Terms of Service
Effective 22 August 2026
1. About us
These Terms of Service (“Terms”) govern your use of Bast.sh, including the website, documentation, installer, CLI and terminal application, Bast Vault, and related APIs (together, the “Services”).
The Services are provided by ELLIPSE SOFTWARE GROUP LIMITED, a company incorporated in England and Wales with company number 16757915, whose registered office is 4th Floor Silverstream House, 45 Fitzroy Street, London, W1T 6EB, United Kingdom, trading as ellipse Software (“we”, “us”, “our”). Bast.sh is a product and hosted service of ELLIPSE SOFTWARE GROUP LIMITED.
By using the Services you agree to these Terms. If you use the Services for an organisation, you represent that you have authority to bind that organisation.
2. The software
The Bast CLI and terminal application are made available under the MIT Licence published in the public repository. Nothing in these Terms limits rights granted to you under that licence for the software itself.
These Terms govern use of our hosted Services (including bast.sh, Vault, sign-in, telemetry ingest, and sponsorship checkout) and your conduct when using Bast with those Services.
3. Vault and accounts
Vault is an optional hosted sync service. You authenticate with an email address and a one-time code. You choose a passphrase on your machine. Hosts, keys, and metadata that Vault syncs are encrypted on your device before upload. We store ciphertext and revision metadata. We cannot decrypt your vault or reset a lost passphrase so that existing ciphertext becomes readable.
You must:
- keep sign-in codes, session tokens, and passphrases confidential;
- use an email address you control;
- understand that a force passphrase reset overwrites the remote vault with this machine’s managed state and discards remote-only data;
- keep local copies and backups you need; we are not your backup provider.
You may point Bast at a self-hosted API. We are not responsible for self-hosted deployments.
4. Acceptable use
You shall not, and shall not permit anyone else to:
- use the Services unlawfully;
- probe, disrupt, or overload Vault, the website, or related infrastructure;
- bypass rate limits, authentication, or size limits;
- upload malware or content you do not have the right to store or sync;
- use the Services to attack, scan, or access systems without authorisation;
- resell hosted Vault as a service to third parties without our written agreement.
You are responsible for how you use Bast to reach your own servers and for complying with the terms of AWS, Google Cloud, Microsoft Azure, and any other provider you connect.
5. Sponsorships
Sponsorship payments on bast.sh are voluntary contributions to support development. Unless we state otherwise at checkout, they do not buy a subscription, extra Vault capacity, an SLA, or a licence beyond the MIT Licence.
Payments are processed by Stripe. Amounts are in US dollars. The charge may appear as Bast or ELLIPSE SOFTWARE GROUP LIMITED. We do not store full card numbers. Sponsorships are non-refundable except where law requires otherwise.
6. Intellectual property
We and our licensors own the Bast.sh name, site, documentation, and hosted service (other than your vault contents and materials you submit). The CLI remains available under the MIT Licence.
You retain ownership of data you encrypt into Vault and of content you submit as a sponsorship message. You grant us a licence to store and transmit vault ciphertext to provide the service, and to display a public sponsor name, handle, amount, and message if you do not opt to remain anonymous.
7. Third-party services and marks
Amazon Web Services, AWS, Google, Google Cloud, Microsoft, Azure, Upstash, Stripe, Cloudflare, GitHub, OpenSSH, Termius, PuTTY, MobaXterm, SecureCRT, Vercel, PostHog, Sentry, Better Stack, and other product or company names used on this site are trademarks or registered trademarks of their respective owners. We do not own those marks. Their use is for identification only and does not imply any affiliation, sponsorship, or endorsement.
The Services may depend on third-party infrastructure, APIs, and software. Your use of those providers is subject to their terms. We are not responsible for failures, changes, or security incidents at providers outside our reasonable control.
8. Privacy
Our Privacy Policy explains how we process personal data. Each party must comply with applicable data protection law. You are responsible for the lawfulness of data you choose to sync, including any personal data in host labels or notes.
9. Availability and changes
Hosted Services are provided without a service level commitment unless we agree one in writing. We may modify, suspend, or discontinue Vault or any part of the Services. Where practicable we will give notice of material withdrawals.
Preview, nightly, and experimental builds may be incomplete or withdrawn at any time.
10. Warranties
The software is provided under the MIT Licence “as is”. For hosted Services we will use reasonable skill and care. Except as required by law, we do not warrant that the Services will be uninterrupted, secure, or error-free, or that vault ciphertext can be recovered without your passphrase.
Nothing in these Terms excludes statutory rights that cannot be excluded, including rights of consumers under UK law.
11. Liability
Nothing in these Terms limits or excludes liability for death or personal injury caused by negligence, fraud, or any liability that cannot legally be limited.
Subject to that, we are not liable for loss of profit, revenue, business, goodwill, opportunity, or data, or for indirect or consequential loss. Our total aggregate liability arising out of the hosted Services is limited to the greater of £100 and the sponsorship amounts you paid us in the 12 months before the claim.
You are responsible for SSH access, key handling, and the systems you connect to. Unauthorised access to machines is your responsibility, not ours.
12. Suspension and termination
We may suspend or terminate hosted access if we reasonably believe there is a security threat, abuse, legal risk, or a material breach of these Terms. You may stop using Vault by logging out. Logging out does not delete remote ciphertext; request deletion as described in the Privacy Policy.
Clauses that by their nature should survive (including intellectual property, liability, and governing law) remain in force.
13. Governing law
These Terms and any dispute or claim arising out of them are governed by the laws of England and Wales. The courts of England and Wales have exclusive jurisdiction, except that consumers may also bring proceedings in the courts of their UK country of residence where required by law.
14. General
If a provision is unenforceable, the rest remains in force. We may update these Terms by publishing a new version at bast.sh/legal/terms. Continued use of the hosted Services after the effective date constitutes acceptance of the updated Terms where the law allows.
These Terms do not create a partnership, agency, or employment relationship. A person who is not a party has no rights under the Contracts (Rights of Third Parties) Act 1999.
15. Contact
Legal notices: [email protected]
ELLIPSE SOFTWARE GROUP LIMITED
4th Floor Silverstream House, 45 Fitzroy Street, London, W1T 6EB, United Kingdom