Agreement and provider
These Terms of Service govern Actionbox, a hosted human decision layer service operated by Suson Sapkota, operating Actionbox ("Actionbox", "we", "us", or "our"). They apply to the Actionbox website and dashboard at actionbox.cloud, the API at api.actionbox.cloud, related clients, SDKs, CLI tools, documentation, integrations, and any mobile application that Actionbox makes available (together, the "Service").
By creating an account, signing in, creating a Source, or using the Service, you agree to these Terms and the Actionbox Privacy Policy. If you use Actionbox for an organization, you represent that you have authority to accept these Terms for that organization.
Service tiers, billing, and Merchant of Record
Actionbox is a hosted service. Customer integrations use the production Actionbox API and dashboard; the current customer workflow does not include a local or self-hosted Actionbox server.
The Service is provided on an evolving basis. We do not promise uninterrupted availability, fixed response times, or that every client, notification surface, callback, or native application will always be available. Standard self-serve tiers do not include a financially backed uptime Service Level Agreement (SLA). Do not use the Service as the sole control for an emergency, safety-critical operation, or irreversible production action.
Payments, recurring subscriptions, and licensing are processed through an authorized Merchant of Record (MoR, such as Paddle or Lemon Squeezy). The Merchant of Record is the legal entity of record for financial transactions and manages billing, invoicing, currency conversion, local sales tax (VAT/GST), and PCI-DSS compliance. Actionbox does not collect, process, or store raw payment card numbers or security codes.
Paid subscriptions (such as Pro or Team tiers) are billed in advance on a recurring monthly or annual basis as selected during checkout. Subscriptions renew automatically unless cancelled before the renewal date. You may cancel your subscription at any time from your account settings; cancellations take effect at the conclusion of your current prepaid billing cycle. Plan upgrades take effect immediately with prorated billing. We offer a 14-day money-back guarantee for first-time paid subscriptions upon written request to our contact email or through the Merchant of Record.
Accounts and sign-in
The production Service uses Google OAuth and, when enabled for the relevant client, Sign in with Apple. Any mobile application that Actionbox makes available uses the provider's sign-in flow and exchanges the resulting credential for an Actionbox session. You are responsible for using an account you control, keeping access to that identity provider and your device secure, and promptly telling us if you believe your account or session has been compromised.
Actionbox may restrict beta access to an allowlist, refuse or revoke access, or require a new sign-in when security or operational conditions require it. You may not share an account or use another person's credentials without permission.
Mobile applications and app stores
If Actionbox makes an iOS or Android application available to you, these Terms govern your account and use of the hosted Service through that application. Download and use are also subject to the applicable Apple App Store or Google Play terms and usage rules. If you obtain an iOS application through Apple's App Store, Apple's Standard Licensed Application End User License Agreement governs the licence to that copy unless another end-user licence is presented with it; these Terms continue to govern your Actionbox account and the hosted Service.
Subject to these Terms and the applicable platform rules, Actionbox grants you a limited, non-exclusive, non-transferable, revocable licence to install and use any mobile application that Actionbox makes available on devices you own or control solely to access the Service. Actionbox, not Apple or Google, is responsible for that application and Actionbox support. Apple and Google have no obligation to provide maintenance or support except as their own terms require.
Mobile functionality depends on a compatible device and operating system, internet connectivity, the permissions you choose, and third-party platform services. We may issue security or compatibility updates and may require a supported application version. Push notifications are optional and are not a substitute for checking authoritative Action state in the Service.
Signing out or uninstalling the application does not delete your hosted Actionbox account or server-side records. Use Delete account in the mobile application or dashboard, or follow the deletion process in the Privacy Policy, when you want account data deleted. Paid plans are currently purchased and managed through Actionbox's web checkout and Merchant of Record rather than through an in-app purchase flow.
