Legal
Smol API Terms of Service
The agreement for using the Smol API: what you may do, what we do with your files, what it costs, and what happens when something goes wrong.
1. About these terms
1.1These terms are an agreement between you and [TO BE COMPLETED: legal entity name], which operates Smol. In these terms “Smol”, “we” and “us” mean that company, and “you” means the person or organisation that opens the account. If you accept for an organisation, you confirm that you have the authority to bind it.
1.2They cover the Smol API: the hosted compression and conversion service at api.smolmac.com, its dashboard and its documentation (together, the “service”). The Smol Mac app has its own terms.
1.3The service is for business and professional use. You must be at least 18 years old. It is not offered to consumers.
1.4These documents form part of the agreement: the Acceptable Use Policy, the Data Processing Addendum where it applies, the Uptime Agreement for the plans it covers once it is in force, and the prices on the pricing page. If they conflict, this order applies: a contract signed by both of us, then the Data Processing Addendum on data protection matters, then these terms, then the other documents.
1.5You accept these terms when you open an account, add a payment method, or use an API key, whichever comes first.
2. Accounts and API keys
2.1You sign in with your email address through the smolmac.com sign-in. Keep your account details accurate and your email address reachable: we send notices there.
2.2The dashboard issues test keys and live keys. A key is shown in full once, when it is created. We store only a SHA-256 hash of it, plus its first and last four characters so that you can recognise it, so we cannot show it again or recover it. If you lose a key, revoke it and create a new one.
2.3Keys are secrets for servers. Do not put a key in a web page, a mobile app or a public code repository. The API does not accept calls made directly from a browser.
2.4You are responsible for everything done with your keys, including the charges, until you revoke them. A revoked key can keep working for up to 30 seconds while the change spreads. Tell us promptly if you think a key has been exposed.
2.5Test keys work only on the sample files we publish. Requests made with them are free and are limited to a lower request rate.
3. Using the service
3.1While you keep to these terms, you may use the service and its documentation in your own products and for your own business. This right is not exclusive and you may not transfer it.
3.2Each plan has limits on request rate, requests and jobs running at once, file size, image dimensions, page count and media length. The limits are published in the documentation. A request beyond a limit is refused with an error and is not charged.
3.3You must follow the Acceptable Use Policy. You are responsible for how your own users and customers use the service through your product.
3.4Some features are switched on account by account (at launch, video processing and HEIC output). A feature we label as beta or preview is provided as it is, may change or be withdrawn without the notice in section 6, and is not covered by the Uptime Agreement.
3.5Keep your own copy of every file you send. Compression usually discards data on purpose, results are deleted on a timer, and the service is not a place to store or back up files.
4. Your content
4.1“Content” means the files you send, the files we return, the file names you give us and any metadata you attach to a job.
4.2Your content is yours. We claim no ownership of it and no rights in it beyond clause 4.3.
4.3You give us permission to receive your content, hold it temporarily, read it, transform it, return it to you or deliver it where you tell us, and delete it, only as far as needed to carry out your requests and to meet our legal duties. This permission extends to the sub-processor that hosts the service. It ends when the content is deleted. We do not use your content for advertising, to train models, or for any purpose of our own.
4.4How files are handled is set out on the security page and is part of what we promise. In short: a direct request (files up to 25 MB) is processed and returned without being written to our file storage. For a job, the input is stored until the job finishes, fails or is canceled, and the output is stored until it expires (1 hour by default; you can set between 60 seconds and 24 hours) or until you delete the job, whichever is sooner.
4.5The service has to read a file in the clear to compress or convert it. This is not end-to-end encryption, and we do not describe it as such.
4.6We do not look at, scan or review your content. How we respond when someone reports unlawful content is set out in the Acceptable Use Policy.
4.7You confirm that you have the rights and permissions needed to send your content to us and have it processed, including for any personal data in it.
4.8We keep records about requests, not their content: sizes, file kinds, timings, error codes, and key and account identifiers. The file name and metadata you supply for a job stay with the job’s record for 30 days after it finishes, so the job can be shown to you. The security page lists what is recorded.
5. Fees and payment
5.1Prices. Usage is metered and charged at the unit prices on the pricing page, in US dollars. The pricing page defines each unit (for example per image, per started 100 pages of a PDF, or per started minute of audio or video). The price in force when a request is made applies to it.
5.2What is not charged. A request that fails is not charged. A request where we cannot make the file smaller and return your original (“kept original”) is not charged. Requests made with test keys are not charged.
5.3Pay as you go. Pay as you go is the smallest monthly plan. You keep a card on file. We charge US$20 in advance for each billing month and add the same amount to your account as usage credit for that month, which expires at the end of it like any plan's included usage. Usage beyond that credit is charged to the card after the billing month has ended. If unbilled usage reaches a threshold during the billing month (currently US$25), we charge the card at that point instead of waiting for the month to end.
