1. Purpose & Acceptance of Terms
These Terms of Service (hereinafter the "Terms") define the reciprocal rights and obligations between AURABASE SAS (hereinafter "Aurabase") and any natural or legal person (hereinafter the "Customer" or "User") accessing our services.
Creating an account on Aurabase Studio or utilizing our APIs implies full, unreserved acceptance of these Terms. If you accept these conditions on behalf of a company or entity, you represent and warrant that you hold legal authority to bind that entity.
2. Description of BaaS Services
Aurabase provides an integrated suite of backend services for web and mobile applications, including in particular:
- Relational & Vector Databases: Managed PostgreSQL 16+ instances with
pgvectorextension and native Row-Level Security (RLS) support. - Identity & Access Management (Auth): Multi-factor authentication (MFA), session lifecycle management, and SSO.
- Object Storage: S3-compatible file storage with presigned URLs and granular access policies.
- Edge Functions & Serverless: Distributed function execution in a secure WebAssembly (WASM) runtime environment.
- Realtime & WebSockets: Live database change streaming and presence channels.
- MCP Server (Model Context Protocol): Native connector for AI assistants and autonomous agents.
3. Account, API Keys & Security Responsibilities
To use Aurabase, the User must create an account by providing accurate and complete information. The User is solely responsible for:
- Maintaining the confidentiality of their credentials, passwords, and secret API keys (
anon_key,service_role_key). - Any actions performed through their account or using their API keys.
- Enabling multi-factor authentication (MFA) to secure access to the management console.
service_role key confers full administrative privileges bypassing RLS rules. It must never be exposed on the client side (browser or mobile application).4. Service Levels (SLA) & Availability
Aurabase commits to providing a guaranteed monthly availability rate based on your subscription tier:
5. Data Ownership & Intellectual Property
Customer Exclusive Ownership: The Customer retains full and exclusive ownership of all data, tables, schemas, files, code, and content hosted on their Aurabase instance. Aurabase claims no intellectual property rights over your data and will never use it to train AI models.
Platform Ownership: Aurabase and its licensors retain all intellectual property rights pertaining to the software, Studio, trademarks, and technical documentation.
6. Personal Data & Data Processing Agreement (DPA)
The processing of personal data by Aurabase is subject to our Privacy Policy and governed by our Data Processing Agreement (DPA) compliant with Article 28 of the GDPR.
Aurabase production infrastructure is hosted in datacenters located within the European Union (France and Germany), without unlawful transfers of data to third jurisdictions subject to the CLOUD Act.
7. Pricing, Subscriptions & Payment Terms
Applicable fees are those published on our pricing page at the time of subscription.
- Paid subscriptions (Pro / Team Plan) are billed monthly in advance by direct debit or credit card securely processed via our European partner Mollie B.V. (GDPR-compliant).
- Any billing period begun is due in full.
- In the event of exceeding included quotas (storage, requests, MAU), overage is billed at the prevailing unit rate.
8. Term, Termination & Data Reversibility
The Customer may terminate their subscription or delete their project at any time directly from the Studio console without notice or exit fees.
Reversibility guarantee: Prior to any deletion, the Customer may export all databases in standard SQL format (pg_dump) and download their S3 storage objects. Upon confirmation of deletion, data is permanently purged within a maximum of 72 hours.
9. Limitation of Liability & Warranties
Aurabase executes its obligations with due diligence according to standard cloud hosting industry practices. However, Aurabase shall not be liable for indirect damages, loss of profits, or data loss resulting from misconfiguration of RLS policies by the Customer, or compromise of API keys due to User negligence.
10. Governing Law & Jurisdiction
These Terms of Service are governed by and construed in accordance with French law.
In the event of a dispute relating to the validity, interpretation, or performance of these Terms, and failing amicable resolution within 30 days, express jurisdiction is granted to the competent courts of Paris, France, notwithstanding multiple defendants or third-party warranty claims.