1. Who we are and what these Terms cover
These Terms of Use govern the Vibosome website, Vibosome Mailroom private beta, the retained Vibosome hosted-automation platform, its Agent API and MCP features where available, documentation, support, and related services. The service is operated by MB Nordhub, referred to as "Vibosome", "we", "us", or "our". The person or organization using a service is "you", "your", or the "Customer".
Vibosome Mailroom is an invite-only AI-assisted email workspace. It can connect an approved mailbox, search and read relevant mail, create editable drafts, organize messages, prepare exports, and stage guarded mailbox actions. The retained automation platform can host and run Customer-provided Node.js, Playwright, Puppeteer, and related automation projects. Each product has different limits, data flows, and availability, which are explained on its product and documentation pages.
By accepting an invitation, signing in, connecting a mailbox, importing a project, authorizing an agent, accepting a written pilot offer, or otherwise using a Vibosome service, you agree to these Terms. If you act for an organization, you confirm that you have authority to bind it. If you do not agree, do not use the service.
2. Private beta, accounts, and access
Mailroom is a private beta, not a generally available multi-tenant service. The current hosted deployment supports one invited owner and one active mailbox. It does not provide team invitations, tenant-separated storage, multiple simultaneous mailbox owners, high availability, or a service-level agreement. Do not add another user, concurrent worker, or production mailbox unless Vibosome has confirmed in writing that the architecture has been upgraded for that use.
Mailroom access uses Amazon Cognito through a protected sign-in flow. Public self-registration is disabled. An invitation may include a temporary password that must be replaced, and software-token multi-factor authentication is required. You must protect your password, authenticator seed and recovery material, session, mailbox password, API keys, agent tokens, and any connected accounts. Tell us promptly if you suspect compromise.
The automation platform may use other sign-in methods and can issue scoped agent tokens. You are responsible for every person or tool you authorize and for revoking or rotating access when it is no longer needed. You must not share access to bypass approval, audit, usage, billing, or security controls.
3. Connecting and using a mailbox
You may connect only a mailbox that you own or are authorized to administer and process. The hosted beta currently accepts the documented Hostinger IMAP and SMTP configuration over TLS. Generic compatible IMAP/SMTP support may exist in local builds, but it is not a promise that every provider will work in the hosted beta.
You are responsible for the mailbox address, credentials, provider terms, recipients, messages, attachments, signatures, retention rules, and the lawfulness of every email workflow. Use a dedicated or least-privilege mailbox where practical. Do not connect a mailbox containing regulated or unusually sensitive data without first agreeing appropriate legal and security arrangements with us.
Mailbox providers remain the source of truth. Folder names, UIDs, threading, delivery, spam filtering, quotas, provider outages, rate limits, recipient-server decisions, and user actions outside Mailroom can change or invalidate what the interface shows. Vibosome cannot guarantee delivery, inbox placement, complete synchronization, or preservation of provider data.
4. AI assistance, untrusted email, and human approval
Email content is untrusted data, not trusted instruction. Messages, attachments, signatures, and quoted text may contain misleading requests or prompt-injection attempts. Mailroom uses bounded tools and policy instructions, but AI output can still be incomplete, incorrect, outdated, or manipulated.
Compose and reply drafts remain editable and require explicit human review and approval. External or destructive actions, including sending, forwarding, moving, or deleting mail, are staged behind the product's approval controls when offered. An approval authorizes only the described action and does not mean that Vibosome has verified its legality, accuracy, recipients, attachments, financial terms, or business consequences. Do not approve an action you do not understand.
Mailroom may use a selected source message, a bounded and correlated view of prior Sent-mail context, your mailbox profile, and the text necessary to carry out a request. Historical Sent content is context, not proof that an old price, promise, policy, or status remains current. You must verify material facts before sending. Do not use Mailroom as an unsupervised sender, legal reviewer, payment approver, emergency system, or substitute for professional judgment.
5. Mailbox credentials, attachments, and security boundaries
Mailbox credentials are processed server-side to connect through IMAP and SMTP. In the current hosted beta, the active credential record is encrypted at rest. Credential values are not intentionally returned to the browser after connection and are not intentionally included in OpenAI prompts. Never paste credentials into a message, AI command, public prompt, screenshot, support note, or source repository.
