Legal
Terms of service
Every section below opens with a plain-English summary of what it actually means. The legal wording follows it — but the summary is written to be the honest version, not the friendly one.
01The service
Gemmein is a backend-as-a-service for authentication, storage, and subscription payments. You build the frontend; we keep identity, data, and subscription state safe.
Gemmein ("we", "us", "our") is operated by Gemmein Limited, a company registered in England and Wales (company number 17339623). Gemmein provides a hosted backend platform that gives your web applications passwordless authentication, structured data storage, and managed subscription state (via your own Stripe account) through an API. Gemmein never holds, moves, or processes funds; all payments are processed end-to-end by Stripe. When we say "the service", we mean the Gemmein API, dashboard, documentation, and client libraries.
"You" means the person or entity that creates a Gemmein account and builds applications on the service. "End-users" means the people who use your applications.
Every application on Gemmein — including apps still being built for free — includes the following security and infrastructure features at no additional cost:
- Layered edge protection in front of every request
- Rate limiting and brute-force protection
- Tenant isolation enforced by the platform
- Private by architecture
- Audit logs for every sign-in and every write
- Domain-locked keys
- Server-decided identity
- Passwordless auth (no password database to breach)
- Encrypted in transit and at rest
- Spike protection with graceful rate limiting
- Hosting, scaling, and patching
- Automated backups and deletion protection
- Controls aligned with OWASP API Top 10, NIST CSF 2.0, and ISO 27001
- A full pre-launch security review and continuous automated security testing
These are not add-ons. They are how the service works.
02Your account
You need to be 18 or older, use a real email address, and keep your credentials safe. One person, one account.
To create an account you must be at least 18 years old and able to enter into a binding agreement under the laws of your jurisdiction. By creating an account you confirm that you meet this requirement.
Each account is for a single person or legal entity. Sharing account credentials is not permitted. You may create multiple applications within your account.
We will verify your email address during signup. You must keep your email address current so we can reach you about billing, security, and service changes.
You are responsible for all activity that occurs under your account, including the security of your secret keys. If you believe your account or keys have been compromised, rotate your keys immediately and contact us at legal@gemmein.com.
03Billing
No card at signup. Building is free; you pay for the state your live app is in, plus any storage capacity you switch on. You will never wake up to a bill you didn't set.
The pricing model
Building and testing are free, with no payment method required. When you take an app live, it enters the Live state: a flat monthly subscription (currently $50/month) that includes room for up to 1,000 people and 10 GB of file storage. A "person" means a unique enabled end-user identity attached to your live application. When your product outgrows Live, the Growing state (currently $150/month) includes room for up to 10,000 people and 50 GB of file storage; you can move between states from the dashboard, and moving down takes effect without a pro-rata refund of the current period. Above 10,000 people, pricing is agreed individually — contact hello@gemmein.com.
Additional file storage is available as pre-consented capacity (currently $5/month per additional 100 GB), turned on by you before it is used. Nothing on your bill is metered after the fact: your monthly charge is the state you are in plus the capacity you have chosen, and reaching a usage boundary never generates an automatic charge or an automatic state change.
A card is required at go-live, collected and processed by Stripe. Prices may change with notice; apps already live keep the price they signed up at.
Monthly billing cycle
Billing is monthly from the date your app goes live. You are billed at the start of each cycle for the state and storage capacity you have set.
Adjusting and cancelling
You may change state or adjust storage capacity at any time from the dashboard. Downward changes apply immediately without a pro-rata refund of the current period. You may take your app off live status or cancel through the billing portal at any time, which stops future charges; building remains free.
Refunds
We do not provide pro-rata refunds for partial months. Downward changes to your state or storage capacity apply immediately, but the amount already charged for the current cycle is not refunded.
Your first charge is refundable within 14 days, no questions asked
If your first bill isn't what you expected, email legal@gemmein.com and we will refund it in full. This is a one-time, unconditional refund on your very first paid cycle.
Room, warnings, and no surprises
As your app approaches the room included in its state, we show it in the dashboard. If an app reaches its room, people already using it that month keep working untouched; only new sign-ins wait until room is added. Nothing breaks silently, and nothing charges you beyond the state and capacity you chose.
You will never wake up to a bill you didn't set. The amount you owe each month is determined entirely by the state and storage capacity you chose.
Payment failure
If a payment fails, our payment processor retries on its schedule. We may suspend your account while a payment failure remains unresolved. Suspension means your applications' API requests will return errors, but your data is preserved. Your account will be reactivated when payment is resolved.
04Acceptable use
Build what you want, but don't use Gemmein for anything illegal, harmful, or that puts children at risk. If you see abuse, report it.
You agree not to use the service, or allow your end-users to use applications built on the service, to:
- Store, distribute, or facilitate access to illegal content under the laws of England and Wales or the jurisdiction in which you or your end-users operate
- Store, distribute, or generate child sexual abuse material (CSAM) in any form. We are obligated to report any such material discovered on the service to the relevant authorities, and will do so without notice to you
- Distribute malware, conduct phishing, or attempt to gain unauthorised access to any system
- Reverse-engineer, decompile, or attempt to extract the source code of the service
- Circumvent or attempt to circumvent rate limits, usage ceilings, or other protective measures
Your responsibility for end-users
By using the service, you warrant that your applications are not directed at children. End-users of your applications must meet the applicable minimum age: 13 years in the United States and United Kingdom, 16 years in the European Union, or the minimum age required by the laws of their jurisdiction, whichever is higher.
