legal

terms of service · privacy policy · end user license agreement

Moud — Terms of Service

Effective Date: August 22, 2026 · Last Updated: August 22, 2026

These Terms of Service ("Terms") govern access to and use of Moud, an AI and developer infrastructure platform developed and operated by OpceanAI, a technology startup based in Mexico ("OpceanAI", "Moud", "we", "us", or "our").

Moud is made available through mound.opceanai.com, its APIs, applications, clients, and related services (collectively, the "Service").

By creating an account, accessing the Service, or using any part of it, you agree to these Terms and the policies incorporated by reference. If you do not agree, you must not use the Service.

1. The Service

Moud provides a unified platform for AI and developer infrastructure. Depending on availability, the Service may include:

  • AI model access and inference APIs;
  • Moud-hosted models and AI services;
  • third-party models and inference providers;
  • OpenAI-compatible APIs and related interfaces;
  • OCR, vision, embeddings, speech, search, and other AI services;
  • BYOK integrations;
  • Agents, Moonlight, and developer tooling;
  • compute resources and temporary virtual machines;
  • application deployment and managed DNS;
  • Moud-managed subdomains;
  • Channels and third-party integrations; and
  • Community features, including Chat, Groups, Tips, Reviews, and Sharing.

The Service is continuously developed. We may add, remove, replace, restrict, or modify models, providers, endpoints, features, quotas, infrastructure, or regions without creating an obligation to maintain a particular configuration.

Features identified as beta, experimental, preview, or otherwise limited may be changed or withdrawn at any time.

2. Eligibility and Authority

You may use Moud only if you are legally capable of entering into these Terms under the laws applicable to you.

If you access Moud on behalf of an organization, you represent that you have authority to bind that organization. In that case, "you" includes that organization.

You are responsible for complying with laws and regulations applicable to your use of the Service.

3. Accounts

Certain features require an account.

You agree to provide accurate information and to keep account information reasonably current.

You are responsible for:

  • maintaining the confidentiality of account credentials;
  • controlling access to your account;
  • activities performed through your account; and
  • promptly notifying Moud of unauthorized access or credential compromise.

Unless Moud expressly permits otherwise, an individual may maintain only one free-tier account.

Bulk registration, account farming, quota farming, and creation of accounts for the purpose of circumventing Service limits are prohibited.

We may suspend or terminate accounts involved in fraud, abuse, security incidents, or violations of these Terms.

4. API Keys and Authentication

Moud may authenticate requests through API keys, OAuth, device authentication, session credentials, or other mechanisms.

API keys and similar credentials are confidential authentication information.

You must not:

  • publish or expose credentials;
  • share credentials with unauthorized persons;
  • resell or sublicense access through your credentials;
  • use another user's credentials;
  • attempt to obtain credentials belonging to another account; or
  • bypass authentication or authorization mechanisms.

Moud may revoke, rotate, or disable credentials where necessary to address compromise, abuse, fraud, security incidents, or operational risk.

5. Models and Providers

Moud may provide models operated by OpceanAI ("Moud Hosted Models") and models or services supplied by third parties ("Third-Party Models" or "Third-Party Services").

Third-Party Models may be subject to separate licenses, usage policies, geographic restrictions, commercial-use restrictions, retention policies, training policies, safety requirements, and other conditions.

The applicable terms of a model or provider govern your use of that model or provider's service where they impose requirements specific to it.

Moud does not represent that it owns or operates every model available through the Service.

A model or provider may be unavailable, replaced, restricted, or removed because of licensing requirements, provider decisions, infrastructure changes, security considerations, legal requirements, or other circumstances.

6. Moud Hosted and ZDR Services

Moud may host and operate selected models and AI services directly.

Certain services may be expressly designated ZDR (Zero Data Retention).

A service is ZDR only when Moud explicitly identifies it as such in the applicable product or service documentation.

For a designated ZDR service, Moud does not intentionally retain the submitted request content after processing is complete, except where temporary processing, security measures, abuse prevention, legal obligations, or another specifically disclosed operational necessity requires limited retention or processing.

