WHY notebookFactoryOS
User Agreement · Revision 2026-08-10

Factory-OS User Agreement

This agreement is between you (and the organization you represent) and Factory-OS, Inc. ("Factory-OS", "we", "us"), and governs your use of the Factory-OS service.

Plain-English summary

The full terms below control, but here is what they say, plainly:

  • Factory-OS is an early-stage development build. It may have bugs, may lose data, and may change substantially. If we discontinue the service or terminate your account without cause, we will give 30 days' notice, keep your data exportable for 30 days after that, and refund the pro-rata unused portion of anything you prepaid. Don't rely on it for anything you can't afford to lose.
  • You own your data — projects, requirements, designs, validation records, attachments. Tenant isolation is enforced by the database on every query, so another organization's members cannot read it. We do not sell data that identifies you, your organization, your people, or your parts, and we don't share it with advertisers. Owning your data and licensing uses of it are different things — the next bullets are the licenses, and which apply depends on the mode your organization chooses.
  • We use your content in up to three ways, and you control the third. (1) To operate the service — every mode, necessarily. (2) To run AI features for your own organization — analysis, recall, suggestions returned to you; the inference providers we engage are bound by API terms that prohibit them training on your content. (3) To learn across customers (the learning license below) — on by default, and your organization can decline it (no-training mode) without losing any AI feature.
  • In exchange for the service, organizations participating in cross-customer learning (the default) license us to learn from their work — specifically, to de-identify their content and learn from the de-identified result, not to train on raw engineering records. We use those derivatives to train, evaluate, and improve our AI and machine-learning systems, including models and aggregated industry insights we may offer as products in their own right. Trained models and de-identified derived data may be retained and used after your account closes. We do not intentionally publish, sell, or license anything that identifies you.
  • Failed and abandoned work is kept, de-identified. Dead ends are the most useful thing we learn from — they are how the product can tell the next team "this was tried." Your identifiable content is still deleted as described in Data retention, export, and deletion; the de-identified form is what remains. (Like the rest of the learning license, this applies to participating organizations — no-training mode declines it.)
  • Our engineers may access content only for specific reasons — a support request you made, a security or abuse investigation, a legal obligation, or diagnosing a failure — and, for organizations participating in learning, curating training data. We do not read no-training organizations' records for model improvement.
  • If Factory-OS is acquired or merges, this agreement — including the learning license — transfers with the business, and whoever takes over is bound by it. If your organization is in no-training or restricted mode, that opt-out transfers too: a successor inherits the exclusion, not a fresh start.
  • No-training mode — declining the learning license — is a switch in your organization's own settings (Settings → Data & learning, owner/admin), free, effective immediately, with no functional cost: every AI feature keeps working. One exception: free education workspaces. Participation in cross-customer learning is a condition of the free education tier, so the switch is locked while the education designation is active — see Choosing your mode. Restricted mode goes further: it also disables third-party AI inference entirely, for organizations whose obligations rule out any external model egress; AI features then require your organization's own local endpoint. See Choosing your mode below.
  • Industry-standard encryption in transit and at rest; database-enforced tenant isolation; multi-factor authentication including passkeys; tamper-evident, externally-anchored audit logs on sensitive operations.
  • We are not SOC 2 certified, not HIPAA covered, not PCI-DSS compliant, not FedRAMP authorized, not CMMC certified, and not approved for ITAR / EAR / USML / classified / export-controlled data. Don't upload that material here — in any mode, restricted included.
  • Service is provided AS IS with no warranties. See Limits, liability, term below.

Stage of development

Factory-OS is early-stage software under active development. Features may change, break, or be removed without notice. Performance, availability, and data durability are not guaranteed. There is no service-level agreement, no commitment to a future release, and no expectation that any feature you rely on today will continue to exist tomorrow.

We may suspend or throttle access immediately where we have cause (see Term and termination below). If we terminate your access or discontinue the service without cause, we will give thirty (30) days' written notice, your data will remain exportable for thirty (30) days after the effective date, and we will refund the pro-rata unused portion of any prepaid fees.

