← Back to home

Terms of Service

Version 2.0 · Effective: August 27, 2026 · Entity: AiTrade LLC, a Florida limited liability company

Published for review. This is Version 2.0, and it replaces Version 1.0 on this page. It has not yet been reviewed by counsel. Where it differs from Version 1.0 it differs by removing claims we could not support and by scoping every restriction to services we actually operate — §25 lists each change and the reason for it. If something reads unfairly or inaccurately, email legal@railcall.ai — that is the actionable form of feedback right now.
Counsel — publicationTwo decisions belong to you, not to the draft. (1) Adoption status. The draft was written as "effective on adoption, Version 1.0 remains operative until then." Publishing it at this URL replaces Version 1.0, so that sentence would be false and is not used; the banner above says "published for review" instead. Confirm whether v2.0 is adopted as of the effective date or published for comment first. (2) Prior version access. §21.1 commits to keeping the prior version accessible, and Version 1.0 is no longer served anywhere once this page ships. Ship a snapshot at a stable URL — /legal/terms/v1.0 — in the same change, or amend §21.1. The same applies to Marketplace v0.1 and to the Acceptable Use Policy v1.0.Counsel / Founder — do not publish until these are trueFour facts outside this document have to change in the same deploy, or a sentence in this document becomes false on publication day. Each was checked against the live site on 2026-08-27; none is a drafting question.
  1. The HIPAA claim — closed in this change.§14.1 says we hold no HIPAA certification and §14.5 withdraws the “100% compliant” assertion. The same change withdraws that assertion everywhere else it appeared: /enterprise, /for-teams, /legal/security, and the HipaaStrip, Hero, Regulated and MissingLayer components. The §164.312 substance is kept — it was always the true part. Compliance is a property of a covered entity’s programme, not a product claim, so no page now asserts one.
  2. The cross-references. /legal/licensing and /legal/trademark return 404 today. §0.3, §3.1, §4 and the footer all link to them. All four pages ship together or none of them do.
  3. The brand assets page. The Trademark Policy conditions two standing permissions on artwork "from the brand assets page." There is no /brand route. Those clauses are redrafted in this change to point at the logo as published on railcall.ai, so the policy is compliable today — but shipping /brand is still the right end state.
  4. The deployed site is not this repository. The live homepage and pricing page contain zero occurrences of "HIPAA" and copy that exists nowhere in this working tree, while git ls-remote reports local HEAD equal to origin/main. Something other than this branch is serving railcall.ai. Deploying this tree would therefore publish these legal pages alongside a homepage that mounts a "100% HIPAA compliant" banner and a pricing component that charges $100 per seat — creating the exposure item 1 exists to close. Resolve why live ≠ repo before any deploy.

Read this part first. RailCall is two different things, governed by two different documents. Almost every misunderstanding about our terms comes from mixing them up, so the distinction goes before anything else.

The SoftwareThe Services
What it isRailCall Station, RailHub Studio, and the RailCall CLI — the code you download and run on your own hardware.The things we operate: the hosted gateway, the hosted RailHub platform, the Marketplace, the dashboard, accounts, entitlements, and metering.
Who runs itYou do, on your machines.We do, on ours.
What governs itThe LICENSE file inside the release you downloaded. Every version released to date is under the MIT License.These Terms.
What these Terms do to itNothing. These Terms place no restriction on the Software.Everything below.

Said plainly: these Terms are not a licence for the Software, and they do not narrow one.

If you download RailCall and run it on your own hardware, you do not need an account, you do not agree to these Terms, and nothing on this page applies to you. The MIT licence in your copy is what governs, and it grants you the right to use, copy, modify, merge, publish, distribute, sublicense, and sell that software. We are not taking any of that back, and §3 below says so in terms.

These Terms begin to apply when you use something we operate.

0. How to read this document

0.1 Plain language is intentional. Where a normal sentence does the job, we use a normal sentence. Where a term has to be precise to be enforceable, it is precise. Nothing here is drafted to be hard to read on purpose.

0.2 Headings are part of the agreement. They are not decoration and they scope the sections under them. Where a restriction sits under a heading that says "Services," it reaches the Services and nothing else.

0.3 Which document controls.

  • What you may do with the Software you run yourself — the LICENSE file in that release, and the Licensing notice.
  • The hosted gateway, the hosted RailHub platform, the dashboard, accounts, entitlements, metering — these Terms.
  • Publishing or buying on the Marketplace — the Marketplace Terms, then these Terms for anything they do not cover.
  • Our name and marks — the Trademark Policy, expanded by §4.
  • Personal data — the Privacy Policy and the Data Flow Disclosure.
  • What you may not do with the Services — the Acceptable Use Policy, expanded by §7.

Where documents overlap, the more specific one controls for its own subject. No document listed above narrows the licence on a version of the Software you already hold. If one of them ever appears to, the LICENSE file wins and the conflicting clause is void as to that version.

0.4 Counsel markers. This draft was written by non-lawyers. Where a fact could not be verified, or a decision belongs to counsel, the text says so in line rather than guessing. Each one renders as an amber block. None of them should survive into an adopted version.

0.5 Two effective dates, because most of this version helps you and some of it does not. Version 1.0 promised at least 30 days' notice before a material change. Almost everything in Version 2.0 removes a restriction, withdraws a claim we could not support, or grants you something — and applying that to you on the day it publishes costs you nothing, so it takes effect immediately. A small number of sections impose obligations that Version 1.0 did not, and honouring our own notice promise about them matters more than having them a month sooner.

  • §8.3, §8.4, §8.5, and the §20 indemnity as it applies to hosted compose take effect 30 days after the publication date above for anyone who held an account on that date. For accounts created after it, they apply on acceptance.
  • Everything else — including all of §3, §4, §8.1, §8.2, §11, §12, §14, §17.5 and §25 — takes effect on the publication date.
Counsel — staged adoptionThis paragraph exists because publishing the whole document as effective on day one would breach the change-notice clause of the version it replaces, in a package whose entire premise is that we honour our own terms. Confirm the split above is the right one and that 30 days is the right deferral. The equivalent question arises on the Marketplace Terms, whose live v0.1 promises 14 days' notice and whose §8.2 and §17.3 are new adverse obligations.

1. Definitions

"AiTrade," "we," "us," "our" — AiTrade LLC, a Florida limited liability company.

CounselState of formation supplied and applied — every entity block on this page now reads "AiTrade LLC, a Florida limited liability company". The registered address and registered agent are still outstanding; the single open ask for them is in the entity block at §24, not repeated here.

"You," "your" — the individual or organization using the Services. If you use the Services for an organization, you confirm you are authorized to bind it, and "you" means that organization.

"The Software" — RailCall Station, the RailCall command-line interface, and the desktop client that ships with them (distributed as "RailHub Studio"), in any version, together with any modification or fork of them. The Software is licensed by the LICENSE file distributed with each release, not by these Terms. What matters for this definition is what a component is, not what it is called: any client we distribute for you to run on your own hardware is the Software, whatever name it ships under. RailHub Studio carries a RailHub name and is nonetheless the Software, not the Services. It is MIT-licensed, and the fact that its name is our trade mark restricts nothing about the code — see the Licensing notice.

Counsel — product naming, decision recordedDecision recorded, 2026-08-27: the free MIT-licensed downloadable desktop client is “RailHub Studio”. RAILHUB covers both the hosted organizational platform and the free desktop client. RAILCALL covers the protocol, RailCall Station, the RailCall CLI and the RailCall Marketplace. An earlier draft raised this as open, on the ground that the free, MIT, runs-on-your-machine client shipped as “RailHub Studio” while the Trademark Policy reserved RAILHUB for the hosted tier — so a mark sat on both sides of the Software/Services split this document is built on. It was resolved by fixing the Trademark Policy rather than by renaming the product: the live download button had read “Download RailHub Studio” all along, and RAILHUB now expressly covers both. The trade-mark scope no longer decides which document governs a component — the definition above does, on what the component is. The Services list below names the hosted RailHub platform, and it does not reach RailHub Studio on your machine. Confirm one drafting consequence: because a single mark now spans a downloaded product and a hosted service, every clause that leans on the name alone to sort the two has been rewritten to name “the hosted RailHub platform” explicitly — the “Read this part first” table above, the which-document-controls list at §0.3, and the Services definition in this section. Confirm that reading holds across the executed agreement, and confirm whether RAILHUB should be filed in the goods class as well as the services class. Trademark Policy §1.1 and Licensing notice §3 and §5.1 are written to the same decision.

