1. Agreement and what Forkbench is
By downloading, accessing, or using the Forkbench macOS app, website, and related services (the "Service") — or by creating an account — you agree that these Terms form a binding agreement between you and Forkbench ("we," "our," or "us"). If you do not agree, do not use the Service.
Forkbench is a macOS application for running AI coding agents — each piece of work in its own Thread, carrying its own notes and its own credentials — together with a website and web dashboard that support it. Some functionality is free. Certain features (the "Paid Features") require an active Pro subscription and today include:
- Notebooks — briefs, conventions, and notes ("notes") that you write and your agents read. We store these and synchronize them across your branches, devices, and the teammates you share them with.
- Talk — a link between the web and the AI coding agents running in terminals on Macs you have paired to your account, so you can read those conversations and send instructions to them from the web.
- Collaboration — each Thread carries a board: one objective and a task backlog that agents claim, work, and hand off. We store and synchronize that board across the Macs you have paired to your account, and, where you invite one, with a colleague you have added to that Thread.
- Vault — a place to keep credentials on your Mac so that an agent can use one without the value being disclosed to it, and so that the same credentials are available on the other Macs you have enrolled. Section 7 sets out what this does and, just as importantly, what it does not do.
We may add, change, or remove features over time. Forkbench is a tool that helps you operate and communicate with AI coding agents; it is not a party to what those agents do (see Sections 5 and 6).
How you accept, and what you are accepting
You accept these Terms by ticking the acceptance box when you create your account, or by accepting them in the Forkbench application when you are asked to. We record that you accepted, when, and which version, and we keep that record for as long as your account exists and for as long afterwards as we may need it to establish or defend a legal claim.
Each version of these Terms carries a version identifier, shown at the top of this page. When we publish a version that materially changes what you are agreeing to, we ask you to accept it again before you carry on using the Service (Section 20).
2. Eligibility and accounts
You must be at least 16 years old — or the minimum age of digital consent where you live, if lower but no younger than 13 — to use the Service. You need an account for most functionality. You agree to:
- Provide accurate account information and keep it current.
- Keep your password and sign-in credentials confidential.
- Take responsibility for all activity that occurs under your account and your paired devices.
- Notify us promptly at [email protected] of any unauthorized use of your account or devices.
We may suspend or terminate accounts that violate these Terms or that create risk or legal exposure for us or others.
3. Subscriptions, billing, trials, and refunds
Paid Features are offered on a recurring subscription (currently EUR 30 per month, plus any applicable taxes such as VAT). Subscriptions and payments are handled by our third-party payment processor (currently Polar), which acts as merchant of record and may collect and remit taxes. By subscribing, you authorize us and our processor to charge your payment method for the subscription, plus applicable taxes, on each renewal until you cancel.
New subscriptions may include a 30-day free trial. If you do not cancel before the trial ends, the subscription converts to paid and your payment method is charged. Trial length is set on the product and may change.
You may cancel at any time from your account page. Cancellation takes effect at the end of the current billing period, and you keep access to Paid Features through the end of that period. We do not provide partial-period refunds except as described below or as required by law.
Refunds. If you are unhappy with a charge, email [email protected] within 14 days of that charge and we will refund the most recent billing period. Refunds outside that window are at our discretion. Refunds are issued to your original payment method through our payment processor.
Fair use and plan limits
A Pro subscription is for a single individual and the devices that individual controls. You may pair up to the number of devices stated in our documentation, and you agree not to share your account or subscription with others, or to use a single subscription to provide the Paid Features to multiple people or to an organization. Use by a team is offered separately.
The Paid Features are provided on a fair-use basis. Notebooks storage and Talk relay are generous but are not intended to support automated, abnormal, or abusive volumes. We may apply reasonable technical and rate limits to protect the Service and other users, and we may contact you about — or limit, suspend, or downgrade — use that materially exceeds normal individual use or that breaches Section 11 (Acceptable use).
Right of withdrawal (EU/EEA consumers)
If you are a consumer in the EU or EEA, you normally have 14 days to withdraw from a distance contract without giving a reason. Because a Pro subscription gives you immediate access to digital services, by subscribing you ask us to begin providing the Paid Features right away and you acknowledge that you lose your right of withdrawal once provision has begun. This does not affect your statutory rights, and independently of it you can cancel at any time from your account page; the refund practice above also still applies.
