Terms of Service
Article 1 (Definition of the service; acknowledgment of data flow)
DroFi structures the design decisions and process content your team enters and delivers that context through the MCP connections, files, prompts and share links you select. Transmission to external AI providers (Anthropic, OpenAI, Google, etc.) occurs when you use the relevant connection or export path. You acknowledge that the service is a delivery conduit for team content and consent to the resulting data transmission.
Article 2 (Prohibited content — secrets and sensitive data)
You must not enter or store the following in any form (nodes, memos, contract fields, attachments, imported documents, etc.): (1) credentials and secrets — API keys, access tokens, passwords, private keys and certificates (PEM, etc.), .env file contents, database connection strings, cloud secrets; (2) sensitive personal data — resident registration numbers, passport numbers and other identifiers, payment card numbers, health or biometric data and other sensitive data under applicable law. DroFi provides secret scanning as a supplementary safeguard without guaranteeing completeness; responsibility for leaks or damages caused by violations rests with the user. DroFi may block or delete such content upon detection.
Article 3 (No malicious or deceptive content)
You must not enter content designed to manipulate AI agents — prompt injection, malicious instructions, malware inducement, data-exfiltration prompts — nor impersonate others or register content under a false source. Given the nature of large language models, such threats cannot be fully blocked by technical means, so this obligation is expressly the user's responsibility.
Article 4 (Acknowledgment and consent to transmission when connecting external AI)
You acknowledge and consent that DroFi context may be transmitted to the external AI providers you choose to connect. Reviewing and complying with those third-party providers' terms and data practices is your responsibility. On-premises deployment, self-hosting and organization-dedicated isolation are planned options, not completed features currently available. If you handle regulated data, do not enter it until a suitable deployment and separate contract have been confirmed.
Article 5 (Tokens and access management)
Do not commit MCP or access tokens in plain text to public repositories; referencing them via environment variables (e.g. ${CODOC_TOKEN}) is recommended. If a token leaks, you are responsible for rotating or revoking it immediately. Managing workspace/project member invitations and permissions (viewer/editor/admin) is the responsibility of the administrating user; unauthorized sharing and abuse of permissions are prohibited. Share links expose the context delivered to the selected role, so do not share them outside your circle of trust.
Article 6 (Responsibility for import sources)
Import documents only from sources you trust. You acknowledge and bear the risk of indirect prompt injection or malicious content introduced by importing untrusted documents. DroFi provides safeguards in its import parsers (safe parsing, size and time limits), but you must judge the trustworthiness of the content itself.
Article 7 (Limitation of liability — inherent AI risks)
We disclose that, given the nature of large language models, prompt injection and misbehavior cannot be completely prevented. DroFi provides reasonable defenses on a best-effort basis — separating data from instructions, provenance labeling, excluding sensitive nodes, secret scanning — without warranting their completeness. Final review and approval of AI output and agent actions is your responsibility.
Article 8 (Security measures and tenant isolation)
In its multi-tenant environment, object access is checked against project scope and enforced with database row-level security (RLS) to block cross-tenant access. Access tokens are bound to a project and default to read-only. Project changes are kept in change history; context delivered through DroFi is recorded in project delivery history by channel, role, exact included blocks and size, while the content body itself is not stored in that ledger. Tokens retain a last-request timestamp. This is not an organization-wide audit log of every action taken by external AI outside DroFi. These measures constitute reasonable security efforts and do not guarantee absolute safety.
Article 9 (Reporting and enforcement)
DroFi provides a channel for reporting security vulnerabilities and abuse (hello@drofi.ai). If you violate the security provisions of these Terms, DroFi may take necessary measures including blocking the content or temporarily suspending the account.
Article 9-2 (Confidentiality during the beta period)
While the service is in beta (closed testing), you must not disclose, leak or transmit to third parties — without the Company's prior written consent — the service's features, screens, structure, performance, or any non-public information learned in the course of use. This article applies until the service is opened to the public and takes effect upon your agreement to these Terms (the time of consent is recorded and retained). Materials the Company has expressly made public (the official website, public demos, etc.) are excluded.
Article 10 (Related documents; effect of these Terms)
These Terms apply together with the Privacy Policy. A DPA, sub-processor list and organization-specific security documents are not completed standard offerings today; they are planned for separate execution or publication after organization pilots and legal review. This document is a product- and security-oriented draft, not legal advice, and legal review must be completed before formal adoption. Until finalized, these provisions have effect as operational guidance.
Article 11 (Accounts and the service agreement)
The service agreement is formed when you agree to these Terms and complete sign-up. Children under 14 may not sign up. You are responsible for keeping your account information accurate, and accounts may not be transferred or lent to others. You may export your data and then close your account at any time from settings. Once deletion completes, the account and linked personal information are deleted without delay and cannot be restored; only information subject to a legal retention duty is kept separately under Section 6 of the Privacy Policy.
Article 12 (Provision, modification and suspension of the service)
The service is currently provided free of charge during the beta period, and features may be improved or changed without prior notice. The Company may modify or suspend all or part of the service for substantial reasons such as maintenance, outages or technical necessity, with prior notice as a rule and subsequent notice in urgent cases.
Article 13 (Intellectual property and user content)
Rights to the content you enter or upload (blocks, memos, documents, etc.) belong to you (or your team). The Company uses such content only to the extent necessary to provide the service (storage, structuring, context delivery, backup). Intellectual property in the service and its software belongs to the Company, and feedback you provide may be used to improve the product.
Article 14 (Paid services)
If paid plans are introduced, fees, payment methods, billing cycles and refund terms will be announced separately and consented to before taking effect, by revision of these Terms or a separate policy.
Article 15 (Disclaimer and liability)
The Company is not liable for damages caused by force majeure, causes attributable to the user, or failures of third-party services such as external AI providers and hosting. During the free beta period, the Company bears no liability for damages arising from use of the service absent intent or gross negligence. Users who violate these Terms are liable for damages caused to the Company or third parties.
Article 16 (Changes to the Terms; governing law and jurisdiction)
The Company may amend these Terms, giving notice in the service or by email at least 7 days before taking effect (30 days for changes unfavorable to users). Continued use after notice constitutes agreement. These Terms are governed by the laws of the Republic of Korea, and disputes are subject to the competent court under the Civil Procedure Act.