Signoos Terms of Service

Last updated 17 August 2026

These terms are the agreement between you and Signoos for use of the service at signoos.com, its API, the @signoos/cli command-line client and the @signoos/mcp editor server. By creating an account or using the service you accept them. If you are accepting on behalf of an organisation, you confirm you may bind it, and “you” means that organisation.

1. What Signoos is

Signoos is team and product management built around a live mirror of a repository you connect. It provides a hosted repository browser kept in step by pushes, a team, and tasks that are delegated in plain words, located in the code, bound to a branch and reviewed by an advisory AI. It can optionally attempt a task automatically, mine review sources for latent needs, and let a team leader choose which AI model performs which job.

Signoos is a tool used by your team. It does not manage your repository for you and it does not make decisions on your behalf. It writes to your repository only within the bounds set out in clause 5, which your team leader controls — see clauses 5 and 6.

2. Your account and eligibility

  • You must be at least 16 years old and legally able to enter into this agreement.
  • You must give accurate account information and keep it current. One account belongs to one person; do not share credentials.
  • You are responsible for everything done under your account and for keeping your password, two-factor device, recovery codes and connected device credentials secure. Tell us promptly at [email protected] if you believe your account has been compromised.
  • A project has a team leader with administrative control over that project — its members, its AI configuration, its stored keys and its deletion. If you join a project you do not own, that leader controls it.

3. Acceptable use

You agree not to:

  • connect a repository, add a review source, or upload content you do not have the right to have processed — including code belonging to somebody else, or personal data you have no lawful basis to share with us and our sub-processors;
  • use the service to build or operate anything unlawful, or to develop malware, credential harvesters or tooling whose purpose is to attack systems you are not authorised to test;
  • attempt to defeat the service's security or isolation — including probing or escaping the execution sandbox, attempting to reach other tenants' data, or using prompts or repository content to try to make an AI job act outside the task it was given;
  • circumvent rate limits, spend ceilings or quotas, or automate the service in a way that degrades it for others;
  • resell, sublicense or provide the service to third parties as your own, or reverse engineer it except to the extent that restriction is unenforceable where you live;
  • use the service in breach of the terms of any third party it relies on — notably GitHub's terms and the terms of any AI provider whose key funds your work.

We may investigate suspected breaches and take the steps described in clause 12.

4. Your content and who owns it

Your code stays yours. Nothing in these terms transfers ownership of your source code, your repositories, your tasks, your tickets, your review data or anything else you or your team put into Signoos (“your content”). You keep all intellectual property rights in it.

You grant us only the licence we need to run the service for you: a non-exclusive, worldwide, royalty-free licence to host, copy, store, transmit, index, display and process your content, and to disclose it to the sub-processors named in the Privacy Policy, for the sole purpose of providing and securing the service to you. That licence exists to make the product work and for no other purpose. It ends when the content is deleted, subject to the retention periods in the Privacy Policy and to backups expiring on their normal cycle.

We do not train models on your content. Your code, tasks, reviews and tickets are not used to build, train, fine-tune or evaluate any model or product we offer to anyone else. What the AI providers may do with a request is governed by the agreement covering the account that paid for it — see clause 7 and the AI processing page.

Your code is read only with your consent. Code access is off until you enable it, and is scoped to the folders you choose. We do not read code outside that grant.

We keep all rights in the Signoos service itself — the software, the interface, the brand and the documentation. These terms grant you a limited, revocable, non-transferable right to use it, nothing more.

You may give us feedback, and if you do we may use it without obligation to you. Feedback is not your content.

5. AI output is advice, and a person decides what happens to it

Signoos uses third-party AI models to review pushes, reply on task threads, draft fixes and attempt a task automatically. Everything they produce is a draft for a human to judge. Specifically:

  • What Signoos may write to your repository is bounded, and these are the bounds. A patch produced by the solver arrives as text on the task thread. Pushing that patch is available to your team unless a team leader switches it off, and when somebody uses it the patch is committed to that task’s own branch and a pull request is opened against the base. The person pushing may instead choose a different branch that already exists, your default branch included — and where they choose the base, the page says before the button that no pull request is opened. A team leader may additionally switch on a separate setting, off by default, under which a finished run commits and pushes itself to that task’s own branch only, authored by the signoos-ai account because no person has read it. In every case Signoos never merges anything, never force-pushes over work that moved, and writes nothing at all where a leader has switched pushing off.
  • The AI never closes work. A review is advice about whether a push matches what was asked. It does not block a submission, it can be disagreed with on the thread, and only a person moves a task to done.
  • It can be wrong. AI output may be inaccurate, incomplete, insecure, out of date, or confidently mistaken. It may miss a defect, and it may report one that is not there. A localization that cannot find the code says so and lists candidates rather than guessing — but a localization that does return an answer is still a suggestion.
  • Verification is not certification. Where an execution sandbox is configured, the solver runs the repository's own declared commands against a patched copy and reports what came back. That is evidence, not a guarantee that the patch is correct, complete or safe to ship.
  • You are responsible for what you merge. You must review AI output before relying on it, and you remain responsible for your code, your releases and your compliance obligations. Do not use Signoos as the only control on a change where a defect would be dangerous.
  • Some of it can start without you. A team leader can turn on a standing permission for their project, and findings from the analysis then start the solver by themselves rather than waiting for somebody to press anything. Nothing above changes: the limits on writing are the same ones stated above, the AI still closes nothing, and every result is still a draft for a person to judge. What changes is when the work begins — the permission is given once, in advance, by the leader, in that project's settings, and can be withdrawn there at any time.
  • AI models are non-deterministic. The same task may produce different output on different runs, and we do not warrant any particular result.