4. Your content
"Your Content" means the notes, notebooks, messages, instructions, project names, and other material you create, upload, or send through the Service. As between you and us, you own Your Content. You grant us a worldwide, non-exclusive, royalty-free license to host, store, copy, transmit, display, and process Your Content solely to operate and provide the Service to you — for example, to synchronize your notes across your devices and teammates, and to relay your messages and instructions to the agents on your paired Macs, including queuing them while a Mac is offline.
You are responsible for Your Content, and you represent that you have the rights needed to submit it and that it does not violate these Terms, any law, or anyone else's rights. Do not put secrets you don't want stored — passwords, API keys, access tokens, or other credentials — into your notes or messages. Notes and messages are stored on our servers so the Service can work; treat them accordingly.
5. AI coding agents and their output
Forkbench helps you run and communicate with AI coding agents. Those agents, and the AI models and providers behind them, are third-party tools that you choose, configure, and operate. We do not create, own, control, supervise, review, or endorse the agents or anything they produce.
You understand and agree that:
- AI-generated output — code, commands, suggestions, explanations, and other results — may be inaccurate, incomplete, insecure, or otherwise harmful and may not be suitable for your purpose.
- You are solely responsible for reviewing, testing, and deciding whether to rely on, run, or ship any AI output. Do not execute or deploy output you have not reviewed.
- Your use of any third-party agent or AI provider is also governed by that provider's own terms and policies and is at your own risk.
We are not responsible or liable for the agents, the AI providers, or any output, action, or oscope produced through them.
6. Talk, commands, and your devices
Talk lets you pair Macs to your account and send messages, instructions, and commands from the web to AI coding agents and terminals running on machines you control. We transmit and queue what you send and relay what your Macs report back; we do not execute, vet, or supervise it.
You are solely responsible for:
- The instructions and commands you send and everything that happens on any machine as a result — including code execution, file and data changes, data loss, and any effect on your systems or third-party systems.
- Keeping your devices, accounts, and pairings secure, and promptly revoking any device or pairing you no longer control from your account's devices page.
Only pair machines you are authorized to control, and only send instructions you are authorized to run on them.
7. Vault, credentials, and key material
Vault is where you keep credentials (API keys, tokens, passwords and similar secrets) so that Forkbench can let an agent use one without disclosing its value to that agent. Where you have bound a credential to a destination, Forkbench substitutes the real value on the way out to that destination, and refuses and records an attempt to send it anywhere else. Credentials are held encrypted on your Mac under keys that do not leave it, and where they sync between your Macs they sync encrypted.
You need to understand the boundary of that, because it is narrower than it sounds:
- Forkbench governs what Forkbench holds. It does not govern your computer. A credential that also exists somewhere else on your Mac (in a project file, a shell profile, an environment variable, another application's configuration, your clipboard, or your shell history) can be read by anything running on that Mac, including an agent, and Forkbench has no way to prevent that. Putting a copy into Vault does not remove the other copies and does not make the other copies safe.
- A credential you have not bound to a destination is handled by the weaker mechanism. The substitution described above applies to credentials with an established destination. Without one, the credential is supplied to the command in the ordinary way and can be read by what you ran.
- Containing a credential is not containing the authority it carries. An agent permitted to use a key can take any action that key permits, including destructive and irreversible ones, without ever reading the value. Deciding which credentials an agent may use, and in which Threads, is your decision and your responsibility.
- A credential already exposed stays exposed. If a credential has been read by an agent, written into a transcript, committed to a repository, or sent to a model provider, importing it into Vault afterwards does nothing about that. Rotate it at its issuer. That is the only remedy, and only you can carry it out.
You agree that you will only place in Vault credentials you are entitled to hold and use; that you will keep your Mac, your account and your enrolled devices secure; that you will remove an enrolled Mac you no longer control; and that you will rotate at its issuer any credential you have reason to believe has been exposed. The behaviour described in this Section is a description of how the feature is built, not a warranty that it cannot be defeated. Sections 16 and 17 apply to it in full.
8. Encryption, and data we cannot recover
Some of what you keep in the Service is encrypted on your devices under keys we do not hold and cannot obtain. That includes your Notebooks content, the values of your Vault credentials, and the material inside a shared Thread, including its board. We can see that the encrypted data exists, and we serve it back to your devices, but we cannot read it.
That design has a consequence we want you to read before you rely on it, rather than afterwards:
If you lose access to every Mac you have enrolled and to your recovery code, the data encrypted under those keys is permanently unrecoverable. It is unrecoverable by you and it is unrecoverable by us. There is no reset, no master key, no support request and no legal process that can restore it, because we do not hold anything that could. This is a property of the design, not a failure of the Service, and to the maximum extent permitted by law we are not liable for a loss that follows from it.
