Terms of Service
The agreement between Waltz and the organizations that use it, covering accounts, plans and billing, your data, models, and liability.
Draft · Last updated
Draft for counsel's review. Not yet in effect.
1. Who these terms are between
These Terms of Service ("Terms") are an agreement between [Waltz legal entity], [registered address] ("Waltz", "we", "us") and the organization that creates an account or signs an order form for the Service ("Customer", "you").
If you accept these Terms for an organization, you confirm that you may bind it. If you can't, don't use the Service.
An order form signed by both parties, or a plan you choose in the console, forms part of these Terms. If an order form conflicts with these Terms, the order form wins for that order. The Data Processing Addendum and the Acceptable Use Policy are part of these Terms.
2. Definitions
- Service: Waltz's hosted platform at waltz.run and api.waltz.run, the web console, the Brief viewer, the analysis runner, the Waltz CLI, the Waltz MCP server, the APIs and the related documentation.
- Org: a Customer's workspace in the Service. Data never crosses between orgs, except as anonymized aggregates under section 7.5.
- Member: a person you invite to your org, in the role of owner, admin, member or viewer.
- Recipient: a person you subscribe to receive Briefs. A recipient need not be a member.
- Customer Data: data that the Service receives from your connected systems, from your members and from your uploads, and what the Service derives from it for your org: facts, system snapshots, Briefs, annotations, edits, decisions, memory, your org chart and recipient lists.
- Brief: a short document the Service composes for one audience in your org (for example an Engineering Manager, a VP of Engineering, a CTO or CEO, or a Product Manager), with the evidence it cites.
- Output: Briefs and any other content the Service generates for your org, including text written with a language model.
- Integration: a third-party system you connect to the Service, such as GitHub, GitLab, Jira, Linear, Slack, or an AI agent vendor.
- Seat: an active human contributor, as defined in section 5.2.
3. Accounts, orgs and roles
3.1 Sign-in. Members sign in with a single-use link sent to their email address. [Enterprise: single sign-on through SAML or OIDC, when available.] Keep access to your email account secure. You are responsible for what happens under your members' accounts.
3.2 Roles. Owners and admins manage the org: integrations, members, recipients, settings and billing. Members read and review Briefs and may create CLI and MCP tokens for themselves. Viewers read.
3.3 Tokens. CLI tokens can only upload agent session facts. MCP tokens can only read the org's Briefs and facts. Each token acts as the member who made it and stops working when it is revoked, or when that member leaves the org, becomes a viewer or is suspended.
3.4 Accurate information. Give us accurate account and billing information, and keep it current.
4. The Service
4.1 What Waltz does. Waltz is Engineering Intelligence software. It reads the systems you connect, derives facts about how your software is built and how it changes, and delivers Briefs to the people you choose. Waltz is software, not a professional adviser. It does not give legal, financial, security-certification or employment advice, and its Output is not a substitute for your own judgment.
4.2 Facts and insights. Briefs are built from facts the Service derives by rule. Each insight cites the facts it rests on. Recommendations are off by default. If an admin turns them on, each recommendation is marked "Generated by AI; verify before acting."
4.3 Where analysis runs. By default, your code is analyzed in a short-lived, isolated runner that Waltz hosts. The runner clones the repository, derives facts, uploads them and deletes the clone. Source code is not stored by the Service. Short code excerpts (40 lines or fewer) may be kept when a Brief cites them. [Enterprise: a customer-hosted runner, when available, analyzes code in your own infrastructure and sends only facts and the excerpts you allow, down to none.] Developers may also run the Waltz CLI on their own machines.
4.4 Changes to the Service. We improve the Service over time and may add, change or remove features. We won't materially reduce the core functionality of a paid plan during its current term. Section 16 covers beta features.
4.5 Support. We provide support by email at [support@waltz.run]. [Enterprise support terms and any service level are set in the order form.]
5. Plans, seats and billing
5.1 Plans. The Service is offered on Free, Paid and Enterprise plans. The current features and limits of each plan are on [waltz.run/pricing]. A plan's limits apply when you add something (a repository, an integration, a Brief type or a feature). A downgrade never deletes or hides what your org already has; it only stops new additions the plan no longer includes.
5.2 Seats. A seat is a human who contributed to your org's analyzed work in the last 90 days: an author of a commit or pull request on an analyzed repository, or a person who delegated an agent session, as reported by an agent vendor or the Waltz CLI. Bots and agents never count. A person with several linked identities counts once. People who only read Briefs are not seats. The console shows the current count, who is counted and why.
