Terms

Terms of service

The agreement between you and x6c LLC for the rypt API, the dashboard, these websites and the command line.

Effective 2026-09-25.

In brief

What matters most

  • Your keys stay with rypt. If a key's material is destroyed, or your account or the Service ends, anything encrypted under that key can no longer be decrypted through the Service. Decrypt what you need first.
  • Some actions cannot be undone by you. Rotating a Free or Extra wrapped key retires its previous version at once, and deleting any key retires every version. Retired key material is destroyed 24 hours later.
  • Paid keys are billed monthly in arrears, a full month for any month the key exists while you have a subscription, plus tax. Fees are non-refundable except where the law requires.
  • There is no uptime guarantee, and our liability is limited.

This summary is not the whole agreement. The sections below are.

Section 1

Agreement

These terms are an agreement between you and x6c LLC, a West Virginia limited liability company ("x6c", "we", "us"), which operates rypt. They govern the rypt API at api.rypt.dev, the dashboard at dashboard.rypt.dev, the websites rypt.dev and sh.rypt.dev, and the command-line tools we distribute (together, the "Service").

You accept these terms by signing in to the dashboard, by calling the API, or by otherwise using the Service. If you do not agree, do not use the Service. If you use the Service for an organization, you accept these terms on its behalf and confirm that you have the authority to; "you" then means that organization.

The privacy policy describes how we handle personal information. It is a notice to you, not part of this agreement. The pricing on rypt.dev sets out current prices and included operations, and is part of these terms; Section 7 explains how they are billed.

Section 2

Who can use rypt

You must be at least 18 and able to form a binding contract. The Service is intended for developers and businesses. You may not use it if the laws of the United States, or of where you live, bar you from doing so, including the sanctions laws in Section 19.

Section 3

Your account and API keys

  • One account per sign-in identity. The first time you sign in with an identity, such as a Google account or an email address and password, an account is created and you become its owner. Signing in with a different identity, even one with the same email address, can create a separate, empty account. Each account has one user.
  • You are responsible for your credentials. You are responsible for everything done with your sign-in and your API keys, including the fees they incur. Keep them secret.
  • An API key is full control. Besides the cryptographic operations, an API key can create, rotate and delete every key in your account, including paid keys that incur fees, and read its audit logs and usage. There are no read-only or per-key API keys, and API keys do not expire: each one works until it is revoked. A new API key is shown once and cannot be recovered.
  • API keys we issue. x6c can also issue and revoke API keys in your account with its own tools. An API key issued this way appears in your list of API keys in the dashboard, where you can revoke it. You are not responsible for the use of an API key we issued without your request.
  • Your sign-in is the root credential. A dashboard sign-in can issue and revoke API keys, and create, rotate and delete keys. Protect it accordingly.
  • Report exposure at once. If you think a credential has been exposed, revoke the API key in the dashboard and tell us at support@rypt.dev. We are not responsible for loss caused by someone else using your credentials, except to the extent our breach of these terms caused it.

Section 4

The Service

  • What it does. The Service performs symmetric encryption over HTTPS, with keys that it creates and holds for you. The security page describes how keys are held, what the Service records, and what it does not claim.
  • Tiers. Each key has a tier, Free, Extra wrapped, Software or Hardware, fixed when the key is created. In the API and on invoices, Extra wrapped is called wrapped, and Hardware is called hsm or HSM. The dashboard uses both sets of names.
  • Keys stay with rypt. You cannot take key material out of rypt or bring your own key material into it. Ciphertext from Free and Extra wrapped keys is in rypt's own format, which only rypt can decrypt.
  • Not zero-knowledge. Your plaintext reaches rypt so it can be encrypted, and rypt holds the keys that decrypt it. On the way it passes through Cloudflare, which terminates TLS in front of the API, and for Software and Hardware keys it is also sent to Google Cloud KMS.
  • Limits. The Service has limits. Today they are: a request body of at most 128 KiB; plaintext of 1 to 65,536 bytes, or 8,192 bytes together with any aad on a Hardware key; aad of at most 65,536 bytes; about 100 requests a second per API key; and 10,000 operations a month on a free key. The API's error responses name the limit you reached. Section 14 covers changes to them.

