1. The Agreement
These Terms of Service (the “Terms”) are an agreement between Lucubra LLC, a Washington (USA) limited liability company operating the Pharen platform (“Lucubra,” “we,” “us”), and the organization that accepts them (“Customer,” “you”). They govern access to and use of the Service.
You accept these Terms on the earliest of:
- indicating acceptance where the Service or an onboarding flow offers it;
- executing — or confirming by email — an order form or onboarding exchange that references these Terms (an “Order”); or
- accessing or using the Service after credentials are provisioned at your request.
The person accepting represents that they are at least 18 years old and authorized to bind the Customer. The Service is offered for business use; there are no consumer accounts. If you do not agree to these Terms, do not use the Service.
The agreement set. The following are part of the agreement between us, and in a conflict they apply in this order: (1) an Order, for the matters it addresses; (2) the Data Processing Agreement (the “DPA”), for the processing of personal data; (3) these Terms; (4) the Acceptable Use Policy (the “AUP”); (5) the Documentation. Each document is identified by version; the versions you accept are recorded at onboarding.
2. Definitions
“Agreement” means these Terms together with the AUP, the DPA, the Documentation, and any Order.
“App” means a Customer application or other software that integrates with the Service under Customer’s account.
“Customer Data” means data submitted to the Service by or for Customer, including data an App’s SDK integration sends (events, diagnostics, attributes), build artifacts Customer uploads, and content End Users submit through an App.
“Documentation” means the usage documentation for the Service that we make available, as updated.
“Early Access” means the current, pre-general-availability phase of the Service described in Section 3.
“End User” means an individual who uses an App — including a tester Customer distributes builds to.
“SDKs” means the Pharen software development kits and related integration code we make available for inclusion in Apps.
“Service” means the Pharen platform’s hosted services made available to Customer — ingestion, processing, storage, build distribution and link infrastructure, and the administrative console we host for Customer’s team — together with the Documentation. The SDKs are licensed separately (Section 8) and are not part of the hosted Service.
“Usage Data” means operational data about use of the Service itself — volumes, feature usage, performance, and diagnostics — that does not include the contents of Customer Data.
3. Early Access
The Service is in Early Access: it is operated for you — onboarding is done with you by a person, and capabilities are enabled for your account deliberately rather than self-served. During Early Access:
- the Service’s capabilities may change, and we may add, alter, or discontinue features. We will give you reasonable advance notice of any change that materially reduces a capability you actively use;
- we do not offer an availability commitment or service-level agreement, and no uptime representation is made anywhere. We communicate incidents and material operational changes to the contact on your account;
- support is provided on a reasonable-efforts basis by email (hello@pharen.ai).
Features identified as beta, preview, or experimental are provided for evaluation, may be changed or withdrawn at any time, and are excluded from any commitments an Order may add.
4. Accounts, credentials & keys
Access to the administrative console and control-plane APIs is authenticated through a third-party developer identity provider; what we receive is described in the Privacy Notice. You are responsible for the people you authorize, for what they do in your account, and for keeping account information accurate.
Credentials come in two kinds, and they carry different duties:
- Control-plane credentials (sessions and tokens that can administer your account) are secrets. Safeguard them, scope them to the people and systems that need them, and tell us promptly at hello@pharen.ai if one may be compromised.
- Ingest keys are designed to be embedded in your Apps: they are write-scoped, and the Service derives your tenant and environment from the key server-side — an ingest key cannot read data. Still, use each environment’s key only for that environment, do not publish keys outside your Apps, and ask us to rotate a key you believe is being abused.
We may rotate or revoke a credential where reasonably necessary to address compromise or abuse, with notice where practicable.
5. Customer Data
You own Customer Data. You grant Lucubra a non-exclusive, worldwide license to host, copy, transmit, process, and display Customer Data solely as necessary to provide, secure, and support the Service in accordance with your instructions — your configuration of the Service, the Agreement, and the DPA — and as required by law. We acquire no other rights in Customer Data.