5.3 Monthly plans. Paid monthly plans include [10] seats. Each month, the subscription's quantity becomes that month's peak seat count, and the next invoice bills it. Growth is billed one invoice in arrears, and a quieter month lowers the bill.
5.4 Annual plans. A Paid annual plan has no committed minimum. It starts billed on the seats active at checkout, at the annual rate. At the end of each of the first three quarters, the quantity rises to the larger of the current quantity and that quarter's peak, and we invoice the increase, prorated for the rest of the term. The quantity never decreases during the term. A renewal starts from the seats active at renewal. Enterprise commitments are set in the order form.
5.5 Payment. Paid plans are billed in advance through Stripe, our payment processor. Card details go to Stripe and never reach Waltz. Fees are in [USD], exclude taxes, and are due [on the invoice date / within 30 days of invoice for invoiced customers]. You are responsible for taxes other than taxes on our income.
5.6 Late payment. If a payment fails, your plan stays in place while Stripe retries. If the subscription becomes unpaid or is canceled, your org moves to the Free plan. [Interest on overdue invoiced amounts: counsel to decide.]
5.7 Price changes. We may change prices with at least [30] days' notice. A change applies from your next renewal, or for monthly plans from the next billing period after the notice period.
5.8 Refunds. Fees are non-refundable except where these Terms or the law say otherwise. [Counsel to decide whether a pro-rata refund applies on termination for Waltz's breach; see section 18.4.]
6. Free plan
6.1 The Free plan is for evaluation. It has limits, currently: GitHub only, up to [3] repositories and [1] system, and Baseline and Engineering Manager Briefs for [28] days from the org's creation. Free orgs use Waltz-hosted models with a hard spending cap.
6.2 We provide the Free plan as is, without any service commitment, and may change or end it with notice. Section 20.3 limits our liability for the Free plan.
7. Customer Data
7.1 You own it. As between you and Waltz, you own Customer Data and Output. These Terms give Waltz no rights in Customer Data except those in this section.
7.2 Licence to operate. You give Waltz a worldwide, non-exclusive licence, for the term of the agreement, to host, copy, process, transmit and display Customer Data only to provide, secure and support the Service for you, to prevent abuse, and as the law requires.
7.3 What we read and keep. The Service reads only what the scopes you grant allow, and keeps only derived facts and what Briefs cite. In particular:
- Source code is read during analysis and then discarded. It is not stored, except short excerpts that a Brief cites.
- Pull request and ticket text is kept only where a fact or a Brief cites it.
- Agent vendors: counts, tokens, cost, session ids, commit links and model names. Never prompts, responses or tool inputs and outputs.
- Chat: only Waltz's own messages and the reactions on them. Never any other message.
- Security tools: rule, severity, location, state and dates. Never secret values or code snippets.
The Privacy Policy lists what each kind of integration gives Waltz and what it never keeps.
7.4 People in your data. Customer Data names people who work for you. Facts record them only as hashed source identities. You decide whether Briefs name individuals, per Brief type. By default, Briefs for VPs and above are team-level. The Service does not model how skilled any individual is, does not rank people, and does not record who opened which Brief.
7.5 Isolation and aggregates. One org's data never appears in, or is used to generate, another org's Brief. Waltz may use aggregate, de-identified statistics about how the Service is used across orgs (for example, how often a kind of finding is dismissed) to improve default ranking, templates and the Service. These statistics contain no content of any org, no facts, text, names or memory, and identify neither you nor any person.
7.6 Pooled benchmarks. If an admin turns on benchmark contribution, your org contributes monthly aggregate metrics (for example, median pull request cycle time) to pooled benchmarks. Pooled figures are published only for cohorts of at least 10 orgs and 100 engineers, where no single org contributes more than 30%, and with noise added. Briefs never show another org's values. Turning contribution off deletes your contributions at once. [Contribution is currently off unless an admin turns it on. If Paid and Enterprise later default to on, as planned, this section must say so before it takes effect.]
7.7 Your responsibilities. You are responsible for Customer Data and for having the rights and notices needed to connect your systems and to process your people's data through the Service, including any notice to or consultation with employees or their representatives that applies to you.
8. Models and Output
8.1 Hosted models. Unless you bring your own, Waltz uses a third-party model provider (currently Anthropic) to write the text of Briefs from template text and facts. What may be sent to a model: facts; pull request and commit titles and messages; ticket text; document excerpts; and short code excerpts of 40 lines or fewer. [An org can restrict these classes, for example "no code excerpts to models", when this control is available.] Model calls are recorded without their content, and model responses are cached per org and never shared across orgs.