Attachment metadata and guarded byte downloads can be shown when requested. Raw attachment bytes, mailbox credentials, full mailbox dumps, and signature-logo bytes are not intentionally sent to OpenAI by the current Mailroom AI workflow. An attachment can still be malicious or sensitive. A filename, media type, preview, or successful download is not a malware scan or proof that the file is safe.
No security control removes all risk. You remain responsible for endpoint security, mailbox-provider controls, credential rotation, recipient verification, safe attachment handling, and minimizing the data exposed to the service.
6. Retained automation platform
The retained automation platform can store selected project files and variables, install dependencies, run Customer code in disposable or containerized workspaces, schedule jobs, retain logs and outputs, explain failures, propose guarded fixes, and expose scoped agent actions. Feature availability depends on the account and deployment.
You own or control your project content and are responsible for its code, commands, schedules, data sources, legal permissions, API contracts, rate limits, outputs, and business effects. A technically successful run does not prove that its result is correct. Keep secrets in designated variable controls, avoid printing them to logs, and review outputs before relying on them.
You must not use the platform for malware, credential harvesting, spam, unauthorized scraping, denial of service, evading third-party controls, cryptomining, persistent unauthorized services, illegal surveillance, or high-risk systems such as emergency response, medical diagnosis, regulated trading, weapons, or critical infrastructure.
7. Customer content and permissions
You retain the rights you hold in mailbox content, drafts, project files, prompts, profiles, signatures, logs, outputs, and other Customer materials. You grant Vibosome the limited rights needed to receive, host, copy, secure, transform, transmit, execute, display, back up, troubleshoot, and delete those materials to provide the selected service.
You confirm that you have all rights, notices, consents, contracts, and lawful bases required for the data, people, mailboxes, recipients, websites, APIs, and systems involved. You must respect privacy, confidentiality, intellectual-property, anti-spam, employment, communications, provider, and sector-specific rules that apply to your use. Vibosome cannot create a lawful basis or third-party permission for you.
Do not provide more personal or confidential data than necessary. If you process data for a client or another controller, you are responsible for determining whether a data processing agreement, written instructions, transfer mechanism, or other safeguards are required before using the service.
8. Acceptable use
Use Vibosome only for lawful, authorized, and reasonable work. You must not impersonate another person, deceive recipients, distribute unlawful or infringing content, send unsolicited bulk email, harvest personal data or credentials, bypass provider restrictions, interfere with other users, probe private infrastructure, exploit vulnerabilities, or use AI output to cause fraud or harm.
You must not ask the service or its AI provider to reveal passwords, tokens, private keys, hidden prompts, another person's data, or security controls. You must not approve staged actions on the basis of fabricated or unverified instructions. We may limit, pause, or refuse a workflow that creates unusual security, privacy, legal, delivery, infrastructure, or cost risk.
9. Pilot pricing, billing, and limits
The public Mailroom amounts of €149 setup and €99 per month are proposed founding-pilot terms only. They are not a self-service checkout, automatic entitlement, or promise that every applicant will be accepted. A paid Mailroom pilot begins only after scope, mailbox eligibility, price, taxes, payment method, start date, and any special terms are confirmed in a written offer accepted by both sides. Unless the accepted offer says otherwise, there is no automatic renewal or charge merely because you submit a beta request.
The retained automation platform may continue to use Stripe checkout, subscriptions, invoices, and a customer billing portal for accounts where those features are available. Stripe, not Vibosome, processes full payment-card details. Plan limits, compute limits, run limits, storage limits, concurrency, log retention, and repair limits are part of that platform and can pause work when reached.
Prices may change before a written offer is accepted or for a later renewal. Taxes are excluded unless stated otherwise. Paid support, setup, repair, or pilot work is a reasonable-efforts service, not a guarantee of delivery, conversion, cost savings, inbox placement, error-free automation, or a particular business outcome.
10. Third-party services
Vibosome depends on third parties. The current Mailroom beta uses Amazon Web Services for hosting, storage, monitoring, backups, secrets infrastructure, and Cognito authentication; OpenAI for bounded AI processing; and the Customer's Hostinger mailbox service for IMAP/SMTP transport and source mailbox storage. The retained automation platform can also use Stripe, sign-in providers, WorkOS features when expressly enabled, package registries, browser downloads, and Customer-selected external services.
