Legal

Terms of Service

Effective 9 September 2026 · Privacy Policy

The short version

Onlay lets you publish a document to a URL so that other people, and your agent, can read it, comment on it and edit it. You keep ownership of everything you publish or post. You give us permission to host it, store it and show it to the people you share it with, including any images you attach to comments. Don't use Onlay for anything illegal, deceptive or harmful, and don't publish things you have no right to publish. We can remove content or close accounts that break these rules. The service is provided as is.

1. Who we are, and who you are

Onlay is operated by Onlay Ltd, a company registered in Scotland ("Onlay", "we", "us"). You can reach us at hello@onlay.io.

These terms are an agreement between you and Onlay. They apply whenever you use the Onlay service: the website at onlay.io, the dashboard at app.onlay.io, the onlay command-line tool, the documents served from onlaycontent.com and any custom domain, and the software we inject into those documents so that you can comment on and edit them. If you use Onlay on behalf of a company or another organisation, you confirm that you have authority to accept these terms for it, and "you" means that organisation as well.

You need to be at least 16 years old to create an account or post content.

2. The service

Onlay is a feedback loop for documents. An author, usually with a coding agent, publishes an HTML or Markdown file with the CLI. Onlay serves it at a permanent URL. People who open that URL can read it, select text and leave comments, attach images to those comments and, where the author allows, edit the text in place. The author pulls all of that back down as structured feedback with the same CLI.

The service is in active development. Features change, and some are experimental. We will do our best to warn you before removing something you rely on, but we cannot promise that every feature will remain available.

3. Accounts and API keys

You do not need an account to read a document, and by default you do not need one to comment on one. You need an account to publish, to manage your documents and to comment on documents whose author has chosen to require it.

Accounts are created and signed in through Clerk, our identity provider. You are responsible for keeping your sign-in method secure and for everything that happens under your account. API keys issued in the dashboard are secrets: keep them out of shared repositories and revoke any key you think has leaked. Anything published with your key is treated as published by you.

4. Your content

"Your content" means everything you put into Onlay: the documents you publish, the edits you make, the comments you write and the images you attach to them.

You own your content. These terms do not transfer ownership of anything to us. What they do is give us the permission we need to run the service, described in the next section.

You are responsible for your content. By posting it you confirm that you have the rights needed to post it and to give us the licence below, that it does not infringe anyone else's rights, and that it does not contain anything you are not allowed to share, such as other people's personal data or confidential information you hold under an obligation of secrecy.

5. The licence you give us

To run Onlay we have to copy your content, keep it on our servers and show it to other people. So, for every piece of content you post, you grant Onlay a worldwide, non-exclusive, royalty-free licence to host, store, reproduce, transmit, display, distribute and adapt that content for the purpose of operating, securing and improving the service. "Adapt" here means the technical processing the service does: rendering Markdown to HTML, injecting the commenting runtime into a page, re-encoding and resizing an image, indexing text so that a comment can be anchored to it, and similar. It does not mean rewriting your document.

Images attached to comments. When you paste or upload an image into a comment, you grant us the same licence for that image. In particular you agree that we may store it, serve it from the document's own web address and display it to everyone who can see the document it was posted on, including the document's author and any agent the author uses to pull feedback. Images are re-encoded before upload so that metadata such as location data is not kept; see the Privacy Policy for how they are handled.

This licence lasts for as long as the content is on the service. When you delete a comment or a document, or we remove it, the licence ends for that content, except that copies may remain in backups for a limited period and other people may already have pulled a copy of the feedback they were entitled to see.

Comments on someone else's document. A comment belongs to the conversation on the document it was left on. The author of that document may read it, pull it, act on it, share it with their tools and keep it, and other people who can see the document may see it. Do not post something in a comment that you would not be happy for the author to have.

You also give other users of the service permission to view your content, and to comment on and edit it, to the extent that you have chosen to allow that on each document.