Accordingly you agree that:
- You are responsible for keeping your recovery code somewhere you will still have it after losing a machine, and for keeping at least one enrolled Mac or a working recovery route available.
- You are responsible for exporting anything you could not afford to lose. The application provides an export for this purpose.
- Removing or revoking a Mac rotates the affected keys and re-seals your data, so a removed Mac cannot read what comes afterwards.
Not everything is encrypted this way, and we will not let you believe otherwise. Your account and billing records, and Talk conversation content, are held in a form our servers can read, because delivering and queueing them requires it. The Privacy Policy sets out precisely which is which.
9. Sharing a Thread with other people
Sharing in Forkbench is done by Thread: you invite a person into a Thread, and while they are a member they can reach what that Thread holds. You are responsible for deciding who you invite, for what you put into a Thread you have shared, and for having the right to share it. If you are sharing material that belongs to an employer or a client, make sure you are permitted to.
Removing somebody ends their access going forward. It does not recall what they already saw. When you remove a member we rotate the Thread's keys and re-seal its contents, so that what comes afterwards is out of their reach. Nothing can retrieve what they have already read, copied, screenshotted, or acted on, and no screen in the product should be read as promising otherwise. If material must never reach a person, do not put it in a Thread they are in.
Roles and permissions within a shared Thread govern what a member may do next. They are not a way to un-disclose something already disclosed.
If you are the person invited into somebody else's Thread: you may use what you are given only for the purpose it was shared with you, you must comply with these Terms in that Thread, and the person who owns it may remove you at any time.
10. Security: what we do, what you do, and what we do not promise
We describe how the Service is built, in the product, on our website and in our documentation, in more detail than is usual. We do that so you can judge it. Those descriptions describe the design as it stands, they may change as the product changes, and they are descriptions, not warranties. Nothing in them, and nothing in our marketing, forms a promise of any particular security outcome or becomes a term of this agreement.
We hold no security or compliance certification. We are not SOC 2, ISO 27001, PCI DSS or HIPAA certified or audited, we are not a HIPAA business associate and we do not offer a business associate agreement. Do not use the Service to handle protected health information, payment card data, classified or export-controlled government material, or any other category of data whose handling requires an assurance or a signed agreement we have not given you. If your organisation's policy requires such assurances, the Service is not suitable for it and you should not use it for that purpose.
Some parts of the Service are containment and evidence, not a security boundary. In particular, the controls that scope which notes, boards and material a given terminal can reach decide who is asking on the basis of what the calling process reports about itself. They are built to help you organise what you deliberately hand out and to limit the damage of an ordinary mistake. They are not built to withstand a program on your own Mac that is actively trying to defeat them, and you must not rely on them to contain software you believe to be hostile. Likewise, controlling where a credential may be sent is not the same as controlling what is sent: it limits the destination, not the payload.
No system is secure against every attack, including this one, and we do not represent otherwise.
What is yours to do:
- Keep macOS and the Forkbench application up to date. Updates carry security fixes, and running an old build is a risk you are choosing.
- Protect your account with a strong, unique password and a second factor, and do not share it.
- Only pair or enrol machines you control, review them periodically, and revoke promptly any you no longer control.
- Review what you grant. An agent reaches what you gave it, and the decision about what to give it is yours.
- Tell us promptly at [email protected] if you believe your account, a device, or your data has been compromised.
11. Acceptable use
You agree not to — and not to help or permit anyone else to:
- Use the Service, or any agent operated through it, to do anything unlawful, or to create, distribute, or operate malware, ransomware, or other harmful or unauthorized code.
- Access, attack, disrupt, or test any system, network, data, or account you are not authorized to access.
- Infringe or misappropriate intellectual-property, privacy, or other rights, or submit content you do not have the rights to.
- Reverse-engineer, decompile, or attempt to extract source code from the Service, except to the extent this restriction is prohibited by law.
- Resell, sublicense, rent, or redistribute the Service without our written permission.
- Interfere with, overload, probe, or circumvent the security, rate limits, or infrastructure of the Service, or use it to send spam or otherwise abuse the relay.
- Use the Service in violation of applicable export, sanctions, or data-protection laws.
We may investigate and take appropriate action, including suspending or terminating access, for any violation.