Sources, Actions, and customer content
A Source is a machine identity for a script, bot, pipeline, agent, or other integration. Source API keys authorize machine requests and must be treated like passwords. The raw key is shown only at creation or rotation; you are responsible for storing it securely, limiting its use, and rotating or revoking it when it is exposed or no longer needed. Any API request authenticated with a valid Source Key is deemed authorized by you; Actionbox has no liability for unauthorized API activity or consumption resulting from credentials leaked or exposed by the customer.
An Action is a durable question or request created by a machine. You control the titles, descriptions, options, typed interaction definitions, metadata, callback URLs, and responses that you submit ("Customer Content"). You retain all ownership rights in Customer Content. You grant Actionbox only the limited license needed to host, store, secure, display, transmit, deliver callbacks for, back up, and operate the Service on your behalf.
Actionbox will never sell your Customer Content or use your Action titles, descriptions, options, metadata, code snippets, form inputs, or decision responses to train artificial intelligence or machine learning models.
You may not sublicense, rent, resell, lease, or white-label access to the Actionbox API or dashboard as a standalone commercial product without our prior written authorization.
Do not put passwords, Source tokens, OAuth secrets, payment-card data, health information, government identifiers, or other sensitive information into Action titles, descriptions, metadata, options, or callback payloads unless you have a documented legal and security basis to do so. Actionbox is not a regulated data-processing service by default.
Callbacks, webhooks, and push notifications
If you provide a callback_url, Actionbox queues a signed webhook after a terminal Action event. You are responsible for using an HTTPS endpoint, validating the Actionbox signature and timestamp, handling retries and duplicate deliveries safely, and authorizing the receiving system to act on the payload.
A callback failure does not undo or reopen a human decision. You remain responsible for reconciling webhook delivery status with the API, avoiding recursive webhook loops, and ensuring your receiving endpoint can handle incoming delivery volume without crashing.
Mobile and desktop push notifications rely on third-party carrier and platform networks, including Apple Push Notification service (APNs) and Google Firebase Cloud Messaging (FCM). Notifications are delivered on a best-effort basis without delivery time guarantees; notifications may be delayed, grouped, or suppressed by device power modes, operating system settings, or upstream network conditions.
Acceptable use and high-risk activities prohibition
You may use the Service only for lawful purposes and in a way that does not harm the Service, other users, or the people and systems affected by your workflows.
- Do not use the Service to violate law, regulation, a contract, or another person's rights.
- Do not send malware, credential-harvesting content, unlawful surveillance, spam, or content designed to deceive or harm.
- Do not probe, scan, reverse engineer, bypass rate limits, defeat authentication, or attempt to access another user's Sources, Actions, sessions, devices, or metrics.
- High-risk activities prohibition: Do not use Actionbox as a fail-safe control or primary signaling mechanism for emergency dispatch (911/112), life-support or medical diagnosis systems, nuclear or chemical facilities, weapons systems, autonomous vehicle navigation, high-frequency financial trading, or other high-risk operations where delayed, incorrect, or omitted delivery could reasonably cause physical injury, loss of life, or severe environmental or financial catastrophe.
- Do not create unreasonable traffic, automated account farms, recursive loops, or integrations that interfere with the availability or security of the Service.
- Do not access or use the Service if you are located in a comprehensively sanctioned or embargoed jurisdiction or identified on applicable government restricted-party lists.
Security responsibilities
Actionbox applies reasonable technical controls for the current MVP, including HTTPS at the public edge, secure HttpOnly sessions, hashed Source keys and sessions, authorization boundaries, callback validation, rate limiting, backups, and privacy-filtered product analytics. No service or transmission method is completely secure.
You are responsible for your own code, infrastructure, Google or Apple account, Source-key storage, callback endpoint, access controls, exported data, and decisions made from Actionbox notifications. Report suspected vulnerabilities or unauthorized access to us at the contact address below and do not exploit or disclose a vulnerability while it is being investigated.
Intellectual property and publicity
The Service, its software, visual design, documentation, names, logos, and underlying technology are owned by Actionbox or its licensors. These Terms give you a limited, non-exclusive, non-transferable right to use the Service during the applicable account period. They do not transfer our intellectual property to you.
