Version 2.0 · Effective: August 27, 2026 · Entity: AiTrade LLC, a Florida limited liability company
/legal/terms/v1.0 — in the same change, or amend §21.1. The same applies to Marketplace v0.1 and to the Acceptable Use Policy v1.0.Counsel / Founder — do not publish until these are trueFour facts outside this document have to change in the same deploy, or a sentence in this document becomes false on publication day. Each was checked against the live site on 2026-08-27; none is a drafting question./enterprise, /for-teams, /legal/security, and the HipaaStrip, Hero, Regulated and MissingLayer components. The §164.312 substance is kept — it was always the true part. Compliance is a property of a covered entity’s programme, not a product claim, so no page now asserts one./legal/licensing and /legal/trademark return 404 today. §0.3, §3.1, §4 and the footer all link to them. All four pages ship together or none of them do./brand route. Those clauses are redrafted in this change to point at the logo as published on railcall.ai, so the policy is compliable today — but shipping /brand is still the right end state.git ls-remote reports local HEAD equal to origin/main. Something other than this branch is serving railcall.ai. Deploying this tree would therefore publish these legal pages alongside a homepage that mounts a "100% HIPAA compliant" banner and a pricing component that charges $100 per seat — creating the exposure item 1 exists to close. Resolve why live ≠ repo before any deploy.Read this part first. RailCall is two different things, governed by two different documents. Almost every misunderstanding about our terms comes from mixing them up, so the distinction goes before anything else.
| The Software | The Services | |
|---|---|---|
| What it is | RailCall Station, RailHub Studio, and the RailCall CLI — the code you download and run on your own hardware. | The things we operate: the hosted gateway, the hosted RailHub platform, the Marketplace, the dashboard, accounts, entitlements, and metering. |
| Who runs it | You do, on your machines. | We do, on ours. |
| What governs it | The LICENSE file inside the release you downloaded. Every version released to date is under the MIT License. | These Terms. |
| What these Terms do to it | Nothing. These Terms place no restriction on the Software. | Everything below. |
Said plainly: these Terms are not a licence for the Software, and they do not narrow one.
If you download RailCall and run it on your own hardware, you do not need an account, you do not agree to these Terms, and nothing on this page applies to you. The MIT licence in your copy is what governs, and it grants you the right to use, copy, modify, merge, publish, distribute, sublicense, and sell that software. We are not taking any of that back, and §3 below says so in terms.
These Terms begin to apply when you use something we operate.
0.1 Plain language is intentional. Where a normal sentence does the job, we use a normal sentence. Where a term has to be precise to be enforceable, it is precise. Nothing here is drafted to be hard to read on purpose.
0.2 Headings are part of the agreement. They are not decoration and they scope the sections under them. Where a restriction sits under a heading that says "Services," it reaches the Services and nothing else.
0.3 Which document controls.
Where documents overlap, the more specific one controls for its own subject. No document listed above narrows the licence on a version of the Software you already hold. If one of them ever appears to, the LICENSE file wins and the conflicting clause is void as to that version.
0.4 Counsel markers. This draft was written by non-lawyers. Where a fact could not be verified, or a decision belongs to counsel, the text says so in line rather than guessing. Each one renders as an amber block. None of them should survive into an adopted version.
0.5 Two effective dates, because most of this version helps you and some of it does not. Version 1.0 promised at least 30 days' notice before a material change. Almost everything in Version 2.0 removes a restriction, withdraws a claim we could not support, or grants you something — and applying that to you on the day it publishes costs you nothing, so it takes effect immediately. A small number of sections impose obligations that Version 1.0 did not, and honouring our own notice promise about them matters more than having them a month sooner.
"AiTrade," "we," "us," "our" — AiTrade LLC, a Florida limited liability company.
CounselState of formation supplied and applied — every entity block on this page now reads "AiTrade LLC, a Florida limited liability company". The registered address and registered agent are still outstanding; the single open ask for them is in the entity block at §24, not repeated here."You," "your" — the individual or organization using the Services. If you use the Services for an organization, you confirm you are authorized to bind it, and "you" means that organization.
"The Software" — RailCall Station, the RailCall command-line interface, and the desktop client that ships with them (distributed as "RailHub Studio"), in any version, together with any modification or fork of them. The Software is licensed by the LICENSE file distributed with each release, not by these Terms. What matters for this definition is what a component is, not what it is called: any client we distribute for you to run on your own hardware is the Software, whatever name it ships under. RailHub Studio carries a RailHub name and is nonetheless the Software, not the Services. It is MIT-licensed, and the fact that its name is our trade mark restricts nothing about the code — see the Licensing notice.
Counsel — product naming, decision recordedDecision recorded, 2026-08-27: the free MIT-licensed downloadable desktop client is “RailHub Studio”. RAILHUB covers both the hosted organizational platform and the free desktop client. RAILCALL covers the protocol, RailCall Station, the RailCall CLI and the RailCall Marketplace. An earlier draft raised this as open, on the ground that the free, MIT, runs-on-your-machine client shipped as “RailHub Studio” while the Trademark Policy reserved RAILHUB for the hosted tier — so a mark sat on both sides of the Software/Services split this document is built on. It was resolved by fixing the Trademark Policy rather than by renaming the product: the live download button had read “Download RailHub Studio” all along, and RAILHUB now expressly covers both. The trade-mark scope no longer decides which document governs a component — the definition above does, on what the component is. The Services list below names the hosted RailHub platform, and it does not reach RailHub Studio on your machine. Confirm one drafting consequence: because a single mark now spans a downloaded product and a hosted service, every clause that leans on the name alone to sort the two has been rewritten to name “the hosted RailHub platform” explicitly — the “Read this part first” table above, the which-document-controls list at §0.3, and the Services definition in this section. Confirm that reading holds across the executed agreement, and confirm whether RAILHUB should be filed in the goods class as well as the services class. Trademark Policy §1.1 and Licensing notice §3 and §5.1 are written to the same decision."The Services" — everything we operate and you reach over a network, including:
The Services do not include the Software running on your own hardware, even when that Software is configured to call a Service.