You acknowledge that you are using Factory-OS at your own risk, that you maintain alternative records of any data you cannot afford to lose, and that you do not depend on Factory-OS for safety-critical, mission-critical, or regulated workflows.

Data ownership and usage

You retain all ownership rights to the content you upload or generate in Factory-OS — project hierarchies, requirements, design decisions, validation outcomes, CAD files, attachments, and exported reports ("your content").

What we never do. We do not sell your identifiable data. We don't share it with advertisers. We don't disclose it to any third party except the subprocessors we use to operate the service (hosting, database, transactional email, optional integrations you explicitly connect — see Subprocessors below) or where required by law. Tenant isolation is enforced at the database layer on every operation, so members of other organizations cannot read or write your content.

We use your content in three distinct ways. The first two are how the product works; the third is a license your organization can decline.

Use 1 — operating the service. We process your content to display it, search it, connect engineering records to each other, generate your reports and exports, secure the service, take backups, and support you. This applies in every mode — it is what delivering the service means, and it involves no model training. Aggregate, non-identifying telemetry (counts of nodes created per phase, time-to-advance, error rates, feature usage) also informs product decisions in every mode.

We also run an internal review pass that looks at operational signals to decide what to fix next. Where that pass would read organization-authored text rather than counts, organizations in no-training or restricted mode are excluded from it, because its output can shape the product for every customer.

Use 2 — AI inference for your organization. Factory-OS's AI features — suggestions, recall of your prior failures, conflict checks, classification of your own records, quality analysis, the assistant — analyze your organization's content to produce answers for your organization. This is inference, not training: your content is processed transiently to return a result to you, and this use applies in standard and no-training modes alike (in restricted mode it runs only through your organization's own endpoint — see below).

Inference is not training. We engage AI inference providers only under enterprise or API terms that prohibit the provider from using customer inputs and outputs to train the provider's general-purpose models. This is a condition of our selecting them and it applies in standard and no-training modes alike. Declining the learning license therefore does not require giving up AI features: cross-customer learning is something we do under the license below, not something an inference provider is permitted to do in any mode.

Being precise about what that does not mean: "no training" is not the same as "no retention". A provider may retain inputs and outputs for limited periods for security, abuse prevention, service operation, or legal compliance, may permit limited provider personnel access for those purposes, and may process data in the regions its terms specify. Our subprocessor documentation records, per provider, the terms we rely on as we verify them in writing; where a provider's specific retention or training terms have not yet been verified, that documentation says so rather than implying more. We do not claim zero retention unless the provider contractually offers it and we have enabled it — where that is true, the subprocessor documentation says so specifically.

Use 3 — the learning license (cross-customer learning). This license applies only while your organization participates in cross-customer learning — the default; declining it is described under Choosing your mode below. Factory-OS gets better when its AI — suggestions, recall of prior failures, classification, quality analysis, manufacturing intelligence, and similar — learns from real engineering work.

The grant is deliberately two-step, so it is clear that your raw engineering records are not themselves the thing we commercialize. With this license in effect, you grant Factory-OS, Inc. a non-exclusive, worldwide, royalty-free license to:

  1. process your content solely to create de-identified or aggregated derivatives of it, applying the de-identification described below; and
  2. use those derivatives — not the raw content — to develop, train, fine-tune, and evaluate our current and future products, services, features, and machine-learning models (including models, datasets, and data products that may be offered, deployed, or licensed separately from the service), and to create and commercialize aggregated or de-identified insights (for example: industry benchmarks, failure-mode statistics, design-practice or supplier-performance indices) derived from content across customers.

What this means in practice: we need transient access to raw content in order to de-identify it, and step 1 licenses exactly that and nothing more. Your raw CAD, project records, and engineering decisions are not the licensed training asset — the de-identified derivatives are. Rights we need to actually run the product for you, and to run AI features for your own organization, come from Uses 1 and 2 above and are unaffected by this narrowing.

