# exployt.ai Legal and Terms Summary Last updated: 2026-08-25 Canonical legal page: https://exployt.ai/legal Canonical privacy page: https://exployt.ai/privacy Canonical Trust and Security page: https://exployt.ai/security ## Legal operator exployt.ai is operated by exployt Software GmbH, Merangasse 53/3, 8010 Graz, Austria. Commercial register: FN 675480d, Landesgericht fuer ZRS Graz. VAT ID: ATU83180825. Managing director: Michael Martin Schoeggl. Contact: office@exployt.ai. ## Terms of Service highlights Pricing model: private, non-commercial use by an individual is free of charge and requires no paid subscription; commercial use requires a commercial subscription. As a time-limited transition, commercial use by an individual (Professional scope) is also free until 1 January 2027 (through 31 December 2026), after which private non-commercial use stays free. Company and enterprise use always requires the applicable paid subscription. See https://exployt.ai/pricing and Terms sections 5, 6, 12 and 13. The Terms of Service cover account use, subscriptions, acceptable use, intellectual property, termination, disclaimer, governing law, subscription compliance, project integrity, marketplace/user budget features, payout/tax handling and liability limitations. Marketplace publishing is a deliberate upload: files and metadata chosen by the publisher are transmitted for review, hosting, sharing, sale and buyer delivery. Marketplace items can include integrations, modules, standalone apps, settings sets, workflows, connector packages or other reusable assets. For code-containing Marketplace items, exployt recommends package minimization and obfuscation where appropriate and can support that workflow. The legal page is the canonical source. ## Material changes Material pricing, tier-threshold or entitlement changes keep the Terms section 17 transparency rule: affected users receive thirty days advance notice where that rule applies. Non-material clarifications can take effect on publication. Stricter Austrian or EU consumer-protection rights prevail where applicable. ## User budget, payouts and tax information User Budget payouts are available only through channels shown in the Account page. exployt is not obligated to offer any specific payout channel, including a particular bank-transfer network, e-money wallet or third-party service; channels may be added, changed or removed at reasonable discretion. Any supported payout can be subject to identity checks, payment-provider fees, currency conversion and taxes that exployt is legally required to withhold. Tax information in the Terms is informational only, without warranty, and is not legal or tax advice. Users remain responsible for their own tax compliance and should consult their own tax advisor. As checked against official Austrian sources on 2026-08-25, Austrian section 109a EStG payor notification may apply only to enumerated payment categories; official guidance allows omission only if both the total paid to a recipient in the calendar year is not more than EUR 900 and each individual covered payment is not more than EUR 450. If either limit is exceeded and the payment category is covered, reporting may be required. For marketplace activity, DAC7/DPMG reporting may require annual transmission of seller identity data and payout totals to the Austrian Federal Ministry of Finance. The current sale-of-goods de-minimis exemption is fewer than 30 sales of goods and no more than EUR 2,000 total consideration in the reporting period. Austrian tax/accounting records are generally retained for seven years under BAO section 132; DAC7/DPMG reporting datasets follow the DPMG retention/deletion rule, currently deletion ten years after the relevant reporting period. VAT notes in the Terms are also informational only. The Austrian small-business VAT threshold is currently described in official BMF guidance as approximately EUR 55,000 gross per calendar year, subject to the law and tolerance rules in force for the relevant year. ## Website analytics privacy The public website privacy section is separate from app/project privacy. Optional website analytics may use Google Analytics 4 and Microsoft Clarity only where deployment config enables the provider and the consent setting permits loading. Where consent is required, GA4 and Clarity scripts load only after the visitor accepts analytics in the website prompt. The local browser decision uses the key exployt_analytics_consent. Blazor-ApexCharts is used only for client-side chart rendering in admin dashboards; it is not a separate analytics provider. ## Service availability and SLA Support requests sent to office@exployt.ai or submitted through product support/feedback forms receive an initial response within 24 hours. exployt cloud is needed for account creation, login/account management, billing, payment, subscription/license validation, Marketplace cloud actions and fresh entitlement checks. Ordinary desktop project work is local-first: the desktop app keeps a signed entitlement snapshot with a maximum 72-hour grace window, so transient server outages do not immediately remove access to subscription-locked features. If an exployt cloud outage occurs, the operational commitment is to restore the account/subscription service before that 72-hour grace window expires. This public commitment does not create service credits unless a separate written enterprise agreement says so. ## Security and certification status Security and compliance information is published at https://exployt.ai/security and in plain text at https://exployt.ai/trust.txt, https://exployt.ai/security.txt and https://exployt.ai/faq-security.txt. The current published security wording states that exployt is not ISO 27001 certified and does not provide a SOC 2 Type I or Type II report. exployt is preparing the control documentation, risk assessment, access-review evidence, incident-response evidence, vendor review and management-review material needed for an ISO 27001 or SOC 2 readiness/audit process. ## DPA, subprocessors and data residency Business and enterprise customers can request a Data Processing Agreement by contacting office@exployt.ai. exployt is preparing a public DPA package and will publish it when it is ready. The primary production web service is hosted on Microsoft Azure in the West Europe region (Netherlands). Current service providers for the public website, account service, billing, email, security and optional website analytics stack include Microsoft Azure, Stripe, Resend, MaxMind offline geolocation data, and optional Google Analytics 4 / Microsoft Clarity website analytics where enabled and consented where required. Customer-selected AI providers, Git services, tools, plugins, connectors, OpenRouter and local Ollama models used by the desktop app are chosen or configured by the customer and are not exployt cloud subprocessors for local project content. ## Export, deletion and exit Local project files, source code, agent history, local credentials and the local project database remain under customer control during ordinary desktop-app operation. The project database is a local SQLite database stored under the project's .exployt folder; when local database encryption is not enabled, it can be inspected or exported with ordinary SQLite-compatible tools. exployt also provides export/import flows for workflows, settings sets and many configuration assets such as agent/workflow settings. Project content leaves the local boundary only through explicit user actions: the customer selects a cloud AI provider or external tool and sends task context to it, publishes selected files and metadata as a Marketplace item for sharing or sale, or submits a support/bug report after preview and confirmation. The Terms do not restrict customers from using their own local project data with other software. Cloud account data and personal data requests are handled under the Privacy Policy and applicable law. Some records must be retained for legal, tax, accounting, fraud-prevention, dispute or security reasons.