Terms of Service
Effective date: June 18, 2026.
Last updated: June 18, 2026.
Governing law: Federal Republic of Germany. See § 14.
Operated by: an individual developer ("Brume", "we", "us"), not a registered company. See § 1.
These Terms of Service (the "Terms") govern your use of the Brume rate-limiting service, including the marketing website at brume.run, the dashboard at app.brume.run, the application programming interfaces (APIs), the TypeScript SDK packages, and any related services operated by us (collectively, the "Service"). By creating an account or using the Service, you agree to these Terms.
1. Who is Brume
Brume is operated by an individual developer. It is not operated by a registered company, partnership, or limited liability partnership. References in these Terms to "Brume", "we", "us", or "our" refer to that individual in their capacity as operator of the Service. This matters for legal notices, dispute resolution, and indemnification, all of which are addressed below.
The Service's operational infrastructure is hosted in Frankfurt am Main, Germany, on a single VPS provided by our sub-processor Datalix.eu.
2. Eligibility
You must be at least 18 years old (or the age of majority in your jurisdiction) and have the legal capacity to enter into a binding contract under the laws applicable to you, to use the Service. If you are accepting these Terms on behalf of an organization, you represent that you have authority to bind that organization, and "you" refers to that organization.
3. The Service
3.1 What Brume provides
Brume is a hosted rate-limiting service. The Service delivers:
- A rate-limiting gateway with four algorithms (token bucket, fixed window, sliding window log, sliding window counter)
- Per-identifier overrides, long-window quotas, and block & allow lists
- Per-identifier analytics in the dashboard
- Outbound webhooks for operational events, signed with HMAC-SHA256
- A dashboard for project management, API key rotation, rule management, webhook configuration, billing, and analytics
3.2 Architectural commitments
These commitments are part of the contract, not aspirational marketing:
- No payload storage. A rate-limit check carries a namespace, an identifier, and a cost. There is no request body to log, and the Service does not write request payloads to any database, log file, or analytics pipeline.
- Ephemeral counters. Counter state lives in Redis with window-bound lifetimes; it is not an audit trail and is not written to any database.
- API keys hashed at rest. The plaintext key is returned exactly once, at creation.
- TLS-only at the edge. The dashboard and the gateway reject plaintext connections in non-test builds.
3.3 What Brume is not
The Service is not a database, not a message queue, not a job runner, not a content delivery network, not a backend-as-a-service, not an API key management product, and not a DDoS mitigation service. We do not provide SOC 2, HIPAA, GDPR Article 28 processor agreements, or contractual uptime SLAs at the current tier of the Service. We do not provide custom domains, dedicated infrastructure, private networking, or single-tenant deployments.
4. Accounts
You must provide a valid email address and a password of at least 12 characters. You are responsible for keeping your credentials secure. We will not ask for your password by email or by any direct message.
You may not share account credentials, transfer your account to another person, or use the Service through an account that is not yours.
5. Plans and billing
5.1 Plans
The Service is offered in the following tiers at the time of writing: Free (10,000 checks/day, 5 rules), Starter, Pro, and Business. Pricing is published at /pricing and may change for new customers. Existing customers keep their plan price for the duration of their current subscription.
5.2 Metering
Nothing is metered. Checks are not billed per request. Every tier is a flat rate with capacity caps. Exceeding a cap rejects the operation that would exceed it with a PLAN_LIMIT error; nothing is invoiced retroactively. The only data Brume collects about check activity is aggregate counters needed to enforce the caps and the analytics you can view in the dashboard.
5.3 Payment
Paid plans are billed in advance by Polar.sh, our payment processor. By starting a paid plan you authorize Polar.sh to charge your payment method on a recurring basis until you cancel. Polar.sh handles payment information; we never see or store your card number.
5.4 Cancellation
You can cancel a paid plan at any time from the dashboard Billing tab or directly in the Polar.sh billing portal. Cancellation stops future charges; the Service remains active until the end of the current billing period. There are no refunds for partial periods except as required by applicable consumer protection law.
5.5 Late payment and suspension
If a payment fails, we retry the payment method over a 7-day grace window. After the grace window, the affected project is downgraded to the Free tier. We are not liable for damages caused by suspension for non-payment.
6. Acceptable Use
You agree not to use the Service to:
- Violate any applicable law, regulation, or third-party right.
- Facilitate unsolicited bulk communications (spam) by rate-limiting it into legitimacy.
- Harass, threaten, or harm any person.
- Distribute child sexual abuse material (CSAM) or content that exploits minors.
- Distribute malware, ransomware, or any code designed to disrupt, damage, or gain unauthorized access to any system.
- Attempt to bypass rate limits, plan restrictions, payload size limits, or any other technical safeguard.
- Attempt to attack the Service itself, including its infrastructure, its other customers' data, or the data of its sub-processors.
- Resell the Service without our written permission, except as part of an application you ship to your own end users.
- Use the Service to train machine learning models on data that passes through it.