"The Services" — everything we operate and you reach over a network, including:

  • the hosted gateway (including hosted compose and any metered API endpoint we run);
  • the hosted RailHub platform — the organizational service we operate, which is a different thing from RailHub Studio, the client you download and run yourself;
  • the RailCall Marketplace, including listings, checkout, payouts, and publisher tooling;
  • the web dashboard and account console at railcall.ai;
  • account creation, authentication, and session management;
  • entitlement issuance, licence and key minting, and the metering that measures use of the above;
  • our websites, documentation sites, and any API we publish for these.

The Services do not include the Software running on your own hardware, even when that Software is configured to call a Service.

"Your Content" — anything you submit to, store in, or transmit through the Services.

"Marks" — the RailCall name and logo, RailHub, RailHub Studio, RailCall Station, and our other trade names, product names, service marks, logos, and wordmarks, whether registered or unregistered. A name being a Mark says nothing about the licence on the code under it. RailHub Studio and RailCall Station are Marks and are also MIT-licensed Software; §4 restricts what you may call your thing, never what you may do with the code.

CounselConfirm which Marks are the subject of filed or registered applications, in which classes and jurisdictions, and whether the ™ / ® designations should be used in this section and on the site.

"Marketplace" — the RailCall Marketplace we operate, together with its published publisher and buyer terms.

2. Agreement, capacity, and who is bound

2.1 You agree to these Terms by creating an account, by using any Service, or by paying us for anything. If you do not agree, do not use the Services. Running the Software on your own hardware is not agreement to these Terms, and does not require it.

Counsel — assent, unresolved§2.1 states how you agree. Today, on most surfaces, nothing records that you did. Verified 2026-08-27: /marketplace/signup presents an unchecked checkbox reading "I've read and agree to the Marketplace Terms and Privacy Policy" and will not submit without it — that one is correct. /signup contains no reference to any agreement at all, and /cli-activate/signup carries only the sentence "By signing up you agree to our terms · no lock-in", unlinked, with no version and no affirmative act. Every restriction in §8, the §20 indemnity, and the §22 arbitration and class-waiver provisions depend on contract formation. Against an account created through those two flows they are browsewrap, and a court is unlikely to enforce them. Until an unchecked checkbox with live links to this document and the Privacy Policy ships on the account signup and CLI activation flows — and the accepted version and timestamp are stored per account — treat every Services restriction in this document as advisory. This is the single largest gap in the package and it is a few hours of work.

2.2 You must be able to form a binding contract where you live, and you must not be barred from using the Services under applicable law.

2.2a Minimum age. You must be at least 13 years old to use the Services, and at least 16 where the law that applies to you sets that threshold for consent to processing. We do not knowingly collect personal data from anyone below the applicable age; if we learn that we have, we delete it. Running the Software on your own hardware involves no account and no data reaching us, and this paragraph does not reach it.

CounselThe Privacy Policy already states a 13/16 floor. Version 1.0 of these Terms stated none, and the Marketplace Terms state only contractual capacity. Confirm the thresholds and whether a parental consent mechanism is needed anywhere. Payment processors and app-store reviewers both ask.

2.3 If you use the Services on behalf of an organization, these Terms bind that organization, and you represent that you have authority to accept them for it.

2.4 You may not use the Services if you are located in, or ordinarily resident in, a country or region subject to comprehensive economic sanctions applicable to either party, or if you appear on an applicable restricted-party list. You are responsible for your own export-control compliance.

3. The Software — what these Terms do not do

This section exists because the previous version of these Terms got this wrong, and we would rather correct it in the open than quietly.

3.1 The Software is licensed by its own LICENSE file. Each release of the Software ships with a LICENSE file. That file is the licence. Every version of the Software released to date is licensed under the MIT License. Under it you may use, copy, modify, merge, publish, distribute, sublicense, and sell the Software, including commercially, subject only to the notice requirement in the licence text itself.

3.2 These Terms impose no restriction on the Software. Nothing in these Terms — including the acceptable-use and restriction sections that follow — limits what you may do with a copy of the Software you hold. Specifically, and without limiting the licence you already have:

You may run the Software for any purpose, including commercial purposes, on any number of machines, without telling us and without an account.

You may modify it, fork it publicly or privately, and keep your changes to yourself forever.

You may study, audit, decompile, and reverse engineer it. It ships as readable source; there is nothing to conceal and we are not going to pretend otherwise.

You may redistribute it and you may sell it, on the terms of the licence you received it under.

You may build products on it and sell those products, including products that compete with ours.

You may operate a hosted service built from the Software and offer it to other people, subject to §4 (you must not use our Marks to do it) and §8 (you must not use our Services to do it).

3.3 We do not claim sole ownership of the Software. Copyright in the Software is held by its contributors. The LICENSE file in the shipped releases reads "Copyright (c) 2026 MeterCall contributors", and the repository history records who wrote what. Version 1.0 of these Terms stated that the software was owned by AiTrade LLC. That was inaccurate as to the codebase, and this version withdraws it. What we do own is set out in §16.

3.4 Support is not part of the licence. We are not obliged to support, maintain, update, or fix the Software you run yourself, and no version of these Terms creates that obligation. Support commitments, if any, come from a separate written agreement or from a paid Service, not from the licence.

3.5 Reservation of rights and forward notice. Read this carefully; it is the only forward-looking claim in this document.

  • No implied rights. Except for the rights the LICENSE file grants you in the Software, and the rights §5 grants you in the Services, no licence or right is granted to you by implication, estoppel, or otherwise. We reserve all rights not expressly granted.
  • Future releases may carry different terms. New components, new products, and future versions of the Software may be released under licence terms that differ from the terms on current releases. If that happens, the terms for a release will be stated in the LICENSE file distributed with that release, and we will say so publicly rather than let it be discovered.
  • Nothing reaches backwards. No change of licence, and no change to these Terms, alters, revokes, conditions, or reaches back to the licence on any version of the Software already released. A copy you hold stays on the terms you received it under, permanently. Choosing to stay on an older release is a legitimate choice and we will not treat it as a breach of anything.
  • As of this version, no such change has been made. Every released version is MIT. This paragraph reserves an option; it does not exercise one.
CounselConfirm this is the correct posture to publish now. A relicence of existing code is separately blocked on contributor consents that do not exist today. This clause is drafted so that publishing it makes no representation that a relicence has occurred or is imminent.Counsel / Founder — marketing conflict§3.5 is the most valuable forward-looking clause in this package, and the live homepage argues against it. Fetched 2026-08-27, railcall.ai carries three unqualified statements of permanence: "Nothing here is gated, metered, or seat-counted — and it stays that way"; "This is the part that never changes and never costs anything"; and "This is the free layer everything else is built on, and it stays free." A reservation of rights is weakest exactly where the marketing promised permanence, and a customer who relied on those sentences has a reasonable argument that we represented otherwise. Three ways out, and the decision is a business one: (a) soften the homepage to match §3.5 — "free today, and any change is version-forward only, never retroactive"; (b) keep the homepage and narrow §3.5 to new components only, giving up the option on future versions of existing components; or (c) publish both and accept that (a) estoppel argument. Do not leave it unresolved — it is cheap to fix in one sentence of homepage copy and expensive to argue later.

4. Trademarks and naming

This is the section that matters most, and it is the one we will actually enforce.

We gave the code away. We did not give away the name. The Marks are owned by AiTrade LLC, they are not licensed by the MIT licence on the Software, and no fork, redistribution, or modification of the Software carries any right to use them. This section applies to everyone, whether or not you use the Services and whether or not you have an account. The operative detail is in the Trademark Policy.

4.1 What you may do without asking. You may use the word "RailCall" truthfully, to say true things:

  • "Works with RailCall." "Built on RailCall." "Compatible with RailCall." "A fork of RailCall."
  • Naming RailCall in documentation, articles, comparisons, reviews, talks, and course material, including critical ones.
  • Redistributing the Software unmodified, with its original name and notices intact, as the licence contemplates.
  • Using the name in ordinary descriptive prose where no reasonable reader would think we published or endorsed the thing.

This is nominative use, we do not require permission for it, and we will not send you a letter about it. Keep it accurate and keep it in plain text — a claim of compatibility is not a licence to use our logo.