For personal data within Customer Data, you are the controller and Lucubra is your processor; the Data Processing Agreement governs. You represent that you have the rights, notices, and consents needed to submit Customer Data to the Service.
Store Data. The Service can maintain publicly available app-store listing information — ratings summaries, rankings, listing metadata — collected once from the store’s public surfaces and made available to customers that register interest in a listing, including a listing you don’t own. That shared listing data is third-party public information, not Customer Data, contains no personal data, and is provided as-is. Separately, where you connect your own store credential, data obtained with it — your app’s customer reviews, sales, and performance data — is retrieved at your instruction, kept to your account, and is Customer Data under this Agreement and the DPA.
6. Our data commitments
These commitments apply to all Customer Data, always:
- We never sell or rent Customer Data or End-User personal data, and we do not use it for advertising.
- We do not use Customer Data — or Usage Data derived from your use — to train machine-learning or AI models — ours or anyone else’s. If we ever make AI-assisted analysis available to you, it runs under the DPA’s conditions (pseudonymized, minimized inputs; providers bound to no-training and zero-retention terms) and this commitment still holds.
- Direct identifiers stay off the event stream. Identity traits route to a restricted attribute store, separate from events, and the Service rejects events that carry fields it classifies as identifying — enforced server-side, where it cannot be skipped. We commit to maintaining that enforcement.
- Deletion propagates. Deletion instructions are honored across live stores and backups within the windows the DPA states.
We use Usage Data to operate, secure, improve, and plan the Service (and to bill, if fees apply). We do not disclose Usage Data in any form that identifies you, your Apps, or your End Users — outside the Agreement’s own confidentiality terms, Usage Data leaves our hands only aggregated or de-identified.
7. Your responsibilities
- Use the Service in compliance with applicable law and the AUP — including the AUP’s rules about data that must never be sent to the event stream.
- End-User notices and consents are yours. The platform provides consent mechanics — purposes stamped on events, enforcement at the point of collection — but your configuration is the policy: you decide what to collect, under which purposes, with which disclosures to your End Users. Whether your use of the Service complies with the GDPR, the CCPA, or any other regime is a legal determination that stays with you and your counsel.
- You are responsible for your Apps, their content, and your relationships with End Users — including compliance with the policies of the app platforms you distribute through.
- You will not use the Service in violation of export-control or sanctions law (Section 20).
8. Software & licenses
SDKs and other software we make available are licensed, not sold, under the license that accompanies them — the Pharen SDK license for the SDKs, the Pharen CLI License for the command-line tool (source-available, packaged with it), and permissive open-source licenses (stated in each component) for integration glue such as release-lane tooling. Those licenses govern that code; these Terms govern the hosted Service. We and our licensors retain all rights not expressly granted; you retain all rights in your Apps.
9. Build distribution & install links
Where you use the Service to distribute App builds:
- you may upload and distribute only builds you have the right to distribute, signed under credentials you are entitled to use, and you are responsible for complying with the distribution policies of the relevant platform vendor;
- install links are served at unguessable, unlisted addresses but are not access-controlled: anyone you give a link to can use it where the platform permits, so distribute links with the same care as the builds themselves. The artifact behind an install page is fetched through short-lived signed download links minted per visit, so the page’s address is the only durable thing to share;
- you must not distribute malware, spyware, or deceptive software through the Service (see the AUP). We may scan artifacts, and may suspend or remove an artifact or link where reasonably necessary to address malware, an AUP violation, or a legal requirement — with notice where practicable.
10. Communications & automated actions
If you use the Service to deliver communications to End-User devices, you control their content, audience, and timing, and you are responsible for complying with applicable messaging and electronic-communications laws and platform policies, including honoring End-User opt-outs. Any capability that executes automated, rule-driven actions is disabled or simulation-only by default and acts only after you explicitly enable it; what you enable and configure is your responsibility.
