Legal

Terms of Service.

Effective July 14, 2026

These Terms, version 2026-07-14, form a contract between you and SMASHING DIVS for the Trumpets Services. They also serve as the rules for electronically supplied services under Polish law. Read them before creating an account or buying a paid Service.

1 · Provider and scope

The Services are provided by SMASHING DIVS, EU VAT ID PL9930619827, Stanisława Moniuszki 26, 33-100 Tarnów, Poland ("SMASHING DIVS", "Trumpets", "we", or "us"). Contact: hello@trumpets.ai.

These Terms govern trumpets.ai, the Trumpets Dashboard, agent and workflow runtime APIs, and company-operated products that link to these Terms, including Trumpets-powered Apps (together, the "Services"). Product-specific pricing, feature descriptions, order forms, and expressly agreed special terms also apply. If they conflict, a signed order form or special terms control for that subject, then the Data Processing Addendum, then these Terms.

You may save or print these Terms. They are provided in English. The current version is available at trumpets.ai/terms.

2 · Definitions

  • App a standalone company-operated product powered by Trumpets and linking to these Terms.
  • Business Customer a person or entity using the Services mainly for a trade, profession, organization, or other business purpose.
  • Consumer an individual entering the contract for purposes mainly outside their trade, business, craft, or profession, including any individual entrepreneur entitled to consumer-like protection under mandatory Polish law.
  • Customer the person or entity that accepts these Terms or orders the Services.
  • Customer Content prompts, instructions, files, knowledge sources, messages, tool results, data, configurations, and other material submitted to or generated through the Services for a Customer.
  • Output material generated, transformed, classified, extracted, or returned by an AI model, workflow, tool, or App.
  • Credits usage points, credits, or another product-specific unit used to meter eligible actions. Credits are not money, electronic money, or a transferable financial asset.
  • User an individual authorized to access a Customer account or organization.

3 · Acceptance and eligibility

You accept these Terms by selecting the unticked Terms acceptance control before creating an account, by signing an order form, or by another affirmative acceptance method we present. We record the Terms version, time, account, method, and locale as contract evidence. A Privacy Policy link is a notice and is not bundled into this contractual acceptance. If you do not agree, do not create an account or use the Services.

You must be at least 18 years old or the age of legal majority where you live and able to enter a binding contract. If you act for an organization, you confirm that you have authority to bind it. An organization administrator may accept these Terms and manage the organization for all authorized Users.

Our Privacy Policy is a notice about personal data, not a request to consent to all processing. Where consent is legally required, we ask for it separately.

4 · The Services

Trumpets lets Customers configure, test, run, monitor, and improve AI agents and workflows using prompts, knowledge sources, models, tools, schedules, APIs, and integrations. Apps use parts of that platform for a defined task, such as drafting, narration, research, or interview preparation.

Electronically supplied services can include account registration and authentication, workspace and team management, cloud storage, AI generation, search, integration access, run history, support, subscription management, and related App features.

You need a supported modern browser or API client, a working internet connection, JavaScript where the interface requires it, and an email address you can access. Some features need a compatible third-party account, API key, permission, file format, or paid plan. You are responsible for your equipment, connectivity, and third-party fees.

5 · Accounts and organizations

  • Provide accurate account information and keep it current. Do not create an account using another person's identity or an email you do not control.
  • Keep passwords, sessions, API keys, integration credentials, and recovery methods confidential. Tell us promptly about suspected unauthorized access.
  • You are responsible for activity under your account and for Users you authorize, except to the extent caused by our breach of these Terms or applicable law.
  • Organization owners and administrators can invite and remove Users, assign roles, manage billing and content, and access organization data according to the Service's permissions. A Customer is responsible for choosing administrators and permissions.
  • An account is personal and may not be sold or transferred. A Business Customer may reassign a seat or account access to another authorized User through supported controls.

6 · AI systems and Outputs

The Services use generative and other AI systems. You are interacting with AI when an agent, workflow, or App generates or analyzes material. AI is probabilistic: an Output can be inaccurate, incomplete, outdated, biased, offensive, or similar to material produced for another user.

