BackendX Terms of Use

Effective Date: September 7th, 2026 Last Updated: September 7th, 2026 Contact: team@email.backendx.ai

These Terms of Use ("Terms") govern the use of the BackendX service (the "Service") provided by BackendX Inc. (주식회사 백엔드엑스) (the "Company").

BackendX is a software-as-a-service (SaaS) platform that enables users to generate, deploy, and manage backend services online. The Service includes software features that process user-submitted requirements and configurations to generate outputs such as source code, infrastructure definitions, deployment-related artifacts, and related software-generated results.

By creating an account or using the Service, you ("User") agree to be bound by these Terms and related policies.

These Terms apply to users worldwide. Mandatory consumer protection rules of the User's country of residence may apply to the extent required by law.


1. Definitions

  1. "User" means any individual or legal entity using the Service.
  2. "Account" means a login identity created to access the Service.
  3. "Requirements" means any user-submitted descriptions, specifications, text, or configuration inputs.
  4. "Task" means a software-generated or software-processed unit of work requested through the Service, such as backend generation, modification, deployment-related execution, or related in-product workflows.
  5. "Subscription" means a recurring paid plan attached to an individual project (the project is the billing unit) that determines that project's feature access, deployment tier, included Seats, and included Change-Runs. Subscriptions are offered in tiered plans and billed on a monthly or yearly basis.
  6. "Seat" means an entitlement for one user to participate as a member of a subscribed project. Each plan includes a stated number of Seats, and additional Seats may be purchased on eligible plans.
  7. "Change-Run" means a limited usage entitlement to run one regeneration of a project (an update of the generated service from revised Requirements). Change-Runs may be included in a Subscription on a recurring monthly basis or purchased separately as top-up Change-Runs.
  8. "Output" means any generated source code, configuration files, documents, scripts, or infrastructure definitions (IaC), together with artifacts built from them (including container images and deployment bundles).
  9. "Access Token" means cloud API credentials provided by the User (e.g., AWS Access Key ID/Secret Access Key, Google Cloud service-account keys, or equivalent credentials) that the User registers with the Service for Customer-Cloud deployment and operation.
  10. "Billing Policy" means the separate policy titled "Subscription & Billing Policy" governing Subscriptions, Seats, Change-Runs, payments, cancellations, and refunds.
  11. "Deployment Option" means the manner in which a generated service is hosted and operated, as described in Section 2: Managed Hosting, Customer-Cloud (Company-Operated), or Self-Operated (Export).
  12. "Self-Operated (Export)" means a Deployment Option in which the Company generates and delivers the Outputs to the User and the User hosts and operates the generated service entirely on its own, without the Company hosting, operating, accessing, or processing the generated service or any end-user data.

2. Deployment Options

  1. The Company may continue to evolve the Service through successive releases as the Service matures, and may introduce, expand, or phase out features accordingly.
  2. The Service offers the following Deployment Options, distinguished by who operates the generated service:
    • Managed Hosting (default). The Company hosts and operates the generated service on shared, multi-tenant infrastructure managed by the Company (currently located in the AWS Asia Pacific (Seoul) region). Projects are isolated at the application, network, and database level (including a dedicated database and database role per project on shared database infrastructure). The User is the controller of end-user personal data processed through the generated service; the Company processes such data as a processor (consignee) on the User's behalf and in accordance with the User's documented instructions, as further described in the Privacy Policy and the Data Processing Agreement referenced in Section 12. Managed Hosting is currently offered on a shared-infrastructure tier; higher plan tiers may provide additional isolation (such as a dedicated network environment) and additional features (such as custom domains), and a fully dedicated-infrastructure tier may be offered in a later phase, in each case as described in the plan descriptions in the Service.
    • Customer-Cloud (Company-Operated). The generated service runs in the User's own cloud account, and — at the User's request and only within the scope of an Access Token the User registers with the Service — the Company provisions and operates it on the User's behalf (including deployment, monitoring, scaling, and operational assistance) as described in Section 11. Even where the generated service and its associated data reside in the User's own cloud account, to the extent the Company processes end-user personal data on the User's documented instructions while performing the above work, the User is the controller of end-user personal data and the Company acts as a processor under a separate operational delegation arrangement. In that case, Section 12 and the Data Processing Agreement (DPA) apply. Availability of this option, supported cloud providers, and supported regions are described in the Service.
    • Self-Operated (Export). The Company generates and delivers the Outputs to the User (Section 7), and the User hosts and operates the generated service entirely on its own — locally, on-premises, or in a cloud account the User controls — without the Company hosting, operating, accessing, or processing the generated service or any end-user data. In Self-Operated (Export) deployment the Company's role ends at delivery of the Outputs; the User is solely the controller and operator, and the Company is neither a controller nor a processor of end-user personal data. The Company provides no operational support for a Self-Operated deployment except as separately agreed in writing.
  3. The following scope limitations currently apply to generated services under Managed Hosting:
    • End-user file uploads are supported only with customer-provided storage: uploaded files are stored in storage the User provides and controls (e.g., the User's own Amazon S3 bucket), not on Company-managed infrastructure, as described in Section 8.5.
    • Services in the categories listed in Section 8.2 or Section 8.3 are not eligible for Managed Hosting: Section 8.2 categories are refused at interview, and Section 8.3 categories are refused at deployment.
  4. The Company may add, modify, restrict, suspend, or discontinue any feature of the Service.

