Terms of Service

Last updated: 11 September 2026

These terms are the agreement between you and OKShip. They cover what the service does, what you are promising us when you point it at an application, what a verdict does and does not mean, and how billing works. Please read section 5 carefully: it is the one that matters most, because a run takes real actions on a real application.

1. Accepting these terms

You accept these terms by creating an account or by using OKShip. The sign-up page tells you so before you continue, and links both this page and the Privacy Policy. If you are agreeing on behalf of an organization, you are telling us you have the authority to bind it, and “you” in these terms means that organization.

2. Which documents govern

Three things can govern your use of OKShip, and this is the order:

  • These Terms of Service and the Privacy Policy are the agreement.
  • Where your plan, your subscription or an order you signed specifies a term differently, that term governs for that plan. It can be more generous or less generous than what these documents say.
  • Everything else on this website, including pricing pages and product descriptions, is a description rather than a term of the agreement.

The clearest example is retention. The Privacy Policy commits to deleting run files 90 days after the run and account data 90 days after closure. If your plan states a different period, longer or shorter, your plan is the one that applies to you. The same holds for any other term a plan states expressly.

3. You must be 18

You must be at least 18 years old to use OKShip. If you are not, do not create an account. We may close an account if we learn the holder is under 18.

4. Accounts and organizations

Some practical points about accounts:

  • Your account belongs to a person. Do not share your sign-in with anyone else.
  • An account sits inside an organization, and members have roles: owner, editor or viewer. Owners can invite people, change roles, connect integrations and manage billing.
  • You are responsible for what the people you invite do with the access you gave them.
  • API keys act on behalf of your organization. We show a key once, when we issue it, and store only a hash of it afterwards, so we cannot recover it for you. Treat a key as a password and revoke it if it leaks.
  • Keep your contact email current. It is how we send reports and how we tell you about changes.

5. Authorization to test

This is the section you must not skim. When you ask OKShip to run against an application, you are telling us all of the following, for every application and every credential involved:

  • You own the application, or you have permission from the person who does to have it tested by an automated browser.
  • You are authorized to use every credential you connect, and the account behind it is one you are entitled to sign in as.
  • You accept that a run performs real actions. The browser clicks buttons, types into fields, chooses options and navigates. It can submit forms, create records, change records, send messages your application sends, and trigger anything your application does in response to those actions.
  • You understand there is no read-only mode and no rehearsal. Every run is a real interaction with whatever address you gave us.
  • You accept the consequences of running against production. We ask whether an application is production and offer a safety flag, but neither of those changes what the browser is capable of doing to it. If you point us at production, you have chosen to.
  • You will not point OKShip at an application belonging to someone who has not agreed to this, whether to test it, probe it, scrape it or measure it.

We cannot verify any of this, and we do not try to. It rests on you. If you are not certain you are allowed to test something, do not run OKShip against it.

6. Acceptable use

You agree not to use OKShip to:

  • Access, test or interfere with any system you are not authorized to access.
  • Attack, overload, or attempt to bypass the protections of any system, ours or anyone else's.
  • Reach internal, private or metadata addresses, or use OKShip as a way to send requests you could not send yourself.
  • Break the law, infringe someone else's rights, or handle data you have no right to handle.
  • Circumvent plan limits, share one plan across organizations that should hold their own, or resell the service without our agreement.
  • Upload or generate material that is unlawful, or that we would be required to remove.
  • Reverse engineer the service, or use it to build a competing product from what you learn about how it works.

We may investigate suspected misuse and take the steps in section 12.

7. Your content, and our role as your processor

Your content stays yours. That includes the addresses and scenarios you enter, and everything a run produces about your application: screenshots, the page-health archive, the video, the certificate and the verdict text.

A screenshot of your application may contain personal data about your own users. For that data you are the controller and OKShip is your processor. We process it only to provide the service, only on your instructions, and not for our own purposes. We will keep it confidential, use the measures set out in the Privacy Policy, tell you without undue delay if we become aware of a breach affecting it, use subprocessors of the categories the Privacy Policy lists, help you respond to a request from one of your users, and delete or return it in line with the retention commitments in the Privacy Policy or your plan. If you require a separate data processing agreement, email privacy@okship.dev and we will provide one.

You give us only the permission we need to run the service: to store, process, transmit and display your content for the purpose of producing and delivering what you asked for. That permission ends when the content is deleted.

9. What a verdict, a video and a certificate are

OKShip produces a verdict for each scenario, a narrated video and a PDF we call a Certificate of Verification. Here is what each of them is:

  • A verdict is a machine-generated judgment. A large language model looks at a screenshot and a summary of the page and decides pass, fail or ambiguous. Like any such judgment it can be wrong in both directions: it can pass something broken and fail something that works.
  • A step marked as passing means only that our runner recognized one of a short list of after-effects: the page address changed, a new element or new text appeared, a new element appeared inside an embedded frame, or a network response arrived together with an on-screen message. It does not mean the right thing changed. Where something changed but our runner could not identify it reliably, the step is marked ambiguous rather than passing. And where the action itself failed, the step carries no result of its own: it inherits the verdict given to the whole scenario, so a step whose action failed can still read as passing.
  • The video is assembled from the screenshots the run captured, with a spoken sentence naming each scenario and its verdict. It is a record of what our browser saw, not a demonstration that your application is correct.
  • The certificate is a summary of one run at one moment. It is a record of what ran and what the model concluded.