6. Your repository and third-party services

Connecting a repository means installing the Signoos GitHub App on repositories you select, on GitHub, under GitHub's own consent screen. We store no GitHub credential of yours; access is a short-lived token minted for each request from that installation. You can end that access at any time by uninstalling the App on GitHub, and it ends immediately and completely because there is no stored credential to outlive it.

Your use of GitHub, of any AI provider, and of any other service you connect (such as Jira or a review source) is governed by your agreement with that provider. We are not responsible for those services, their availability, their pricing or their handling of your data, and their changes may affect what Signoos can do.

7. Provider keys, spend and costs

  • You may bring your own AI provider key. A key you store is encrypted, bound to the project, owner and provider it was stored for, and never returned by any endpoint. Storing it is your authorisation for us to use it to make the requests you and your team ask for — including work that a standing permission you have turned on starts without a further request, which is described in section 5 and remains subject to every ceiling below.
  • Work funded by your key is billed by the provider to you. Those charges are between you and that provider. We do not receive them, cannot refund them, and do not warrant any estimate we display — the cost figures shown in Signoos are computed from published list prices for budgeting and are not an invoice.
  • Ceilings are yours to set on your key. A stored key carries a daily and a monthly spend ceiling set by the project's team leader, plus a smaller per-member share for anyone other than the key's owner. Setting a sensible ceiling is your responsibility; we enforce whatever ceiling is set, and refuse the call rather than allow it through when spend cannot be metered.
  • Work funded by Signoos' own account runs under fixed ceilings we set and may be withdrawn, reduced or changed at any time. It is a courtesy, not an entitlement, and a project can switch it off.
  • Fees for the Signoos service itself, if any, are only those separately agreed with you in writing. Nothing on the public site is an offer or a price.
  • A leader granting a member permission to spend a stored key grants permission to spend it, never access to the secret.

8. Availability and changes to the service

We aim to keep Signoos available and working, but we do not commit to any uptime level unless we have agreed one with you in writing. We may change, add or remove features, and may impose or adjust technical limits — rate limits, quotas, spend ceilings, model catalogues — as the service evolves. Where a change removes something you depend on, we will give reasonable notice if we can.

We may run maintenance, and we may suspend parts of the service to protect it, to protect other customers, or to comply with the law.

9. No warranty

To the fullest extent permitted by law, the service is provided “as is” and “as available”, and we disclaim all warranties, conditions and representations that are not expressly set out in these terms — including any implied warranty of merchantability, fitness for a particular purpose, quiet enjoyment, accuracy or non-infringement.

We do not warrant that the service will be uninterrupted or error-free, that defects will be corrected, that any AI output will be accurate or suitable, or that the service will detect any particular problem in your code. Nothing in this clause limits rights you have as a consumer that cannot lawfully be excluded.

10. Limitation of liability

To the fullest extent permitted by law, neither party is liable for indirect, incidental, special, consequential or punitive damages, nor for loss of profits, revenue, goodwill, business opportunity or anticipated savings, however caused and on any theory of liability.

To the fullest extent permitted by law, our total aggregate liability arising out of or relating to the service or these terms is limited to the greater of (a) the total fees you paid us for the service in the twelve months before the event giving rise to the claim, and (b) one hundred pounds sterling (or its equivalent). Charges you paid an AI provider, GitHub or any other third party are not fees paid to us.

Nothing in these terms limits liability for death or personal injury caused by negligence, for fraud or fraudulent misrepresentation, or for any liability that cannot lawfully be limited.

You accept in particular that we are not liable for loss arising from your reliance on AI output, given clause 5.

11. Indemnity

You will defend and indemnify us against third-party claims, and reasonable costs and damages awarded or agreed in settlement, arising from your content, your use of the service in breach of these terms or of the law, or your infringement of anyone's rights — including a claim that you had no right to have the code, review data or personal data you connected processed by us and our sub-processors. This does not apply to the extent the claim arises from our own breach of these terms.

12. Suspension and termination

You may stop at any time. Uninstall the GitHub App, delete a project, or delete your account from your account settings. Deleting a project starts a 30-day window in which you can restore it, after which it is purged; the periods are set out in the Privacy Policy.

We may suspend or terminate an account or a project if you materially breach these terms, if your use threatens the security, integrity or availability of the service or of another customer, if we are required to by law, or if a third-party service the account depends on withdraws access. Where the circumstances allow, we will warn you first and give you a chance to put it right; where they do not — an active threat, a legal requirement — we may act immediately and tell you afterwards.

We may also discontinue the service as a whole, on reasonable notice, giving you an opportunity to export your content first.

Clauses 4 (as to ownership), 9, 10, 11 and 14 survive termination.

13. Changes to these terms

We may update these terms. The date at the top of this page always says when. For a change that materially affects your rights or obligations we will give notice in the product and by email to your account address before it takes effect. Continuing to use the service after that means you accept the updated terms; if you do not, stop using the service and delete your account, and clause 12 applies.

14. Governing law

These terms, and any dispute arising out of or in connection with them or the service, are governed by the laws of the country in which the operator of Signoos is established, and the courts of that country have exclusive jurisdiction, without prejudice to any mandatory right you have as a consumer to bring proceedings where you live.

Provisional. Signoos is operated by an individual and is not yet an incorporated company, so there is no registered seat to name here. We will state the governing country and courts by name on this page as soon as the operating entity is registered, and will give notice of that change under clause 13. Until then you can ask for the operator’s full legal identity at [email protected].

If any provision of these terms is held unenforceable, the rest continues in force. Our failure to enforce a provision is not a waiver of it. These terms, together with the Privacy Policy and the AI processing page, are the entire agreement between us about the service, and replace any earlier understanding about it. You may not assign these terms without our consent; we may assign them to a successor to our business.

15. Contact

Questions about these terms, or notices under them: [email protected].