"Your Content" — anything you submit to, store in, or transmit through the Services.
"Marks" — the RailCall name and logo, RailHub, RailHub Studio, RailCall Station, and our other trade names, product names, service marks, logos, and wordmarks, whether registered or unregistered. A name being a Mark says nothing about the licence on the code under it. RailHub Studio and RailCall Station are Marks and are also MIT-licensed Software; §4 restricts what you may call your thing, never what you may do with the code.
CounselConfirm which Marks are the subject of filed or registered applications, in which classes and jurisdictions, and whether the ™ / ® designations should be used in this section and on the site."Marketplace" — the RailCall Marketplace we operate, together with its published publisher and buyer terms.
2.1 You agree to these Terms by creating an account, by using any Service, or by paying us for anything. If you do not agree, do not use the Services. Running the Software on your own hardware is not agreement to these Terms, and does not require it.
Counsel — assent, unresolved§2.1 states how you agree. Today, on most surfaces, nothing records that you did. Verified 2026-08-27:/marketplace/signup presents an unchecked checkbox reading "I've read and agree to the Marketplace Terms and Privacy Policy" and will not submit without it — that one is correct. /signup contains no reference to any agreement at all, and /cli-activate/signup carries only the sentence "By signing up you agree to our terms · no lock-in", unlinked, with no version and no affirmative act. Every restriction in §8, the §20 indemnity, and the §22 arbitration and class-waiver provisions depend on contract formation. Against an account created through those two flows they are browsewrap, and a court is unlikely to enforce them. Until an unchecked checkbox with live links to this document and the Privacy Policy ships on the account signup and CLI activation flows — and the accepted version and timestamp are stored per account — treat every Services restriction in this document as advisory. This is the single largest gap in the package and it is a few hours of work.2.2 You must be able to form a binding contract where you live, and you must not be barred from using the Services under applicable law.
2.2a Minimum age. You must be at least 13 years old to use the Services, and at least 16 where the law that applies to you sets that threshold for consent to processing. We do not knowingly collect personal data from anyone below the applicable age; if we learn that we have, we delete it. Running the Software on your own hardware involves no account and no data reaching us, and this paragraph does not reach it.
CounselThe Privacy Policy already states a 13/16 floor. Version 1.0 of these Terms stated none, and the Marketplace Terms state only contractual capacity. Confirm the thresholds and whether a parental consent mechanism is needed anywhere. Payment processors and app-store reviewers both ask.2.3 If you use the Services on behalf of an organization, these Terms bind that organization, and you represent that you have authority to accept them for it.
2.4 You may not use the Services if you are located in, or ordinarily resident in, a country or region subject to comprehensive economic sanctions applicable to either party, or if you appear on an applicable restricted-party list. You are responsible for your own export-control compliance.
This section exists because the previous version of these Terms got this wrong, and we would rather correct it in the open than quietly.
3.1 The Software is licensed by its own LICENSE file. Each release of the Software ships with a LICENSE file. That file is the licence. Every version of the Software released to date is licensed under the MIT License. Under it you may use, copy, modify, merge, publish, distribute, sublicense, and sell the Software, including commercially, subject only to the notice requirement in the licence text itself.
3.2 These Terms impose no restriction on the Software. Nothing in these Terms — including the acceptable-use and restriction sections that follow — limits what you may do with a copy of the Software you hold. Specifically, and without limiting the licence you already have:
You may run the Software for any purpose, including commercial purposes, on any number of machines, without telling us and without an account.
You may modify it, fork it publicly or privately, and keep your changes to yourself forever.
You may study, audit, decompile, and reverse engineer it. It ships as readable source; there is nothing to conceal and we are not going to pretend otherwise.
You may redistribute it and you may sell it, on the terms of the licence you received it under.
You may build products on it and sell those products, including products that compete with ours.
You may operate a hosted service built from the Software and offer it to other people, subject to §4 (you must not use our Marks to do it) and §8 (you must not use our Services to do it).
3.3 We do not claim sole ownership of the Software. Copyright in the Software is held by its contributors. The LICENSE file in the shipped releases reads "Copyright (c) 2026 MeterCall contributors", and the repository history records who wrote what. Version 1.0 of these Terms stated that the software was owned by AiTrade LLC. That was inaccurate as to the codebase, and this version withdraws it. What we do own is set out in §16.
3.4 Support is not part of the licence. We are not obliged to support, maintain, update, or fix the Software you run yourself, and no version of these Terms creates that obligation. Support commitments, if any, come from a separate written agreement or from a paid Service, not from the licence.
3.5 Reservation of rights and forward notice. Read this carefully; it is the only forward-looking claim in this document.
railcall.ai carries three unqualified statements of permanence: "Nothing here is gated, metered, or seat-counted — and it stays that way"; "This is the part that never changes and never costs anything"; and "This is the free layer everything else is built on, and it stays free." A reservation of rights is weakest exactly where the marketing promised permanence, and a customer who relied on those sentences has a reasonable argument that we represented otherwise. Three ways out, and the decision is a business one: (a) soften the homepage to match §3.5 — "free today, and any change is version-forward only, never retroactive"; (b) keep the homepage and narrow §3.5 to new components only, giving up the option on future versions of existing components; or (c) publish both and accept that (a) estoppel argument. Do not leave it unresolved — it is cheap to fix in one sentence of homepage copy and expensive to argue later.This is the section that matters most, and it is the one we will actually enforce.
We gave the code away. We did not give away the name. The Marks are owned by AiTrade LLC, they are not licensed by the MIT licence on the Software, and no fork, redistribution, or modification of the Software carries any right to use them. This section applies to everyone, whether or not you use the Services and whether or not you have an account. The operative detail is in the Trademark Policy.