4.2 What you may not do. You may not, without our prior written permission:

  • Name a fork, derivative, distribution, or modified build "RailCall," or any name that includes a Mark or is confusingly similar to one. If you fork the Software and ship it, ship it under your own name. This is the normal outcome for a permissively licensed project, and it is not a restriction on the code — it is a restriction on our name.
  • Use a Mark in the name of your company, product, service, application, domain name, subdomain, social media handle, package name, or app-store listing. "RailCall" as a component of your identity is not available. Descriptive suffixes do not fix this. Repository names are not on that list. A descriptive third-party source repository — railcall-connectors and the like — is permitted without asking, as Trademark Policy §3.1 and §6.2 set out. What is not available is a published package namespace or a product name, which is a different thing from the name of a repository.
  • Use our logos, wordmarks, or brand assets in any product, interface, packaging, marketing, or user interface.
  • Represent that anything is certified, verified, approved, endorsed, official, authorized, partnered, or affiliated unless we have said so in writing. In particular, "RailCall Certified," "Official RailCall," "RailCall Verified," "RailCall Partner," and any construction of similar effect are prohibited. Our signing, receipt, and verification systems are the only things that certify anything in this ecosystem, and they say so cryptographically. Claiming their result in words when you do not hold it is a misrepresentation as well as a trademark violation.
  • Sell, host, or offer a fork or derivative under our Marks, or in a way that implies the offering is ours or comes from us. You may absolutely compete with us using the code. You may not compete with us using our name.
  • Use the Marks in a way that suggests your modified build is the reference implementation, or that our verification, receipts, or evidence apply to output your build produced.
  • Register or attempt to register a Mark, a confusingly similar mark, or a domain incorporating one, in any jurisdiction.

4.3 Modified builds must be identified as modified. If you distribute a modified version of the Software, do not present it under our name, and do not present its behaviour as ours. This protects your users as much as it protects us: a receipt is only worth something if the thing that issued it is what it says it is.

4.4 Quality and confusion. We may require you to stop a use of the Marks that is likely to cause confusion, that misrepresents the origin of software, or that attributes to us a security property, certification, or verification result that does not exist. We will say what the problem is and give you a reasonable period to fix it before doing anything else, unless the use is fraudulent or is causing active harm.

4.5 This is not a code restriction, and we will not use it as one. We will not assert trademark rights to stop you from forking, modifying, redistributing, selling, or hosting the Software under a name of your own. If we ever do, that is a breach of this paragraph and you should hold us to it.

CounselThis section is drafted to be enforceable on its own terms and independent of the copyright position. Please confirm (i) the ownership recital in the §4 opening paragraph is accurate for AiTrade LLC, (ii) whether the separate published Trademark Policy page should carry the operative detail with this section incorporating it by reference, and (iii) whether §4.2 (last bullet) should include a domain-recovery/UDRP mechanic.

5. The Services — what we provide and what you may do with them

5.1 Grant. Subject to these Terms and to your payment of any applicable fees, we grant you a limited, non-exclusive, non-transferable, revocable right to access and use the Services for your own purposes, including your organization's commercial purposes.

5.2 The Services are optional. The Software runs without them. The local engine has no runtime dependency on any RailCall-operated service: once installed, it runs, executes workflows, and writes and verifies receipts with no outbound connection to us at all. You reach a Service only when you choose to use one.

Stated precisely, because the difference matters. Getting the Software does involve us: the install script is served from railcall.ai and fetches pinned release files, and checking for an update is an outbound request by design. That is distribution, not a runtime dependency — you can mirror the release, install from a copy, or install on a machine that never speaks to us again, and nothing degrades. The claim we make is about running, and it is the one that is true.

5.3 What we may change. The Services are a live system. We may add, change, deprecate, or remove features. §11 states what we commit to when we do.

6. Accounts and security

6.1 Some Services require an account. Provide accurate information and keep it current.

6.2 You are responsible for the confidentiality of your credentials, API keys, and tokens, and for everything done under your account. Tell us promptly at legal@railcall.ai if you believe your account or a key has been compromised, so we can revoke it.

6.3 Do not share credentials across organizations, and do not use another party's account without their authorization.

6.4 We are not liable for loss arising from credentials you failed to protect, other than to the extent the loss was caused by our own failure.

6.5 Local key hygiene. Keys you hold locally — provider keys in your vault, signing keys, receipt stores — are yours to protect. We recommend restrictive file permissions (0600) on the local vault. We cannot recover a local key for you, by design: we do not hold it.

7. Acceptable use of the Services

The Acceptable Use Policy applies to the Services and is part of these Terms. In summary, you may not use the Services:

  • for anything illegal, fraudulent, or deceptive;
  • to send spam, run phishing, or distribute malware or malicious code;
  • to harass, threaten, defame, or infringe anyone's rights;
  • to access any system, account, or data without authorization;
  • to violate the terms of a connected service or provider you route through;
  • to store or transmit content you have no right to store or transmit;
  • to interfere with, overload, or degrade the Services or anyone else's use of them;
  • in a way that exposes us or other users to legal liability or security risk.

These restrictions apply to the Services. They are not, and must not be read as, restrictions on what you may do with the Software on your own hardware.

Because §7 incorporates the Acceptable Use Policy into these Terms, the two documents have to agree, and Version 1.0 of each did not. AUP v1.0 §2.4 prohibited "using RailCall to build a competing product without license" and §2.7 prohibited "reverse engineering RailCall for competitive purposes" — the same two acts §3.2 of this document expressly permits. Both are deleted in AUP v2.0, which ships in the same change as this version and adopts the same Software/Services split. If you are ever reading a version of the Acceptable Use Policy that restricts what you may do with the Software, §3.2 and §0.3 govern and that restriction is void.

CounselConfirm AUP v2.0 is adopted and published in the same deploy as this version. If for any reason it is not, the incorporation sentence at the head of this section must be cut before this page ships — otherwise these Terms both grant and prohibit the same conduct, which is the defect Version 1.0 was rewritten to remove.

8. Restrictions on the Services

These are the restrictions we can actually enforce, because they concern systems we operate. Each is scoped to the Services on purpose.

8.1 No circumvention. You may not, in respect of the Services:

  • bypass, disable, tamper with, forge, or work around entitlement checks, licence validation, metering, quotas, or rate limits that a Service performs;
  • present a forged, replayed, altered, or another party's entitlement, licence, receipt, signature, or key as your own to a Service, or to any third party;
  • misreport, suppress, or manipulate usage data that our metering relies on;
  • use multiple accounts, automated account creation, or any other device to exceed a quota, evade a suspension, or obtain Services you have not paid for;
  • access a Service through an interface, credential, or route we did not authorize for you.

This paragraph concerns checks a Service performs. Checks your own installation performs on your own hardware are yours to configure. Local signing, local receipt issuance, and local receipt verification are functions of the Software, they run on your machine, they are MIT-licensed, and §3.2 expressly permits you to modify and reverse engineer them. Turning off receipt signing on your own station is not a breach of anything — it is a configuration choice, and the only person it costs is you, because what you lose is your own evidence. Version 1.0's cardinal error was writing restrictions that reached the customer's machine, and re-committing it here would also be unenforceable in practice: detecting it would require visibility into your system that §11.2 and §12.3 promise we do not have.

What remains prohibited is passing off the result: presenting something as carrying a RailCall signature, receipt, or verification when it does not. That is the second bullet above, and it is a misrepresentation claim, not a claim about what runs on your computer.

8.2 Verification is not restricted, and never will be. §8.1 does not restrict, and we will not read it to restrict: studying how signing, receipts, entitlements, or verification work; independently implementing a verifier; publishing a verifier; verifying our receipts, signatures, and evidence with tools you wrote yourself; or publishing the results of doing so, including results that make us look bad. The verification path is meant to be checkable by anyone without our permission and without our software, and if it ever stops being checkable, that is our defect. Security research on the Services conducted in good faith, without degrading the Services or accessing other users' data, is likewise not a breach of §8.1.

8.3 No resale or white-labelling of the Services. You may not resell, sublicense, rent, lease, timeshare, white-label, or otherwise make the Services available to a third party as your own offering, or as a component of your offering, without a written agreement with us. Using a Service on behalf of your own organization, its affiliates, and contractors acting under your direction is not resale. Using a Service to deliver work product to your clients — where they receive the output, not access to the Service — is also not resale.

8.4 No competing hosted service built from our Services. You may not use the Services to develop, train, or operate a hosted or managed service that substantially replicates a Service and is offered to third parties.