You must review Outputs before using or sharing them, check important facts and sources, and apply qualified human judgment. Outputs do not replace legal, medical, tax, financial, employment, safety, or other professional advice. Clause is not a law firm and does not provide legal advice. Callback does not guarantee employment or interview outcomes. Narration and media Users, including on Narrata, must hold the necessary text, voice, likeness, music, and publication rights.

You may not represent an AI Output as human-created where law or context requires disclosure. You are responsible for notices, labeling, provenance, accessibility, and human oversight required for your use. Do not make a solely automated decision with legal or similarly significant effects about a person through the Services unless it is lawful, documented, appropriately supervised, and separately agreed with us where required.

7 · Models, tools, and third-party services

A feature may use Google Gemini, Google Search, OpenRouter and a downstream model provider, Stripe, Supabase, Google Workspace, an MCP server, or another third-party service. We can add, replace, or remove providers while preserving the material function of the Service, subject to the change and data processing sections below.

When you select or connect a third-party service, you authorize us to send it the data and instructions reasonably needed to perform the request and to receive its result. Third-party services can have separate terms, usage limits, content rules, retention, geographic processing, and availability. You are responsible for an account or API key you supply and for complying with its terms.

Google Search grounding and other web research can process a query outside the EEA. Do not include confidential or unnecessary personal data in a search query. We are not responsible for third-party content or websites returned by a search tool, but this does not limit our responsibility for selecting subprocessors as required by GDPR.

8 · Acceptable use

You must not use, or help another person use, the Services to:

  • break a law, court order, sanction, export control, or third-party right;
  • submit personal, confidential, copyrighted, or regulated data without the necessary rights, legal basis, notices, permissions, and safeguards;
  • create or distribute malware, phishing, spam, fraud, impersonation, deceptive content, child sexual abuse material, non-consensual intimate material, or content that facilitates violence or other serious harm;
  • perform prohibited manipulation, exploitation, social scoring, unlawful biometric identification or categorization, unlawful surveillance, or another AI practice prohibited by applicable law;
  • make an unlawful discriminatory decision or a high-impact decision without qualified human review and required safeguards;
  • probe, scan, attack, overload, disrupt, bypass, or obtain unauthorized access to the Services, another tenant, or a provider;
  • reverse engineer or extract source code, models, prompts, or non-public data except to the extent a non-waivable law expressly permits it;
  • evade usage, billing, safety, rate, access, or model-provider controls, including by creating accounts or automations to circumvent a limit;
  • resell, sublicense, or provide the Services as a competing service unless a written agreement permits it; or
  • use Output or personal data to train or evaluate a biometric identification system, conduct unlawful profiling, or infer sensitive traits in a prohibited manner.

We may investigate suspected abuse and preserve or disclose relevant information when lawfully required. Report illegal content or misuse to hello@trumpets.ai with enough detail to identify it.

9 · Customer Content

As between you and us, you retain your rights in Customer Content. You grant us a worldwide, non-exclusive, royalty-free license to host, copy, transmit, transform, display, and otherwise process Customer Content only as needed to provide, secure, support, and comply with law in relation to the Services. This license ends when the content is deleted, except for limited backup, legal, and technical retention described in the Privacy Policy.

You confirm that you have the rights and lawful basis needed for Customer Content and our processing under your instructions. You are responsible for its accuracy, legality, notices, retention, and the consequences of using or sharing it.

Subject to applicable law and third-party rights, we assign to you any rights we may have in an Output generated specifically for you. This does not transfer our platform, templates, models, prompts, tools, or pre-existing materials, and does not guarantee that an Output is protectable, exclusive, non-infringing, or unique. You must perform an appropriate rights review before commercial publication or use.

We do not use Customer Content to train our own general-purpose model. Provider-side processing and limited abuse-monitoring retention are described in the Privacy Policy.

10 · Privacy and data protection

The Privacy Policy explains processing for which SMASHING DIVS is controller, including accounts, billing, support, security, analytics, and marketing.

Where a Business Customer is controller of personal data in Customer Content and we process it on the Customer's behalf, the Data Processing Addendum in section 23 applies automatically. A Customer must not instruct us to process personal data in violation of law. The Customer remains responsible for its data subjects, lawful bases, notices, requests, retention rules, and data protection impact assessments.

11 · Plans, Credits, and billing

11.1 Plans and pricing

Available plans, included Credits, action prices, currency, billing interval, taxes, seat minimums, and pack terms are shown in the relevant Service or order flow. Prices may differ between Apps. A price shown before checkout controls for that purchase.