4.1 What you may do without asking. You may use the word "RailCall" truthfully, to say true things:
This is nominative use, we do not require permission for it, and we will not send you a letter about it. Keep it accurate and keep it in plain text — a claim of compatibility is not a licence to use our logo.
4.2 What you may not do. You may not, without our prior written permission:
4.3 Modified builds must be identified as modified. If you distribute a modified version of the Software, do not present it under our name, and do not present its behaviour as ours. This protects your users as much as it protects us: a receipt is only worth something if the thing that issued it is what it says it is.
4.4 Quality and confusion. We may require you to stop a use of the Marks that is likely to cause confusion, that misrepresents the origin of software, or that attributes to us a security property, certification, or verification result that does not exist. We will say what the problem is and give you a reasonable period to fix it before doing anything else, unless the use is fraudulent or is causing active harm.
4.5 This is not a code restriction, and we will not use it as one. We will not assert trademark rights to stop you from forking, modifying, redistributing, selling, or hosting the Software under a name of your own. If we ever do, that is a breach of this paragraph and you should hold us to it.
CounselThis section is drafted to be enforceable on its own terms and independent of the copyright position. Please confirm (i) the ownership recital in the §4 opening paragraph is accurate for AiTrade LLC, (ii) whether the separate published Trademark Policy page should carry the operative detail with this section incorporating it by reference, and (iii) whether §4.2 (last bullet) should include a domain-recovery/UDRP mechanic.5.1 Grant. Subject to these Terms and to your payment of any applicable fees, we grant you a limited, non-exclusive, non-transferable, revocable right to access and use the Services for your own purposes, including your organization's commercial purposes.
5.2 The Services are optional. The Software runs without them. The local engine has no runtime dependency on any RailCall-operated service: once installed, it runs, executes workflows, and writes and verifies receipts with no outbound connection to us at all. You reach a Service only when you choose to use one.
Stated precisely, because the difference matters. Getting the Software does involve us: the install script is served from railcall.ai and fetches pinned release files, and checking for an update is an outbound request by design. That is distribution, not a runtime dependency — you can mirror the release, install from a copy, or install on a machine that never speaks to us again, and nothing degrades. The claim we make is about running, and it is the one that is true.
5.3 What we may change. The Services are a live system. We may add, change, deprecate, or remove features. §11 states what we commit to when we do.
6.1 Some Services require an account. Provide accurate information and keep it current.
6.2 You are responsible for the confidentiality of your credentials, API keys, and tokens, and for everything done under your account. Tell us promptly at legal@railcall.ai if you believe your account or a key has been compromised, so we can revoke it.
6.3 Do not share credentials across organizations, and do not use another party's account without their authorization.
6.4 We are not liable for loss arising from credentials you failed to protect, other than to the extent the loss was caused by our own failure.
6.5 Local key hygiene. Keys you hold locally — provider keys in your vault, signing keys, receipt stores — are yours to protect. We recommend restrictive file permissions (0600) on the local vault. We cannot recover a local key for you, by design: we do not hold it.
The Acceptable Use Policy applies to the Services and is part of these Terms. In summary, you may not use the Services:
These restrictions apply to the Services. They are not, and must not be read as, restrictions on what you may do with the Software on your own hardware.
Because §7 incorporates the Acceptable Use Policy into these Terms, the two documents have to agree, and Version 1.0 of each did not. AUP v1.0 §2.4 prohibited "using RailCall to build a competing product without license" and §2.7 prohibited "reverse engineering RailCall for competitive purposes" — the same two acts §3.2 of this document expressly permits. Both are deleted in AUP v2.0, which ships in the same change as this version and adopts the same Software/Services split. If you are ever reading a version of the Acceptable Use Policy that restricts what you may do with the Software, §3.2 and §0.3 govern and that restriction is void.
CounselConfirm AUP v2.0 is adopted and published in the same deploy as this version. If for any reason it is not, the incorporation sentence at the head of this section must be cut before this page ships — otherwise these Terms both grant and prohibit the same conduct, which is the defect Version 1.0 was rewritten to remove.These are the restrictions we can actually enforce, because they concern systems we operate. Each is scoped to the Services on purpose.
8.1 No circumvention. You may not, in respect of the Services:
This paragraph concerns checks a Service performs. Checks your own installation performs on your own hardware are yours to configure. Local signing, local receipt issuance, and local receipt verification are functions of the Software, they run on your machine, they are MIT-licensed, and §3.2 expressly permits you to modify and reverse engineer them. Turning off receipt signing on your own station is not a breach of anything — it is a configuration choice, and the only person it costs is you, because what you lose is your own evidence. Version 1.0's cardinal error was writing restrictions that reached the customer's machine, and re-committing it here would also be unenforceable in practice: detecting it would require visibility into your system that §11.2 and §12.3 promise we do not have.
What remains prohibited is passing off the result: presenting something as carrying a RailCall signature, receipt, or verification when it does not. That is the second bullet above, and it is a misrepresentation claim, not a claim about what runs on your computer.
8.2 Verification is not restricted, and never will be. §8.1 does not restrict, and we will not read it to restrict: studying how signing, receipts, entitlements, or verification work; independently implementing a verifier; publishing a verifier; verifying our receipts, signatures, and evidence with tools you wrote yourself; or publishing the results of doing so, including results that make us look bad. The verification path is meant to be checkable by anyone without our permission and without our software, and if it ever stops being checkable, that is our defect. Security research on the Services conducted in good faith, without degrading the Services or accessing other users' data, is likewise not a breach of §8.1.
8.3 No resale or white-labelling of the Services. You may not resell, sublicense, rent, lease, timeshare, white-label, or otherwise make the Services available to a third party as your own offering, or as a component of your offering, without a written agreement with us. Using a Service on behalf of your own organization, its affiliates, and contractors acting under your direction is not resale. Using a Service to deliver work product to your clients — where they receive the output, not access to the Service — is also not resale.
8.4 No competing hosted service built from our Services. You may not use the Services to develop, train, or operate a hosted or managed service that substantially replicates a Service and is offered to third parties.
