Engrym Terms of Service

Provider: RTK AI Labs Ltd, a company registered in England and Wales under company number 17179962 ("RTK AI Labs Ltd," "we," "us," "our"), the company behind the Engrym product ("Engrym," the "Service").

Last updated: 19 September 2026

Terms version: 2026-09-19. Where the Service records the version of these terms you agreed to, or the version under which you opened a Brain, it records this identifier.

Scope: the Free tier (three Projects), the Solo Builder tier (€29.99 per month, or €287.90 per year), and (during the founding window only) the Founding Supporter price on the Solo Builder tier (Section 5.5). The Team tier is shown in-product as "coming soon" and is not currently purchasable. These terms make no commitments about capabilities that are not yet available.


1. Service description and definitions

1.1 What Engrym is

Engrym is a knowledge layer for software and project teams. It stores a project's documented knowledge: markdown documents and the structured "atoms" (decisions, conventions, constraints, and context entries) extracted from those documents. It serves that knowledge to the AI agents you already use. Where a documented claim can be checked against your code, your own AI agent (running in your editor, where it already holds your repository) reads the code and returns a verdict (upheld, violated, or uncertain) together with an evidence pointer (a path:line locator) and an optional written note. Engrym records the verdict. Engrym does not read, receive, or store your code.

1.2 What Engrym is not

Engrym is not an AI coding assistant, and it is not a replacement for any AI coding tool. It works alongside them. Engrym does not read, index, navigate, or retrieve over your source code (see Section 6, the code-privacy guarantee).

1.3 Definitions

  • Project: a bounded scope of work (a codebase, a product, a research initiative) with its own knowledge layer.
  • Document: a markdown file with optional frontmatter that you create or import into a Project.
  • Atom: a structured knowledge entry (a decision, convention, constraint, or context item) extracted from a Document, with provenance and supersession tracking.
  • Brain: the queryable set of a Project's Atoms served to your agents.
  • Reconciliation Verdict: the upheld / violated / uncertain result your agent returns when it checks a documented claim against your code at a specific commit.
  • Evidence Pointer: a path:line locator string accompanying a Reconciliation Verdict. It never contains code text.
  • BYOK Key ("bring your own key"): an AI provider API key (Anthropic, OpenAI, or Google) that you supply so that Engrym can dispatch AI work using your provider account.
  • Connected Agent: an MCP-compatible AI tool of your own (for example, Claude Code or Claude Desktop) that you connect to Engrym and that runs on your own AI subscription, in your own environment.
  • Extraction Mode: the per-Project setting that controls where extraction runs and who funds it: BYOK mode, agent mode, or mix mode (Section 4.1).
  • Platform Key: an AI provider key that RTK AI Labs Ltd supplies and funds, used only for the limited platform-funded operations described in Section 4.3.
  • Sync Daemon: the optional local program you install on your own machine to sync a local folder with your Project.
  • Git Export: the optional feature that writes your Project's documents, knowledge base, decision log, and activity stream to a Git repository you control.
  • Public Atom Page: a single Atom made publicly readable at a share link, without sign-in, by a member of the Project that owns it.
  • Share Link: the unguessable URL of a Public Atom Page.
  • Sharing Lock: a Project-level setting that blocks new Share Links from being created until the Project's owner explicitly removes it by typed confirmation.
  • Open Brain: a Project whose Brain its owner has made publicly readable, at a public address the owner chooses. An Open Brain is readable by anyone, with no account, both as a web page and by an AI agent connected to its public read-only endpoint.
  • Closed Brain: an Open Brain its owner has taken out of public view. A Closed Brain is not served to new readers and cannot be Forked; its public address answers exactly as an address that never existed. Its owner can reopen it.
  • Forkable: a setting on an Open Brain that permits any reader to take a copy of its Atoms and Documents into a new Project of their own, under the licence in Section 7.7.
  • Fork: a new Project created from a copy of a Forkable Open Brain's Atoms and Documents, owned by the person who made it.
  • Origin Credit: the system-generated line naming the Open Brain a Fork came from, and the person or team that maintains it. It is generated by the Service and is not an editable field.
  • Frozen: the state an Open Brain enters when it is deleted with no members remaining. A Frozen Brain accepts no further writes, continues to be served publicly, and can still be Forked if it was Forkable.
  • Handle: the unique public name you claim for your account or team (for example @yourname), which forms the address of your Public Profile and appears in the Origin Credit of every Open Brain you publish and every Fork taken from it.
  • Public Profile: the public page at your Handle's address, showing the information you choose to put on it and the list of your Open Brains.

2. Eligibility and account

2.1 Eligibility

You must be at least 16 years old (or the age of digital consent in your jurisdiction, if higher) and able to form a binding contract to use the Service.

2.2 Your account

You are responsible for the accuracy of the information you register, for keeping your credentials secure, and for all activity under your account.

2.3 Your AI provider accounts

When you use a BYOK Key, you are responsible for maintaining your own account in good standing with that AI provider, for the validity of the key, and for all usage and charges your provider bills to you for that key. When you use a Connected Agent, your agent's usage is governed by your own subscription agreement with your AI provider; Engrym never receives your subscription credentials. See Section 4.

2.4 Your Handle and your Public Profile

Both are optional, and both are off until you act. You do not need a Handle or a Public Profile to use Engrym. Neither is created for you. If you never claim a Handle, you have no Public Profile, no public page exists at any address for you, and nothing about you is published by us anywhere. Publishing an Open Brain requires a Handle, and claiming one is how you choose to be publicly named.

What a Handle is, and the one thing to understand before claiming it. A Handle is a unique public name, for example @yourname. Some names are reserved and cannot be claimed. A Handle you use to publish an Open Brain becomes part of that Brain's Origin Credit, and of the Origin Credit of every Fork taken from it. Section 7.8 sets out exactly what that means, including what happens if you later delete your account. Read Section 7.8 before you publish. We show you this at the moment you claim a Handle and again at the moment you publish.

What your Public Profile shows. Your Public Profile shows only what you put on it, plus the list of your Open Brains. You choose whether to add a photo, a display name, a description, links to your accounts on other services, and any other links you want to publish. Every one of those fields is optional and every one starts empty. The list of your Open Brains is generated by the Service and reflects the Brains you have chosen to open; it never lists a private Project or a Closed Brain.