11. Fees
During Early Access the Service is provided without fees unless an Order states otherwise. If we introduce fees for your use, they will apply through an Order you accept or on at least 30 days’ advance notice under Section 19 — never retroactively. Fees are exclusive of taxes; you are responsible for taxes on your use (excluding taxes on our income). Payment terms, if any, are stated in the Order; unless the Agreement or an Order says otherwise, fees are non-refundable (the pro-rata refunds Sections 16, 18, and 19 provide are the “otherwise”).
Where paid plans exist, the mechanics are these: fees are billed through our payment processor or by invoice, as the Order says; subscription and renewal terms are stated in the Order; amounts not disputed in good faith that remain unpaid ten days after written notice may lead to suspension of the Service until paid (Section 18’s scoped-and-loud rules apply), and late amounts may accrue interest at the lesser of 1.5% per month and the maximum lawful rate. We never suspend over an amount you are disputing in good faith.
12. Confidentiality
Each party will use the other’s Confidential Information only to perform under the Agreement, will protect it with at least the care it uses for its own similar information (and no less than reasonable care), and will not disclose it except to personnel and advisers bound by comparable obligations. “Confidential Information” means non-public information disclosed under the Agreement that is marked confidential or would reasonably be understood to be confidential — including Customer Data (yours) and non-public Service information (ours). It excludes information that is or becomes public through no fault of the recipient, was known without restriction before disclosure, is independently developed, or is rightfully received from a third party.
A party may disclose Confidential Information where legally compelled, with prior notice to the other party where lawful and reasonable cooperation on protective measures. These obligations survive for three years after the Agreement ends — except that obligations for trade secrets survive as long as the information remains a trade secret, and obligations with respect to Customer Data survive for as long as we retain any of it.
13. Feedback
If you give us suggestions, ideas, or other feedback about the Service, we may use it without restriction or obligation to you, and you assign no Customer Data by doing so. We will not name you as its source without your consent (Section 14).
14. Publicity & trademarks
Customer reference. You grant us the right to identify Customer as a customer — name and logo, in customer lists and marketing materials — subject to any brand guidelines you give us, and never in a way that suggests endorsement beyond the fact of being a customer. You can revoke this at any time by written notice (email suffices): we stop new uses immediately and remove existing uses from materials we control within 30 days. Anything more than name and logo — case studies, quotes, press releases — happens only with your prior written consent.
One carve-out: truthful, nominative references are always permitted — you may say your App “works with Pharen” or is “built with Pharen,” provided the reference does not alter our marks, display them more prominently than your own, or suggest endorsement or affiliation. “Pharen” and the beam mark are trademarks of Lucubra LLC; all use inures to our benefit.
15. Warranties & disclaimers
Each party warrants that it is validly existing and has the authority to enter into the Agreement.
TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, THE SERVICE, THE SDKS, AND THE DOCUMENTATION ARE PROVIDED DURING EARLY ACCESS “AS IS” AND “AS AVAILABLE,” AND WE DISCLAIM ALL OTHER WARRANTIES, EXPRESS OR IMPLIED, INCLUDING MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, NON-INFRINGEMENT, AND ANY WARRANTY ARISING FROM COURSE OF DEALING OR USAGE OF TRADE. WE DO NOT WARRANT THAT THE SERVICE WILL BE UNINTERRUPTED, ERROR-FREE, OR SECURE FROM ALL THREATS.
High-risk use. The Service and SDKs are not designed or licensed for use in circumstances where their failure could lead to death, personal injury, or severe physical or environmental damage — such as life support, emergency dispatch, air traffic, nuclear facilities, or weapons systems — and you may not rely on them as a safety-critical component of any such system.
App platforms. Decisions of app platforms about your Apps — review outcomes, rejection, removal, policy enforcement — are theirs, not ours. Use of the Service or the SDKs does not assure any platform outcome, and we are not responsible for those decisions.
AI-assisted output. If we make AI-assisted analysis available to you, its output is probabilistic decision support, not a statement of fact; verify it before acting on it. Responsibility for decisions made using the Service remains yours.
