01The short version
The full agreement is below. This is the shape of it:
- Redeep is free, and yours to use for real work. Personal or commercial, on as
many Macs as you own or control. There is no seat count and nothing to activate.
- You bring the intelligence. We ship no models and resell no tokens. The
provider whose key you saved bills you directly, and what your agents spend is yours
to watch.
- Your agents act as you. They run on your machine, with the permissions you
grant, against the accounts you connect. What they do is your responsibility —
review it before it ships.
- We hold nothing of yours. No account, no upload, no server of ours in the
path. The privacy policy spells that out.
- It comes as is. Free software, no warranty, and a hard cap on what we could
ever owe you. Everything below is the long form of these five lines.
02Who this is between
Slideform, Inc. ("we," "us") publishes Redeep and operates
redeep.app. You are the person or organization
using them. Downloading, installing, or using Redeep means you accept these terms; if
you don't accept them, don't use the app, and delete any copy you have.
These terms cover the macOS app, this website, the update feed the app checks, and the
documentation and skills we ship alongside it. Our privacy policy
is part of this agreement.
You must be at least 16 years old to use Redeep. If you are accepting on behalf of a
company or other organization, you confirm you are authorized to bind it, and "you"
means that organization.
03Your license to use Redeep
Redeep is provided free of charge. We grant you a personal, non-exclusive,
non-transferable, revocable license to install and run it on Macs you own or control,
for your own work or your employer's — commercial use included, with no separate
license to buy.
What that license does not cover:
- Selling, renting, sublicensing, or redistributing Redeep, on its own or bundled into
something else.
- Reverse-engineering, decompiling, or disassembling the app, except to the extent law
expressly permits despite this restriction.
- Removing or altering copyright, trademark, or other proprietary notices.
- Circumventing the security boundaries in the app to reach data or systems you would
not otherwise be allowed to reach.
Redeep is not open-source software, and we keep every right we haven't granted here.
It does include third-party open-source components, each under its own license; where
one of those licenses says something different about its own component, that license
wins for that component.
If we introduce paid features later, they will arrive with their own terms. They will
not retroactively change the license for the free app you already have.
04What Redeep is, and isn't
Redeep is a desktop application — a client, not a cloud service. It coordinates
things that are already yours: your files, your models, your tools, your accounts.
- We run no inference. There is no Redeep model. Every cloud request goes from
your Mac to the provider whose key you supplied; open-weight models run on your own
hardware.
- We host nothing. There is no account to create and no project of yours stored
with us. Deployments are served from your Mac, not from ours.
- There is no service for us to suspend, and so no uptime for us to promise.
Whether Redeep works tomorrow depends on your Mac, your keys, and the third parties
you point it at.
What we do operate is small: this website, the download, and the update feed the app
checks for new versions.
05Your keys, your bills
You supply the credentials, and they stay in your macOS Keychain. We never receive
them, which also means we cannot meter, cap, or revoke them for you.
Your provider bills you. Every token an agent spends is charged by that provider
on your account, under their pricing and their terms — whether you started the run
by hand or a board or schedule started it for you. The same is true of connected
services that charge for use.
Autonomous work can get expensive. A long run, a large repository, or a loop can
consume far more than you expected. Redeep shows a running cost ledger and lets you stop
work at any point, but those figures are our best estimate from what providers report
— they are not a bill, and they can be wrong. If cost matters to you, set a
spending limit with your provider, where the limit is actually enforced.
We are not responsible for provider charges, rate limits, outages, model deprecations,
or account suspensions. Those are between you and them. Handing work to your own Codex
or Claude Code CLI likewise runs on your account and your billing, and Redeep never puts
your API keys into those tools.
06Services you connect
Redeep becomes useful when you point it at things you already have: model providers,
Google Workspace, Slack, cloud consoles, databases, HTTP APIs, MCP servers, a browser.
Each connection is your decision, and each carries a few obligations with it.
- You are allowed to connect them. The accounts are yours, or you have
permission to use them, and using them through Redeep doesn't breach their terms or
your employer's policy.
- Each service governs its own data under its own agreement and privacy policy.
We are not a party to those exchanges and receive no copy of them.
- Google Workspace data reached through Redeep is used only to carry out the
task you asked for in the app, in line with the Limited Use requirements of the Google
API Services User Data Policy. The Google Workspace page has
the permission-by-permission detail.