You are responsible for ensuring that your applications comply with all laws applicable to you and your end-users.
Reporting abuse
If you become aware of content or usage that violates these terms, report it to abuse@gemmein.com. We review every report.
05Your data
Your data belongs to you. We process it on your behalf, we don't sell it, and you can export or delete it at any time.
Ownership
You retain all rights to the data you and your end-users store on the service. Gemmein claims no ownership of your data.
Data processing
When you store your end-users' personal data on the service, you are the data controller and Gemmein is the data processor. Our processing of that data is governed by our Data Processing Agreement (DPA), which is incorporated into these terms by reference. You may request a copy of the DPA by emailing legal@gemmein.com.
Data export
You may request an export of your stored data at any time by contacting us: your records, your files, and the details of your end-users as they relate to that data. We will provide the export in a standard machine-readable format within a reasonable timeframe. Exports cover the data you and your end-users stored on the service; they do not include operational information Gemmein generates in running it.
Deletion and retention
When you delete a record through the API or dashboard, it is soft-deleted and recoverable for 30 days. After 30 days, it is permanently purged.
When you delete your account, we begin permanent deletion of all associated data. The process completes within 30 days, with encrypted backups aging out over an additional 7 days (37 days total from the deletion request).
Data location
All data is stored in the United States, with a leading cloud infrastructure provider. Transfers of personal data from the UK and EU are covered by the UK-US Data Bridge and the EU-US Data Privacy Framework respectively. For further detail, see our Privacy Policy.
06Early access
Gemmein is in early access. Features may change and support may be slower than we'd like. But what we promise about data protection is not hedged — those commitments are live now.
The service is currently in early access. During this period:
- Features may be added, changed, or removed without notice
- We do not guarantee specific uptime targets or SLAs
- Support response times are best-effort and not guaranteed
Early access affects what we promise about uptime and features. It does not change what we promise about how we protect data.
The security commitments listed in section 1 — including encryption, tenant isolation, audit logging, rate limiting, and all other items in the vault list — are fully in effect during early access. They are production commitments, not aspirational targets. We do not disclaim or weaken them during this period.
07Liability
Our liability is capped at what you've paid us in the last 12 months. If you're building for free, that's zero. UK law requires us to say certain things can never be excluded, and we say them clearly here.
Liability cap
To the maximum extent permitted by law, the total aggregate liability of Gemmein to you for all claims arising out of or relating to these terms or the service shall not exceed the total fees paid by you to Gemmein in the 12 months immediately preceding the event giving rise to the claim. For users who are building for free and have paid no fees, this cap is zero.
What we do not exclude
Nothing in these terms excludes or limits our liability for:
- Death or personal injury caused by our negligence
- Fraud or fraudulent misrepresentation
- Any other liability that cannot be excluded or limited under the laws of England and Wales
What we are not liable for
Subject to the carve-outs above, we are not liable for:
- Loss of data beyond what is recoverable from our automated backups
- Actions taken by third parties, including your end-users, payment processors, or infrastructure providers
- Indirect, incidental, special, consequential, or punitive damages, including lost profits or revenue
- Any failure or delay caused by events beyond our reasonable control (force majeure), including but not limited to natural disasters, acts of government, internet outages, and failures of third-party infrastructure
08Termination
You can leave anytime. We can suspend your account if you don't pay or break the rules, but we'll always tell you first (except in cases of illegal content). You get 30 days to export your data.
By you
You may delete your account at any time from the dashboard or by contacting us. Deletion is effective immediately; any remaining time in your current billing cycle is not refunded.
By us
We may suspend or terminate your account if:
- A payment failure remains unresolved (suspension, with reactivation on payment)
- You breach the acceptable use terms in section 4
- You breach any other material term and fail to remedy the breach within 14 days of our written notice
Where legally permitted, we will notify you by email before taking action. In cases involving illegal content or imminent harm, we may act immediately.
After termination
Following termination by either party, you have 30 days to request an export of your data, scoped as described in section 5. After 30 days, your data enters the deletion process described in section 5. Encrypted backups age out within a further 7 days.
09Governing law
These terms are governed by the laws of England and Wales, and any disputes go to the courts of England and Wales.
These terms, and any dispute or claim arising out of or in connection with them (including non-contractual disputes or claims), shall be governed by and construed in accordance with the laws of England and Wales.
The courts of England and Wales shall have exclusive jurisdiction to settle any dispute or claim arising out of or in connection with these terms.
10Changes to these terms
If we change these terms, we'll email you at least 30 days before the new version takes effect. If you keep using the service after that, the new terms apply.
We may update these terms from time to time. When we do, we will email you at the address associated with your account at least 30 days before the changes take effect, and we will update the "last updated" date at the top of this page.
Your continued use of the service after the effective date of the updated terms constitutes your acceptance of the changes. If you do not agree to the updated terms, you may delete your account before the effective date.
11Contact
Questions about these terms? Email us.
- legal@gemmein.com
- Questions about these terms, billing, or legal matters. Email legal
- privacy@gemmein.com
- Privacy and data protection. Email privacy
- abuse@gemmein.com
- Report abuse or policy violations. Report abuse