tokendrift

Terms

Reproduced verbatim from TERMS.md in the TokenDrift repository. It is shown as written rather than reformatted, so that nothing on this page can drift from the document it quotes. Plain source.

# TokenDrift Terms of Use

> ### ⚠️ DRAFT — NOT LEGAL ADVICE, NOT YET IN FORCE
>
> This document was drafted by the operator of TokenDrift, who is not a lawyer.
> It has not been reviewed by counsel, it has not been filed or executed
> anywhere, and nothing in it constitutes legal advice to anyone — including to
> the operator. **It must be reviewed and revised by a qualified attorney before
> TokenDrift is published or offered to anyone.**
>
> Its value is that the operator has worked through the actual risk surface and
> written down honest commitments. Its wording has not been tested for
> enforceability and should not be assumed to be enforceable.
>
> Two markers appear throughout:
> - `TODO(counsel)` — a legal question that requires an attorney's judgement.
> - `TODO(operator)` — a fact or decision the operator must supply or verify
>   before publication. These are not legal questions.
>
> ### 🛑 Four open questions block publication outright
>
> Every `TODO` below must be resolved, but these four are not drafting polish —
> the document has no answer to them at all, and none has been invented:
>
> | # | Question | Where |
> |---|---|---|
> | 1 | **Governing law, forum and arbitration.** Nothing has been chosen. §16 is a blank with a note, not a clause. | §16 |
> | 2 | **What licence, if any, we grant over our own published dataset.** The selection, reconciliation and provenance layer is our work even where the underlying facts are not. Unresolved, and it constrains the resale restriction in §5. | §8, §5 |
> | 3 | ***Feist* is US law only.** The EU and UK have a *sui generis* database right with no *Feist* equivalent. Several of our sources are non-US. The legal footing stated in §8 does not travel. | §8 |
> | 4 | **robots.txt compliance is not ToS compliance.** Several vendors' terms restrict automated access regardless of robots. §9 describes what our crawler does; it does not establish that doing it is permitted. | §9 |
>
> These have been left open deliberately. **They need an attorney. Do not draft
> around them, soften them, or remove these markers.**
>
> **Draft version 0.2 — 2026-08-16.** Companion document:
> [DISCLAIMER.md](DISCLAIMER.md). Both must be reviewed together; the disclaimer
> circulates on its own and carries the same draft status.

---

## 0. Who we are, and what these terms cover

TokenDrift is operated by `[TokenDrift ___ LLC]`.

> `TODO(operator)`: insert the exact registered name of the LLC, its state of
> formation, and its registered address. Do not publish with a placeholder.
>
> `TODO(counsel)`: confirm that the entity named here is the correct
> contracting party, and that the entity — not the individual operator — is the
> party offering the Service. This is the whole point of having formed it.

In these terms, **"we"**, **"us"** and **"TokenDrift"** mean that entity;
**"you"** means anyone who uses the Service.

The **Service** means, together and separately: the TokenDrift website; the
TokenDrift JSON API; the TokenDrift MCP endpoint; and any dataset dump,
download, or feed we publish.

> `TODO(operator)`: **this has moved since the first draft and must be
> re-checked, not assumed.** All four surfaces now exist in the codebase and are
> tested — the static website, the JSON API, the MCP endpoint, and the JSON dump
> — together with the machinery to deploy the site to a public domain. Whether
> any of them is actually *offered to anyone* on the day these terms take effect
> is a fact only the operator can supply. Sections 5 and 6 are written to apply
> to each surface when and if it is offered, and must be re-read against what
> has actually shipped on that day. Do not publish these terms on the assumption
> that this note is still accurate.

These terms incorporate two other documents, which are part of the agreement:

- **[DISCLAIMER.md](DISCLAIMER.md)** — what the data does and does not promise.
- **[METHODOLOGY.md](METHODOLOGY.md)** — how the numbers are produced, what
  every published field means, and the standing list of known limits.

Where these terms and METHODOLOGY appear to conflict about how the data
behaves, **METHODOLOGY governs**. It is deliberately the more detailed and more
frequently updated document, and these terms do not restate its contents.

## 1. Acceptance

By using the Service you accept these terms. If you do not accept them, do not
use the Service.