3. Accounts and User Responsibilities

  1. Eligibility. The Service is available only to persons who have reached the age of majority under the law of their nationality, and in any case are at least eighteen (18) years of age. The User confirms at registration that they meet this requirement and warrants that the confirmation is accurate. The Company may refuse registration, or suspend or terminate an Account, where this requirement is not met.
  2. Users must provide accurate information and must not impersonate others.
  3. Users are responsible for safeguarding their Accounts and notifying the Company of any suspected unauthorized access.
  4. Users must not submit sensitive personal data or regulated information within Requirements except as expressly permitted by the Acceptable Use Policy in Section 8 and under a lawful basis applicable to the User. The Company applies the security measures described in the Privacy Policy but cannot guarantee against harm arising from submissions that violate these Terms or the Acceptable Use Policy.

4. Subscriptions, Seats, Change-Runs, and Payments

  1. The Service is offered through per-project Subscriptions: each project has its own Subscription plan (including a free tier), and charges for a project (plan fees, Seat fees, purchased Change-Runs, and any usage-based fees) are billed to that project's designated payment method. A free tier and a limited number of free projects per Account may be offered as disclosed in the Service.
  2. A Subscription may include a monthly Change-Run allowance. Unless otherwise expressly stated, included monthly Change-Runs reset at the start of each billing period, do not roll over into the next billing period, and expire if unused.
  3. Users may also purchase additional Change-Runs separately as top-up Change-Runs. Unless otherwise expressly stated, purchased top-up Change-Runs remain valid for twelve (12) months from the date of purchase and expire if unused after that period. Unless otherwise expressly stated, included monthly Change-Runs are consumed before purchased top-up Change-Runs.
  4. Seats. Each plan includes a stated number of Seats. On eligible plans, additional Seats may be purchased at the per-Seat price disclosed in the Service. Unless otherwise expressly stated: (a) Seat charges for a billing period are based on the highest number of Seats configured during that period; (b) Seat increases take effect immediately and are billed on the next invoice; (c) Seat decreases take effect at the start of the next billing period and do not entitle the User to a refund or credit for the current period; (d) Seats not in use at renewal (neither occupied by a member nor reserved by a pending invitation) are automatically reduced at the start of the new billing period — though never below the plan's included Seats — and are not billed for the new period; and (e) if the number of project members exceeds the available Seats at renewal, the Company may restrict excess members' access until Seats are added or members are removed.
  5. Usage-based fees. Certain plans include usage allowances (such as API-call volume or database storage). Where the Service so discloses, usage beyond an included allowance may be billed as overage on the next invoice, or — where the User enables a hard-stop option — the Service may instead restrict further usage for the remainder of the period.
  6. Change-Runs and other usage entitlements are used solely within the BackendX Service, are not cash, electronic money, stored value, deposits, or payment instruments, have no monetary exchange value outside the Service, and are non-transferable and non-resellable except where required by applicable law or expressly permitted by the Company.
  7. Plan entitlements, Seat rules, Change-Run validity, cancellation effects, and refunds (if any) are governed by the Billing Policy.
  8. Specific Subscription tiers, purchase options, or payment methods may be unavailable, limited, or offered on a preview basis. Payments are currently collected by the Company's wholly-owned U.S. payment subsidiary (BackendX US, Inc.) through a third-party payment processor (Stripe), acting solely as the Company's payment-processing agent, as further described in the Billing Policy; the Company will disclose current availability and payment methods through the Service.
  9. The Company may change Subscription tiers, included allowances, pricing, and feature access from time to time. Any such changes will be disclosed through the Service or by other reasonable means before they take effect for future billing periods, unless immediate changes are required by law, security, or abuse-prevention reasons.
  10. Unless otherwise expressly stated, the purchase of a Subscription, Seats, or Change-Runs does not include offline consulting, manual development services, or any physical goods.
  11. Automatic Renewal. Unless expressly stated otherwise at the time of purchase, Subscriptions automatically renew at the end of each billing period (monthly or annual, as applicable) for a successive period of the same length, and the Company (or its payment processor) will charge the User's designated payment method at the then-current price for the renewing period until the User cancels. By purchasing a Subscription, the User authorizes such recurring charges.
  12. Price-Change Notice. The Company will provide reasonable advance notice of any price increase that will apply at the next renewal, by email or through the Service, at least thirty (30) days before the increase takes effect (or such longer period as required by applicable law, including California Business & Professions Code §17602 and equivalent U.S. state automatic-renewal statutes). If the User does not wish to accept the new price, the User may cancel the Subscription before the renewal date; continued use after the effective date constitutes acceptance of the new price.
  13. Cancellation and "Easy Cancel." The User may cancel a project's Subscription at any time through the project's billing settings within the Service or by contacting team@email.backendx.ai. Cancellation will take effect at the end of the then-current billing period, and the User will retain access to paid features until that date, after which the project reverts to the free tier. The Company will not require the User to make a phone call, send mail, or otherwise leave the online account-cancellation interface in order to cancel, consistent with the U.S. FTC "Click-to-Cancel" standard and California Automatic Renewal Law requirements for online cancellation.
  14. Renewal Reminder. Where required by applicable law (including, without limitation, Korea's Act on Consumer Protection in Electronic Commerce and U.S. state automatic-renewal statutes), the Company will send a renewal reminder before each automatic renewal, identifying the amount to be charged, the billing date, and cancellation instructions.
  15. Free Trials and Introductory Offers. Where a free trial or introductory-rate Subscription is offered, the Company will disclose in a clear and conspicuous manner before the User's acceptance: (a) the length of the trial or introductory period, (b) the price that will apply after the trial/introductory period ends, (c) the renewal cadence, and (d) how to cancel before being charged. For EU and EEA consumers, the Company will comply with the "button solution" in Article 8(2) of Directive 2011/83/EU by labeling the purchase button with an explicit obligation-to-pay indication (e.g., "Order with obligation to pay" / "Subscribe and pay").