Third-party services have their own terms, privacy notices, security controls, locations, availability, pricing, and retention. We do not control them. A provider outage, policy change, model error, API change, security event, quota, spam decision, or account suspension can interrupt or change Vibosome. You are responsible for the accounts, licenses, contracts, and permissions for services you connect.
11. Availability, beta changes, and support
Mailroom is an early beta on a deliberately small, single-owner, single-host, single-Availability-Zone architecture. It is not highly available. Maintenance, deployments, host failure, mailbox-provider failure, OpenAI failure, cloud incidents, queue state, local storage problems, DNS, certificates, network faults, or security work can make it unavailable or lose in-progress work.
We may add, remove, rename, limit, suspend, or change beta functionality, AI models, provider support, approval gates, storage, retention, pricing, architecture, and eligibility. We may reset or stop a beta if necessary to protect people, data, infrastructure, or cost. Material paid-pilot commitments are only those in an accepted written offer.
No uptime, response-time, recovery-time, recovery-point, support-time, or feature-continuity service level applies unless separately agreed in writing.
12. Intellectual property and feedback
Vibosome's software, interface, brand, documentation, workflows, and non-Customer content belong to MB Nordhub or its licensors. These Terms give you a limited, revocable, non-exclusive right to use the service as permitted; they do not transfer our ownership.
You may not resell, copy, sublicense, frame, white-label, or operate Vibosome as a competing service without written permission. If you send feedback, feature ideas, or bug reports, you allow us to use them without restriction or payment. Do not include confidential information in general feedback unless we have agreed to receive it.
13. Suspension, termination, and deletion
You may stop using a beta or request closure through the published contact channel. Manual-pilot cancellation and refunds follow the accepted written offer. Automation-platform subscriptions, where still active, can be managed through the billing portal or support; cancellation timing and continued access follow the terms shown for that subscription.
We may suspend or terminate access for non-payment, misuse, unlawful content, security risk, compromised credentials, provider restrictions, excessive cost, breach of these Terms, or risk to another person or service. We may preserve records required for security, fraud prevention, billing, disputes, legal obligations, backups, or the rights of others.
Disconnecting a mailbox stops new Mailroom access through that connection but does not itself erase mail held by the mailbox provider. Account or application deletion also does not prove immediate deletion from backups or every third-party provider. See the Privacy Policy and contact us for the current deletion process.
14. Disclaimers and liability
To the maximum extent permitted by law, Vibosome and each beta are provided "as is" and "as available". We disclaim warranties of uninterrupted or error-free operation, fitness for a particular purpose, merchantability, non-infringement, data or AI accuracy, delivery, synchronization, preservation, security, compatibility, and business results.
To the maximum extent permitted by law, MB Nordhub and its owners, workers, contractors, and suppliers are not liable for indirect, incidental, special, consequential, exemplary, punitive, lost-profit, lost-revenue, lost-data, lost-goodwill, or replacement-service damages. This includes consequences of an incorrect draft, wrong recipient, approved action, provider failure, mailbox change, missed message, malicious content, automation output, exposed Customer credential, or reliance on AI.
To the maximum extent permitted by law, our aggregate liability relating to a service is limited to the amount paid to Vibosome for that service during the three months before the event giving rise to the claim, or €100 if you used only a free beta. Nothing excludes liability that applicable law does not allow us to exclude. Mandatory consumer rights remain unaffected.
15. Indemnity, changes, law, and contact
To the extent permitted by law, you agree to defend and indemnify MB Nordhub and its personnel against third-party claims and reasonable costs arising from your mailbox, recipients, content, code, data, approvals, illegal or unauthorized use, infringement, or breach of these Terms. You may not settle a claim in a way that imposes an obligation or admission on us without written consent.
We may update these Terms as the products, providers, or law change. The current version and date will be published here, and we will try to give reasonable notice of material changes where practical. Continued use after an effective update means acceptance, subject to mandatory law.
These Terms are governed by Lithuanian law, without overriding mandatory consumer protections. Lithuanian courts have jurisdiction unless non-waivable law provides otherwise. Questions should be sent through https://vibosome.com/contact using the relevant legal, privacy, security, billing, or product category.