What your Public Profile never shows, and what its record does not contain. Your Public Profile never shows your email address, your billing or payment details, any subscription or customer identifier, your plan or price, your usage, your private Projects, the names of your private Projects, or any content from them. The record that renders your Public Profile does not contain any of those things.

You are responsible for what you put on it. Anything you add to your Public Profile is published by you. Do not put on it anything you are not entitled to publish, and do not use it to impersonate another person or organization, to advertise, or to place links for search-ranking purposes. Section 3 applies to your Public Profile in full.

Editable and removable, with one exception. You can change or clear any field on your Public Profile at any time, and you can take the whole Profile down. Taking it down removes the public page. It does not close an Open Brain, which is a separate action (Section 7.6), and it does not remove your Handle from an Origin Credit, which Section 7.8 governs. You can change your Handle; changing it changes what every Origin Credit displays.


3. Acceptable use

You agree not to:

  • upload, store, or process content you do not have the right to upload, store, or process;
  • upload unlawful content, or content that infringes a third party's rights;
  • use Engrym's AI-dispatch features in a way that violates the terms of the AI provider whose key is used (yours under BYOK, or ours on the Platform Key path), or use a Connected Agent with Engrym in a way that violates your agreement with your AI subscription provider;
  • attempt to circumvent the per-account usage limits described in Section 4.4 or the technical rate limits applied to the API;
  • reverse-engineer, decompile, or attempt to extract source from the Service, except to the extent that restriction is prohibited by applicable law;
  • use the Service to build a product that is substantially the same as Engrym;
  • publish an Atom to a Public Atom Page, or open a Brain, where doing so would disclose personal data about another person without a lawful basis, or would disclose special-category personal data, confidential information, or anything you are not entitled to make public;
  • use Public Atom Pages, Open Brains, or Public Profiles as general web hosting, as a content-delivery mechanism, or to place content on our domain for search-ranking purposes;
  • publish content on any public surface of the Service that is unlawful, infringing, or that you would not be entitled to publish on your own website;
  • claim or use a Handle in order to impersonate another person or organization, or in a way calculated to mislead people about who maintains a Brain;
  • remove, alter, obscure, or misstate an Origin Credit, whether through the Service or by any other means;
  • Fork an Open Brain that is not marked Forkable, or attempt to copy an Open Brain's content by means other than the Fork feature in order to avoid the Origin Credit; or
  • use an Open Brain's public read-only endpoint in a way that places an unreasonable load on the Service.

We may suspend or limit access to protect the Service, other users, or our providers from abuse, security risk, or runaway cost.

We may disable any Public Atom Page, any Open Brain, any Public Profile, and any Handle, and may switch off public publishing across the Service, without notice, where content appears unlawful or infringing, where we receive a valid legal or regulatory demand, where a Handle impersonates someone, or where a public surface is being abused. Disabling a public page does not delete the underlying Atoms or Documents, which remain in the Project they belong to. Section 3.1 sets out how to report content and what we do about a report.

3.1 Reporting content, and what we do about it

How to report. If you believe something published on Engrym is unlawful, infringes your rights, discloses your personal data, or breaches this Section 3, tell us at the address in Section 12. Please include the address of the page, what specifically is wrong with it, enough detail for us to find the content on the page, and how to reach you. If you are reporting on behalf of a rights holder, tell us who they are and that you are authorized to act for them.

What we do with a report. We review reports and act on them without undue delay. Where content is unlawful, infringing, or in breach of this Section 3, we may disable the page or the Open Brain, remove a Handle, or suspend the account, in each case in proportion to what we find. We acknowledge every report, and we tell you the outcome once we have reviewed it.

How we act. Where we disable a page or a Brain, we do it with a control that only we hold. It stops us serving the page or the Brain; it is not a setting the publisher or anyone else can change; and it is separate from a publisher's own decision to close a Brain (Section 7.6) or to revoke a Share Link (Section 7.5). Disabling does not delete anything: the Atoms and Documents remain in the Project they belong to.

What we do not do. We do not review content before it is published, and we are not able to judge every dispute between two people about who owns what. We may decline to act where a report is unclear, is not made in good faith, or asks us to resolve a dispute that belongs in another forum.

If we act against your content, we tell you. If we disable something you published, we tell you what we disabled, why, and what to do if you disagree, unless a law or a valid legal demand prevents us from telling you. You can respond at the address in Section 12, and we will look again. Where we disabled content on the strength of someone else's report and you tell us the report was wrong, we may restore it.

What disabling does and does not reach. Disabling stops us serving the page. It does not delete the Atoms or Documents in the Project they belong to, and it cannot recall copies that other people or other services already made, including a Fork taken before we acted, and previews cached by other services when a link was pasted into them. Sections 7.6 and 7.9 explain this in more detail.

Repeat infringement. We may suspend or terminate the account of anyone who repeatedly publishes infringing content.


4. AI work, extraction modes, and our handling commitments

4.1 Extraction runs on your own compute: three modes

The AI extraction that turns your Documents into Atoms never runs at RTK AI Labs Ltd's expense, is never marked up, and is never billed to you by us. Each Project is set to one of three extraction modes (the default is BYOK; you can change the mode per Project):

  • BYOK mode (the default). Our servers dispatch the extraction request to the AI provider you choose (Anthropic, OpenAI, or Google) using your BYOK Key. That inference uses your provider account and is governed by your agreement with that provider.
  • Agent mode. No provider key is required. Your Connected Agent pulls the Document text and the extraction instructions from Engrym, runs the extraction model inside your own agent session, on your own AI subscription, and submits the extracted Atoms back to Engrym. Submitted Atoms are recorded as provisional knowledge, subject to your review and ratification. We never receive, store, or use your AI subscription credentials, and we never re-route agent-mode work to any paid key: a Document with no Connected Agent simply waits in an explicit "pending: needs agent" state until an agent picks it up.
  • Mix mode. A Connected Agent handles foreground extraction as in agent mode, and a configured BYOK Key handles background extraction as in BYOK mode.