How de-identification actually works. Before content is used for training or evaluation — at every point where content or a derivative of it leaves the operating service for that purpose, including dataset exports and the nightly model-evaluation replay — we do two things, automatically and by default: we remove contact details (email addresses and phone numbers), and we substitute the identifiers the product has on record — your organization's name, your members' names, your project names, your part numbers, and your supplier names — with anonymous placeholders, consistently, so the substituted text keeps its structure without keeping your identity. Being precise about where this runs: curation records inside the service hold content in its original form (they are working records, access-controlled and logged); the de-identification is applied at the boundary where material is used for training or evaluation. The stated limit: free text that names something we have no record of (for example, a supplier you discussed but never added to the product) is not caught by substitution, and identifiers shorter than three characters are not substituted because doing so would corrupt ordinary text.

What we commit to, stated as a process rather than an absolute. We do not intentionally publish, sell, or license information that identifies a customer, organization, person, project, or part. We apply the documented de-identification controls above and other reasonable measures designed to prevent identification, and we prohibit recipients of licensed data from attempting re-identification. We state it that way deliberately: because the limits above are real — an unrecorded name in free text may not be caught — it would be dishonest to promise that no output could ever identify anyone.

How this squares with tenant isolation. Your raw content is not exposed to another tenant. Machine-learning models and aggregate statistics trained on de-identified content may serve every customer — that is the mechanism by which the product's intelligence improves — and we take reasonable measures designed to prevent model outputs from reproducing your identifiable content for another tenant.

Human review, and its limits. Authorized personnel may access customer content only where reasonably necessary to respond to a customer-authorized support request, investigate a security or abuse concern, comply with law, diagnose a service failure, or — for organizations participating in learning — curate training and evaluation data. Access is limited by role, logged, and reviewed. Content belonging to organizations in no-training or restricted mode is not accessed for general model improvement, dataset development, or training-data curation. We do not grant ourselves an open-ended right to read your engineering records.

Abandoned and failed work is retained, de-identified — deliberately. For organizations participating in learning: when you abandon an approach, kill a concept, or record a test that failed, that material stays in scope of the learning license and is retained in de-identified form even though the work itself went nowhere. We say this plainly because it is easy to assume discarded work is discarded everywhere: it is not, and the reason is that failed approaches are the most instructive thing an engineering corpus can contain — they are what let the product warn the next team that a path has already been tried. Deleting your account still deletes your identifiable content as described in Data retention, export, and deletion below; what survives is the de-identified form, same as everything else under Survival.

Survival. The license above survives account or organization closure with respect to de-identified or aggregated data, derived datasets, trained model parameters, and insights created while your account was active: we may retain and continue to use them after closure. Survival reaches only material created while your organization participated in learning — content produced after an opt-out is excluded from the corpus, so there is nothing of it to survive. Your identifiable raw content is handled per Data retention, export, and deletion below.

Change of control, and what transfers with the business. We may assign this agreement, in whole or in part, to a successor in connection with a merger, acquisition, reorganization, or sale of all or substantially all of our assets or of the business line to which the service relates. This agreement binds and benefits each party's permitted successors and assigns.

For the avoidance of doubt, what transfers in such a transaction includes the learning license granted above and everything created under it — your content as licensed, de-identified and aggregated derivatives, derived datasets, curated training and evaluation corpora, and trained model parameters — on the same terms and subject to the same limits stated here. A successor acquires no greater rights in your content than we have, and every restriction in this agreement continues to apply to them: we do not sell identifiable data, and neither may they.

We will give notice of a change of control through the service or by email. Your rights under Data retention, export, and deletion are unchanged by such a transaction — you may export your content and close your account as described there.

Choosing your mode: standard, no-training, restricted

Your organization operates in exactly one of three modes:

ModeCore platformAI features for your orgCross-customer learning (Use 3)
Standard (default)YesYes — shared modelYes — unless you decline
No-trainingYesYes — shared model (providers' API terms prohibit training)No
RestrictedYesOnly via your organization's own AI endpointNo

