Terms of Service

Last updated: July 2026

These Terms govern your use of Zephex and the dashboard (the "Service"). By creating an account, generating an API key, or using the Service, you agree to these Terms.

How Zephex is built

Zephex is a hosted MCP (Model Context Protocol) service. Your MCP client connects to zephex.dev/mcp; tool calls run on our MCP Server; account data lives in our database; sign-in and API keys are handled by our authentication layer. Live health for each layer is published at zephex.dev/status.

  • SupabasePostgres database and dashboard authentication (accounts, API key hashes, usage logs, sessions).
  • Auth0OAuth authorization server for MCP connector clients (Claude.ai, ChatGPT, PKCE flows).
  • RailwayMCP Server — hosts tool execution (find_code, read_code, check_test, etc.).
  • VercelDashboard, public MCP endpoint proxy (zephex.dev/mcp), and edge routing.
  • Upstash RedisRate limiting, session cache, and health-check coordination.
  • StripePayments, subscriptions, and billing meters.
  • ResendTransactional email (verification, security alerts, billing notices).
  • SentryError monitoring with PII redaction.
  • PostHogProduct analytics (optional; EU users can decline via cookie banner).

Full detail: Authentication, Data Handling, Privacy Policy (docs).

1. Eligibility and Age Requirement

You must be at least 13 years old to use Zephex. If you are under 13, you may not create an account.

By using Zephex, you represent that you are 13 or older. Users under 13 may not create accounts or use paid features.

2. What the Service does

Zephex routes Model Context Protocol (MCP) requests through our hosted proxy using your API key. The Service may also include built-in tools and a dashboard for keys, usage, and billing.

3. Accounts and API keys

  • You are responsible for all activity under your account and API keys.
  • Keep API keys secret. Do not post them in public repos, screenshots, or logs.
  • If a key is exposed, rotate or revoke it immediately.
  • API keys are stored as HMAC-SHA256 hashes with a per-key salt — plaintext is never retained after creation.
  • Keys may expire after 365 days by default; you may configure shorter lifetimes.

Team and organizational use

If you roll Zephex out to a team, the account owner remains responsible for every API key created under that account. Each developer should use named keys per environment; shared keys in chat or public repos violate our acceptable-use rules.

  • The account owner is responsible for all API key usage under their organization, including contractors.
  • API keys must not be embedded in client-side code, public repositories, or shared chat channels.
  • Each team member should use their own named key where possible so usage and revocation are attributable.
  • Pro and Max plans may restrict keys to specific tools; calls outside the allowlist are rejected.
  • Users must keep at least four of ten MCP tools enabled in editor configuration.
  • Exceeding plan quotas or abusing rate limits may result in throttling (HTTP 429) or suspension.
  • Enterprise volume or custom limits: contact support@zephex.dev.

Rollout guidance: Team MCP rollout (docs).

4. Acceptable use

You agree not to misuse the Service, including:

  • Trying to bypass rate limits, quotas, or security controls.
  • Attempting to access data that is not yours.
  • Using the Service for unlawful activity or to harm others.
  • Interfering with or disrupting the Service.

5. Usage limits and billing

  • Plans include request limits and may enforce rate limits by tier.
  • Paid plans are billed through Stripe. Taxes may apply.
  • We may suspend or limit access if you exceed limits or abuse the Service.

6. Availability

We work hard to keep the Service available, but we do not guarantee uninterrupted operation. Maintenance, outages, and upstream dependencies can affect availability.

7. Your content

You may send content through the Service (for example: tool inputs, prompts, URLs, and configuration). You retain your rights to your content. We process it only to provide and secure the Service as described in our Privacy Policy and Data Use policy.

Zephex does not use prompts, tool inputs, tool outputs, or repository content accessed through tools to train, fine-tune, or evaluate AI models. This applies to all plans without exception.

Tool call content is processed in memory for a single request/response cycle and is not persistently stored. See Data Use and Data Handling (docs).

8. Termination

You can stop using the Service at any time. We may suspend or terminate access if we reasonably believe you violated these Terms or if continued access creates risk for the Service.

9. Disclaimers and limitation of liability

The Service is provided "as is" and "as available." To the maximum extent permitted by law, we disclaim warranties and limit liability for indirect, incidental, special, or consequential damages.

10. Force Majeure

We are not liable for any failure to perform due to causes beyond our reasonable control, including natural disasters, war, terrorism, riots, embargoes, acts of civil or military authorities, fire, floods, accidents, strikes, or shortages of transportation, facilities, fuel, energy, labor, or materials.

11. Governing Law and Arbitration

These Terms are governed by the laws of the State of Delaware, USA. Any dispute arising from these Terms will be resolved through binding arbitration in accordance with the American Arbitration Association rules. Arbitration will be the sole remedy for any dispute, and you waive any right to participate in class actions or jury trials.

12. DMCA and Copyright

We respect intellectual property rights. If you believe your copyright has been infringed, please send a DMCA notice to our designated agent with the following information:

  • Description of the copyrighted work
  • Location of the infringing material
  • Your contact information
  • A statement of good faith belief
  • A statement of accuracy under penalty of perjury

13. Contact

Questions about these Terms: support@zephex.dev