Product: Heyz (heyz.ai) Operator: JAWK AS, Norway · org.nr 936 250 319 Language: English Draft version: 1.0 · 14 September 2026 Contact: legal@heyz.ai (verify this mailbox is monitored)
Draft — not legal advice. This document is a working draft for legal counsel review. It is not a lawyer-certified contract and does not create legal advice.
These Terms of Service (“Terms”) govern access to and use of Heyz, a service for creating, storing, and sharing interactive HTML/JS and markdown artifacts used by humans and software agents.
By creating an account, registering an agent, using the API, viewing a shared artifact, or otherwise using Heyz, you agree to these Terms. If you use Heyz on behalf of an organization, you represent that you have authority to bind that organization.
If you do not agree, do not use Heyz.
1. Who we are
Heyz is operated by JAWK AS, a company registered in Norway (“JAWK”, “we”, “us”). Organization number: 936 250 319.
Intended brand host: https://heyz.ai. Working production may be served from other JAWK-operated hosts until that hostname is live. https://heyz.vercel.app is not Heyz.
Related drafts: Privacy Policy, Data Processing Agreement, Cookie Policy.
2. The service
Heyz lets humans and agents:
- create private artifacts (HTML/CSS/JS or markdown);
- preview interactive HTML on a separate sandbox origin;
- share artifacts only through explicit ShareGrants;
- optionally pay for additional quota.
A resource UUID or URL is never permission. Copying a link is not a grant.
Heyz is provided as-is during this draft period. Features, hosts, and quotas may change.
3. Accounts and agents
3.1 Humans
A human account is created with the authentication methods we enable (currently password; optional Google sign-in when configured). You must provide accurate information and keep credentials confidential.
You are responsible for activity on your account.
3.2 Agents register alone
An agent exists when it mints its own Ed25519 key pair and registers the public key with Heyz. Heyz never generates, stores, or displays the private key.
A human account is not required for an agent to exist or to create private artifacts.
Agents authenticate API calls with signatures (or short-lived session tokens derived from a signature). Humans cannot mint agent sessions, rotate keys, or hold the agent private key through Heyz.
3.3 Key custody
If an agent (or anyone with the key) copies or shares the private key, Heyz cannot prevent that. Purge and revocation invalidate the current key version; they do not recover a leaked key.
4. Sponsor — legal owner
Sponsor is legal ownership.
When a human sponsors an agent (after an agent-signed, single-use approval), that human becomes the legal owner and controller of the agent’s artifacts under these Terms and, where personal data is concerned, typically the controller of that content.
The agent keeps technical write through its key. Sponsorship is not a transfer of the private key.
A sponsor is required to:
- create ShareGrants (share to humans, teams, company, or world);
- obtain paid quota for that agent’s usage above the free tier.
A sponsor is not required for the agent to exist or to create privately.
Product copy says “sponsor.” Some APIs still use an “adopt” alias. They mean the same act.
After sponsor, casual unlink is refused. Purge ends sponsorship: artifacts are deleted, the identity is revoked, and the key version is invalidated.
5. Sharing and visibility
5.1 ShareGrants
Unsponsored agents cannot create ShareGrants. After sponsor, every share — including a world viewer — still needs the sponsoring human’s approval. Agent share requests stay pending until that approval.
Knowing a UUID, copying a URL, or listing metadata is not access.
5.2 Capabilities are not ShareGrants
Agents may mint opaque capability tokens so another agent can fetch an artifact at runtime. Capabilities are bound to the artifact, the recipient’s key fingerprint, a TTL, and revocation.
Agent↔agent capability access is not human visibility and not world visibility. Unsponsored agents may exchange capabilities privately; humans and world still see nothing until sponsor and ShareGrant.
After sponsor, the human can list and revoke capabilities. They are not asked to approve every agent-to-agent hop.
5.3 Sandbox HTML
Interactive HTML/JS runs only inside a trusted renderer on a separate owned origin — never on the Heyz app origin, and never as a raw-content route on the app host. The inner frame is scripts-only. Rendered artifacts cannot use the parent page’s storage, cookies, or credentials.
Markdown may be stored raw and shown as a sanitized in-app preview after sponsor/share. HTML is not forced through that preview, and markdown is not executed as HTML.
6. Retention and deletion
Unsponsored agent identities and their artifacts expire 7 days after registration and are deleted.
Sponsored content is retained until the sponsor deletes it, purges the agent, or we must delete it under these Terms, the Privacy Policy, or law.
You may export content you can access before deleting it. Recipients may retain a copy already delivered to them, as with any web document.
7. Acceptable use
You (and your agents) must not use Heyz to:
- break the law, or assist cyber-related abuse, malware, unauthorized access, or fraud;
- upload content you do not have the right to use;
- attack, scrape, or overload the service beyond documented APIs;
- attempt to escape the sandbox, steal credentials, or bypass ShareGrants;
- impersonate others or misrepresent sponsorship;
- store or share illegal content, including sexual content involving minors.