5. EU and EEA Consumer Rights

  1. If you are a consumer residing in the European Union or European Economic Area, you benefit from any mandatory consumer protection rights granted to you by the laws of your country of residence. Nothing in these Terms limits or excludes those mandatory rights.
  2. Where the Service is supplied to an EU or EEA consumer as a digital service or digital content, the Company will provide the service in conformity with the contract and with mandatory applicable law, including any mandatory rights relating to remedies for failure to supply or lack of conformity.
  3. If you are an EU or EEA consumer purchasing a Subscription or other digital service at a distance, you may have a statutory 14-day right of withdrawal from the date of conclusion of the contract, except to the extent an exception or reduction applies under mandatory law.
  4. If you ask us to begin supplying a paid digital service during the withdrawal period, you expressly request immediate performance. Where mandatory law so requires, we will obtain the additional confirmations needed for immediate performance and will inform you of the consequences for your withdrawal right.
  5. If you validly withdraw from a contract after requesting immediate performance of a digital service during the withdrawal period, you may be required to pay a proportionate amount for the service supplied up to the time of withdrawal, to the extent permitted by applicable law.
  6. If mandatory law grants you a right to terminate due to a negative modification of the Service, lack of conformity, or failure to supply, you may exercise that right notwithstanding any other provision of these Terms.

6. Account Deletion

  1. Users may request account deletion at any time, subject to Section 6.2.
  2. Owned projects first. An Account cannot be deleted while the User owns one or more projects. The User must first delete each project they own; each project deletion ends that project's Subscription in accordance with the Billing Policy and triggers the deletion of the project's data and artifacts as described in the Privacy Policy. When the User requests account deletion, the Service identifies any projects still owned by the User so they can be deleted. Where the User participates in projects owned by others, account deletion removes the User's membership from those projects without affecting the projects themselves.
  3. Upon account deletion, the Account may be permanently removed, and remaining Change-Runs and other unused entitlements may be forfeited or expire in accordance with the Billing Policy.
  4. Account deletion does not automatically trigger a refund. Refund eligibility for Subscriptions and unused purchased Change-Runs is governed by the Billing Policy and applicable laws.
  5. This Section governs deletion requested by the User. Suspension, restriction, or termination by the Company is governed by Section 14 and is not subject to Section 6.2.

7. Delivery of Outputs and GitHub Collaboration

  1. The Company generates each project's source code in a private, Company-controlled repository on Company-managed infrastructure. The Company may deliver Outputs to the User by one or more of the following methods, subject to the User's plan:
    • a downloadable source-code archive (ZIP);
    • a downloadable deployment bundle (e.g., container-composition configuration, environment files, and related credential files) for local or self-managed execution; and
    • where provided under the User's plan, a private GitHub repository under an account or organization owned or managed by the Company, to which the User is invited as a read-only collaborator and which mirrors the project's main branch. The GitHub Repository Delivery Policy Addendum applies to this delivery method.
  2. The Company may change the delivery method or repository structure at its discretion. Mirrored repositories reflect the current state of the project's main branch and may be rewritten or force-updated when the project is regenerated.
  3. Upon project deletion, the Company may delete associated delivery repositories and mirrors; the Company-controlled source repository is deleted after a reasonable retention grace period as described in the Privacy Policy.
  4. The Company is not obligated to provide technical support for Outputs (e.g., debugging, operations, performance tuning, or security reviews), unless otherwise agreed in writing.
  5. Delivery of the Outputs under this Section constitutes the mechanism for the Self-Operated (Export) Deployment Option defined in Section 2; the User's operation of a service built from delivered Outputs is governed by Sections 8.6 and 15.

8. Acceptable Use Policy

8.1 General prohibitions

Users must not use the Service to:

  • create, distribute, deploy, or operate services, systems, or content that violate applicable laws or regulations;
  • generate, distribute, or deploy malware, spyware, stalkerware, surveillance tools, or software intended to defeat security controls;
  • engage in hacking, credential stuffing, unauthorized access, or infringement activities;
  • infringe third-party rights (including intellectual property, trade secrets, privacy rights, or publicity rights);
  • facilitate or promote criminal or unlawful activities;
  • process the personal data of any person without a lawful basis under applicable data-protection law.

