Legal / base agreement

Terms of Service

Archived draft

Last updated July 28, 2026. Written for the current prelaunch product.

Version
2026-07-28
Effective
Not yet effective
Review by
Before public signup

Not yet effective. This operational draft reflects the current product and planned account foundation. The contracting entity, governing law, dispute process, liability cap, and legal notice address must be completed with counsel before public signup opens.

1. Agreement and scope

These Terms govern access to Wildflower Computer’s websites, APIs, software, account tools, documentation, and related services. “Wildflower,” “we,” and “us” refer to the Wildflower contracting entity identified in the final version. “Customer” means the individual or organization accepting these Terms. If you use the Services for an organization, you represent that you have authority to bind it.

“Services” means Wildflower’s software, APIs, websites, account and administration tools, and related services for creating, connecting to, routing requests to, operating, and managing isolated compute environments. Where made available, a sandbox may run on Wildflower-operated infrastructure, on a third-party provider selected by Customer, or on a provider selected under routing rules Customer authorizes.

The Sandbox Services Scheduleidentifies the modes and features currently available. Marketing, documentation, or a future roadmap does not create a commitment to deliver an unannounced feature.

2. Eligibility and authority

You may use the Services only if you can form a binding contract and your use is permitted by applicable law. You must provide accurate account information and promptly tell Wildflower if you believe an account, session, API key, or connected provider credential has been compromised.

3. User profiles and accounts

A User Profile represents a human identity. A Personal Account is the individual workspace associated with one User Profile. An Organization Account is a shared customer workspace whose resources are controlled by the organization. Projects organize API keys, provider profiles, sandboxes, and related operational records within an account.

When organization features are available, owners and administrators may manage membership, roles, projects, provider connections, API keys, sandbox resources, and related metadata according to their permissions. Customer is responsible for its Authorized Users and for obtaining any notices or consents needed to let its administrators exercise those controls.

Do not share individual browser sessions. Project API keys are workload credentials and may be used by applications or authorized systems. Removing the person who created a project API key does not automatically revoke that key. Customer must review and rotate project credentials as its people and systems change.

4. Organization membership and project transfers

Organization owners and administrators must use invitations, roles, and project assignments only for people they are authorized to manage. Organization projects are private by default. Account and project roles may grant different administrative and workload permissions.

Where transfer is supported, moving a project from a Personal Account to an Organization Account transfers control of the project and its associated API keys, provider profiles, sandbox records, idempotency records, and lifecycle history to the destination organization. The transferor represents that they have authority to make that transfer.

5. Provider credentials and connected services

If Customer connects a provider account or supplies provider credentials, Customer authorizes Wildflower to store, decrypt, transmit, and use those credentials as reasonably necessary to provide, secure, and support the configured Services. Customer represents that it is authorized to use the credentials and instruct Wildflower to act through the associated provider account.

Connected credentials may remain encrypted until Customer disconnects the provider profile or deletes the associated project or account, subject to protected backup retention. Inline credential overrides are used for the requested operation and are not intentionally persisted by Wildflower. Customer remains responsible for credential scope, rotation, and provider-side revocation.

6. Third-party and Wildflower-operated infrastructure

In a customer-connected or BYOK mode, the selected sandbox provider is an independent service. Customer’s agreement, charges, quotas, availability, security configuration, data handling, and remedies with that provider remain between Customer and the provider.

If Wildflower later offers managed provider routing or Wildflower-operated sandbox capacity, the applicable Service Schedule or Order Form will identify the operator, fees, service levels, data location commitments, and any terms that differ from the customer-connected mode. Wildflower does not currently resell provider capacity or offer Wildflower-hosted sandboxes.

7. Customer Content

“Customer Content” includes code, commands, environment values, files, input, output, configuration, and other material submitted to or processed through the Services. As between Customer and Wildflower, Customer retains its rights in Customer Content.

Customer gives Wildflower the limited rights needed to receive, process, transmit, and, where a feature requires it, temporarily store Customer Content to provide, secure, troubleshoot, and support the Services and comply with law. Customer is responsible for having all rights, notices, and permissions needed for its Customer Content and intended workloads.

Wildflower does not use Customer sandbox content to train AI models. A sandbox provider may have different data practices under its own agreement with Customer.

8. Acceptable use

Customer and its Authorized Users must follow the Acceptable Use Policy. Wildflower may rate-limit, restrict, suspend, or terminate access when reasonably necessary to address abuse, security risk, legal requirements, provider requirements, or material breach.

9. Service changes and prelaunch features

Prelaunch, preview, and beta features may be incomplete, interrupted, changed, or withdrawn. Test data may be lost. Do not use a prelaunch service for safety-critical, regulated, or production workloads unless Wildflower expressly identifies the relevant service as production-ready in writing.

Wildflower may add or remove providers and features. We will use reasonable efforts to give advance notice before discontinuing a generally available material feature, except where immediate action is required for security, legal compliance, provider availability, or prevention of harm.

10. Fees

The current prelaunch service does not include Wildflower billing or provider resale. Customer remains responsible for charges assessed by a connected provider. Before Wildflower introduces paid Services, the applicable pricing, taxes, payment terms, and cancellation rules will be presented in an Order Form or updated terms.

11. Ownership, software, and feedback

Wildflower and its licensors retain their rights in the Services, documentation, branding, and non-customer materials. Open-source software is governed by its applicable license. These Terms do not override an open-source license.

If Customer voluntarily provides feedback, Customer permits Wildflower to use it without restriction or compensation, provided that this does not grant Wildflower rights in Customer Content or Customer Confidential Information.

12. Confidentiality and security

Each party may receive non-public business or technical information that should reasonably be understood as confidential. The receiving party will use reasonable care, use it only for the relationship, and disclose it only to people and service providers who need it and are subject to appropriate confidentiality obligations.

Wildflower uses technical and organizational safeguards designed for the current Services. No system is perfectly secure. Customer is responsible for securing its devices, accounts, application code, provider accounts, and copies of credentials outside Wildflower.

13. Suspension, termination, and deletion

Customer may stop using the Services and may request deletion through available account controls. Deletion may be delayed or rejected while active or outcome-unknown sandboxes remain, while the user is the sole owner of an Organization Account, or where retention is required by law or an applicable agreement.

Leaving or deleting a User Profile does not delete resources owned by an Organization Account. Organization deletion requires appropriate owner authority and cleanup of active sandboxes. Limited audit and security records may survive with direct account and project references removed.

14. Disclaimers and liability

To the extent permitted by law, prelaunch Services are provided “as is” and “as available.” Wildflower does not warrant uninterrupted or error-free operation, provider availability, portability between providers, or that the Services will meet every Customer requirement.

The final Terms will include a negotiated allocation of direct and indirect damages, exclusions, liability caps, indemnification, and exceptions. Those provisions are intentionally not fabricated in this prelaunch draft and must be completed before these Terms are offered for acceptance.

15. Order of precedence and updates

A signed Order Form, enterprise agreement, or service-specific schedule may supplement these Terms. The final agreement will state the order of precedence between those documents, the Data Processing Addendum, and these Terms.

Material updates will be dated and communicated through a reasonable account or contact channel before taking effect. If an update requires renewed acceptance, continued access may depend on an authorized user accepting the updated agreement.

16. Questions and legal notices

Email legal@wildflower.computer for questions about these Terms or legal notices. Follow the support guidance for product or security help. Do not send API keys, provider credentials, session cookies, Customer Content, or sandbox output in a legal or support message. A mailing notice address will be published before public signup.