- MCP servers and skills you install are third-party code that runs on your
machine with the access you give it. Treat one the way you'd treat any other program
you install: know where it came from.
07What your agents do
Redeep gives agents real capability. They read and write files, run shell commands and
code, query databases, browse the web, drive your screen when you allow it, call the
APIs you've connected, and open pull requests.
Everything they do, they do as you — on your machine, with your
credentials. To every system they touch, the actor is you, and that is how these terms
treat it too. You are responsible for the actions your agents take and for the
consequences, including work you set running and walked away from.
Redeep's guardrails are real, and they are not a guarantee. Shell and code execution
run inside a macOS Seatbelt sandbox confined to the session's workspace; agents work in
separate git worktrees; destructive and sensitive actions stop for your approval; tools
and connections carry allowlists. All of that is defense in depth. You can widen it, and
a determined instruction can still do damage inside the room you've opened.
So the working habits matter more than the guardrails: keep backups and use
version control, read the approval prompts instead of clicking through them,
review agent work before you merge, send, publish, or deploy it, and don't aim an
unattended run at a production system you can't afford to have changed.
If you turn on computer use, an agent clicks and types on your Mac exactly as you would
— including in applications that are not Redeep, and including anything already
signed in there. Watch it while it works.
08Acceptable use
Use Redeep for real work. Don't use it for any of this:
- Anything unlawful, or that helps someone else do something unlawful.
- Reaching systems, accounts, or data you aren't authorized to reach — including
scanning, credential stuffing, or exploiting other people's infrastructure.
- Building or distributing malware or ransomware, or tooling whose purpose is to cause
damage or evade security controls.
- Scraping or automating a website against its terms, its robots directives, its rate
limits, or applicable law. An agent's browser is still your browser.
- Generating or distributing sexual content involving minors, non-consensual intimate
imagery, targeted harassment, or material that deceptively impersonates a real person
or organization.
- Bulk unsolicited messaging, spam, or fraud, including through connected mail or
chat.
- Infringing anyone's copyright, trademark, patent, or trade secrets, or violating
anyone's privacy or data-protection rights.
- Breaking the acceptable-use policy of a model provider or any other service you've
connected. Their rules apply to whatever you send through them.
- Presenting Redeep's output as vetted professional advice — legal, medical,
financial, or otherwise — without review by someone qualified to give it.
We can't monitor your machine, and we don't try to; there is no channel that would let
us. What we can do, if you break these rules, is stop supplying you the app and pursue
whatever remedies the law gives us.
09Your content & the output
Yours stays yours. Your prompts, files, repositories, notebooks, boards, and
everything agents produce from them belong to you. We claim no ownership and take no
license in them — we couldn't use them if we wanted to, because we never receive
them.
Model output isn't ours to grant. Whether you own what a model generates, and on
what terms you may use it commercially, is set by the provider whose model produced it.
If that matters for your work, read their terms.
Output is generated, not verified. Models get facts wrong, invent details, write
code with security bugs, and sometimes produce text close to someone else's. Treat what
an agent hands you as a draft from a fast, tireless, occasionally overconfident
colleague, and check it before you rely on it.
None of it is professional advice. Nothing Redeep produces is legal, medical,
financial, tax, or safety advice, and none of it substitutes for a qualified
professional.
10Sharing what you build
Deployments run on your Mac. There is no hosting account and no upload, and nothing is
reachable beyond your machine until you deliberately share it.
When you do share, you are the publisher and the host. You are responsible for
what is in it, for who you let in, for having the rights to what you're serving, and for
any law that applies to it. Access controls — secure links, allowlists — are
yours to manage, so revoke them when someone should no longer have access.
The traffic travels over the tunnel you chose (Tailscale, Cloudflare, or an SSH
forward), carried by that provider under their own terms rather than ours. And a share
stays up only while your Mac is awake and the tunnel is running.
11Updates & availability
- Updates. The app asks
redeep.app/appcast.xml whether a newer
version exists and can install it for you. You can turn that off in Settings;
if you do, keeping current — including with security fixes — is on
you.
- Change. Redeep is under active development. Features get added, changed, and
occasionally removed, and a change at a model provider or in macOS can break an
integration without warning.
- Experimental features. Anything marked beta or experimental is offered as is
even by the standards of this page. Expect rough edges, and don't build a critical
process on one.