Section 5

Keys, rotation and deletion

Some actions in the Service permanently destroy key material. Once key material is destroyed, nothing encrypted under it can be decrypted through the Service again, by you or by us.

  • Rotation happens only when you request it. Rotating a Free or Extra wrapped key retires its previous version at once: anything encrypted under that version stops decrypting when the rotation succeeds. A Software key keeps its three most recent versions and a Hardware key its two. A rotation past that count retires the oldest version.
  • Deletion is final. Deleting a key retires every version. The key stops answering at once, apart from its audit log. You cannot undo a deletion, and we do not undo deletions.
  • Retired versions are destroyed. A retired version's key material is destroyed 24 hours after it is retired. Within that time we may, at our discretion, be able to restore a retired version of a key that has not been deleted, but we do not promise to.
  • Lapsed billing and rotation. While billing is not in good standing, rewrap is refused on paid keys (Section 8), so do not rotate a paid key until billing is restored.
  • Backups. Destroyed key material of Free and Extra wrapped keys can survive, still wrapped, in database backups until they expire.

You are responsible for keeping what you need decryptable. Before you rotate a Free or Extra wrapped key, decrypt what you need and encrypt it again under another key, because nothing can be moved onto the new version once the old one is retired. Before a rotation takes a Software or Hardware key past its version count, rewrap what you need onto the current version. Before you delete a key, and before your account or the Service ends, decrypt what you need.

Section 6

The free key

Each account may hold one live free key, at no charge. It includes 10,000 operations a month. Past that, every operation on it, decrypt and unwrap included, is refused until 00:00 UTC on the 1st of the next month. A free key keeps only its current version (Section 5).

Deleting your free key lets you create another, but do not do so to get more than 10,000 operations in a month, and do not create extra accounts to get more free keys or operations.

We may change or end the free tier. We will post the change on rypt.dev, and email it as Section 22 describes, at least 30 days before it takes effect. If we end the free tier, decrypt and unwrap on existing free keys will keep working, within the monthly limit, for at least 90 days after that date, so you can recover your data.

Section 7

Fees and billing

Automatic renewal. Setting up billing starts a subscription that renews automatically every calendar month in UTC until you cancel it. After each month ends, we charge your payment method for that month: the monthly fee for each paid key you held, plus operations past each key's allowance, plus tax. The amount changes with the keys you hold and the operations you use. Nothing is charged when you set up billing. You can cancel at any time in Stripe's billing portal, which the dashboard links to, and cancellation takes effect at the end of the current month.

  • Paid keys. Extra wrapped, Software and Hardware keys are paid keys. Their prices and included operations are in the pricing on rypt.dev. Today they are $3, $10 and $35 a month per key, including 50,000, 100,000 and 250,000 operations a month, with further operations at $0.10, $0.20 and $0.50 per 10,000.
  • Setting up billing. You must set up billing through Stripe, from the dashboard, before you create a paid key. You authorize us, through Stripe, to charge your payment method for all fees when they are due.
  • Billing period. Fees are billed monthly in arrears, for each calendar month in UTC. Your first invoice covers the time from when you set up billing to the next 1st.
  • Whole months. While you have a subscription, a paid key's monthly fee is charged in full for every calendar month in which the key exists at any time, including the month it is created, the month it is deleted, and the month you set up billing, even for a key deleted earlier that month. Fees are not prorated. Paid keys that remain after your subscription ends incur no fees until you set up billing again.
  • Operations. Encrypt, decrypt, wrap, unwrap and rewrap each count as one operation, and only once the cryptography succeeds. Each paid key gets its full monthly allowance. Operations past a key's allowance are charged per operation at its tier's rate, totalled for each invoice line and rounded to the cent. Paid keys are not stopped at their allowance, and there is no spending limit or usage alert; the dashboard shows an estimate of the month so far.
  • Taxes. Prices are in US dollars and do not include taxes. We add sales tax, VAT or similar taxes through Stripe where we are registered to collect them. You are responsible for all taxes on your purchases other than taxes on our income, including any we do not collect.
  • Invoices. Stripe prepares an invoice after each month ends, and you can see your invoices in Stripe's billing portal, which the dashboard links to. The estimate in the dashboard is before tax and is not a bill; the invoice is.
  • No refunds. Fees are non-refundable, except where the law requires a refund. If you think an invoice is wrong, tell us at support@rypt.dev within 60 days of its date; we will look into it and correct any error we find. An invoice you have not questioned within that time is final, except where the law gives you longer. Please contact us before disputing a charge with your card issuer.
  • Setting up billing again. We may require you to set up billing again, for example if we change payment provider or payment account. From that change until you set up billing again, your billing is not in good standing (Section 8), and each paid key is charged its full fee for the month in which you do.