Agent auto-pull is off by default. By default, your Connected Agent pulls extraction work only when you ask it to. You may opt in, per Project, from the dashboard, to allow a Connected Agent to pull waiting work automatically; the same settings let you require an in-session re-confirmation and control how eagerly the agent may pull. Until you opt in, no agent auto-pulls anything.

The contradiction-finding feature's AI judging runs against your BYOK Key.

4.2 How we handle your BYOK key

  • Your BYOK key is encrypted at rest using strong, industry-standard encryption. It is never stored in plaintext.
  • Your key is decrypted only momentarily, in memory, at the moment an AI request is dispatched, and is then discarded.
  • Your key in plaintext is never written to a log, never persisted, and never returned to any caller.

4.3 The Platform Key: the one place we send your text to an AI provider on our account

For the operations below, where you have not configured your own Google key, Engrym uses a Platform Key that RTK AI Labs Ltd supplies and funds:

  1. Semantic-search embeddings. Your Atom text is sent to Google's Gemini API to produce search vectors, so your knowledge base can be searched by meaning and not only by keyword.
  2. Search queries. When you run a search that uses meaning rather than keywords, the text of your query is sent to Google's Gemini API to produce a vector to search with. Your query text is not stored by us; it is held in memory only for as long as the search takes, and repeated identical queries may reuse a result held briefly in memory.
  3. Duplicate detection (claim-merge). Pairs of your Atom texts are sent to Google's Gemini API to decide whether a new Atom duplicates an existing one.

On the Platform Key path we send Atom text and search query text only, never your source code, and never your Documents beyond the Atom text already extracted from them. If you configure your own Google key, that key is used instead for your Project, and the Platform Key is not used for it.

The Platform Key funds embeddings, search queries, and duplicate detection only. It is never used for chat, extraction, or any other generation. The contradiction-finding feature's AI judging always runs on your key, not ours (Section 4.1).

Public reads are never funded from your key or your limits. Where you open a Brain to the public (Section 7.6), a reader's searches against it are not dispatched on your key and are not counted against your usage limits in Section 4.4. Nothing a stranger does with your Open Brain spends your provider account or degrades your own search.

4.4 Usage limits

To keep platform-funded AI spend bounded, per-account, per-period limits apply:

  • Contradiction-finding calls (run on your BYOK key): Free is limited to a set number of invocations per period and is soft-blocked at the ceiling (the feature returns an empty result flagged "limit reached"); Solo is allowed a higher number per period and proceeds with a warning at the ceiling.
  • Agent-mode extraction submissions are limited to a set number per account per period. At the ceiling, further Documents remain in the "pending: needs agent" state until the next period; the work is never silently re-routed to a paid key, and you are never billed.
  • Platform-funded embedding spend and platform-funded duplicate-detection spend are each capped per account per period. At a ceiling, the affected feature degrades gracefully, with semantic search falling back to keyword search and new Atoms simply created without duplicate-merging, rather than incurring further spend or charging you.

These are usage controls, not additional charges: reaching a ceiling degrades or pauses a feature; it does not bill you. The current numeric limits are shown on the pricing page and in your billing settings, and may change as described in Section 11.


5. Subscriptions, billing, and refunds

5.1 Tiers and prices

  • Free: €0. Three Projects. Projects on the Free tier cannot be linked to one another (connecting Projects is a paid feature). Extraction runs on your own provider key or your own agent subscription (Section 4.1). No card required, no model-usage markup, no metered trial. History views display the trailing 90 days (Section 7.4); no data expires on any tier (Section 7.4).
  • Solo Builder: €29.99 per month, or €287.90 per year (20% off the monthly run-rate). Unlimited Projects.
  • Founding Supporter (closed window): €14.99 per month, monthly only, on the Solo Builder tier: the same tier, the same features, the same limits as Solo Builder, at a locked price. There is no yearly Founding Supporter price. Available only while the founding window is open; see Section 5.5. €29.99 per month (or €287.90 per year) remains the standard Solo Builder price.
  • Team: shown in-product as "coming soon"; not currently purchasable. We make no commitment as to its availability, features, or price.

5.2 Billing mechanics

Paid subscriptions are billed through our payment processor. RTK AI Labs Ltd does not receive or store your full card number; card data is held by the payment processor, which is the PCI boundary. We store customer and subscription identifiers and subscription status only. Subscriptions renew automatically each period until cancelled. Prices are stated in euros (EUR). RTK AI Labs Ltd is not registered for VAT, so no VAT is added; the EUR prices stated are the total amount payable.

A paid subscription is attached to your user account, not to a single Project: a Solo Builder subscription entitles your account on every Project you use, and one account holds at most one active paid subscription at a time.

5.3 Checkout terms

The following applies to every paid purchase, and is presented at checkout:

  • Prices are in euros (EUR): €29.99 per month, or €287.90 per year, for Solo Builder.
  • You choose the billing interval, monthly or yearly, at checkout. Billing is in advance, at the start of each period.
  • There is no free trial: the paid period starts when the purchase completes, and the Free tier remains available without payment.
  • Subscriptions renew automatically at the end of each period until cancelled.
  • You can cancel at any time through the billing portal linked from your billing settings; cancellation takes effect at the end of the current paid period, and you retain paid features until then.
  • If you are a consumer in the UK or the EU, you may have a statutory 14-day right of withdrawal for purchases made online. Where you request that the service start immediately, the checkout will ask for your express acknowledgement, and the statutory rules on early supply of digital services then apply. Nothing in these terms limits rights you have under mandatory consumer-protection law.
  • During the founding window only, checkout also offers the Founding Supporter price on the Solo Builder tier. That price is monthly only, so the interval choice above does not apply to it. Section 5.5 governs that price, its lock, and the supporters-wall opt-in presented at founding checkout.

5.4 Effect of downgrade or cancellation on your data

Your right to export your Project (Section 7) survives cancellation. Export, deletion, and retention windows are set out in our Privacy Policy and govern this Section and Section 9. After cancellation, export remains available for a limited period, as described in our Privacy Policy.

