Locality Terms of Service


Effective Date: July 22, 2026


These Locality Terms of Service (the "Terms") are a binding agreement between

you and CodeFlash Inc. ("CodeFlash," "we," "us," or "our"). Please read them

carefully.


Your rights in software made available under an Open-Source License arise solely

under that license. Downloading, installing, copying, modifying, distributing,

or using that software in exercise of those rights does not by itself constitute

agreement to additional restrictions in these Terms.


By affirmatively accepting these Terms when presented, or by using the

CodeFlash-operated OAuth broker, update service, or support after receiving

conspicuous notice of these Terms, you agree to these Terms for the Locality

Desktop Services. If you do not agree, do not use those CodeFlash-operated

services.


If you use Locality for a company or other organization, "you" includes that

organization, and you represent that you have authority to bind it to these

Terms. If you do not have that authority, you may not use Locality on its

behalf.


1. Eligibility


You must be at least 18 years old and legally capable of entering into a

contract to use Locality. You may use Locality only where permitted by law.


2. Scope of These Terms


These Terms apply whether the Locality desktop product is used by an individual

or an organization, and they apply only to:


- the Locality desktop application for macOS, Windows, and Linux;

- the `loc` command-line interface and `localityd` background daemon bundled

with the application;

- Locality's local Model Context Protocol ("MCP") integration;

- the CodeFlash-operated OAuth broker used by supported connections;

- official Locality software updates; and

- support that CodeFlash provides for those components.


Together, these are the "Locality Desktop Services." The Locality Desktop

Services are limited to the locally installed desktop product and the narrow

operated services listed above that support that product.


These Terms do not govern the CodeFlash.ai website or products, a Locality

marketing website, or any separate enterprise backend, hosted content service,

or other cloud-hosted Locality offering that CodeFlash may introduce in the

future. No such backend, cloud-hosted product, enterprise service, or

content-hosting service is part of the Locality Desktop Services. Separate terms

will apply to those offerings.


3. Open-Source Software


CodeFlash makes the first-party Locality source code in the official repository

available under the Apache License, Version 2.0. Official distributions may also

contain third-party components governed by other open-source licenses

(collectively, the "Open-Source Licenses"). Rights in all such software are

governed solely by the applicable Open-Source Licenses. Nothing in these Terms

limits rights granted under an Open-Source License. If these Terms conflict with

an Open-Source License as to the software covered by that license, the

Open-Source License controls.


Operating or publishing the source code for the OAuth broker does not grant a

right to use or interfere with CodeFlash's hosted infrastructure, provider OAuth

applications, client secrets, signing credentials, domains, or trademarks.

CodeFlash's operation of the hosted OAuth broker, update infrastructure, and

support is governed by these Terms.


4. How Locality Works


Locality is a local-first application that presents information from supported

third-party services as files on your device. Under the Locality Desktop

Services, connected source content travels directly between your device and the

service you connect. CodeFlash does not operate a content relay under these

Terms.


Locality may download, cache, index, render, search, edit, create, move, delete,

or synchronize content on your device and, when you direct or authorize it,

apply actions to a connected service. Depending on the connector and the action,

this may include changing documents or records, creating drafts, sending or

modifying communications, creating calendar events, or deleting or moving

remote content.


You authorize Locality to access your device and connected services to perform

the actions you request or enable. You are responsible for reviewing connection

scopes, proposed changes, Live Mode settings, and agent actions and for

maintaining appropriate backups. Locality includes safety and review controls,

but those controls cannot prevent every user error, software defect,

third-party-service change, conflict, or data loss.


5. Connected Services and Authorization


To connect a third-party service, you must have a valid account and sufficient

permission to access and act on the data you connect. You represent and warrant

that:


- you have all rights and authorizations needed to connect the account,

workspace, files, and content;

- your use of Locality and connected content complies with law, contracts,

organizational policies, and the connected provider's terms;

- you will not use Locality to access another person's or organization's data

without authorization; and

- you are responsible for actions performed through credentials, devices,

agents, or configurations under your control.


Providers may change or discontinue their APIs, scopes, rate limits, data

formats, or other functionality. CodeFlash does not control and is not

responsible for a connected provider's availability, security, acts, omissions,

terms, or data practices.


6. Authentication and Credentials


Supported OAuth connections use a CodeFlash-operated broker to perform the

confidential OAuth exchange and refresh steps required by the provider. The

broker handles authentication data but does not relay connected source content.

Other connectors may use credentials or API keys supplied directly to the

application.


