Terms of service
The short version
- No mining
- No cryptocurrency mining, proof-of-work, or any workload whose product is the compute it burns.
- No spam
- No bulk unsolicited email or messaging, and no posting, form, or comment spam.
- No abusing other services
- No credential stuffing, bulk account creation, or scraping that breaks another site's terms.
- No attacks
- No denial of service, intrusion, malware, phishing, or botnet command and control.
This summary is a shortcut, not the agreement. Section 3 is the full list.
1. The agreement
mrin provides on-demand sandboxes — isolated microVMs built for AI agents — and the services around them: snapshots, forking, replay, suspend and hibernate, networking, the API, the CLI, and this site (together, the “Service”). These terms are an agreement between you and mrin (“we”, “us”), and they apply whenever you use the Service.
You accept them by creating an account, by clicking to accept them, or by using the Service. If you do not accept them, do not use the Service.
If you accept on behalf of a company or other organization, you are confirming that you may bind it, and “you” means that organization.
You must be at least 18, or the age of majority where you live. You must not be located in, or acting on behalf of anyone in, a country or on a list that export control or sanctions law bars us from serving.
2. Your account and your agents
- Give accurate account and billing information, and keep it current.
- You are responsible for everything that happens under your account: every sandbox it runs, every API key it issues, and everything your teammates do with it.
- That includes your agents. A workload an agent starts with your credentials is your workload, whether or not a human reviewed it first. Build the guardrails your agents need; “the agent did it on its own” does not move responsibility off your account.
- Keep passwords, API keys, and identity tokens secret. Anything done with your credentials counts as done by you.
- Tell us at amit@mrin.ai as soon as you suspect an account, key, or sandbox has been compromised.
- Free allowances are per person and per organization. Opening extra accounts to multiply a free allowance, to get around a limit, or to come back after a suspension breaks these terms, and is grounds for closing every account involved.
- We may require a payment card, a verified email address, or other verification before an account can use the Service, and we may decline to open an account.
3. Acceptable use
A sandbox is a general-purpose computer, and most of what you would do with a computer is fine here. This section is the list of things that are not. Breaking any of it can stop your sandboxes and close your account — and it applies equally whether a human or an agent is at the keyboard.
Mining and compute-for-its-own-sake
- No cryptocurrency mining or minting of any kind — proof-of-work, proof-of-space, solo or pooled, in the foreground or buried inside another workload.
- No validators, sequencers, plotting, or similar workloads run for token rewards rather than for what they compute, unless we have agreed to it in writing.
- No “passive income”, bandwidth-sharing, proxy-selling, ad-viewing, or reward-farming networks that rent out your sandbox's capacity or its IP address to third parties.
- No benchmarking or stress-testing services offered to others, and no reselling raw mrin compute, unless your agreement with us says otherwise.
This is the rule we enforce most bluntly. Mining workloads are stopped as soon as we see them, the account is suspended without notice, and the usage they ran up is still owed.
Email, messaging, and spam
- No bulk unsolicited email, and no mail to a list you did not collect with consent.
- No open relays, no mail infrastructure used to launder someone else's mail, and no spoofed or forged senders.
- No bulk SMS, direct messages, comments, reviews, posts, or form submissions that the recipient service and its users did not ask for.
- No evading a service's spam filters, sender-reputation systems, or rate limits.
We may restrict outbound mail from sandboxes, and may ask what you intend to send before lifting that restriction.
Other people's services
- Do not use the Service to access anything in a way that breaks that service's terms of use, its robots directives, or a technical limit it put in your way.
- No credential stuffing, password spraying, or signing in to accounts that are not yours.
- No bulk account creation on other platforms, and no automating signups, votes, views, follows, or engagement.
- No purchase bots or scalping, no CAPTCHA-solving-for-evasion, and no other automation whose purpose is to defeat a control someone else put in place.
- No scraping personal data, and no scraping at a volume that degrades the service you are scraping.
Agents automating the web is what this platform is for. Automation aimed at a control someone else put in place is not.
