What this is
nth Labs is a testing tool. Ten agents drive a real browser against a product you point it at, file what they find with the steps and the screenshot that produced it, and turn a finding you confirm into a check that runs again. Some of that work is deterministic. The rest needs a model, which runs on an API key you supply.
nth Labs comes two ways: a hosted console at console.nthlabs.dev, and software you run on your own machine or server. Both are in beta, and these terms cover both.
Creating an account or running the software means you agree to what is on this page. If you do not, do not use it.
Who this is with
“You” is whoever creates the account or runs the software. Doing either for a company means you are agreeing on that company’s behalf, and that you are allowed to.
“We” and “us” mean the operator of nth Labs: [operating entity: to be named].
That blank is real and it is not filler. The entity behind the beta is not settled, and a
plausible name typed in to close a gap is the exact kind of unchecked claim this product
exists to find. Whoever it turns out to be answers at
hello@nthlabs.dev, and the clauses that lean on it
(the licence, the cap, the indemnity, the governing law) are read against them.
Your account
You must be 13 or older to create an account, or older if the law where you live says so. Under 18, a parent or guardian has to be the one who agrees to these terms for you, and any payment or API key is theirs. The 13 is not a content rating: it is where children’s data law begins, and this side of it is the side that does not require your parents to sign consent forms.
An account is one person. Give it an address you can actually be reached at, keep your password and your sign-in to yourself, and tell us if either stops being yours. What happens under your account is treated as yours, including a run somebody else started with your credentials. Working with other people is what workspaces are for, and they have their own section below.
You can sign in with an email and password, or through Google or GitHub. Those are sign-in only. We ask for your email address and the basic profile that comes with it, and for nothing else: we neither read nor write anything else in your account there.
Only test what you are authorised to test
This is the rule that matters most, so it is the longest one here.
You may only point nth Labs at a product you own, or one whose owner has explicitly given you permission to test it. Permission means somebody who can give it has given it, for automated testing, before the run starts. A public URL is not permission. A bug bounty page is not permission unless it says browser automation is in scope.
Automated browsing of someone else’s site without authorisation may violate their terms and, depending on where you are, the law. You are responsible for every target you configure and every credential you hand it, on every run, scheduled runs included, which fire with nobody watching.
Each time a run starts you are warranting that you hold that authorisation, and that you understand what the agents do with it. They act as you: they fill in forms, press buttons, submit them, sign in with the credentials you gave them, and can create, change or delete data in the product they are pointed at. Whatever they do there, you did.
Said as plainly as an indemnity can be said: if you point it at something you were not allowed to, whatever comes of that is yours. You agree to stand between us and any claim that your use of the tool caused, and to cover what defending it costs.
Practically: point them at staging or a preview deployment where you can, and give a signed-in run an account you would not mind an intern using.
Acceptable use
Beyond the authorisation rule, there are things you may not do with the service or the software.
- Use it to attack, overload or interfere with anything: ours, a stranger’s, or a product you genuinely do have permission to test.
- Work around the guard that decides where a run may point. The guard resolves a target and refuses private, loopback and link-local addresses, and it exists because a browser running inside a shared console can otherwise be aimed at that console.
- Work around plan limits, seat counts, the credit ledger, or anything else that meters what an account may spend on our key.
- Resell or sublicense access, or run the service for other people as though it were yours.
- Reverse engineer, decompile or disassemble the software, except where the law where you live says you may anyway.
- Scrape the console, or drive it with anything other than the interfaces we publish.
- Remove or obscure a copyright, licence or brand notice.
- Break the law with it, or help somebody else do so.
Benchmarking is the one people expect to find banned here, and it is not. Publish what you measure, including the parts that come out badly. Say which version you ran, and show the method.
Your API key, your costs
The console is free to use on your own key. That is the whole arrangement, not a trial of one: bring a key and the model-driven agents are never metered, never capped and never billed by us. The only bill is the provider’s, to you. The deterministic agents cost nothing to anybody and need no key at all.
Model analysis runs on the key you supply, and which company receives the run depends on the model you pick. The catalogue spans Anthropic, OpenAI, Google, Mistral and OpenRouter, and the default model today is an OpenAI one, so a run you do not change the model on goes to OpenAI. Whichever you choose, what the run sends is governed by that provider’s own terms (Anthropic’s among them) and billed by that provider to you.
The hosted console can instead run on prepaid credits, which are spent in dollars against the console’s own key as runs record their usage. During the beta we grant those by hand, so write and ask. When credits run out, runs that need a model stop and say so; the deterministic modules keep running either way.
Costs shown in nth Labs are estimates, built from the usage a run reports and the prices we hold on file. The provider’s invoice is the real number. nth Labs is not affiliated with Anthropic or with any other model provider.
Plans, prices and tax
A plan sets what an account may do: how many projects it may hold, how many seats a shared workspace may fill, and how much monthly spend on our key is included. The included allowance resets each month and does not accumulate. Credits are a separate pool and are not touched by that reset.