Benchmarking is not in that list, deliberately. Version 2.0 as first drafted prohibited using the Services to "benchmark for publication," which contradicted §8.2 of this document and §2.3 and §3.3 of the Trademark Policy in the same breath. You may benchmark the Services, publish the numbers, and publish them when they are bad for us.
This restriction covers our Services. It does not cover the Software. You are free to fork the Software and operate a competing hosted service built from it — the MIT licence permits that, §3.2 confirms it, and we are not going to argue otherwise. What you may not do is build that competing service on top of, or out of, the systems we run and pay for. Use your own infrastructure and your own name (§4), and we have no complaint.
8.5 No scraping or bulk extraction. You may not use crawlers, scrapers, or automated means to extract data from the Services except through an API we publish for that purpose and within its documented limits, and except as a published robots.txt permits. You may not systematically copy Marketplace listings, catalogue metadata, pricing, publisher information, or user information, and you may not use the Services to build a competing index or dataset of them.
Counsel / OpsThis clause and our own robots.txt currently disagree.app/robots.ts allows / for every user agent with no disallow, so the file this paragraph defers to affirmatively invites the crawl it prohibits. It also reaches only account holders: against a scraper with no account there is no contract here, and after hiQ v. LinkedIn there is no Computer Fraud and Abuse Act claim over publicly served pages either. Decide which is true. If the catalogue is worth protecting, disallow the listing and seller paths for non-search agents and rate-limit them; if it is not, this clause is decoration and should say less.8.6 No interference. You may not probe or stress-test the Services in a way that degrades them, circumvent access controls, or attempt to gain access to another user's data or account. Good-faith security research within §8.2 is excepted.
8.7 No reverse engineering of non-public Service interfaces. You may not reverse engineer the non-public internals of the Services in order to circumvent §8.1 or to build a substitute for a Service under §8.4. For the avoidance of doubt, this does not apply to the Software, which ships as source and which you may reverse engineer freely under §3.2, and it does not apply to anything within §8.2.
8.8 Non-circumvention of the Marketplace. Marketplace non-circumvention is stated once, in Marketplace Terms §8, and it binds Publishers. It is not restated here.
Why it moved. This section previously carried its own version, running twelve months from the introduction, while Marketplace §8.2 runs twelve months from the Buyer's most recent transaction. Two clocks and two triggers for one obligation is a drafting defect, not a belt-and-braces. Worse, the version here bound "you" — which on this page means every account holder, so it purported to stop buyers from transacting off-platform. We do not want that term, it appears nowhere in the Marketplace Terms a buyer actually reads, and it is not defensible. The Marketplace version is the one we keep: one clause, publisher-side only, one clock, with the burden of proving that a relationship was first sourced through the Marketplace on us.
8.9 Consequences. A breach of this section may result in rate limiting, suspension, or termination under §17, and in the case of §8.1 may also result in revocation of issued entitlements.
9.1 The Marketplace is a Service. Publishing on it, and buying through it, is governed by the Marketplace Terms, then by these Terms for anything those terms do not cover.
9.2 Fees, stated in full. As published on railcall.ai/pricing: the seller fee is 0%, the publisher keeps 100% of the list price, and a 15% buyer assurance fee is charged to the buyer on top of the listed price. Nothing is deducted from the publisher; the assurance fee is what funds the guarantee, and it is disclosed to the buyer at checkout as its own line. Both fees are disclosed on the pricing page and in checkout. Those two fees, the deductions listed in Marketplace Terms §6.4, and taxes are the complete set of amounts we take from a sale — Marketplace §6.5 states the closed list and controls over this paragraph.
CounselVersion 0.1 of the Marketplace page stated "the listed price is the price you pay — RailCall does not add hidden fees at checkout," which was inconsistent with a buyer-side fee, and disclosed only the seller fee in its publisher section. Marketplace Terms v1.0 deletes that sentence and discloses both fees together at §6.1 and §6.2; it ships in the same change as this document, so no further correction is outstanding there. Still to confirm: consumer-protection disclosure requirements for the buyer-side fee in each jurisdiction where checkout is offered, before paid transactions are enabled — now at 15% rather than the 10% that figure was assessed against.Counsel — rate change of 2026-08-27This paragraph carried 5% seller / 10% buyer, publisher keeps 95% on publication day and was changed to 0% / 15%, publisher keeps 100% by the change order of 2026-08-27. Marketplace Terms §6.7 requires not less than 30 days' notice of a rate change, prospective only; the seller-side reduction is favourable and immediate, the buyer-side increase is not. Set and publish the effective date for the buyer-side increase, and record which schedule governed which period for sales that have already settled.Counsel / Ops — “as published on railcall.ai/pricing” is not yet trueThis paragraph asserts what the pricing page says, and that page is outside this application. railcall.ai/pricing is served by nginx from static files on the server, not from the Next.js app that renders this document, so the 0% / 15% correction applied here could not be applied there in the same change. The static page was last observed carrying the superseded 5% seller / 10% buyer / keep 95%schedule. Until it is republished at 0% / 15%, the words “as published on railcall.ai/pricing” and “both fees are disclosed on the pricing page” in §9.2 describe a state of affairs that does not exist, which is the same defect — one live surface contradicting another — that this revision exists to remove. Republish the static pricing page at 0% / 15% / keep-100%, or amend §9.2 to stop sourcing the fee schedule to it. The identical assertion appears at railhub.ai/terms.html §9.2 and needs the same fix.Counsel / Founder — live pricing conflictThe live pricing page, fetched 2026-08-27, advertises "optional featured placement available" alongside "no listing fees." Marketplace Terms §6.1 promises "no placement fees, no featuring fees" and §6.5 says we do not charge "to be featured"; §3.2 promises that search ranking and category placement apply the same rules to first-party and third-party Listings. A paid placement product and those three clauses cannot both be true. Decide which one goes, and do it before either publishes.9.3 We are not a party to the underlying transaction between a publisher and a buyer except as the Marketplace terms state. We do not warrant any third-party listing.
