Terms
Three documents govern Euthynos, and they cover different things. Apache-2.0 covers the software and controls what you may do with it. A separate trademark policy covers the name and the logo. This page covers euthynos.dev — the pages you are reading, the early-access form, and the endpoints behind it. Nothing here narrows the licence.
Last updated 19 August 2026.
This page does not limit your rights to the code. The engine you install from npm
is licensed under the Apache License 2.0, and the licence text is what controls. Nothing on this
page adds a condition to it, narrows a grant, or reserves a right the licence already gave you. If
this page and the LICENSE file ever appear to disagree about what you may do with the
software, the LICENSE file is the one that counts. What follows is about the website.
Two things, governed differently
Conflating the two is the usual way a terms page quietly becomes a licence restriction. So, plainly:
| The thing | Governed by | Where the text lives |
|---|---|---|
| The engine, the CLI and the MCP server — the npm package and the source in the repository | Apache License 2.0 | LICENSE and NOTICE in the repository |
| euthynos.dev — these pages, the early-access form, the endpoints behind it | This page | Here |
| The name “Euthynos” and the logo | A trademark policy, not the code licence | docs/TRADEMARK.md, summarised below |
You can use the software without ever visiting this site, and the licence does not depend on anything written here. The reverse is also true: reading this site grants you nothing about the code that the licence has not already granted.
The software
The engine, the CLI and the MCP server are licensed under the Apache License 2.0.
The full text is in LICENSE at the root of the
repository, and it ships inside the
npm package along with NOTICE.
Read those rather than this summary if the difference matters to you.
What it grants
Section 2 gives you a perpetual, worldwide, non-exclusive, no-charge, royalty-free and irrevocable copyright licence to reproduce the work, prepare derivative works, publicly display and publicly perform it, sublicense it, and distribute it in source or object form. Commercial use is included. Use inside a closed-source product is included. Forking is included — that is what the licence is for.
Section 3 adds a patent licence to make, have made, use, offer to sell, sell, import and otherwise transfer the work. It terminates if you institute patent litigation alleging that the work infringes.
What it asks in return
Section 4 sets four conditions when you redistribute:
- Give recipients a copy of the licence.
- Make modified files carry prominent notices saying you changed them.
- Retain the copyright, patent, trademark and attribution notices in the source you received.
- Include a readable copy of the attribution notices in
NOTICE.
Warranty and liability
Both live in the licence, and the licence is what applies. Section 7 provides the work on an “AS IS” basis, without warranties or conditions of any kind, express or implied, including title, non-infringement, merchantability and fitness for a particular purpose. Section 8 excludes liability for direct, indirect, special, incidental and consequential damages, including loss of goodwill, work stoppage and computer failure. Section 9 covers the case where you choose to offer support, a warranty or an indemnity yourself when you redistribute — you do that on your own behalf, not on anyone else’s.
This page does not restate those sections and does not add to them. Nothing here
disclaims more than section 7 disclaims or excludes more than section 8 excludes. If you want to
know where you stand, read sections 7, 8 and 9 in LICENSE. They are short.
What the licence does not cover
Section 6 does not grant permission to use the trade names, trademarks, service marks or product
names of the licensor, beyond reasonable and customary use in describing the origin of the work and
reproducing the contents of NOTICE. So the split between the code and the name is not
something this page invented — it is in the licence. See
Trademarks below for where that line sits in practice.
Two things worth being clear about
The licence is not a trial. docs/CONTRIBUTING.md states that the engine stays
Apache-2.0 permanently, and the README describes the free local CLI as a commitment rather than a
trial. There is no relicensing plan, no open-core split waiting in a branch, and no CLA that would
make one easy. The part of that which is legally irrevocable is the section 2 grant on the copy you
already have; the rest is a stated intention about future releases, said plainly here so you can
judge it as one.
And the software makes a narrower claim than tools in this category usually do. Euthynos provides structural evidence about a repository. It does not certify that a change is safe, and no page on this site should be read as saying it does. The measurements published on /research are what one harness recorded on one repository with one model, reported with the sessions that failed as well as the ones that did not. They are not a prediction about your codebase.
The website
euthynos.dev is a set of static pages and a few serverless functions. It is provided as it is, with no warranty of any kind, express or implied, and no liability is accepted for any loss arising from using it or from being unable to use it.
Who is in the request path
Two companies sit between your browser and this project’s code, and both are worth naming because both handle your request before anything written here runs.
- Cloudflare is in front. It terminates TLS, so it is the thing your browser actually talks to. It necessarily receives your IP address, your user agent, the URL you asked for and the time you asked for it — before Vercel sees any of that.
- Vercel is behind it, and serves the static pages and runs the serverless functions.
-
Cloudflare’s edge also sends Network Error Logging directives. Those
instruct your browser to report failed requests to
a.nel.cloudflare.comon its own. That reporting is done by your browser at the edge’s instruction, not by any script on these pages. -
Typing www costs you an extra request.
www.euthynos.devredirects to the apex domain, so a visitor who types www makes one additional request that Cloudflare sees before the one that returns a page.