Benchmarking is not in that list, deliberately. Version 2.0 as first drafted prohibited using the Services to "benchmark for publication," which contradicted §8.2 of this document and §2.3 and §3.3 of the Trademark Policy in the same breath. You may benchmark the Services, publish the numbers, and publish them when they are bad for us.

This restriction covers our Services. It does not cover the Software. You are free to fork the Software and operate a competing hosted service built from it — the MIT licence permits that, §3.2 confirms it, and we are not going to argue otherwise. What you may not do is build that competing service on top of, or out of, the systems we run and pay for. Use your own infrastructure and your own name (§4), and we have no complaint.

8.5 No scraping or bulk extraction. You may not use crawlers, scrapers, or automated means to extract data from the Services except through an API we publish for that purpose and within its documented limits, and except as a published robots.txt permits. You may not systematically copy Marketplace listings, catalogue metadata, pricing, publisher information, or user information, and you may not use the Services to build a competing index or dataset of them.

Counsel / OpsThis clause and our own robots.txt currently disagree. app/robots.ts allows / for every user agent with no disallow, so the file this paragraph defers to affirmatively invites the crawl it prohibits. It also reaches only account holders: against a scraper with no account there is no contract here, and after hiQ v. LinkedIn there is no Computer Fraud and Abuse Act claim over publicly served pages either. Decide which is true. If the catalogue is worth protecting, disallow the listing and seller paths for non-search agents and rate-limit them; if it is not, this clause is decoration and should say less.

8.6 No interference. You may not probe or stress-test the Services in a way that degrades them, circumvent access controls, or attempt to gain access to another user's data or account. Good-faith security research within §8.2 is excepted.

8.7 No reverse engineering of non-public Service interfaces. You may not reverse engineer the non-public internals of the Services in order to circumvent §8.1 or to build a substitute for a Service under §8.4. For the avoidance of doubt, this does not apply to the Software, which ships as source and which you may reverse engineer freely under §3.2, and it does not apply to anything within §8.2.

8.8 Non-circumvention of the Marketplace. Marketplace non-circumvention is stated once, in Marketplace Terms §8, and it binds Publishers. It is not restated here.

Why it moved. This section previously carried its own version, running twelve months from the introduction, while Marketplace §8.2 runs twelve months from the Buyer's most recent transaction. Two clocks and two triggers for one obligation is a drafting defect, not a belt-and-braces. Worse, the version here bound "you" — which on this page means every account holder, so it purported to stop buyers from transacting off-platform. We do not want that term, it appears nowhere in the Marketplace Terms a buyer actually reads, and it is not defensible. The Marketplace version is the one we keep: one clause, publisher-side only, one clock, with the burden of proving that a relationship was first sourced through the Marketplace on us.

8.9 Consequences. A breach of this section may result in rate limiting, suspension, or termination under §17, and in the case of §8.1 may also result in revocation of issued entitlements.

9. The Marketplace

9.1 The Marketplace is a Service. Publishing on it, and buying through it, is governed by the Marketplace Terms, then by these Terms for anything those terms do not cover.

9.2 Fees, stated in full. As published on railcall.ai/pricing: the seller fee is 0%, the publisher keeps 100% of the list price, and a 15% buyer assurance fee is charged to the buyer on top of the listed price. Nothing is deducted from the publisher; the assurance fee is what funds the guarantee, and it is disclosed to the buyer at checkout as its own line. Both fees are disclosed on the pricing page and in checkout. Those two fees, the deductions listed in Marketplace Terms §6.4, and taxes are the complete set of amounts we take from a sale — Marketplace §6.5 states the closed list and controls over this paragraph.

CounselVersion 0.1 of the Marketplace page stated "the listed price is the price you pay — RailCall does not add hidden fees at checkout," which was inconsistent with a buyer-side fee, and disclosed only the seller fee in its publisher section. Marketplace Terms v1.0 deletes that sentence and discloses both fees together at §6.1 and §6.2; it ships in the same change as this document, so no further correction is outstanding there. Still to confirm: consumer-protection disclosure requirements for the buyer-side fee in each jurisdiction where checkout is offered, before paid transactions are enabled — now at 15% rather than the 10% that figure was assessed against.Counsel — rate change of 2026-08-27This paragraph carried 5% seller / 10% buyer, publisher keeps 95% on publication day and was changed to 0% / 15%, publisher keeps 100% by the change order of 2026-08-27. Marketplace Terms §6.7 requires not less than 30 days' notice of a rate change, prospective only; the seller-side reduction is favourable and immediate, the buyer-side increase is not. Set and publish the effective date for the buyer-side increase, and record which schedule governed which period for sales that have already settled.Counsel / Ops — “as published on railcall.ai/pricing” is not yet trueThis paragraph asserts what the pricing page says, and that page is outside this application. railcall.ai/pricing is served by nginx from static files on the server, not from the Next.js app that renders this document, so the 0% / 15% correction applied here could not be applied there in the same change. The static page was last observed carrying the superseded 5% seller / 10% buyer / keep 95%schedule. Until it is republished at 0% / 15%, the words “as published on railcall.ai/pricing” and “both fees are disclosed on the pricing page” in §9.2 describe a state of affairs that does not exist, which is the same defect — one live surface contradicting another — that this revision exists to remove. Republish the static pricing page at 0% / 15% / keep-100%, or amend §9.2 to stop sourcing the fee schedule to it. The identical assertion appears at railhub.ai/terms.html §9.2 and needs the same fix.Counsel / Founder — live pricing conflictThe live pricing page, fetched 2026-08-27, advertises "optional featured placement available" alongside "no listing fees." Marketplace Terms §6.1 promises "no placement fees, no featuring fees" and §6.5 says we do not charge "to be featured"; §3.2 promises that search ranking and category placement apply the same rules to first-party and third-party Listings. A paid placement product and those three clauses cannot both be true. Decide which one goes, and do it before either publishes.

9.3 We are not a party to the underlying transaction between a publisher and a buyer except as the Marketplace terms state. We do not warrant any third-party listing.

10. Fees, prepaid balance, and refunds

10.1 Local execution is free and is not metered. Running the Software on your own hardware costs nothing, is not charged by us, and is not counted by us. We do not meter workflows, runs, actions, or machines you execute locally, and we will not introduce a charge for local execution of a version you already hold. This is a term of these Terms, not only a marketing statement.

10.1a What §10.1 does not say. It is a promise about the Software, not a promise about how paid Services are priced. A paid Service may be charged per organization, per unit of deployed capacity, per seat, prepaid, or transactionally — §10.3 lists the shapes and railcall.ai/pricing states the current model. Nothing in §10.1 commits us never to price a Service per seat, and you should not read it that way.

Counsel — do not restore the absoluteAn earlier draft of §10.1 said local execution "is not limited by seat, machine, user, workflow, or run," as a term of the contract. That went further than the business can stand behind and is narrowed above. Verified 2026-08-27: the live for-teams page sells the Team tier at "$100 per seat per month, two seats minimum, with a 14-day free trial," while the live pricing page says of RailHub "priced per org · unlimited users · never per seat"; and this repository's own pricing component records that the billing API returns {"min_seats":2,"free_seat_cap":1,…} with the free cap enforced server-side — a 403 on the first colleague invited — together with a standing instruction not to re-add an absolute "never per seat" promise while the biller still charges per seat. §10.1 as narrowed is true under every one of those. Do not widen it again until the biller, the pricing page, and the for-teams page say the same thing.

10.2 Current prices. Prices for paid Services are published at railcall.ai/pricing. That page is the authoritative price list, and it controls over any figure stated anywhere else, including in this document. We deliberately do not restate prices here, because a price written into a legal document goes stale and then contradicts the page customers actually read. Version 1.0 of these Terms made exactly that mistake.

Counsel — pricing unresolvedPricing must be settled before adoption. Four different price models are simultaneously live or asserted inside the business: (1) railcall.ai/pricing, fetched 2026-08-27, shows the protocol at $0 forever, RailHub priced per org, "unlimited users," "never per seat," and Marketplace 5% / 10% / 95% — a schedule superseded the same day by the 0% seller / 15% buyer / keep-100% change order, which is what §9.2 and the Marketplace Terms now state. (2) The published Terms v1.0 §7 states "$100 per seat / month, minimum 2 seats, 14-day free trial." (3) The website repository's pricing component reads live values from the billing API GET /billing/pricing, which returns {"min_seats":2,"trial_days":14,"price_per_seat_month_usd_cents":10000,"free_seat_cap":1} — i.e. the biller charges $100/seat with a 2-seat minimum and enforces a 1-seat free cap. The deployed page and the repository component do not agree. (4) The brief for this draft specifies "$9 per node all-in, $0 usage inside," a figure that appears nowhere on the live site. No price should be written into these Terms until the biller, the pricing page, and the repository agree. §10.2 is drafted to be correct under any of the four outcomes.

