Skip to content
Inkstand

legal

Terms

The agreement for using Inkstand. Read clauses 10, 15 and 17 before anything else.

Version 0.5Effective 29 July 202619 min readTouch Grass AB

Written from the system, not from a template. Every statement here describes what the software actually does — the region, the sub-processors, what is collected, what is retained, what leaves the EEA. It is a description of a system rather than legal advice, and it is published rather than sent after a call. If your counsel needs redlines, or your own paper, that is a conversation and not a problem.

Contents — 23 clauses

1Who you are contracting with#

Inkstand is operated by Touch Grass AB, a private limited company (aktiebolag) registered in Sweden since 2024, registration number 559484-7435, registered office Idunsgatan 46, 214 46 Malmö, Sweden, VAT number SE559484743501. In these terms "we" and "us" mean that company, and "you" means the organisation on whose behalf an account is used.

These terms, the privacy notice and the data processing agreement are the whole of the agreement between us. If we sign something else with you, that document wins wherever the two disagree.

2Accepting these terms#

2.1Creating an account, redeeming an invitation, or using Inkstand accepts these terms. There is no separate signature step, and there is not currently a click-through record of acceptance — if your procurement process requires an executed copy, say so and you will get one.
2.2If you use the product for an organisation, you confirm you are authorised to accept these terms for it, and "you" means that organisation. An individual using it for themselves is bound in their own name.
2.3The product is for professional and business use. It is not offered to consumers, and nothing in it is intended for anyone under sixteen.

3What the service is, and that it is a beta#

3.1What the service is. Inkstand is a governance engine for marketing content. It holds the rules your organisation sets for what may and may not be said, checks content against them, reports which of those checks actually ran, and keeps a record of what was found and who decided to publish anyway. It is invite-only and in beta.
  • The editor. A browser application that composes social media carousels, checks their copy before an export is allowed, records each release, and can send one post to someone outside your organisation for comment and sign-off under clause 9.
  • The API. Two HTTP endpoints, reached with a key issued under clause 10. One takes blocks of text and returns findings against the rules of one brand in your account; the other records a person's override or set-aside of a finding into the same audit trail. Neither can read, create, alter or export your content, and neither accepts rules supplied in the request — a check is only ever made against a rule set your account owns.
Both surfaces call the same checker, so neither is more permissive than the other, and an account rule holds over both. Clause 10.5 states the one respect in which the API reports less than the editor does. Nothing else is offered as a service today: there is no scheduling, no publishing and no archiving, and clause 16 governs what any of it is warranted to do.
3.2Two defined terms, used throughout. Beta Access means any use of the service before we notify account owners in writing that it has become generally available. Pilot means Beta Access under a written arrangement that names a period, a scope or a fee — including a founding rate. Everything in this clause applies to a Pilot exactly as it applies to any other Beta Access, and paying does not change the status. Where a signed order form says otherwise, the order form wins for that customer only.
3.3Beta means specific things, not a general disclaimer. Features can change or be withdrawn without notice. Data models can change, and a change that requires migrating your content will be done by us but may briefly make it unavailable. There is no uptime commitment, no support commitment, and no response time. Some described behaviour is not wired in yet, and where that is true the product and the security page say so rather than implying otherwise.
3.4We may end the beta, or your access to it, on 30 days written notice, except where clause 19 allows a faster suspension. On any ending, clause 19.4 governs getting your data out.
3.5Do not rely on this as the only copy of anything. Export your work. Artwork exports as PNG and PDF and the governance record exports as JSON, all without asking us, which is the practical answer to what happens if we stop.
3.6Interfaces can change during Beta Access, including the API. Request and response shapes, rule identifiers, finding fields and the addresses of endpoints may change, and a change may break software you have built against them. We will give account owners holding an active API key 30 days written notice of a change we know to be breaking, and cannot promise to have identified every one in advance. Clause 10 governs the keys themselves.
3.7Nothing here is a determination that the service is fit for a regulated process. Whether to put it in the path of anything you are accountable for is your decision, made with the information the product gives you about which checks actually ran — clause 11 — and it stays your decision during a Pilot. We do not certify it, and no statement by us, in a demonstration or in writing, should be read as certifying it.

4Accounts, invitations and access#

4.1Sign-in is a one-time link sent to your email address. There is no password and no second factor. Whoever controls the mailbox controls the account, so keeping that mailbox secure is your responsibility, and telling us promptly if it is compromised is part of it.
4.2Access is by invitation. An invitation is single-use, expires in fourteen days, and is bound to the address it was sent to. Accounts are for one person and must not be shared.
4.3An account has owners, editors and viewers, each reaching every workspace in it, and limited seats that reach only the workspaces they are granted. The boundary between them is enforced by the database rather than by hiding buttons. You are responsible for who you invite and at what level, and for the acts of everyone using your account.

