Terms of Service

Causilo is in beta. This page is the whole agreement, and it is short on purpose: there is not much to promise yet and we would rather say so than write around it.

1. Beta

The service is not finished. Models, limits, response shapes and prices can change without notice, and the service can stop. We will tell you what we can when we can, at the address on your account, but you should not build anything you cannot afford to have break.

2. What we do not promise

There is no availability commitment and no accuracy commitment. The service is provided as it is: to the extent the law allows we do not promise that it will be uninterrupted or error-free, that a prediction will be right, or that it fits a purpose of yours — including one you have told us about.

Predictions are predictions. They are not advice and they are not a substitute for a decision made by a person who is accountable for it. Model versions change and a changed version returns different numbers; the version that answered is in metadata.served_by on every response.

3. Your account and your key

A key is shown once, at issue, and stored only as a hash — we cannot recover it for you, and a lost key is replaced rather than retrieved. Calls made with your key are treated as yours and spend your allowance, so tell us at api@nums.world if you think it has been taken and we will revoke it.

The account records which version of these terms you accepted, and when.

4. Limits

A free account includes 25,000,000 cells a month and 6,250,000 a day, at 60 requests a minute and 1,500 an hour. A cell is one value in a table you send, counting context and query rows together and excluding the target column. What your own account has left is at GET https://api.nums.world/usage, and what this deployment enforces is at GET https://api.nums.world/limits.

A request that fails is not charged. A request you abandon is charged in full: closing the connection does not reach the machine running the prediction, which finishes the work either way.

5. What happens to the table you send

We do not train our models on your tables. Not by default and not quietly: a table is used to answer the request you sent it with, and that is all. If we ever want to use one for anything else we will ask you, and you will be able to say no and keep using the service.

It is stored while we work on it. Your request is written to storage in our own AWS account in Seoul, read by the machine that runs the prediction, and the copy is deleted as soon as the answer is returned to you, along with the answer itself; a lifecycle rule removes within a day anything that survives that. A context you ask us to keep, by sending cache_context, lives under a prefix belonging to your account alone. It stops being readable six hours after it was stored, and the same lifecycle rule removes it within a day of that.

If you want anything of yours gone sooner, write to api@nums.world from the address on the account. We delete it within thirty days and tell you when it is done.

The contents of your tables are never written to our logs. What a request log holds is its shape — how many rows, how many columns, which model, how long it took, what it cost — and never a value from inside the table.

6. What not to send

Do not send personal information. This service is not built to receive it and we have not agreed the terms that handling it would require. The same goes for health or biometric information, government identifiers, payment card numbers and credentials, and anything a law or a contract of yours requires to be held under conditions we have not agreed with you in writing. The list is not exhaustive; if you are not sure, ask us before you send it.

Sending a table is you telling us you are entitled to send it. If somebody else brings a claim against us because of what you sent, that is yours to answer.

7. Personal information

This section is our privacy notice. It is here rather than on a page of its own because it is short, and it is short because we collect little.

What we hold about you, and why. Your email address and name, to confirm the address and to answer you. Your organisation and what you want to predict, if you chose to say. The version of these terms you accepted and when. If you sign up through a form rather than with Google, also the address you sent it from and your browser string, to stop automated sign-ups — signing in with Google needs a Google account, which does that on its own, so that route records neither. Then, per request: an identifier, which key called, which account it belongs to, the status, how long it took, how many cells were charged, the model, the shape of the table, and — if you send one — the causilo-user label you chose. Never a value from inside a table. We do not record the address a prediction came from: the inference path carries no such field, so there is nothing to keep.

How long. The account and its usage for as long as the account exists. Request records for thirty days. Records of changes to our own infrastructure for a year. A confirmation link expires in twenty-four hours.