10.3 How paid Services are charged. Depending on the Service, charges may be:

  • per organization, on a recurring basis, for a Service made available to that organization;
  • per unit of deployed capacity, on a recurring basis, where a unit is defined on the pricing page at the time you subscribe;
  • prepaid, by drawing down a balance you have purchased in advance;
  • transactional, as a fee on a Marketplace sale under §9.2.
CounselIf a per-unit-of-capacity model is adopted, a precise definition of the billable unit ("node," "gateway," "door," or otherwise) belongs here — what counts as one, when it starts and stops counting, how it is measured, and whether it is measured by us or self-declared. It cannot be drafted until the pricing decision above is settled.Counsel / Founder — a fifth charge shape is already advertisedThe live pricing page, fetched 2026-08-27, answers "What do you charge for?" with three things, one of which is "Premium protocol upgrades, à la carte." That is a paid-Software revenue line. It is not any of the four shapes above; it sits uneasily with §10.1 (local execution is free and is not metered); and it collides head-on with the Licensing notice, which tells readers "there is no activation, no licence key, and no entitlement check standing between you and the code you downloaded." Either the phrase describes a paid Service and the pricing page should say so, or it describes paid components of the Software and both §10 and the Licensing notice need a fifth category plus a statement of how entitlement is checked. Resolve before either publishes.

10.4 Prepaid balance. Where a Service is prepaid:

  • Your balance is a prepaid entitlement to use that Service. It is not a deposit, not a stored-value instrument, and not money we hold for you.
  • Usage draws the balance down as it is consumed. We publish your current balance and consumption in the dashboard.
  • When the balance reaches zero, the metered Service stops accepting new requests until the balance is topped up. Nothing you run locally is affected.
  • Free-tier balances that we grant and periodically refill are a courtesy. We may change or discontinue them prospectively; we will not invoice you retroactively for a balance we gave you.
  • Balance does not expire while your account is in good standing.
CounselConfirm expiry, breakage, and escheat treatment for unused prepaid balance, and whether the "not stored value" characterisation holds in the states where customers are located. This interacts with the Marketplace creator-wallet structure, which raises a separate money-transmission question flagged in the Marketplace Terms.

10.5 Included usage. Where a paid unit includes usage, requests within that inclusion are not separately metered or surcharged. We will not introduce a usage surcharge inside an existing paid unit during a term you have already paid for.

CounselConfirm this commitment is one the business wants to make contractually, and that it matches how the meter actually behaves.

10.6 Taxes. Prices exclude taxes. You are responsible for any sales, use, VAT, GST, or similar taxes, other than taxes on our income.

10.7 Refunds.

  • Prepaid balance is refundable, pro rata for the unused portion, on request within 30 days of purchase.
  • Recurring subscriptions may be cancelled at any time, effective at the end of the current period. We do not pro-rate a partial period unless the law where you are requires it.
  • If we terminate you without cause under §17.3, we refund the unused portion of anything you prepaid.
  • If we terminate you for cause under §17.2, we do not.
  • Marketplace purchases follow the refund terms published on the Marketplace, which control over this paragraph.
  • Statutory refund and cancellation rights, where you have them, are unaffected by any of the above.
CounselConfirm the refund windows above, and whether an EU/UK consumer withdrawal-right clause is needed given customers outside the US.

10.8 Non-payment. If an invoice goes unpaid, we may suspend the paid Service after notice and a reasonable opportunity to cure. You remain liable for amounts already incurred. Suspension of a Service never disables the Software on your machines, never revokes a licence you hold in it, and never touches your local receipts, vault, or data.

11. Service levels, availability, and changes

We would rather state this honestly than promise a number we cannot keep.

11.1 No uptime commitment. We do not commit to a specific uptime percentage for the Services, and these Terms contain no service-level agreement. The Services may be unavailable for maintenance, for reasons outside our control, or because something broke. If you need a contractual availability commitment, that comes from a separate written agreement.

CounselConfirm no SLA has been contractually committed to any existing customer. The site's Enterprise material references a "contractual SLA + incident response commitment," which if offered would need to be reconciled with this section — either by carving out signed agreements (as drafted) or by publishing an actual SLA.

11.2 The Software does not depend on us being up. This is the point of the architecture, and it is the reason §11.1 can be honest. If our Services are down, your local station keeps running, your receipts keep being written, and your workflows keep executing. What you lose is access to the hosted pieces.

11.3 Changes and deprecation. We may change the Services. For a change that materially and adversely affects a paid Service you are actively using, we will give at least 30 days' notice by the method in §21 before it takes effect, unless the change is required for security, legal compliance, or to stop active abuse — in which case we will act first and tell you as soon as we reasonably can.

11.4 Beta and preview. Anything we label beta, preview, alpha, or experimental is provided as-is, may change or disappear without notice, is excluded from §11.3, and should not be relied on in production.

12. Your content, your keys, your data

12.1 You own Your Content. We claim no ownership of your code, workflows, configurations, data, or output.

12.2 The licence we need, and no more. You grant us a limited licence to host, store, transmit, display, and process Your Content solely to operate and provide the Services to you, and to comply with law. That licence ends when the content is deleted or your account is closed, except for backups on their ordinary rotation and records we must keep by law.

We do not use Your Content to train models, and we do not sell it or license it to anyone who will. Where a Service routes your content to a third-party inference provider — hosted compose is the one path that does this — we commit to contracting for zero retention and no training on transmitted content, and to naming that provider in the Data Flow Disclosure and the subprocessor list. What we cannot honestly do is promise, in our contract, what a company that is not a party to it will do. So the promise is stated as what it is: an absolute commitment about our own conduct, and a procurement obligation as to theirs. If we ever cannot obtain those terms from a provider, the honest response is to say so on the Data Flow page rather than to keep a flatter sentence here.

CounselUnverified as of drafting. The absolute form of this sentence — "we do not use Your Content to train models," full stop — could not be confirmed for hosted compose, because the downstream inference provider's own terms were not reviewed. The clause above is drafted to be true either way. Two things to close it out: (1) confirm the provider contract actually carries zero-retention and no-training terms, and if it does, this can be restated flat; (2) confirm the provider is named on the Data Flow page and in the subprocessor list, which §13.5 and Art. 13 both require.

12.3 Content that never reaches us. Most of what RailCall does never touches our systems. Your provider keys stay in your local vault. Approved actions go directly from your machine to the provider you chose. Local receipts and audit records are written to your disk. The Data Flow Disclosure lists the flows that leave your machine, when they happen, and where they go. These Terms govern the content you actually send to a Service. They do not create rights for us over content that never arrives.

CounselAn earlier draft said the Data Flow Disclosure describes exactly what leaves your machine. That word was not survivable: §1 of this document defines the Services to include entitlement issuance, licence and key minting, and metering, and the disclosure's table covers none of those, nor Marketplace checkout and install fetch, publisher key registration, or the installer and update fetch. The word is removed here and the table is extended in the same change to cover them. Re-check the table against the code before adoption and restore a stronger word only if it holds.

12.4 Your responsibility for what you send. You are responsible for having the right to submit Your Content, and for its lawfulness. If you send us personal data, the Privacy Policy governs how we handle it.

12.5 Data processing agreement. If we process personal data on your behalf, a processor DPA is available on request to any customer, at no charge and regardless of tier.

CounselVersion 1.0 of the Security page gated the DPA to "Enterprise customers upon request," while the Trust page offered it on request with no tier gate. Under GDPR Art. 28 a controller is entitled to the terms whenever we act as processor, so this section adopts the ungated version and the Security page is corrected to match in the same change. Confirm the DPA itself exists as a signable document — an ungated offer of a document nobody has drafted is worse than a gated offer of one that exists.

12.6 Deletion. You may delete Your Content and close your account at any time. On closure we delete or de-identify account data per the Privacy Policy's retention schedule. Data on your own machines is untouched by any of this — we cannot reach it and closing an account does not remove it.

13. Third-party services, BYOK, and MCP

Preserved from Version 1.0 because it was accurate.

