1. Parties, Scope & Acceptance
These Terms are between you and KazmaAI / Mubder Alfaris ("Kazma", "we"). They govern: (A) your use of kazma.ai (site, docs, product pages); and (B) your download/use of Kazma software. By accessing the site, cloning the repository, or running kazma serve, you agree. If you disagree, do not use them. If you act for an organization, you warrant authority to bind it.
Open-source license prevails for code: Kazma software is licensed under the MIT License (Copyright © 2026 Mubder Alfaris / KazmaAI). These Terms do not restrict MIT rights; where they conflict for the code itself, MIT controls. These Terms govern the website/services layer, support, trademarks, and acceptable use.
2. What Kazma Is (and Is Not)
- Self-hosted agent framework: LangGraph supervisor + swarm, bi-temporal memory, HITL gates, Web/TUI/CLI + Telegram/Discord/Slack gateways, X publisher, IDE, encrypted vault, document intelligence. You host and configure it.
- Not SaaS by default: we do not run your agents, see your mailbox, or store your prompts. You choose LLM providers, channels, and backups.
- AI is probabilistic: outputs may be wrong, incomplete, or hallucinated. You must verify consequential outputs with a qualified human (see the AI Disclaimer). HITL gates mitigate — they do not guarantee correctness or safety.
- Single-operator trusted-host by default: public multi-user SaaS requires extra hardening (identity provider, tenancy, Postgres, RBAC) described in the security documentation — not the default threat model.
3. Eligibility & Accounts
You must be 13+ (16+ in the EEA where applicable; higher where local law requires) and legally capable. No accounts are required for the static site. Self-host operators manage their own users/roles (viewer/operator/admin) and credentials. You are responsible for strong secrets (KAZMA_SECRET, KAZMA_VAULT_KEY), OAuth hygiene, and timely revocation.
4. Licenses Granted
- Software: MIT License — use, copy, modify, merge, publish, distribute, sublicense, sell, subject to including the copyright/permission notice.
- Website content/docs: limited, revocable, non-exclusive license to view for personal/evaluation use. No scraping at abusive rates; respect robots.txt and rate limits.
- Trademarks: the "Kazma" name and logo may be used nominatively (to refer to the project) without implying endorsement or affiliation; no use that suggests sponsorship by us. Do not remove copyright or license notices.
- Your content: you retain ownership of prompts, files, configurations, and outputs. You grant us no rights except where you voluntarily submit contributions (governed by the repository's contributing guide) or contact emails (to respond).
5. Acceptable Use (Binding Summary)
You must comply with the Acceptable Use Policy (AUP), incorporated by reference. Key points: no illegal use; no violation of EU AI Act prohibited practices (Art. 5: e.g. social scoring, manipulative subliminal techniques, exploitative targeting of vulnerabilities, non-consensual biometric identification, emotion inference at work/school); no spam or abuse of Gmail/Drive/Telegram/Discord/Slack/X APIs; no malware, intrusion, crypto-mining abuse, or bypassing HITL/safety gates in production; no infringing or deceptive synthetic media (disclose AI generation where Art. 50 / applicable law requires).
6. AI-Specific Duties (EU AI Act, Transparency Laws)
- Disclose AI interaction: if you deploy Kazma facing other people (chatbot, agent, voice), inform exposed persons that they interact with AI at/before first interaction, accessibly (Art. 50(1)/(3)).
- Label synthetic content: mark AI-generated audio/image/video/text as machine-generated, including machine-readable provenance where technically feasible (Art. 50(2); grace to 2 Dec 2026 for pre-2-Aug-2026 systems). Respect California SB-942 / Utah AI Policy Act disclosure duties for covered deployments.
- Keep human oversight: do not disable HITL in production for consequential actions (file writes, shell execution, outbound sends, vault access, payments, legal/medical/financial communications). YOLO mode only in isolated development sandboxes at your risk.
- Data & copyright hygiene: you warrant that you have rights to data you connect; respect robots.txt, paywalls, and licenses. GPAI-provider-style duties (training-data summary, copyright policy) sit with upstream model providers — your deployer duties include honoring opt-outs and not inducing infringement.
- AI literacy: ensure operators/users understand capabilities, limits, and risks (Art. 4).