> `TODO(counsel)`: assent mechanics. For a public website and an unauthenticated
> API, a browsewrap link is weak. If the API issues keys, consider requiring
> affirmative acceptance at key issuance, and advise whether the free tier can
> reasonably be bound at all.

## 2. What the Service is

TokenDrift publishes reconciled LLM API pricing data reconstructed from vendors'
own published rate cards and documentation, with per-value provenance.

It is a reference dataset. It is not a rate card, a quotation, an offer, a price
index, a benchmark within the meaning of any financial-benchmark regulation, or
financial, investment, procurement, or professional advice of any kind.

> `TODO(counsel)`: the phrase "benchmark" is used informally in METHODOLOGY §10,
> which cites the Dated Brent precedent as a cautionary tale about changing a
> methodology. Please confirm that publishing a versioned pricing methodology
> does not bring the Service within any benchmark-administration regime in the
> jurisdictions we intend to serve, and advise whether this sentence should be
> stronger, softer, or removed.

## 3. The data is provided as is

**All data published through the Service is provided "as is" and "as available",
without warranty of any kind, express or implied, including without limitation
any warranty of accuracy, completeness, currency, merchantability, fitness for a
particular purpose, or non-infringement.**

We do not warrant that any published value is correct, that it is current, that
it matches the vendor's price today, or that any part of the Service is free of
error.

This is not a formality. [DISCLAIMER.md](DISCLAIMER.md) §3 lists the specific,
documented ways the data is known to be imperfect, including values published
with `confirmed: false`, values seen by a single source, partial coverage by
design, and a standing table of known limits in METHODOLOGY §9. Read those
before relying on anything.

**The vendor's own page is always the authoritative source for that vendor's
prices.** We link it on every value. Where a TokenDrift value and the linked
vendor page disagree, the vendor page is correct.

## 4. Reliance, and the fields you are expected to check

You are responsible for your own decisions. If you use the Service to prepare a
budget, build a cost model, select a vendor, price an offering, or design a
system, that decision is yours, and you make it on your own judgement about a
dataset whose limits we publish.

Each published price carries `confirmed`, `verified_at`, `needs_review`,
`source`, `source_url`, `extractor`, `corroborating_sources` and
`dissenting_sources`. Those fields exist so that you can judge a number before
you rely on it, and their meanings are defined in METHODOLOGY §§2–4. **We do not
warrant a maximum age for any published value; `verified_at` is the field that
tells you, and METHODOLOGY §2 defines exactly what it means.**

If a number is load-bearing for you, open its `source_url` and check it against
the vendor.

## 5. Acceptable use of the Service, the API, and the MCP endpoint

When using the Service you must not:

- exceed any published rate limit, or evade one by rotating keys, addresses, or
  identities;
- use automated means to retrieve data at a volume or rate that degrades the
  Service for others, or that amounts to bulk mirroring, where a published dump
  is available instead;
- misrepresent TokenDrift data as a vendor's own statement of its prices, or as
  endorsed, verified or supplied by any vendor;
- strip, alter or suppress the provenance fields — `source`, `source_url`,
  `verified_at`, `confirmed` — when redistributing values, or present a value in
  a way that implies a confidence the fields do not support;
- present TokenDrift data as your own original research or as independently
  verified by you when it is not;
- use the Service to build or operate a service whose purpose is to resell
  TokenDrift data as a paid feed without our agreement;

> `TODO(counsel)`: this bullet is a commercial restriction, not a safety rule,
> and it sits awkwardly beside the intended openness of the dataset. It also
> interacts directly with the data licence question in §8. Advise whether to
> keep it, and if so how it squares with the licence we choose.

- use the Service in violation of any applicable law, or in any way that would
  put us in violation of a vendor's terms; or
- attempt to gain unauthorised access to any part of the Service or its
  infrastructure.

We may suspend or block access that breaches this section, and we may do so
without notice where the Service's availability is at risk.