By default, credentials are stored locally using Apple Keychain on macOS,

Windows Credential Manager on Windows, and current-user-restricted files on

Linux. If a file-based credential store is explicitly configured on macOS or

Windows, credentials are stored in current-user-restricted files instead. You

are responsible for protecting your operating-system account, device, backups,

credential stores, API keys, OAuth grants, and local MCP capability token. You

must promptly revoke credentials and notify us at support@codeflash.ai if you

believe CodeFlash-operated authentication infrastructure has been compromised.


7. Local Agents, MCP, and Live Mode


Locality may detect supported local agent tools and install instructions or MCP

configuration into their documented local configuration files. A configured

agent may be able to search, read, or modify mounted content and request Locality

operations within the permissions available to that agent and the connected

provider.


Locality's Live Mode may automatically pull clean remote changes or push local

changes when its safety rules consider the operation eligible. You are

responsible for choosing whether to enable these features and for supervising

software agents that use them. Do not grant an agent, editor, script, or other

person access to Locality unless you are comfortable allowing that access to

the connected content and actions.


CodeFlash does not operate or control third-party agents used with Locality and

is not responsible for their outputs, instructions, security, or data practices.


8. Local Data, Backups, and Removal


Locality may store provider content, metadata, search indexes, synchronization

state, journals, media, logs, backups, and recovery copies on your device. You

retain your rights in content you own. As between you and CodeFlash, these Terms

do not transfer ownership of your connected content to CodeFlash.


Locality provides controls to disconnect sources, reset local application

state, and prepare the application for uninstall. Resetting or uninstalling

Locality may not remove visible mounted files, exported diagnostics, source

backups, recovery copies, or copies created by other applications. You are

responsible for reviewing and deleting residual files when appropriate. You are

also responsible for using the connected provider's controls to revoke access

or delete provider-held data.


You should maintain backups appropriate to the importance of your content and

test Locality with non-critical content before relying on a workflow that may

make remote changes.


9. Updates


Official direct-download builds may automatically check GitHub Releases for

updates, download an update in the background, and prompt you to install or

restart. When Locality is running in the background and no protected work is in

progress, an update may install and relaunch the application automatically.

Versions obtained through an application marketplace may be updated under that

marketplace's processes.


Updates, patches, enhancements, or fixes become part of the Locality Desktop

Services and are subject to these Terms and applicable Open-Source Licenses.

CodeFlash may stop supporting an older version. An older version may become

insecure, incompatible with provider APIs, or unable to operate correctly.


10. Acceptable Use


You may not use the CodeFlash-operated portions of the Locality Desktop

Services to:


- violate law or another person's intellectual-property, privacy,

confidentiality, contractual, or other rights;

- access, collect, modify, transmit, or delete data without authorization;

- distribute malware, facilitate unlawful surveillance, or harm another person

or system;

- attack, probe, overload, disrupt, or circumvent security, rate limits, or

access controls of the OAuth broker, update infrastructure, or connected

services;

- obtain or misuse CodeFlash or provider secrets, credentials, tokens, or

signing material;

- impersonate another person or misrepresent your authority; or

- assist another person in doing any of the above.


This section restricts misuse of services and infrastructure operated by

CodeFlash. It does not restrict rights granted under an applicable Open-Source

License.


11. Privacy


The Locality Privacy Policy explains how CodeFlash processes personal

information in connection with the Locality Desktop Services. Please review it

before using CodeFlash-operated services. Connected providers and third-party

agents process information under their own privacy notices.


12. Support Materials and Feedback


Local diagnostic logs and trace files are not uploaded automatically. If you

manually assemble diagnostic materials or use a support-bundle export feature

when available, CodeFlash receives them only if you separately choose to send

them. You authorize us to process submitted materials to investigate the issue,

provide support, troubleshoot and secure the Locality Desktop Services, and

comply with law. We may use aggregated or deidentified diagnostic information

to improve the product, but will not use connected source content for unrelated

product improvement or model training without separate permission.


Review support materials before sending them. Never send passwords, API keys,

OAuth tokens, refresh handles, MCP tokens, or other credentials. Send connected

source content only when necessary to resolve the issue and specifically

requested through an appropriate secure channel.


You may provide ideas, suggestions, or other feedback about Locality. You grant

CodeFlash a worldwide, perpetual, irrevocable, transferable, sublicensable,

royalty-free license to use and exploit that feedback for any lawful purpose,

without an obligation to compensate or credit you. This license does not grant

CodeFlash rights in connected content merely because you used Locality.