5.5 The Founding Supporter price (closed window)

5.5.1 What it is: a price, not a tier

During the founding window (Section 5.5.2), you can subscribe to the Solo Builder tier at the Founding Supporter price: €14.99 per month, instead of the standard €29.99 per month. The Founding Supporter price is monthly only. There is no yearly Founding Supporter price, and none is calculated from the monthly one; were one ever offered, it would be stated here first. The Founding Supporter price is a price, not a separate plan: a Founding Supporter subscription is a Solo Builder subscription in every respect: the same features, the same Project limits, the same usage limits (Section 4.4), and the same checkout terms (Section 5.3). There are no features available to Founding Supporters that are not available to standard Solo Builder subscribers, and no features withheld. The standard prices stated in Section 5.1 remain the Service's live prices throughout.

5.5.2 The founding window: when the price is available

The Founding Supporter price is available only during a single, closed founding window. The window opens on a date we announce. There is no countdown and no closing date. The window closes on the first of these to happen:

  • 500 founding places have been claimed. This closure is permanent: once the 500th place is claimed the window does not reopen, and a later cancellation does not free a place or bring the price back.
  • We close the window. We may close the founding window at any time before the cap is reached.

A place counts as claimed once a Founding Supporter subscription has become live, and it stays claimed from then on. A checkout that is abandoned, or whose first payment never succeeds, claims no place.

Once the window has closed, no new Founding Supporter purchase is possible, and the checkout will refuse founding purchases from that moment. Checkouts already in progress when the cap is reached may still complete, so the founding cohort can marginally exceed 500. The close of the window has no effect on existing Founding Supporter subscriptions (Section 5.5.3): it ends availability to new supporters, not existing price locks. We publish a live counter of claimed founding places during the window; the authoritative control is the checkout's own refusal, not the displayed counter.

5.5.3 The price lock: what "locked" means, exactly

If you subscribe at the Founding Supporter price during the window, that price is locked for the life of your continuous Founding Supporter subscription: for as long as the subscription remains in effect, each renewal bills at €14.99 per month, regardless of the Service's standard prices at the time. Nothing in the Service re-prices a Founding Supporter subscription, and Section 11 (changes to the Service and these terms) does not permit us to raise the price of an existing, continuing Founding Supporter subscription.

The lock ends when the subscription ends. Specifically:

  • Cancellation ends the lock. If you cancel (Section 5.3), your Founding Supporter subscription, and with it the founding price, ends at the end of the current paid period.
  • The subscription otherwise ending ends the lock, including where the subscription is cancelled after repeated payment failure. A temporary payment failure that is resolved within the payment processor's retry process does not by itself end the subscription or the lock.
  • Moving to a different plan ends the lock. The Founding Supporter price attaches to the Solo Builder tier only; it does not carry to any other tier or plan (including any future Team plan).
  • No re-entry once the window has closed. If your Founding Supporter subscription ends after the founding window has closed, the founding price is not available to you again, because the window is closed to all new founding purchases (Section 5.5.2), and a new subscription is at the then-standard prices. If the window is still open when your subscription ends, you may subscribe at the Founding Supporter price again on the same terms as any other new supporter, for as long as the window remains open.

5.5.4 The public supporters wall: opt-in, display name only, revocable

During and after the window, we publish a supporters wall: a public page listing Founding Supporters who chose to be listed. The wall works like this:

  • Opt-in only, and off by default. You are listed only if you explicitly opt in, via the checkbox at checkout (unchecked by default) or later from your account settings. If you do not opt in, you are never listed; you are counted only in the aggregate supporter count, which contains no names.
  • Display name only. The wall shows a display name and nothing else. When you opt in, at checkout or from your account settings, the name shown is the display name already on your account, resolved on our side at that moment; where your account has no display name set, the wall shows "Anonymous" instead, and your account settings tell you so. You can change the name shown on the wall at any time from your account settings, including to a pseudonym. We never display, and the wall's data source does not even contain, your email address, your payment details, any payment or subscription identifier, or the price you pay.
  • Listed only while you are a supporter and opted in. Your name appears only while you both remain opted in and hold a live Founding Supporter subscription. The close of the founding window does not remove any name: opted-in supporters remain listed after the window closes. If your Founding Supporter subscription ends, your name leaves the wall.
  • Revocable at any time. You can withdraw from the wall at any time from your account settings. Withdrawal deletes the opt-in record outright: your name is removed from the wall promptly, and re-opting in later starts a fresh opt-in. Deleting your account removes the opt-in record automatically.

5.5.5 Founding extras: courtesies, not purchased features

Alongside the price lock, which is the contractual substance of the Founding Supporter purchase, we currently extend Founding Supporters some courtesies:

  • Weighted feedback votes. On the public feedback board, a Founding Supporter's upvote currently carries five times the ranking weight of a standard vote. The board discloses this, and the displayed supporter counts always reflect real numbers of people.
  • Team-beta priority. The Team tier is a private beta and is not purchasable (Section 5.1). While that remains true, Founding Supporters who ask to join the Team beta are admitted ahead of the queue. This does not change Section 5.1's position: we make no commitment as to the Team tier's availability, features, or price.
  • The supporters wall (Section 5.5.4).

These extras are provided as courtesies to the founding cohort. They are not part of the paid subscription (what you purchase is the Solo Builder tier at the locked founding price, Sections 5.5.1 and 5.5.3), and we may adjust how the courtesies work as the product develops. We will not remove the price lock itself, which Section 5.5.3 governs.


6. The code-privacy guarantee (the transient-sensor boundary)

This is a core commitment of the Service:

Engrym does not read, store, embed, index, cache, or persist any representation of your source code. This means no file contents, no abstract syntax tree, no call graph, no import graph, no file tree, no snippet, and no code text inside a Reconciliation Verdict beyond the path:line Evidence Pointer.

Reconciliation is performed by your AI agent, in your own environment, which already holds your repository. Your agent reads the code transiently within its own session and returns only the verdict, the evidence pointer, and an optional note. Engrym serves the documented claim and records the verdict.


7. Your data: ownership, portability, and export

7.1 You own your content

As between you and RTK AI Labs Ltd, you own the Documents, Atoms, verdicts, and other content you create or import.

For your private content, which is all of it unless you publish it: you grant RTK AI Labs Ltd the limited licence necessary to operate the Service for you, to store, sync, extract Atoms from, index, and serve your content to your own AI agents, and to provide the features described in these terms. We claim no broader rights over your private content, and nothing you keep private is covered by the paragraph below.