And here is what none of them is:

  • None of these is a guarantee that your application works.
  • None is a certification, an accreditation or an approval, by us or by anybody else.
  • None is a security assessment, a penetration test, a vulnerability report or a compliance attestation of any kind, and none should be presented to a customer, auditor or regulator as though it were.
  • None is legal, accessibility or professional advice. The accessibility scan in the page-health archive is the output of an automated tool and does not establish conformance with any standard.
  • None replaces your own testing, review or judgment before you ship.

Decide for yourself what a run tells you. If a verdict matters to a decision, check it against the screenshots and the step record we give you alongside it.

10. Using your own AI provider key

You can supply your own AI provider key so that runs are billed to your account with that provider rather than to ours. If you do, your use is governed by that provider's own terms as well as these, you are responsible for the charges it incurs, and you are responsible for keeping the key valid. We check a stored key weekly and will tell you if it stops working. Some features require a key of your own before they can be switched on.

11. Plans, billing and refunds

OKShip is sold on plans. Prices, allowances and what each plan includes are on the pricing page; no price is stated here, so the pricing page is where to look.

  • A paid plan is a subscription. It renews automatically at the end of each period, monthly or annually as you chose, at the price then shown for that plan, until you cancel.
  • You can cancel at any time from your billing settings. Cancelling stops the next renewal.
  • If you cancel a subscription part-way through a period, we will refund the unused part of that period, prorated.
  • A one-off purchase of a single run is not refundable once the run has started. It is a single execution, and it consumes what it consumes.
  • Plan allowances are checked before a run is queued, not afterwards. A run that would exceed your allowance is refused rather than run and billed.
  • We may change prices. If we do, we will tell account owners before the change applies to them, and it will not apply until your next renewal.
  • Taxes are yours where they apply to you.
  • If a payment fails we may suspend paid features until it succeeds.

Checkout and subscription handling are performed by a payment processor. We never see or hold your card details.

12. Suspension and termination

Either of us can end this:

  • You can stop using OKShip at any time, and you can ask us to close your account by emailing privacy@okship.dev. We will delete your account data 90 days after closure, subject to section 2 and to records we are required to keep.
  • We can suspend or close an account, or refuse a run, if we believe these terms have been broken, if a run is harming a third party or our service, if payment fails, or if we are required to.
  • Where it is reasonable to do so, we will tell you first and give you a chance to put it right. Where a run is causing active harm, we may stop it immediately and explain afterwards.
  • We may withhold a run's artifacts from being sent or shared if we have reason to believe they are wrong. A run in that state still exists and you can still see it; what stops is delivery to anyone else.
  • Sections 7, 9, 13, 14, 15 and 16 continue to apply after this agreement ends.

13. Disclaimers

OKShip is provided as it is and as it is available. To the fullest extent the law allows, we make no warranties of any kind, express or implied, and we specifically disclaim the implied warranties of merchantability, fitness for a particular purpose, title and non-infringement. We do not warrant that the service will be uninterrupted, timely, secure or error-free, that any verdict will be accurate, that any defect will be found, or that a run will produce the same result twice. We are not responsible for a third-party service we depend on being unavailable, nor for what your own application does when our browser interacts with it. Where the law gives you rights that cannot be excluded, nothing here limits them.

14. Limitation of liability

To the fullest extent the law allows: neither party is liable for indirect, incidental, special, consequential or punitive damages, or for lost profits, lost revenue, lost data, or business interruption, even if told such damages were possible. Our total liability arising out of or relating to this agreement is limited to the greater of the amount you paid us in the twelve months before the claim arose, or one hundred United States dollars. This limit applies in aggregate across all claims and whatever the theory of liability. Nothing here excludes liability that cannot lawfully be excluded, including for fraud or for death or personal injury caused by negligence.

15. Indemnity

You will defend, indemnify and hold OKShip harmless against any claim, loss, damage, liability, cost or expense, including reasonable legal fees, arising from a run you asked for against an application you were not authorized to test; from your use of a credential you were not entitled to use; from what an application did in response to a run; from content you gave us or that a run captured; from a proof link or report link you shared; or from your breach of these terms or of the law. We will tell you promptly about any such claim and let you control its defense, provided any settlement releases us fully and admits nothing on our behalf.

16. Governing law

This agreement is governed by the laws of the State of Delaware, United States, without regard to its conflict-of-laws rules. The state and federal courts located in Delaware have exclusive jurisdiction, and both of us submit to them. Before filing anything, please email privacy@okship.dev and give us 30 days to resolve it with you; most disputes end there. If any part of this agreement is held unenforceable, the rest continues in force.

17. Changes to these terms

We may change these terms. If we do we will change the date at the top, and we will email account owners before a material change takes effect. Continuing to use OKShip after that date means you accept the new version. If you do not, cancel and stop using the service; section 11 covers what happens to a subscription you cancel part-way through a period.

18. Contact

Write to privacy@okship.dev about anything here, including a request for a data processing agreement. The Privacy Policy explains what we collect and how long we keep it, and forms part of this agreement.

Questions about this page? Email privacy@okship.dev.