5Fees, plans and what is actually enforced#

5.1There is no billing system, no self-serve checkout, and no charge for use during the beta. Published pricing describes what a subscription is intended to cost, not a sum currently owed.
5.2The published plans are not enforced by the software. The pricing page describes plans distinguished by the number of brands, the number of seats, and access to the API. None of those boundaries is currently metered or applied in the product: there is no seat count, no limit on how many workspaces an account may hold, and no measurement of API call volume for billing purposes. What your account can actually do is what these terms and the product allow, and a plan boundary becomes real only when a written agreement under 5.3 makes it so.
5.3Charging begins only under a separate written agreement setting the price, term, invoicing and notice period, and — where a plan meters anything — the included volume, the unit and the rate. Until one exists, nothing in these terms obliges you to pay anything, and nothing obliges us to keep a published rate, including a founding rate, available to someone who has not taken it.
5.4Where the pricing page marks a capability as not yet available, that marking is part of what we are telling you and is not superseded by anything else the page says about the plan it appears in.

6Your content, and who owns it#

6.1You keep every right you had in the content you put in and the content you produce with the product. Nothing here transfers ownership to us.
6.2You grant us a non-exclusive, worldwide, royalty-free licence to host, copy, transmit, render and display that content, and to send it to a sub-processor, strictly to operate the service for you and for as long as we do. It ends when the content is deleted.
6.3We do not use your content to train models, and we do not use it to improve the product for anyone else. Content sent to a model provider is sent for that single request. Whether the provider retains it is governed by their terms and by the account configuration recorded on the sub-processors page.
6.4We will not use your name, logo or work as a reference or case study without asking you first.

7Output from the AI features#

7.1As between you and us, whatever rights exist in text or imagery produced by the generation features are yours, and we assign to you any we might otherwise have. We claim no ownership and take no licence beyond clause 6.2.
7.2That is not the same as a warranty that the output is yours to use. Three things are true of any current generative model and we are not going to write around them:
  • Machine-generated material may attract no copyright at all in some jurisdictions, because authorship is treated as a human act. We cannot grant you a right that does not exist.
  • A model can reproduce material it was trained on. Output may resemble, or in fragments reproduce, somebody else's work.
  • Two customers giving similar instructions can receive similar output. Nothing here gives you exclusivity over what a model returns.
7.3The practical consequence: treat generated copy as a draft you are responsible for reviewing, not as an asset delivered to you. Clause 10 applies to the checks that run over it, and clause 19 applies to what you publish.

8What you upload, and the rights you have to hold#

8.1You confirm that you own, or are licensed to use, everything you put into the product, including images, logos, fonts, quotations and any name or likeness in them, for the purposes you use it for.
8.2Fonts specifically. A font cannot be stored without an attestation that the workspace holds a licence permitting its use in this way, and that attestation is enforced by a database constraint rather than a tick box, recorded against the person who gave it. It is a durable record that the question was asked and answered. It is not a licence check and cannot be one — we do not verify licences and do not undertake to.
8.3If we are told that something in your workspace infringes somebody's rights, we may remove or restrict access to it, and we will tell you what was removed and why.

9Review links#

9.1You can create a link that opens one carousel for someone without an account. The link is the whole of the authorisation: anyone holding it has the access it grants, including anyone it is forwarded to. Every link carries a mandatory expiry and can be revoked at any time.
9.2Sending a link to a person outside your organisation is a disclosure by you, not by us, and choosing to make one is your instruction under the data processing agreement.
9.3A name typed by a link holder is self-asserted and the product treats it as such. A sign-off made through a link only reaches a release record once a signed-in member of your workspace confirms they have read it. Do not treat an external sign-off as verified identity.