Attacks, intrusion, and malware
- No denial-of-service traffic, amplification, or “stress testing” aimed at anyone.
- No scanning, probing, or exploiting systems you do not own and are not authorized in writing to test.
- No writing, hosting, or distributing malware, ransomware, exploit kits, or credential harvesters, and no botnet or malware command and control.
- No phishing pages, fake sign-in pages, or infrastructure that impersonates another business.
- No hosting stolen data or cracked credentials, and no tooling for trading in them.
Security testing against systems you own or are authorized to test is fine. Testing against mrin's own infrastructure needs our written permission first. Vulnerability reports are welcome at amit@mrin.ai.
Fraud and deception
- No card testing, carding, or use of any payment instrument you are not authorized to use — against us or against anyone else.
- No identity fraud, forged documents, or impersonating a person or organization.
- No fake reviews, engagement-for-hire, click fraud, or the services that supply them.
Networking
- No public anonymizing proxies, VPN exits, or Tor exit nodes, and no relays used to launder abusive traffic.
- No spoofing IP or MAC addresses or DNS responses, and no injecting traffic or routes into networks that are not yours — including our networks and other tenants'.
- No port scanning, flooding, or otherwise interfering with the networks your sandbox shares.
Illegal and harmful content
- Nothing illegal where you are or where we operate.
- No child sexual abuse material. We report it to the authorities and terminate the account immediately.
- Nothing that infringes someone else's copyright, trademark, or other rights.
- No harassment, threats, doxxing, or material inciting violence.
Our platform and the tenants next to you
- Do not attempt to escape sandbox isolation, reach the host, or read data belonging to another account.
- Do not interfere with metering, quotas, billing, or abuse detection, and do not falsify usage.
- Do not work around rate limits and quotas — ask us to raise them instead.
- Do not reverse engineer the Service in order to build a competing one.
4. Alpha status
The Service is in private alpha. Access is by invitation, capacity is deliberately limited, and features — including forking, replay, suspend, and hibernate — can change, misbehave, or disappear while we build. Published rates are indicative; the rates that bind you are the ones in your agreement with us or in the dashboard for your account. Do not run anything on the alpha whose loss you cannot absorb.
5. Usage and payment
- The Service is metered. You pay for what your account uses — vCPU time, memory time, storage, hibernated state, data transfer, and any other metered resource — plus any plan fee, at the rates that apply to your account.
- Metered resources accrue while they are allocated, not only while they are busy: a running sandbox is billed for the vCPU and memory it holds, and disks and snapshots are billed while they exist. A suspended or hibernated sandbox is billed at the cold-tier storage rate for the state it keeps, not at compute rates — hibernating or deleting is what shrinks or stops the meter.
- Usage above an included allowance is billed at your account's rates. Unused allowance does not roll over.
- We may require a valid payment card before an account can run workloads, and may place small verification charges on it.
- Amounts are due when invoiced and are charged to the payment method on file. If a charge fails we may retry it, suspend the account, and stop or delete its resources.
- Prices, plans, and allowances can change. We give notice before a change takes effect for an existing paid account, and it applies from your next billing period.
- Taxes are on top of published prices unless we say otherwise.
- Refunds are at our discretion. Disputing a charge you owe instead of writing to amit@mrin.ai is grounds for termination.
6. Limits, capacity, and durability
- Accounts have limits: concurrent sandboxes, vCPU, memory, storage, snapshots, hibernated state, and rate limits on the API. We may change them, and may lower them for an account that looks like abuse.
- We may throttle, pause, stop, or decline to allocate resources to protect the platform, our other customers, or capacity. This includes moving your sandboxes between hosts and restarting them for maintenance.
- Nothing here is a backup service. Snapshots, forks, and sandbox disks live on infrastructure that can fail, and a sandbox can be restarted or replaced. Keep your own copies of anything you cannot lose.
- Free-tier resources may be reclaimed after a period of inactivity.
