Loading
These terms govern your use of the site at useagentfox.com: the playground, the dashboard, and the API behind them. They are an agreement about a demonstration someone else is paying to run. They are not a software licence.
Last updated 24 September 2026.
The AgentFox software is licensed under the Apache License 2.0, in the LICENSE file at the root of the repository. That licence is the whole of your rights to the software: to use it, copy it, modify it, run it commercially, and distribute your changes, on its own terms and subject only to its own conditions.
No sentence on this page restricts, conditions or withdraws any right Apache-2.0 grants you, and none is intended to. If anything here appears to conflict with the licence where the licence applies, the licence wins and the conflicting sentence should be treated as an error and reported. These terms reach only the hosted service: the machines, the shared database and the demonstration environment we operate. Take the software and run it yourself and you owe us no agreement at all.
The hosted service is provided as-is and as-available, with no warranty of any kind, express or implied, including any implied warranty of merchantability, fitness for a particular purpose, or non-infringement. To the fullest extent the law allows, the maintainer is not liable for any direct, indirect, incidental, special, consequential or exemplary damages arising out of your use of the hosted service, including lost profits, lost data or business interruption.
There is no service level agreement. There is no uptime commitment, no support commitment on this tier, no response time and no credit for an outage. This is a demonstration operated by one person.
Do not use the hosted service to govern production agents, and do not rely on anything it stores as your record of anything. It is here so you can see the product work before you decide to run it. Running it yourself is the supported way to use AgentFox for real, and it costs nothing.
Your playground sandbox is isolated from everyone else’s, but it runs on shared infrastructure with a deliberately short life. It is deleted after thirty minutes of inactivity, and it can be deleted sooner when the deployment is at its concurrent-sandbox cap. The whole playground can be reset, changed or removed at any time without notice.
Two consequences worth stating plainly. Nothing in a sandbox is durable, so do not put anything in one that you would mind losing in the next half hour. And the sandbox id in your URL is the only credential protecting it, so anyone you send the link to can read it.
The timings and the cap, and the code that enforces them, are described on the privacy page.
This is a security product, so the usual template wording would be actively misleading. The line is between the target and the infrastructure.
Attack the sandboxed agent as hard as you like. Prompt injection, indirect injection through the document you are given to edit, multi-turn payload splitting, obfuscation, jailbreaks, attempts to make it call a tool it was never granted: all of that is what the playground is for. Finding a way through is the point, and if you find one, we want the report.
Attacking the infrastructure rather than the target. Do not attempt to reach another tenant’s or another visitor’s data, guess or enumerate sandbox ids, escalate a token’s permissions, break out of the sandbox into the host or the database, or run denial of service, volumetric load or automated scanning against this deployment.
Also not allowed, and this one is not a technical boundary but a straightforward one: do not use the hosted service as a staging post for an attack on anyone else, and do not use it to generate, store or route content that is unlawful where you are or where it lands. Do not upload other people’s personal data, credentials or confidential material into a playground sandbox. It is a public demonstration, not a vault, and you have no reason to need to.
If you think you have found a way through the infrastructure boundary rather than the sandbox one, stop, and report it. Reporting it is the supported path, and it is described on the security page. Testing only far enough to confirm a finding, and then stopping, is welcome. Continuing past that point is not.
Accounts and sandboxes that breach any of this can be suspended or removed without notice. Rate limits apply to the playground and are not a challenge to be routed around.
Signing in with GitHub creates an account and an organisation you own. You are responsible for what happens under it and for the repositories you choose to connect. Connect a repository only if you are entitled to, and revoke the authorisation in your GitHub settings when you are done: that takes effect at GitHub’s end immediately.
The hosted service can be changed, restricted, suspended or discontinued at any time, for any reason, with or without notice, in whole or for any one account. These terms can change too; the date at the top is when they last did, and continuing to use the site after a change is how you accept it. Material changes will be noted in the repository, which has a public history you can read rather than a notice you have to trust.
None of this can take the software away from you. If the hosted service is switched off tomorrow, the Apache-2.0 grant is unaffected and the repository is still there.
These terms are governed by the laws of [jurisdiction to be set by the maintainer], and the courts of [jurisdiction to be set by the maintainer] have exclusive jurisdiction over any dispute arising from them.
That placeholder is real and unfilled. It is left visible rather than guessed at, because naming a jurisdiction we have not chosen would be the sort of decorative accuracy this project exists to avoid.
support@nometria.com. Security reports go somewhere else, and the route is on the security page.