11.2 Subscriptions

A paid subscription renews for the interval shown at checkout until canceled. You authorize Stripe and us to charge the selected payment method at each renewal, including applicable taxes. You can cancel through the billing portal or by contacting us. Unless the order flow says otherwise, cancellation takes effect at the end of the paid billing period and does not retroactively refund amounts already due, without limiting mandatory Consumer rights.

11.3 Credits and usage

An action can consume the number of Credits shown in the Service. Subscription Credits can reset at renewal and may not roll over. Purchased packs are governed by the terms shown at purchase. Failed eligible actions may be automatically reversed where the Service says so. Credits have no cash value, cannot be transferred outside the permitted organization, and are not redeemable for cash except where law requires a refund.

11.4 Changes, failed payments, and taxes

We may change a recurring price prospectively by giving reasonable advance notice. A price change applies no earlier than the next renewal after the notice period. You may cancel before it applies.

If payment fails, we may retry the charge, restrict paid features, or suspend the paid plan after notice. You remain responsible for undisputed amounts. Prices include or exclude VAT and other taxes as stated at checkout. You must provide accurate billing and tax information.

11.5 Checkout information and confirmation

Immediately before a paid checkout, the Service presents separate affirmative controls for an express request to begin performance during the withdrawal period and for the applicable withdrawal consequences. Stripe Checkout presents the final total, currency, taxes, billing interval, and renewal terms before the order is placed. After successful payment, Stripe and/or Trumpets sends a durable transaction or order confirmation that identifies the purchase and the applicable Terms version. Keep that confirmation.

12 · Consumer rights

This section applies only to Consumers and supplements, but does not limit, mandatory consumer law. If a mandatory rule where you live gives you greater protection, that rule controls.

12.1 Right to withdraw

A Consumer who concludes a distance contract may generally withdraw without giving a reason within 14 days from the day the service contract is concluded. To withdraw, send an unambiguous statement to SMASHING DIVS at the postal or email address in section 1 before the deadline. You may use, but do not have to use, the model form in section 24.

If you expressly request a paid service to begin during the withdrawal period and then withdraw before it is fully performed, you may have to pay an amount proportionate to the service supplied up to withdrawal, where the law permits. You lose the withdrawal right for a fully performed paid service only after the legally required express prior request, information, and acknowledgement. For paid digital content not supplied on a tangible medium, loss of the right requires the express prior consent, acknowledgement, and contract confirmation required by law. Merely using the Service does not remove a right where those formalities were not met.

After a valid withdrawal, we will return payments due without undue delay and no later than 14 days after receiving the notice, using the original payment method unless you agree otherwise, subject to lawful deductions for service already supplied.

12.2 Conformity and remedies

We must supply a digital service that conforms to the contract, including applicable functionality, continuity, security, and updates required by mandatory law. If it does not conform, a Consumer may request that it be brought into conformity and may be entitled to a price reduction, termination, or refund under applicable law. A Consumer's statutory remedies are not replaced by a commercial refund policy or a warranty disclaimer in these Terms.

12.3 Consumer complaints

Send a complaint to hello@trumpets.ai with your account email, the Service, order or transaction reference where relevant, the issue, and the remedy requested. We will respond within the period required by applicable law, including 14 days where Polish consumer law requires that period.

13 · Our intellectual property

The Services, software, interfaces, designs, documentation, brands, templates, platform prompts, workflows, and other materials supplied by us are owned by or licensed to SMASHING DIVS. Except for Customer Content and rights expressly granted in section 9, no right is transferred to you.

During the contract, we grant you a limited, non-exclusive, non-transferable, revocable right to access and use the Services for their intended purpose and within your plan. You may not remove notices or use our names or marks to imply endorsement without permission.

If you voluntarily provide product feedback, you grant us a perpetual, worldwide, royalty-free right to use it without identifying you or disclosing your confidential information. You are not required to provide feedback.

14 · Confidentiality

Each party receiving non-public information that is marked confidential or should reasonably be understood as confidential will use it only to perform or receive the Services, protect it with reasonable care, and disclose it only to personnel and providers who need it and are bound by confidentiality.

