Summary
This summary helps you find your way. It does not replace the terms below, and the terms below control.
- Oxagen is for businesses. You must be at least 18 and able to accept these terms for your organization.
- Oxagen does not run your agents. You and your operators are responsible for what your agents do, including actions that Oxagen records but does not block.
- Your organization owns its data and the output it gets from Oxagen. Oxagen uses that data to provide the service and does not train AI models on it.
- AI output can be wrong. Check it before you rely on it.
- Paid plans renew until you cancel. Fees are not refundable except where the law requires or Oxagen agrees in writing.
- Oxagen provides the service as it is. Its liability is limited to the fees you paid in the last 12 months or US$100, whichever is more.
- California law governs these terms, and disputes go to the courts in San Francisco.
Agreement
These terms of service (the “Terms”) are an agreement between you and Oxagen, Inc. (“Oxagen”). They apply when you create an account, use the Services, or click to accept them.
If you accept these Terms for a company or other organization, “you” means that organization. You confirm that you have the authority to bind it. If you do not have that authority, or you do not agree to these Terms, do not use the Services.
Your organization may sign an order form or other written agreement with Oxagen. If that document conflicts with these Terms, the signed document controls for the part that conflicts. A data processing agreement signed with Oxagen controls over these Terms on how Oxagen processes personal data.
The privacy policy explains how Oxagen collects and uses personal data. Read it together with these Terms.
Definitions
These words have the following meanings in these Terms.
- Services
- The Oxagen web app at app.oxagen.sh, its API and MCP endpoints, the Oxagen desktop app, the
oxagencommand line tool, the agent wrappers, the relay, the documentation at docs.oxagen.sh, the websites at oxagen.sh, and related support. - Organization
- The company or other entity that holds an Oxagen account. An organization can contain one or more workspaces.
- Workspace
- A partition inside an organization that has its own agents, rules, and records.
- Member
- A person your organization invites or provisions to use its account, including operators, owners, and administrators.
- Agent
- An AI agent you register with Oxagen or wrap with an Oxagen wrapper, such as a coding agent in Claude Code, Codex, Cursor, or Stella. Each agent has its own identity in Oxagen.
- Stella
- The name of two things: Oxagen’s open-source command line agent, and the AI agent built into the Oxagen app. The open-source agent’s own license governs its use, as the section on software you install explains. The agent in the app is part of the Services.
- Operator
- The member accountable for an agent and its runs.
- Mandate
- The settings an agent works under in Oxagen: its access, its budget and rules, and its equipment (the tools, skills, and business context it may use).
- Run
- One agent working on one task under one operator. Oxagen records a run as a series of steps.
- Governed action
- One call routed through Oxagen that Oxagen checked against your rules and recorded.
- Customer Data
- Data that you, your members, or your agents submit to the Services, or that the Services collect for you. It includes run records, prompts, model responses, tool calls and their results, files, code, rules, and settings.
- Output
- Content that an AI feature of the Services produces for you.
- Third-party service
- A product or service that Oxagen does not provide, such as a model provider, an agent tool, a code host, or an identity provider.
- Order form
- A document that you and Oxagen sign, or that you accept in the app, that sets out a plan, fees, or other commercial terms.
Eligibility and accounts
- The Services are for business and professional use. They are not for personal, family, or household use.
- You must be at least 18 years old, and old enough to form a binding contract where you live.
- You may not use the Services if United States law or the law where you live bars you from doing so, or if Oxagen has ended your access before.
Give accurate information when you sign up, and keep it current. You are responsible for your account credentials and for everything done under your account. Use two-factor authentication or single sign-on where you can. Tell Oxagen at security@oxagen.sh as soon as you learn that someone has used your account without permission.
Your organization controls its account. Its owners and administrators can invite and remove members, change roles, read the records of runs in the organization, export data, and close the account. If you joined through your organization’s invitation or single sign-on, your organization can see and manage your use of its account. Oxagen may act on instructions about the account from your organization’s owners and administrators.
Your organization is responsible for making sure its members follow these Terms.
The Services
Oxagen is workforce management for autonomous agents. You give each agent an identity, set its authority and budget, equip it with tools and skills, and review what it did and what its operators spent. Oxagen applies those decisions to the actions your agents route through it, and keeps a record of them.
Oxagen may change the Services over time, and may add, change, or remove features. If Oxagen removes a feature that is a material part of a paid plan you use, it will tell you in advance where it reasonably can.
Oxagen does not commit to any level of uptime or support response time unless an order form says so. For support, write to success@oxagen.sh.