You may provide product feedback. You grant us permission to use that feedback without restriction or payment, provided we do not identify you publicly without permission.
Publicity: Unless you opt out by emailing us at our contact address, Actionbox may identify you or your organization as an Actionbox customer by displaying your name, logo, or public trademark on our website and marketing materials.
Data protection and Data Processing Addendum (DPA)
Between the parties, you are the Data Controller (or Business) and Actionbox is the Data Processor (or Service Provider) with respect to Customer Content processed through the Service. You are solely responsible for ensuring you have all required notices, legal bases, and consents to submit personal data to Actionbox.
For customers subject to GDPR, UK GDPR, or CCPA/CPRA, our standard Data Processing Addendum (DPA) incorporating Standard Contractual Clauses (SCCs) is available upon written request to our contact address and applies to the processing of personal data within Customer Content.
Third-party services
The Service relies on third-party infrastructure and providers, including Google and Apple for sign-in, hosting and infrastructure providers for the API, database, queues, backups, and delivery, and PostHog for privacy-filtered product analytics. Those providers may have their own terms and privacy notices. We are not responsible for third-party services that we do not control.
You are responsible for any third-party system you connect to Actionbox, including a callback receiver, CI provider, cloud account, or native client environment.
Suspension and termination
You may stop using the Service at any time by signing out, uninstalling a client, and revoking Sources and keys. Those actions alone do not close your hosted account; use the self-service Delete account control or contact us about account closure. We may suspend or terminate access if you materially breach these Terms, create a security or legal risk, abuse the Service, fail to provide required information, or if we discontinue the MVP.
Suspension or termination may prevent new machine requests and dashboard access. It does not automatically erase historical Actions, events, webhook records, backups, or legally required records. The Privacy Policy explains the current deletion and retention process.
Indemnification
You agree to defend, indemnify, and hold harmless Actionbox, its operators, contractors, and licensors from and against any third-party claims, damages, liabilities, losses, and reasonable legal expenses arising out of or related to your Customer Content, your automated workflows, your use of the Service in violation of applicable laws, or your breach of these Terms.
Disclaimers, force majeure, and liability limits
To the maximum extent permitted by law, the Service is provided on an "as is" and "as available" basis without warranties that it will be uninterrupted, error-free, secure, or suitable for a particular workflow. You make your own decisions about whether a human approval, callback, notification, or API result is sufficient for your use case.
Force Majeure: Actionbox is not liable for any failure or delay in performing its obligations caused by events beyond reasonable control, including acts of God, natural disasters, utility or telecommunication failures, cyberattacks, denial of service attacks, cloud infrastructure or third-party OAuth outages, or governmental actions.
To the maximum extent permitted by law, Actionbox and its provider will not be liable for indirect, incidental, special, consequential, or punitive damages, lost profits, lost revenue, lost data, or business interruption. Aggregate liability arising from or related to the Service is limited to the greater of CAD $100 or the total amounts paid by you to Actionbox in the 12 months preceding the claim. These limits do not exclude liability that cannot lawfully be excluded.
Governing law and disputes
These Terms are governed by the laws of Nepal, without regard to conflict-of-law rules. Before filing a claim, contact info@actionbox.cloud and allow 30 days for a good-faith informal resolution attempt.
If a dispute cannot be resolved informally, the courts located in Kathmandu, Nepal will have exclusive jurisdiction, except where applicable consumer law gives you a mandatory right to bring a claim elsewhere.
Changes and contact
We may update these Terms as the Service changes. The effective date at the top of this page identifies the current version. If a change materially affects users, we will provide notice through the Service or the account contact information we have.
Questions, account closure requests, security reports, and legal notices should be sent to info@actionbox.cloud. Please include enough context for us to identify the relevant account or request without sending credentials, Source tokens, or OAuth secrets.
Questions about this policy?
Contact the Actionbox team.
Suson Sapkota, operating Actionbox maintains these policies for the hosted Actionbox service.
Email info@actionbox.cloud