Terms of Service
These terms govern your use of Lochless, including the website at lochless.io, the console at console.lochless.io, the API at api.lochless.io and the MCP server (together, the "Service"). The Service is provided by Synoptic Data Ltd. (company no. 517379954), an Israeli company ("Lochless," "we," "us").
By signing in or using an API key, you agree to these terms. Our Privacy Policy explains how we handle personal data. If you use the Service for an organization, you confirm you can bind it, and "you" means that organization.
1. The Service
Lochless is a hosted text index. You send text through the API, and you or your applications query it with the context and ask endpoints or through the MCP server. The Service is in early access. Features, limits and performance may change. Support and availability are covered in section 16.
2. Who can use it
The Service is for business and professional use, not for personal, family or household use. You must be at least 18. You may not use it if sanctions or export laws bar you from receiving it.
3. Your workspace and keys
- Signing in with Google lets you request access. If we approve your request, we create one workspace for you. We may decline any request. Keep your sign-in secure.
- API keys give full access to your workspace. Keep them secret. You are responsible for all use of your keys, including by your applications and agents, until you revoke them in the console.
- Tell us promptly at support@lochless.io if you believe a key or your sign-in has been compromised.
4. Your content
- You keep all rights to the text and metadata you send and the queries you run ("Your Content"). As between you and us, the results and answers the Service returns to you ("Output") are yours too.
- You give us a limited license to host, copy, process and transform Your Content only to provide, secure and support the Service for you, as these terms and the Privacy Policy describe.
- Your Content is used only to serve your workspace. We do not use it to train, tune or evaluate models or settings for any other customer. How our AI providers handle data is described in the Privacy Policy.
- Workspace learning. The Service may learn from your workspace's own queries and documents, to improve results for your workspace. What it learns serves only your workspace and is never used for any other customer. You can ask us to turn this off at any time, and to delete what it has learned.
- Keep your own copies of Your Content. The Service is not a backup.
- You confirm you have the rights and any notices or consents needed to send Your Content to us and to have it processed as these terms describe, including any personal data in it.
- Do not send data that needs special legal handling, such as protected health information under HIPAA, payment card data, government ID numbers, or special categories of personal data under the GDPR (such as health data), unless we have signed a written agreement covering it. The Service is not designed for that data.
5. Acceptable use
You will not, and will not let others:
- break the law or infringe anyone's rights using the Service, including privacy and intellectual property rights;
- send content that sexually exploits children, or use the Service to promote violence or terrorism, or to carry out fraud, make weapons or cause other serious harm;
- use Output as the only basis for decisions that significantly affect people, such as decisions about credit, employment, housing, insurance, health or legal rights, without meaningful human review;
- send malware, or probe, scan, disrupt or bypass the Service's security, limits or billing, unless we agree in writing;
- scrape or crawl the Service or the website, or access another workspace's data;
- create extra workspaces or accounts to get more free credit, avoid limits or evade a suspension, or share keys to get around limits;
- resell the Service as a standalone index without our written consent;
- use the Service or its Output to build or train a competing product or model, or reverse engineer it except where the law allows.
We may suspend a key, a workspace or a feature to stop a breach of these terms, to deal with a security risk or illegal content, to comply with law, or to prevent harm to the Service or others. Where we reasonably can, we will tell you first. Otherwise we will tell you promptly after, and restore access once the issue is resolved. We may remove or block content we reasonably believe is illegal. Suspension does not reduce your balance.
6. Fees and billing
- Prices. You pay for context and ask calls, including calls through MCP, at the prices shown on lochless.io when the call is made. Every response reports what it scanned. You also pay for indexing, per page as defined on lochless.io, at the price shown there when a document is indexed. Re-sending a document with unchanged text is free. Changed text is charged again in full. A document that fails to index is not charged. Document status, delete and dry runs are free for now.
- Free credit. Each workspace gets a one-time free credit when it is created, in the amount shown on lochless.io at that time. It is used before any paid credit. It cannot be moved to another workspace, has no cash value and is never refunded. One free credit per person or organization. We may change or end the free credit, or start charging for free features, with at least 30 days' notice.
- Paid credit. You buy credit in the console in the amounts offered there. It is added to your balance once payment is confirmed. Paid credit does not expire while your workspace is open. When your balance reaches zero, paid calls and indexing stop until you add credit. New ingests are refused, and queued documents wait.
- Spend cap. Each workspace has a monthly spend cap, shown in the console. Calls and indexing stop when it is reached and resume the next month. Contact us to change it.
- A call, or a document's indexing, that starts before your balance or spend cap runs out finishes and is charged in full. So your balance can go below zero, or your spend over the cap. A negative balance comes out of your next purchase.
- Payment. Purchases are made through our reseller and merchant of record, Polar, which handles checkout, payment, invoices and taxes under its own buyer terms. Prices exclude taxes. Polar adds any that apply.
- Refunds. Paid credit is non-refundable, except where the law requires. If a call fails to return results or an answer, the credit charged for it goes back to your balance. If you see a charge for a failed call, send us its request id within 60 days. If Polar refunds a payment or it is charged back, we remove the matching credit from your balance and may suspend paid usage until any negative balance is settled.
- Price changes. We may change prices with at least 30 days' notice on lochless.io or by email. New prices apply to calls made and documents indexed after they take effect. Your balance is held in US dollars, so a price change changes how much it buys. If you do not accept a price change, stop using the Service before it takes effect.
- Billing questions. If you think a charge is wrong, tell us within 60 days of the charge. Our usage records are the basis for charges unless you show they are wrong.
7. Limits
The Service has rate limits, queue limits and similar controls, described in the docs. A large ingest may take more than a day to become searchable. We may change these controls to protect the Service.