8.2 Intrinsically prohibited service categories

The Service may not be used for the generation, hosting, or operation of services in the following categories, regardless of Deployment Option, and the Company will refuse generation and deployment for any service falling within them:

  • services that target, are primarily designed for, or knowingly accept end-users under the age of thirteen (13) (or fourteen (14) in the Republic of Korea, or sixteen (16) in the European Union / EEA, as applicable);
  • adult, sexually explicit, or pornographic services;
  • gambling, betting, lotteries, or games of chance offered for monetary stakes;
  • firearms, ammunition, explosives, weapons, or weapons-accessory sales or configurators;
  • sale or distribution of controlled substances, prescription medications, or narcotics (including cannabis where not expressly permitted);
  • political-campaign targeting, voter-profiling, or electioneering platforms.

8.3 Generation-only service categories (no deployment through the Company)

For services in the following categories, the Company does not offer Managed Hosting or Customer-Cloud (Company-Operated) deployment, and will refuse or reverse any such deployment. The Company may, in its discretion, generate and deliver Outputs for such services for Self-Operated (Export) use only. Licensure, registration, and lawful operation of any such service are solely the User's responsibility; by requesting generation of such a service, the User represents that its intended operation will comply with applicable law, including any required licenses, registrations, or lawful bases. The Company does not verify this representation and may refuse generation at its discretion. Sections 8.6 and 15 govern the User's operation of any such service:

  • licensed financial services (including banking, lending, money transmission, securities brokerage, cryptocurrency exchange or custody, stablecoin issuance, and insurance underwriting);
  • healthcare services that create, transmit, or store protected health information subject to HIPAA, EU medical-device regulation, or equivalent regimes (the Company's infrastructure is not certified for such data; the User must deploy on its own compliant infrastructure);
  • biometric identification or verification systems;
  • trust-and-safety or content-moderation platforms whose operation requires processing categories of content (such as CSAM) that the Company does not host;
  • any other service whose hosting or operation by the Company would require the Company to hold licenses, registrations, or certifications it does not hold.

8.4 Service categories conditionally permitted for deployment

Services in the following categories are permitted, including generation and all Deployment Options. When such a service is deployed under Managed Hosting, the User must additionally complete the deployment questionnaire accurately, accept the Data Processing Agreement referenced in Section 12, give the warranties in Section 12.2, and deliver the end-user privacy notice described in Section 12.3. Disclosed personal-data categories are checked against the generated database schema before deployment; other answers are recorded declarations on which the Company relies, and a material inconsistency between them and the deployed service's actual behavior may trigger reactive inspection (Section 10) and suspension (Section 14). No additional conditions apply to Self-Operated (Export) use of these categories beyond Sections 8.6 and 15. The categories are:

  • services that collect any personal data from end-users;
  • services offered to end-users located in the European Union, European Economic Area, United Kingdom, or California;
  • services with user-generated text content;
  • services where minors (13 and above in the US, 14 and above in Korea, 16 and above in the EU) may be among end-users;
  • business-to-business services processing employee or human-resources data.

8.5 End-user file uploads (customer-provided storage only)

Generated services may include end-user file upload features only where the uploaded files are stored in storage that the User provides and controls (e.g., the User's own Amazon S3 bucket or equivalent object storage, connected using credentials the User supplies). File uploads and downloads are performed directly between the end-user's client and the User's storage using pre-signed URLs: the generated service issues time-limited pre-signed URLs, and the file contents themselves do not pass through, and are not stored on, Company-managed infrastructure. Users must not enable or configure a generated service to store end-user files on, or serve them from, Company-managed infrastructure. The User is responsible for its storage account, including its credentials, access configuration, retention, costs, and the lawfulness of stored content; storage credentials the User supplies are used solely to operate the file features of the User's own generated service and are handled as described in the Privacy Policy.

8.6 User responsibility

Users are solely responsible for the legality, deployment, operation, and consequences of any service built using the Outputs, including the conduct of their end-users. The Company's acceptance or deployment of a generated service does not constitute legal advice, does not certify compliance with any law, and does not transfer to the Company any duty owed by the User to its end-users.


9. Automated Analysis and Illegal Use Detection

  1. To prevent unlawful use, abuse, violations of these Terms, and to reduce legal risk, the Company may analyze Requirements and related configuration inputs using automated methods.
  2. For this purpose, the Company may use third-party AI tools solely as auxiliary means to detect potential illegality or violations.
  3. Only the minimum information necessary is used, and such information is not provided for external model training, subject to provider constraints.
  4. Automated analysis results are supporting indicators only and do not constitute final legal determinations.