## 6. Availability, rate limits, and changes

- **There is no service level agreement.** No uptime commitment, no latency
  commitment, no support commitment. The free tier in particular is offered on
  a best-effort basis and nothing more.
- **We may impose, publish, and change rate limits** on the API and the MCP
  endpoint at any time.
- **We may change, restrict, degrade, or withdraw** any part of the Service,
  including any endpoint, any field, any schema, and the Service in its
  entirety, at any time and without notice.
- **We do not warrant that any endpoint stays up,** that any URL remains stable,
  or that any response schema remains unchanged.
- Scheduled and unscheduled outages, data gaps, failed runs, and partial runs
  are expected operating conditions, not breaches of these terms.

> `TODO(counsel)`: if a paid tier is ever offered, this section cannot stand as
> written for paying customers. Flag the point at which a separate paid-tier
> agreement with actual commitments becomes necessary.

## 7. Corrections

Our correction policy is METHODOLOGY §9 and is not restated here. In summary: a
published **number** is never rewritten — a wrong value is superseded by a later
run rather than edited or deleted — and the archive of numbers is append-only.
Provenance metadata on already-published rows has been repaired, by numbered
migrations that are part of the public record and only ever to claim less than
before; METHODOLOGY §9 states that exception exactly and lists every instance.

Change events that move a number carry a published `cause` distinguishing a
vendor repricing from a change of our own, and the change feed can be filtered
on it. METHODOLOGY §9 states precisely what that label does and does not
establish, and discloses the limit that remains: **there is no push notification
of any kind.** A correction is labelled and queryable; it is never announced.
**If you cite a TokenDrift value in a context where a later correction would
matter, retain the dump you cited and re-check it.**

We do not undertake to notify you of a correction, and no term of this agreement
should be read as creating such an undertaking.

## 8. Where the data comes from, and what we republish

TokenDrift reconstructs pricing **facts** — numbers, units, currencies, model
identifiers, tiers, and effective dates — from vendors' own published pages, and
cites the exact page each fact was read from.

Facts are not subject to copyright protection. *Feist Publications, Inc. v.
Rural Telephone Service Co.*, 499 U.S. 340 (1991).

To be precise about the boundary, because this is the actual legal footing of
the product:

- **We do republish**: individual price values, the units and currencies they
  are quoted in, model identifiers and display names, tier and variant labels,
  effective dates stated by the source, context window and maximum output
  figures, and a URL pointing back to the page each came from.
- **We do not republish**: page text, prose, descriptions, tables reproduced as
  tables, page structure, layout, styling, images, logos, or any other
  expressive content from a vendor's page. Raw fetched bytes are retained
  internally as an audit record of what we read and are not published.

We store raw fetched bytes so that a published number remains auditable against
what the page actually said at the time. Those bytes are not redistributed.

> `TODO(counsel)`: four questions here.
>
> 1. Whether case citations belong in public-facing terms at all. This is
>    unusual drafting; the substance may sit better in a "data sourcing"
>    explainer with only the boundary statement kept in the terms.
> 2. *Feist* is US law. The EU and UK have a *sui generis* database right with no
>    *Feist* equivalent, which can protect a substantial investment in obtaining
>    and verifying a database's contents independently of copyright. Several of
>    our sources are non-US. This interacts directly with §16 (governing law).
> 3. Whether retaining raw fetched bytes internally, unpublished, as an audit
>    record raises any issue distinct from publishing the facts.
> 4. **What licence, if any, TokenDrift grants over its own published dataset.**
>    The selection, reconciliation and provenance layer is our work even where
>    the underlying facts are not. This is unresolved and blocks publication.

> `TODO(operator)`: choose the data licence, and make it consistent with the
> resale restriction in §5. These cannot be decided independently.

## 9. Crawling, and how a site operator can stop us

We collect data by fetching publicly served pages. Our crawler:

- **identifies itself honestly**, as
  `TokenDriftBot/0.1 (+https://tokendrift.ai/bot; pricing-data research)`,
  with a contact URL in the user-agent string;
- **respects robots.txt** in accordance with RFC 9309, and treats an
  **unreachable** robots.txt — 5xx, DNS failure, TLS failure, or timeout — as a
  **complete disallow**. Silence is not consent. Robots rules are re-checked for
  each host in a redirect chain;
- **rate-limits per domain**, waiting a fixed delay between requests to the same
  host, with a request timeout and a bounded number of retries on transient
  failures only;
- **never retries a robots denial**, and records it;
- **does not attempt to evade** access controls, paywalls, login walls, or bot
  detection. Some vendors publish prices only through client-side rendering; if
  we ever add a rendering fetch path to read such a page, that renderer will
  identify itself as `TokenDriftBot` and honour robots.txt on exactly the same
  terms as the fetcher above.

