Terms of Service

Last updated: 5 September 2026

These terms govern your use of Othor AI Private Limited's website, application and related services. By using our services, you agree to them in full.

1. Acceptance of terms

By accessing or using our website or application, you agree to be bound by these Terms of Service. If you disagree with any part of these terms, you may not use our services.

You may not modify, amend or alter these terms, and any attempt to do so is void unless explicitly agreed by Othor in writing. Where you have signed a separate order form, master services agreement or Data Processing Agreement with Othor, that document prevails over these terms to the extent of any conflict.

2. Definitions

Othor handles several categories of information differently, so these terms use the following defined words.

  • Source Data : the records held in the data sources you connect; your warehouse, database, Drive, SFTP or uploaded files.
  • Metadata : connection credentials, column names, column types, summary statistics, metric definitions and the SQL behind them.
  • Derived Content : the insights, narratives, charts, briefs and numbers that Othor generates from your Source Data.
  • Document Extracts : the tables Othor extracts from files when you enable the optional document intelligence agent.
  • Usage Data : records of how you and your users interact with the product.
  • Model Provider : the AI provider that processes a request, whether contracted by Othor, contracted by you, or hosted by you.

3. Our services and deployment models

Othor provides AI-driven business intelligence and data analysis. It is offered in three deployment models, and your rights and our obligations differ between them.

  • Othor Cloud : we host the platform in AWS and route analysis through our contracted Model Providers.
  • Cloud + your keys : we host the platform; you bring your own Model Provider contract and API keys. Analysis then runs under the terms you negotiated with that provider, including any zero-retention tier.
  • Self-hosted : Othor runs inside your own perimeter. Paired with a model you host, no business data reaches Othor or any external Model Provider. Available to Enterprise customers only, under a separate agreement.

Unless your order form says otherwise, you are on Othor Cloud and these terms apply in full.

Some features described on our website are Enterprise options, are optional per connection, or are on our roadmap. Nothing on our website or in these terms obliges us to make a roadmap item generally available on any particular date.

4. Your data and what we store

1. Source Data is queried in place:

For SQL sources, Othor does not copy or warehouse your database. We run a query, keep the answer, and do not retain the tables behind it. The one exception is the document intelligence agent in clause 4.3.

2. What we hold:

Retained while your account is active:

  • Connection credentials, encrypted
  • Column names, types and summary statistics
  • Derived Content, including the numbers inside the insights, narratives and charts we generate
  • Metric definitions and the SQL behind them
  • Workspace and dashboard configuration
  • Account details and Usage Data

3. Held transiently, in caches that expire on a defined TTL:

  • Query results materialised during an analysis
  • Cached responses that avoid re-running identical analyses

4. Never retained, at any point:

  • A replica of your warehouse or production database
  • Payment card details
  • Credentials in cleartext, anywhere

5. Document intelligence agent:

Files are not queryable the way a database is. If you enable the document intelligence agent for a Drive, SFTP or upload connection, Othor extracts the tables from those files and stores those Document Extracts in our database for the life of that connection. For those connections only:

  • "Queried in place" does not apply.
  • Document Extracts do not expire on a cache TTL. They persist so the agent can answer without re-reading every file, and are deleted when you disconnect the source.
  • If a file contains personal data, its Document Extracts and the narratives generated from it may contain that personal data too.

Document Extracts are encrypted at rest, scoped to your workspace, never used for model training, and never sold or shared. If you connect only SQL sources, this clause does not apply to you.

6. Deletion:

Connection credentials are removed when you terminate your account. Document Extracts are deleted when the relevant connection is removed, and on account closure, they are not held through the reactivation window in clause 16. Other retention periods are set out in clause 16 and in our Cancellations and Refunds Policy. We will confirm the retention behaviour of any specific connector in writing on request to security@othor.ai.

5. AI models and model providers

1. Model routing:

On Othor Cloud, analysis is processed by our contracted Model Providers. You may assign models per task and change that assignment at any time.

2. No training on your data:

Your Source Data, Metadata and Derived Content are not used to train Othor's models. Our contracts with our Model Providers prohibit training on submitted content. Nothing we cache is used for model training.

3. Zero-retention processing:

Zero-retention processing at the Model Provider is available on Enterprise plans, or where you bring your own keys.

4. Bring your own keys and custom models:

You may bring your own Model Provider contract and keys, or ask us about routing to a custom or self-hosted model. Where you do, that provider's terms govern the processing of data sent to it, we are not responsible for that provider's retention or security practices, and the contractual prohibition on training in clause 5.2 is a matter between you and that provider.