10. Monitoring Scope and Reactive Inspection

  1. The Company may review system metadata, configuration information, and traffic patterns to the minimum extent necessary for security, stability, and abuse prevention.
  2. The Company does not routinely access, scan, or inspect application-level end-user data (such as databases or application logs) stored within generated services. The Company does not perform proactive database-level scanning for illegal content.
  3. Error-event capture (deployments through the Company). To provide error diagnostics and the operations dashboard for the User's own project, generated services deployed through the Company — under Managed Hosting or Customer-Cloud (Company-Operated) — may capture error events (HTTP responses with status 400 and above). Each captured event includes limited clear-text metadata (status code, HTTP method, route template, error fingerprint, trace identifier, timestamp) and, where necessary for error diagnostics, may include the associated request, response body, and stack trace. The request body, response body, or stack trace may in turn contain personal data of end-users, such as email addresses, contact details, account identifiers, input values, or other personal information. The Company collects such information only to the minimum extent necessary for error diagnostics; it is credential-redacted at capture time and then encrypted with a per-project key before leaving the service. The encrypted contents are decrypted only to present incident details to authorized members of the User's own project (and in the reactive-inspection cases described in this Section), and are retained as described in the Privacy Policy. Container-level resource metrics (CPU, memory, network) and service-liveness signals are also collected; these do not contain application payloads. Retention and deletion of error events are governed by the Privacy Policy and the Data Processing Agreement (DPA).
  4. The Company may conduct a reactive inspection of a generated service — limited in scope to the minimum data necessary to verify the report or request — when triggered by any of the following:
    • a credible abuse report received through the Company's abuse-reporting channel or any other reasonable means;
    • a law-enforcement request, court order, or lawful request from a competent authority;
    • a payment-processor, cloud-provider, or trust-and-safety flag affecting the service;
    • a material inconsistency between interview or deployment-stage answers and the actual behavior or data of the deployed service;
    • a third-party complaint alleging infringement of intellectual property, privacy, or other legal rights.
  5. Where a reactive inspection touches end-user personal data, the Company acts under the Data Processing Agreement referenced in Section 12 and under applicable legal bases; the scope, timing, and actors involved are recorded in an internal audit log. Solely for the security, abuse-prevention, and legal-compliance processing described in this Section, the Company acts as an independent controller to the narrow extent required.
  6. Evidence preservation and law-enforcement cooperation. The Company may preserve evidence and disclose information to competent authorities as required or permitted by law. Disclosure will be limited to the minimum necessary to comply with the specific legal demand.
  7. User notification of law-enforcement requests. Where legally permitted, the Company will notify the User of a law-enforcement request, court order, or comparable legal demand concerning the User's Account or generated service before complying, to give the User an opportunity to seek a protective order or challenge the demand. Where notification is prohibited (such as under a lawful gag order or sealed subpoena), the Company will notify the User as soon as the legal restriction is lifted. The Company will publish its law-enforcement response policy at a stable URL on the Service and may publish periodic transparency reports regarding the volume and type of legal demands received.

11. Infrastructure Management Support and Access Tokens (Customer-Cloud, Company-Operated)

  1. Where the generated service is deployed under the Customer-Cloud (Company-Operated) option (in the User's own cloud account), and at the User's request, the Company may provide technical management or operational support within the User's cloud account (e.g., provisioning, deployment, monitoring, scaling configuration, operational assistance). Such support may require a separate operational delegation agreement or addendum.
  2. The User may register an Access Token with the Service for such support, and the Company may perform actions using that Access Token. Registered Access Tokens are stored in an encrypted secrets store and used only for the purposes described in this Section.
  3. The Company will act only within the scope of permissions granted by the User and will not exceed such permissions. The User should scope the Access Token narrowly to the tasks for which it is provided.
  4. The User is responsible for issuing, scoping, rotating, revoking, and securing the Access Token, and may revoke or deactivate the Access Token at any time, including by deleting it from the Service.
  5. Final operational responsibility and decision-making authority remain with the User. The Company's support does not imply joint operation or joint liability, except as expressly set out in a separately signed Data Processing Agreement or operational delegation addendum.
  6. Removal of Customer-Cloud deployments. Resources provisioned in the User's own cloud account remain the User's resources. Before deleting a project (or where the User no longer wishes to incur cloud charges), the User should request removal of the Customer-Cloud deployment through the Service; the Company does not automatically tear down resources in the User's cloud account upon project deletion, and the User remains responsible for charges its cloud provider levies for resources left running.

12. Personal-Data Processing, DPA, and End-User Privacy Notice for Deployments through the Company

  1. Deployment questionnaire and DPA at deployment. Before a generated service may be deployed or begin operation under Managed Hosting or Customer-Cloud (Company-Operated), the User must complete the Company's deployment questionnaire (which may cover legal matters — such as end-user jurisdictions, personal-data categories, minors, payment posture, and privacy contacts — and operational matters) and must review and accept the Company's Data Processing Agreement (which includes processor terms under Article 28 of the GDPR and a consignment arrangement under Article 26 of PIPA). The Company will present the Data Processing Agreement for active acceptance at deployment time and will record the document version, timestamp, accepting user, and the IP address from which acceptance was given. Questionnaire answers are recorded in the same manner; certain answers (such as confirmed personal-data categories and payment posture) must be re-confirmed when the generated service is regenerated. Certain answers (such as an intention to store raw payment-card data, or an indication that end-users are under the age of digital consent — see Section 8.2) block deployment. Where Managed Hosting is offered for a fee, the User must additionally accept the applicable pricing terms, and such acceptance is recorded with the policy version and timestamp.