Section 8

Late payment and lapsed billing

If a payment fails, Stripe may retry it, and the Service keeps working while it does. If the invoice stays unpaid, or your subscription ends, your billing is no longer in good standing. Then you cannot create paid keys, and encrypt, wrap and rewrap on paid keys are refused.

Decrypt and unwrap on paid keys are not refused because of billing, so you can still decrypt data under any key version that has not been retired (Section 5). Free keys are not affected.

While an invoice is unpaid and your subscription is still open, paid keys keep incurring their monthly fees and any overage, including overage from decrypt and unwrap. You cannot start a new subscription while that one is open. To restore good standing, pay the open invoice in Stripe's billing portal, which the dashboard links to. Delete paid keys you no longer need to stop their fees. Amounts you owe remain due, and we may suspend or terminate your account for non-payment under Section 15.

Section 9

Cancelling a subscription

You can cancel your subscription in Stripe's billing portal, which the dashboard links to. Cancellation takes effect at the end of the current UTC calendar month, and usage up to then is billed. After that your paid keys remain: decrypt and unwrap keep working at no charge, and encrypt, wrap and rewrap are refused until you set up billing again. If you set up billing again, each paid key that existed at any time in that month is charged its full fee for the month (Section 7), even one you deleted earlier in the month. To stop using a key altogether, delete it.

If you end up with more than one subscription, for example by completing checkout twice or by setting up billing again while an older subscription is still open, we may cancel all but one of them at once, without a final invoice for the ones we cancel. Amounts already invoiced on them remain due.

Section 10

Acceptable use

You will not, and will not help anyone else to:

  • use the Service for anything unlawful, or to process content you have no right to process;
  • access, or try to access, another account or its keys or data;
  • bypass or undermine authentication, rate limits, operation caps, billing, or the network path in front of the API;
  • probe or test the security of the Service beyond your own account, or interfere with it or place unreasonable load on it, including load testing without our written permission;
  • create multiple accounts to get more free keys or operations, or to avoid fees;
  • resell the Service, or offer it to others as a standalone encryption or key management service, without our written permission. Building your own products on the Service is fine;
  • reverse engineer the Service, except as the law permits. Reading the source of the command-line tools is fine;
  • publish or share API keys, including in public code; or
  • use the Service in breach of export control or sanctions laws (Section 19).

If you find a vulnerability, report it to support@rypt.dev, as the security page describes, and keep any testing within your own account.

Section 11

Your content

Your content is what you send to the API, meaning plaintext, ciphertext, data keys and aad, and the names you give keys and API keys. You own it. You give us the rights we need to process it in order to provide the Service.

How we treat it. We process your content only to provide the Service to you, following the instructions you give through the API, and for no other purpose. We do not sell or share it, use it for advertising, or combine it with other data. Only people at x6c who operate the Service can reach the systems that process it, and they are bound to keep it confidential. The providers named in the privacy policy process it for us. We will tell you if we can no longer meet these commitments, and you may then stop using the Service.

What is stored. The Service does not store your plaintext, ciphertext, aad, or the data keys you send to wrap or unwrap, in its database; the privacy policy and security page describe what is recorded. Key and API key names, and the value of any x-request-id header you send, are stored, so do not put sensitive information in them.

Your responsibilities. You are responsible for your content, for having the right to send it, and for any notice or consent your own users need. We do not offer the agreements that some laws and card-network rules require before regulated health data or payment card data can be processed, so do not send us such data where one is required.