- Use the Service in connection with regulated data categories (health, financial, government identifiers) where the regulation requires a contractual data processing agreement that we do not currently offer.
We may suspend or terminate your account for violation of this section. We may, but are not obligated to, give you notice before suspension if the violation is causing harm to the Service or other customers.
7. Service availability and changes
The Service is provided on an as-is and as-available basis. We do not guarantee uninterrupted availability, error-free operation, or any specific uptime percentage. We may change, deprecate, or remove features at any time, with reasonable notice for breaking changes.
We will use commercially reasonable efforts to notify you of material changes by email and on the dashboard. Continued use of the Service after a change constitutes acceptance of the change.
8. Intellectual property
The Service, including its source code for the Rust gateway, the marketing site, and the dashboard, is owned by Brume. The TypeScript SDK packages (@brume/limit and the Fern-generated REST client) are open source under the MIT License; see the LICENSE file in the relevant package.
You retain ownership of data you submit to the Service. You grant us a limited, non-exclusive license to use that data solely to operate the Service for you.
Feedback you send us (suggestions, bug reports, comments) may be used by us without restriction or compensation.
9. Termination
9.1 By you
You can terminate your account at any time from the dashboard Settings tab. Termination is a 30-day grace window: during those 30 days you can sign back in and restore your account. After 30 days the account is permanently deleted and a deletion receipt is emailed to your verified address.
9.2 By us
We may terminate or suspend your account:
- For violation of these Terms.
- For non-payment after the grace window in § 5.5.
- If we are required to do so by law.
- If we discontinue the Service entirely, with 60 days' notice.
9.3 Effect of termination
On termination we delete or anonymize your personal data as described in the Privacy Policy. Aggregate, non-personally-identifiable metrics may be retained indefinitely.
10. Disclaimers
To the maximum extent permitted by applicable law, the Service is provided "as is" and "as available". We disclaim all warranties, express or implied, including warranties of merchantability, fitness for a particular purpose, and non-infringement. We do not warrant that the Service will be uninterrupted, secure, or error-free, or that the results obtained from the Service will meet your requirements.
11. Limitation of liability
To the maximum extent permitted by applicable law, Brume's total aggregate liability arising out of or relating to these Terms or the Service will not exceed the greater of (a) the total fees you paid to Brume in the 12 months before the event giving rise to liability, or (b) EUR 100.
In no event will Brume, its operators, contractors, or sub-processors be liable for any indirect, incidental, special, consequential, or punitive damages, including loss of profits, data, goodwill, or business opportunities, even if advised of the possibility of such damages.
The limitations in this section do not apply to liability that cannot be excluded or limited under applicable law, including (where applicable) liability for death or personal injury caused by negligence, fraud, or fraudulent misrepresentation.
12. Indemnification
You will indemnify and hold Brume harmless from any third-party claim arising out of (a) your use of the Service in violation of these Terms, (b) data you submit to the Service, or (c) your application that integrates with the Service.
13. Dispute resolution
13.1 Informal resolution
Before filing any formal dispute, contact us at legal@brume.run and attempt to resolve the dispute informally for 30 days.
13.2 Arbitration
If the dispute is not resolved informally, it will be resolved by binding arbitration under the rules of the German Institution of Arbitration (DIS). The arbitration will be conducted by a sole arbitrator, in the English language, with the seat of arbitration in Frankfurt am Main, Germany. The award will be final and binding.
13.3 Exceptions
Either party may bring an action in a court of competent jurisdiction for injunctive relief to prevent irreparable harm. Nothing in this section prevents either party from bringing a claim in small claims court if the claim qualifies.
13.4 Class action waiver
To the maximum extent permitted by applicable law, disputes will be brought only in an individual capacity and not as a class action, consolidated action, or representative action.
14. Governing law
These Terms are governed by the laws of the Federal Republic of Germany, without regard to conflict-of-laws principles. The mandatory consumer protection laws of your jurisdiction, if more favourable to you, will prevail over any conflicting term.
15. Changes to these Terms
We may update these Terms from time to time. Material changes will be communicated by email and on the dashboard at least 14 days before they take effect. Continued use of the Service after the effective date of a change constitutes acceptance.
16. Contact
- General:
hello@brume.run
- Legal:
legal@brume.run
- Privacy:
privacy@brume.run
- Security:
security@brume.run
Postal address is not provided. Brume is operated by an individual developer; written notices sent by email to legal@brume.run are valid notices for the purposes of these Terms.
17. Severability
If any provision of these Terms is held by a court or arbitrator to be invalid or unenforceable, the remaining provisions will continue in full force and effect, and the invalid provision will be replaced by an enforceable provision that most closely reflects the original intent.
18. Entire agreement
These Terms, together with the Privacy Policy and the Acceptable Use Policy, constitute the entire agreement between you and Brume regarding the Service, and supersede any prior agreements or understandings, whether written or oral.
19. Acceptance
By creating a Brume account or using the Service, you acknowledge that you have read, understood, and agree to be bound by these Terms.