13.1 Bring your own keys. When you configure keys for connected services such as Slack, Stripe, or GitHub:

  • you keep ownership and control of those keys;
  • the keys are stored locally and are never transmitted to AiTrade;
  • you are responsible for their security and rotation, and for complying with each provider's terms;
  • approved actions are sent directly from your machine to the provider. We are not a party to that transaction and it does not pass through us.

13.2 Controller roles for connected-service action content. For content sent from your machine to a connected provider: you are the data controller; the provider is your processor or an independent controller, per your arrangement with them; AiTrade is neither, because that content never reaches us. This allocation concerns action content only. For account data that you do send us, AiTrade is the controller, as the Privacy Policy states.

13.3 Third-party terms. Each connected service is governed by its own terms and privacy policy. You agree to comply with them. We make no warranty about any third-party service, and we are not responsible for their acts, outages, pricing, or decisions.

13.4 MCP. Local MCP connections to an AI assistant are loopback or stdio sessions with no network egress to us. The MCP host sees what you put into it, on its own terms. RailCall governs the execution locally with dry-run, approval, and receipts. Complying with the MCP host's terms is your responsibility.

13.5 Hosted compose. If you choose to use a hosted composition Service, your prompt content is transmitted to us and onward to an inference provider in order to fulfil that request. This is the one path where content you author reaches our infrastructure, it happens only when you choose that Service, and the Data Flow Disclosure describes it.

CounselConfirm the hosted-compose data path, retention, and the identity of the downstream inference provider are disclosed accurately on the Data Flow page and in the subprocessor list.

14. Security posture — stated honestly

14.1 No certification is claimed. We do not hold, and these Terms do not represent that we hold, a SOC 2 report, HIPAA certification, PCI DSS attestation, ISO 27001 certification, or any equivalent. Where our public material describes a target date for an independent report, that is a target, not a report.

14.2 What we actually have is published at railcall.ai/trust and railcall.ai/legal/security, and those pages limit themselves to what can be backed by an artifact today: adopted written policies, a documented security risk analysis, a published threat model, a complete list of subprocessors, and an architecture in which the local engine has no runtime dependency on any service we operate. Read those pages rather than this one for the current state; they are maintained, and a Terms of Service is the wrong place to keep a security fact fresh.

14.3 Compliance is a shared outcome, and most of it is yours. Product controls are one input to your regulatory posture. How you configure, deploy, operate, and supervise the system is the rest of it, and that part is yours. No property of our software makes your organization compliant with anything.

14.4 We report incidents. If a security incident affects Your Content or your account data, we will notify you without undue delay and within any period the law requires, and we will tell you what we know rather than the minimum we can get away with.

14.5 What Version 1.0 said, and why it is gone. Version 1.0 §10 stated that RailCall is "100% compliant with the HIPAA §164.312 technical safeguards." That claim is withdrawn in full and does not appear anywhere in this document. There is no such certification for a software vendor to hold, we do not hold one, and an unqualified compliance assertion is a representation we cannot support.

Counsel — HIPAA claim withdrawn site-wideResolved in this change, not deferred. The “100% HIPAA compliant” assertion has been withdrawn from every surface that carried it — the Enterprise and Teams pages, the Security page, and the four marketing components. What remains is the claim we can actually support: the §164.312 technical safeguards are mapped and implemented, and the evidence is cryptographic. Two things still need counsel. First, whether “SOC 2 audit in progress” and “independent audit in flight” are supportable as written, since neither has produced an artifact. Second, that the deployed site is built from something other than this working tree — see the publication blockers above — so this correction only reaches users once the deploy path is resolved.CounselVersion 1.0 of the Security page stated that the gateway runs on "AWS (or GCP)" with EBS/S3/KMS/CloudWatch/RDS/Secrets Manager, while the published subprocessor list names Render, WorkOS, Stripe, Resend, GitHub, and Cloudflare, and railcall.ai resolves to a DigitalOcean address — a GDPR Art. 13/28 subprocessor-disclosure defect. The Security page and the Privacy Policy are both corrected in this change: the incorrect vendor names are removed and both point at the single maintained subprocessor list. The underlying question is still open — confirm the actual hosting, database, secrets, and logging providers and restore concrete names, because removing a wrong disclosure is only half of an Art. 13 fix. The same page's password-hashing primitive (bcrypt on the Security page, argon2id on the subprocessor page) is likewise flagged rather than guessed.

15. Feedback

If you send us feedback, suggestions, or ideas about the Services, we may use them without obligation, restriction, attribution, or payment. This does not give us any right in your code, your products, or anything you build. Do not send us anything confidential that you do not want used on those terms.

16. Intellectual property — what we do and do not own

Stated precisely, because Version 1.0 was not.

16.1 What AiTrade owns:

  • The Marks — in full, and §4 governs them.
  • The Services — the hosted systems we operate: our gateway, the hosted RailHub platform, the Marketplace platform, the dashboard, our server-side code, our infrastructure, and our operational data. This bullet does not reach RailHub Studio, which is Software you run, not a hosted system we operate — the bullet below governs our contributions to it.
  • The site and its content — railcall.ai and its pages, copy, documentation text, designs, and media, except where a page states otherwise.
  • Our own contributions to the Software — the copyright in the code AiTrade personnel wrote, which is ours in the same way every other contributor's is theirs, and which we have licensed to the public under MIT along with the rest of each release.

16.2 What AiTrade does not own or claim:

  • The Software as a whole. Copyright is held by its contributors. See §3.3.
  • Anything you build. Your workflows, modules, configurations, integrations, forks, and products are yours. We claim no ownership of them and no licence to them, whether or not they were built with RailCall, and whether or not they run on it.
  • Your data and content. See §12.

16.3 These Terms transfer nothing. No ownership passes in either direction.

17. Suspension and termination

17.1 By you. Close your account at any time, from the dashboard or by contacting us. You do not need a reason.

17.2 By us, for cause. We may suspend or terminate your access to the Services for: breach of these Terms or the Acceptable Use Policy; breach of §8; non-payment after notice and an opportunity to cure; illegal activity; or conduct that presents a genuine security or legal risk to us, to the Services, or to other users. Where the circumstances allow it, we will give notice and a chance to fix the problem first. Where they do not — active abuse, fraud, an ongoing attack, a legal demand — we may act immediately and will tell you promptly afterwards.

17.3 By us, without cause. We may discontinue a Service, or stop offering it to you, on 30 days' notice, and will refund the unused portion of anything you prepaid for it under §10.7.

17.4 Effect of termination. Your right to use the Services ends. We may delete your account data per the Privacy Policy retention schedule.

17.5 What termination does not do. This is the paragraph that matters most, and it is unconditional:

It does not terminate your licence in the Software. The LICENSE file governs that, we cannot revoke it by terminating an account, and we do not purport to.

It does not disable, deactivate, time-bomb, or degrade software running on your machines.

It does not touch your local data — your vault, your keys, your receipts, your audit chain, your workflows. Those are on your hardware and they stay there, readable and verifiable, whether or not you ever speak to us again.

It does not invalidate receipts already issued. A receipt is verifiable offline against a published key. Ending an account does not un-sign anything.

17.6 Export before you go. Before termination takes effect, and for 30 days afterwards where we terminate you, you may export your account data and anything you have stored in a Service, in a machine-readable form.

CounselConfirm the 30-day post-termination export window is operationally deliverable before committing to it.

17.7 Survival. The following survive termination, together with any provision that by its nature should: §3 (the Software, in full), §4 (trademarks), §8.2 (verification is not restricted), §10.6 (taxes), §10.7 (refunds, as to amounts already owed), §10.8 (amounts already incurred, and what suspension never does), §12.1 (you own Your Content), §12.2 (the licence ends, with its backup and legal-records carve-out), §12.6 (deletion), §13.2 (controller roles), §14, §15, §16, §17.5 (what termination does not do), §17.6 (export), §18, §19, §20, §21.4, §22, and §23.

§17.5 survives whatever else does not. It is called unconditional two paragraphs above, so it is named here rather than left to "by its nature" — a survival list that omits the clause the page describes as the one that matters most is the kind of drafting slip that gets read against us later. The same reasoning adds §10.8, §12.2, §13.2 and §21.4, each of which does work only after the relationship has ended.