12. Security research and vulnerability reporting
We want to hear about security problems in the Service, and we would rather hear about them from you than read about them later. If you believe you have found a vulnerability, report it to [email protected]. Please give us enough detail to reproduce it, and please give us a reasonable opportunity to fix it before you tell anybody else.
Safe harbour. If you research in good faith, and you stay inside the rules below, then we treat your activity as authorised. We will not bring a claim against you for it, whether under computer-misuse law, contract, or these Terms; we will not report you for it; and if a third party brings a claim against you for activity we authorised here, we will make clear that it was authorised. To the extent the restrictions in Section 11 would otherwise prohibit that activity, we waive them for it.
The rules, which are the whole of the deal:
- Test only against your own account and your own data. Do not access, modify, delete, or retain anybody else's data, and if you encounter somebody else's data by accident, stop, do not keep it, and tell us.
- Stop as soon as you have confirmed a vulnerability. Confirming access is research; using it is not.
- No denial-of-service or load testing, no spam, no social engineering of anyone (including our providers and our users), and no physical attacks.
- Do not degrade the Service for other people, and do not disrupt the operation of anyone's machine other than your own.
- Give us a reasonable period to remediate before public disclosure, and coordinate the timing with us in good faith.
- Do not demand payment in exchange for withholding a report or for details of a vulnerability. We do not currently run a paid bug bounty, and a report is not an invoice.
- Comply with the law. This safe harbour is what we can give you; it cannot authorise you on anybody else's behalf.
Activity outside these rules is outside the safe harbour, and Section 11 applies to it in full.
13. License to use the software
Subject to these Terms, we grant you a personal, limited, non-exclusive, non-transferable, revocable license to download and use the Forkbench application on Macs you control, and to use the website and dashboard, for their intended purpose. The Service may download and install updates automatically. We may modify, suspend, or discontinue any part of the Service at any time.
14. Intellectual property
The Service — including the Forkbench software, website, and their look, feel, and content, but excluding Your Content — is owned by Forkbench and our licensors and is protected by intellectual-property laws. Except for the rights expressly granted here, we reserve all rights. Any feedback you send us is given freely, and we may use it without obligation to you.
15. Third-party services
The Service relies on and interoperates with third parties — including AI agent and model providers, our payment processor, sign-in providers such as Google and Apple, and infrastructure and email providers. Your use of those services may be governed by their own terms and privacy policies. We are not responsible for third-party services and do not guarantee their availability, security, or output.
16. Disclaimers
TO THE EXTENT PERMITTED BY APPLICABLE LAW, THE SERVICE IS PROVIDED "AS IS" AND "AS AVAILABLE," WITHOUT WARRANTIES OF ANY KIND, WHETHER EXPRESS, IMPLIED, OR STATUTORY, INCLUDING IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, AND NON-INFRINGEMENT.
WITHOUT LIMITING THE ABOVE, WE DO NOT WARRANT THAT THE SERVICE WILL BE UNINTERRUPTED, SECURE, OR ERROR-FREE; THAT MESSAGES, INSTRUCTIONS, OR COMMANDS WILL BE DELIVERED, QUEUED, OR EXECUTED RELIABLY OR ON TIME; OR THAT ANY AI-GENERATED OUTPUT WILL BE ACCURATE, SECURE, OR FIT FOR ANY PURPOSE. YOU USE THE SERVICE, YOUR AGENTS, AND THEIR OUTPUT AT YOUR OWN RISK. This Section does not affect mandatory legal guarantees that cannot be excluded, including any statutory guarantees owed to consumers.
17. Limitation of liability
TO THE MAXIMUM EXTENT PERMITTED BY LAW, FORKBENCH AND ITS OFFICERS, EMPLOYEES, AND SUPPLIERS WILL NOT BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, EXEMPLARY, OR PUNITIVE DAMAGES, OR FOR ANY LOSS OF PROFITS, REVENUE, DATA, CODE, GOODWILL, OR BUSINESS, ARISING OUT OF OR RELATED TO THESE TERMS OR THE SERVICE — INCLUDING DAMAGES ARISING FROM AI-GENERATED OUTPUT, FROM COMMANDS OR INSTRUCTIONS EXECUTED ON YOUR OR OTHERS' MACHINES, FROM LOST OR CORRUPTED DATA OR CODE, OR FROM THIRD-PARTY AGENTS OR PROVIDERS — EVEN IF WE HAVE BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.