8. Confidentiality and security
We keep Your Content confidential and protect it with reasonable administrative, technical and organizational safeguards, as described in our Privacy Policy. Our staff access it only to provide the Service to you, to fix problems, to keep the Service secure, or when the law requires. If we confirm a security breach affecting Your Content, we will tell you without undue delay.
9. Personal data in Your Content
When Your Content includes personal data, you are the controller (or a processor for your own customer) and we are your processor or service provider. This section is our data processing agreement with you under the GDPR, the UK GDPR, Israel's Privacy Protection Law and US state privacy laws such as the CCPA.
- We process it only on your instructions. These terms and your use of the Service are your instructions. We will tell you if we believe an instruction breaks data protection law.
- Everyone who processes it for us is bound by confidentiality.
- We protect it with the safeguards in section 8.
- You authorize the subprocessor categories listed in the Privacy Policy. We bind each subprocessor to data protection terms at least as protective as these, except as section 5 of the Privacy Policy describes for AI providers, and we remain responsible for them. A list of named subprocessors is available on request. We give at least 14 days' notice of a new subprocessor to anyone who asks to be notified. If you object on reasonable data protection grounds, you may stop using the Service and close your workspace.
- We help you respond to requests from individuals and meet your security, breach notification and impact assessment duties, as far as reasonable given what we can see. You can handle most requests yourself through the API, for example by deleting documents.
- We tell you without undue delay after we confirm a personal data breach affecting Your Content.
- When you ask, we delete Your Content as section 11 describes, unless the law requires us to keep it.
- We give you the information reasonably needed to show we meet this section, including our audit reports when available, and we answer reasonable security questionnaires. Any audit must be on reasonable notice, at your cost, and no more than once a year unless a regulator requires it.
- We are based in Israel, which the European Commission and the UK recognize as providing adequate protection. Where personal data moves to a country without that status, we use safeguards the law accepts, such as the European Commission's standard contractual clauses.
- We do not sell or share it. We do not retain, use or disclose it outside our direct business relationship with you, or for any purpose other than providing the Service, or combine it with other personal data, except as the CCPA and similar laws allow. We will tell you if we can no longer meet these duties, and you may take reasonable steps to stop and fix any unauthorized use.
- If you need a signed copy of these data processing terms, email support@lochless.io.
10. Feedback
If you send us feedback or ideas, we may use them without obligation to you.
11. Ending use
- You can stop using the Service at any time and revoke your keys in the console. To close your workspace, email support@lochless.io from the address you sign in with.
- We may suspend or end your access for a material breach of these terms, for non-payment, or where the law requires. Where a breach can be fixed, we will give you a reasonable chance to fix it first.
- We may also end the Service or your workspace for any other reason, with at least 30 days' notice.
- We may close a workspace that has no paid credit and has made no API calls for 12 months, after 30 days' notice by email.
- We delete query history automatically, as section 7 of the Privacy Policy describes. At any time, including when you close your workspace, you can ask us to delete your query history and what the Service has learned from your workspace, or your whole workspace with all its content. We do so within 30 days of your request, and copies in backups are removed within a further 7 days. We keep billing records as the law requires.
- Unused paid credit is not refunded when a workspace is closed, except as section 6 says.
- Sections 4, 6 (for amounts owed), 9 (for as long as we hold Your Content), 10 and 12 to 15 survive.
12. Disclaimers
The Service is in early access and provided "as is" and "as available." To the fullest extent allowed by law, we disclaim all warranties, express or implied, including merchantability, fitness for a particular purpose and non-infringement. Results, answers and citations are generated automatically and may be incomplete or wrong. Check them before relying on them, especially for decisions about people. Published benchmarks describe specific test conditions and do not promise the same results on your data.
13. Limitation of liability
To the fullest extent allowed by law, neither party is liable for indirect, incidental, special, consequential or punitive damages, or for lost profits, revenue or data. Each party's total liability under these terms is limited to the greater of the amounts you paid for the Service in the 12 months before the claim and US$100. These limits do not apply to your payment obligations, your obligations under section 14, a breach of section 5, a party's fraud or willful misconduct, or where the law does not allow them.
14. Indemnity
You will defend and indemnify us against third-party claims arising from Your Content, your use of Output, or your breach of section 5, and pay resulting damages and reasonable costs. We will tell you promptly about the claim and let you control its defense. You will not settle a claim in a way that admits fault for us or binds us without our consent.
15. General
- These terms are governed by the laws of the State of Israel. The competent courts of Tel Aviv-Jaffa have exclusive jurisdiction. Either party may seek urgent injunctive relief in any competent court.
- We may update these terms. We will post the new version here with a new effective date, and give at least 30 days' notice of material changes by email or in the console. Changes required by law, or that only add features, may apply sooner. If you do not accept a material change, stop using the Service before it takes effect. Continued use after that means you accept the change.
- We send notices to the email address you sign in with, or post them in the console. You send notices to support@lochless.io.
- You may not assign these terms without our consent. We may assign them in a merger, acquisition or sale of assets.
- Neither party is liable for delays or failures caused by events beyond its reasonable control, other than payment obligations.
- If any part is unenforceable, the rest still applies. Not enforcing a right is not a waiver.
- These terms, the Privacy Policy and any signed order or agreement are the whole agreement on this subject. If they conflict, a signed agreement wins, then these terms, then the Privacy Policy.
16. Support and availability
- Support is by email at support@lochless.io, on a best-effort basis. We do not promise response times.
- During early access there is no uptime commitment or service level agreement (SLA), unless we sign one with you. The Service may at times be slow, interrupted or unavailable, including for maintenance.
17. Contact
Synoptic Data Ltd., Israel. Company no. 517379954.
support@lochless.io