Who else sees it. It is not sold, shared or used for advertising, and no human at Causilo reads a table you send. Two processors are involved. Amazon Web Services runs the infrastructure, in the Asia Pacific (Seoul) region, and every table, key and request record stays there. Google runs the sign-in, and only if you choose it: pressing Continue with Google sends you to Google, which tells us your email address and name so we can create the account. That exchange happens on Google’s servers outside Korea. Nothing you later send to the API reaches Google. If you would rather not involve them, write to api@nums.world and we will issue a key by hand.

How it is protected. TLS 1.2 or later in transit and AES-256 at rest. Your key is stored as a hash and cannot be recovered. Each service runs as a role scoped to what it needs, with no long-lived credentials in any container, and storage is not reachable from the public internet. We hold no certification: no SOC 2, no ISO 27001, and no third-party penetration test.

Who processes it for us. Amazon Web Services Korea LLC and Amazon Web Services, Inc. host the service — the servers, the storage and the logs — in the Asia Pacific (Seoul) region, for as long as you hold an account. Google LLC handles sign-in only, if you choose that route, and receives nothing but what Google already holds about you. We do not entrust your tables to anyone else, and neither processor is permitted to use them for its own purposes.

What leaves Korea. Only the sign-in exchange, and only if you press Continue with Google. Google LLC receives your email address and name, on servers in the United States, for as long as you hold an account, so that we can create it. You can refuse by writing to us instead, and refusing costs you nothing but the wait for a reply. Everything else — every table, every key, every request record — stays in Seoul.

When it is destroyed, and how. A sign-up that is never completed goes when its link expires, within twenty-four hours. Request records go at thirty days. Your account and its usage go when you close the account or ask us to delete it. Electronic records are deleted so that they cannot be recovered; we hold nothing on paper.

Who is responsible. Nums AI Inc., 36 Banseok-ro, Yuseong-gu, Daejeon. Reach our privacy contact at api@nums.world, which is read by the people who run this service.

No automated decisions about you. This service makes predictions from tables you send. It makes no decision about you, and nothing you send is used to profile you or to decide anything concerning you.

Cookies. One, and only while you sign in with Google: a short-lived cookie that ties the redirect back to the request that started it, so somebody else cannot finish your sign-in. It is deleted when you arrive back. There is no analytics, no advertising and no tracking anywhere on this site.

What you can ask for. To see, correct, delete, or stop the processing of what we hold, and to withdraw consent — write to api@nums.world and we will verify who you are, act, and tell you what we did, within thirty days. In Korea you may also contact the Personal Information Infringement Report Centre (118) or the Personal Information Dispute Mediation Committee (1833-6972). Privacy enquiries reach us at the same address.

8. Misuse

Do not attack the service, work around its limits, open accounts you are not entitled to, or use it against the law. We can suspend an account immediately for any of these, and we will say why.

Misuse can carry criminal and civil liability — ours to pursue, and the law's to impose, separately from anything in this document.

9. Liability

Neither of us is liable to the other for indirect or consequential loss, or for lost profits, revenue, data or business opportunity.

Our total liability to you for everything arising out of these terms is limited to the greater of what you have paid us in the twelve months before the event and one million Korean won. A free account pays nothing, so the limit is one million won.

None of this applies to liability we cannot limit by law, including liability for our wilful misconduct or gross negligence.

10. Ending it

Close your account whenever you like by writing to api@nums.world from the address on it. We revoke the keys and stop the account: the key stops working within the minute and nothing further can be called with it.

The record of the account itself stays in our ledger, marked closed, because that is what an invoice and an audit are reconstructed from. If you want it deleted as well, say so in the same message and we will, within thirty days. Section 7 is the standing version of that right.

We can stop offering the service, or this free tier, with notice to your account address.

11. Changes, law, and where to write

A changed document is published here with a new version. If a change matters to you it takes effect thirty days after we write to the address on your account, and using the service after that is how you accept it.

Korean law governs. If something goes wrong, write to us first and give us thirty days; if that does not settle it, the Seoul Central District Court has exclusive jurisdiction as the court of first instance. This English text is the operative version.

Causilo is operated by Nums AI Inc. (주식회사 넘즈에이아이), business registration 814-87-03805. Write to api@nums.world.