Terms of Service

Last updated: July 25, 2026

1. The service

bulgur ("we", "us") provides a hosted secrets manager at bulgur.dev: a dashboard, an API, a command-line tool, and an MCP interface for storing and distributing configuration secrets such as API keys and environment variables. By creating an account or using the service you agree to these terms.

2. Accounts

You must provide accurate information and keep your credentials secure. You are responsible for everything that happens under your account, including actions performed with API tokens you create. Usernames are claimed on a first-come basis; we may reclaim usernames that squat on trademarks or impersonate others.

3. Your data and secrets

The secrets you store belong to you. We encrypt secret values at rest and decrypt them only to serve requests you or your tooling authorize. We do not access, use, or disclose your secrets except as necessary to operate the service, comply with law, or with your explicit permission. Details are in the Privacy Policy.

You are responsible for the contents of what you store — do not store data you have no right to hold.

4. Plans, billing, and cancellation

The Free plan is free forever within its published limits. Paid plans (Pro, Team) are billed monthly through our payment provider, Polar, acting as merchant of record — your payment details never reach our servers. Prices are shown in your local currency at checkout and may change with notice; changes apply from your next billing cycle.

You can cancel anytime from the billing portal. Access to paid features continues until the end of the paid period, after which the organization returns to the Free plan. Fees are non-refundable except where required by law.

5. Acceptable use

Do not use bulgur to violate the law, infringe others' rights, probe or disrupt the service or other tenants, resell the service, or attempt to bypass plan limits or access controls. We may suspend accounts that put the service or other customers at risk.

6. Availability and support

We work hard to keep bulgur available and your data durable, but the service is provided "as is" without a formal SLA. We may modify or discontinue features with reasonable notice; if we ever discontinue the service entirely, we will give you at least 30 days to export your data.

7. Liability

To the maximum extent permitted by law, our total liability arising out of the service is limited to the amounts you paid us in the twelve months before the claim. We are not liable for indirect or consequential damages, or for losses caused by secrets you chose to store or distribute.

8. Termination

You may delete your organizations and account at any time; deletion is permanent and removes your stored secrets. We may terminate accounts that materially breach these terms, with notice where practicable.

9. Changes and contact

We may update these terms; material changes will be announced by email or in the dashboard at least 14 days in advance. Continued use after the effective date constitutes acceptance. These terms are governed by the laws of Germany. Questions: hello@bulgur.dev.