ZDR is service-specific. It does not automatically apply to Third-Party Models, BYOK requests, Community features, Compute, Deployments, or other services.

7. BYOK

Moud may allow users to connect credentials issued by third-party providers through Bring Your Own Key ("BYOK").

You represent that you are authorized to use any credentials submitted through BYOK.

When BYOK is used:

  • the relevant provider processes the request in accordance with its own policies;
  • provider-side retention, logging, training, pricing, and availability are controlled by that provider;
  • Moud cannot guarantee the policies or availability of an independent provider; and
  • Moud will not intentionally expose your BYOK credentials to another user through supported functionality.

8. Usage Limits and Fair Use

Moud may enforce multiple limits simultaneously, including limits based on account, API key, IP address, model, provider, resource type, request volume, token consumption, or time.

Limits may be fixed or rolling and may vary by model or provider.

Examples include:

  • requests per minute, hour, or day;
  • token quotas;
  • community pools;
  • personal allocations;
  • compute runtime;
  • deployment limits;
  • sharing limits; and
  • abuse-prevention controls.

Published limits are operational limits, not guarantees of availability.

We may adjust limits in response to capacity, provider requirements, abuse, security incidents, or changes to the Service.

Attempts to circumvent or manipulate limits are prohibited.

9. Free Services and Credits

Moud may provide free models, API access, credits, compute, or other allocations.

Free access is provided subject to availability and applicable limits.

Unless expressly stated otherwise, free allocations:

  • have no monetary value;
  • are not redeemable for cash;
  • are not transferable outside supported Moud functionality;
  • may expire; and
  • may be modified or discontinued.

Community-shared resources are subject to the rules displayed by the relevant sharing feature.

10. Compute, Agents, and Virtual Machines

Moud may provide temporary virtual machines, compute resources, Agents, and related infrastructure.

Where administrative or root access is provided, you are responsible for activity performed within the assigned environment.

You must not use Moud infrastructure to:

  • attack third-party systems;
  • conduct unauthorized scanning or penetration testing;
  • distribute malware;
  • perform denial-of-service activity;
  • obtain unauthorized access;
  • evade network restrictions; or
  • interfere with other customers, users, providers, or Moud infrastructure.

Temporary resources may be subject to automatic expiration, suspension, reclamation, or destruction.

Moud does not guarantee recovery of data stored on temporary compute resources after termination or expiration.

11. Deployments and Managed Domains

Moud may provide deployment services and Moud-managed subdomains, including addresses under *.opceanai.com.

A requested name is subject to availability and naming restrictions.

You may not use a Moud-managed domain for phishing, fraud, malware, impersonation, unlawful content, or activity designed to evade enforcement.

We may suspend or reclaim a domain where reasonably necessary to protect users, the Service, or third parties.

You are responsible for applications, files, content, and services deployed through your account.

12. Community and User Content

Moud may provide Chat, Groups, Tips, Reviews, Sharing, and other Community features.

You retain rights in content you submit to the extent you possess those rights.

By submitting content to a Community feature, you grant Moud the limited rights necessary to host, transmit, display, moderate, and operate that feature.

Public content may be visible to other users and may be copied by third parties.

You must not publish content that violates applicable law, these Terms, the Acceptable Use Policy, or the rights of others.

13. Acceptable Use

Your use of Moud is subject to the Moud Acceptable Use Policy.

Without limiting that policy, you may not use Moud to:

  • violate applicable law;
  • facilitate fraud, phishing, credential theft, or unauthorized access;
  • generate or distribute child sexual abuse material;
  • distribute malware or ransomware;
  • infringe intellectual property or privacy rights;
  • attack, scan, or disrupt infrastructure without authorization;
  • bypass authentication, quotas, rate limits, CAPTCHAs, or abuse controls;
  • automate account or key farming;
  • systematically harvest Moud traffic or infrastructure to operate a competing gateway without written permission;
  • extract model weights, secrets, or provider credentials;
  • impersonate Moud, OpceanAI, their personnel, or third-party organizations; or
  • use Moud-managed domains for unlawful or abusive purposes.