Neither of those is an analytics vendor and neither is asked for a profile of you. But both are in the path, both keep their own operational records under their own terms, and no sentence on this site should be read as saying a request reaches this project’s code first. Privacy covers what that means.
What the site does and does not offer
- There is no uptime commitment. No SLA, no status page, no support obligation. If it is down, it is down, and nothing here commits to otherwise.
- Pages can change, move or be removed without notice — including this one.
- A page can fall behind the code. The site describes software that keeps changing. Where the two disagree, the repository is the accurate one.
- Nothing on the site is advice. It describes what a tool does. Decisions about your own code stay yours.
There is no visitor account and nothing for you to sign in to, and nothing a visitor writes is ever published on the site. The admin area exists so one person can read the signup list; it is not a product surface and is excluded from search.
Early access
Euthynos for Teams is not generally available. There is no public instance to log into today. The early-access form is a short list of signups — your address, the optional answers you gave, and a couple of technical fields. Privacy describes the fields that are stored.
Being direct about what joining does and does not buy, because burying this would be the dishonest option:
- It is not a contract. No money changes hands, nothing is sold, and nothing is owed in either direction.
- It does not guarantee access. Not first, not eventually. There is no queue position, and signing up earlier reserves nothing.
- There is no launch date. None is being implied by the word “early”.
- The hosted product may never ship. That is a real outcome, not a formality. Nothing on this page commits to it opening at all.
- No price is being quoted. Nothing on this site fixes a price, a tier, a discount or a free allowance for a product that does not exist yet. Any pricing that ever exists would be published at that point, and would not be bound by anything written here.
What actually happens when you submit the form: the fields go into one row of a Postgres database. The most that is said about what follows is one email if and when early access opens, and nothing else. If it never opens, no email is ever sent, and that is a permitted outcome rather than a failure to deliver something.
The local CLI needs none of this. The copy you install is Apache-2.0 and runs locally, and the CLI in the repository is free to use — whether or not you ever fill the form in.
There is no unsubscribe link, because there is no mailing system yet. There is no self-service delete button either. To come off the list, email [email protected] and the row is removed by hand. That is one person doing it manually, so it is not instant and no timescale is committed to here.
Using the site and its endpoints
Most of what you might want to do needs no permission. Read the pages, copy the commands, quote
them, link to them, archive them. Crawling the public pages is allowed — robots.txt
says so, and it names GPTBot, ClaudeBot, PerplexityBot, Google-Extended and CCBot explicitly.
Published text is meant to be readable by agents; that is the point of the project.
Four things are not allowed:
-
Automated submission to the signup endpoint.
/api/waitlistis for a person filling in the form. Do not script it, do not load-test it, and do not submit an address that is not yours. - Scraping the form or its endpoint. The endpoint answers a signup with a success flag and nothing else. A new signup and a repeat signup get identical responses, deliberately, so the endpoint cannot be used to test whether an address is already on the list. There is no bulk read behind it.
-
Attempting to reach the admin area. The endpoints under
/api/adminrequire a signed-in session./adminitself is just the sign-in page — it loads for anyone and shows nothing without a password. Probing either is not permitted whether or not it works. - Anything that degrades the site for other people — floods, amplification, or using the endpoints as a relay.
What happens
Requests are rate-limited. The mechanisms are named below without their thresholds, because the thresholds are tuned as needed and can change without notice — a number printed here would become false the day it is adjusted.
-
The signup endpoint accepts a small number of signups an hour from one network address, then
answers
429and stores nothing. - The signup row stores no IP address. What it stores is a salted SHA-256 hash of the address, on the same row as the signup, and that is what the counter matches on — it stays there rather than being discarded once the hour is up. If the salt is not configured on the deployment, the endpoint refuses the request and stores nothing at all rather than writing a hash that only looks protective. Hosting-level request logs at Cloudflare and Vercel sit outside all of this and are theirs, not this site’s. Privacy covers what that means.
- Some submissions are discarded without being written anywhere.
- Repeated failed admin sign-ins are rate-limited and delayed.
Beyond that there is no blocklist and no automated banning. Sustained abuse gets handled by hand or at the host. The honest description of the ceiling is that this is a small site with a small amount of enforcement behind it, and the rate limits above are most of it.
If you find a security problem, report it privately through the security policy rather than testing it further against the live site. Never open a public issue for a vulnerability — a public issue is a disclosure. Handling is best-effort by one person: no response time is committed to, and no commitment is made that a given report results in a fix, an advisory or a reply.
Trademarks
The Apache 2.0 licence covers the code. It does not cover the name.
“Euthynos” and the Euthynos logo are claimed as unregistered trademarks of Tonil Kumar. No registration has been applied for or granted, which makes them common-law marks resting on use rather than on a registry entry. That is stated here for the same reason it is stated in the repository: a reader should not have to assume a registration exists.