Security incidents and legal demands. If we learn that someone without authorization has accessed your content, your API keys or your account's records, we will tell you without undue delay. Because rypt holds the keys, a lawful demand could require us to decrypt ciphertext under your keys, or to disclose your account's records. Unless the law or a court order forbids it, or there is an emergency, we will tell you before we comply, and we will do only what the demand requires.

Feedback. If you send us feedback or suggestions, we may use them without any obligation to you.

Section 12

Our software and rights

We and our licensors own the Service, including its software, documentation, design and the rypt name and mark. Subject to these terms, we give you a limited, non-exclusive, non-transferable and revocable right to use the Service, and to install and run the command-line tools we distribute, only to access the Service. If a tool or file comes with its own licence, that licence governs it. The fonts on our websites are licensed under the SIL Open Font License.

Section 13

Third-party services

The Service relies on third parties, including Cloudflare, Google Cloud, Auth0 and Stripe. Stripe processes payments under its own terms, and signing in with Google is subject to Google's terms. We are not responsible for third-party services you choose to use alongside rypt.

Section 14

Changes, availability and support

  • Changes. We may change the Service, add or remove features, and change its limits. We will post price increases, and changes that reduce what a paid tier includes, at least 30 days before they apply to you, and email them as Section 22 describes.
  • The API. The API is versioned under /v1. We may make changes that are not backward compatible, and will try to give notice of them first.
  • No service level. There is no service level agreement. The Service runs in a single Google Cloud region, and it may be unavailable, slow or interrupted, including for maintenance, without notice.
  • Discontinuing the Service. If we decide to discontinue the Service, we will post notice on rypt.dev, and email it as Section 22 describes, at least 90 days before. Decrypt and unwrap will keep working during that period, within the limits that apply to your keys, so you can recover your data.
  • Support. Support is by email at support@rypt.dev, with no guaranteed response time.

Section 15

Suspension and termination

You can stop using the Service at any time. To close your account, cancel any subscription and email support@rypt.dev from the email address you sign in with. We will confirm by replying to that address before we act. There is no self-service closure yet.

We may suspend your access, in whole or in part, at once, if we reasonably believe your use breaches these terms, threatens the security or operation of the Service or of others, or exposes us to legal liability. We will tell you why by email, unless the law or a security concern prevents it. A suspension may mean revoking your API keys. A revoked API key cannot be restored, so when a suspension ends you will need to issue new ones. Non-payment is handled as Section 8 describes, and does not by itself stop decrypt or unwrap.

We may terminate your account for a material breach of these terms, for non-payment, or where the law requires it. We may also terminate it for any other reason with 90 days' notice.

When we end your account, we will tell you by email the date on which your sign-in and API keys stop working, at least 30 days ahead, unless the law forbids it or your account is being used to attack the Service or others. Decrypt what you need before that date. On that date we block your sign-in, revoke your API keys and delete your keys, after which nothing encrypted under them can be decrypted through the Service. Fees already incurred remain due, and we keep records as the privacy policy describes.

Anything in these terms that by its nature should continue after your account ends, or after these terms are replaced, does, including Sections 3 and 5 as to responsibility for the use of your credentials and for keeping your data decryptable, Sections 7 and 8 as to amounts owed, this Section 15, and Sections 11, 12 and 16 to 23.

Section 16

Disclaimers

Except for the commitments these terms state expressly, the Service is provided "as is" and "as available". To the fullest extent the law allows, x6c disclaims all other warranties, express or implied, including warranties of merchantability, fitness for a particular purpose, title and non-infringement, and any warranty that the Service will be uninterrupted, secure or error-free, or that data will not be lost or become undecryptable.

There is no compliance guarantee: using rypt does not by itself satisfy any law, regulation or certification. The audit log is evidence, and auditors draw the conclusions. You are responsible for deciding whether the Service fits your needs, and for keeping what you need to recover your data.

Section 17

Limitation of liability

To the fullest extent the law allows, x6c is not liable for any indirect, incidental, special, consequential, exemplary or punitive damages, or for lost profits, revenue, goodwill or data, including data that cannot be decrypted because key material was destroyed, even if x6c was told they were possible.