Your agents
Oxagen is an agent control plane. It decides what agents may do, hands them what they need, and keeps the record. It does not run your agents. Your agents run on your computers or on services you choose, under accounts you hold with those services.
- Rules apply to routed actions only. A rule in Oxagen answers a request only when the agent routes that action through Oxagen. An agent can still take actions that do not pass through Oxagen, such as commands it runs on a machine or calls it makes with credentials it holds itself.
- Observe mode records and does not enforce. When a workspace runs in observe mode, Oxagen records what the agent does and does not stop it.
- Records show what Oxagen received. A run record holds the events that your wrapper or agent sent to Oxagen. If a wrapper is off, set up wrong, or offline, the record can be incomplete.
- Spend figures are estimates. Oxagen works out cost from token counts and published rates. Your model provider’s invoice is the final word on what you owe that provider.
You are responsible for your agents and for what they do, whether Oxagen allowed, denied, routed, or only recorded the action. This includes the rules, budgets, and permissions you set, the credentials you give Oxagen or your agents, and any action a person approves when a rule routes a request to them. Review your agents’ work before you depend on it. Take particular care before an agent changes production systems, sends messages, moves money, or deletes data.
When you give Oxagen a credential for a connection, you authorize Oxagen to use that credential on your agents’ behalf, within the scope you set, to carry out the actions your rules allow. Give each connection only the scopes your agents need.
AI features
Some parts of the Services use AI models. These include Stella, the AI agent built into the Oxagen app, and the summaries and suggestions Oxagen shows you. To produce Output, these features send your prompts and related Customer Data to a model provider.
- Output can be wrong. AI models can produce Output that is inaccurate, incomplete, out of date, or offensive. They can describe code or systems that do not behave the way the Output says. Check Output before you rely on it. Do not use it in place of advice from a qualified professional.
- Output may not be unique. Other customers may receive Output that is similar or identical to yours.
- You own your Output. As between you and Oxagen, you own the Output you receive, to the extent the law allows. Oxagen assigns to you any rights it has in that Output.
- No training on your data. Oxagen does not use Customer Data or Output to train AI models. If you rate a reply or send feedback on it, Oxagen staff may read that reply and the turn behind it to fix problems and improve the feature.
- Model providers. When Oxagen supplies model access, it sends requests through a model gateway, such as OpenRouter or Vercel AI Gateway, which passes them to a model provider. When you bring your own key, requests go to the provider you choose, under your own agreement with that provider. Each provider handles requests under its own terms.
Do not use AI features for anything the acceptable use section forbids, or in a way that breaks the usage policy of the model provider that serves the request.
Customer Data
You own your Customer Data. Oxagen claims no ownership of it.
You give Oxagen a worldwide, non-exclusive, royalty-free license to host, copy, process, transmit, and display Customer Data. Oxagen may use this license only as needed to provide, secure, and support the Services, to prevent abuse, and to comply with the law. The license ends when Oxagen deletes the Customer Data, as the privacy policy describes.
Oxagen may create aggregated or de-identified data from use of the Services, such as counts of governed actions, error rates, and which features are used. Oxagen may use that data to run, improve, and bill for the Services. That data will not identify you, your members, or any other person, and will not contain the content of your Customer Data.
You are responsible for your Customer Data. You confirm that you have the rights and permissions needed to submit it and to let Oxagen process it under these Terms. That includes giving any notices to, and getting any consents from, the people whose personal data it contains.
Recorded content. By default, Oxagen records the content of runs. That includes prompts, model responses, tool inputs and results, and the model requests and responses that pass through Oxagen’s local proxy. Before storing content, Oxagen removes common credential formats, such as API keys and access tokens. It does not remove other sensitive data, such as personal data or confidential business information. A workspace can choose to keep only digests and metadata instead of content.
Do not send health records, payment card numbers, or other regulated data through a run that Oxagen records, unless you have a written agreement with Oxagen that covers that data.
Acceptable use
You must not use the Services, and must not let your agents or anyone else use them, to do any of the following.
- Break a law, or help someone else break one.
- Infringe or misuse anyone’s intellectual property, privacy, or other rights.
- Get into a system, account, network, or data without permission. Probe, scan, or test the weaknesses of a system without its owner’s permission.
- Make or spread malware, or carry out denial-of-service attacks, phishing, spam, or fraud.
- Harass, threaten, or harm anyone, or create or share sexual content involving minors.
- Present an agent’s actions or Output as the work of a person in a way that deceives someone.
- Make decisions that have legal or similarly significant effects on a person, such as decisions about employment, credit, housing, insurance, or health care, without meaningful human review.
- Break the terms or usage policies of a model provider, agent tool, or other third-party service you use with Oxagen.
You also must not do any of the following.