5.4Plans. A monthly plan is charged in advance and includes an amount of usage credit for that billing month, shown on the pricing page. Included usage that you do not use expires at the end of that billing month and is not carried over. Usage beyond the included amount is charged at the unit prices, after the billing month has ended. Enterprise terms are set by a separate contract.
5.5Changing or canceling a plan. If you move to a higher plan, we charge the difference for the rest of the billing month straight away. If you move to a lower plan, we credit the difference. If you cancel, the plan runs to the end of the period you have paid for, and usage up to then is still invoiced.
5.6Payment. Stripe processes payments for us. You authorise us to charge the card on file for fees as they fall due, including the charges in clause 5.3. Stripe holds your card details; we see only the card brand and its last four digits. If your bank asks you to confirm a charge, the payment is not complete until you do.
5.7Monthly spend cap. Every account has a monthly spend cap. It starts at a default for your plan and you can change it in the dashboard. Once the month’s usage reaches the cap, new requests are refused until the next calendar month (UTC) begins or you raise the cap. The cap is checked when a request starts, so requests already running finish and are charged, and the total can pass the cap by their cost. The cap is a safeguard, not a guarantee of a maximum bill.
5.8Taxes. Prices do not include taxes. Where we are required to collect sales tax, VAT or a similar tax, we add it to the invoice. Give us a valid tax ID where one applies to you. You are responsible for any other taxes on your purchase, apart from taxes on our income.
5.9Failed payments. If a charge fails, Stripe retries it over a period of [TO BE COMPLETED: retry period set in Stripe; planned at up to two weeks], and your account is marked past due. If the invoice is still unpaid when the retries end, live keys stop working and return a payment-required error until the invoice is paid. Test keys keep working. If a charge is disputed with the card issuer (a chargeback), we suspend the account while we review it.
5.10Refunds. Fees are not refundable, except where the law requires it, where we charged you in error, or where these terms say otherwise. If you think an invoice is wrong, tell us within 60 days of its date; we correct errors with a credit or a refund. If we close your account without cause or stop offering the service, we refund any plan fee for the period after the end date and any unused part of the credit in clause 5.3.
5.11Price changes. We give at least 30 days’ notice by email and on the pricing page before a price increase takes effect. It applies from your next billing period after the notice ends.
6. Changes to the service
6.1We may add features and improve the service at any time. We update the tools that do the compression, so the exact bytes of a result can differ from one release to the next.
6.2The API is versioned by date. Your account is pinned to a version, and a change that would break a working integration is released only under a new version date.
6.3We give at least 90 days’ notice, by email and in the changelog, before we retire an API version, remove a documented endpoint or feature, or lower the limits of a plan you are on.
6.4We may act on shorter notice where we must: to fix a security problem, to comply with the law, to stop abuse, or because a supplier withdraws something the service depends on. We then give as much notice as we reasonably can.
6.5If we decide to stop offering the service, we give at least 90 days’ notice and the refund in clause 5.10 applies.
7. Suspension
7.1We may suspend an account or a key, fully or in part, if:
- an invoice is still unpaid after the retries in clause 5.9, or a charge is disputed;
- you break the Acceptable Use Policy, or we reasonably believe you have;
- your use puts the security or stability of the service, or other customers, at risk; or
- the law or a public authority requires it.
7.2We keep a suspension as narrow and as short as the reason allows. We tell you by email beforehand where we reasonably can, and otherwise straight afterwards. We lift it promptly once the cause is fixed.
7.3Plan fees continue during a suspension caused by your breach.
8. Ending the agreement
8.1You may stop at any time. Cancel your plan in the dashboard and revoke your keys. Cancellation takes effect as set out in clause 5.5.
8.2We may end the agreement for any reason with at least 30 days’ notice by email.
8.3Either of us may end the agreement by written notice if the other materially breaks it and does not put things right within 30 days of being asked to. We may end it immediately for a serious breach of the Acceptable Use Policy, such as sending unlawful content, attacking the service or fraud.
8.4When the agreement ends, your keys stop working and you pay for usage up to the end date. Files still held for a job continue to be deleted on the timers in clause 4.4; there is nothing further for us to return. Account and billing records are kept as the law requires. Clauses that by their nature should outlast the agreement do so, including clauses 5, 9, 12, 13, 14 and 15.
9. Confidentiality
9.1Each of us may receive information from the other that is marked confidential or that a reasonable person would understand to be confidential. The receiving party must use it only for this agreement, protect it with reasonable care, and share it only with staff, advisers and suppliers who need it and are bound to keep it confidential.
9.2This does not apply to information that is public through no fault of the receiving party, that it already knew, that it developed on its own, or that it lawfully received from someone else without a duty of confidence.
9.3A party may disclose confidential information where the law requires it, and must tell the other first where the law allows.
9.4These duties last for 3 years after the agreement ends, and for trade secrets as long as they remain secret. Your content is governed by sections 4 and 10 rather than this section.
10. Data protection
10.1If your content contains personal data and data protection law (such as the GDPR or the UK GDPR) applies to it, the Data Processing Addendum applies automatically and forms part of this agreement. For that data you are the controller and we are your processor.