16. Indemnification
By Customer. You will defend Lucubra against any third-party claim arising from your Apps, Customer Data, your relationships with End Users, your breach of Section 7 or the AUP, or your violation of law — except to the extent the claim arises from Lucubra’s breach of the Agreement (including the DPA), negligence, or willful misconduct — and you will indemnify Lucubra for the damages, costs, and reasonable attorneys’ fees finally awarded on (or agreed in settlement of) such a claim.
Infringement remedies (by Lucubra). If the Service, as provided by us and used as the Agreement permits, becomes — or in our reasonable opinion is likely to become — the subject of a third-party intellectual-property infringement or misappropriation claim, we will at our expense procure the right for you to keep using it, modify or replace it without material loss of capability, or — if neither is commercially reasonable — terminate the affected part, refund any prepaid unused fees for it, and let you terminate the Agreement on notice. During Early Access we offer these remedies in place of a defense-and-indemnification obligation; a backed indemnity is available on negotiated paper (Section 3). These remedies are your exclusive remedy for third-party infringement claims relating to the Service, and they do not cover claims arising from Customer Data, your Apps, combinations with items we did not supply, modifications we did not make, or use of a superseded version after we provided a non-infringing update.
The indemnified party must give prompt notice of the claim (late notice matters only to the extent it prejudices the defense), give the defending party sole control of defense and settlement (no settlement imposing obligations on the indemnified party beyond ceasing infringing use or paying indemnified amounts without its consent), and provide reasonable cooperation at the defending party’s expense.
17. Limitation of liability
TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW: (a) NEITHER PARTY WILL BE LIABLE FOR INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, EXEMPLARY, OR PUNITIVE DAMAGES, OR FOR LOST PROFITS, REVENUES, GOODWILL, OR DATA, EVEN IF ADVISED OF THEIR POSSIBILITY; AND (b) EACH PARTY’S TOTAL AGGREGATE LIABILITY ARISING OUT OF OR RELATED TO THE AGREEMENT WILL NOT EXCEED THE GREATER OF US $100 AND THE AMOUNTS PAID OR PAYABLE BY CUSTOMER FOR THE SERVICE IN THE 12 MONTHS BEFORE THE FIRST EVENT GIVING RISE TO LIABILITY — AND IN ANY EVENT WILL NOT EXCEED US $100,000.
These limits do not apply to Customer’s payment obligations or to Customer’s indemnification obligations under Section 16, and they do not limit either party’s liability for what cannot be limited under applicable law (such as fraud or willful misconduct). Multiple claims do not enlarge the cap. Each limitation applies even if a limited remedy fails of its essential purpose; the parties agree these allocations are a reasonable basis for a service offered on these economics. The Agreement does not shorten any statutory limitation period for bringing a claim.
18. Term, suspension & termination
The Agreement runs from your acceptance until terminated. Either party may terminate for convenience on 30 days’ written notice, or for cause if the other party materially breaches and does not cure within 30 days of written notice. We may terminate or suspend immediately where a breach of the AUP’s data or security rules, a legal requirement, or a genuine security risk leaves no room for a cure period, or if you become subject to insolvency proceedings.
Suspension is scoped and loud. Where suspension is necessary — to address a security risk, stop an AUP violation, comply with law, protect the Service and other customers, or collect amounts overdue as Section 11 provides — we suspend the narrowest slice practicable, notify you promptly, and restore service promptly once resolved. Suspended ingestion fails with explicit errors rather than silently discarding data.
After termination: your access ends, and for 30 days we will produce Customer Data to you in a machine-readable form on written request, within ten business days of the request (extendable once by ten business days, with notice, for an export of exceptional scope — the DPA states the mechanics) and with reasonable assistance — export is operator-assisted today; there is no self-service export endpoint. The window is yours: instruct deletion sooner under the DPA and it ends early. After that window, we delete Customer Data within 30 days across live systems, with backup copies aging out of the backup cycle within 35 days, as the DPA specifies — subject only to what law requires us to retain. Sections that by their nature survive (including 5 to the extent of retained copies, 6, 8, and 12–20) survive.