14. Inputs and Outputs

You retain the rights you have in content submitted to the Service ("Input").

Moud does not claim ownership of your Input merely because you provide it to the Service.

Outputs generated by a model ("Output") may be subject to model-specific licenses and applicable law. Moud does not guarantee that Output is unique, accurate, lawful, or eligible for intellectual-property protection.

You are responsible for reviewing Output before using, publishing, or relying on it.

15. Intellectual Property

Moud software, documentation, interfaces, branding, trademarks, and proprietary infrastructure are owned by OpceanAI or its licensors.

Third-party models, model weights, names, trademarks, and related intellectual property remain subject to their respective rights and licenses.

These Terms do not transfer ownership of Moud software or third-party model weights.

16. Security

You must not circumvent Moud's security controls or access systems, accounts, credentials, or data that you are not authorized to access.

Good-faith vulnerability reports are encouraged through Moud's designated security or contact channels.

Unauthorized exploitation, persistence, credential extraction, or intentional disruption is prohibited.

17. Availability and Changes

The Service is provided on an "as available" basis.

Moud does not guarantee uninterrupted availability, specific performance, permanent model access, or fixed quotas.

We may perform maintenance, migrate infrastructure, change providers, modify routing, replace models, or suspend services when necessary.

18. Suspension and Termination

We may suspend or terminate access where reasonably necessary to:

  • enforce these Terms;
  • prevent fraud or abuse;
  • protect users or infrastructure;
  • address security incidents;
  • comply with law; or
  • comply with provider or licensing requirements.

You may stop using Moud at any time.

Provisions that by their nature should survive termination will remain effective.

19. Disclaimers

TO THE MAXIMUM EXTENT PERMITTED BY LAW, THE SERVICE IS PROVIDED "AS IS" AND "AS AVAILABLE", WITHOUT WARRANTIES OF ANY KIND, EXPRESS OR IMPLIED.

MOUD DOES NOT WARRANT THAT THE SERVICE WILL BE UNINTERRUPTED, SECURE, ERROR-FREE, OR SUITABLE FOR A PARTICULAR PURPOSE.

20. Limitation of Liability

TO THE MAXIMUM EXTENT PERMITTED BY LAW, OPCEANAI AND ITS AFFILIATES, OFFICERS, DIRECTORS, CONTRIBUTORS, MAINTAINERS, AND SERVICE OPERATORS WILL NOT BE LIABLE FOR INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, EXEMPLARY, OR PUNITIVE DAMAGES, OR FOR LOSS OF DATA, PROFITS, REVENUE, BUSINESS OPPORTUNITY, OR BUSINESS INTERRUPTION ARISING OUT OF OR RELATING TO THE SERVICE.

Nothing in these Terms excludes liability that cannot lawfully be excluded.

21. Changes to These Terms

We may revise these Terms as the Service, applicable law, or our operating practices change.

The revised version will include an updated "Last Updated" date. Where required by law, material changes will be communicated through an appropriate notice.

Your continued use of Moud after the effective date constitutes acceptance of the revised Terms to the extent permitted by law.

22. Governing Law and Entity Information

Moud is developed and operated by OpceanAI, a technology startup based in Mexico. Its primary operations are conducted from Mexico.

Legal entity: OpceanAI Jurisdiction: United Mexican States Legal address: Mexico (contactable electronically through the channels published on the website)

23. Contact

Legal, privacy, security, abuse, and other formal notices may be submitted through the contact information published on the Moud website:


Moud — Developed and operated by OpceanAI · Mexico

Moud — Acceptable Use Policy

Effective Date: August 22, 2026

This Acceptable Use Policy ("AUP") establishes prohibited uses of Moud and supplements the Moud Terms of Service.

