Legal
Platform Terms of Service
The short version
- You own your code, your data, your customers and your revenue.
- Hosting is prepaid in EUR: attributable AWS cost plus 5%, with no subscription. Organizations can add credit through secure payment checkout.
- Your customers pay you directly, through your own Stripe account.
- Early access means no service-level agreement yet, and features will change.
- You can export your data at any time, including while suspended.
- Follow the Acceptable Use Policy; we act on abuse.
This summary is for convenience. The full terms below apply.
1. About these terms
These Platform Terms of Service (the “Terms”) govern your use of saasland.io: the developer portal at app.saasland.io, its APIs, command-line tools and SDKs, and the hosting of the applications you deploy (together, the “Platform”). The Platform is provided by SIA “DryBits”, the operator of saasland.io (“we”, “us”).
“You” means the person who creates a saasland.io account and, where you act for a company or other organisation, that organisation. If you accept these Terms on behalf of an organisation, you confirm that you are authorised to do so.
The Acceptable Use Policy and the hosting credit rules in section 7 form part of these Terms. The Privacy notice explains how we handle personal data. When you create an account, the portal records the version of these Terms you accepted and when you accepted it.
2. Early access
saasland.io is in early access and available by invitation only. Features are still being built and may change, be limited or be withdrawn. During early access the Platform has no service-level agreement: any availability or recovery targets we describe are goals, not commitments.
Organizations can add EUR hosting credit through our payment provider. Confirmed payments fund the organization wallet under the hosting rules below.
3. Your account and organisation
- The Platform is for developers and businesses building their own products, not for personal consumer use. You must be at least 18 years old and able to enter into a binding agreement.
- Give accurate account information and keep it up to date. You can sign in with email and password or with Google.
- Keep your credentials secure, use multi-factor authentication where it is offered, and do not share accounts. You are responsible for activity under your account.
- Resources belong to an organisation. Organisation owners and admins decide who is a member and which role they have (owner, admin, developer, billing admin or viewer), and are responsible for removing access when someone leaves.
- Tell us promptly through Support if you suspect unauthorised access to your account or organisation.
4. Your applications and content
You keep ownership of your source code, container images, configuration, data and other content, including the data of your own users (“Your Content”). We do not claim ownership of your application, your customers or your revenue.
You grant us a non-exclusive, worldwide licence, for as long as you use the Platform and for the retention periods in section 11, to copy, build, scan, store, run, back up and transmit Your Content only as needed to operate the Platform for you, to comply with law and to enforce these Terms.
You confirm that you have the rights needed for Your Content and that your applications comply with the law and the Acceptable Use Policy.
When you connect GitHub, you install the saasland.io GitHub App on the repositories you choose. We use short-lived access to fetch the revision you select, and you can revoke access in GitHub at any time. ZIP uploads are used only to build the application you uploaded them for.
5. How the Platform runs your application
- You supply a Dockerfile. We do not generate one for you. Your application listens on the supplied
PORT, binds to0.0.0.0, answers its health check and shuts down gracefully. Local disk is temporary, so durable data belongs in a database or storage service. - Builds run in isolated AWS CodeBuild jobs using our build specification. Build files in your repository do not override it. The resulting image is scanned and stored as an immutable release.
- Before a deployment you review the source revision, configuration, resources, permissions and estimated cost. An application is marked Ready only after its health checks, TLS and routing are verified.
- Each application runs as a single production environment. To try changes first, deploy a second copy of your application for testing.
- Default limits apply, for example 10 applications per organisation, 100 MiB ZIP uploads, 30-minute builds and 2 GiB images. The portal shows the limits that apply to you. Outbound network access from your application is denied unless you declare it.
6. Your customers, payments and end-user data
You are the merchant
If you enable billing, you connect your own Stripe account. You sell to your customers and their payments go to your Stripe account, under the agreement between you and Stripe. saasland.io is never the merchant of record for your customers.
- You are responsible for your prices, invoices, taxes, refunds, disputes and chargebacks, consumer-law obligations and support for your customers.
- We synchronise plans, subscriptions, payments and entitlements for your application so that you can control access. We never receive or hold your customers’ payments.
- Your customers’ payments never fund your saasland.io hosting balance, and we never cancel your customers’ subscriptions, including when your hosting is suspended.
Your end users
You must give your own users the terms, privacy notice and support contact for your application. The portal lets you link them, but we do not review or approve your text.
For personal data processed through optional features such as login, user administration, billing records and usage metering, you are the controller and we process that data on your behalf as a processor. A data processing agreement is to be provided before paid availability. You need a lawful basis for that processing and must handle your users’ requests; the Platform provides export and deletion tools to help.
7. Hosting charges and prepaid credit
7.1 What you pay
You pay the AWS hosting cost attributable to your applications, plus a 5% service fee, plus any applicable tax. Hosting is charged in euros only. There is no subscription, seat or plan fee: resource tiers choose capacity, not a second price.
Attributable cost means AWS resources used by your applications and builds, identified through billing tags, resource ownership records and measured allocation of shared services. Costs we cannot attribute to you, our own platform and development costs, and our payment-processing fees are not passed on to you. Third-party services you pay directly, such as Stripe or an external database provider, are outside this total.
7.2 Prepaid credit
You top up a prepaid EUR balance through our payment provider (currently EUR 10 to EUR 5,000 per top-up, and a balance of up to EUR 20,000). Only confirmed payments become usable credit. Pending, failed or action-required payments do not.
7.3 Daily usage holds
Every 24 hours we reserve credit for accrued hosting usage, including the 5% service fee and any applicable tax. Holds use the latest available cost data and remain provisional until settlement. They are internal wallet entries, not card authorisations. A daily hold can take your available balance below zero. Build admission may require a separately disclosed allowance. Current policy: hosting-policy/v2.