18. Disclaimers

THE SERVICES ARE PROVIDED "AS IS" AND "AS AVAILABLE," WITHOUT WARRANTY OF ANY KIND. To the maximum extent permitted by law, AiTrade disclaims all warranties, express, implied, and statutory, including merchantability, fitness for a particular purpose, title, non-infringement, and any warranty arising from course of dealing or usage of trade.

We do not warrant that the Services will be uninterrupted, timely, secure, or error-free; that they will meet your requirements; that any result obtained through them will be accurate or reliable; or that any third-party service will be available.

The Software is provided under its own licence, and that licence contains its own warranty disclaimer. Nothing in this section adds to or subtracts from it.

Automation carries risk that is yours to manage. RailCall is designed to make automated action reviewable — dry-run previews, approval gates, and signed receipts exist so that you can see what will happen before it happens and prove what did happen afterwards. Those are controls, not guarantees. You are responsible for what you approve and for what your automation does. We do not warrant the correctness of any action a model proposes.

Some jurisdictions do not allow the exclusion of implied warranties. Where that is so, the exclusions above apply only to the extent permitted, and you may have rights that these Terms cannot remove.

19. Limitation of liability

TO THE MAXIMUM EXTENT PERMITTED BY LAW:

19.1 Neither party will be liable for indirect, incidental, special, consequential, exemplary, or punitive damages, or for lost profits, lost revenue, lost data, or business interruption, arising out of or relating to these Terms or the Services, even if advised of the possibility.

19.2 Cap. AiTrade's total aggregate liability arising out of or relating to these Terms or the Services will not exceed the greater of (a) the fees you paid us for the Services in the twelve months before the event giving rise to the claim, or (b) one hundred US dollars (US$100).

19.3 Actions you approve. We are not liable for the consequences of actions you approve to connected services. You direct those flows, they leave your machine and go directly to the provider, we are not in the path, and the provider is your counterparty.

19.4 The Software. Liability in respect of the Software is governed by the warranty and liability terms of its own licence, not by this section.

19.5 Exceptions. Nothing in these Terms limits liability that cannot lawfully be limited, including liability for fraud, fraudulent misrepresentation, death or personal injury caused by negligence, or a party's wilful misconduct.

19.6 Some jurisdictions do not allow these limitations. Where yours does not, they apply only to the extent permitted.

19.7 Basis of the bargain. The allocation of risk in §18 and §19 is a fundamental part of the terms on which the Services are offered at their price, and both parties acknowledge it as such.

20. Indemnification

20.1 You will defend, indemnify, and hold harmless AiTrade and its officers, employees, and agents from third-party claims, damages, liabilities, and reasonable costs (including legal fees) arising from:

  • your use of the Services in breach of these Terms or the Acceptable Use Policy;
  • your violation of applicable law or of a third party's rights;
  • content you submit to the Services, including content you send through hosted compose;
  • actions your automation takes against third parties, including connected services.

20.2 Scope note, deliberately included. The third bullet is limited to content you actually send to a Service. Version 1.0 indemnified us against "content you transmit via RailCall," which was inconsistent with the rest of our own documentation: most action content never reaches us, and we should not be indemnified against content we never receive.

20.3 Process. We will notify you promptly of any claim, give you sole control of the defence (except that you may not settle in a way that admits our liability or imposes an obligation on us without our consent), and cooperate at your expense.

21. Changes to these Terms

21.1 We may change these Terms. We will publish the updated version with a new version number and effective date, and keep the prior version accessible at a stable URL.

CounselThis commitment and the equivalent one in Marketplace §18 both become false the moment these pages deploy, because Version 1.0 of these Terms, Version 1.0 of the Acceptable Use Policy, and Version 0.1 of the Marketplace Terms are each served at exactly one URL and are overwritten by the new version. Ship snapshot routes — /legal/terms/v1.0, /legal/acceptable-use/v1.0, /legal/marketplace/v0.1 — in the same change, or delete the commitment from all three documents. Keeping superseded versions readable is also what makes §25 and the equivalent change logs checkable rather than merely asserted.

21.2 Notice. For a material change, we will give at least 30 days' notice before it takes effect, by all of the following that apply: in-product notice in the dashboard; email to the address on your account, if you have given us one; and a dated entry on this page. Continued use of the Services after the effective date is acceptance. If you do not accept, stop using the Services and close your account before that date; we will refund any unused prepaid balance under §10.7.

21.3 Why the notice method changed. Version 1.0 promised notice "via email or in-product notice." Most people who run RailCall have no account and have never given us an email address, which means email could not reach them and a term they never saw was purporting to bind them. Under this version, that problem largely resolves itself: these Terms bind only people who use the Services, and using a Service means we have a way to reach you. The dated public entry on this page is the backstop.

CounselConfirm a versioned public changelog on this page is adequate notice for account holders in the relevant jurisdictions, alongside in-product and email notice.

21.4 Changes to the licence on the Software are not changes to these Terms, are not made through this section, and never apply retroactively to a release already made. See §3.5.

22. Governing law and disputes

22.1 Governing law. These Terms are governed by the laws of the State of Florida, USA, without regard to conflict-of-law principles.

CounselFlorida is carried forward from the published Version 1.0. Confirm it matches the entity's actual state of formation and principal place of business, and whether a Delaware or other choice is preferable.

22.2 Informal resolution first. Before filing anything, email legal@railcall.ai with a description of the dispute and what you want. We will do the same for you. If it is not resolved within 30 days, either party may proceed. This step is a condition, not a formality — most disputes end here and it costs both sides nothing to try.

22.3 Arbitration. Any dispute not resolved under §22.2 will be settled by binding arbitration administered by the American Arbitration Association under its applicable rules, seated in Florida. Judgment on the award may be entered in any court of competent jurisdiction.

22.4 Carve-outs. Either party may (a) bring an individual claim in small-claims court, and (b) seek injunctive relief in court to protect intellectual property, including trademark rights under §4, or confidential information.

22.5 No class actions. Claims must be brought individually and not as a plaintiff or class member in any purported class or representative proceeding, and the arbitrator may not consolidate claims. Where this paragraph is unenforceable as to a particular claim, that claim proceeds in court and the rest of this section stands.

22.6 Opt-out. You may reject §22.3 and §22.5 by emailing legal@railcall.ai within 30 days of first accepting these Terms, saying so and identifying your account. Opting out does not affect any other part of these Terms and we will not treat it as a reason to refuse you service.

Counsel — review whole section§22.3 to §22.6 are carried forward and expanded from the published Version 1.0, which contained an unqualified AAA arbitration clause with a jury and class-action waiver and no opt-out. Please advise on: enforceability against consumers and against non-US users; whether an opt-out and a small-claims carve-out should be included (drafted in, as the more defensible position); mass-arbitration and fee-allocation protections; whether AAA consumer rules apply and who pays filing fees; and whether the clause should be excluded entirely for users in jurisdictions where it will not be enforced. Also confirm the notice address in §22.2 and §24 — legal@railcall.ai is published on the current Terms but the support policy is Discord-only, and no one has confirmed the alias is monitored by a human.

23. General

  • Entire agreement: These Terms, together with the Privacy Policy, the Acceptable Use Policy, the Data Flow Disclosure, and any Marketplace terms that apply to you, are the entire agreement between us about the Services. They do not modify the licence on the Software.
  • Severability: If a provision is held unenforceable, it is limited or removed to the minimum extent necessary and the rest stands. §3 and §4 survive independently of every other section, and the unenforceability of any Services restriction does not affect them.
  • No waiver: Not enforcing a right is not a waiver of it.
  • Assignment: You may not assign these Terms without our written consent, except to a successor to your business. We may assign to an affiliate or in connection with a merger, acquisition, or sale of assets, on notice to you.
  • No third-party beneficiaries: Except as §17.5 and §3.2 expressly provide in your favour, these Terms create no rights in anyone who is not a party.
  • Independent contractors: Nothing here creates a partnership, joint venture, employment, or agency relationship.
  • Force majeure: Neither party is liable for delay or failure caused by events beyond its reasonable control. This does not excuse payment obligations.
  • Notices: Notices to you go to the email or in-product address on your account. Notices to us go to legal@railcall.ai.
  • Interpretation: "Including" means "including without limitation." Where a term of this document is genuinely ambiguous, it is read against us as its drafter.
  • Language: These Terms are written in English. A translation, if we publish one, is for convenience; the English version controls.
CounselA physical notice address is customary and is still absent from every published page. The single open ask for it is in the entity block at §24; whatever address is supplied there governs this clause.