10.1 Local execution is free and is not metered. Running the Software on your own hardware costs nothing, is not charged by us, and is not counted by us. We do not meter workflows, runs, actions, or machines you execute locally, and we will not introduce a charge for local execution of a version you already hold. This is a term of these Terms, not only a marketing statement.
10.1a What §10.1 does not say. It is a promise about the Software, not a promise about how paid Services are priced. A paid Service may be charged per organization, per unit of deployed capacity, per seat, prepaid, or transactionally — §10.3 lists the shapes and railcall.ai/pricing states the current model. Nothing in §10.1 commits us never to price a Service per seat, and you should not read it that way.
Counsel — do not restore the absoluteAn earlier draft of §10.1 said local execution "is not limited by seat, machine, user, workflow, or run," as a term of the contract. That went further than the business can stand behind and is narrowed above. Verified 2026-08-27: the live for-teams page sells the Team tier at "$100 per seat per month, two seats minimum, with a 14-day free trial," while the live pricing page says of RailHub "priced per org · unlimited users · never per seat"; and this repository's own pricing component records that the billing API returns{"min_seats":2,"free_seat_cap":1,…} with the free cap enforced server-side — a 403 on the first colleague invited — together with a standing instruction not to re-add an absolute "never per seat" promise while the biller still charges per seat. §10.1 as narrowed is true under every one of those. Do not widen it again until the biller, the pricing page, and the for-teams page say the same thing.10.2 Current prices. Prices for paid Services are published at railcall.ai/pricing. That page is the authoritative price list, and it controls over any figure stated anywhere else, including in this document. We deliberately do not restate prices here, because a price written into a legal document goes stale and then contradicts the page customers actually read. Version 1.0 of these Terms made exactly that mistake.
Counsel — pricing unresolvedPricing must be settled before adoption. Four different price models are simultaneously live or asserted inside the business: (1) railcall.ai/pricing, fetched 2026-08-27, shows the protocol at $0 forever, RailHub priced per org, "unlimited users," "never per seat," and Marketplace 5% / 10% / 95% — a schedule superseded the same day by the 0% seller / 15% buyer / keep-100% change order, which is what §9.2 and the Marketplace Terms now state. (2) The published Terms v1.0 §7 states "$100 per seat / month, minimum 2 seats, 14-day free trial." (3) The website repository's pricing component reads live values from the billing API GET /billing/pricing, which returns{"min_seats":2,"trial_days":14,"price_per_seat_month_usd_cents":10000,"free_seat_cap":1} — i.e. the biller charges $100/seat with a 2-seat minimum and enforces a 1-seat free cap. The deployed page and the repository component do not agree. (4) The brief for this draft specifies "$9 per node all-in, $0 usage inside," a figure that appears nowhere on the live site. No price should be written into these Terms until the biller, the pricing page, and the repository agree. §10.2 is drafted to be correct under any of the four outcomes.10.3 How paid Services are charged. Depending on the Service, charges may be:
10.4 Prepaid balance. Where a Service is prepaid:
10.5 Included usage. Where a paid unit includes usage, requests within that inclusion are not separately metered or surcharged. We will not introduce a usage surcharge inside an existing paid unit during a term you have already paid for.
CounselConfirm this commitment is one the business wants to make contractually, and that it matches how the meter actually behaves.10.6 Taxes. Prices exclude taxes. You are responsible for any sales, use, VAT, GST, or similar taxes, other than taxes on our income.
10.7 Refunds.
10.8 Non-payment. If an invoice goes unpaid, we may suspend the paid Service after notice and a reasonable opportunity to cure. You remain liable for amounts already incurred. Suspension of a Service never disables the Software on your machines, never revokes a licence you hold in it, and never touches your local receipts, vault, or data.
We would rather state this honestly than promise a number we cannot keep.
11.1 No uptime commitment. We do not commit to a specific uptime percentage for the Services, and these Terms contain no service-level agreement. The Services may be unavailable for maintenance, for reasons outside our control, or because something broke. If you need a contractual availability commitment, that comes from a separate written agreement.
CounselConfirm no SLA has been contractually committed to any existing customer. The site's Enterprise material references a "contractual SLA + incident response commitment," which if offered would need to be reconciled with this section — either by carving out signed agreements (as drafted) or by publishing an actual SLA.11.2 The Software does not depend on us being up. This is the point of the architecture, and it is the reason §11.1 can be honest. If our Services are down, your local station keeps running, your receipts keep being written, and your workflows keep executing. What you lose is access to the hosted pieces.
11.3 Changes and deprecation. We may change the Services. For a change that materially and adversely affects a paid Service you are actively using, we will give at least 30 days' notice by the method in §21 before it takes effect, unless the change is required for security, legal compliance, or to stop active abuse — in which case we will act first and tell you as soon as we reasonably can.
11.4 Beta and preview. Anything we label beta, preview, alpha, or experimental is provided as-is, may change or disappear without notice, is excluded from §11.3, and should not be relied on in production.
12.1 You own Your Content. We claim no ownership of your code, workflows, configurations, data, or output.
12.2 The licence we need, and no more. You grant us a limited licence to host, store, transmit, display, and process Your Content solely to operate and provide the Services to you, and to comply with law. That licence ends when the content is deleted or your account is closed, except for backups on their ordinary rotation and records we must keep by law.
We do not use Your Content to train models, and we do not sell it or license it to anyone who will. Where a Service routes your content to a third-party inference provider — hosted compose is the one path that does this — we commit to contracting for zero retention and no training on transmitted content, and to naming that provider in the Data Flow Disclosure and the subprocessor list. What we cannot honestly do is promise, in our contract, what a company that is not a party to it will do. So the promise is stated as what it is: an absolute commitment about our own conduct, and a procurement obligation as to theirs. If we ever cannot obtain those terms from a provider, the honest response is to say so on the Data Flow page rather than to keep a flatter sentence here.
