Legal

Terms & Conditions

Written to be read. If you only read one part, read the summary — it is not marketing, it is the actual position.

The short version. Your content is yours — we claim no ownership of your code, requirements, or data. We access it only to operate the service or when you ask us to. We do not use it to train AI models. You can export everything through the API at any time, including after you stop paying. If we ever need to change something material here, we will tell you before it takes effect.

Last updated 5 August 2026. This summary is for orientation; the sections below govern.

1. Who these terms are between

These Terms govern your use of Oprex ("the Service"), operated by PT Kinetikum Indo Solusi ("we", "us"), an Indonesian company. "You" means the individual or organisation using the Service. If you accept these Terms on behalf of an organisation, you confirm you are authorised to do so.

By creating a workspace, signing in, or using the API or MCP endpoint, you accept these Terms.

2. Your content stays yours

You retain all rights to everything you put into the Service — source code, requirements, specifications, test cases, bugs, tickets, notes, memory documents, and uploaded files ("Your Content"). We claim no ownership over it and we do not acquire a licence to use it beyond what is necessary to run the Service for you.

Specifically, the licence you grant us is limited to: storing Your Content, transmitting it to you and to people you have authorised, backing it up, and displaying it inside your workspace. Nothing more.

3. Who at Oprex can read your data

We designed the system so that the answer is "almost nobody, almost never". In practice, our staff may access Your Content only in these situations:

  • You asked us to. For example, you open a support ticket and ask us to look at a specific project.
  • To fix a live incident. Where diagnosing a fault genuinely requires it, limited to what the fault requires.
  • Where the law compels us. Under a valid legal order — and we will notify you unless we are legally prohibited from doing so.

We do not browse customer workspaces, and we do not read Your Content for product research, marketing, or competitive purposes.

4. AI features and your data

This is the section developers actually want, so it is deliberately explicit:

  • We do not train models on Your Content. Not our own models, and we do not supply Your Content to any provider for training.
  • You choose the provider. AI features are configured per workspace. You may nominate your own OpenAI-compatible or Gemini-compatible endpoint and key, in which case inference happens against a provider you selected and your relationship with that provider governs it.
  • Context is explicit, not ambient. Memory documents and project data are included in an AI request only where you attached them. Nothing is silently swept into a prompt.
  • Agents inherit your permissions. An MCP client or API key acts on behalf of the person who created it and can never see more than that person can.
  • AI output is not warranted. Generated text, code, and suggestions may be wrong. You remain responsible for what you ship.

5. Your responsibilities

  • Keep your credentials and API keys secret. Keys are shown once and stored only as hashes — we cannot recover one for you, and anyone holding a key can act as you within its scope.
  • You are responsible for what the people you invite do inside your workspace.
  • Do not use the Service to store or distribute unlawful material, malware, or content you have no right to hold.
  • Do not attempt to access another tenant's data, probe the Service for vulnerabilities without telling us, or circumvent quotas and rate limits.
  • Do not resell the Service as your own without a written agreement with us.

Security research is welcome — see the Trust Center for how to report a finding responsibly.

6. Plans, quotas, and payment

Plan limits are published on the pricing page and enforced by the Service. When you reach a limit, the action that would exceed it is refused — existing data is never deleted to make room.

Paid plans are billed in advance for the period you selected. If payment lapses, your workspace reverts to the free plan rather than being deleted; data above the free limits becomes read-only rather than destroyed. We will tell you before that happens.

We may change prices, but not retroactively for a period you have already paid for, and not without reasonable notice.

7. Beta status

Oprex is in beta. Features may change, and we would rather say so here than imply a stability we have not yet earned. Where a specific guarantee exists, it is written down — where it is not written down, do not assume it.

Live service status is published at status.oprex.id.

8. Availability

We work to keep the Service available and we publish its live status, but during beta we do not offer a contractual uptime guarantee on self-serve plans. SLA-backed availability is part of the Business and Enterprise plans and is set out in the agreement for those plans.

We take regular backups and test restores. Backups are a safety net for us, not a substitute for your own exports — see the next section.

9. Getting your data out

You can export at any time, without asking us and without a support ticket:

  • Every lifecycle object is readable through the REST API with an API key you create yourself.
  • Uploaded assets are downloadable from the asset browser.

If you close your account, we retain your data for 30 days so an accidental deletion can be undone, then remove it from active systems. Backup copies age out on their normal cycle. If you need immediate deletion instead, ask and we will do it.

10. Suspension and termination

You may stop using the Service and delete your workspace at any time.

We may suspend an account that is causing harm — unlawful content, attacks on the Service or on other tenants, or non-payment after notice. Except where the harm is immediate and severe, we will contact you first and give you a chance to fix it. We will not terminate an account for asking difficult questions, publishing criticism, or reporting a vulnerability.

11. Privacy and personal data

Our handling of personal data is described in the Privacy Policy, which forms part of these Terms. We operate under Indonesian law, including Law No. 27 of 2022 on Personal Data Protection (UU PDP).

We collect the minimum needed to run the Service: your identity from single sign-on, your workspace membership, and operational logs. We never see or store your password.

12. Intellectual property in the Service

The Service itself — the software, design, and documentation — remains ours. These Terms grant you a right to use it, not a right to copy or redistribute it. Feedback you send us may be used to improve the Service without obligation, but feedback is not Your Content and we will not treat your project data as feedback.

13. Warranties and liability

The Service is provided "as is". To the extent permitted by law, we exclude implied warranties, and our aggregate liability arising from the Service is limited to the amount you paid us in the twelve months before the claim. Nothing here limits liability that cannot lawfully be limited.

We are not liable for loss arising from your failure to keep your own exports, from credentials you disclosed, or from decisions made on the basis of AI-generated output.

14. Changes to these Terms

We may update these Terms. For material changes — anything affecting your rights, our access to Your Content, pricing, or data retention — we will give notice before the change takes effect, through the Service and to the address on your account. Continuing to use the Service after that date means you accept the change; if you do not, you may export and close your account.

Non-material changes (clarifications, typos, updated links) take effect when published, and the date at the top of this page changes.

15. Governing law and disputes

These Terms are governed by the laws of the Republic of Indonesia. We would much rather resolve a disagreement by talking to you first — open a ticket and it reaches the people who built the thing.

16. Contact

Questions about these Terms, data handling, or a specific clause: use the support portal. Company details are on the contact page.