Prices are quoted where a plan is offered, and they are exclusive of tax. Nothing is sold on a recurring basis during the beta: a plan is set by hand and credits are bought one payment at a time. If we change a price, the change applies to what you buy afterwards and never to something already paid for.
Tax is yours. The amount you enter at checkout is the amount charged, and we do not add or collect VAT, GST or sales tax. If tax is due where you are, accounting for it is your side of this. That is a description of what the checkout does today, not advice about what you owe.
Credits, refunds and leaving
Credits are the alternative for people who would rather not manage a key: they are prepaid, and they do not expire. During the beta there is no self-serve way to buy them. We grant them by hand, so write to support@nthlabs.dev. Today no card is charged for credits at all, and the paragraphs below describe what happens when that changes rather than something running now.
When purchasing opens, payments will be processed by Stripe on Stripe’s own checkout page: your card number goes to Stripe and never touches this console, and what the console keeps is the ledger entry the payment authorised. Unspent credits are refunded on request, to the card that paid, no reason needed, with one exception stated plainly rather than buried: if an account is ended for breaking the authorisation rule below, credits spent on that abuse are not refunded. Spent credits are otherwise spent: they bought model calls that already ran.
Nothing renews. There is no subscription in the beta and nothing charges on a schedule, so there is nothing you have to remember to cancel. Leaving is Settings, then Danger zone, and it takes your data with it, as the privacy policy describes.
If we ever close the beta or shut the service down, account holders hear first and unspent credits are refunded without being asked.
Workspaces and seats
A workspace is how more than one person works on the same projects. A workspace has an owner, and for that workspace the owner is who we are contracting with: the plan, the credits and the bill are theirs.
The API keys belong to the workspace, not to the person pressing Run. A teammate who starts a run spends the workspace’s key and the workspace’s credits. That is deliberate, because a key that followed whoever pressed Run would bill a teammate for somebody else’s work, and it is worth knowing before you invite anyone.
Roles are owner, admin, member and viewer, and they can do different amounts. A viewer reads findings and cannot start a run, because a run costs somebody real money. Seats are counted including the owner, and the plan sets how many there may be.
Inviting somebody means you are satisfied they may see what is in that workspace, including the findings, the screenshots and the stored sign-in details for the products it tests. Everyone who joins agrees to these terms for themselves. The owner stays responsible for the workspace: for what its members do with it, for the authorisation rule on every target it holds, and for the bill.
Who owns what
We own the software. The code, the agents, the finding schema, the console, this site, the name and the mark are ours, and nothing here hands any of it over. The software is licensed, not sold.
You own your side. Your product, your code, your content, your findings, your verdicts, your guards and the memory a project builds up are yours. Nothing here claims a licence over your product or over the things the tool produces about it, and your findings are not training data.
What we may do with your data, and only this. To run the service for you we need to store what you put into it, show it back to you, send what a module needs to the model provider whose key was used, and make it visible to the people you invite. That is the whole licence. The licence lasts as long as you keep the account, and it exists so the product can work rather than so we can do anything else with it.
Your licence to the software. While your account is in good standing and these terms are kept, you may use the hosted console, and you may install and run the software on your own machines to test your own products and your clients’ products. You may not copy it beyond that, modify it past configuring it, distribute it, or sublicense it. The licence is personal to you, non-exclusive, non-transferable and revocable, and it ends when your right to use the service ends.
Feedback. Send us a suggestion, a bug report or an idea and we may use it, build it and ship it, owing you nothing for it. If you want to keep an idea, do not send it. The clause is here for the ordinary case rather than the dramatic one: an open inbox means people write in with good suggestions, and something we were already building should not turn into a dispute because somebody mentioned it first.
Your data
You can take a copy at any time. Reports export as one HTML file, guards export as standalone Playwright specs that run without us, and if you want the rest of it, email and you get it.
Deleting a project or an account removes it from every live path at once: the record goes, sessions end, and it stops appearing anywhere in the console. The directory behind it is moved to a recycle bin and purged thirty days later, so that somebody who pressed the wrong button can be helped in the days afterwards instead of being told about last night’s backup. Nothing in that bin is reachable from the console, and after the window it is gone for good.
See the privacy policy for what is stored where, and who else ever sees it.
Third-party services
nth Labs is built on other people’s services. Where one of them is involved, its terms apply to that part.
- Model providers: Anthropic by default, and OpenAI, Google, Mistral or OpenRouter if you configure a key for one. What a run sends goes to the provider whose key it used, under that provider’s terms.
- Stripe, for payments. Card details go to Stripe and never to us.
- Railway, where the hosted console runs, and Vercel, where this site is served.
- Google and GitHub, if you sign in through one of them.
We are not affiliated with any of them and we do not control them. If one has an outage, changes its prices, changes its terms or stops serving us, we are not liable for what that costs you, though we will say what happened and what we are doing about it.