- Get around a rule, budget, limit, or security control in the Services, including by splitting requests to stay under a limit.
- Copy, decompile, disassemble, or reverse engineer the Services, except where the law allows it despite this term.
- Scrape the Services, or reach them by automated means other than the API, command line tool, MCP server, and wrappers that Oxagen provides.
- Resell or sublicense the Services, or give access to anyone outside your organization, unless an order form allows it.
- Use the Services or Output to build a competing product, or to train a model that competes with the Services.
- Interfere with the Services, put an unreasonable load on them, or disrupt other customers’ use of them.
- Test the security of the Services without Oxagen’s written permission. To report a vulnerability, write to security@oxagen.sh.
Oxagen may investigate a suspected violation. It may remove content or suspend access as the suspension and termination section describes.
Third-party services
The Services work with third-party services, such as Claude Code, Codex, Cursor, GitHub, GitLab, Slack, Google, model gateways, and model providers. You choose which ones to use. Your agreements with those providers govern your use of their services. These Terms do not.
When you connect a third-party service, you authorize Oxagen to exchange data with it as needed to provide the feature you turned on. For example, when you install the Oxagen GitHub App, Oxagen can read the repositories you choose. If you also turn on push custody, Oxagen can push the changes your rules allow.
Oxagen does not control third-party services and is not responsible for them. That includes their availability, security, prices, and changes to their features. If a provider changes or ends its service, Oxagen may need to change or end the related feature.
Fees and payment
Plans and meters
Some features are free, and others need a paid plan. Oxagen measures use in two units.
- Governed action units (GAUs) count the governed actions that Oxagen checks and records for your agents.
- Usage credits pay for AI features inside the Oxagen app, such as Stella.
The prices, included amounts, and overage rates for your plan are the ones shown in the app or in your order form when you buy. The prices in effect when you buy apply until your plan renews.
Grants
Oxagen may give your organization free GAUs or usage credits, for example when you sign up. A grant lasts only for the period Oxagen states when it gives the grant, and then it expires. GAUs and usage credits, whether granted or bought, have no cash value. You cannot transfer them or exchange them for money, and they end when your account closes.
Model usage
If Oxagen supplies model access for your organization, Oxagen bills that usage as the app shows. Oxagen may set spending limits on that access, such as a daily ceiling. If you bring your own model provider key, the provider bills you directly, and Oxagen does not charge you for those tokens.
Billing and renewal
Subscriptions renew automatically for the same period, monthly or yearly, until you cancel. You authorize Oxagen and its payment processor, Stripe, to charge your payment method for each renewal. You also authorize charges for use above your plan’s included amounts, including any automatic top-ups you turn on.
You can cancel at any time in the billing settings of the app. Cancellation takes effect at the end of the current billing period, and you keep access until then.
If you pay by invoice, payment is due within 30 days of the invoice date unless your order form says otherwise.
Price changes
Oxagen may change its prices. It will tell you at least 30 days before a price increase applies to you, and the new price starts at your next renewal. If you do not agree to the new price, cancel before the renewal.
Taxes
Prices do not include taxes. You are responsible for sales, use, value-added, and similar taxes on your purchases, except taxes on Oxagen’s income.
Late payment
If a payment fails, or an invoice is more than 5 days past due, Oxagen may suspend paid features after telling you. Oxagen restores them once you pay.
Refunds
Fees are not refundable, and Oxagen does not give partial refunds for unused time or units, except where the law requires or Oxagen agrees in writing. If Oxagen refunds a purchase of GAUs or usage credits, it removes the unused units that purchase added.
Billing disputes
If you think a charge is wrong, write to success@oxagen.sh within 60 days of the charge. Oxagen will review it in good faith.
Software you install
The Services include software you install, such as the Oxagen desktop app, the oxagen command line tool, the agent wrappers, and the relay. Oxagen gives you a limited, non-exclusive, non-transferable license to install and use that software to reach the Services while your account is active.
Automatic updates. On macOS, the Oxagen desktop app downloads and installs new versions automatically unless you turn automatic updates off. On Windows and Linux, the desktop app asks before it installs an update. Other Oxagen software may also check for new versions.
Usage telemetry. The oxagen command line tool sends anonymous usage telemetry by default. To turn it off, run oxagen telemetry off, or set OXAGEN_TELEMETRY=0 or DO_NOT_TRACK=1. The privacy policy lists what it sends.
Open-source software. Some software Oxagen publishes is open source, and its own license governs your use of it instead of these Terms. Stella is licensed under the GNU Affero General Public License, version 3. The Context Graph Protocol is licensed under the MIT License or the Apache License 2.0, at your choice. The Services also contain open-source components from others, each under its own license.
