expedited procedures of the JAMS Comprehensive Arbitration Rules and Procedures. The seat of the arbitration is San Francisco, California. Judgment on the award may be entered in any court of competent jurisdiction, and suits to compel or enforce arbitration may be brought in the United States District Court for the District of Delaware, in Wilmington, Delaware.
No class actions. You and we each agree to bring claims against the other only on an individual basis, and not as a plaintiff or class member in any purported class or representative proceeding. If for any reason a claim proceeds in court rather than in arbitration, both parties waive any right to a jury trial.
If you are a consumer, nothing here deprives you of the protection of mandatory provisions of the law of the country where you live, or of your right to bring proceedings there.
If a provision of these terms is held unenforceable, the rest remains in force. Our failure to enforce a provision is not a waiver of it. You may not assign this agreement without our consent; we may assign it in connection with a merger, acquisition, or sale of assets. These terms, with the Privacy Policy, are the entire agreement between us about the service.
17. Contact
General and billing support: legal@self.xyz
Privacy and data protection: legal@self.xyz
Legal notices: SocialConnect Labs, Inc. dba Self Labs, a Delaware corporation, at legal@self.xyz