VibeCodeStorage
Free pilot · Effective 6 October 2026

Terms of Service

These terms cover the VibeCodeStorage hosted pilot and website, operated by Halfpenny Technologies Limited ("we", "us"), a company registered in England and Wales with number 17287043. Our registered office is 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom. Contact: contact form.

1. Using the pilot

By creating a store or using the hosted service, you agree to these terms. You must be at least 18 and authorised to accept them for any organisation you represent. If you do not agree, do not create a store or use the API. See our Privacy Notice for information about personal data.

2. What the service provides

The pilot provides storage for small encrypted JSON records through an API, SDK, CLI and optional browser client component. Current per-store limits are 1,000 rows, 2,000,000 bytes of serialised encrypted data and 10,000 metered requests per calendar month. Encryption overhead counts towards capacity, and one SDK operation may make multiple requests. Burst limits and a total pilot capacity of 200 active stores also apply.

The pilot is free and billing is disabled. Indicative prices shown in older software or API metadata are proposals, not a purchase or subscription. We will not charge you without a separate agreement. The current software assigns a two-year free-until date and a 30-day read/export grace period; these dates are software limits, not a guarantee that the pilot will operate for that entire period.

New stores are provisional: make a successful record write within four hours of creation to activate them. Reads and failed writes do not extend this deadline. Unactivated stores are automatically removed after the deadline. A separate pool of 20 provisional stores and global creation budgets apply; creation does not reserve active capacity. The active-capacity check occurs on first write. Existing stores created before this policy was deployed retain their previous lifetime.

When you build and deploy an application using the API or client component, you operate that application and choose its audience, features and access rules. You are responsible for assessing the requirements that apply to your application and its users. Halfpenny Technologies Limited operates the hosted storage API and the demonstrations on this website, including the Connect notebook. Connect is account-free. The separate Auth preview provides passkey accounts and per-customer records when enabled. These descriptions do not determine statutory provider status or transfer responsibilities imposed by law. See the platform and application boundary.

3. Your data and credentials

You retain ownership of your data and permit us and our hosting providers to store, transmit and otherwise process it as necessary to provide, secure and operate the service. You must have the necessary rights to upload it.

The main SDK and Connect encrypt data before sending it to the API. You are responsible for protecting access tokens, encryption keys, recovery files and exports. We cannot recover a lost encryption key or reset anonymous store credentials. Anyone with your owner access token can access encrypted records, manage share links and delete the store; possession of the encryption key also allows decryption. Keep independent backups.

The optional browser component can create share links containing a separate access token and the store encryption key. New links default to view-only access for seven days; owners can choose edit access and an expiry of up to 30 days. Both scopes cover the whole store. Edit access permits changing and deleting records, but neither scope permits deleting the store or managing share links. Owners can revoke individual links to stop future API access. Revocation or expiry cannot erase copies or encryption keys already received. Earlier links containing owner credentials remain full-access and are not revoked by the share-link controls. Protect links as credentials and do not publish them unintentionally.

Authenticated storage preview

When enabled, Auth offers two modes selected at app registration. Customer-private mode encrypts each customer’s record names and content in their browser; account recovery does not recover their data key. App-managed mode lets the service decrypt authorised requests and encrypts values at rest using a service-held key. Authorised app operators can obtain temporary read-only support access to an individual account and issue a one-time passkey reset after verifying the customer. App-managed content is not end-to-end encrypted. The mode cannot be silently changed for existing records.

Preview limits are separate from anonymous stores: 50 apps globally, 3 per owner store, 100 accounts per app and 1,000 globally; 100 records and 1 MB encoded storage per account, and 100 MB aggregate authenticated-record storage. Sessions expire after one hour. App operators must protect management credentials and verify customers before issuing reset links. Reset emails and staff identity management are not provided in this release. Store deletion is blocked while apps are attached; app/account removal currently requires verified operator maintenance. See the Auth guide for recovery and availability.

4. Acceptable use

Do not use the pilot for unlawful material, infringement, malware, harassment, credential theft, attacks, unsolicited bulk activity or attempts to bypass quotas or access another user's store. Do not probe or overload the service without written permission. Report vulnerabilities privately using our contact form.

The pilot is for experimentation with non-sensitive data. Do not store sensitive personal information, payment-card data, health records, secrets belonging to third parties, or information whose loss could cause material harm. Do not use it for safety-critical systems or as the only copy of important data. No enterprise data-processing agreement or regulated-workload support is offered in this pilot.

5. Availability, suspension and closure

This is an early service without an uptime commitment or independently audited security assurance. Interruptions, defects and data loss are possible. We may limit or suspend access to protect the service, respond to abuse or comply with law, and may end the pilot. Where practical, we will give notice on this website and an opportunity to export before a planned shutdown. Urgent security or legal action may require immediate suspension.

You may stop using the service and delete your store with the SDK's destroy() operation. Deletion removes it from the active database; copies may remain temporarily in hosting snapshots or backups until those expire. Expiry of an activated store or share link does not itself erase stored records. Unactivated provisional stores are removed under the four-hour policy above. Contact us about deletion concerns without sending tokens or encryption keys.

6. Responsibility and legal rights

We will use reasonable care and skill in operating the pilot. Nothing in these terms excludes liability for fraud, fraudulent misrepresentation, death or personal injury caused by negligence, or any liability that cannot lawfully be limited. Your mandatory consumer rights are unaffected.

If you use the service for business purposes, to the extent permitted by law we are not responsible for lost profits, lost business opportunities or indirect or consequential losses. You remain responsible for evaluating whether the pilot is suitable, protecting your credentials and maintaining backups. We do not promise uninterrupted or error-free operation.

7. Changes and disputes

We may update these terms for changes to the service or legal requirements. We will publish the revised version and effective date here and provide reasonable advance notice of material changes where practical. Changes will not remove rights already accrued. You may export and stop using the service if you disagree.

These terms are governed by the law of England and Wales. Courts of England and Wales have jurisdiction, except where mandatory consumer law gives you the right to bring proceedings elsewhere or receive protections under the law of your usual residence. Please contact us first so we can try to resolve any concern.