8.2 Bring your own provider. On Enterprise, you may connect your own model provider and key. Your use of that provider is under your agreement with it, and it is not a Waltz subprocessor.
8.3 No training on your data. Waltz does not use Customer Data or Output to train or fine-tune any model, and does not use one org's text to prompt or tune a model for another org. Our agreements with hosted model providers [prohibit them from training on data we send; counsel to confirm against the provider's current commercial terms and retention settings].
8.4 Facts, not prose. Models never write facts. A model may only phrase text and propose layouts that reference facts the Service already derived. The Service validates model text against those facts and falls back to template text when it doesn't pass.
8.5 Accuracy. Output is generated by software and may be incomplete or wrong. Briefs cite their evidence so you can check them. You are responsible for decisions you make using Output. Don't use Output as the sole basis for decisions about an individual's employment.
9. Integrations and third-party services
9.1 You choose which Integrations to connect, and you can disconnect them at any time. Connecting an Integration authorizes Waltz to access it with the scopes shown when you connect. The Service asks for read scopes only, except where an Integration delivers Briefs (for example, posting to Slack) or where you separately grant write-back (for example, a check run linking a Brief on a pull request). Write-back is always opt-in.
9.2 Integrations are provided by third parties under their own terms. They are not Waltz subprocessors: you direct the data flow between you and them. Waltz is not responsible for their availability, their changes, or their handling of your data.
9.3 Integration credentials are stored encrypted and are destroyed when you disconnect the Integration.
9.4 The Service enriches facts with public data about open-source dependencies (for example, end-of-life dates and published vulnerabilities). To do so it sends package names and versions to public data services such as endoflife.date, OSV.dev and deps.dev. [Counsel to confirm the disclosure; an org setting to turn public data off is not yet exposed to customers.]
10. Acceptable use
You will use the Service in line with the Acceptable Use Policy and the law. You won't resell the Service, use it to build a competing product, or try to access another org's data.
11. Confidentiality
11.1 Confidential information is non-public information one party discloses to the other that is marked confidential or that a reasonable person would understand to be confidential. Customer Data is your confidential information. The non-public parts of the Service, its pricing under an order form, and its security documentation are ours.
11.2 The receiving party will use the other's confidential information only to perform under these Terms, protect it with at least reasonable care, and share it only with its employees, contractors and subprocessors who need it and are bound by similar duties.
11.3 This section doesn't cover information that is public through no fault of the receiver, that the receiver already had or developed independently, or that it received lawfully from a third party. A party may disclose confidential information when the law requires, after giving notice where it lawfully can.
12. Security
Waltz maintains the security measures described in the Data Processing Addendum, Annex 2, including encryption in transit and at rest, encrypted integration credentials, isolated analysis runners, an audit log of admin actions, and least-privilege integration scopes. We may update these measures if we don't lower the overall level of protection. Report vulnerabilities to [security@waltz.run].
13. Data protection
Where Waltz processes personal data on your behalf, the Data Processing Addendum applies and forms part of these Terms. The Privacy Policy explains how Waltz handles personal data for which it is a controller, such as account and billing contacts and visitors to waltz.run.
14. Intellectual property
14.1 Waltz owns the Service, including the engine, the catalog of Brief components, templates, and everything Waltz develops, and all related intellectual property rights. These Terms grant you no rights in the Service except the right to use it under these Terms during the subscription.
14.2 You may not copy, modify or reverse engineer the Service, or access it to build a competing product, except where the law allows this despite a contractual restriction.
14.3 Co-branding. If you upload your logo for co-branded Briefs, you give Waltz a licence to display it in your org's Briefs, emails and console for the term.
15. Feedback
If you give us feedback or suggestions, we may use them without obligation to you. This doesn't give us any right to your Customer Data or confidential information.
16. Beta features
We may offer features marked alpha, beta, preview or early access. They are optional, may change or end at any time, may have bugs, and are provided as is, without any service commitment or warranty. [Counsel to decide whether beta features count toward liability caps or are excluded from indemnities.]
17. Publicity
We won't use your name or logo to identify you as a customer without your [prior written consent / consent, which you can withdraw at any time]. [Design partners: case-study rights as agreed in the design-partner agreement.]
18. Term, suspension and termination
18.1 Term. These Terms start when you accept them and continue until every subscription ends. Subscriptions renew for the same period unless either party cancels before renewal. You can cancel through the console's billing settings or Stripe's billing portal.
