Legal

Terms of use

The rules for using Skillhook Cloud: accounts and organisations, acceptable use, what control mode means for your machines, whose data it is, plans and billing, and the limits of our liability.

Last updated:

1. The agreement

These terms are a contract between Meter App Inc. (“Meter”, “we”, “us”) and you for Skillhook Cloud, the service at https://skillhook.dev: the website, the dashboard, the REST API, the hosted MCP server, the hosted webhook URLs and the link paired machines hold to us (together, the “service”). Our privacy policy is part of them.

You accept these terms by using the service. An organisation’s owner accepts them for the organisation and, where the service is used for a company, confirms they may bind it; “you” then means the organisation and the company too, and its members use the service under the same terms. If you do not agree, do not use the service.

2. The service

Skillhook Cloud is the hosted control plane for skillhook machines. A machine you pair with skillhook cloud connect holds an outbound connection to us and reports its webhooks, jobs, questions for a person, health and statistics. The dashboard, the API, the MCP server and the CLI show them for every machine of an organisation, let you answer agents, replay deliveries, run and test skills and receive alerts, and, in control mode, change what runs on a machine. Hosted webhook URLs accept deliveries for a machine that is asleep and hold them, sealed, until it collects them.

skillhook itself, the open-source server that turns a machine into a webhook endpoint for Agent Skills, is published under the MIT licence at github.com/MeterApp/skillhook. It runs without this service and is not part of these terms; its own licence governs it.

3. Accounts and organisations

  • You must be at least 16 years old and give us a working email address. One person, one account; an account is not shared.
  • An organisation’s owner is responsible for it: for its members and the roles they hold, for the API keys its admins create, for the machines it pairs and for everything done with them. Choose roles with care: members can run skills, answer agents and replay webhooks; admins can also change configuration, secrets, skill files and hosted URLs on machines in control mode.
  • API keys, machine tokens, pairing codes, hosted URLs and invitation links are secrets. Keep them on your servers or in your agents’ environment, never in client-side code or public repositories. A key is shown once; if one may have leaked, revoke it under Settings, which ends what it could do from the next request. Keys never manage access: members, roles, keys, pairing and notification channels are changed by a signed-in person on the dashboard only.
  • Tell us promptly at support@skillhook.dev about any unauthorised use of your organisation.

4. Acceptable use

You agree not to, and not to let anyone using your organisation, its keys or its machines:

  • Break the law or infringe anyone’s rights, or put unlawful content into the service, whether through webhooks, skills, problem reports or invitations.
  • Abuse hosted webhook URLs: use them as a relay or as storage for traffic unrelated to the skill they belong to, flood them, or point at them senders you are not entitled to receive from.
  • Try to reach another organisation’s data or machines, or probe, scan or attack the service, its infrastructure or its providers, or interfere with other customers’ use of it. Good-faith security research reported to support@skillhook.dev is welcome.
  • Evade rate limits, plan limits or abuse controls, including by spreading one team’s use across organisations to stay within the Free plan, or by spoofing requests.
  • Resell the service, or offer it as your own, without a written agreement with us. Building products and workflows on it is what it is for.
  • Use invitations, email notifications or problem reports to send mail to people who did not ask for it.

We may throttle, suspend or terminate keys, machines, organisations and accounts that break this section.

5. Your machines and agents

  • Machines pull; we never open a connection to a machine. In observe mode a machine only reports. In control mode the service may queue commands (run and test skills, answer agents, replay, change configuration, write skill files, restart, update) that the machine runs on its next sync. Anyone who can act as a member or admin of its organisation, or who holds a fleet:run or fleet:admin key, can therefore run code on that machine. Control mode is shell access, and you choose it.
  • You choose the mode when you pair, and you narrow what the machine accepts with cloud.allow_commands and cloud.deny_commands on the machine; we cannot widen them, and we can never change its host, port, runners, environment passthrough, projects or cloud settings. A command an offline machine does not collect expires after 10 minutes; the dashboard shows each command’s status rather than assuming it ran.
  • What your skills and agents do on your machines, and with the webhooks they receive, is yours. The runners (Claude Code, Codex or a shell command), the skills you write, the tools you give them and what they produce are under your control and your responsibility, including anything they do to other systems.
  • Machines decide what they upload (cloud.upload_payloads, cloud.upload_artifacts) and redact headers and .env values before sending. We never hold webhook secrets: the machine verifies every delivery’s signature itself, including deliveries that pass through a hosted URL, which we keep sealed and for at most 72 hours.

6. Your data

Everything your organisation, its machines and its webhook senders put into the service (payloads and bodies, jobs and results, skill files, questions and answers, reports) is yours. You give us only the licence we need to operate the service: to store it, show it to your organisation, deliver it to your machines and to the notification targets your admins configure, and email you about it.

Payloads are data. We render them as escaped text, never send them to a model, never use them to train one and never attach them to an error report. You are responsible for having the right to send us what you send, including any personal data in webhooks, and for your senders’ and your agents’ compliance with the law. The privacy policy says what we keep and for how long; you can turn off keeping webhook bodies at any time.

7. Plans, fees and billing

The plans are Free, Pro, Business and Enterprise, as published on the pricing page, which forms part of these terms: Pro at $29 a month or $290 a year, Business at $99 a month or $990 a year, Enterprise under a written agreement. Prices are in US dollars.