Ownership
Oxagen and its licensors own the Services, including the software, designs, documentation, and the Oxagen and Stella names and marks. These Terms give you no rights in them except the limited rights to use the Services that these Terms state. Oxagen keeps all other rights.
Feedback. If you send Oxagen ideas or suggestions about the Services, Oxagen may use them without restriction and without paying you. Oxagen will not name you as their source without your permission.
Publicity. Oxagen will not use your organization’s name or logo to promote Oxagen without your permission.
Confidentiality
“Confidential information” means non-public information that one party shares with the other and that a reasonable person would understand to be confidential. Your Customer Data is your confidential information. The non-public parts of the Services, the pricing in an order form, and Oxagen’s security reports are Oxagen’s confidential information.
The party that receives confidential information will use it only to do what these Terms require. It will share it only with employees, contractors, and service providers who need to know it and who are bound by confidentiality duties at least as strict as these. It will take reasonable care to keep the information secret.
These duties do not apply to information that becomes public through no fault of the receiving party. They also do not apply to information the receiving party already knew, developed on its own, or lawfully received from someone else without a duty to keep it secret. A party may disclose confidential information when the law requires it. Where the law allows, it will first tell the other party and give it a chance to object.
Privacy and security
The privacy policy explains how Oxagen handles personal data. For Customer Data, Oxagen acts as your service provider and processes it on your instructions. These Terms and the way you set up the Services give those instructions. If you need a data processing agreement, write to privacy@oxagen.sh.
Oxagen uses technical and organizational measures designed to keep Customer Data secure. These include encryption in transit over the internet, encryption of stored data, separation of each customer’s data, role-based access, and audit logs. No system is perfectly secure, and Oxagen does not promise that unauthorized access cannot happen.
If Oxagen confirms a security breach that affects your Customer Data, it will tell you without undue delay. It will describe what it knows and keep you updated as it learns more.
You are responsible for the security of your own devices and networks, your accounts with third-party services, and the credentials you hold.
Preview features
Oxagen may offer features marked as preview, beta, early access, or something similar. Preview features may be incomplete, and may change or end without notice. No commitment in an order form covers them. Oxagen provides preview features as they are, with no warranty of any kind.
Suspension and termination
Closing your account
You can stop using the Services at any time. An owner can close your organization’s account in the app, or by writing to success@oxagen.sh. Closing an account cancels its subscriptions at the end of the current billing period.
Suspension
Oxagen may suspend all or part of your access, or stop your agents’ governed actions, in these cases.
- Oxagen reasonably believes that you or your agents broke the acceptable use section.
- Your use creates a security risk for Oxagen, its customers, or anyone else.
- Your use could make Oxagen liable to someone else.
- A payment is overdue, as the fees section describes.
- The law or a third-party provider requires it.
Oxagen will try to tell you first, and will limit a suspension to what is needed. It will restore access once the cause is fixed.
Termination by Oxagen
Oxagen may end these Terms for your organization if you materially break them and do not fix the breach within 30 days after notice. If the breach cannot be fixed, Oxagen may end them right away. Oxagen may also close a free account, or stop offering the Services, with at least 30 days’ notice. If Oxagen stops offering the Services for a reason other than your breach, it will refund prepaid fees for the unused part of your term.
After termination
When these Terms end, your right to use the Services ends. For 30 days after that, an owner can ask Oxagen to export your Customer Data, and Oxagen will provide it in a common file format. After that, Oxagen deletes Customer Data as the privacy policy describes. You must still pay any fees owed up to the end date.
The sections that by their nature should continue after these Terms end will continue. These include the sections on fees owed, Customer Data, ownership, confidentiality, disclaimers, limitation of liability, indemnity, and disputes.
Disclaimers
To the extent the law allows, Oxagen provides the Services and all Output “as is” and “as available”. Oxagen and its suppliers disclaim all warranties, express or implied. These include warranties of merchantability, fitness for a particular purpose, title, and non-infringement, and any warranty arising from a course of dealing or usage of trade.
Oxagen does not promise that the Services will be uninterrupted, error-free, or secure. It does not promise that a rule will stop every unwanted action, that run records will be complete, that cost figures will match your providers’ invoices, or that Output will be accurate. Some places do not allow these disclaimers, so some of them may not apply to you.
Limitation of liability
To the extent the law allows, these limits apply.
- Neither party is liable to the other for indirect, incidental, special, consequential, or punitive damages, or for lost profits, revenue, goodwill, or data. This is true even if the party was told such damages were possible.