  2. Customer warranties. By deploying a generated service under Managed Hosting or Customer-Cloud (Company-Operated), the User represents and warrants that:

    • the intended service is lawful in every jurisdiction in which its end-users are located;
    • the service does not fall within any of the prohibited categories in Section 8.2 or the generation-only categories in Section 8.3;
    • the categories of end-user personal data the service will collect have been accurately disclosed to the Company at interview and deployment;
    • the User has, or will have before the service becomes available to end-users, a lawful basis under applicable data-protection law for processing each category of end-user personal data;
    • the User has implemented, or will implement, age-verification measures where required by applicable law, including measures to prevent use of the service by end-users under the age of digital consent (see Section 8.2);
    • the User will comply with the Acceptable Use Policy and will not introduce regulated-data categories (such as protected health information or payment-card data) into the service without the Company's prior written agreement.
  3. End-user privacy notice. Before making a generated service deployed through the Company available to end-users, the User must publish a privacy notice applicable to that generated service. Depending on the actual processing, the User's privacy notice must include at least the following:

    • that the User, as operator of the generated service, is the controller of end-user personal data;
    • that the Company acts as a processor performing hosting, deployment, operational assistance, error diagnostics, security, and other tasks on the User's documented instructions;
    • the categories or items of personal data that may be collected, used, stored, or transmitted from end-users;
    • the purpose of each processing activity;
    • the retention period of the personal data, or the criteria used to determine it;
    • where sub-processors, cross-border transfers, or third-party services used by the User exist, the matters required by applicable law; and
    • how end-users may exercise their rights and the contact point for privacy inquiries.

    The Company may provide notice language or a draft covering the personal-data items, processing purposes, retention periods, and the scope of the Company's processing as processor, based on the deployment questionnaire, the generated database schema, and the service configuration. The User must review such material and publish it as adapted to the actual operation of its service, and is responsible for adding any notices required for external payments, marketing, analytics, file storage, external login, or other processing activities specific to the User. The User must not remove notice language provided by the Company or narrow or misrepresent the actual scope of the Company's processing.

  4. Data-subject rights routing. The User will designate a privacy-contact email for rights requests from end-users. The Company will route end-user rights requests it receives to that email in the first instance, and the User will respond within the timeframes required by applicable law. The Company will, as processor, assist the User in handling such requests as set out in the Data Processing Agreement.

  5. Breach notification flow. In the event of a personal-data breach, the Company will notify the User without undue delay (and in any case within twenty-four (24) hours of awareness) with the information required for the User to meet its own notification obligations to end-users and competent authorities. The User will notify affected end-users and competent authorities within the statutory timeframes (including, where applicable, the 72-hour supervisory-authority notification under GDPR Article 33, notification of data subjects without undue delay under GDPR Article 34, and equivalent PIPA requirements). The Company may notify end-users directly only where necessary to comply with a direct legal duty or where the User is unresponsive.

  6. Customer indemnity. To the maximum extent permitted by applicable law, the User will indemnify, hold harmless, and — where permitted under the applicable jurisdiction — defend the Company and its officers, directors, employees, and agents from and against any third-party claim, demand, proceeding, or governmental action arising out of or relating to: (a) the User's breach of the warranties in Section 12.2; (b) the legality or operation of the service deployed by or on behalf of the User; (c) the content or conduct of the User's end-users; (d) the User's failure to deliver a compliant end-user privacy notice or to respond to end-user rights requests; or (e) the User's introduction of undisclosed regulated-data categories into the service. The User's obligation includes payment of damages, settlements, fines, and reasonable attorney fees and costs. The Company will (i) promptly notify the User of any such claim, (ii) cooperate reasonably with the User's handling of the claim at the User's expense, and (iii) have the right, but not the obligation, to control the defense of any claim subject to this indemnity with counsel of its choosing, at the User's expense, in which case the User may not settle the claim without the Company's consent. Nothing in this Section limits mandatory consumer rights where applicable.

  7. Reservation of rights. The Company may refuse, delay, or reverse deployment where, in its reasonable judgment, the User's answers at interview or deployment are inconsistent with the actual generated service, with the Acceptable Use Policy, or with applicable law. Refusal at deployment does not entitle the User to a refund of fees paid or Change-Runs consumed for generation, subject to the Billing Policy and applicable law.


13. Automated Deployment and Scaling

  1. Automated deployment (e.g., deploy on source code updates) and automated scaling (e.g., scale when load thresholds are reached) may be offered as optional features.
  2. Responsibility for enabling, configuring (thresholds, scope, targets), and outcomes of such features remains with the User.
  3. Where the Company executes automation under the Customer-Cloud (Company-Operated) option using an Access Token, it will do so only within the User-configured settings and permission scope granted by the User. Where the Company executes automation under Managed Hosting, it will do so in accordance with the Data Processing Agreement referenced in Section 12.