10.2For account data (such as your email address, billing details and usage records) we act as a controller. The API privacy notice explains how we use it.
10.3The companies that process data for us are listed on the sub-processors page.
10.4The service is not designed for data that needs a specific agreement or certification we do not offer, such as protected health information under the US HIPAA rules or payment card data under PCI DSS. Do not send such data unless we have agreed to it in writing.
11. Our property and your feedback
11.1We and our licensors own the service, the API, the documentation and the Smol name and logo. You receive only the rights these terms state. Client libraries we publish are licensed under the licence that comes with each one.
11.2If you send us suggestions, we may use them without restriction or payment. You do not have to send any.
11.3Do not use our name or logo in a way that suggests we endorse your product.
12. Warranties and disclaimers
12.1We will provide the service with reasonable care and skill.
12.2Apart from clause 12.1 and the Uptime Agreement where it applies, the service is provided “as is” and “as available”. As far as the law allows, we exclude all other warranties, whether express or implied, including implied warranties of merchantability, fitness for a particular purpose and non-infringement.
12.3In particular, we do not promise that the service will be uninterrupted or free of errors, that every file can be processed or made smaller, or that a result will look or sound the same as the original or suit your purpose.
12.4We do not yet hold a SOC 2 report or any similar certification, and the service has not yet had an external penetration test. The security page lists what we do not have. Nothing we say elsewhere should be read as claiming otherwise.
13. Limits on liability
13.1Nothing in this agreement limits liability that the law does not allow to be limited, such as liability for fraud.
13.2Neither of us is liable to the other for lost profits, revenue, business or goodwill, for loss of or damage to data, or for indirect, special or consequential loss, even if told that it was possible.
13.3Each party’s total liability under or in connection with this agreement is limited to the greater of (a) the fees you paid us in the 12 months before the event that gave rise to the claim, and (b) US$100.
13.4Clauses 13.2 and 13.3 do not limit your duty to pay fees or your duties under clause 14.1.
13.5Service credits under the Uptime Agreement are your only remedy for the service being unavailable.
13.6Some laws do not allow some of these limits. Where that is so, the limits apply only as far as your law allows.
14. Indemnities
14.1By you. You will defend us against any claim by someone else that arises from your content, from your breach of the Acceptable Use Policy, or from your own product or service, and you will pay the damages and costs finally awarded or agreed in settlement.
14.2By us. We will defend you against any claim by someone else that the Smol API software, used as these terms allow, infringes that person’s copyright, trademark or trade secret, and we will pay the damages and costs finally awarded or agreed in settlement, within the limit in clause 13.3. This does not cover claims that arise from your content, from combining the service with something we did not supply, from use that breaks these terms, from open-source components, or from patents, including patents on file formats and codecs. If such a claim is made, we may change the service so that it no longer infringes, or end the affected part and refund fees paid in advance for it. This clause states our whole liability for such claims.
14.3How it works. The party asking for protection must tell the other promptly, let it control the defence and settlement, and give reasonable help. The defending party may not settle in a way that admits fault or imposes duties on the other without its written consent.
15. Governing law and disputes
15.1This agreement is governed by the laws of the State of California, United States, without regard to its rules on conflicts of law.
15.2Any dispute will be heard in the courts located in San Francisco, California, and each of us accepts their jurisdiction.
15.3Before starting formal proceedings, write to us at [email protected] and give us 30 days to resolve the matter with you. This does not stop either of us from seeking urgent relief from a court.
15.4If a law that cannot be set aside by contract gives you the right to a different law or court, that law prevails.
16. Changes to these terms
16.1We may update these terms. The version and date at the top of this page show which text is current.
16.2For a change that reduces your rights or adds to your duties, we give at least 30 days’ notice by email before it takes effect. Other changes, such as clarifications or terms for a new feature, take effect when published.
16.3If you do not agree to a change, you may end the agreement before it takes effect, and we refund any plan fee for the period after the end date. Using the service after a change takes effect means you accept it.
17. General
17.1Whole agreement. These terms and the documents in clause 1.4 are the whole agreement between us about the service and replace anything said or written before.
17.2Transfer. You may not transfer this agreement without our written consent. We may transfer it to a company that takes over the service, and we will tell you if we do.
17.3Notices. We send notices to the email address on your account. Send notices to us at [email protected].
17.4Events outside our control. Neither of us is liable for a failure or delay caused by something outside its reasonable control. This does not excuse a duty to pay.
17.5Trade rules. You confirm that you are not subject to sanctions and will not use the service in breach of export control or sanctions laws.
17.6Other points. If a court finds part of this agreement unenforceable, the rest still applies. A delay in enforcing a right is not a waiver of it. Nobody other than you and us has rights under this agreement. We are independent parties; neither is the other’s agent or partner.
18. Contact
Smol is operated by [TO BE COMPLETED: legal entity name], based in San Francisco, California. Registered address: [TO BE COMPLETED: registered address].
Questions about these terms: [email protected].