7. Third-Party Services & APIs
Kazma integrates at your direction with Google (Gmail/Drive/Calendar), LLM providers, Telegram, Discord, Slack, X (official API v2 publisher), MCP servers, and others. Your use is governed by their terms (Google APIs ToS + Workspace policies, OpenAI/Anthropic/Google/Azure/AWS terms, platform developer agreements). We are not responsible for their availability, pricing, or policy changes. You must obtain necessary consents and stay within quotas and approved use cases (e.g. no Gmail spam, no Drive CDN abuse, no automated X engagement that violates the X developer agreement).
8. Google OAuth Responsibilities
- Request least-privilege scopes; explain to your end-users why each scope is needed.
- Complete your own OAuth verification / security assessment for your client ID; maintain accurate privacy disclosures and in-product notices.
- Revoke tokens you no longer need; handle user deletion requests; never use Restricted-scope data for ads or generalized-model training.
9. Security & Your Operator Duties
- Follow SECURITY.md: strong secrets,
KAZMA_PRODUCTION=1, secure LAN defaults, trusted-proxy configuration, vault key, backups with tested restores, prompt patching. - Report vulnerabilities privately to admin@kazma.ai / GitHub private advisories — do not exploit or disclose publicly first.
- You are responsible for hardening, access control, and breach response for your instance.
10. Fees; No Hosted SLA
The website and the MIT-licensed code are free. Third-party provider costs are yours. There is no uptime/SLA for the site or the self-hosted code; both are provided "as is / as available".
11. Intellectual Property & Feedback
We retain site/software IP except MIT-granted rights and your content. Voluntary feedback/ideas may be used without obligation unless separately agreed. Respect upstream licenses (LangGraph, FastAPI, Textual, and other dependencies listed in the repository).
12. Warranty Disclaimer
TO THE MAXIMUM EXTENT PERMITTED BY LAW, THE SITE AND SOFTWARE ARE PROVIDED "AS IS" WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, NON-INFRINGEMENT, ACCURACY, OR UNINTERRUPTED/ERROR-FREE OPERATION. YOU ASSUME ALL RISK FROM USE, INCLUDING AI OUTPUTS AND AUTOMATED ACTIONS.
13. Limitation of Liability
TO THE MAXIMUM EXTENT PERMITTED BY LAW, KAZMA AND CONTRIBUTORS ARE NOT LIABLE FOR INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES (INCLUDING LOSS OF PROFITS, DATA, OR GOODWILL), EVEN IF ADVISED. AGGREGATE LIABILITY FOR THE WEBSITE SHALL NOT EXCEED 100 USD. FOR MIT-LICENSED CODE, LIABILITY IS 0 USD TO THE EXTENT PERMITTED (PROVIDED "AS IS"). NOTHING HERE LIMITS LIABILITY THAT CANNOT BE LIMITED (E.G. DEATH/PERSONAL INJURY FROM NEGLIGENCE, FRAUD, OR MANDATORY CONSUMER RIGHTS UNDER EU/KUWAIT LAW).
14. Indemnity
You indemnify and defend us against claims arising from your misuse, AUP violation, unlawful data connection, undisclosed AI deployment, or breach of third-party terms, to the extent permitted by law.
15. Termination & Suspension
We may suspend site access for abuse or illegality. You may stop using the software and uninstall at any time; revoke OAuth tokens and delete local data/backups per your retention schedule. MIT rights, once granted, are irrevocable while you comply with the MIT License.
16. Governing Law & Disputes
Primary: the laws of Kuwait, courts of Kuwait. Consumer/EEA carve-out: mandatory protections of your habitual residence (e.g. EU consumer fora, GDPR remedies) remain. We ask that you attempt informal resolution first via contact@kazma.ai for 30 days before filing.
17. Changes
We may update these Terms; material changes get prominent notice (site banner + updated date). Continued use after the effective date constitutes acceptance. For self-hosted code, pinned versions/tags govern until you upgrade.
18. General
Entire agreement for site use (plus the AUP, Privacy Policy, AI Disclaimer, MIT License, and SECURITY.md). Severability; no waiver by delay; no assignment of site rights without consent; export/sanctions compliance (you warrant lawful use location); force majeure.
19. Contact
General: contact@kazma.ai · Privacy: privacy@kazma.ai · Security: admin@kazma.ai · Address: Kuwait (available upon written request).
Related: Privacy Policy · AI Disclaimer · Acceptable Use Policy · MIT License