1. About these Terms
These AI Build Agent Terms (the “AI Terms”) govern your use of the AI Build Agent and any other AI-assisted feature in Kirak Studio. They are part of the Terms of Service, and terms defined there have the same meaning here. If these AI Terms conflict with the rest of the Terms of Service on a matter specific to the AI Build Agent, these AI Terms control.
“AI Build Agent” — the feature that uses one or more third-party AI models to help you produce a Kirak declaration and related code from a description of what you want to build.
“Prompts” — the descriptions, specifications, questions, instructions, and other inputs you provide to the AI Build Agent, together with the project context (such as your existing models.json and kirak.json) that Studio sends with them.
“Output” — the content the AI Build Agent returns to you, including generated models.json / kirak.json declarations, hooks, custom endpoints, and code.
2. How the AI Build Agent works
When you use the AI Build Agent, Studio sends your Prompts, together with relevant context from your project, to a third-party AI model provider. The provider returns Output, which Studio presents to you. You decide whether to accept, edit, or apply the Output. The AI Build Agent does not deploy anything on its own.
The AI Build Agent is a tool that assists you. It is not a person, not an agent in the legal sense, and does not exercise judgement on your behalf.
3. Your Prompts
3.1 Responsibility. You are responsible for your Prompts. You must have all rights needed to submit them, and they must not contain anything prohibited by the Acceptable Use Policy (kirak.io/legal/acceptable-use).
3.2 Sensitive data. Do not put credentials, secrets, or special category personal data into Prompts unless you intend for them to be processed as described in these AI Terms. Use Studio’s secrets store for credentials.
3.3 Prohibited uses. You must not use the AI Build Agent to generate malware, exploits, phishing content, or anything else prohibited by the Acceptable Use Policy, or to attempt to extract another party’s confidential information or training data.
4. Output
4.1 Ownership. As between you and us, you own the Output. To the extent we have any right, title, or interest in the Output, we assign it to you, and we make no claim to it. You are free to use, modify, distribute, and commercialise the Output, subject to your compliance with these Terms.
4.2 Similar Output for others. AI models can generate the same or similar Output for different users, especially for common patterns (a standard auth model, a Stripe webhook handler, and so on). We do not warrant that your Output is unique, and other customers may receive Output that is identical or similar to yours.
4.3 Your responsibility to review. Output may be incorrect, incomplete, insecure, outdated, non-functional, or infringing. Before you rely on Output — and in particular before you deploy it to production — you are responsible for reviewing, testing, and securing it, and for confirming it does what you need and complies with any law that applies to you. Generated hooks and endpoints run inside the runtime’s declared access rules, but that does not make the business logic in them correct or safe.
4.4 Not professional advice. Output is not legal, security, compliance, financial, or other professional advice.
5. No warranties
To the fullest extent permitted by law, the AI Build Agent and all Output are provided “as is” and “as available”, with no warranties of any kind, express, implied, or statutory, including any warranty of accuracy, completeness, reliability, security, fitness for a particular purpose, non-infringement, or originality. We do not warrant that Output is free of third-party intellectual property, that it will meet your requirements, or that the AI Build Agent will be available or error-free. This section supplements, and does not limit, Section 12 of the Terms of Service.
6. No indemnity for Output
We do not indemnify you against, and are not responsible for, any claim, loss, or liability arising from your use of Output, including any claim that Output infringes a third party’s rights. Section 13 (Indemnification) and Section 14 (Limitation of Liability) of the Terms of Service apply.
7. Third-party AI model providers
7.1 Providers. The AI Build Agent uses AI models provided by third parties — currently Google (Gemini), OpenAI, and Anthropic. These providers act as our sub-processors and are listed on our Subprocessor List (kirak.io/legal/subprocessors). We may add, remove, or change providers, and will update the Subprocessor List accordingly.
7.2 No third-party model training on your data. We use these providers under their business/API terms, under which they do not use Prompts or Output submitted through the API to train or improve their foundation models. Providers may retain data for a limited period for abuse monitoring, as described in their terms.
7.3 Provider terms. Your use of the AI Build Agent is also subject to the acceptable-use rules of the underlying providers (for example, prohibitions on generating certain categories of content). We pass through and enforce equivalent rules in our Acceptable Use Policy.
8. How we use Prompts and Output
We use Prompts and Output to:
8.1 Provide the feature — send them to model providers, return Output to you, and store them as part of your project’s build history so you and your team can see how the project was built.
8.2 Safety and abuse prevention — log and review a sample of Prompts and Output for a limited period to detect and prevent breaches of the Acceptable Use Policy and misuse of the models.
8.3 Improve Kirak’s own AI project-builder — we may use de-identified and aggregated information derived from Prompts and Output (for example, to improve our prompt templates, evaluations, and safety guardrails). We do not use this information to train or fine-tune any third-party foundation model, and we do not use it in any form that identifies you, your project, or your End Users. You can opt out by emailing privacy@kirak.io. After you opt out, we will not analyse your Prompts or Output for this purpose. Opting out does not affect Sections 8.1 or 8.2.
8.4 No sale. We do not sell Prompts or Output.
9. Retention
Retention is tied to your project. If you delete the project, the Prompts and Output are deleted from our active systems. The only data that persists after that is residual copies in our encrypted backups (purged within 30 days) and the limited safety-log sample below.
| Data | Retention |
|---|---|
| Prompts and Output | Kept as part of the project’s build history for as long as the project exists. Deleted from active systems when you delete the project; residual copies in encrypted backups are purged within 30 days and are not restored or accessed except to recover the platform from a failure. |
| Safety and abuse logs (Section 8.2) | A minimal sample of flagged Prompts and activity, kept up to 30 days — longer only if needed for an active investigation into misuse or to meet a legal preservation obligation. This is the only Prompt data that can outlive a deleted project. |
| De-identified, aggregated data (Section 8.3) | Retained without a fixed period, because it no longer identifies you, your project, or any individual, and cannot be linked back to you. |
10. Data protection
Where your Prompts contain personal data relating to your End Users, we process that data as your processor and the Data Processing Addendum (kirak.io/legal/dpa) applies. The model providers in Section 7 are sub-processors for that processing. For personal data relating to you (for example, your account identity associated with a build), our Privacy Policy applies.
11. Changes
We may update these AI Terms as the AI Build Agent and the underlying providers change. Material changes will be notified as described in the Terms of Service.
12. Contact
Questions about these AI Terms: legal@kirak.io
Opt-out and data questions: privacy@kirak.io