10API keys and machine access#

10.1An account owner can issue keys that let software you run — a plugin, a pipeline, an agent — check content against your rules and record an override. A key carries the access it grants to anyone holding it, exactly like a review link, and it is issued only by an owner because it is a standing grant of access to your rule set.
10.2The secret is shown once and is not recoverable. We store only a cryptographic hash of it, so we cannot read it back to you, and a lost key is replaced rather than recovered. You are responsible for keeping keys secret, for revoking one you no longer control, and for everything done with a key issued from your account until it is revoked.
10.3A key can check content and record a disposition. It cannot read your carousels, change your rules, export, or reach any account other than the one it was issued from. We may rate-limit, suspend or revoke a key that is being used in a way that threatens the service or another customer, and will tell the account owner when we do.
10.4Rate limits and request size limits apply and can be changed. Under Beta Access they are set to protect the service rather than to meter a plan — nothing is counted for billing today, and clause 5.2 says so of every plan boundary. The published pricing describes an intention to include a monthly call volume and to meter above it; that becomes an obligation on either of us only through an agreement under clause 5.3, which has to state the included volume, the unit and the rate. Clause 3.6 governs changes to the interface itself.
10.5The endpoint runs the deterministic checker and calls no model. A rule whose check is model-assisted is returned as steered — reported as not inspected — and the field naming rules a model reviewed comes back empty on every response. The model-assisted pass described in clause 11.1 runs inside our editor and is not exposed over the API. Software you build against this endpoint must not present its result as a reviewed one.
10.6An override recorded through a key is attributed to the key, not to a person. The record names the integration because that is what we can know; it does not name a human, and you should not read it as identifying one. If you need per-person attribution, your integration has to carry it.
10.7The engine is licensed for checking your own content and your clients'. It is not licensed to be resold, rebranded, or offered to third parties as a checking service of your own, and you may not use it to build a competing product. Clause 13 governs the software itself.

11What the checks are, and are not#

11.1The product checks content against rules you configure. Findings come in three kinds and the difference is the point of the product:
  • Verified. A deterministic check in code. The result is a fact about the text.
  • Reviewed. A model was asked. The result is probabilistic and will miss violations.
  • Steered. The rule only ever reached a generation prompt. Nothing inspected the output against it.
Which one applies is stated in the interface and written into every release record, so it is answerable after the fact for a named piece of work.
11.2Nothing in this product is legal, regulatory, medical or financial advice, and it does not make your content compliant. Sector rule packs encode common marketing conventions, not the obligations of your jurisdiction or your regulator. Responsibility for what you publish is entirely yours.
11.3The product can be made to release content that has failed a check, by a person with authority to waive it, who is required to give a reason. That waiver and that reason are recorded permanently. It is a deliberate escape hatch and using it is your decision.
11.4Claim research compares a claim against sources you nominate and requires a citation for every finding. It reduces guesswork; it does not establish that a claim is true, and it is not a substitute for a disclosure review.

12Acceptable use#

You must not use the service to:

  • produce or distribute unlawful content, or content that infringes anyone's rights;
  • impersonate a person or organisation, or produce material designed to be mistaken for somebody else's official communication;
  • generate deliberately false or misleading claims, in particular financial, health or regulatory ones;
  • reach a workspace, a review link or an account you were not given access to, or probe, scan or test the system's defences other than under the vulnerability disclosure policy;
  • upload malware, attempt to interfere with the service, or place a load on it designed to degrade it for others;
  • resell, sublicense or provide the service to a third party as your own, or use it to build a competing product;
  • circumvent a rule, a role or a waiver record in order to hide who released something.

Automated access is fine within reason. Scraping the product, or driving it at a rate that is obviously not a person using it, is not.

13Our intellectual property, and your feedback#

13.1The service, the software, the rule engine, the templates and the design system are ours and stay ours. You get a non-exclusive, non-transferable right to use them during the term, and nothing more. You must not copy, decompile or reverse engineer the software except where the law says you may despite this clause.
13.2Anything you make with the product is yours under clause 6, including the artwork, whatever template it started from.
13.3If you send us feedback, a bug report or an idea, we can use it without restriction and without owing you anything. This does not give us any right to your content or your confidential information.

14Confidentiality#

14.1Each of us will keep the other's confidential information confidential, use it only for this agreement, and protect it at least as carefully as our own. Your content is your confidential information by default.
14.2You are seeing an unreleased product. Unreleased features, prices offered to you, and anything we tell you about the roadmap are our confidential information. This does not stop you describing your experience of the product publicly, and it does not stop you telling your own regulator or auditor anything they ask for.
14.3Neither of us is bound as to information that is public without our fault, was already known, is independently developed, or must be disclosed by law — in which case the other is told first where that is permitted.

15Data protection#

Where your use of the service involves personal data for which you are the controller, the data processing agreement applies and forms part of these terms. Personal data for which we are the controller is covered by the privacy notice. Where the two documents conflict on a processing matter, the data processing agreement wins.