  • Free costs nothing and has the limits the pricing page lists. Every organisation starts on it.
  • Paid plans (Pro and Business) are billed by Stripe monthly or yearly in advance and renew at the end of each period until you cancel. Stripe’s terms apply to the payment itself; we never see your card number. You can cancel at any time; the cancellation takes effect at the end of the period you have paid for, and we do not refund the remainder except where the law requires it. If a renewal payment fails, Stripe retries it for a few days and the plan stays in force meanwhile; after that the organisation returns to the Free plan and its limits.
  • Enterprise is sold under a written agreement, with invoicing and limits as agreed; where that agreement and these terms differ, the agreement prevails.
  • Limits (machines, people, hosted webhook URLs, hosted deliveries a month, how long webhook bodies are kept, notification channels, API keys and API requests a minute per key) are enforced; the pricing page and the docs say what each one counts. Deliveries straight to a machine never count as hosted deliveries.
  • Price changes take effect at your next renewal after we have emailed the organisation’s owners at least 30 days in advance.
  • Taxes may be added where the law requires it.

Where a plan cannot yet be chosen in the dashboard, write to support@skillhook.dev and we set it up with you.

8. Availability and support

We make reasonable efforts to keep the service available and fast, and it reports its health at /api/health, but we do not promise uninterrupted operation and give no service-level agreement except under a written Enterprise agreement. We may change or remove features, and set rate limits and other limits to protect the service; where a change removes something you depend on, we try to announce it first.

Support is by email at support@skillhook.dev, and through the problem reports you can file from the dashboard, the API, the MCP server and a paired machine’s skillhook cloud report. We answer in the order received; an Enterprise agreement may name a contact on the Skillhook team.

9. Third-party services

The service works with things we do not provide:

  • Runners such as Claude Code and Codex run on your machines under your own subscriptions and their providers’ terms; their usage, cost and behaviour are between you and them. The cost and token figures we show are what the machine reports.
  • Webhook senders (GitHub, Sentry, Stripe, Zapier and the rest) and the targets of your alerts (Slack, your own endpoints, email) are governed by their own terms; we deliver to them and receive from them as your admins configure.
  • Sign-in through Google or GitHub is governed by their terms.

We are not responsible for third-party services, and a change on their side may change what the service can do.

10. Intellectual property

The service, the website, the documentation and everything we make available through them are ours or our licensors’ and stay so; these terms give you a right to use the service, nothing more, and you may not copy, modify or reverse-engineer it except as the law allows. skillhook is open source under the MIT licence, and your skills, projects and data are yours. If you send us feedback, suggestions or problem reports, we may use them without restriction or payment and without naming you. We name your organisation as a customer only with your written agreement.

11. Termination

You can stop at any time: disconnect your machines (skillhook keeps running on its own), revoke your keys, cancel a paid plan, which runs to the end of the period you have paid for, and ask us at support@skillhook.dev to delete your organisation and your account. We delete their data within 30 days of the request, except what we must keep for tax or accounting; records the privacy policy’s retention schedule has already removed stay removed.

We may suspend or terminate an organisation or an account that breaks these terms, with notice and a chance to put it right where that is possible, and at once where it is not (an attack, unlawful content, a legal order); and we may end the service with reasonable notice. On termination, machine tokens and keys stop working, hosted URLs stop accepting deliveries, and the data is deleted as above. The sections on your machines and agents, your data, intellectual property, disclaimers and liability, indemnity and governing law survive termination.

12. Disclaimers and limitation of liability

The service is provided “as is” and “as available”, without warranties of any kind, express or implied, including merchantability, fitness for a particular purpose and non-infringement, and without any promise that it will be uninterrupted or error-free, that a command will reach a machine, that an alert will arrive or that an agent will do what you expect. Some jurisdictions do not allow these exclusions, in which case they apply to the fullest extent the law permits.

To the fullest extent the law allows, neither Meter nor the people who work on the service are liable for indirect, incidental, special, consequential or punitive damages, or for lost profits, revenue, data or goodwill, arising out of or related to the service or these terms, however caused and under any theory of liability, even if told such damages were possible, including for what an agent does on your machines or to other systems. Our total liability for all claims arising out of or related to the service or these terms is limited to the fees you paid us for the service in the 12 months before the event that gave rise to the claim. Nothing here limits liability that cannot be limited by law.

13. Indemnity

You will defend and indemnify Meter and the people who work on the service against claims, damages and costs, including reasonable legal fees, arising from your use of the service, your data, your machines and what your agents do, your webhook senders, or your breach of these terms, including a claim by a member of your organisation or by someone whose machine you paired.

14. Changes to these terms

We may update these terms. When we do, we change the date at the top of this page and, for material changes, email the organisation’s owners at least 14 days before they take effect. Using the service after that date means you accept the new terms; if you do not, stop using the service and cancel any paid plan before then.

15. Governing law and venue

These terms are governed by the laws of the State of Delaware, United States, without regard to its conflict-of-law rules, and any dispute arising out of them or the service will be brought in the state or federal courts located in Delaware, whose jurisdiction you and we accept, unless the consumer-protection law where you live gives you the right to bring it elsewhere. Before filing anything, write to us; most problems are quicker to fix than to litigate.

16. Contact

Meter App Inc., meterapp.co, the company behind Skillhook Cloud: support@skillhook.dev. For how we handle personal data, see the privacy policy.