13. CodeFlash and Third-Party Rights


CodeFlash and its licensors retain all rights in the Locality Desktop Services

not granted under applicable Open-Source Licenses, including rights in

CodeFlash's hosted infrastructure, service configuration, branding, trademarks,

and non-public materials. These Terms do not grant permission to use CodeFlash

or Locality names, logos, or marks except as necessary to accurately refer to

the product.


Third-party software included with Locality is governed by its applicable

license. If you obtain Locality through an application store or other

distributor, that distributor's terms may also apply. As between CodeFlash and a

distributor, CodeFlash, not the distributor, is responsible for these Terms,

subject to the distributor's required terms.


14. Changes, Availability, and Support


CodeFlash may add, change, suspend, or discontinue operated features of the

Locality Desktop Services. We will use reasonable efforts to provide notice of

material changes when appropriate. We do not promise that every connector,

provider feature, operating system, agent, or older application version will

remain supported.


Unless CodeFlash agrees otherwise in a separate written agreement, the Locality

Desktop Services do not include a service-level agreement, guaranteed response

time, guaranteed support, or a commitment to provide any particular update or

feature.


15. Suspension and Termination


You may stop using Locality at any time. CodeFlash may suspend or terminate your

access to CodeFlash-operated infrastructure if we reasonably believe you have

violated these Terms, created a security or legal risk, or used the

infrastructure in a way that could harm CodeFlash, a provider, or another user.

When reasonably practicable, we will provide notice and an opportunity to cure.


Termination of these Terms does not terminate rights in open-source software

except as provided by the applicable Open-Source License. Sections that by

their nature should survive termination will survive, including ownership,

feedback, disclaimers, limitations of liability, indemnification, dispute, and

general provisions.


16. Disclaimers


TO THE MAXIMUM EXTENT PERMITTED BY LAW, THE LOCALITY DESKTOP SERVICES ARE

PROVIDED "AS IS" AND "AS AVAILABLE." CODEFLASH AND ITS LICENSORS DISCLAIM ALL

EXPRESS, IMPLIED, AND STATUTORY WARRANTIES, INCLUDING WARRANTIES OF TITLE,

NON-INFRINGEMENT, MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, QUIET

ENJOYMENT, ACCURACY, SECURITY, AVAILABILITY, AND DATA INTEGRITY.


CODEFLASH DOES NOT WARRANT THAT LOCALITY WILL BE ERROR-FREE, THAT SYNCHRONIZATION

OR SAFETY CONTROLS WILL IDENTIFY OR PREVENT EVERY CONFLICT OR UNINTENDED CHANGE,

THAT CONNECTED SERVICES WILL REMAIN COMPATIBLE, OR THAT DATA WILL NOT BE LOST,

ALTERED, DISCLOSED, OR CORRUPTED. YOU ARE RESPONSIBLE FOR REVIEWING OUTPUTS AND

REMOTE CHANGES, MAINTAINING BACKUPS, AND DETERMINING WHETHER LOCALITY IS

APPROPRIATE FOR YOUR USE.


SOME JURISDICTIONS DO NOT ALLOW CERTAIN WARRANTY DISCLAIMERS. IN THAT CASE,

THESE DISCLAIMERS APPLY ONLY TO THE EXTENT PERMITTED BY LAW.


NOTHING IN THESE TERMS EXCLUDES, RESTRICTS, OR MODIFIES STATUTORY CONSUMER

GUARANTEES OR OTHER RIGHTS THAT CANNOT LAWFULLY BE EXCLUDED.


17. Limitation of Liability


TO THE MAXIMUM EXTENT PERMITTED BY LAW, CODEFLASH AND ITS DIRECTORS, OFFICERS,

EMPLOYEES, AFFILIATES, AGENTS, LICENSORS, AND SERVICE PROVIDERS WILL NOT BE

LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, EXEMPLARY, OR

PUNITIVE DAMAGES, OR FOR LOST PROFITS, REVENUE, GOODWILL, BUSINESS OPPORTUNITY,

OR DATA, ARISING OUT OF OR RELATING TO THE LOCALITY DESKTOP SERVICES OR THESE

TERMS, EVEN IF ADVISED OF THE POSSIBILITY OF THOSE DAMAGES.


