Legal · Pre-launch draft

Draft Terms of Use

A non-binding description of the current GenCMS build. Public signup and billing are closed, marketplace execution is not deployed, and project services require a separate fixed-price quotation.

Draft pending legal review

Pre-launch draft only. These are not executed terms and have not been approved by counsel. Opening the site, receiving an administrator-created account or calling an endpoint does not make this draft an operative agreement.

Effective date: not yet effective — draft updated 27 August 2026

1.Draft status

This page is a pre-launch working draft for legal review. It is not an executed agreement, is not an offer of paid platform service, and should not be relied on as the terms governing an account, API call or project engagement.

Public signup and account billing are closed in the current launch posture. Platform administrators create member accounts and assign them to tenants. Any project engagement is covered by its own accepted quotation or other written agreement.

The draft will need counsel approval and an explicit effective date before it can become operative terms.

2.Operator and contact

GenCMS is developed and operated by iGears Technology Limited in Hong Kong.

  • Address: Unit 23B, Block 4, Golden Dragon Industrial Centre, 182–190 Tai Lin Pai Road, Kwai Chung, New Territories, Hong Kong.
  • Telephone: +852-2117-8811.
  • Draft-terms questions: [email protected].
  • Security reports: [email protected].

3.Current account and tenant access

Administrators create accounts and tenants, assign members to tenants, select the tenant’s Hong Kong or Canada AI gateway, and can disable members or suspend tenants. An unassigned member or a member of a suspended tenant cannot use the normal tenant workspace or its AI gateway.

Password sign-in creates a revocable HTTP-only session cookie. Account holders can inspect active sessions, revoke another session, change their password and update their name or language preference. Optional approved-IP administrator entry is disabled unless the operator explicitly configures it.

A signed-in workspace user can create scoped API keys. The plaintext secret is returned once; the server stores its hash and safe identifying metadata. Supported scopes are workspace read, workspace write, Guard scan and Composer run. Creating, listing and revoking keys remains session-only.

Session cookies and API-key secrets are credentials. This draft does not create a support, recovery or reimbursement commitment for a lost or disclosed credential.

4.What the current build does

AreaCurrent code behavior
WorkspaceStores tenant-scoped settings, activity metadata, Skill-install records, Memory collections and sources, and Agent/Workflow/App drafts.
MemoryStores source records and supplied text or metadata. It does not index, embed, retrieve, cite, export or send Memory content to a model.
Skills and draftsStores validated records and configuration only. It does not install executable packages or execute Skills, Agents, Workflows or Apps.
ComposerCan send chat through the active tenant’s assigned AIHK or AICA gateway when a ready region-locked tenant key includes chat. It does not silently fall back to another region or an external provider.
GuardRuns the shipped static rules against pasted content or selected files from an exact public GitHub repository.

Catalogue entries, marketplace labels, model comparisons, credits, pricing plans and other roadmap descriptions are product or reference previews. They are not deployed marketplace transactions or execution services.

5.Regional AI gateway

A tenant must be assigned to AIHK in Hong Kong or AICA in Canada before tenant AI access can be issued. The region cannot be changed while an active tenant AI key or cross-region cleanup remains.

When an authorized Composer request is made, the server uses the active tenant’s region-locked key and the chat alias on that assigned gateway. It does not auto-route to the other region or to an outside provider.

Composer activity can record gateway and model identifiers, timing, token counts, response status and a short failure reason. It deliberately excludes the prompt, system instruction and model output.

Outside providers such as OpenAI or DeepSeek are not a current tenant option. Any future switch requires separate controls and updated data-location and external-service terms.

6.Guard scope

Guard remote collection is restricted to exact public github.com repository targets. It does not fetch arbitrary URLs, MCP endpoints, private repositories or redirects, and the current route does not accept ZIP uploads. Pasted content is analysed directly without a network fetch.

Authenticated Guard activity may record target type, score, risk label, byte/file/finding counts or a short failure reason. It does not place the repository URL, pasted content or full report in workspace activity.

Guard reports observed static signals. A Low Risk result is not a certification or guarantee that a package is safe, complete or suitable, and Guard does not execute the scanned package.

7.No platform billing

The current site has no subscription, checkout, payment-method, invoice, credit-balance, marketplace-purchase, publisher-payout or refund system. It does not take a payment from the workspace billing screen.

iGears project services are offered at a fixed price. The quotation states the agreed scope, fee, deliverables and acceptance checks before project work starts. That quotation, not this draft page, records the commercial agreement.

8.Matters not promised by this draft

This pre-launch draft does not state an uptime or support SLA, backup schedule, disaster-recovery commitment, data-export window, deletion deadline, general data-retention guarantee, provider availability promise or API deprecation notice period.

The code exposes record-level create, update and delete operations, API-key revocation, session revocation and configurable workspace activity settings. Those functions should not be read as broader contractual guarantees.

9.Next legal step

Before public signup, billing or marketplace transactions open, counsel should replace this status disclosure with executed terms that match the production deployment and any accepted quotation, provider or payment arrangement.

Third-party component licences and attribution are listed separately on the Third-party notices page.