5. Accuracy:

Outputs generated by large language models can be incomplete, out of date or wrong. Derived Content is decision support, not a warranty of fact. You are responsible for validating any output before relying on it for a financial, legal, regulatory, employment or other consequential decision.

6. Subprocessors

We use a limited number of third parties to operate Othor Cloud. The current list, what each one does, the categories of data it can access, and its processing region, is published at /subprocessors and is also available from security@othor.ai.

We give at least 30 days' notice before adding or replacing a subprocessor that processes customer data. Email security@othor.ai to be added to that notification list.

Your own data warehouse or production database is your system, not our subprocessor. We connect to it using the credentials you provide.

7. Data storage location and transfers

By default, everything Othor stores is hosted in AWS eu-north-1 (Stockholm). Content delivery edge locations may serve the application globally.

Analysis may be processed by your configured Model Provider, which can sit outside that region, by default in the United States, unless you bring your own model or self-host. Certain subprocessors under clause 6 also process limited data outside the European Union.

Enterprise customers may request a different storage region where residency requirements demand it, subject to written agreement.

8. Security, certifications and compliance status

We state the real status of each control rather than implying more than we have earned. As at the date of these terms:

1. In place:

TLS 1.2 or higher on our APIs and load balancers; AES-256 encryption at rest; separately encrypted credentials that are never displayed back in cleartext; organisation admin and member roles with per-agent sharing; workspace-scoped request authorisation enforced at the database layer; least-privilege staff access that is logged and revoked on departure; centralised logging with alerting on anomalous activity; a documented incident response plan with named owners; peer-reviewed changes, automated dependency and vulnerability scanning, separated environments, and encrypted backups with documented restore procedures; and a customer-facing audit log that workspace admins can export.

2. SOC 2 Type II — observation underway:

Our control environment is implemented and operating, and we are inside the observation window. The independent audit is targeted for Q4 2026. Until a report is issued we share control documentation and complete security questionnaires directly.

3. DPDP Act, 2023 — in practice today:

We operate to the Act's requirements today, including breach notification to the Data Protection Board of India within the timelines the Act requires. We will notify you of a personal data breach affecting you without undue delay.

4. Data Processing Agreement — available:

Covering processing scope, subprocessors, security measures and breach notification. Request it from security@othor.ai.

5. SSO and penetration test — on roadmap:

SAML and OIDC single sign-on are in development. An independent penetration test is planned ahead of our SOC 2 report, with a summary available under NDA once complete. Neither is available today.

6. HIPAA — not supported:

We do not sign Business Associate Agreements. You must not connect sources containing Protected Health Information.

9. Your responsibilities

You are responsible for:

  • Maintaining the confidentiality of your account and the credentials you supply to Othor;
  • Having the lawful right and any necessary consents to connect each data source and to have its contents processed by Othor and the relevant Model Provider;
  • The acts and omissions of the users you invite to your workspace, and for managing their roles and sharing settings;
  • Reviewing the privacy policies and data handling practices of the Model Providers and subprocessors in your chosen path;
  • Deciding whether to enable the document intelligence agent for each connection, in light of clause 4.3; and
  • Validating Derived Content before relying on it.

10. Prohibited uses

You agree not to engage in activities that could harm, disrupt or negatively impact our services or other customers, including:

  • Exploiting vulnerabilities, other than good-faith research reported to security@othor.ai;
  • Automated scraping of our website or product;
  • Submitting malicious content, including prompt content intended to make a model exfiltrate data or bypass workspace boundaries;
  • Bypassing security or access-control mechanisms, including attempting to read another workspace's briefs, jobs or sources;
  • Engaging in harassment;
  • Connecting sources containing Protected Health Information, or otherwise submitting data we have told you the service does not support; and
  • Acting in bad faith, or attempting to unfairly compete with or discredit Othor.

We may restrict or terminate access where misuse occurs. Where practicable we will give notice first. Where the misuse threatens the security or availability of the service or other customers' data, we may act immediately.

11. Our commitments

These commitments apply to Othor Cloud and bind us for as long as they appear in these terms.

  • We do not copy or warehouse your SQL sources, subject to clause 4.3.
  • Your data is not used to train our models, and our Model Provider contracts prohibit training on submitted content.
  • We do not lock you to one model. You may bring your own keys, assign models per task, and switch at any time.
  • We do not require you to use our infrastructure, where a self-hosted Enterprise deployment is agreed.
  • We do not sell or share your data. No resale, no advertising use, and no disclosure beyond the subprocessors listed under clause 6, other than where legally compelled.
  • We state the real status of each control, including roadmap items.