No-training mode (declining the learning license). Any organization may decline the learning license — with one stated exception, free education workspaces, described below — at no charge and with no functional cost: every platform capability and every AI feature keeps working exactly as in standard mode. What changes is one thing — your content is excluded from cross-customer training, evaluation, and insight corpora. Every ingestion path our code audits have identified enforces this in the product, at the point content would enter a corpus rather than at export time, and those checks are covered by automated tests that execute them against a real database. One path cannot be enforced in code — an operator manually curating text they have read — and is governed instead by stated procedure plus a permanent operator-access log; we treat any newly discovered gap as a defect to fix, not a permitted exception. If you need the current state of that enforcement in writing for a diligence review, ask us. The exclusion is prospective from when it is set; de-identified derivatives created while you participated are handled under Survival above. You set it yourself. An owner or administrator of your organization turns cross-customer learning off (or back on) in Settings → Data & learning. The choice takes effect immediately, the effective date is shown, and each change is recorded in an immutable audit entry. You do not need to ask us, and we do not need to approve it. An operator can also set it on request, which is recorded the same way.

Free education workspaces (the education carve-out). If your workspace is on the free education tier, participation in cross-customer learning is a condition of that tier: the learning license stays in effect, and the no-training switch is locked while the education designation is active — the product refuses the change server-side, including when our own operators attempt it. This is the exchange the free tier is offered on, and we state it here rather than leave it to a settings screen. The lock is exactly as wide as the designation: removing the education designation (for example, by moving to a paid plan — contact support) unlocks the switch, and both the removal and any later opt-out are recorded in the same immutable audit entries as every other mode change. Everything else in this agreement — tenant isolation, the de-identification requirement, deletion rights, and every security control — applies to education workspaces unchanged. If an education workspace's obligations require restricted mode, contact us: we will resolve the tier condition first rather than leave the two in conflict.

Restricted mode (no external AI egress at all). Restricted mode is for organizations whose policies or contracts forbid their content reaching any third-party model, even transiently for inference. It includes everything no-training mode does, and additionally disables third-party AI inference for the organization — no organization content is sent to an external LLM, and the server refuses such calls regardless of per-organization feature flags, failing closed. AI features then work only through an AI endpoint your organization operates or designates (configured under Settings → AI). Tenant isolation, encryption, audit logging, and every other security control apply identically in every mode. It is set by the Factory-OS operator on request, with the reason recorded for audit.

Restricted mode is a data-path reduction, not permission to upload regulated data. It changes where AI calls go; it does not change what Factory-OS is certified to host. The Compliance posture list below still controls, and the prohibition on uploading ITAR / EAR / classified / export-controlled material applies in every mode, restricted included.

Restricted mode is a meaningful opt-out, not a regulatory certification. We remain not SOC 2, ISO 27001, HIPAA, FedRAMP, CMMC, or ITAR certified — see Compliance posture below. Restricted mode addresses one specific concern — training and third-party LLM exposure — and nothing more. If your contract or regulator demands certified hosting, cleared-personnel handling, or dedicated subprocessor agreements, restricted mode alone is not sufficient. Talk to us before uploading; we may not be the right fit yet.

If your data is restricted by law, take that seriously. ITAR / EAR / classified / HIPAA / PCI-DSS / FedRAMP / CMMC / GDPR-special-category data has requirements beyond an AI opt-out. Don't upload material that requires more than we can offer.

Opt-outs survive a change of control. Restricted mode survives a change of control: if we are acquired or merge (see Change of control above), an organization's restricted-mode exclusion transfers with the agreement and binds the successor. Content excluded from training before such a transaction stays excluded after it — a successor does not acquire a fresh right to train on it, and cannot re-enable third-party inference for that organization under this agreement without its consent. No-training mode survives a change of control the same way: the successor inherits the exclusion, not a fresh start.

Security practices

We employ commercially reasonable security practices appropriate for early-stage SaaS, including:

  • encryption in transit and at rest;
  • tenant isolation enforced by the database itself (row-level security) on every query, backed by least-privilege database roles — the role that serves tenant requests cannot read credentials at all;
  • modern password hashing, sign-in rate limiting and lockout, immediate session revocation;
  • multi-factor authentication, including phishing-resistant passkeys (WebAuthn) and authenticator-app codes;
  • append-only, hash-chained audit logs on sensitive operations, anchored against truncation, with tamper-evident verification runnable on demand (scheduled verification is being stood up and we will state it as routine only once it is);
  • server-side authorization on every state-changing operation;
  • encrypted backups with a scripted, repeatable restore-drill procedure (we will describe drills as routine only once the schedule is operating);
  • pull-request review with automated security checks before code ships.