**If you operate a site and want us to stop**, any of these works:

1. **Disallow `TokenDriftBot` in your robots.txt.** We honour it automatically
   on the next run, with no action needed from you and no appeal from us.
2. **Email us** at the address in §17 and ask. We will remove the source from
   the registry. We do not require a reason and we will not argue.
3. **Ask us to remove already-published values** from your pages. Because the
   archive is append-only, historical observations are not deleted — but we will
   stop publishing current values from that source, and we will say so.

> `TODO(operator)`: `https://tokendrift.ai/bot` is advertised in the crawler's
> user-agent string and this section depends on it existing. It must be live
> before the first non-trivial crawl, and it must carry: what the bot does, the
> robots.txt directive that blocks it, and a monitored contact address.
>
> `TODO(counsel)`: robots.txt compliance is not the same thing as compliance
> with a site's terms of service, and several vendors' terms restrict automated
> access regardless of robots. Please advise on the exposure from fetching pages
> whose ToS purport to prohibit it, on whether a claim would sound in contract
> or otherwise, and on whether the removal route above is sufficient as a
> practical matter.

## 10. Trademarks and no affiliation

**TokenDrift is not affiliated with, endorsed by, sponsored by, certified by, or
authorised to speak for** OpenAI, Anthropic, Google, DeepSeek, xAI, Zhipu
(Z.ai), OpenRouter, Mistral, or any other vendor whose prices, models or names
appear in the Service. We have no agreement with any of them. Nothing published
through the Service is a statement by, or on behalf of, any vendor.

All product names, model names, company names, logos and trademarks are the
property of their respective owners. We use vendor and product names **only
descriptively, to identify whose prices are being reported** — the minimum use
necessary to say what a number is a price for, with no suggestion of sponsorship
or endorsement. This is the nominative use of a mark to refer to the thing the
mark names.

**Our practice, stated as a commitment:**

- **Text-only references to vendor names. No vendor logos anywhere** — not on
  the website, not in documentation, not in marketing material, not in social
  cards, not in favicons.
- No vendor name in the TokenDrift name, domain, logo, or product branding.
- No styling that imitates a vendor's brand, and no implication of a
  relationship.
- Vendor names in headings and tables identify a data source; they are not
  endorsements.

> `TODO(counsel)`: Mistral's terms restrict use of its name and logo without
> written approval. Mistral is currently a parked (unfetched) source, but is a
> likely future addition. Please advise whether the descriptive-use practice
> above is sufficient for Mistral specifically, whether written approval should
> be sought before adding it, and whether any other vendor in the registry
> imposes a comparable restriction. The no-logos rule above is our own policy
> and should be kept regardless of the answer.

## 11. Privacy

The pricing datasets contain **no personal data**. They are prices, model
identifiers, units, dates, and URLs read from public vendor documentation. We do
not collect personal data from the sources we read.

Using the Service is different from consuming the datasets. A website and an API
necessarily process request data — IP addresses, user-agent strings, requested
paths, timestamps, and, where issued, API keys and the account details behind
them. We log requests for operational purposes: rate limiting, abuse prevention,
debugging, and capacity planning.

> `TODO(operator)`: **a Privacy Policy is required and does not yet exist.** It
> must state, at minimum: what request data is logged; how long it is retained;
> what analytics, hosting, CDN and payment processors receive it; whether
> anything is shared or sold (the answer should be no); and how to contact us
> about it. This section is a placeholder and is not a privacy policy.
>
> `TODO(counsel)`: applicable privacy regimes depend on where we operate and who
> we serve. GDPR/UK GDPR (if EU/UK users are in contemplation), CCPA/CPRA (if
> the California thresholds are met), and any state-law equivalents all need
> assessment, together with the cookie/consent question if any analytics are
> used. Please advise on scope before the policy is drafted.