For content you publish, and only from the moment you publish it: when you publish an Atom to a Public Atom Page (Section 7.5) or open a Brain to the public (Section 7.6), you additionally grant RTK AI Labs Ltd a non-exclusive, worldwide, royalty-free licence to reproduce, host, cache, transmit, and publicly display that content, and to serve it to any person and to any AI agent that requests it, for the purpose of operating the public features you have chosen to use. Where you mark an Open Brain Forkable, that licence extends to copying its Atoms and Documents into another user's Project when they Fork it, and to generating and displaying the Origin Credit.

The scope of that additional licence is exactly the scope of what you published. It covers the specific Atoms and Documents you published, from the moment you published them. It does not reach any other content in the Project, any content you did not publish, any Project you have not opened, or anything you keep private. It is a licence to operate the public features, not a licence to use your content for anything else. We claim no broader rights. In particular, we do not use your published content to train any model (Section 7.3 applies to published and private content alike), and we do not sell it or license it to anyone except as described in Section 7.7, which is your grant to other users and not ours.

This licence outlives publication in one respect only. Because copies other people took while your Brain was open persist as their own (Sections 7.6 and 7.9), the licence continues for content that has already been copied by another user, to the extent needed to keep serving that user's own copy and its Origin Credit. It does not entitle us to keep publishing content you have closed or emptied, or content that has been taken down under Section 3.1.

7.2 Portability and export

Engrym is built so you can leave with your data. Every Project can be exported, and you may configure an optional Git export that writes a standard, human-readable copy of your Project, in open formats, to a Git repository you control, containing your documents, your knowledge base, and your decision and activity history, and no source code.

7.3 We do not train on your content

RTK AI Labs Ltd does not use your content to train any model. We run no first-party model training. Platform-funded inference is dispatched to Google's Gemini API solely to provide the features described in Section 4.3.

7.4 Free-tier history views: a 90-day display window (not deletion)

Some parts of the Service present a chronological history of Project activity: timeline and history views. On the Free tier, these history views display the most recent 90 days of events, on a per-account rolling basis. This is a display rule applied when history is read. It is not a data-retention rule, and nothing about it deletes anything. Specifically:

  • No customer data expires on any tier, Free included. Your Atoms, your Documents, your decisions, search, and the current Brain never expire and are never subject to this window. The complete underlying event stream remains stored in full and remains the Service's system of record; the window changes only what a Free-tier history view displays.
  • Reconciliation Verdict history is exempt on every tier. Verdict history (Section 1.3) always displays in full, on Free and on every paid tier.
  • Nothing disappears silently. Where a Free account has history older than the window, the history view says so: it indicates that older events exist beyond the 90 days shown.
  • Per-account rolling window. The 90 days are measured per account, rolling with time: the trailing 90 days as of the moment you read. There is no fixed cut-off date and no cohort freeze.
  • Upgrading restores full history reads immediately. Because the data was never removed, upgrading to a paid tier makes your full history readable at once, with no restoration step, no waiting period, and no data operation of any kind. If a paid subscription later ends and the account returns to the Free tier, the display window applies to reads again; the underlying data remains untouched throughout.
  • The window applies to history views however they are accessed, in the dashboard, through the API, or through a Connected Agent, and applies identically in each.
  • This window limits nothing else in these terms. It does not limit your ownership of your content (Section 7.1), your export and portability rights (Section 7.2; export always covers your full data, not a 90-day slice), or anything in our Privacy Policy, whose retention and deletion commitments are unchanged by this section.

Effective date of enforcement. We state this display rule here, in advance, so that it is transparent from the start and is never applied retroactively: the window will not begin to be enforced in the product until at least 90 days after this section first appears in these terms. Until it is enforced, Free-tier history views display full history.

7.5 Publishing an Atom publicly

What it is. Any member of a Project can publish a single Atom to a Public Atom Page. Publishing is always an explicit, per-Atom act, and the product shows you a preview of exactly what will be public before you confirm. Nothing is published automatically, and every Atom is private unless someone publishes it. Publishing is available on every tier at no charge.

What becomes public. The Atom's category, title, content, status, confidence band, dates, and your Project's display name. Nothing else: not the Atom's internal identifier, not the document it came from or its file path, not your Project's internal name, not its tags or scope, and not the title of any related Atom that has not itself been published.

Anyone with the link can read it. Share Links are long and random and are not listed in search engines, but they are not secret. Treat publishing as making the content public.

You decide, and you are responsible for the decision. You are the controller of the content you publish. Deciding to make an Atom public is a separate decision from deciding to store it in Engrym, and it needs its own lawful basis where it contains personal data about anyone. Before you publish, check the preview for anything that should not be public, including confidential client information, personal data about other people, and any source-code fragment or file path someone pasted into the Atom's text. We do not review published content, and we are not responsible for what you choose to publish.

Revoking, and the limit of revoking. You can revoke a Share Link at any time. Revoking is permanent: the link returns a neutral not-found response from then on, and re-publishing the same Atom creates a different link. Revoking stops us serving the page. It cannot recall copies that other services already made. Slack, LinkedIn, iMessage, Notion, and similar tools cache the title, the preview image, and a short excerpt of the content when a link is pasted into them, and those copies are outside our control and outside our ability to delete. Publishing should be treated as irreversible in that respect.

The Sharing Lock. Projects created by importing existing content start with sharing locked, so that no Share Link can be created until the Project's owner deliberately unlocks it by typed confirmation. The Sharing Lock is a control we provide, not a guarantee about outcomes: an owner can remove it, and once removed, members can publish. It does not warrant that confidential material will not be published, and nothing in this Section should be read as such a warranty.

What we may do. Section 3 sets out when we may disable a Public Atom Page, and Section 3.1 sets out how to report one and what happens then.

7.6 Opening a Brain to the public, and closing it

What it is, and it is off until you do it. The owner of a Project can open its Brain to the public. An Open Brain is readable by anyone at the public address you choose, with no account and no sign-in, both as a web page and by any AI agent connected to its public read-only endpoint. Every Project is private. A Brain becomes public only when its owner deliberately opens it, and never by any other route. Opening is available on every tier at no charge.