This duty does not cover information the recipient can show was lawfully known without restriction, independently developed, lawfully received from another source, or made public without breach. A legally compelled disclosure is permitted after notice where legally allowed and reasonable assistance to seek protection.

15 · Availability, maintenance, and Service changes

We aim to keep the Services available but do not promise uninterrupted operation unless a separate service level agreement says so. Maintenance, security incidents, provider failures, internet conditions, model limits, or events outside reasonable control can interrupt or delay a feature.

We may improve, replace, or discontinue a feature. For a material reduction to a paid Service, we will provide reasonable notice where practicable and a remedy required by the contract or mandatory law. We may make an immediate change needed for security, law, provider restrictions, or to prevent harm.

16 · Suspension, termination, and data exit

16.1 By you

You may stop using a free Service at any time. You may cancel a subscription as described in section 11. The Dashboard and current company-operated Apps offer portable JSON export and account deletion controls; you may also email us. Export data you need before closure. Deletion is blocked where automatically deleting a shared organization would affect other members, until ownership or membership is resolved.

16.2 By us

We may suspend or restrict access immediately where reasonably necessary to address a security risk, illegal activity, abuse, unauthorized access, provider mandate, or risk of material harm. For another material breach, we will normally give notice and a reasonable opportunity to cure before termination. We may terminate a free inactive Service or discontinue a Service with reasonable notice.

16.3 Effect

On termination, your right to use the affected Service ends. Amounts already due remain payable. Sections intended by their nature to survive do so, including intellectual property, confidentiality, liability, disputes, and data processing obligations.

We delete or return Customer Content as described in the Privacy Policy, the Data Processing Addendum, and any order form, subject to backup cycles and legally required retention. Consumers retain any mandatory right to access or retrieve non-personal content after termination.

17 · Warranties and disclaimers

We warrant that we will provide paid Services with reasonable care and skill and in material accordance with their current description. Consumer statutory conformity rights remain fully applicable.

For Business Customers, except for an express warranty in these Terms or an order form, the Services and Outputs are provided "as is" and "as available". To the maximum extent permitted by law, we disclaim implied warranties of merchantability, fitness for a particular purpose, non-infringement, accuracy, and uninterrupted or error-free operation. We do not warrant that an Output is correct, unique, lawful for your intended use, or accepted by a court, regulator, employer, publisher, or other third party.

18 · Liability

18.1 Consumers

Nothing in these Terms excludes or limits liability or remedies that cannot lawfully be excluded or limited for a Consumer. Consumer liability is governed by applicable mandatory law.

18.2 Business Customers

To the maximum extent permitted by law, neither party is liable to the other for lost profit, revenue, goodwill, business opportunity, or anticipated savings, or for indirect or consequential loss, arising from the Services, even if advised that it was possible.

To the maximum extent permitted by law, each party's total aggregate liability arising from or relating to the Services during any 12-month period is limited to the fees paid or payable by the Customer for the affected Services during the 12 months before the event giving rise to liability. For a free Service, our aggregate liability is limited to EUR 100.

The exclusions and cap do not apply to payment obligations, fraud, willful misconduct, death or personal injury caused by negligence, infringement or misappropriation of the other party's intellectual property, or any liability that applicable law or binding data transfer clauses do not permit the parties to limit. They do not reduce a data subject's rights under GDPR.

19 · Business Customer indemnity

A Business Customer will defend and indemnify SMASHING DIVS against a third-party claim, damage, or reasonable cost arising from Customer Content or the Customer's unlawful or unauthorized use of the Services, except to the extent caused by our breach, negligence, or misconduct. We will promptly notify the Customer, allow it to control the defense and settlement, and provide reasonable cooperation at its cost. The Customer may not settle a claim in a way that admits fault by us or imposes an obligation on us without our written consent, not to be unreasonably withheld.

20 · Changes to these Terms

We may update these Terms for legal, security, provider, or product reasons. We will post the revised Terms and effective date. For a material change that adversely affects an existing paid contract, we will give at least 14 days' advance notice by an appropriate account or email notice unless law, security, or urgent provider action requires a shorter period.

A material adverse change applies prospectively. If you do not accept it, you may stop using the affected free Service or cancel the affected paid Service before it takes effect. A Consumer may also terminate where mandatory law provides that remedy. We do not treat silence as consent where the law requires express agreement.