7.4 Settlement
AWS reports cost data with a delay. Once AWS’s invoice and detailed cost data for a period reconcile, which can be into the following month, we settle the actual attributable cost plus 5%, release any excess hold and issue the billing documents. Example: with EUR 100 prepaid and EUR 42 held, a final AWS cost of EUR 38 gives a EUR 1.90 fee, a EUR 39.90 settlement and EUR 60.10 remaining (no tax, other holds or adjustments assumed).
If the settled amount is more than your remaining credit, the difference is recorded as a deficit that you owe. Your next top-up repays any deficit first.
7.5 Negative balances and debt allowance
Your available balance is your remaining credit minus active holds. It may be negative. Your debt allowance is 10% of confirmed hosting payments in the previous 12 calendar months, excluding refunded, reversed or disputed amounts and tax. Promotional and test credits do not count. The allowance is rounded down to the nearest cent and recalculated as payments age out.
7.6 Suspension
Apps are suspended when the available balance is below the negative debt allowance. For example, EUR 100 paid in the previous 12 months permits a balance of minus EUR 10; suspension starts below minus EUR 10. With no qualifying payments, any negative balance exceeds the allowance. Delayed usage can exceed the limit before it is reported, so this is not an instant spending cap. Storage and retained resources continue to incur costs during suspension.
7.7 Restoring service
A confirmed top-up repays negative credit first. Hosting eligibility returns when the balance is within the recalculated debt allowance. Abuse, security and operator suspensions require separate resolution and are not lifted by topping up.
7.8 Disputes and refunds
If a top-up is disputed or charged back, new spending is frozen while we review it, and hosting may be suspended if this leaves a deficit. Unused credit can be refunded to the original payment method: the eligible amount is your remaining balance minus active holds, pending refunds or disputes and documented late-cost exposure. Refunds require a recent sign-in and billing permission. Full refund conditions are to be confirmed.
7.9 Policy versions, tax and currency
Every hold, alert and suspension records the hosting policy version used. A new version applies to new holds and future alerts only; it never re-prices periods already settled. Tax, currency conversion (AWS bills in US dollars) and invoicing rules are to be published before paid availability.
8. Acceptable use
You must follow the Acceptable Use Policy and make sure that your applications do too. We may investigate suspected violations and take the steps described there, including removing access to content or suspending applications or accounts.
9. Security
We run each application with its own roles, network rules and logs, store secrets through a dedicated ingestion service and never display stored secret values back. Our staff access customer resources only through scoped, audited tools.
You are responsible for the security of your own code and dependencies, for the secrets you configure and for the access you grant to members. Report suspected vulnerabilities in the Platform through Support. No system is perfectly secure, and we cannot guarantee that the Platform will be free of vulnerabilities.
10. Suspension and termination
By you. You can stop using the Platform at any time. Deleting an application starts a 7-day grace period, which you can cancel, before it is removed. Closing an organisation also has a 7-day cancellation window and completes only after every billing period is settled and any eligible refund is final.
By us. We may suspend or end your access for a serious or repeated breach of these Terms, for violations of the Acceptable Use Policy, for unpaid deficits under section 7, to address a security risk or where the law requires it. Where reasonably possible, we will give notice first and explain how to appeal through Support. Urgent cases, such as malware, attacks or clearly illegal content, may require immediate action.
If we discontinue the Platform or end early access, we will give reasonable advance notice (period to be confirmed) and time to export your data.
11. Data retention, export and deletion
You can export your data at any time, including during suspension and deletion grace periods: application configuration (saasland.app.json), deployment history, domains, audit events, hosting statements and, for applications with users, your user directory and normalised billing and usage records. Password hashes, MFA secrets, provider credentials and signing keys are never exportable.
| Data | Kept for |
|---|---|
| Application runtime logs | 30 days |
| Build logs | 14 days |
| Source archives and images | While used by an active or rollback release, then 90 days |
| Configuration and deployment history | Life of the application plus 1 year |
| Usage events | 25 months |
| Your end users’ profiles | Until deleted; removed within 30 days of a deletion request |
| Invoices, statements and ledger records | 10 years from the end of the financial year (to be confirmed per jurisdiction) |
| Terms acceptance records | Life of your account plus 3 years (to be confirmed) |
| Backups | Expire on their own schedule, within 90 days |
Deleting an application stops its traffic and compute straight away; after the 7-day grace period its runtime, identity pool, secrets and routes are removed, and its users’ data is deleted within 30 days. Deleting your personal account deactivates it immediately and completes within 30 days, unless you are the only owner of an organisation that still has resources or unsettled charges.
12. Third-party services
The Platform runs on Amazon Web Services and works with services such as Stripe, Google and GitHub. Your own accounts with those providers are governed by their terms. We are not responsible for their availability or changes, but we will tell you when they materially affect the Platform.
13. Changes to the Platform and these Terms
We may update the Platform and these Terms. Each version of the Terms has a version identifier, shown at the top of this page. For material changes we will notify you in advance by email or in the portal (notice period to be confirmed) and may ask you to accept the new version before you continue. Changes to the hosting policy apply only to new holds and future alerts, never to periods already settled.
14. Warranties and liability
During early access the Platform is provided “as is” and “as available”, to the extent permitted by law. Nothing in these Terms limits liability that cannot be limited by law.
15. Governing law and disputes
The governing law and the courts or other forum for disputes are to be confirmed. If something goes wrong, please contact us first through Support so we can try to resolve it.
16. Contact
Questions about these Terms: support@saasland.io (mailbox being set up). See Support for what to include.