14. Suspension, Restriction, and Termination

  1. If the Company reasonably suspects a violation of these Terms, the Acceptable Use Policy, or applicable laws, or if a reactive inspection under Section 10 identifies a material concern, the Company may suspend, restrict, or terminate access to the Service without prior notice. Where circumstances permit, the Company will notify the User of the reason and provide an opportunity to respond.
  2. The Company may temporarily suspend the Service for security, maintenance, outages, or legal or regulatory reasons.
  3. The Company may retain logs and records as necessary for security, audit, dispute resolution, and compliance with applicable laws, in accordance with the retention periods in the Privacy Policy.
  4. Upon termination, the Company may cease hosting the User's generated service under Managed Hosting. The Company will, where reasonably feasible and subject to applicable law, provide the User a reasonable opportunity to export the Outputs and data stored within the generated service.
  5. If you are an EU or EEA consumer and mandatory law grants you a remedy because the Service is not supplied, is not in conformity, or is modified in a way that negatively affects your access to or use of the Service beyond what mandatory law allows, those remedies remain available to you.

15. Intellectual Property

  1. User content. As between the Company and the User, the User retains all rights, title, and interest in and to Requirements, configurations, and other content submitted by the User.
  2. Assignment of Outputs. Subject to Section 15.3 (third-party licenses), the User's compliance with these Terms, and payment of applicable fees, the Company hereby assigns to the User all of the Company's rights, title, and interest in the Outputs delivered to the User, to the maximum extent such rights are assignable under applicable law. Where such rights are not assignable, the Company grants the User a worldwide, perpetual, irrevocable, royalty-free, sublicensable license to use, reproduce, modify, distribute, and create derivative works of the Outputs.
  3. Third-party components. Outputs may include third-party components, including open-source software. Such components remain subject to their respective license terms, and nothing in Section 15.2 purports to assign rights the Company does not hold.
  4. Back-license to the Company. The User grants the Company a worldwide, non-exclusive, royalty-free license to use Requirements, configurations, and Outputs solely as necessary to provide, secure, operate, and improve the Service, to comply with legal obligations, and to exercise the Company's rights under these Terms. This license does not authorize use of Requirements for training the Company's own AI models except where separate consent has been obtained.
  5. Company marks and platform. The BackendX name, logo, and platform software are and remain the Company's intellectual property. No right, title, or interest in Company marks or the underlying platform is transferred to the User.
  6. Feedback. Where the User voluntarily provides feedback or suggestions regarding the Service, the User grants the Company a perpetual, irrevocable, royalty-free license to use such feedback without restriction.
  7. AI-generated Outputs; no warranty. Outputs are generated by AI systems and may contain errors, inaccuracies, or security vulnerabilities. This applies equally to artifacts built from Outputs — including container images and deployment bundles — and to services deployed and operated from them. The Company makes no warranties regarding the accuracy, completeness, security, legality, or fitness of Outputs for any purpose, except as expressly provided in these Terms or required by mandatory applicable law.

16. Third-Party Services

The Service may integrate with third-party services such as GitHub, cloud infrastructure providers (e.g., AWS), payment processors (e.g., Stripe), and external AI providers (e.g., OpenAI, Google, Anthropic). The Company is not responsible for third-party outages, policy changes, suspensions, or limitations, except to the extent caused by the Company's willful misconduct or gross negligence.


17. Disclaimer and Limitation of Liability

  1. Except as expressly required by mandatory applicable law (including, without limitation, mandatory conformity and remedy rights granted to consumers in the European Union, European Economic Area, and United Kingdom, and mandatory consumer-protection rights under the laws of the User's country or state of residence), the Service and Outputs are provided on an "AS IS" and "AS AVAILABLE" basis, and to the maximum extent permitted by law, the Company disclaims all warranties, whether express, implied, statutory, or otherwise, including warranties of merchantability, fitness for a particular purpose, non-infringement, and uninterrupted or error-free operation. Nothing in this Section limits any non-excludable statutory warranty or consumer right.
  2. Users are solely responsible for the legality and operation of services built using the Outputs.
  3. Subject to Section 17.5, and to the maximum extent permitted by applicable law, the Company's total aggregate liability arising out of or relating to these Terms or the Service is limited to the greater of (a) the fees actually paid by the User to the Company during the six (6) months immediately preceding the event giving rise to the claim, or (b) one hundred U.S. dollars (USD 100). Where the Service is provided free of charge (e.g., free tiers, trials, or other no-charge offerings), the Company shall have no liability except to the extent liability cannot be excluded under applicable mandatory law (including the carve-outs in Section 17.5).
  4. Subject to Section 17.5, and to the maximum extent permitted by applicable law, the Company shall not be liable for any indirect, special, incidental, consequential, exemplary, or punitive damages, including loss of profits, revenue, data, goodwill, or reputation, even if advised of the possibility of such damages.
  5. Carve-outs. Nothing in Sections 17.1, 17.3, or 17.4 shall exclude or limit the Company's liability for: (a) death or personal injury caused by the Company's negligence; (b) the Company's own fraud or fraudulent misrepresentation; (c) the Company's own willful misconduct or gross negligence; (d) any other liability of the Company that cannot be excluded or limited under applicable mandatory law (including mandatory EU, EEA, UK, U.S. state, or Republic of Korea consumer-protection rules). For clarity, this Section addresses only the extent to which the Company's own liability may be limited; the User's responsibility for its services and end-users (Sections 8.6 and 12.6) is unaffected.
  6. Some jurisdictions do not allow the exclusion or limitation of certain warranties or damages; in such jurisdictions, the exclusions and limitations in this Section apply only to the maximum extent permitted by law, and the User may have additional rights.