Statements elsewhere on our website about features that are planned, targeted or on our roadmap are forward-looking and are not commitments as to timing.

12. Availability and changes to the service

We aim to provide a reliable service but do not guarantee uninterrupted availability except where a service level applies under your order form. We may change, add or remove features. Where a change materially reduces the security posture or data handling commitments described in clauses 4 to 8, we will notify affected customers in advance.

13. Limitation of liability

Our services are provided on an "as-is" basis, and we disclaim any warranty beyond what is explicitly stated in these terms. To the maximum extent permitted by law, Othor is not liable for incidental, indirect, or consequential damages, or for loss of profits, revenue, goodwill or data, arising from:

  • Use of, or inability to use, our services;
  • Data handling by Model Providers, including the transmission and processing of your Source Data, and their security measures and practices;
  • The accuracy or completeness of AI-generated analysis results, or any decision taken in reliance on them;
  • Your configuration choices, including which sources you connect, whether you enable the document intelligence agent, and which model you assign;
  • Data sources, systems or third-party services that you control.

Nothing in these terms excludes or limits liability that cannot be excluded or limited under applicable law, including liability for fraud or for our obligations as a data fiduciary or processor under applicable data protection law.

Subject to the paragraph above, our aggregate liability arising out of or relating to these terms is limited to the fees you paid to Othor in the twelve months preceding the event giving rise to the claim.

14. Fees and billing

Paid plans are billed through Stripe. Card details are entered with Stripe and are never stored by Othor. Fees are exclusive of taxes unless stated otherwise.

Subscriptions renew automatically unless cancelled before the renewal date. We send a renewal reminder before each renewal, and give at least 30 days' notice of a price change. If a payment fails we will notify you and may suspend service until payment details are updated. Full billing terms, including upgrades, downgrades and disputed charges, are in our Cancellations and Refunds Policy.

15. Cancellation and refunds

We offer a 30-day money-back guarantee on paid plans. A refund request must be made within 30 days of the initial subscription purchase or package activation, covers the most recent subscription period, and is limited to one refund per customer.

Approved refunds are processed within 7–10 business days of approval, to the original payment method. Eligibility verification is required, and some purchases, including Enterprise agreements and renewals beyond the first period, are handled differently.

Eligibility, exclusions, cancellation steps and the full timeline are set out in our Cancellations and Refunds Policy, which forms part of these terms. Contact uk@othor.ai to cancel or request a refund.

16. Term, termination and return of data

Either party may terminate as set out in the applicable plan or order form. On cancellation or termination:

  • Your subscription remains active until the end of the current billing period.
  • Connection credentials are removed when your account terminates.
  • Document Extracts are deleted with their connections and on account closure.
  • Column names and definitions, metric definitions, analysis results and workspace configuration are retained for 90 days after cancellation so you can reactivate, and are then permanently deleted.
  • You may export your Derived Content and configuration in standard formats at any time during that 90-day window.
  • Usage Data is retained in line with our Privacy Policy.
  • Records we are required to keep for tax, accounting or other legal purposes are retained for the period the law requires.

On a self-hosted deployment, your business data never reaches our infrastructure, so there is nothing for us to return or delete beyond account and billing records.

17. Changes to these terms

We may update these terms to reflect changes in our practices, our deployment models, our subprocessors, or applicable law. Significant updates are communicated by email or in-app notification. Changes to our subprocessor list carry the 30 days' notice in clause 6. Continued use of the services after a change takes effect indicates acceptance of the revised terms.

18. Governing law and dispute resolution

These terms are governed by the laws of India. Disputes will be resolved by binding arbitration seated in Bangalore, Karnataka, under the Arbitration and Conciliation Act, 1996, before a sole arbitrator, in English. The courts of Bangalore, Karnataka have exclusive jurisdiction over any matter not subject to arbitration, including applications for interim relief.

To the extent permitted by applicable law, you waive the right to bring class actions or collective claims against Othor. Nothing in this clause limits your ability to raise a complaint with the Data Protection Board of India or another competent supervisory authority, or affects mandatory consumer protection rights that apply to you.

19. Severability

If any provision of these terms is found unenforceable, the remainder stays in full effect.

20. Contact

  • General, billing, cancellations and refunds: uk@othor.ai
  • Security, subprocessors, DPA, control documentation and vulnerability reports: security@othor.ai
  • Privacy requests and grievances: see our Privacy Policy

Othor AI Private Limited, Bangalore, Karnataka, India.