CounselUnverified as of drafting. The absolute form of this sentence — "we do not use Your Content to train models," full stop — could not be confirmed for hosted compose, because the downstream inference provider's own terms were not reviewed. The clause above is drafted to be true either way. Two things to close it out: (1) confirm the provider contract actually carries zero-retention and no-training terms, and if it does, this can be restated flat; (2) confirm the provider is named on the Data Flow page and in the subprocessor list, which §13.5 and Art. 13 both require.12.3 Content that never reaches us. Most of what RailCall does never touches our systems. Your provider keys stay in your local vault. Approved actions go directly from your machine to the provider you chose. Local receipts and audit records are written to your disk. The Data Flow Disclosure lists the flows that leave your machine, when they happen, and where they go. These Terms govern the content you actually send to a Service. They do not create rights for us over content that never arrives.
CounselAn earlier draft said the Data Flow Disclosure describes exactly what leaves your machine. That word was not survivable: §1 of this document defines the Services to include entitlement issuance, licence and key minting, and metering, and the disclosure's table covers none of those, nor Marketplace checkout and install fetch, publisher key registration, or the installer and update fetch. The word is removed here and the table is extended in the same change to cover them. Re-check the table against the code before adoption and restore a stronger word only if it holds.12.4 Your responsibility for what you send. You are responsible for having the right to submit Your Content, and for its lawfulness. If you send us personal data, the Privacy Policy governs how we handle it.
12.5 Data processing agreement. If we process personal data on your behalf, a processor DPA is available on request to any customer, at no charge and regardless of tier.
CounselVersion 1.0 of the Security page gated the DPA to "Enterprise customers upon request," while the Trust page offered it on request with no tier gate. Under GDPR Art. 28 a controller is entitled to the terms whenever we act as processor, so this section adopts the ungated version and the Security page is corrected to match in the same change. Confirm the DPA itself exists as a signable document — an ungated offer of a document nobody has drafted is worse than a gated offer of one that exists.12.6 Deletion. You may delete Your Content and close your account at any time. On closure we delete or de-identify account data per the Privacy Policy's retention schedule. Data on your own machines is untouched by any of this — we cannot reach it and closing an account does not remove it.
Preserved from Version 1.0 because it was accurate.
13.1 Bring your own keys. When you configure keys for connected services such as Slack, Stripe, or GitHub:
13.2 Controller roles for connected-service action content. For content sent from your machine to a connected provider: you are the data controller; the provider is your processor or an independent controller, per your arrangement with them; AiTrade is neither, because that content never reaches us. This allocation concerns action content only. For account data that you do send us, AiTrade is the controller, as the Privacy Policy states.
13.3 Third-party terms. Each connected service is governed by its own terms and privacy policy. You agree to comply with them. We make no warranty about any third-party service, and we are not responsible for their acts, outages, pricing, or decisions.
13.4 MCP. Local MCP connections to an AI assistant are loopback or stdio sessions with no network egress to us. The MCP host sees what you put into it, on its own terms. RailCall governs the execution locally with dry-run, approval, and receipts. Complying with the MCP host's terms is your responsibility.
13.5 Hosted compose. If you choose to use a hosted composition Service, your prompt content is transmitted to us and onward to an inference provider in order to fulfil that request. This is the one path where content you author reaches our infrastructure, it happens only when you choose that Service, and the Data Flow Disclosure describes it.
CounselConfirm the hosted-compose data path, retention, and the identity of the downstream inference provider are disclosed accurately on the Data Flow page and in the subprocessor list.14.1 No certification is claimed. We do not hold, and these Terms do not represent that we hold, a SOC 2 report, HIPAA certification, PCI DSS attestation, ISO 27001 certification, or any equivalent. Where our public material describes a target date for an independent report, that is a target, not a report.
14.2 What we actually have is published at railcall.ai/trust and railcall.ai/legal/security, and those pages limit themselves to what can be backed by an artifact today: adopted written policies, a documented security risk analysis, a published threat model, a complete list of subprocessors, and an architecture in which the local engine has no runtime dependency on any service we operate. Read those pages rather than this one for the current state; they are maintained, and a Terms of Service is the wrong place to keep a security fact fresh.
14.3 Compliance is a shared outcome, and most of it is yours. Product controls are one input to your regulatory posture. How you configure, deploy, operate, and supervise the system is the rest of it, and that part is yours. No property of our software makes your organization compliant with anything.
14.4 We report incidents. If a security incident affects Your Content or your account data, we will notify you without undue delay and within any period the law requires, and we will tell you what we know rather than the minimum we can get away with.
14.5 What Version 1.0 said, and why it is gone. Version 1.0 §10 stated that RailCall is "100% compliant with the HIPAA §164.312 technical safeguards." That claim is withdrawn in full and does not appear anywhere in this document. There is no such certification for a software vendor to hold, we do not hold one, and an unqualified compliance assertion is a representation we cannot support.
Counsel — HIPAA claim withdrawn site-wideResolved in this change, not deferred. The “100% HIPAA compliant” assertion has been withdrawn from every surface that carried it — the Enterprise and Teams pages, the Security page, and the four marketing components. What remains is the claim we can actually support: the §164.312 technical safeguards are mapped and implemented, and the evidence is cryptographic. Two things still need counsel. First, whether “SOC 2 audit in progress” and “independent audit in flight” are supportable as written, since neither has produced an artifact. Second, that the deployed site is built from something other than this working tree — see the publication blockers above — so this correction only reaches users once the deploy path is resolved.CounselVersion 1.0 of the Security page stated that the gateway runs on "AWS (or GCP)" with EBS/S3/KMS/CloudWatch/RDS/Secrets Manager, while the published subprocessor list names Render, WorkOS, Stripe, Resend, GitHub, and Cloudflare, and railcall.ai resolves to a DigitalOcean address — a GDPR Art. 13/28 subprocessor-disclosure defect. The Security page and the Privacy Policy are both corrected in this change: the incorrect vendor names are removed and both point at the single maintained subprocessor list. The underlying question is still open — confirm the actual hosting, database, secrets, and logging providers and restore concrete names, because removing a wrong disclosure is only half of an Art. 13 fix. The same page's password-hashing primitive (bcrypt on the Security page, argon2id on the subprocessor page) is likewise flagged rather than guessed.If you send us feedback, suggestions, or ideas about the Services, we may use them without obligation, restriction, attribution, or payment. This does not give us any right in your code, your products, or anything you build. Do not send us anything confidential that you do not want used on those terms.
