Terms of service
These terms are the agreement between you and the provider of Pikapod for the hosting of your Forgejo instance. They are written to be read once, understood, and not needed again.
1. Who we are
The provider's registered name and address are not published here yet. Until they are, this service is not being offered for sale, and the address below is the way to reach whoever is operating it.
Email: support@forgejo.dc-analytic.com
Full details, and the single point of contact for authorities and for customers, are in the Impressum.
2. What we provide
A dedicated instance of Forgejo, run for you: its own virtual machine, its own address, backups, and the tools to restore and export it yourself. Forgejo is free software published by the Forgejo project under the GNU General Public Licence, version 3 or later. We are not affiliated with that project; we host their software and give 2% of revenue back to it.
Your plan decides your allowances. At the time of writing: Solo is €12 per month for 3 users and 10 GiB of storage; Team is €24 per month for 10 users and 25 GiB of storage, and can serve your forge at a domain you own. The pricing page is authoritative on price and on what is included.
One allowance covers everything your instance stores: repositories, Git LFS objects, packages and container images, artifacts and logs from Forgejo Actions, attachments, and the database.
3. Your account
- You must be able to enter into a contract, and you must give accurate account and billing details and keep them current.
- You are responsible for what happens under your account, including what the people you give access to do with your forge. Turning on two-factor authentication is strongly advised: your account can export every repository you have.
- You receive Forgejo site administrator rights on your own instance. That includes the ability to run code inside it, which is why every instance has a machine of its own. You are responsible for how you use it.
- One account per legal person. Do not share credentials.
4. Payment
Subscriptions are monthly and renew automatically until cancelled. Payment is taken by our merchant of record, who is the seller for the transaction, calculates and remits any tax that applies to you, and issues your invoice. We never see your card details. The final amount, including tax, is shown before you confirm.
Cancel at any time, from the billing pages, effective at the end of the period you have paid for. We do not pro-rate a part-month on cancellation.
If a payment fails, your payment provider will retry it on their own schedule. If a subscription is still unpaid seven days after it was marked past due, the instances on it are suspended and stop serving. A successful payment inside those seven days changes nothing; a successful payment after suspension starts them again. Section 8 says what happens to your data meanwhile.
5. Getting your money back
Fourteen days, no argument. If Pikapod is not what you wanted, ask within 14 days of your first payment and we refund it in full, to the payment method you used, through our merchant of record. You do not have to say why.
Two limits on it, and they are the only two:
- It does not apply to an account we have terminated for breaching section 6. The money-back guarantee exists so that people can try the service without risk, not so that abuse can be run at our expense and refunded afterwards.
- Metered consumption may be deducted. Where a plan includes an allowance that is consumed rather than merely available — continuous integration minutes, for example, once managed runners are offered — what you used is deducted from a refund at the published rate. Nothing in the plans as sold today is metered in this way, so today a refund is the whole first payment.
If you are a consumer in the EU, you also have a statutory right to withdraw from a distance contract within 14 days. Because we start providing the service immediately — that is the point of a five-minute signup — you are asking us to begin performance during the withdrawal period, and if you then withdraw you may be charged in proportion to what has already been provided. Our money-back terms above are offered in addition to that right and are more generous than it; nothing here reduces any right you have by law.
6. Acceptable use
Shared infrastructure only works if nobody uses it to hurt anybody else. Do not use Pikapod to:
- Mine cryptocurrency, or otherwise consume compute for its own sake. This is not a grey area: instances are sized to host a forge.
- Send unsolicited bulk email, run a mailing list you have no consent for, or otherwise use the platform's mail path for anything but the notifications a forge sends to people who asked for them.
- Store or distribute unlawful content, or content you have no right to distribute. What is unlawful is decided by the law that applies to us and to you, not by our taste.
- Attack anyone: scanning, brute-forcing, denial of service, hosting phishing pages, distributing malware or credential dumps, or acting as command-and-control infrastructure.
- Attack us: circumventing quotas or isolation, attempting to reach another customer's instance or the platform's own systems, or testing any of the above without written agreement. Good-faith security research is welcome and has its own page, which is the written agreement.
- Resell the service as your own hosting product without agreeing that with us first. Hosting your own clients' code on your own instance is fine and expected.
We do not read your repositories to police this. What reaches us is the consequence — a complaint, an abuse report from an upstream provider, or a host that is suffering — and section 7 is what we do then.
7. Suspension and termination
We may suspend an instance for non-payment (section 4), for a breach of section 6, or where we are legally required to. Suspension stops the instance; it does not delete anything.
Except where content is manifestly illegal or somebody is in danger, we will tell you what the problem is and give you a chance to fix it before suspending. When we do suspend, you get a written statement of what we did, on what ground, and how to contest it. Contesting it is a reply to that email; we will look again and answer.
Repeated or deliberate breaches end the agreement. So does using the service to harm people. We may also end the agreement on 30 days' notice for our own reasons — if we do that, we refund the unused part of what you have paid.
Content on customer forges reported to us as illegal is handled through the process on the reporting page.
8. What happens to your data
When an instance is suspended — for non-payment, on cancellation, or because you asked us to delete it — your data and its backups are kept for 30 days from that suspension.
We email you 14 days, 7 days and 1 day before the deadline.
Throughout those 30 days you can export everything from the portal, and exports work on a suspended instance for exactly this reason. Restarting a subscription inside the window brings the instance back as it was.
After 30 days the instance's storage and all of its backups are permanently destroyed. The same 30 days appears in the data processing agreement, because there is one retention period and not two.
Your instance's name is then held out of circulation for a further 90 days before anyone else can be given it, so that old clone URLs and build configurations never quietly reach a stranger's forge.
9. Your content is yours
You keep every right in everything you put on your instance. You grant us only the permission we need to run the service for you: to store it, transmit it, back it up, restore it, and copy it into a temporary environment to prove that a backup restores. That permission exists for the duration of the agreement plus the retention window in section 8, and for nothing else.
We do not use your content to train anything, we do not analyse it, and we do not share it. What our staff can technically reach, and the limits on it, are described in the data processing agreement rather than glossed over here.
10. Availability and support
Our availability target, how it is measured, and our recovery objectives are on the service levels page. Support is by email, and we aim to reply within one business day on a best-effort basis.
Backups are ours to take and yours to rely on — but a backup is not an excuse, and you should keep your own copy of anything you cannot afford to lose. Every repository you have is a git repository, which means every clone of it is already a copy.
11. Changes to these terms
We will give you at least 30 days' notice by email of any change that materially affects you, and the date on this page always says when it last changed. If you do not accept a change, cancel before it takes effect and ask for a refund of anything you have paid for time you will not use.
12. Liability
We provide the service with reasonable skill and care. We are liable for death or personal injury caused by our negligence, for fraud, and for anything else the law does not permit us to exclude. Nothing in these terms limits those.
Beyond that, our total liability to you in any twelve-month period is limited to what you paid us in that period, and we are not liable for lost profits, lost business, or lost or corrupted data to the extent that a copy you could reasonably have kept would have prevented the loss.
You are responsible for what is done with your instance, and you will cover us for claims by third parties that arise from your use of it in breach of section 6.
13. Law and disputes
These terms are governed by the law of the country in which the provider is established, as published in the Impressum, and its courts have jurisdiction. If you are a consumer, the mandatory consumer-protection law of your own country of residence still applies to you and you can still bring a claim where you live.
Before either of us goes to court: email us. Almost everything is a misunderstanding that one honest reply fixes.