## 12. Disclaimer of warranties

To the maximum extent permitted by applicable law, the Service and all data
provided through it are provided **"as is"** and **"as available"** with all
faults, and we disclaim all warranties, express, implied and statutory,
including without limitation the implied warranties of merchantability, fitness
for a particular purpose, accuracy, quiet enjoyment, and non-infringement.

No advice or information, whether oral or written, obtained from us or through
the Service, creates any warranty not expressly stated in these terms.

> `TODO(counsel)`: some jurisdictions do not permit the exclusion of certain
> warranties, and consumer-protection regimes may override this section
> entirely. Please add the required savings language for the jurisdictions in
> scope, and confirm that a free service is treated as we assume it is.

## 13. Limitation of liability

To the maximum extent permitted by applicable law:

- **We are not liable for any indirect, incidental, special, consequential,
  exemplary or punitive damages**, or for any lost profits, lost revenue, lost
  savings, lost business opportunity, cost of substitute services, or loss or
  corruption of data, arising out of or relating to the Service or the data,
  whether in contract, tort (including negligence), strict liability or
  otherwise, and whether or not we were advised of the possibility.
- **In particular, and without limiting the above, we are not liable for any
  decision made in reliance on a published value** — including budgeting,
  forecasting, vendor selection, architecture, procurement, contracting or
  pricing decisions — or for any loss arising from a value that was wrong,
  stale, incomplete, unconfirmed, missing, or later corrected.
- **Our total aggregate liability** for all claims relating to the Service is
  limited to `[the greater of (a) the amount you paid us for the Service in the
  twelve months before the claim arose, and (b) US$100]`.

> `TODO(counsel)`: the cap above is a placeholder, and for a free service the
> first limb is zero. Please advise on the appropriate cap, on whether a
> nominal-consideration floor is worth stating, and on the carve-outs that
> cannot be excluded (fraud, wilful misconduct, death or personal injury, and
> any others required by the governing law once chosen). Please also advise
> whether a limitations-period clause is worth including.

## 14. Indemnity

You agree to indemnify and hold harmless TokenDrift, its members, officers and
contractors from any claim, demand, loss, liability or expense (including
reasonable legal fees) arising from:

- your use of the Service or of data obtained through it;
- your redistribution of any value obtained through the Service, including any
  representation you make about that value's accuracy, currency or provenance;
- your breach of these terms, including the acceptable use section; or
- your violation of any law or of any third party's rights in connection with
  your use of the Service.

> `TODO(counsel)`: an indemnity from anonymous free-tier users is of limited
> practical value and may read as overreach. Please advise whether to keep it in
> full, narrow it to redistribution and misrepresentation only, or drop it for
> the free tier and reserve it for any future paid or key-holding tier.

## 15. Changes to these terms

We may change these terms. The current version is always published at this
location with a version number and a date, and material changes will be noted in
a changelog at the foot of this document. Continuing to use the Service after a
change takes effect means you accept the changed terms.

Changes to how the data is produced are governed separately, by METHODOLOGY §10,
which commits — once third parties cite TokenDrift numbers — to announcing a
meaning-changing methodology change **before** it takes effect, with an
effective date and the old and new methodology stated side by side. That is a
stronger commitment than this section, it is deliberate, and nothing here
weakens it.

> `TODO(counsel)`: unilateral-amendment clauses are attacked routinely. Please
> advise on notice mechanics for a service with no user accounts, and on whether
> the METHODOLOGY §10 commitment creates an enforceable obligation we should be
> conscious of before third-party citation begins.

## 16. Governing law and disputes

> `TODO(counsel)`: **governing law, jurisdiction and venue are deliberately left
> blank.** No jurisdiction has been chosen, and the operator has not invented
> one. Please advise on:
>
> - the governing law and exclusive forum, taking into account the LLC's state
>   of formation and where the operator is resident;
> - whether an arbitration clause and class-action waiver are appropriate for a
>   free public data service, or whether they add more risk than they remove;
> - how the choice interacts with the *Feist* / EU database-right question in §8
>   and with the privacy regimes in §11;
> - whether the Service should be geo-restricted at launch to narrow the set of
>   regimes in scope.

Governing law: `[TBD — see TODO(counsel) above]`.
Forum: `[TBD — see TODO(counsel) above]`.