Continuity. If Lucubra permanently ceases to operate the Service, we will give you as much advance notice as circumstances permit — targeting 60 days — keep export available through the wind-down (extending the export window above to 60 days), and complete deletion under the DPA afterward. If we assign the Agreement to a successor (Section 20), you may terminate on notice within 30 days of ours, with the same export window.
19. Changes to the Service & these Terms
The Service evolves per Section 3. For these Terms, the AUP, and the DPA: we may update them, and each version carries a number and effective date, with history noted on its page. For a change that materially reduces your rights or expands your obligations, we will give at least 30 days’ advance notice — by email to your account contact, through the console, or by prominent notice on this site — before it takes effect for you. If you object, you may terminate effective immediately on notice given before the change’s effective date, notwithstanding Section 18’s notice period (with a pro-rata refund of any prepaid, unused fees); continuing to use the Service after the effective date is acceptance. Non-material changes take effect on posting. No change to the DPA will reduce the protections it affords Customer Personal Data during your term.
20. General
Governing law & venue. The Agreement is governed by the laws of the State of Washington, USA, excluding its conflicts rules and the U.N. Convention on Contracts for the International Sale of Goods. The state and federal courts located in King County, Washington have exclusive jurisdiction over disputes arising out of the Agreement, and each party consents to their jurisdiction and venue. This paragraph does not apply to disputes governed by the Standard Contractual Clauses incorporated through the DPA, which are governed by their own Clauses 17 and 18.
JURY WAIVER. TO THE MAXIMUM EXTENT PERMITTED BY LAW, EACH PARTY WAIVES ITS RIGHT TO A JURY TRIAL IN ANY DISPUTE ARISING OUT OF THE AGREEMENT. EACH PARTY ACKNOWLEDGES THAT IT MAKES THIS WAIVER KNOWINGLY AND VOLUNTARILY, AND THAT IT HAS HAD THE OPPORTUNITY TO CONSULT COUNSEL ABOUT IT.
Export & sanctions. Each party will comply with applicable export-control and sanctions laws. You represent that you are not located in an embargoed jurisdiction and are not on any U.S. government list of prohibited or restricted parties, and you will not permit End Users to use the Service in violation of these laws.
U.S. Government use. The Service and SDKs are commercial computer software and documentation under FAR 12.212 and DFARS 227.7202; government users acquire only the rights these commercial terms grant.
Assignment. Neither party may assign the Agreement without the other’s prior written consent, except that either party may assign it in its entirety, on written notice, to an affiliate or to a successor in connection with a merger, acquisition, corporate reorganization, or sale of substantially all assets. The Agreement binds and benefits permitted successors and assigns.
Notices. Notices to Lucubra go to hello@pharen.ai or to the postal address below, and are effective on receipt. Notices to you go to your account’s contact email or through the console, and are deemed received one business day after sending. Each party will keep its notice contacts current.
Miscellaneous. The parties are independent contractors; the Agreement creates no partnership, agency, or third-party beneficiaries — except that data subjects retain the third-party beneficiary rights the Standard Contractual Clauses and the UK Addendum incorporated by the DPA confer on them, and any rights data-protection law gives them directly. Neither party is liable for delay or failure caused by events beyond its reasonable control, provided it resumes performance as soon as reasonably practicable — but force majeure does not excuse the notification, deletion, and confidentiality obligations of Section 12 and the DPA. The Agreement is the entire agreement about its subject and supersedes prior discussions. If a provision is unenforceable, it will be enforced to the maximum extent permissible and reformed to best reflect the parties’ intent, and the rest remains in effect. A waiver applies only if written, and only to the instance given. “Including” means “including without limitation.”
Version history
- 1.0 — September 2, 2026 — initial publication.
The Pharen platform is operated by Lucubra LLC, a Washington (USA) limited liability company, operating the Pharen platform. 522 W Riverside Ave, Ste N, Spokane, WA 99201-0581, USA · hello@pharen.ai