7. Your content and your data
- What you run and store stays yours. You grant us only the license we need to run the Service for you: to store, transmit, and execute your content on your instruction, and to copy it — including into snapshots and forks — for reliability and to provide the features you invoke.
- You are responsible for having the rights to everything you run, and for the laws that apply to the data you put on our systems.
- We do not look inside your sandboxes except where we need to in order to operate the Service, to comply with the law, or to investigate a specific abuse or security report. Abuse enforcement runs on operational signals — resource usage, network metadata, and process-level indicators — not on reading your files.
- We keep operational data (usage records for billing, network metadata, logs, and security signals) for as long as we need it for billing, security, and legal obligations.
- We disclose customer data to authorities only where legally required, and we tell you when we are permitted to.
8. Enforcement
We look for abuse automatically and by hand. When we act, we try to do the smallest thing that stops the problem: throttling an account, pausing or stopping a sandbox, blocking an address, and — where that is not enough — suspending the account.
- Mining, attacks, fraud, and child sexual abuse material are stopped immediately and without notice.
- For everything else we try to reach you first. Either way you can appeal at amit@mrin.ai, and we will tell you what we saw.
- A suspended account keeps its data during the suspension. If the suspension becomes a termination, the data is deleted after the grace period in the next section.
- Usage incurred before a suspension is still owed, including usage from the workload that caused it.
9. Availability and changes to the Service
- The Service is provided on an as-available basis. We do not promise a level of uptime unless you have a written agreement with us that says we do.
- We may add, change, or remove features. Anything marked alpha, beta, or preview can change or disappear without notice.
- Planned maintenance and incident response can restart your sandboxes.
10. Ending the agreement
- You can stop using the Service and delete your account at any time. Deletion starts a grace period, after which your sandboxes, snapshots, and account data are permanently deleted and cannot be recovered. Amounts already owed remain due.
- We can suspend or terminate an account for breaking these terms, for non-payment, or where the law requires it. We can also terminate for convenience with reasonable notice, refunding prepaid amounts you have not used.
- The parts of these terms that should outlive the agreement do: amounts owed, content ownership, disclaimers, limits of liability, and indemnity.
11. Changes to these terms
We update these terms as the Service changes. The effective date at the top of this page says which text is current.
For material changes we give notice in the dashboard or by email before they take effect. Continuing to use the Service after that means you accept the new version; if you do not, stop using the Service and close your account.
12. Warranty disclaimer
The Service is provided “as is” and “as available”, without warranties of any kind, express or implied, including merchantability, fitness for a particular purpose, and non-infringement. We do not warrant that the Service will be uninterrupted or error-free, or that data stored on it will not be lost.
The Service is not designed for uses where failure could lead to death, personal injury, or severe environmental damage — life support, aircraft navigation, nuclear facilities, weapons systems. Do not use it for those.
13. Limitation of liability
- To the fullest extent the law allows, neither party is liable for indirect, incidental, special, consequential, or punitive damages, or for lost profits, revenue, goodwill, or data.
- Our total liability arising out of or relating to the Service is limited to the amounts you paid us for the Service in the twelve months before the event that gave rise to the claim.
- These limits do not apply to your obligation to pay for the Service, or to any liability that cannot be limited by law.
14. Indemnity
You will defend us against, and cover, third-party claims arising from your use of the Service, from your content, from what your agents do with it, or from your breach of these terms — including claims by a service you attacked, scraped, or spammed from our infrastructure.
15. Everything else
- These terms, together with any written agreement we have signed with you, are the entire agreement between us. A signed agreement wins where the two conflict.
- You may not assign these terms without our consent. We may assign them to a successor to our business.
- If any provision is unenforceable, the rest stays in force.
- Not enforcing a right on one occasion does not waive it.
- Notices to you go to the email address on your account. Notices to us go to amit@mrin.ai.
16. Contact
Questions about these terms, appeals against a suspension, abuse reports, and security reports all go to amit@mrin.ai.
Include your account ID when you write about your own account. When you are reporting abuse coming from ours, include the address involved and timestamps with a time zone — that is what lets us find the sandbox.