21 · Complaints, law, and disputes

First send a complaint to hello@trumpets.ai or the postal address in section 1. Include enough information for us to identify the account, transaction, or content and the resolution you seek.

These Terms are governed by Polish law. For a Business Customer, courts with jurisdiction over Tarnów, Poland have exclusive jurisdiction, unless an order form says otherwise. For a Consumer, this choice does not deprive you of mandatory protection under the law of your habitual residence or your right to bring a claim in any court available under mandatory consumer law.

A Consumer may seek out-of-court help from a municipal or district consumer ombudsman, the Polish Trade Inspection, a competent consumer ADR body, or the European Consumer Centre where applicable. Information is available from the Polish Office of Competition and Consumer Protection. Participation in a particular ADR procedure is voluntary unless mandatory law says otherwise.

22 · General terms

  • Notices. We may send operational or contractual notices to your account email, display them in the Service, or post them on the relevant legal page. You must keep your email current.
  • Assignment. You may not assign the contract without our consent, except as part of a permitted transfer of an entire business with written notice. We may assign it in a merger, reorganization, sale of business, or to an affiliate, provided this does not reduce Consumer rights or data protection safeguards.
  • Force majeure. Neither party is liable for delay caused by events outside reasonable control, but this does not excuse payment already due or obligations that can still reasonably be performed.
  • No waiver. A failure to enforce a term is not a waiver. A waiver must be in writing and applies only to the stated instance.
  • Severability. If a term is unenforceable, it will be limited to the minimum extent necessary and the remaining terms continue. For a Consumer, a mandatory rule replaces an unfair or unenforceable term.
  • Entire agreement. These Terms, the order, applicable product terms, and the Data Processing Addendum are the entire agreement about the Services, without excluding liability for fraud or a statement that law does not permit a party to exclude.
  • No third-party beneficiaries. Except for rights expressly granted to data subjects under GDPR or Standard Contractual Clauses, the contract does not give rights to a third party.

23 · Data Processing Addendum

This Data Processing Addendum ("DPA") forms part of the Terms whenever a Customer is a controller or processor of personal data in Customer Content and SMASHING DIVS processes that data on the Customer's behalf. GDPR terms such as controller, processor, personal data, processing, data subject, and personal data breach have the meanings given in GDPR.

23.1 Roles, scope, and instructions

The Customer is the controller or a processor authorized by the relevant controller. SMASHING DIVS is the processor or subprocessor. We will process personal data only on the Customer's documented instructions, including these Terms, the Customer's use and configuration of the Services, an order form, and written support instructions, unless EU or Member State law requires other processing. If legally permitted, we will notify the Customer before processing required by law. We will promptly tell the Customer if we believe an instruction infringes applicable data protection law and may suspend the affected processing while the parties resolve it.

23.2 Customer responsibilities

The Customer confirms that its instructions are lawful and that it has provided all required notices and obtained all necessary rights and lawful bases. The Customer will minimize personal data, configure appropriate access and retention, respond to data subjects, and not submit special-category or criminal-offence data unless the processing is lawful, necessary, risk-assessed, and protected by appropriate safeguards.

23.3 Confidentiality

We ensure that persons authorized to process Customer personal data are bound by confidentiality or an appropriate statutory duty and access it only as needed for their role.

23.4 Security

Taking account of the state of the art, implementation cost, and the nature, scope, context, purposes, and risks of processing, we will maintain appropriate technical and organizational measures under Article 32 GDPR. Current measures include TLS in transit; identity, tenant, role, and row-level access controls; scoped API and integration credentials; restricted administrator access; audit and operational logging; environment separation; backups and recovery procedures; vulnerability and dependency review; and incident response procedures.

The Customer is responsible for secure endpoints, passwords, API keys, permissions, lawful configurations, and its own backups or exports. We may update measures as technology and risk change without materially reducing overall protection.

23.5 Subprocessors

The Customer gives general written authorization for us to use subprocessors needed to provide the Services. Current provider categories and principal providers are listed in the Subprocessor Register. We will impose data protection obligations on a subprocessor that provide substantially the protection required by this DPA, and we remain responsible for its performance to the extent required by Article 28 GDPR.