1. Prohibited Conduct

You may not use Moud to facilitate, perform, or materially enable:

Abuse and unlawful activity

  • Fraud, scams, extortion, or impersonation.
  • Unauthorized access to accounts, systems, or networks.
  • Credential theft or token theft.
  • Distribution of malware, ransomware, spyware, or destructive code.
  • Denial-of-service attacks or intentional resource exhaustion.
  • Phishing or fraudulent websites.
  • Distribution of child sexual abuse material.
  • Illegal exploitation of personal, financial, or confidential information.

Infrastructure abuse

  • Unauthorized scanning or enumeration.
  • Exploitation of Moud, provider, or third-party infrastructure.
  • Attempts to escape isolation boundaries.
  • Attempts to obtain host-level access from Compute or Agent environments.
  • Circumvention of firewalls, egress controls, quotas, or authentication systems.
  • Resource abuse intended to interfere with other users.

Platform abuse

  • Automated account creation.
  • Account or credential farming.
  • Quota farming.
  • Automated draining of community pools.
  • Manipulation of sharing, referral, or free-resource systems.
  • Circumvention of CAPTCHAs or rate limits.
  • Reselling Moud access without authorization.
  • Systematic scraping or harvesting of Moud infrastructure.

Content and impersonation

  • Phishing pages on Moud-managed domains.
  • Impersonation of OpceanAI, Moud, staff, providers, or protected organizations.
  • Fraudulent customer-support pages.
  • Illegal or malicious software distribution.
  • Content intended to evade moderation or enforcement.

2. Security Research

Good-faith security research is permitted only when performed within an expressly authorized security-testing program or with prior authorization.

You must not access, modify, retain, or disclose another user's data or credentials.

Report vulnerabilities responsibly and provide sufficient information for investigation.

3. Enforcement

Moud may respond to violations using measures proportionate to the circumstances, including:

  • rate limiting;
  • resource suspension;
  • credential revocation;
  • account suspension;
  • domain suspension;
  • content removal;
  • termination; or
  • referral to appropriate authorities where legally required or permitted.

We may take immediate action where necessary to protect users, infrastructure, or third parties.

4. Interpretation

This AUP is intended to establish baseline prohibited conduct.

Additional restrictions may apply to specific models, providers, deployment environments, Community features, or Compute products.

Nothing in this AUP requires Moud to permit conduct that is lawful but materially harmful to the security or integrity of the Service.

5. Contact

Abuse reports and enforcement questions:

Moud — Privacy Policy

Effective Date: August 22, 2026 · Last Updated: August 22, 2026

This Privacy Policy describes how OpceanAI, a technology startup based in Mexico, processes information in connection with Moud.

Moud is an AI and developer infrastructure platform available through mound.opceanai.com, its APIs, applications, clients, and related services.

1. Scope and Roles

OpceanAI operates Moud from Mexico.

Moud uses infrastructure and service providers located in Mexico, Canada, and the United States.

For account, platform, and operational information, OpceanAI generally acts as the organization responsible for determining the purposes and means of processing.

For content submitted to Moud for processing through an applicable service, OpceanAI may process that content on the user's instructions to provide the requested service.

When a request is sent to an independent third-party provider, that provider may separately determine how it processes the request under its own terms and policies.

2. Where Information Is Processed

Moud's primary operational activities are conducted from Mexico.

Moud primarily stores account, platform, authentication, and operational data in Canada.

Depending on the service and provider involved, AI inference and related processing may occur in Canada or the United States.

Information may also be processed in another jurisdiction where necessary to operate a particular service, maintain security, prevent abuse, provide infrastructure, or comply with law.

3. Information We Collect

The categories of information we process include:

Account and identity data

  • Name;
  • email address;
  • OAuth provider;
  • provider account identifier;
  • account status;
  • account creation and deletion information.

Authentication and security data

  • session identifiers;
  • OAuth state;
  • device-authentication information;
  • API key identifiers and metadata;
  • authentication events;
  • security events;
  • IP addresses and related request information where necessary for security and abuse prevention.

Usage and operational data

  • requested model or service;
  • provider or routing information;
  • endpoint;
  • timestamps;
  • token counts;
  • latency;
  • status codes;
  • quota usage;
  • compute consumption;
  • deployment metadata.