Open, closed, and what each means. A Brain is private, open, or closed. Opening makes it public. Closing takes it out of public view: from the moment you close, new readers cannot reach it, new Forks cannot be taken, and its public address answers exactly as an address that never existed. You can reopen a Closed Brain, and reopening takes you through the review below again.

What closing cannot do, and this is the most important paragraph in this Section. Closing stops us serving the Brain. It cannot recall copies that other people already made. A Fork taken while the Brain was open continues as an independent copy in its owner's Project, keeps its Origin Credit, and keeps the licence it received (Section 7.7). Previews cached by other services when the address was pasted into them remain there. Before you open a Brain, satisfy yourself that everything in it, and everything you might add to it while it is open, can be copied by strangers and kept by them. Treat opening as something you can stop but cannot take back.

The review before you open. Because copies taken while a Brain is open cannot be recalled, the product requires you to review what will become public before it does. You see the full content of every Atom that will be published. The Service flags Atoms that appear to contain credentials, email addresses, internal addresses, or people's names, and you must deal with each flag explicitly before you can proceed. You can exclude individual Atoms. The step ends with a typed confirmation. The review is a control we provide, not a guarantee about outcomes. It is automated, it will miss things, and it does not warrant that nothing confidential or personal is published. What is published is what you confirmed.

What becomes public. The Brain's name, the description its owner writes, the Origin Credit (Section 7.8), the Handles and Public Profiles of the people or teams named in it, the time it was last updated, the number of Atoms in each category, and the full content of every published Atom, including superseded versions and the links between them. If you mark the Brain Forkable, its Documents become copyable too (Section 7.9).

What does not become public. Your other Projects, the members of this Project and their identities beyond the Handle shown in the Origin Credit, your Project's private history, your provider keys, your billing information, your email address, and anything in a Project you have not opened.

You decide, and you are responsible for the decision. You are the controller of what you open. Opening a Brain is a separate decision from deciding to store its content in Engrym, and it needs its own lawful basis for any personal data it contains, including personal data about your colleagues, your customers, and anyone named in a Document. We do not review what you open. Section 7.7 sets out what opening grants to the people who read and copy it.

What you can still do while it is open. You can keep editing an Open Brain, add to it, and remove Atoms from it. Removing every Atom leaves an empty Open Brain at the same address; it does not close it. You can turn Forkable off, which stops new Forks but does not affect Forks already taken. You can transfer the Brain to someone else (Section 7.10). And you can close it.

What we may do. Section 3 sets out when we may disable an Open Brain, and Section 3.1 sets out how anyone can report one and the control we use to act.

7.7 What opening a Brain grants to other people

Opening a Brain grants rights to other people. This Section says exactly which. We record each grant when you open a Brain, including who granted it, what was granted, the licence it was granted under, the version of these terms, and when.

To everyone, while a Brain is open: the right to read it. You grant every person a non-exclusive, worldwide, royalty free licence to read your Open Brain, to have their own AI agents read it, and to quote and reference it, on condition that they keep the Origin Credit intact when they do. This grant does not permit copying the Brain into another Engrym Project unless you have also marked it Forkable. Closing the Brain ends this grant for new readers.

When you mark a Brain Forkable: the Creative Commons Attribution 4.0 licence. Marking a Brain Forkable publishes its Atoms and Documents under the Creative Commons Attribution 4.0 International licence (CC BY 4.0). The product tells you this, and links to the licence, at the moment you turn Forkable on. In plain terms, CC BY 4.0 lets anyone copy, adapt, combine, and use the material for any purpose, including a commercial one, on condition that they credit you, do not suggest you endorse what they made, and do not add restrictions that would stop others doing the same. The licence's own text governs: it is at creativecommons.org/licenses/by/4.0, and where this Section summarizes it, the licence text prevails.

The CC BY 4.0 grant runs from you to every recipient directly, not through a chain. Under the licence, every person who receives the material receives their licence from you, not from whoever they copied it from. A person who Forks a Fork of your Brain holds their licence from you. Nothing that later happens to anyone in between, including their account being deleted, their Brain being Frozen, or their Brain being closed, affects it.

Attribution is a condition of the licence, not a request. The Origin Credit is how attribution is given inside the Service. Under CC BY 4.0, a person who fails to give attribution loses their rights under the licence automatically, and the licence sets out how those rights can be reinstated. Removing, altering, or misstating an Origin Credit is also a breach of Section 3.

What turning Forkable off, closing, or freezing does to these grants. Turning Forkable off stops new Forks. Closing stops new readers and new Forks. Neither withdraws a licence someone already received: CC BY 4.0 is irrevocable for material already received under it, and a Fork taken while the Brain was open keeps its licence. This is what makes a Fork safe to build on, and it is why the product asks you to review before you open rather than relying on closing afterwards.

What you do not grant. You grant nothing over content you have not published, over Projects you have not opened, or over any Atom you excluded during the review. You grant no rights in your Handle, your name, your Public Profile, or any trade mark, beyond the right to state accurately in the Origin Credit that the work originated with you. Nothing here transfers ownership: you continue to own what you published (Section 7.1).

What you receive as a reader or a Forker. When you read or Fork someone else's Open Brain you receive the licence set out above and nothing more. You are responsible for what you do with what you copied. The person who published it has told you nothing about whether it is accurate, whether it is suitable for your purpose, or whether they had the right to publish it, and we have not checked any of those things (Section 8). If the content includes personal data, or someone else's confidential or copyrighted material, your own use of it is your responsibility.

7.8 The Origin Credit

What it is. Every Open Brain and every Fork carries an Origin Credit naming where the work came from and who maintains it now, in the form "Originated by @A, Maintained by @B". It is generated by the Service from the record made when the Brain was opened. It is not a text field, nobody types it, and it cannot be edited.

Nobody else can remove your credit. No person who Forks your work can remove, alter, or obscure the Origin Credit through any part of the Service, and doing so by any other means ends their licence under Section 7.7 and breaches Section 3. This is the point of the Origin Credit and it is the commitment we make to you when you publish.

What appears in it, and for how long. While your account exists, the Origin Credit shows your Handle and links to your Public Profile. Changing your Handle changes what is displayed, everywhere it appears.