We do not represent that these practices meet any specific regulatory or contractual standard (SOC 2, ISO 27001, HIPAA, PCI-DSS, FedRAMP, CMMC, or otherwise). They are the controls we have today and may evolve. Implementation details are not published; we will discuss them under NDA where appropriate for legitimate due diligence.

Subprocessors

We use third-party providers to operate the service (hosting, database, transactional email, AI inference for organizations not in restricted mode — engaged only under API terms that prohibit the provider training on customer content — and optional integrations). The current subprocessor list is available on written request. We notify customers in writing before adding a subprocessor that handles customer data. Integrations that access an individual user's external account (for example, a CAD connection) are engaged only when that user explicitly connects it; operational channels we configure ourselves — such as the escalation-notification channel that can carry conversation summaries to our operators — are part of the subprocessor list above rather than something a user connects.

Data retention, export, and deletion

Customer data is retained for the life of your account. You may export project data in standard formats from within the application, subject to any feature limitations in effect at the time. If we terminate without cause or discontinue the service, export remains available for thirty (30) days after the effective date, as described in Term and termination below.

When an account or organization is closed, access is disabled immediately and the closed organization's content stops being served. Deletion from active systems is currently performed on written request, not on an automatic schedule: tell us in writing that you want the content deleted and we will delete the identifiable content from active systems and confirm when it is done. (A closure can also be reversed by support request while the content still exists.) We are building a scheduled deletion pipeline, and will state a fixed timetable here only once it is actually running — we would rather describe the process we operate than promise one we do not yet. Residual copies may remain in encrypted, access-restricted backups until those backups expire through ordinary rotation; those copies are not restored except as part of disaster recovery, and are not used for any other purpose. Our backup design targets immutable (Object-Lock) storage — a control chosen so that neither we nor an attacker can selectively alter one organization's content in an existing backup; the trade-off of that immutability is that backup copies expire on the rotation schedule rather than on demand. Consent and mode-change audit records (for example, when your organization declined or re-entered cross-customer learning) are retained indefinitely; other audit-log records may be retained for at least one year after deletion to support security investigations and compliance obligations. As described in Data ownership and usage, de-identified or aggregated derivatives, derived datasets, and trained model parameters created while your organization participated in learning are not subject to deletion on closure and may be retained and used thereafter.

We perform encrypted backups of customer data, and we maintain a scripted, repeatable restore-drill procedure for verifying restorability (as with the security practices above, we will describe that verification as routine only once its schedule is operating). We do not guarantee that any specific data can be recovered from backup, and you should maintain your own copies of any data you cannot afford to lose.

Compliance posture (what we are NOT)

Factory-OS is not:

  • SOC 2 Type 1 or Type 2 certified
  • HIPAA covered or BAA-eligible
  • PCI-DSS assessed
  • FedRAMP authorized
  • CMMC certified at any level
  • Approved for ITAR / EAR / USML / classified / export-controlled data
  • Suitable for personally identifiable information of children, or for data subject to GDPR Article 9 (special-category) restrictions

Do not upload or process data that requires any of the above — in any mode, restricted included. If your use case requires regulated-data hosting, do not use this service.

User responsibilities

  • Use a unique, strong password. Enable multi-factor authentication — a passkey is the strongest option we offer.
  • Keep credentials private. Each user gets their own account; do not share.
  • Do not upload regulated, classified, or export-controlled data (see above).
  • Maintain your own copies of any data you cannot afford to lose.
  • Promptly notify us if you suspect a credential compromise, an unauthorized access, or any security issue.

Acceptable use

You may not bypass authentication, authorization, or audit logging; probe or scrape other tenants' data; reverse-engineer the service except as permitted by law; use the service or its outputs to build a competing dataset or train competing models; submit content that violates law or third-party rights; transmit malware; or flood, deny service to, or harass others. Good-faith vulnerability research reported per the disclosure process below is welcome and will not be treated as a violation.