- Each party’s total liability arising out of or relating to these Terms or the Services is limited to the greater of two amounts: the fees you paid Oxagen in the 12 months before the event that caused the claim, or US$100.
These limits do not apply to your duty to pay fees, to your indemnity duties, or to your breach of the acceptable use section. They also do not apply to a party’s liability for fraud, gross negligence, or willful misconduct, or to anything else the law does not allow a party to limit.
These limits apply even if a remedy fails of its essential purpose. They reflect how the parties have shared risk, and Oxagen’s prices depend on them.
Indemnity
You will defend Oxagen and its officers, directors, and employees against any claim by a third party that arises from your Customer Data, your agents’ actions, your use of third-party services with Oxagen, or your breach of these Terms or of the law. You will pay the damages, costs, and reasonable lawyers’ fees that a court awards in a final judgment, or that you agree to in a settlement, for that claim.
Oxagen will tell you promptly about the claim, let you control its defense and settlement, and give reasonable help at your cost. You may not settle a claim in a way that admits fault for Oxagen, or requires Oxagen to act, without Oxagen’s written consent.
If an order form includes an indemnity from Oxagen, that indemnity applies as the order form states.
Disputes and governing law
The laws of the State of California govern these Terms and any dispute arising out of or relating to them or the Services, without regard to conflict-of-laws rules. The United Nations Convention on Contracts for the International Sale of Goods does not apply.
Before either party files a claim, it will try to resolve the dispute informally. It will send the other party a written description of the dispute. If the parties cannot resolve it within 30 days, either party may go to court.
The state and federal courts in San Francisco County, California, have exclusive jurisdiction over any dispute, and both parties consent to their jurisdiction. Either party may ask any court with jurisdiction for an injunction or other urgent relief to stop misuse of its intellectual property or confidential information.
To the extent the law allows, each party may bring claims against the other only as an individual. Neither party may bring claims as a plaintiff or class member in a class or representative action.
Export controls and sanctions
United States export control and sanctions laws apply to the Services. You confirm that you are not located in, organized under the laws of, or ordinarily resident in a country or region under a United States embargo. You also confirm that you are not on a United States government list of restricted parties. You will not use the Services, or let anyone use them, in a way that breaks those laws.
Changes to these terms
Oxagen may update these Terms. For a material change, Oxagen will tell you at least 30 days before it takes effect, by email to your organization’s owners or by a notice in the app. A change that the law requires, or that covers a new feature, can take effect sooner. The “Last updated” date at the top of this page shows when these Terms last changed.
If you keep using the Services after a change takes effect, you accept the updated Terms. If you do not agree, stop using the Services and close your account before the change takes effect. If you paid in advance for a fixed term, the earlier Terms keep applying until that term ends, unless the law requires the change.
General terms
Entire agreement
These Terms, together with any order form and data processing agreement, are the entire agreement between you and Oxagen about the Services. They replace any earlier agreement on the same subject. Terms in your purchase order or a similar document do not apply, even if Oxagen accepts the order.
Assignment
You may not transfer these Terms without Oxagen’s written consent, except to a successor in a merger, an acquisition, or a sale of all or most of your assets. Oxagen may transfer these Terms in the same circumstances. Any other transfer is void.
Notices
Oxagen sends notices by email to your organization’s owners or by a notice in the app. Send legal notices to Oxagen at hello@oxagen.sh, with a copy by mail to the address in the contact section. A notice takes effect when the other party receives it. You agree to receive notices, agreements, and other communications from Oxagen electronically.
Events beyond control
Neither party is liable for a delay or failure caused by events beyond its reasonable control. Examples are natural disasters, war, terrorism, strikes, government action, and failures of the internet or of a third-party provider. This does not excuse a duty to pay.
Relationship
You and Oxagen are independent contractors. These Terms do not create a partnership, joint venture, employment, or agency relationship. These Terms give no rights to anyone other than you and Oxagen.
Waiver and severability
If a party does not enforce a term, it does not give up the right to enforce it later. If a court finds a term unenforceable, the court will enforce it as far as the law allows, and the rest of these Terms stay in effect.
Government use
If you are a United States government entity, the Services are commercial products and commercial computer software. You receive only the rights that these Terms give to all customers.
Language
These Terms are written in English. If a translation conflicts with the English version, the English version controls.
Contact
Write to the address that matches your question.
- These Terms and legal notices
- hello@oxagen.sh
- Support and billing
- success@oxagen.sh
- Privacy
- privacy@oxagen.sh
- Security reports
- security@oxagen.sh
- Oxagen, Inc., 2261 Market Street STE 87168, San Francisco, CA 94114, United States
Oxagen, Inc. Terms of service. Effective October 1, 2026.