User-submitted content

Depending on the feature, this may include:

  • prompts;
  • generated outputs;
  • source code;
  • documents;
  • images;
  • audio;
  • video;
  • OCR input;
  • TTS input; and
  • other files or data submitted to the Service.

4. How We Use Information

We process information to:

  • provide and operate Moud;
  • authenticate users;
  • route requests;
  • enforce quotas and rate limits;
  • maintain service reliability;
  • operate Compute, Deploy, Community, and related services;
  • detect and prevent fraud and abuse;
  • secure accounts and infrastructure;
  • diagnose failures;
  • provide support;
  • maintain aggregate usage statistics;
  • comply with legal obligations; and
  • establish, exercise, or defend legal claims.

Moud does not use user content to train its own AI models unless the applicable service explicitly states otherwise and the required legal basis or consent is obtained.

5. Moud Hosted Services and ZDR

Some Moud-hosted AI services may be explicitly labeled ZDR (Zero Data Retention).

For a service designated ZDR, Moud does not intentionally retain submitted request content after processing.

This does not mean that no information is processed or that every technical record disappears immediately. Security records, authentication data, quota metadata, operational logs, and information required by law may still be retained.

ZDR applies only to the service identified as ZDR.

It does not apply automatically to:

  • third-party providers;
  • BYOK;
  • Community features;
  • Compute;
  • Deployments;
  • account records; or
  • operational metadata.

6. Third-Party Model Providers

When you request a model or service operated by a third party, the relevant Input may be transmitted to that provider.

Providers may process Inputs and Outputs under their own:

  • privacy policies;
  • retention policies;
  • terms;
  • model licenses;
  • security practices; and
  • training or model-improvement policies.

Different providers may have materially different data practices.

Moud may identify provider-level information in the model catalog or service documentation where available.

You should review the applicable provider policy before submitting sensitive information to a third-party model.

7. BYOK

When you use BYOK, Moud may process your provider credential and the request necessary to execute the requested operation.

Moud will not intentionally disclose your BYOK credential to another user through supported functionality.

The third-party provider remains responsible for its own processing after a request is transmitted to it.

Provider-side retention, logging, training, billing, and security practices are governed by the provider's terms.

8. Data Retention

Data categoryPrimary purposeGeneral retention
Account informationAccount operationWhile the account exists
Session dataAuthenticationLimited to the required session period
API metadataCredential managementWhile necessary for the credential
Usage metadataQuotas, analytics, reliabilityRolling or operational periods
Security recordsAbuse prevention and incident responseAs reasonably necessary
Legal recordsComplianceAs required by law
ZDR request contentService processingNot intentionally retained after processing

Security, fraud-prevention, legal, and operational requirements may require longer retention for specific records.

9. Storage and Infrastructure

Moud primarily stores platform and operational data in Canada.

Infrastructure supporting Moud may be located in Mexico, Canada, the United States, or another jurisdiction used by an applicable service provider.

Storage location does not necessarily determine where a request is processed.

10. Cookies and Similar Technologies

Moud uses essential cookies and related technologies required for:

  • authentication;
  • session management;
  • OAuth security;
  • account security; and
  • recording required terms or consent state.

Moud does not use advertising cookies for behavioral advertising.

Third-party authentication providers may place or process their own cookies under their respective privacy policies.

Login is additionally protected by Google reCAPTCHA, subject to Google's privacy policy.

11. Public and Community Content

When you intentionally publish content to public Community features, that content may be accessible to other users and may be indexed, copied, or redistributed outside Moud.

Examples include public Tips, Reviews, Chat messages, community posts, public contributions, and other intentionally public content.

Do not publish confidential, sensitive, or private information in a public Community feature.

12. Deployments and Member Subdomains

Applications deployed under Moud-managed domains are controlled by the account holder.

Public deployments may be accessible to anyone on the Internet.