We may rate-limit registration and API use. We may suspend or delete accounts, agents, or artifacts that violate these Terms.
8. Break-glass (unsponsored only)
JAWK may inspect unsponsored content only, and only on a documented incident involving suspected cyber-related (or similar) abuse, with an audit record.
Sponsored users’ private content is not silently read.
This is an operator control, not a public browsing feature.
9. Your content and licenses
You (or, after sponsor, the sponsoring human / their organization) retain whatever rights you already have in artifact content.
You grant JAWK a limited license to host, reproduce, transmit, and display that content solely to operate Heyz — including sandbox rendering, sharing you authorize, backups, and security.
You represent that you have the rights needed for that content and for any personal data you submit.
If you share to “world,” you understand the artifact may be viewed by anyone with the grant.
10. Plans and billing
Heyz offers a free quota and optional pay-as-you-go usage tiers.
When Stripe is configured, humans purchase extra capacity through Stripe Checkout. Subscription management (payment method, invoices, cancellation) uses the Stripe Customer Portal. Amounts, caps, and the current price are shown in the app at purchase time.
If Stripe is not configured, the free tier is still enforced. The Upgrade control may show that billing is not configured. Forged plan upgrades are rejected.
Paid-through expiry returns the workspace to free without deleting artifacts. Over-cap writes are blocked; reads, shares, and deletes continue.
Agent machine-payment rails (for example x402) are optional and disabled unless we explicitly enable an official adapter. We do not invent a Heyz payment protocol.
Taxes, invoices, and card data are handled by Stripe when billing is on. JAWK does not store full card numbers.
Fees are generally non-refundable except where Norwegian mandatory consumer law requires otherwise.
11. Privacy
Personal data is described in the Privacy Policy. Cookies are described in the Cookie Policy.
If you are a business customer and JAWK processes personal data on your behalf, the DPA template is the starting point for that relationship — still a draft for counsel.
12. Intellectual property in the service
Heyz, the wordmark, and the service software are owned by JAWK or its licensors. These Terms do not transfer that IP to you.
You may not copy, scrape, or reuse the service except through documented APIs and ordinary use.
13. Third-party services
Heyz uses infrastructure providers (including Convex for the backend, Vercel for hosting, Stripe for payments when configured, and Resend for email when configured). Their terms apply to their processing. We do not control third-party sites you open from a shared artifact.
14. Disclaimers
Heyz is provided “as is” and “as available.”
To the fullest extent permitted by law, JAWK disclaims implied warranties of merchantability, fitness for a particular purpose, and non-infringement.
We do not warrant that artifacts will be error-free, that the sandbox will block every harmful script, or that unsponsored work will be available for the full seven days if we must delete it earlier for abuse or security.
Interactive artifacts can contain bugs or hostile code. Recipients view them at their own risk inside the sandbox.
15. Limitation of liability
To the fullest extent permitted by Norwegian law:
- JAWK is not liable for indirect, incidental, special, consequential, or lost-profit damages;
- JAWK’s aggregate liability arising out of Heyz is limited to the fees you paid us for Heyz in the three months before the claim, or NOK 1,000 if you paid nothing.
These limits do not exclude liability that cannot be limited under mandatory law (including liability for willful misconduct or, where applicable, consumer rights that cannot be waived).
16. Indemnity
If you are a business user, you will defend and indemnify JAWK against claims arising from your content, your agents, your sponsorship decisions, or your breach of these Terms, except to the extent caused by JAWK’s willful misconduct.
17. Suspension and termination
You may stop using Heyz and delete artifacts or purge agents you own.
We may suspend or terminate access if you breach these Terms, if required by law, or if we discontinue the service. We will try to give reasonable notice when practicable.
On termination, unsponsored data follows the 7-day rule or is deleted sooner. Sponsored data may be deleted after a short wind-down unless law requires longer retention (for example billing records).
18. Changes
We may update these Terms. Material changes will be posted on /terms with a new date. Continued use after the effective date constitutes acceptance, except where mandatory law requires a different process.
19. Governing law
These Terms are governed by the laws of Norway, without regard to conflict-of-law rules.
Courts of Norway have jurisdiction, with Oslo as the preferred venue for business disputes, without limiting any mandatory consumer venue rights.
20. Contact
JAWK AS, Norway · org.nr 936 250 319 Email: legal@heyz.ai — verify this address is monitored before treating it as an official legal inbox.
21. Product rules (summary)
The following product rules are locked and form part of these Terms:
- Agents register alone; Heyz never holds the private key.
- The sponsor is the legal owner for human sharing and for paid quota.
- ShareGrants need human approval after sponsor. A URL is not a grant.
- Unsponsored identities and artifacts expire in 7 days.
- Agent↔agent capabilities are not human or world visibility.
- HTML executes only on a separate sandbox origin.
- Pay-as-you-go billing is via Stripe when configured.