Terms of Service
Article 1 (Definition of the service; acknowledgment of data flow)
DroFi is a tool that structures the design decisions and process content your team enters, and delivers that context (digests and exports) via the MCP standard to the external AI providers you personally choose to connect (Anthropic, OpenAI, Google, etc.). You acknowledge that the essence of this service is a conduit that feeds team content to external AI, and you consent to the data transmission this entails.
Article 2 (Prohibited content — secrets and sensitive data)
You must not enter or store the following in any form (nodes, memos, contract fields, attachments, imported documents, etc.): (1) credentials and secrets — API keys, access tokens, passwords, private keys and certificates (PEM, etc.), .env file contents, database connection strings, cloud secrets; (2) sensitive personal data — resident registration numbers, passport numbers and other identifiers, payment card numbers, health or biometric data and other sensitive data under applicable law. DroFi provides secret scanning as a supplementary safeguard without guaranteeing completeness; responsibility for leaks or damages caused by violations rests with the user. DroFi may block or delete such content upon detection.
Article 3 (No malicious or deceptive content)
You must not enter content designed to manipulate AI agents — prompt injection, malicious instructions, malware inducement, data-exfiltration prompts — nor impersonate others or register content under a false source. Given the nature of large language models, such threats cannot be fully blocked by technical means, so this obligation is expressly the user's responsibility.
Article 4 (Acknowledgment and consent to transmission when connecting external AI)
You acknowledge and consent that DroFi context (digests and exports) is transmitted to the external AI providers you choose to connect. Reviewing and complying with those third-party providers' terms and data practices is your responsibility. If you handle regulated data, you are responsible for using an appropriate configuration such as on-premises or Enterprise.
Article 5 (Tokens and access management)
Do not commit MCP or access tokens in plain text to public repositories; referencing them via environment variables (e.g. ${CODOC_TOKEN}) is recommended. If a token leaks, you are responsible for rotating or revoking it immediately. Managing workspace/project member invitations and permissions (viewer/editor/admin) is the responsibility of the administrating user; unauthorized sharing and abuse of permissions are prohibited. Export links can expose the full context — do not share them outside your circle of trust.
Article 6 (Responsibility for import sources)
Import documents only from sources you trust. You acknowledge and bear the risk of indirect prompt injection or malicious content introduced by importing untrusted documents. DroFi provides safeguards in its import parsers (safe parsing, size and time limits), but you must judge the trustworthiness of the content itself.
Article 7 (Limitation of liability — inherent AI risks)
We disclose that, given the nature of large language models, prompt injection and misbehavior cannot be completely prevented. DroFi provides reasonable defenses on a best-effort basis — separating data from instructions, provenance labeling, excluding sensitive nodes, secret scanning — without warranting their completeness. Final review and approval of AI output and agent actions is your responsibility.
Article 8 (Security measures and tenant isolation)
In its multi-tenant environment, every object access is checked against project scope and enforced with database row-level security (RLS) to block cross-tenant access. Access tokens are bound to a project and default to read-only. Audit logs are kept for contract changes, context exports and token use, and sensitive values such as tokens and context bodies are redacted in logging. These measures constitute reasonable security efforts and do not guarantee absolute safety.
Article 9 (Reporting and enforcement)
DroFi provides a channel for reporting security vulnerabilities and abuse (hello@drofi.ai). If you violate the security provisions of these Terms, DroFi may take necessary measures including blocking the content or temporarily suspending the account.
Article 9-2 (Confidentiality during the beta period)
While the service is in beta (closed testing), you must not disclose, leak or transmit to third parties — without the Company's prior written consent — the service's features, screens, structure, performance, or any non-public information learned in the course of use. This article applies until the service is opened to the public and takes effect upon your agreement to these Terms (the time of consent is recorded and retained). Materials the Company has expressly made public (the official website, public demos, etc.) are excluded.
Article 10 (Related documents; effect of these Terms)
These Terms apply together with the separate Privacy Policy, the Data Processing Agreement (DPA, for Enterprise/B2B), and the sub-processor list. This document is a product- and security-oriented draft, not legal advice, and legal review must be completed before formal adoption. Until finalized, these provisions have effect as operational guidance.
Article 11 (Accounts and the service agreement)
The service agreement is formed when you agree to these Terms and complete sign-up. Children under 14 may not sign up. You are responsible for keeping your account information accurate, and accounts may not be transferred or lent to others. You may close your account at any time from account settings; data handling on closure (30-day retention then destruction, with export available) follows Section 6 of the Privacy Policy.
Article 12 (Provision, modification and suspension of the service)
The service is currently provided free of charge during the beta period, and features may be improved or changed without prior notice. The Company may modify or suspend all or part of the service for substantial reasons such as maintenance, outages or technical necessity, with prior notice as a rule and subsequent notice in urgent cases.
Article 13 (Intellectual property and user content)
Rights to the content you enter or upload (blocks, memos, documents, etc.) belong to you (or your team). The Company uses such content only to the extent necessary to provide the service (storage, structuring, context delivery, backup). Intellectual property in the service and its software belongs to the Company, and feedback you provide may be used to improve the product.
Article 14 (Paid services)
If paid plans are introduced, fees, payment methods, billing cycles and refund terms will be announced separately and consented to before taking effect, by revision of these Terms or a separate policy.
Article 15 (Disclaimer and liability)
The Company is not liable for damages caused by force majeure, causes attributable to the user, or failures of third-party services such as external AI providers and hosting. During the free beta period, the Company bears no liability for damages arising from use of the service absent intent or gross negligence. Users who violate these Terms are liable for damages caused to the Company or third parties.
Article 16 (Changes to the Terms; governing law and jurisdiction)
The Company may amend these Terms, giving notice in the service or by email at least 7 days before taking effect (30 days for changes unfavorable to users). Continued use after notice constitutes agreement. These Terms are governed by the laws of the Republic of Korea, and disputes are subject to the competent court under the Civil Procedure Act.