This is not a restriction added on top of the licence. Section 6 already withholds trade names and
marks; the rules below describe where that line sits rather than moving it. The full policy is
docs/TRADEMARK.md in the repository, and this summary is deliberately not allowed to add a restriction that file does not.
Permitted without asking
- Use, modify, distribute and sell the software under Apache-2.0, including commercially and inside closed-source products.
- Run it as a service. Section 2 covers using the software, including offering it to other people over a network, and nothing here narrows that. There is no network-copyleft or source-available clause anywhere in this project and this page does not add one. Only the name is restricted — brand the service as something other than Euthynos and you are inside the lines.
- Say your project uses it. “Built with Euthynos”, “compatible with Euthynos”, “an MCP client for Euthynos” — factual, descriptive references are fine and welcome.
- Write about it, benchmark it, criticise it, and publish the results. We publish our own failures; we are not going to object to yours.
- Fork it.
Requires permission
Five things, and they are the same five as in docs/TRADEMARK.md. If you find a sixth
here, it is an error on this page and the repository file wins.
- Naming your fork or derivative “Euthynos”, or a name confusingly similar to it. Call it something else. This is ordinary practice for permissively licensed projects and is the reason the mark exists.
- Using the logo as your project’s or product’s identity.
- Implying endorsement, affiliation, partnership or certification.
- Using the mark in a company name, product name, domain or app-store listing.
- Selling merchandise bearing the mark.
The reason is narrow: a permissive licence deliberately gives away the ability to fork and sell the code, and the mark is what stops a fork from also taking the identity. For a tool whose product is trustworthy answers, someone shipping a modified engine under this name could attach its credibility to output nobody verified.
If you are unsure whether your use is fine, ask before shipping — the answer is usually yes, and asking costs less than renaming later. Open an issue.
Links to other sites
This site links out to GitHub, npm and X, because that is where the source, the package and the updates are. Those links are not endorsements, and they do not run the other way either: Euthynos is not affiliated with, funded by, endorsed by or partnered with GitHub, npm, Anthropic, or any company named anywhere on this site. Agent names appear because the tool works with those agents.
Once you follow a link you are on someone else’s site, under their terms and their data practices. Nothing here controls that, and no responsibility is taken for what is on the other end.
Some third parties are involved without you clicking anything. Every public page loads a stylesheet
from fonts.googleapis.com and font files from fonts.gstatic.com, so Google
receives your IP address and user agent on each page load. Cloudflare and Vercel receive the request
itself, as described under Who is in the request path above. That is a
set of facts about how the site is built rather than an endorsement of any of them.
Privacy covers what it means.
Contributions
There is no CLA, and there will not be one. Nothing is assigned to anyone. You keep the copyright in your contribution.
Inbound licensing is handled by Apache-2.0 section 5: unless you state otherwise, anything you intentionally submit for inclusion is licensed under the same terms the project ships under. No separate agreement is needed to merge your work.
What is asked for instead is a sign-off — one line per commit certifying the Developer
Certificate of Origin 1.1, that you wrote the code or otherwise have the right to submit it under
Apache-2.0. git commit -s adds the line. A GitHub Actions check runs on pull requests:
it skips merge commits and, on every other commit, requires a Signed-off-by line matching the commit
author’s name and email. docs/CONTRIBUTING.md also asks that Co-authored-by
trailers each carry their own sign-off — that one is a convention in the guide, not something
the check enforces. The full text sits in DCO in the repository so you can read what
you are certifying.
One consequence is worth stating before you sign rather than after. DCO clause (d) means the record of your contribution, including the name and email address in your sign-off, is kept indefinitely and may be redistributed. It becomes part of the public git history. That is not reversible, by anyone, later.
Changes to these terms
This page can change. When it does, the date at the top changes with it. There is no account system and no mailing list for the site, so nothing will notify you — checking that date is the mechanism, and it is the only one.
You are not asked to accept anything in order to read this site. There is no checkbox and no banner, and continuing to browse after an edit is not treated as agreement to it. No governing law, venue or dispute-resolution term is stated here, and none should be inferred from anything on this page.
A change here cannot reach backwards into the licence. Section 2 grants an irrevocable licence: a copy of the software you already have stays licensed on the terms it came with, whatever this page says afterwards.
Contact
- Anything about this page
- [email protected]
- Bugs, questions, trademark permission
- GitHub issues
- Security reports
- Security policy — private, and never a public issue
- Source, licence and NOTICE
- github.com/euthynos-org/euthynos
- Package
- npmjs.com/package/euthynos
- Updates
- @EuthynosDev
Mail to that address is read by one person. Not every message gets a reply, and one that does can take a while.
© 2026 Tonil Kumar. Euthynos is maintained by one person as an individual project. There is no company behind it, and nothing on this page should be read as implying one.