Moud may process deployment metadata such as:

  • project identifier;
  • deployment identifier;
  • domain or subdomain;
  • deployment status;
  • timestamps;
  • resource consumption;
  • operational logs.

The content of a deployment is controlled by the user, except where Moud must access it to provide or secure the deployment service.

13. Security

Moud maintains technical and organizational safeguards intended to protect information.

These may include:

  • TLS encryption in transit;
  • access controls;
  • credential protection;
  • network segmentation;
  • infrastructure firewalls;
  • reverse proxies;
  • authentication controls;
  • rate limiting;
  • audit logging; and
  • security monitoring.

No online service can guarantee absolute security.

14. Data Sharing and Subprocessors

Moud may disclose information to:

  • infrastructure providers;
  • AI model providers;
  • hosting providers;
  • authentication providers;
  • security and anti-abuse providers;
  • service providers supporting Moud operations; and
  • competent authorities where legally required.

We do not sell personal information.

A current list of material subprocessors should be maintained by Moud and published or otherwise made available where required by applicable law or contractual commitments.

15. International Transfers

Because Moud operates across Mexico, Canada, and the United States, personal information may be transferred between these jurisdictions.

Where applicable law imposes specific requirements on international transfers, OpceanAI will use the safeguards required by that law.

16. Your Privacy Rights

Depending on your location, you may have rights to:

  • request access to personal information;
  • request correction;
  • request deletion;
  • request export or portability where applicable;
  • object to or restrict certain processing; and
  • request information regarding processing practices.

Requests may be submitted through the contact information published by Moud.

Moud may require reasonable information to verify the identity of the person making a request.

17. Account Deletion

You may request deletion of your Moud account.

Deletion will remove or anonymize account information that is no longer required for legitimate operational, security, or legal purposes.

Certain records may remain where required by law, reasonably necessary for security or fraud prevention, or preserved in aggregated form that no longer identifies the user.

Backups may persist for a limited period before normal expiration.

18. Children's Privacy

Moud does not knowingly collect personal information from children where doing so would violate applicable law.

If you believe a child has provided personal information improperly, contact Moud through the published privacy contact.

19. Changes to This Policy

We may update this Privacy Policy as Moud's services, infrastructure, providers, or legal obligations change.

The effective date will be updated whenever this policy is materially revised.

Where required, material changes will be communicated through an appropriate notice.

20. Contact

Moud is developed and operated by OpceanAI, a technology startup based in Mexico.

Legal entity: OpceanAI Legal address: Mexico (contactable electronically through the channels above)

End User License Agreement (EULA)

Last updated: 2026-08-22

1. License grant

Moud grants you a personal, revocable, non-exclusive, non-transferable license to access the Service's API and console for lawful purposes, subject to these terms, the Terms of Service and the Privacy Policy.

2. Scope of use

  • You may build applications on top of the API within your key's rate limits.
  • You may use generated outputs in personal or commercial projects.
  • You may NOT: redistribute API access, resell pooled capacity, train competing gateways/routers on harvested traffic, or extract model weights.

3. Model licenses

Outputs come from third-party open-weight models (Qwen, DeepSeek, Kimi, GLM, Llama, Mistral, Nemotron, Gemma and others). Each publisher's license travels with its outputs. Some models restrict commercial use — check the publisher license before shipping.

4. Output ownership and responsibility

Generated text belongs to you to the extent permitted by the upstream model license. Moud claims no ownership over your prompts or outputs. You are responsible for reviewing outputs before relying on them.

5. Restrictions summary

No reverse engineering of the Service, no scraping of the catalog at scale, no circumventing quotas or captchas, no hosting illegal content on member subdomains, no impersonation of people or brands.

6. Updates

The Service evolves continuously. Models may be added, disabled or replaced; breaking API changes will be avoided but are possible during major incidents.

7. Termination of license

Violation of any clause terminates this license immediately. Upon termination you must stop accessing the Service.

8. Governing terms

This EULA incorporates by reference the Terms of Service and Privacy Policy. In case of conflict between documents, the Terms of Service prevail.