16Availability, and the absence of a warranty#

16.1The service is provided as-is and as-available. There is no service level agreement, no availability target, no maintenance window, and no credit for downtime. We can take it offline at any time, and we will try to say so first.
16.2To the fullest extent the law allows, we exclude every implied warranty, including merchantability, fitness for a particular purpose, non-infringement, and any warranty arising from a course of dealing. We do not warrant that the service will be uninterrupted, error-free or secure, that findings will be complete or accurate, or that generated output will be original, accurate or lawful to publish.
16.3A Pilot is not a warranty. Agreeing a period, a scope or a fee with us does not create an availability target, a support commitment or a fitness determination, and neither does anything said in a demonstration, a proposal or a sales conversation. Only a term written into a signed order form changes what this clause says, and then only for the customer who signed it.
16.4Nothing in this clause displaces a right you have as a matter of Swedish or EU law that cannot be excluded by agreement.

17Liability#

17.1Neither of us is liable to the other for loss of profit, loss of revenue, loss of business or goodwill, loss of anticipated savings, loss or corruption of data, regulatory fines, or any indirect or consequential loss, however it arises.
17.2Our total liability arising out of or in connection with this agreement is limited to the total fees you paid us in the twelve months before the claim. Under Beta Access that figure is zero unless you are paying, and a founding rate makes it small. Your procurement team should read that as a real limitation rather than as boilerplate, and it is the honest reason to keep the scope of what you put in the product proportionate to it.
17.3Neither of us limits liability for death or personal injury caused by negligence, for fraud or fraudulent misrepresentation, for gross negligence or wilful misconduct, or for anything else that cannot lawfully be limited. Your obligation to pay fees that are actually due is not capped, and neither is your indemnity under clause 18.

18Your indemnity#

You will indemnify us against claims, losses and reasonable costs arising from content you put into or publish out of the service, from your use of material you did not have the rights to, from your breach of clause 12, or from a claim by someone you gave a review link to. We will tell you promptly about any such claim, let you control the defence of it so long as any settlement releases us fully, and give you reasonable help at your cost.

19Suspension, termination and getting your data out#

19.1You can stop using the service and ask for your account to be closed at any time, for any reason, with no notice.
19.2We may suspend access immediately where there is a real risk to the service, to other customers, or to us — an active attack, a legal demand, or a serious breach of clause 12. We will tell you why, and restore access once the cause is resolved.
19.3We may terminate for material breach that is not put right within thirty days of being described in writing, or under clause 3.4.
19.4On termination. Artwork exports as PNG and PDF and the governance record exports as JSON, at any time, without asking us. For thirty days after termination we will keep your data and restore access on request so you can export it. After that, it is deleted in accordance with clause 7 of the privacy notice and clause 12 of the data processing agreement — except records whose evidential purpose is exactly that they survive, which are retained and are not readable by us beyond the metadata described in the privacy notice.
19.5Clauses 6, 7, 10.7, 13, 14, 16, 17, 18 and 23 survive termination.

20Changes to these terms#

These terms carry a version number and an effective date. A material change will be notified by email to account owners at least 30 days before it takes effect. Continuing to use the service after that date accepts the change; if you do not want to, close the account under clause 19.1 and export your work.

21Notices#

Notice to you is by email to the address on your account owner's account, and takes effect when sent. Notice to us is by email to privacy@touchgrass.consulting or in writing to Touch Grass AB, Idunsgatan 46, 214 46 Malmö, Sweden. A notice terminating this agreement or alleging a material breach has to be in writing and cannot be an in-product message.

22Governing law and disputes#

22.1This agreement and any dispute arising out of it, including a non-contractual one, is governed by the laws of Sweden, without regard to conflict-of-law rules and excluding the UN Convention on Contracts for the International Sale of Goods.
22.2The courts of Sweden have exclusive jurisdiction, with Malmö District Court (Malmö tingsrätt) — the district court for our registered office — as the court of first instance. Either of us can still seek an injunction wherever it is needed to protect intellectual property or confidential information.

23General#

23.1You may not transfer this agreement without our written consent. We may transfer it to a company acquiring the business or its assets, and will tell you if we do.
23.2If a clause is unenforceable, it is limited to the minimum extent needed and the rest stands. Not enforcing something is not a waiver of it.
23.3Nothing here creates a partnership, agency or employment between us, and no third party can enforce any of it.
23.4Neither of us is liable for a failure caused by something genuinely outside our control, though it does not excuse paying money that is due.

Terms of service, version 0.5, effective 29 July 2026. Every agreement, and who you are contracting with, on the legal index.