Stated precisely, because Version 1.0 was not.
16.1 What AiTrade owns:
16.2 What AiTrade does not own or claim:
16.3 These Terms transfer nothing. No ownership passes in either direction.
17.1 By you. Close your account at any time, from the dashboard or by contacting us. You do not need a reason.
17.2 By us, for cause. We may suspend or terminate your access to the Services for: breach of these Terms or the Acceptable Use Policy; breach of §8; non-payment after notice and an opportunity to cure; illegal activity; or conduct that presents a genuine security or legal risk to us, to the Services, or to other users. Where the circumstances allow it, we will give notice and a chance to fix the problem first. Where they do not — active abuse, fraud, an ongoing attack, a legal demand — we may act immediately and will tell you promptly afterwards.
17.3 By us, without cause. We may discontinue a Service, or stop offering it to you, on 30 days' notice, and will refund the unused portion of anything you prepaid for it under §10.7.
17.4 Effect of termination. Your right to use the Services ends. We may delete your account data per the Privacy Policy retention schedule.
17.5 What termination does not do. This is the paragraph that matters most, and it is unconditional:
It does not terminate your licence in the Software. The LICENSE file governs that, we cannot revoke it by terminating an account, and we do not purport to.
It does not disable, deactivate, time-bomb, or degrade software running on your machines.
It does not touch your local data — your vault, your keys, your receipts, your audit chain, your workflows. Those are on your hardware and they stay there, readable and verifiable, whether or not you ever speak to us again.
It does not invalidate receipts already issued. A receipt is verifiable offline against a published key. Ending an account does not un-sign anything.
17.6 Export before you go. Before termination takes effect, and for 30 days afterwards where we terminate you, you may export your account data and anything you have stored in a Service, in a machine-readable form.
CounselConfirm the 30-day post-termination export window is operationally deliverable before committing to it.17.7 Survival. The following survive termination, together with any provision that by its nature should: §3 (the Software, in full), §4 (trademarks), §8.2 (verification is not restricted), §10.6 (taxes), §10.7 (refunds, as to amounts already owed), §10.8 (amounts already incurred, and what suspension never does), §12.1 (you own Your Content), §12.2 (the licence ends, with its backup and legal-records carve-out), §12.6 (deletion), §13.2 (controller roles), §14, §15, §16, §17.5 (what termination does not do), §17.6 (export), §18, §19, §20, §21.4, §22, and §23.
§17.5 survives whatever else does not. It is called unconditional two paragraphs above, so it is named here rather than left to "by its nature" — a survival list that omits the clause the page describes as the one that matters most is the kind of drafting slip that gets read against us later. The same reasoning adds §10.8, §12.2, §13.2 and §21.4, each of which does work only after the relationship has ended.
THE SERVICES ARE PROVIDED "AS IS" AND "AS AVAILABLE," WITHOUT WARRANTY OF ANY KIND. To the maximum extent permitted by law, AiTrade disclaims all warranties, express, implied, and statutory, including merchantability, fitness for a particular purpose, title, non-infringement, and any warranty arising from course of dealing or usage of trade.
We do not warrant that the Services will be uninterrupted, timely, secure, or error-free; that they will meet your requirements; that any result obtained through them will be accurate or reliable; or that any third-party service will be available.
The Software is provided under its own licence, and that licence contains its own warranty disclaimer. Nothing in this section adds to or subtracts from it.
Automation carries risk that is yours to manage. RailCall is designed to make automated action reviewable — dry-run previews, approval gates, and signed receipts exist so that you can see what will happen before it happens and prove what did happen afterwards. Those are controls, not guarantees. You are responsible for what you approve and for what your automation does. We do not warrant the correctness of any action a model proposes.
Some jurisdictions do not allow the exclusion of implied warranties. Where that is so, the exclusions above apply only to the extent permitted, and you may have rights that these Terms cannot remove.
TO THE MAXIMUM EXTENT PERMITTED BY LAW:
19.1 Neither party will be liable for indirect, incidental, special, consequential, exemplary, or punitive damages, or for lost profits, lost revenue, lost data, or business interruption, arising out of or relating to these Terms or the Services, even if advised of the possibility.
19.2 Cap. AiTrade's total aggregate liability arising out of or relating to these Terms or the Services will not exceed the greater of (a) the fees you paid us for the Services in the twelve months before the event giving rise to the claim, or (b) one hundred US dollars (US$100).
19.3 Actions you approve. We are not liable for the consequences of actions you approve to connected services. You direct those flows, they leave your machine and go directly to the provider, we are not in the path, and the provider is your counterparty.
19.4 The Software. Liability in respect of the Software is governed by the warranty and liability terms of its own licence, not by this section.
19.5 Exceptions. Nothing in these Terms limits liability that cannot lawfully be limited, including liability for fraud, fraudulent misrepresentation, death or personal injury caused by negligence, or a party's wilful misconduct.
19.6 Some jurisdictions do not allow these limitations. Where yours does not, they apply only to the extent permitted.
19.7 Basis of the bargain. The allocation of risk in §18 and §19 is a fundamental part of the terms on which the Services are offered at their price, and both parties acknowledge it as such.