Availability
There is no service level agreement, and during the beta there is not going to be one. Nothing here promises uptime, a response time or a support window. The console fires scheduled runs and needs maintenance, so it will be unavailable sometimes with notice and sometimes without.
We may change the product: add modules, retire them, change how one works, change a limit, or stop offering something. Where a change takes away something you were relying on we will tell account holders before it happens if we can. We may discontinue the service entirely, in which case the refund position above applies, and applies without you having to ask.
A copy you run yourself keeps running. Nothing in it phones home to check whether it still may.
Beta, honestly
This is beta software provided as it is, without warranty of any kind: no warranty of merchantability, fitness for a particular purpose, title, non-infringement, accuracy, or uninterrupted or error-free operation. Findings are evidence-backed but not guarantees: a clean run is not a promise that your product has no defects, and it is not a substitute for your own judgement before you ship. Agents miss things, and a model can be confidently wrong.
To the maximum extent permitted by law, liability is limited to the amount you have paid us in the twelve months before the claim. If you have paid nothing, that is nothing. Neither of us is liable to the other for indirect, incidental, special or consequential loss, or for lost profits, lost revenue, lost data, or the cost of buying a substitute, including damage done to a product a run was pointed at, which is the case the authorisation rule exists for.
Some places do not allow parts of that to be excluded. Where that is so, this applies as far as it lawfully can and no further, and nothing here excludes liability for fraud, for death or personal injury caused by negligence, or for anything else that cannot be signed away.
Indemnity
You agree to defend us against, and to cover, any claim, loss or cost arising from a target you were not authorised to test, your breach of these terms, your use of the service, anything done under your account or in a workspace you own, and your own product or content.
How that works in practice, because an indemnity with no procedure is unworkable: we tell you about a claim promptly, you run the defence with counsel we can reasonably accept, we cooperate at your cost, and neither of us settles in a way that admits fault for the other or binds them without their agreement. We may join the defence with our own counsel at our own expense.
Suspension and termination
You can stop at any time: Settings, then Danger zone, or simply stop using it. A copy you run yourself is yours to delete.
We can suspend an account straight away where a run is doing harm, where a target looks unauthorised, where a payment fails or is disputed, or where the law requires it. For anything fixable, we say what is wrong and give you a fair chance to fix it before going further. Either of us may end this for convenience with thirty days’ notice, by email to the address on the account.
Ending for convenience refunds unspent credits. Ending for the authorisation rule or another serious breach does not: credits tied to the abuse are the one kind that is not refunded. Either way you get thirty days from the notice to export your data before it is removed, unless the law or the harm being done makes waiting impossible.
Some of this outlives the account, and has to. The authorisation warranty and the indemnity for what you did while you had one, the limits on liability, who owns what, the feedback licence, the governing law and the dispute clauses, and anything else that plainly needs to, all survive. A cap that dies with the agreement caps nothing.
Governing law and disputes
These terms, and any dispute about them or about the service, are governed by the law of the Province of Ontario and the federal laws of Canada that apply in it, without regard to conflict-of-law rules, and the courts of Ontario have exclusive jurisdiction over them. That is where nth Labs is operated from today. If it is later incorporated elsewhere, this section changes and the change is announced the way any other material change is. Nothing here moves quietly.
Before either of us files anything, write. Send it to hello@nthlabs.dev and give us thirty days to answer. Most of what gets this far is a misunderstanding about a charge or about what a run did.
You keep the right to bring a qualifying claim in a small-claims court where you live. Nothing here removes a right the law where you live gives you and does not let you sign away: if you are a consumer, your local consumer protection still applies, whatever this section says.
There is no arbitration clause here, and no class-action waiver. Plenty of agreements this size have both. If we ever add one it will arrive with the notice these terms require, and it will not reach back over anything that already happened.
Changes to these terms
These terms will change as the beta matures, and the blanks above are the plainest evidence of that. Material changes are announced to account holders before they take effect, by email to the address on the account, and the date at the top of this page moves. Smaller ones (a clearer sentence, a corrected link) go in when they are written.
If a change does not suit you, stop using the service before it takes effect and ask for your unspent credits back. Carrying on afterwards is how you accept it.
The rest
If a clause turns out to be unenforceable, it is cut back to what is enforceable or dropped, and the rest of this stands.
These terms and the privacy policy are the whole agreement between us about the service, and they replace anything said before them in an email, a demo or a page on this site. A marketing sentence does not override a clause here.
We may transfer this agreement to whoever takes the business on: a sale, a merger, or the new entity when the blanks above are filled. You may not transfer yours without our written agreement.
Not enforcing something once does not mean we have given it up. Nothing here makes either of us the other’s partner, agent or employer.
Questions, or anything that reads as unfair: hello@nthlabs.dev.
This is a plain-language beta agreement written by the people who build the product. This page is not legal advice, and three blanks in it are still open: the operating entity, the governing law and the venue. This agreement will be replaced by a full agreement, with those filled in, before general availability.