To the fullest extent the law allows, x6c's total liability for all claims arising out of or relating to the Service or these terms is limited to the greater of the fees you paid x6c for the Service in the 12 months before the event giving rise to the claim, and one hundred US dollars.

These limits apply to every theory of liability, and even if a remedy fails of its essential purpose. Some jurisdictions do not allow some of these limits, and there they apply as far as the law allows.

Section 18

Indemnity

You will defend and indemnify x6c and its members, managers, employees and agents against any third-party claim, and the resulting losses, damages and reasonable costs including legal fees, arising from your content, your use of the Service in breach of these terms, or your violation of any law or of anyone else's rights.

Section 19

Export controls and sanctions

The Service uses encryption, and the Service and the command-line tools are subject to United States export control and sanctions laws, including the Export Administration Regulations and the sanctions administered by the Office of Foreign Assets Control. You confirm that you are not located in, or ordinarily resident in, a country or region subject to comprehensive United States sanctions, and that you are not on, or owned or controlled by anyone on, a United States restricted-party list. You will not use, export or re-export the Service or the tools in breach of those laws.

Section 20

Governing law and disputes

These terms are governed by the laws of the State of West Virginia and applicable United States federal law, without regard to conflict-of-laws rules. The United Nations Convention on Contracts for the International Sale of Goods does not apply.

Before filing a claim, you agree to email us a description of it and give us 30 days to try to resolve it. Any dispute arising out of or relating to these terms or the Service will be brought only in the state or federal courts located in West Virginia, and you and x6c consent to their jurisdiction. Either party may seek an injunction in any competent court to protect its intellectual property or the security of the Service.

If you are a consumer, nothing in these terms takes away rights you have under the mandatory laws of the place where you live.

Section 21

Changes to these terms

We may change these terms. We will post the new version on this page with a new effective date. If a change is material, we will post it, and email it as Section 22 describes, at least 30 days before it takes effect. A change does not apply to a dispute that arose before it. If you keep using the Service after a change takes effect, you accept it. If you do not accept it, stop using the Service and cancel your subscription before it takes effect; usage before then is billed under the terms that applied to it.

Section 22

Notices

We send notices by email to the address you sign in with, which Auth0 holds for us, and, if you have set up billing, to the billing email on your Stripe record. We email, and also post on rypt.dev, any notice of a material change to these terms, a price increase or a reduction in what a paid tier includes, a change to or the end of the free tier, setting up billing again, the suspension or termination of your account, or discontinuing the Service. Other notices may be given by posting them on rypt.dev. Keep your sign-in and billing email addresses current. You give us notices by email to support@rypt.dev.

Electronic records. You agree that we may provide these terms, notices, invoices, receipts and other records electronically, by email or by posting them as this section describes, and that they satisfy any requirement that they be in writing. To read them you need a web browser and an email account. You can ask for a paper copy of any record at no charge, or withdraw this consent, by email to support@rypt.dev. Because the Service is offered only electronically, withdrawing consent means we may close your account under Section 15.

Section 23

General

  • Entire agreement. These terms, including the pricing on rypt.dev, are the whole agreement between you and x6c about the Service, and replace any earlier understanding.
  • Order of precedence. If these terms conflict with anything else we publish or show you, including the pricing, the privacy policy, the security page, the dashboard, sh.rypt.dev, the API's responses, and the text on Stripe's pages and invoices, these terms control. Statements elsewhere do not add to our obligations unless these terms adopt them.
  • Assignment. You may not assign these terms without our written consent. We may assign them as part of a merger, acquisition, or sale of all or most of our assets or of rypt.
  • Severability and waiver. If any part of these terms is found unenforceable, the rest stays in effect. Not enforcing a term is not a waiver of it.
  • Events beyond control. Neither party is liable for a delay or failure caused by events beyond its reasonable control, except for obligations to pay.
  • Relationship. We are independent contractors. These terms create no partnership, agency or employment, and no rights for anyone else.

Section 24

Contact

x6c LLC, at support@rypt.dev.