6. Sharing and visibility

Each published document has a URL. Unless you set it otherwise, anyone who has the URL can open the document, and anyone who can open it can comment on it. The URL is not listed anywhere by us and is not guessable, but it is only as private as the people you send it to. If you need more control, the CLI lets you require an account to comment, restrict commenting or editing to people you invite, or turn commenting off.

Feedback on a document flows back to whoever holds the document's API key. If you are commenting on a document that someone else published, assume the publisher will see everything you post, along with the name you gave when you posted it.

7. Acceptable use

You may not use Onlay to publish, post or share anything that:

You also may not try to get around the limits or protections of the service, share access to an account or key with people who are not entitled to it, scrape other people's documents at scale, or resell the service without our written agreement.

Content that comes out of an automated tool is still your content. If your agent publishes it under your key, you are responsible for it.

8. Removal and termination

We may remove or stop serving any content, and suspend or close any account, if we reasonably believe it breaks these terms, creates a legal or security risk for us or for other people, or if we are required to by law. Where we can, we will tell you why. For abuse that puts other people at risk, such as phishing, we act first and explain afterwards.

You can delete your own comments and documents at any time, and you can ask us to close your account by emailing hello@onlay.io. We may also stop offering the service altogether, in which case we will give reasonable notice where we can so that you can pull your content.

To report a document that breaks these rules, such as phishing, a scam or malware, see Report a document or email abuse@onlay.io with its URL. If you believe content on Onlay infringes your rights, email the same address with the URL, what you believe it infringes and how we can reach you.

9. Fees

Publishing on the free plan costs nothing. The Pro plan is a subscription, billed monthly or yearly in US dollars at the price shown before you buy, and it renews until you cancel it from your account. Payments are processed by Stripe through Clerk; we do not see or store your card. When a subscription ends, your documents and links stay, and the features the plan enabled stop at the end of the paid period: documents you published with outbound network access are served with approved hosts only, and camera, microphone and location access is switched off. Subscribing again restores them. Nothing you already have on the free plan will start costing money without clear advance notice.

10. The CLI and the runtime

We provide the onlay command-line tool and the script that is injected into published documents so that you can use the service. You may use them for that purpose. They run on your machine and in your browser respectively; the CLI reads and writes files you point it at and talks to our servers, and it does not collect usage data beyond what those requests carry. Open-source components included in them are covered by their own licences.

11. No warranty, and limits on our liability

The service is provided "as is" and "as available", without warranties of any kind, whether express or implied, including any warranty of merchantability, fitness for a particular purpose or non-infringement. We do not promise that the service will be uninterrupted, error-free or secure, or that content will never be lost. Keep your own copies of anything that matters; the CLI makes that easy.

To the fullest extent the law allows, Onlay will not be liable for any indirect, incidental, special, consequential or punitive damages, or for lost profits, revenue, data or goodwill, arising out of or in connection with the service, however caused. Our total liability to you for all claims relating to the service is limited to the greater of the amount you paid us in the twelve months before the claim and one hundred pounds sterling.

Nothing in these terms excludes liability that cannot be excluded by law, and nothing in them limits any rights you have as a consumer that the law says cannot be limited.

You agree to indemnify Onlay against claims by third parties, and the reasonable costs of dealing with them, that arise from content you posted or from your breach of these terms.

12. Changes to these terms

We may update these terms. For material changes we will give notice on the site or by email to account holders at least fourteen days before the change takes effect. The date at the top tells you when the current version started to apply. If you keep using the service after a change takes effect, you accept the new terms; if you don't accept them, stop using the service and, if you like, pull your content first.

13. Governing law

These terms are governed by the laws of Scotland, and any dispute that cannot be resolved between us will be brought before the Scottish courts. If you are a consumer living elsewhere in the United Kingdom or in another country, you may also rely on the mandatory consumer-protection rules of the place you live in, and bring a claim in its courts.

14. Contact

Questions about these terms: hello@onlay.io.