20.1 You will defend, indemnify, and hold harmless AiTrade and its officers, employees, and agents from third-party claims, damages, liabilities, and reasonable costs (including legal fees) arising from:
20.2 Scope note, deliberately included. The third bullet is limited to content you actually send to a Service. Version 1.0 indemnified us against "content you transmit via RailCall," which was inconsistent with the rest of our own documentation: most action content never reaches us, and we should not be indemnified against content we never receive.
20.3 Process. We will notify you promptly of any claim, give you sole control of the defence (except that you may not settle in a way that admits our liability or imposes an obligation on us without our consent), and cooperate at your expense.
21.1 We may change these Terms. We will publish the updated version with a new version number and effective date, and keep the prior version accessible at a stable URL.
CounselThis commitment and the equivalent one in Marketplace §18 both become false the moment these pages deploy, because Version 1.0 of these Terms, Version 1.0 of the Acceptable Use Policy, and Version 0.1 of the Marketplace Terms are each served at exactly one URL and are overwritten by the new version. Ship snapshot routes —/legal/terms/v1.0, /legal/acceptable-use/v1.0, /legal/marketplace/v0.1 — in the same change, or delete the commitment from all three documents. Keeping superseded versions readable is also what makes §25 and the equivalent change logs checkable rather than merely asserted.21.2 Notice. For a material change, we will give at least 30 days' notice before it takes effect, by all of the following that apply: in-product notice in the dashboard; email to the address on your account, if you have given us one; and a dated entry on this page. Continued use of the Services after the effective date is acceptance. If you do not accept, stop using the Services and close your account before that date; we will refund any unused prepaid balance under §10.7.
21.3 Why the notice method changed. Version 1.0 promised notice "via email or in-product notice." Most people who run RailCall have no account and have never given us an email address, which means email could not reach them and a term they never saw was purporting to bind them. Under this version, that problem largely resolves itself: these Terms bind only people who use the Services, and using a Service means we have a way to reach you. The dated public entry on this page is the backstop.
CounselConfirm a versioned public changelog on this page is adequate notice for account holders in the relevant jurisdictions, alongside in-product and email notice.21.4 Changes to the licence on the Software are not changes to these Terms, are not made through this section, and never apply retroactively to a release already made. See §3.5.
22.1 Governing law. These Terms are governed by the laws of the State of Florida, USA, without regard to conflict-of-law principles.
CounselFlorida is carried forward from the published Version 1.0. Confirm it matches the entity's actual state of formation and principal place of business, and whether a Delaware or other choice is preferable.22.2 Informal resolution first. Before filing anything, email legal@railcall.ai with a description of the dispute and what you want. We will do the same for you. If it is not resolved within 30 days, either party may proceed. This step is a condition, not a formality — most disputes end here and it costs both sides nothing to try.
22.3 Arbitration. Any dispute not resolved under §22.2 will be settled by binding arbitration administered by the American Arbitration Association under its applicable rules, seated in Florida. Judgment on the award may be entered in any court of competent jurisdiction.
22.4 Carve-outs. Either party may (a) bring an individual claim in small-claims court, and (b) seek injunctive relief in court to protect intellectual property, including trademark rights under §4, or confidential information.
22.5 No class actions. Claims must be brought individually and not as a plaintiff or class member in any purported class or representative proceeding, and the arbitrator may not consolidate claims. Where this paragraph is unenforceable as to a particular claim, that claim proceeds in court and the rest of this section stands.
22.6 Opt-out. You may reject §22.3 and §22.5 by emailing legal@railcall.ai within 30 days of first accepting these Terms, saying so and identifying your account. Opting out does not affect any other part of these Terms and we will not treat it as a reason to refuse you service.
Counsel — review whole section§22.3 to §22.6 are carried forward and expanded from the published Version 1.0, which contained an unqualified AAA arbitration clause with a jury and class-action waiver and no opt-out. Please advise on: enforceability against consumers and against non-US users; whether an opt-out and a small-claims carve-out should be included (drafted in, as the more defensible position); mass-arbitration and fee-allocation protections; whether AAA consumer rules apply and who pays filing fees; and whether the clause should be excluded entirely for users in jurisdictions where it will not be enforced. Also confirm the notice address in §22.2 and §24 — legal@railcall.ai is published on the current Terms but the support policy is Discord-only, and no one has confirmed the alias is monitored by a human.Legal and these Terms: legal@railcall.ai
Support: Discord — railcall.ai/discord
Entity: AiTrade LLC, a Florida limited liability company
Governing law: Florida, USA
Registered address: not yet published — see the counsel note below.
Counsel — registered address still requiredThe registered business address was requested and was not supplied, so it is not stated anywhere on this page. None has been invented. This is the single open ask for it on this document; §1 and §23 point here rather than repeating it. Provide it and it will be added to the entity blocks in the masthead, in this section, and in the page footer, on this domain and at railhub.ai/terms.html in the same pass.Not operative. Published because a correction nobody can read is not much of a correction.
Version 1.0 defined "the Service" to mean everything — the MIT-licensed code you run yourself and the hosted systems we operate, merged into one defined term. Every restriction it wrote then landed on both. The consequence was that the document granted a "limited, non-exclusive, non-transferable license… for your internal business or personal purposes" over software we had already released under MIT, with a README that says "Fork it. Use it. Ship on it." A licence cannot regrant less than it has already given away irrevocably. The fix is two defined terms — the Software and the Services — and a table at the top of this page saying which document governs which. Every restriction in this version is scoped to the Services and says so.
Two hostile reviews were run against this draft before publication. What they caught is listed here rather than silently patched, on the same principle as the rest of this section.
BYOK and key custody (v1.0 §5, now §13.1); the controller-role allocation for connected-service content (§13.2); the MCP loopback description (§13.4); account security responsibilities (§6); the feedback licence (§15); the liability cap structure and the US$100 floor (§19.2); Florida governing law (§22.1); entity name AiTrade LLC.
Entity: AiTrade LLC, a Florida limited liability company · Governing law: Florida · Last updated: August 27, 2026
See also: Licensing · Trademark Policy · Privacy Policy · Data Flow Disclosure · Acceptable Use