## 17. Contact

- **General and data corrections:** `[TODO(operator): monitored email address]`
- **Crawler questions and removal requests:** `[TODO(operator): address, and it
  should also appear at https://tokendrift.ai/bot]`
- **Legal notices:** `[TODO(operator): entity name and registered address]`

We would rather hear about a wrong number than not. Reports of suspected errors
are welcome and are acted on under METHODOLOGY §9.

## 18. General

- **Severability.** If any provision is held unenforceable, the rest remains in
  effect and the unenforceable provision is limited to the minimum extent
  necessary.
- **No waiver.** A failure to enforce any provision is not a waiver of it.
- **Entire agreement.** These terms, together with DISCLAIMER.md and
  METHODOLOGY.md, are the entire agreement between you and us about the Service.
- **Assignment.** You may not assign these terms. We may assign them to a
  successor to the business.
- **No third-party beneficiaries.** Nothing here gives any third party a right
  to enforce these terms.

> `TODO(counsel)`: review §18 as a set; these are conventional but should not be
> assumed correct for the governing law once chosen. Note the tension between
> "entire agreement" and §0's rule that METHODOLOGY governs on data behaviour
> while being independently and frequently revisable — please advise on how to
> reference a versioned external document without leaving the agreement open to
> unilateral rewriting.

---

## Open items index

Everything below must be resolved before publication.

### Requiring an attorney — `TODO(counsel)`

| § | Question |
|---|---|
| 0 | Correct contracting party; entity vs individual |
| 1 | Assent mechanics for a public site and unauthenticated API |
| 2 | Whether a published pricing methodology touches any benchmark-administration regime |
| 5 | Whether the resale restriction should survive, given the data licence |
| 6 | When a paid tier requires a separate agreement with real commitments |
| 8 | Case citations in public terms; EU/UK database right vs *Feist*; retention of raw bytes; **what licence we grant over our own dataset** |
| 9 | Vendor ToS restricting automated access, independent of robots.txt |
| 10 | Mistral's name/logo restriction specifically; any comparable vendor restriction |
| 11 | Which privacy regimes are in scope |
| 12 | Warranty-exclusion savings language per jurisdiction |
| 13 | Liability cap for a free service; non-excludable carve-outs; limitations period |
| 14 | Whether the indemnity should survive for free-tier users |
| 15 | Unilateral amendment and notice without user accounts |
| 16 | **Governing law, forum, arbitration — nothing has been chosen** |
| 18 | Boilerplate review; "entire agreement" vs a versioned external methodology |

### Requiring an operator decision or fact — `TODO(operator)`

| § | Item |
|---|---|
| 0 | LLC legal name, state of formation, registered address |
| 0 | Re-read §§5–6 against the surfaces that actually ship |
| 8 | Choose the data licence, consistently with §5 |
| 9 | Stand up `https://tokendrift.ai/bot` before the first non-trivial crawl |
| 11 | Write an actual Privacy Policy; this section is a placeholder |
| 17 | Monitored contact addresses |
| — | **Re-verify METHODOLOGY against shipping code, on publication day.** A standing item, because it has now drifted twice: first the treatment of `--use-cache` and `observed_at`, then §9's change-attribution disclosures, which still said the `cause` label was unpublished after it had shipped. These terms point at METHODOLOGY as governing on data behaviour (§0), so a stale claim there is a published falsehood carrying the weight of this agreement. Last re-verified for METHODOLOGY v1.2 (2026-08-16) against commit `eb5ef83`, 1,390 tests passing. |

---

## Changelog

| Version | Date | Change |
|---|---|---|
| 0.2 (draft) | 2026-08-16 | Re-synced against METHODOLOGY v1.2. **§7** corrected: it said a correction was not yet distinguishable from a vendor repricing in the change feed, which stopped being true when `cause` was published; the remaining limit is that there is no push notification. **§0** `TODO(operator)` corrected: the website, JSON API and MCP endpoint now exist and are tested, so the note that only the pipeline exists was stale. The four questions that block publication are now called out at the head of the document. Still not reviewed by counsel. Not in force. |
| 0.1 (draft) | 2026-08-15 | First draft. Not reviewed by counsel. Not in force. |