TO THE MAXIMUM EXTENT PERMITTED BY LAW, THE AGGREGATE LIABILITY OF CODEFLASH AND

ITS DIRECTORS, OFFICERS, EMPLOYEES, AFFILIATES, AGENTS, LICENSORS, AND SERVICE

PROVIDERS FOR ALL CLAIMS ARISING OUT OF OR RELATING TO THE LOCALITY DESKTOP

SERVICES OR THESE TERMS WILL NOT EXCEED THE GREATER OF (A) ONE HUNDRED U.S.

DOLLARS (US $100) OR (B) THE AMOUNT YOU PAID CODEFLASH SPECIFICALLY FOR THE

LOCALITY DESKTOP SERVICES DURING THE TWELVE MONTHS BEFORE THE EVENT GIVING RISE

TO THE CLAIM.


THE LIMITATIONS IN THIS SECTION DO NOT APPLY TO FRAUD OR FRAUDULENT

MISREPRESENTATION, DEATH OR PERSONAL INJURY CAUSED BY NEGLIGENCE, WILLFUL

MISCONDUCT, GROSS NEGLIGENCE WHERE IT CANNOT LAWFULLY BE LIMITED, OR ANY OTHER

LIABILITY THAT APPLICABLE LAW PROHIBITS LIMITING. THEY DO NOT LIMIT RIGHTS

AVAILABLE TO A CONSUMER UNDER MANDATORY LAW.


18. Indemnification


If you use the Locality Desktop Services on behalf of a company or other

organization, then, to the extent permitted by law, that organization will

defend, indemnify, and hold harmless CodeFlash and its affiliates, officers,

directors, employees, agents, and service providers from third-party claims,

liabilities, damages, losses, and reasonable costs and attorneys' fees to the

extent caused by: (a) its unlawful or unauthorized use of the Locality Desktop

Services; (b) content, accounts, or systems it connects without sufficient

rights; (c) its violation of these Terms, law, or a third party's rights; or (d)

acts of agents, scripts, or other persons it authorizes to use Locality.


This obligation does not apply to the extent a claim results from the

negligence, willful misconduct, or breach of these Terms by a person seeking

indemnification. CodeFlash will provide prompt notice of an indemnified claim,

allow the organization to control its defense and settlement, and provide

reasonable cooperation at the organization's expense. The organization may not

settle a claim in a way that admits fault by or imposes non-monetary obligations

on a CodeFlash party without that party's written consent.


19. Governing Law and Venue


These Terms are governed by the laws of the State of California, without regard

to conflict-of-law principles. Subject to any mandatory consumer right to bring

a claim elsewhere, the state and federal courts located in San Francisco,

California have exclusive jurisdiction, and you and CodeFlash consent to their

personal jurisdiction and venue.


The United Nations Convention on Contracts for the International Sale of Goods

does not apply. Nothing in these Terms limits non-waivable rights under the law

of your place of residence.


20. Export and Sanctions Compliance


You may not use, export, re-export, or transfer the Locality Desktop Services in

violation of United States or other applicable export-control or sanctions

laws. You represent that you are not prohibited from receiving the Locality

Desktop Services under those laws.


21. Changes to These Terms


CodeFlash may update these Terms prospectively to reflect changes to the

CodeFlash-operated portions of the Locality Desktop Services, law, or business

practices. We will post updated Terms with a revised effective date and provide

additional in-application notice of material changes when required. If required

by law, we will request renewed agreement. Continued use of CodeFlash-operated

services after updated Terms take effect constitutes acceptance to the extent

permitted by law. Changes to these Terms do not alter rights already granted

under an Open-Source License.


22. General


These Terms are the entire agreement between you and CodeFlash concerning the

Locality Desktop Services, except for an applicable Open-Source License or a

separate written agreement that expressly controls. An applicable Open-Source

License controls the software it covers.


You may not assign these Terms without CodeFlash's prior written consent.

CodeFlash may assign them in connection with a merger, acquisition,

reorganization, sale of assets, or by operation of law. CodeFlash may use

subcontractors to provide operated portions of the Locality Desktop Services.


Neither party is liable for delay or failure caused by events beyond its

reasonable control. If a provision is unenforceable, it will be enforced to the

maximum extent permitted and the remaining provisions will remain in effect.

Failure to enforce a provision is not a waiver. These Terms do not create an

agency, partnership, joint venture, fiduciary, or employment relationship.


23. Contact


Questions about these Terms or the Locality Desktop Services may be directed to:


CodeFlash Inc.

465 California St., Floor 7

San Francisco, CA 94105, USA

Support: support@codeflash.ai

Privacy: privacy@codeflash.ai