Limits, liability, term, and governing law

AS IS. The service is provided "AS IS" and "AS AVAILABLE" without warranties of any kind, express, implied, statutory, or otherwise — including but not limited to merchantability, fitness for a particular purpose, non-infringement, accuracy, reliability, availability, freedom from defects, security, or that the service will meet your requirements or operate uninterrupted. AI-generated suggestions and analyses are assistive outputs, may be wrong, and are not professional engineering advice; you are responsible for independently verifying any engineering decision.

No consequential damages. To the maximum extent permitted by applicable law, neither party shall be liable for any indirect, incidental, special, consequential, exemplary, or punitive damages, or for any loss of profits, revenue, business, data, goodwill, or other intangible losses, arising out of or related to this agreement or the service, regardless of the legal theory and even if advised of the possibility of such damages.

Aggregate cap. Our aggregate liability for any and all claims arising out of or related to this agreement or the service is limited to the greater of (a) one hundred U.S. dollars ($100) or (b) the fees actually paid by you to us in the three (3) months preceding the event giving rise to the claim. This cap applies regardless of the form or legal theory of the claim, and applies in the aggregate across all claims.

Indemnification. You agree to indemnify, defend, and hold harmless Factory-OS, Inc. and its operators, contractors, employees, and affiliates from any third-party claim, demand, loss, or expense (including reasonable attorneys' fees) arising out of (a) your use of the service in violation of this agreement or applicable law, (b) data you upload that violates law or third-party rights, (c) your failure to maintain appropriate security on your account or credentials, or (d) any representation or warranty you make to a third party regarding the service that we have not authorized in writing.

Term and termination. This agreement is in force while you have an active account. Without cause: we may terminate the service or your account with thirty (30) days' written notice (through the service or by email); your data remains exportable as described in Data retention, export, and deletion for thirty (30) days after the effective date, and if you have prepaid fees we will refund the pro-rata unused portion. For cause — material breach of this agreement, a security or legal risk, non-payment, or prohibited content — we may suspend or terminate immediately; we will tell you the reason and, where the cause allows, still make export available. You may stop using the service at any time. Sections covering data ownership and usage (including the learning license, its survival, and the mode opt-outs), indemnification, limitation of liability, and dispute resolution survive termination.

Force majeure. Neither party is liable for delay or failure to perform caused by circumstances beyond reasonable control, including without limitation infrastructure provider outages, denial-of-service attacks, governmental actions, network failures, pandemics, or natural events.

Governing law and venue. This agreement is governed by the laws of the State of Delaware, USA, without regard to its conflict-of-laws principles. Any dispute arising out of or related to this agreement or the service shall be resolved exclusively in the state or federal courts located in Delaware. Each party irrevocably consents to the personal jurisdiction of such courts and waives any objection to venue.

Severability and waiver. If any provision of this agreement is held unenforceable, the remaining provisions remain in effect. No failure to enforce any provision is a waiver of the right to enforce it later.

Entire agreement. This agreement is the entire agreement between the parties regarding the service and supersedes all prior or contemporaneous communications and proposals.

Changes. We may update this agreement from time to time. Material changes will be surfaced in the application and require re-acceptance before continued use; continued use after acceptance constitutes agreement to the updated terms.

Contact and security disclosure

  • All inquiries, including security reports: support@factory-os.com
  • For security reports, please include reproduction steps and your contact info. We aim to acknowledge within two business days. Coordinated disclosure is appreciated; we will not pursue legal action against good-faith research that follows this process.

Acceptance

By clicking I agree, you confirm that you have read this agreement, that you have authority to bind your organization to it, that you understand Factory-OS is an early-stage development build, that you understand which data-use mode applies to your organization and the data-usage terms above (including the learning license if it applies), and that you accept the AS-IS, no-warranty, limited-liability terms above.

Revision 2026-08-10 · published 2026-08-10 · Factory-OS, Inc. · support@factory-os.comback to sign in →