TO THE MAXIMUM EXTENT PERMITTED BY LAW, OUR TOTAL LIABILITY FOR ALL CLAIMS ARISING OUT OF OR RELATED TO THESE TERMS OR THE SERVICE WILL NOT EXCEED THE GREATER OF (A) THE AMOUNT YOU PAID US FOR THE SERVICE IN THE 12 MONTHS BEFORE THE EVENT GIVING RISE TO THE CLAIM, OR (B) EUR 100 (OR ITS EQUIVALENT).
Nothing in these Terms excludes or limits our liability where it would be unlawful to do so — including liability for death or personal injury caused by our negligence, for fraud or fraudulent misrepresentation, or for any other liability that cannot be excluded or limited under applicable law. Where your local law gives you mandatory rights or guarantees as a consumer, nothing in these Terms affects them.
18. Indemnification
To the extent permitted by applicable law, you agree to defend, indemnify, and hold harmless Forkbench and its officers, employees, and suppliers from and against any claims, liabilities, damages, losses, and expenses (including reasonable legal fees) arising out of or related to: (a) Your Content; (b) the instructions or commands you send and anything they cause on any machine; (c) your use of the Service or of any third-party agent or provider; or (d) your violation of these Terms or of any law or third-party right.
19. Termination, deletion, and unused accounts
You may stop using the Service at any time and may delete your account from your account page. We may suspend or terminate your access if you breach these Terms or create risk or legal exposure for us or others. On termination, the rights granted to you end; provisions that by their nature should survive — including Sections 4 through 19, 21 and 22 — survive.
Deleting your account is not instant, on purpose. When you ask us to delete it, we sign you out everywhere and disconnect every paired Mac straight away, then permanently erase your account and its contents 30 days later. During those 30 days you can cancel, using a link we email you that works without signing in. We do this so that a mis-click, or somebody else using your account, cannot destroy your work irreversibly in one step. After the 30 days the erasure is final and we cannot recover anything.
We delete accounts nobody uses. If an account goes unused for 2 years — no sign-in, no API call, no paired Mac — we will delete it and everything in it. We email you 30 days beforehand and again 7 days beforehand, and either email lets you keep the account with one click and no sign-in. Signing in, or using a paired Mac, has the same effect. An account with a subscription or any payment history is never deleted this way. This is not a licence for us to reclaim accounts at will; it is us not holding personal data we have no reason to hold, and the Privacy Policy sets out the same rule from the data-protection side.
Take your data first. Your account page has a one-click export of everything we hold. Do it BEFORE you request deletion: from the moment you do, the account can no longer be signed into — that is what stops somebody who has taken it over from carrying on using it — so the export is no longer reachable either. Content that is end-to-end encrypted comes out sealed, since we have never held those keys; export from an enrolled Mac if you need the plaintext.
20. Changes to these Terms
We may update these Terms from time to time. If we make material changes, we will notify you through the Service or by email, and — where required — give you reasonable advance notice. Changes take effect when posted, or on any later effective date we state, and your continued use of the Service after that means you accept the updated Terms.
Where a change materially alters what you are agreeing to, we do not rely on your silence. We ask you to accept the new version, in the application and on the web, and we record that acceptance against the version identifier shown at the top of this page. Until you accept, you can still sign in on our website, reach your account page, download your data and cancel a subscription. If you would rather not accept, you may stop using the Service and delete your account, and Section 3 governs any refund.
21. Governing law and disputes
These Terms, and any dispute or claim arising out of or relating to them or the Service, are governed by the laws of the country in which the operator of Forkbench is established, without regard to conflict-of-laws rules. If you are a consumer, this choice of law does not deprive you of the protection of the mandatory provisions of the law of the country where you live, and you keep any right you have under that law to bring proceedings in your local courts.
Before bringing any claim, you agree to first contact us at [email protected] and try in good faith to resolve it informally. Subject to the consumer rights described above, any dispute that is not resolved informally will be subject to the exclusive jurisdiction of the courts competent for the operator's place of establishment; either party may still seek injunctive relief in any court of competent jurisdiction to protect its intellectual property or confidential information. To the extent permitted by applicable law, any claim must be brought within one year after it arises.
22. General
These Terms are the entire agreement between you and us regarding the Service and supersede any prior agreements on that subject. If any provision is held unenforceable, the rest remain in effect. Our failure to enforce a provision is not a waiver of it. You may not assign these Terms without our consent; we may assign them in connection with a merger, acquisition, or sale of assets. We are not liable for delays or failures caused by events beyond our reasonable control.
23. Contact
Questions about these Terms? Email [email protected].