18.2 Suspension. We may suspend access to the Service, in whole or in part, if your use poses a security risk to the Service or others, breaches the Acceptable Use Policy, or would expose us to legal liability, or if an invoice is more than [30] days overdue. We'll give notice in advance where we reasonably can, limit the suspension to what is needed, and restore access when the cause is fixed.
18.3 Termination for breach. Either party may terminate these Terms if the other materially breaches them and doesn't cure the breach within [30] days of notice.
18.4 Effect of termination. When the agreement ends, your access ends and you pay fees due up to the end date. [If you terminate for our uncured breach, we refund prepaid fees for the remaining term.]
18.5 Export and deletion. For [30] days after termination, an admin may export Customer Data [through the API, the MCP server, or on request in a standard format]. After that we delete Customer Data from the Service, including stored facts, Briefs and engine caches, within [30] further days, and from backups as they expire (currently within [7] days for database backups and [30] days for prior object versions). A record that the org was deleted stays in the audit log. [Counsel and product to decide the export format and window; see README.]
18.6 Sections that by their nature should survive termination survive it, including sections 7.1, 11, 14, 15, 18.4–18.6 and 19–23.
19. Warranties and disclaimers
19.1 Each party warrants that it has the authority to enter into these Terms. Waltz warrants that, during a paid subscription, the Service will perform materially as described in its documentation. If it doesn't, your remedy is for us to fix it, or, if we can't within a reasonable time, to terminate the affected subscription and receive a refund of prepaid fees for the remaining term.
19.2 Except as stated in these Terms, the Service and Output are provided as is. To the extent the law allows, Waltz disclaims all other warranties, express or implied, including merchantability, fitness for a particular purpose, non-infringement, and that the Service or Output will be error-free, uninterrupted or accurate.
20. Limitation of liability
20.1 Neither party is liable for indirect, incidental, special, consequential or punitive damages, or for lost profits, revenue or goodwill, even if advised of the possibility.
20.2 Each party's total liability arising out of these Terms is limited to the fees you paid or owe Waltz in the [12] months before the event giving rise to the claim.
20.3 For the Free plan, Waltz's total liability is limited to [USD 100].
20.4 These limits don't apply to [a party's indemnity obligations, your payment obligations, a party's breach of section 11 (Confidentiality), or liability that cannot be limited by law]. [Counsel to decide whether a higher cap applies to data-protection and security breaches, as many comparable B2B terms provide.]
21. Indemnities
21.1 By Waltz. Waltz will defend you against a third-party claim that the Service, as provided by Waltz, infringes that party's intellectual property rights, and pay the damages and costs finally awarded or agreed in settlement. This doesn't cover claims arising from Customer Data, Integrations, your modifications, combination with things we didn't provide, beta features, or the Free plan. If the Service is or may be found infringing, we may modify it, get you the right to keep using it, or end the affected subscription and refund prepaid fees for the remaining term.
21.2 By you. You will defend Waltz against a third-party claim arising from Customer Data, from your connection of systems you weren't authorized to connect, or from your breach of the Acceptable Use Policy, and pay the damages and costs finally awarded or agreed in settlement.
21.3 Process. The indemnified party must give prompt notice, let the indemnifying party control the defence and settlement (no settlement may admit fault for the indemnified party without its consent), and give reasonable help at the indemnifying party's cost.
22. Changes to these Terms
We may update these Terms. We'll post the new version at this address with its date and, for material changes, notify admins by email at least [30] days before they take effect. Changes take effect for paid subscriptions at the next renewal, unless they are required by law. If you don't agree, you can cancel before the change applies to you.
23. Governing law and general terms
23.1 Governing law and venue. These Terms are governed by the laws of [jurisdiction], without regard to conflict-of-laws rules. The courts of [venue] have exclusive jurisdiction. [Counsel to decide, including any arbitration clause.]
23.2 Notices. Notices to Waltz go to [legal@waltz.run] and [postal address]. Notices to you go to the owner's email address on the account.
23.3 Assignment. Neither party may assign these Terms without the other's consent, except to a successor in a merger, acquisition or sale of substantially all of its assets, with notice.
23.4 Force majeure. Neither party is liable for a delay or failure caused by events beyond its reasonable control. This doesn't excuse payment obligations.
23.5 Export and sanctions. You will comply with export control and sanctions laws in your use of the Service.
23.6 Independent parties. The parties are independent contractors. There are no third-party beneficiaries.
23.7 Entire agreement. These Terms, with the documents they incorporate and any order form, are the entire agreement and replace prior agreements on the same subject. If a provision is unenforceable, the rest stays in force. A failure to enforce a provision is not a waiver.