If you delete your account. Deleting your account removes your Handle from public display everywhere, including from every Origin Credit. The Origin Credit does not disappear: it continues to record that the work originated elsewhere, in a form that does not name you. Your Public Profile is removed, and the link from every Origin Credit to it is removed with it.

What deleting your account cannot do. It cannot recall the Atoms and Documents that other people copied while your Brain was open, and it cannot end the licence you granted them under Section 7.7. Those copies exist in their Projects, they may themselves have been opened and copied again, and neither we nor you can reach them. If it matters to you that something you publish can never be traced back to you, do not publish it. We say this to you at the moment you claim a Handle and again at the moment you open a Brain, so that the decision is made with this in front of you.

Transfers. When an Open Brain is transferred (Section 7.10), the "Maintained by" half changes to the new maintainer and the "Originated by" half does not. Transferring does not move the originator's credit, and accepting a transfer does not make you the originator.

7.9 Forking someone else's Open Brain

What a Fork is. If an Open Brain is marked Forkable, you can take a copy of it into a new Project of your own. You own the Project you create. What you may do with what you copied is set out in Section 7.7, which is a licence from the person who published it and not from us.

What copies. The Brain's Atoms and its Documents, as they stand when you Fork. What does not copy: the original's members and their access, the original's private history, its provider keys, its links to other Projects, and anything its owner did not publish. What is permanent: the Origin Credit (Section 7.8).

A Fork is a copy, not a subscription. Your Fork does not change when the original changes. If the original is updated, the Service can tell you what changed and let you take individual changes into your own Project. Nothing is ever merged into your Project without you choosing it, one change at a time.

Your Fork is yours, and it is unaffected by what happens to the original. If the original is emptied, closed, Frozen, transferred, taken down by us, or its owner's account is deleted, your Fork is unaffected and your licence continues (Section 7.7). The Origin Credit continues to show where the work came from, in the form Section 7.8 describes.

What you take on when you Fork. You are responsible for the content in your Project, including the part you copied. If you open your Fork, you are publishing that content, you need your own lawful basis for any personal data in it, and Section 7.6 applies to you exactly as it applied to the person you copied from. We have not checked what you copied, and neither the original publisher nor we make any promise that it is accurate, that it is fit for your purpose, or that they had the right to publish it (Section 8).

7.10 Freezing and transferring an Open Brain

Freezing. If an Open Brain is deleted and no members remain, it does not disappear. It becomes Frozen: it stops accepting any change, and it continues to be served at the same public address. If it was Forkable it stays Forkable. A Frozen Brain says plainly on its page that it is no longer maintained. This is deliberate, so that people who built on a Brain do not lose access to it because its maintainer moved on.

Freezing is not closing. Freezing changes who can write, not who can read. A Frozen Brain keeps being served because nobody remains who could close it: freezing happens only when a Brain has no members left. If you want a Brain out of public view, close it (Section 7.6) before you leave it or delete it. A Brain you closed before deleting is not Frozen; it is simply gone from public view. A Frozen Brain leaves public view only when a transfer is accepted and its new owner closes it, or when we act under Section 3.1.

Transferring. You can offer an Open Brain to another Engrym user. They see what they are being offered and what they take on, and they can decline. An offer expires if it is not accepted. Nothing moves until they accept.

What a transfer changes, and what it does not. On acceptance the recipient becomes the owner and the maintainer, the "Maintained by" half of the Origin Credit changes to them, and a Frozen Brain becomes active again. The "Originated by" half does not change (Section 7.8). Licences already granted under Section 7.7 are unaffected: they were granted by the original publisher, they run directly to each recipient, and a transfer neither withdraws them nor re-grants them.

What the recipient takes on. Accepting a transfer makes you responsible for the Brain, for what is in it, and for what it publishes, from the moment you accept. You are not responsible for what it published before you accepted, and accepting does not make you its originator.


8. Warranties, disclaimers, limitation of liability, and indemnity

8.1 Service provided "as is"

The Service is provided "as is" and "as available." To the maximum extent permitted by law, RTK AI Labs Ltd disclaims all implied warranties, including merchantability, fitness for a particular purpose, and non-infringement. Nothing in these terms excludes or limits any rights you have under mandatory consumer-protection law that cannot be excluded or limited.

8.2 Reconciliation verdicts and extracted Atoms are your agent's, not ours

A Reconciliation Verdict is produced by your AI agent. In agent mode, extracted Atoms are likewise produced by your agent and recorded as provisional pending your review. RTK AI Labs Ltd records these outputs; it does not generate them and does not warrant that they are correct. You are responsible for any decision you make based on a verdict, an Atom, or any content the Service serves to your agents.

8.3 Third-party AI providers

RTK AI Labs Ltd is not responsible for the availability, performance, output, or data-handling of the AI providers you choose under BYOK or through a Connected Agent, or for outages or changes at any AI provider. The relationship between you and your provider is governed by your agreement with that provider.

8.4 Limitation of liability

To the maximum extent permitted by law, RTK AI Labs Ltd will not be liable for indirect, incidental, special, consequential, or punitive damages, and its total liability arising out of or relating to the Service is limited as set out in these terms. Nothing in these terms limits liability that cannot be limited under applicable law, including liability for death or personal injury caused by negligence, for fraud, or under non-excludable consumer rights.

8.5 Indemnity

You are responsible for the content you upload and for your use of the Service, and you will be responsible for claims arising from your breach of these terms or your misuse of the Service, to the extent permitted by applicable law.


9. Suspension, termination, and deleting your data

Archiving a Project (self-serve). You can archive any Project you own from the product at any time. Archiving removes the Project from your working set. Archived-Project data is retained rather than purged (archiving never leads to deletion by itself), and there is currently no self-serve restore for an archived Project: contact us at the address in Section 12 to restore one. (Restoring a Project during the deletion grace window is different, and is self-serve; see the next paragraph.) If you want an archived Project's data gone rather than retained, you no longer need to contact us: you can permanently delete it yourself: the deletion flow below accepts archived Projects.