18. Amendments

The Company may amend these Terms due to changes in laws or Service operations. Material changes will be announced through the Service or by other reasonable means. Continued use after the effective date constitutes acceptance of the amended Terms, except to the extent mandatory law requires a different consequence or gives the User a right to terminate.


19. Governing Law and Jurisdiction

  1. These Terms, and any non-contractual obligations arising out of or in connection with them, are governed by and construed in accordance with the laws of the Republic of Korea, excluding the conflict-of-laws rules of the Republic of Korea's Act on Private International Law.
  2. Non-consumer disputes. If you are not a consumer (that is, if you use the Service for purposes relating to your trade, business, or profession), all disputes arising out of or in connection with the Service, these Terms, or the relationship between the parties shall be subject to the exclusive jurisdiction of the Seoul Central District Court of the Republic of Korea as the court of first instance.
  3. Consumer disputes — choice of law. If you are a consumer, the choice of Korean law in Section 19.1 does not deprive you of any mandatory protection afforded to you by the laws of your country or state of residence that cannot be derogated from by agreement, including (where applicable) mandatory consumer-protection rules under the laws of the European Union and its Member States, the European Economic Area, the United Kingdom, the Republic of Korea, and the individual states of the United States.
  4. Consumer disputes — forum. If you are a consumer residing in the European Union or the European Economic Area, you may bring proceedings against the Company in the courts of the Member State in which you are domiciled, and the Company may bring proceedings against you only in those courts, in accordance with Articles 17 to 19 of Regulation (EU) No 1215/2012 (Brussels Ia). Other consumers, including consumers residing in the United Kingdom or the United States, retain any jurisdictional or consumer-protection rights under the law of their habitual residence that cannot be derogated from by agreement. The jurisdiction clause in Section 19.2 does not apply to, and is not intended to limit, any such consumer.
  5. Nothing in this Section prevents either party from seeking urgent injunctive or equitable relief from a court of competent jurisdiction where necessary to protect intellectual-property rights, prevent unauthorized access to the Service, or otherwise protect rights pending resolution of a dispute.

20. Force Majeure

Neither party will be liable for any failure or delay in performance caused by events beyond its reasonable control, including acts of God, natural disasters, epidemic or pandemic, war, civil unrest, terrorism, governmental action or regulation, labor disputes, power or telecommunications failures, denial-of-service or other cyberattacks, or the failure or interruption of third-party services (including upstream cloud or AI providers) on which the Service depends. The affected party will notify the other of the event and use reasonable efforts to mitigate its effects. This Section does not excuse payment obligations already accrued.


21. Assignment

  1. The User may not assign, transfer, or delegate these Terms or any rights or obligations under them without the Company's prior written consent. Any purported assignment in violation of this Section is void.
  2. The Company may assign, transfer, or delegate these Terms in connection with a merger, acquisition, corporate reorganization, or sale of all or substantially all of its assets, or to an affiliate. Where required by applicable law, the Company will provide affected Users with prior notice and, where applicable, an opportunity to terminate.

22. Severability

If any provision of these Terms is held invalid, illegal, or unenforceable by a court or regulator of competent jurisdiction, that provision will be modified to the minimum extent necessary to be enforceable (and if not modifiable, will be severed), and the remaining provisions will continue in full force and effect.


23. Entire Agreement and Order of Precedence

  1. These Terms, together with the Privacy Policy, the Billing Policy, the GitHub Repository Delivery Policy Addendum (where the User uses the GitHub repository delivery option), the Acceptable Use Policy in Section 8, and any Data Processing Agreement or other written agreement executed by the parties, constitute the entire agreement between the User and the Company with respect to the Service and supersede all prior or contemporaneous understandings, communications, and agreements, whether written or oral.
  2. In the event of a conflict among these documents, the following order of precedence applies:
    • first, any written agreement separately signed by the parties (such as an enterprise agreement or a Data Processing Agreement);
    • second, these Terms of Use;
    • third, the GitHub Repository Delivery Policy Addendum (for matters relating to the GitHub repository delivery option);
    • fourth, the Billing Policy (for matters relating to Subscriptions, Seats, Change-Runs, and payments);
    • fifth, the Privacy Policy (for matters relating to the processing of personal data; provided that, for conflicts on data-protection terms, the Privacy Policy prevails over these Terms).

24. Notices

  1. The User may deliver legal notices to the Company by email to legal@backendx.ai, with a copy to team@email.backendx.ai, and, where required by applicable law, by mail to the Company's registered office address in the Republic of Korea.
  2. The Company may deliver notices to the User by email to the address associated with the User's Account, through an in-product notification, or by posting a notice on the Service. Notice is deemed received when sent by email or when posted prominently in the Service.
  3. It is the User's responsibility to keep the Account email address current. The Company is not responsible for notices that fail to reach the User due to an outdated or inaccurate Account email address.