Terms of service
These are the terms under which Bucker would be offered. They are a draft written by the engineers who built the service, from the repository, so that what they promise is what the code does — and so that the sections a lawyer must write are visibly empty rather than filled with boilerplate nobody checked. Bucker is pre-launch: no contract is in force with anyone, no payment provider is connected, and no price has been charged.
The parties
The operating entity is not yet named in this draft; it will be when the draft is reviewed. "You" means the organization that creates an account, and the people and AI agents acting under it.
The service
Bucker receives error events from your applications through an SDK you install, groups them into issues, and makes each issue readable by a coding agent as a bounded, versioned "error essence". It can run a proposed fix in an isolated sandbox and report the result, present the result to a human for approval, and record that decision with the evidence behind it. What the service captures and keeps is described in the privacy notice.
Where a capability is described on this site as an intention rather than a shipped behaviour, it is labelled as one on the page where it appears, and the label — not this document — is what you should rely on.
Your account
You are responsible for the credentials under your account and for every action taken with them, including actions taken by agents you create. Two-factor authentication is available to every account; single sign-on and directory sync are available on paid plans. Suspending a person also suspends every agent that person sponsors, in one transaction.
Your data
You own the data you send. We process it to provide the service, as the privacy notice describes, and for nothing else. Telemetry is treated as untrusted input throughout the product: strings from your application and from your users are rendered as data, never as instructions, and are labelled with their trust level wherever an agent reads them.
You are responsible for having the right to send what you send. The scrubber removes credentials and card numbers before storage as a safety net; it is not a licence to send them.
Agents, and the one thing they cannot do
An AI agent that acts in Bucker does so as a principal with a named human sponsor, a bounded delegation, a budget and an audit trail. No agent can approve a fix or merge a pull request, on any plan and under any configuration: the approval endpoint refuses non-human principals, the approval scope is never issued to an agent, and there is no merge method in the source-control client to call. A human's decision to approve is the human's decision, and you are responsible for it.
Sandbox verification of a fix runs in infrastructure we operate. It is a cloud capability; the Community Edition does not include it and says so with a 403, not a crash.
Plans, quotas and billing
Plans, their event quotas and their prices are published on the pricing page, which reads the same endpoint the product enforces. The mechanisms that bound your bill are in the code rather than in this document, and the pricing page names the file for each: spend caps are on by default on every plan; past your event quota ingestion degrades to sampling rather than dropping silently, and every dropped event is accounted for; the AI lane bills only for a fix that reached verification tier A or B and was approved by a named human; unused verified-fix credits roll over, capped at three months of your allotment; human seats are unlimited on every plan; agent principals are capped per plan.
No payment provider is connected. Plan changes and proration quotes are computed and recorded; they are not settled, and nothing in this system has ever charged a card. When payment is switched on, these terms will say so in a reviewed revision, and the change will appear in the changelog.
Availability
There is no service-level agreement, no service-level objective, no uptime history and no status page. The decision to publish a status page through a hosted provider rather than build one, and what it would show, is written down in the status-page decision.
Community Edition
A self-hostable subset of Bucker is distributed as the Community Edition. It is governed by the licence that accompanies its source, not by these terms, and its documentation states exactly where the commercial boundary sits.
Suspension and ending the relationship
You may stop using the service at any time and ask for your data to be erased; the shape of erasure is described in the privacy notice. We may suspend an account that abuses the ingest path or the sandbox, or that sends data it is not entitled to send. There is no written enforcement policy or appeals process yet; that gap is stated here rather than implied away.
Warranty, liability and governing law
Not drafted. These sections are intentionally empty in this draft so that no reader takes boilerplate for a commitment. A reviewed revision will state them, and nothing about warranty, liability or jurisdiction should be inferred from their absence.
Changes to these terms
Every change to these terms is a dated, reviewable revision, and the history is published alongside them. Material changes will be announced before they take effect.