# Terms of Service

The agreement between Openhandle and its customers for use of the API, the MCP server, and the dashboard.

Effective date: September 3, 2026

These terms are an agreement between Openhandle, a sole proprietorship registered in the Netherlands (KvK 89247647) ("Openhandle", "we"), and the customer ("you") for use of the Openhandle API, MCP server, dashboard, and website (together, the "Service"). By creating an account or using the API you accept these terms.

## 1. The Service

Openhandle is a read-only API for public data from public accounts on Instagram, TikTok, and X: profiles, posts, comments, followers, and search. Answers come in one normalized shape. The Service includes an MCP server so AI agents can use the same API, and a dashboard for keys, usage, billing, and connected agents.

The Service only reads. It never likes, follows, posts, comments, or messages on any account, on your behalf or anyone else's. It does not read private accounts or private content.

The current API version is stable. We do not remove fields from an active version. Breaking changes move to a new version, such as `/v2`. We announce version retirement well in advance.

## 2. Accounts and workspaces

You must give accurate account information and keep your credentials secret. You must verify your email address before you can make live requests. A workspace's owner controls its members, keys, connected agents, and billing. You are responsible for all activity under your workspace, including activity by your team members, through your API keys, and through connected agents.

## 3. API keys and connected agents

- **API keys.** We show a key secret once, at creation, and store it only as a hash. Keep it secret. Anyone who holds a key can spend your money. You can set a request cap on each key. Rotate or revoke keys in the dashboard. Revocation is immediate. Do not put keys in client-side code.
- **Connected agents.** MCP clients such as Claude, ChatGPT, Cursor, and others connect through OAuth 2.1 with PKCE. When you approve a client, we create an API key named after that client. Usage, request history, and caps work like any other key. Access tokens live one hour. Refresh tokens rotate and live 30 days. When you disconnect a client in the dashboard, we revoke its key and all its tokens.
- **Scripts.** A script may use an API key as a bearer token instead of OAuth.
- **Your responsibility.** Requests a connected agent makes with your key are your requests. Read what a client will do before you approve it.

## 4. Acceptable use

You agree to use the Service only for lawful purposes, and not to:

- harass, stalk, or surveil private persons, or build tools whose purpose is to target private persons;
- use retrieved data for unsolicited mass communication;
- try to access private content, other customers' data, or the Service's internals;
- circumvent rate limits, metering, request caps, or spend caps;
- resell raw, unmodified access to the API without our written agreement;
- use the Service in violation of law that applies to you, including data protection law in your jurisdiction.

You are an independent controller of the data you retrieve. You are responsible for your own legal compliance when you use it, including your GDPR obligations to the people in that data.

## 5. The data

Retrieved data comes from public sources. It shows what the platforms exposed at capture time. Its limits:

- A metric a platform hides is `null`. We never guess, estimate, or fill in a zero.
- Counts change all the time. Every response carries its capture time.
- Platforms change without notice. We do not warrant that retrieved data is complete, accurate, or fit for a particular purpose.
- Rights in platform content stay with the platforms and their users. We grant no rights in retrieved content beyond delivering it to you.
- An account owner can ask us to block their profile, as described in the [public data notice](/legal/public-data-notice). Requests for a blocked profile return an error and are not billed.

## 6. Pricing and billing

- **Pay afterwards.** You pay for what you used by card through Stripe. Every charge includes an invoice. We charge your card when unpaid usage reaches your billing threshold, or at month-end. There are no prepaid credits, no subscription, and no minimum.
- **What costs money.** Live requests and cache hits are priced per answered request. Rates are published on the [pricing page](/pricing). A 30-day cache hit is free.
- **What is an answer.** A confirmed not-found and a private-profile answer are answers, not errors, and are billed.
- **Errors are never billed.** Provider errors, internal errors, invalid input, rate limits, and requests stopped by a cap are never charged.
- **Free requests.** Each workspace gets 100 free live requests once, after email verification. The test environment uses synthetic data and is always free and unlimited.
- **Spend controls.** You can set a request cap per API key and a monthly spend cap per workspace. We stop before crossing either.
- **When we charge your card.** We collect unpaid usage when it reaches a threshold, or at the end of the month. The threshold starts at $1 for a new card and grows to $50 as payments succeed.
- **Failed payments.** If a payment fails, we may suspend API access until the balance is paid.
- **Price changes.** We may change prices with at least 30 days' notice. Changes never apply to past usage.
- **Taxes.** Prices exclude VAT and similar taxes where they apply.

## 7. Suspension and termination

You can stop using the Service and delete your workspace at any time. Charges you already made stay payable. We may suspend or end your access for breach of these terms, non-payment, security risk, or where law requires it. Where practical we warn you first.

## 8. Intellectual property

The Service, its software, documentation, and branding are ours. Your applications and the works you build with retrieved data are yours. Neither party receives rights in the other's property beyond what these terms state.

## 9. Warranties and liability

The Service is provided "as is." To the maximum extent the law allows: we exclude implied warranties; we are not liable for indirect or consequential damages, lost profits, or lost data; and our total liability under these terms is capped at the amounts you paid us in the 12 months before the event that gave rise to the claim. Nothing in these terms excludes liability that cannot be excluded by law.

You will indemnify us against third-party claims that arise from your use of the Service in breach of section 4.

## 10. Privacy

How we process personal data is described in the [privacy policy](/legal/privacy-policy). What we do and never do with public social media data is described in the [public data notice](/legal/public-data-notice).

## 11. Changes to these terms

We may update these terms. We announce material changes at least 30 days in advance by email or in the dashboard. If you keep using the Service after the effective date, you accept the new terms.

## 12. Governing law

These terms are governed by Dutch law. Disputes go to the competent court of the Zeeland-West-Brabant district, without prejudice to mandatory consumer protections that may apply.

Contact: hello@openhandle.dev. Openhandle, Oesterstraat 12, 4691 KT Tholen, the Netherlands, KvK 89247647.