Where required, we will give notice of a new subprocessor before it begins processing Customer personal data. The Customer may object within 14 days on reasonable, documented data protection grounds. The parties will work in good faith on a commercially reasonable alternative. If none is available, either party may terminate only the affected feature or Service, and we will refund prepaid fees for the unused terminated period where appropriate.

23.6 International transfers

We will not transfer Customer personal data outside the EEA except under a lawful transfer mechanism. Where the European Commission Standard Contractual Clauses are required for a transfer by us to a subprocessor, we will enter into the applicable module with that recipient and complete the required options and annex information. We will conduct and support transfer assessments and supplementary measures where required. The Privacy Policy describes known location variability, including search grounding and model routing.

23.7 Assistance

Taking account of the nature of processing and information available to us, we will reasonably assist the Customer with data subject requests, security duties, personal data breach assessments and notifications, data protection impact assessments, and prior consultation with a supervisory authority. If a data subject contacts us about Customer personal data, we will refer the request to the Customer and will not respond substantively unless instructed or legally required.

23.8 Personal data breaches

We will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer personal data. As information becomes available, we will provide the nature of the breach, likely consequences, affected data and data subjects where known, contact point, and mitigation taken or proposed. Our notice is not an admission of fault. The Customer is responsible for notifications it must make as controller.

23.9 Return and deletion

During the contract, available controls and support requests can delete or export certain data. At the Customer's choice after the relevant Service ends, we will delete or return Customer personal data and delete remaining copies, unless law requires storage. Data may remain in isolated backups until normal rotation and may be retained where necessary for legal claims, in each case protected and excluded from further ordinary processing. The Customer should request a return before account closure.

23.10 Demonstrating compliance and audits

We will provide information reasonably necessary to demonstrate compliance with Article 28 GDPR and allow an audit by the Customer or an independent auditor bound by confidentiality. An audit must normally be requested at least 30 days in advance, occur no more than once per year, avoid access to other customers' data, and not unreasonably disrupt the Services. These limits do not apply where a supervisory authority requires otherwise or credible evidence of a material breach justifies an additional audit. The Customer pays its audit costs unless the audit identifies our material breach.

23.11 Processing details

  • Subject matter. Providing AI agent, workflow, storage, collaboration, integration, support, and App services selected and configured by the Customer.
  • Duration. The term of the Services plus the limited deletion, backup, and legal retention period described above.
  • Nature and purpose. Collecting, recording, organizing, structuring, storing, retrieving, consulting, transmitting, generating, transforming, embedding, comparing, evaluating, making available, securing, supporting, deleting, and other processing needed to perform Customer instructions.
  • Data subjects. Customer Users, personnel, clients, prospects, contractors, collaborators, end users, website visitors, correspondents, document authors and subjects, job applicants, matter participants, and other people whose data the Customer submits.
  • Personal data. Identifiers, contact and professional data, account and permission data, communications, document and file content, prompts and Outputs, usage and technical data, integration content, employment and education data, audio or voice recordings, and any other category submitted by the Customer.
  • Sensitive data. The Services are not designed for biometric identification or medical records, but Customer Content can incidentally include special-category data or criminal-offence data. The Customer must apply section 23.2 and any additional safeguards required by law.
  • Frequency. Continuous for stored data and each time a User, API, schedule, integration, agent, workflow, or support instruction initiates processing.

23.12 Conflict and liability

This DPA controls over the rest of the Terms for its subject. An applicable Standard Contractual Clause controls over this DPA where they conflict. Contractual liability limits apply between the parties to the extent permitted, but do not limit a data subject's rights or liability that GDPR or an applicable Standard Contractual Clause does not allow the parties to limit.

24 · Model Consumer withdrawal form

Complete and send this form only if you are a Consumer and want to withdraw from an eligible distance contract:

To: SMASHING DIVS, Stanisława Moniuszki 26, 33-100 Tarnów, Poland, hello@trumpets.ai

I hereby give notice that I withdraw from my contract for the following Service: [Service and plan]
Contract/order date: [date]
Consumer name: [name]
Consumer address: [address]
Account email or order reference: [details]
Date: [date]
Signature: [only if sent on paper]

Stay in tune.

Product notes, orchestration patterns, and the occasional field report - sent only when there’s something worth playing.

One email a month at most. Unsubscribe anytime.