24. Contact

Legal and these Terms: legal@railcall.ai

Support: Discord — railcall.ai/discord

Entity: AiTrade LLC, a Florida limited liability company

Governing law: Florida, USA

Registered address: not yet published — see the counsel note below.

Counsel — registered address still requiredThe registered business address was requested and was not supplied, so it is not stated anywhere on this page. None has been invented. This is the single open ask for it on this document; §1 and §23 point here rather than repeating it. Provide it and it will be added to the entity blocks in the masthead, in this section, and in the page footer, on this domain and at railhub.ai/terms.html in the same pass.

Supplied and applied: the state of formation — every entity block now reads "AiTrade LLC, a Florida limited liability company". Still outstanding: the registered street address, and the name and address of the registered agent. §512 DMCA safe harbour additionally requires a designated agent registered with the U.S. Copyright Office; the Acceptable Use Policy already publishes a takedown process that confers no protection without one. Confirm whether that registration exists.
CounselSix distinct addresses are published across the legal pages — legal@, privacy@, abuse@, support@, sellers@, and a personal address. Mail is deliverable (Google Workspace MX records exist), but the operating support policy is Discord-only and no one has confirmed each alias reaches a human. An unmonitored privacy@ is a GDPR response-clock failure and an unmonitored legal@ breaks both the DMCA process and §22.2 of this document. Verify or consolidate before adoption.

25. What changed from Version 1.0, and why

Not operative. Published because a correction nobody can read is not much of a correction.

The structural fix

Version 1.0 defined "the Service" to mean everything — the MIT-licensed code you run yourself and the hosted systems we operate, merged into one defined term. Every restriction it wrote then landed on both. The consequence was that the document granted a "limited, non-exclusive, non-transferable license… for your internal business or personal purposes" over software we had already released under MIT, with a README that says "Fork it. Use it. Ship on it." A licence cannot regrant less than it has already given away irrevocably. The fix is two defined terms — the Software and the Services — and a table at the top of this page saying which document governs which. Every restriction in this version is scoped to the Services and says so.

Removed

  • §3 Grant: "limited, non-exclusive, non-transferable license… for your internal business or personal purposes." Contradicts the MIT licence shipping inside the product and the homepage copy inviting forks. Replaced by §3, which states plainly that these Terms do not license or restrict the Software.
  • §3: "Use the Service to build a competing product." MIT expressly permits it and the homepage invites it. Replaced by §8.4, which restricts only building a competing hosted service out of our Services, with an explicit carve-out confirming you may fork the Software and compete.
  • §3: "Reverse engineer, decompile, or disassemble." The Software ships as readable source. Prohibiting reverse engineering of source we publish under MIT is unenforceable and reads as bad faith. Replaced by §8.7, scoped to non-public Service internals, with §3.2 and §8.2 confirming the Software and the verification path are open.
  • §3: "Resell, sublicense, or transfer" as applied to the software. MIT expressly grants the right to sublicense and sell. Retained only as §8.3, scoped to reselling the hosted Services.
  • §9: "RailCall software… and related IP are owned by AiTrade LLC." Inaccurate as to the codebase. Copyright is held by the contributors; the shipped LICENSE reads "MeterCall contributors." Replaced by §16, which states precisely what is owned — the Marks, the Services, the site, and our own contributions.
  • §10: "RailCall is 100% compliant with the HIPAA §164.312 technical safeguards." No such certification exists for a software vendor to hold. An unqualified compliance assertion is a representation. Replaced by §14, which claims no certification and points to the maintained trust pages.
  • §10: the SOC 2 assertion. No report is held. §14.1 states that plainly.
  • §7: "$100 per seat / month, minimum 2 seats." Contradicts the live pricing page it cites in the same sentence. Replaced by §10.2, which points to the pricing page as authoritative and states no figure.
  • §7: the seat-validation ping description. Describes a paid seat tier that the live pricing page says does not exist, and a periodic outbound call that the trust page says does not happen. Not carried forward; §5.2 and §11.2 state the honest architecture instead.
  • §12(d): indemnity for "content you transmit via RailCall." Presumed content flows that the rest of our documentation guarantees do not exist. Narrowed to content actually submitted to a Service — §20.1 and §20.2.

Added

  • §4 Trademarks and naming. The protection that is fully owned, needs nobody's consent, and is enforceable today. Anyone may fork the code; nobody may ship it under our name, imply certification, or sell a fork under our Marks. §4.5 binds us not to misuse it as a backdoor code restriction.
  • §3.5 Reservation of rights and forward notice. Preserves the option to release future components under different terms, states that no such change has been made, and guarantees that nothing reaches backwards.
  • §8 Restrictions on the Services. Anti-circumvention of signing, receipts, entitlements, metering and rate limits; no resale or white-labelling; no competing hosted service built from our Services; no scraping; Marketplace non-circumvention. All scoped to systems we operate.
  • §8.2 Verification is not restricted. A counterweight with teeth. Independent verification, independent verifiers, and publication of adverse results are expressly permitted. A verification claim nobody may check is worth nothing.
  • §9.2 Marketplace fees stated in full. Both fees — 0% seller and 15% buyer assurance, publisher keeps 100% — disclosed together.
  • §10.4 Prepaid balance. Mechanics for prepaid Services, including what happens at zero and that local execution is unaffected.
  • §11 Service levels. An explicit statement that there is no uptime commitment, paired with the reason it can be honest: the Software does not depend on us being up.
  • §12.5 DPA available on request. Ungated, matching the trust page and GDPR Art. 28.
  • §14 Security posture. Honest replacement for the compliance claims, pointing at maintained pages rather than freezing a security fact into a contract.
  • §17.5 What termination does not do. Termination cannot revoke your software licence, cannot disable software on your machines, cannot touch local data, and cannot un-sign a receipt.
  • §22.4–22.6. Small-claims and IP carve-outs, and a 30-day arbitration opt-out, added to a clause that had none.
  • §0.5 Staged effective dates. The corrections take effect on publication; the handful of newly restrictive clauses wait 30 days, because Version 1.0 promised 30 days' notice of a material change and a package about honouring our own terms should start by honouring that one.
  • §2.2a Minimum age. Version 1.0 required contractual capacity and stated no age floor.

Corrected during review, before this version was adopted

Two hostile reviews were run against this draft before publication. What they caught is listed here rather than silently patched, on the same principle as the rest of this section.

  • §8.1 reached software running on your machine. It listed signing, receipt issuance, and receipt verification as things you may not "bypass, disable, or work around" — all of which are local functions of MIT-licensed code that §3.2 permits you to modify. That is Version 1.0's cardinal error under a new section number. §8.1 is now scoped to checks a Service performs, with an express statement that local checks are yours to configure.
  • §8.4 prohibited "benchmarking for publication." It contradicted §8.2 of this document and §2.3 and §3.3 of the Trademark Policy. Deleted.
  • §8.8 bound buyers and ran a second clock. Marketplace non-circumvention now lives in one place, binds Publishers only, and runs on one clock.
  • §10.1 promised local execution is "not limited by seat." A contractual promise the biller contradicts. Narrowed to what is true and separated from how Services are priced.
  • §5.2 said installing requires no outbound connection to us. Installing plainly does; running does not, and running was always the claim worth making.
  • §12.2 promised no model training, flatly. A downstream provider's conduct is not ours to promise. Restated as an absolute commitment about our own conduct plus a procurement obligation as to theirs.
  • §12.3 said the Data Flow Disclosure describes "exactly" what leaves your machine. It did not disclose metering, entitlement issuance, Marketplace checkout, or the installer fetch. The word is gone and the table is extended.
  • §17.7 omitted §17.5 from the survival list — the one paragraph this document calls unconditional. Fixed, along with four other omissions.
  • A counsel note misstated where the HIPAA banner is live. It named the homepage and the pricing page; neither contains the string. Corrected to the pages that actually carry it.

Preserved because it was accurate

BYOK and key custody (v1.0 §5, now §13.1); the controller-role allocation for connected-service content (§13.2); the MCP loopback description (§13.4); account security responsibilities (§6); the feedback licence (§15); the liability cap structure and the US$100 floor (§19.2); Florida governing law (§22.1); entity name AiTrade LLC.

Entity: AiTrade LLC, a Florida limited liability company · Governing law: Florida · Last updated: August 27, 2026
See also: Licensing · Trademark Policy · Privacy Policy · Data Flow Disclosure · Acceptable Use