- Ending distribution. We may stop publishing Redeep, this site, or the update
feed at any time. A copy you've already installed keeps running for as long as macOS
supports it — there's no license server to switch off.
- Requirements. macOS 14 or later on Apple Silicon. Some features need runtimes
you provide, such as Python, Node, or an agent CLI, and permissions you grant in
System Settings.
12Our name & your feedback
The Redeep name, the Redeep logo, the app's design, and the text and images on this
site are ours, protected by copyright and trademark law. Nothing here grants you a right
to use our name or logo, beyond the ordinary way anyone refers to a product they use
— writing about it, reviewing it, or saying what you built with it. Don't suggest
we sponsor or endorse you, and don't put our marks in your product name, logo, or
domain.
Feedback is a gift and we treat it as one. If you send us a bug report, an idea,
or a suggestion, we may use it freely — without confidentiality, attribution, or
payment — and you keep every right you already had in it. Please don't send us
anything confidential that you wouldn't want used that way.
13No warranty
Redeep is provided "as is" and "as available," without warranty of any kind. To
the fullest extent the law allows, we disclaim the implied warranties of
merchantability, fitness for a particular purpose, title, and non-infringement, along
with any warranty arising from a course of dealing or trade usage.
In particular, we do not warrant that Redeep will be uninterrupted, error-free, or
secure; that it will work with any particular model, provider, tool, or version of
macOS; or that agent output will be accurate, complete, original, or fit for what you
intend to do with it.
Some places don't allow exclusions like these. Where that is true, this section applies
as far as local law permits and no further, and you may have rights this page cannot
take away.
14Limits on liability
What an agent does on your machine can matter a great deal, and we have neither
visibility into it nor control over it. The limits below are the basis on which we give
the app away.
- We are not liable for indirect, incidental, special, consequential, exemplary, or
punitive damages, or for lost profits, lost revenue, lost or corrupted data, deleted
files, lost business, or the cost of substitute services — even if we were told
such damages were possible.
- Our total liability for all claims relating to Redeep is capped at the amount you
paid us for it in the twelve months before the claim. While Redeep is free, that
amount is zero.
- These limits apply across every theory of liability — contract, warranty,
negligence, strict liability, or anything else — and survive the failure of any
remedy's essential purpose.
- Nothing here excludes liability we are not permitted to exclude, such as for fraud
or fraudulent misrepresentation, or for death or personal injury caused by our
negligence.
You'll cover us for your misuse. If someone brings a claim against us because of
how you used Redeep — what you ran, what you connected, what you shared, or what
you did with the output — you agree to defend and indemnify us against that claim
and its reasonable costs. We will tell you about it promptly and let you take over the
defense of anything we ask you to cover.
15Ending these terms
You can end this agreement whenever you like by deleting Redeep. There is nothing to
cancel and no one to email.
We may end it if you materially breach these terms. In practice that means we stop
supplying you the app and its updates, and you must stop using it and delete your
copy.
Whatever ends it, these survive: the license restrictions, acceptable use, ownership,
no warranty, limits on liability and the indemnity, and governing law.
16Governing law & disputes
These terms are governed by the laws of the State of Delaware, without regard to
its conflict-of-laws rules. The United Nations Convention on Contracts for the
International Sale of Goods does not apply.
Any dispute goes to the state or federal courts located in Delaware, and you and we
each consent to their exclusive jurisdiction and venue. There is no arbitration
clause here and no class-action waiver — if we end up in a dispute, it goes to
a court.
If you are a consumer in a country whose law lets you bring proceedings where you live,
or gives you protections a contract can't waive, this section doesn't take those
away.
Before either of us files anything, please write to us. Almost everything turns out to
be a misunderstanding that an email settles faster than a lawyer.
17Changes & contact
These terms, together with the privacy policy, are the whole
agreement between you and us about Redeep, and they replace anything said before. If a
court finds one part unenforceable, the rest stays in force. Not enforcing something
once doesn't waive it later. You may not transfer this agreement; we may transfer it as
part of a merger, acquisition, or sale of the business.
When these terms change, we will update the date at the top of the page and say so
plainly on the site if the change is material. Continuing to use Redeep after an update
means the revised terms apply, and the version at
redeep.app/terms is always the current one.
Questions, notices, or anything a lawyer wrote:
For what we do and don't receive, read the privacy policy. For
how the sandbox, the worktrees, and the approval gate actually work, see the
privacy and security section of the docs.