Deleting a Project (self-serve, permanent). A Project's owner, and only the owner, can permanently delete the Project, active or archived, from the Project's settings. Deletion requires typing the Project's name to confirm, and the confirmation shows real counts of what will be destroyed. Deletion then runs in two stages: first a grace window (currently seven days; the product shows the exact window and purge date) during which the Project disappears from every part of the Service and the owner, and only the owner, can restore it intact (restoring counts against your plan's Project limit: at the limit, you need a free slot or an upgrade first); then an automatic, irreversible purge of the Project's data. There is no restore after the purge. Deletion is refused while the Project is linked to another Project (remove the link first; the product tells you which linked Projects block and how many cross-references are involved) and, in the rare case that a subscription is anchored directly to the Project, until the billing situation is resolved: contact us at the address in Section 12.

What "permanent" means. The full deletion mechanics are set out in our Privacy Policy (Section 5), which governs this Section: what the purge destroys, what it does not touch, and what happens to your external Git repository (nothing: it is yours, and everything already exported to it stays where it is). Consistent with that policy: the purge removes the Project's data from our live systems, and nothing in the Service can bring it back; copies may persist for a limited period in our hosting providers' routine backups, which expire on those providers' backup-retention cycles, and we do not restore purged Project data from backups; and the Project's encryption keys are destroyed in the purge, which makes its stored provider keys and Git-export credential permanently unreadable everywhere, including in any backup copy. We do not claim deletion is instantaneous everywhere at once.

Deleting your account (via support). Account deletion is not yet self-serve. To delete your account, email us at the address in Section 12 from the email address on the account; we will verify the request and carry out the deletion, and your data is then handled as set out in our Privacy Policy (retention, deletion, and the export window). You may stop using the Service at any time without contacting us.

Suspension and termination by us. We may suspend or terminate your access for material breach of these terms, non-payment, or abuse (including conduct that threatens the security or stability of the Service or our providers). On termination, your data is handled as set out in our Privacy Policy, and the same windows govern this Section and Section 5.4.


10. Telemetry and the local Sync Daemon

The optional Sync Daemon runs on your own machine and ships without third-party error-telemetry, specifically to avoid sending telemetry from your environment. It transmits only your own Project sync data between your machine and your Project.


11. Changes to the Service and these terms

We may change features, tiers, and limits (including moving the Team tier from "coming soon" to available, or adjusting the usage limits in Section 4.4) as the product develops. For material changes to these terms, we will give notice through the Service or by email before the change takes effect.


12. Governing law, venue, and contact

RTK AI Labs Ltd is incorporated in England and Wales (company number 17179962). Registered office: 66 Paul Street, London EC2A 4NA, England. These terms are governed by the laws of England and Wales, and the courts of England and Wales have jurisdiction, except that, where you are a consumer, you retain the protection of mandatory provisions of the law of your country of residence and any right to bring proceedings there.

Contact: notices and legal correspondence can be sent to us by email at oussama.berrahal@engrym.com.


13. Document history

  • 19 September 2026. Section 5.5 corrected to the Founding Supporter terms as actually approved, together with the Section 5.1 and Section 5.3 lines that restate them. The Founding Supporter price is €14.99 per month and is monthly only; there is no yearly founding price. The figures previously published here, €9 per month and €90 per year, were never charged: no Founding Supporter price was ever created with our payment processor, and no Founding Supporter subscription has ever existed. The founding window is closed by a cap of 500 claimed places, permanently once that cap is reached, or by us closing it; the 30-day closing date and 400-place cap previously published here do not apply, and the window has no closing date. Section 5.5.3 keeps the price lock unchanged in substance and states it against the corrected price. Its re-entry rule is corrected to apply once the window has closed, rather than in every case.
  • 5 September 2026. Added the public-publishing sections. Section 7.5 covers Public Atom Pages, which have been live in the product and were not previously described in these terms. Sections 7.6 to 7.10 cover Open Brains: how a Brain is opened and closed, that closing stops new readers and new copies but cannot recall copies already taken, what opening grants to readers and to people who copy it (a Forkable Brain is published under the Creative Commons Attribution 4.0 licence), the Origin Credit and what account deletion does to it, forking, freezing, and transfers. Section 2.4 covers Handles and Public Profiles. Section 3 adds the acceptable-use rules for public surfaces, and new Section 3.1 sets out how to report content, what we do about a report, and the control we use to act. Section 7.1 is rewritten to separate the licence over your private content, which is unchanged, from the additional licence that begins only when you publish something. Section 4.3 is corrected to say that search query text is sent to Google on the Platform Key path, which was true before this revision and was not stated, and to say that public reads are never funded from your key or counted against your limits. A terms version identifier now appears in the header.
  • 11 July 2026. Section 9 updated for self-serve Project deletion, published together with the matching Privacy Policy Section 5 rewrite: a Project's owner can now permanently delete any Project, including an archived one, from the product, with a grace window (currently seven days; restorable by the owner during the window, and only then) followed by an automatic, irreversible purge. The archive paragraph is conformed: archived-Project data remains retained and restoring an archived Project still requires contacting us, but permanently deleting one no longer does. Added "What 'permanent' means" (the Privacy Policy governs; backup copies expire on our hosting providers' retention cycles; the Project's encryption keys are destroyed at purge; no claim that deletion is instantaneous everywhere). Account deletion remains via support, unchanged.
  • 10 July 2026. Added Section 5.5 (the Founding Supporter price: closed window, price lock, supporters-wall consent) and Section 7.4 (the Free-tier 90-day history display window: a display rule, not deletion, stated here before it is enforced so it is never retroactive). Free tier raised from one Project to three (unlinked). Scope line and Section 5.1 updated to match.
  • 3 July 2026. Updated to match the live product: Section 4.1 now describes the three extraction modes (BYOK, agent, mix) and the per-Project agent auto-pull consent switch; the earlier description of extraction as always running on a BYOK key predated agent mode. Removed the "first extraction free" wording from the scope line and Section 5.1: no platform-funded extraction path exists; extraction runs on your own key or your own agent subscription in every mode. Section 4.4 adds the agent-mode submission ceiling. Section 5 sets out the checkout terms (EUR pricing, monthly or yearly interval, no trial, portal cancellation, user-level subscription) and the exact yearly price. Section 9 now describes what exists today: self-serve Project archive (retained data, no self-serve restore) and account deletion via support rather than self-serve. Company-detail fields added for completion.
  • 19 June 2026. First published version.