These Terms govern access to and use of Qryvios, including guest access, registered accounts, dataset uploads, SQL query processing, query history, charts and exports.
By accessing or using the Service, you agree to these Terms. If you do not agree, do not use the Service.
If you use the Service on behalf of an organization, you represent that you have authority to bind that organization to these Terms.
Any additional commercial order form, enterprise agreement or written agreement signed with the operator may supplement or override these Terms where expressly stated.
The Service allows users to upload supported datasets, run read-only analytical SQL queries, inspect results, create charts, maintain query history and export data or visualizations.
Users may begin as guests without creating an email account. Registered users authenticate using Amazon Cognito email-and-password authentication.
SQL execution is performed on backend infrastructure using a restricted DuckDB worker. Query jobs may be processed asynchronously and may pass through QUEUED, RUNNING, COMPLETED, FAILED or CANCELLED states.
Chart and dashboard configuration is currently frontend-owned and may be stored in browser application state or localStorage rather than the backend.
You must be at least [MINIMUM AGE] years old, or the minimum age required by applicable law to use an online service without parental consent.
You must have legal authority to upload, process, query and export all data you submit to the Service.
You may not use the Service if applicable law prohibits you from receiving or using it.
When you use the Service without signing in, the Service may create a backend-generated guest identity and a visible Guest ID. The Guest ID is a reference identifier; it is not, by itself, proof of ownership or a password.
The Service may maintain a separate secure guest session credential, such as a Secure HttpOnly cookie, to prove the active guest session.
Where the Secure Guest Access feature is enabled, you may create an access code or similar credential so that an existing guest can authenticate again. You are responsible for keeping that access code confidential. The operator should store or verify such credentials using appropriate secure credential handling and should not treat the public Guest ID as the secret.
If you lose the guest session and any enabled recovery/access credential, the Guest ID alone may be insufficient to recover guest-owned datasets or query history.
When a guest creates or signs into a registered account, the Service may link the guest identity and resources to that account. Linking may retain the original Guest ID as an audit/reference identifier.
Registered users authenticate using email and password through Amazon Cognito. Email verification may be required.
The Service derives registered identity from the verified Cognito user identifier rather than trusting an email address or user-supplied ownership identifier.
You are responsible for safeguarding your account credentials and for activity occurring through your account, except to the extent caused by a security failure for which the operator is legally responsible.
Notify [SECURITY / SUPPORT EMAIL] promptly if you believe your account or guest access credential has been compromised.
You retain ownership of datasets, SQL text, chart configurations, exports and other content you submit or create, subject to rights held by third parties.
You grant the operator a limited, non-exclusive license to host, copy, transform, validate, process, query and transmit your content only as reasonably necessary to provide, secure, maintain and improve the Service and to comply with law.
You are responsible for ensuring you have all required permissions and lawful bases to upload and process personal, confidential, proprietary or regulated data.
Do not upload data that the Service is not designed or contractually approved to handle, including highly sensitive regulated data, unless the operator has expressly confirmed support for that data category.
Supported uploads may include CSV, XLSX and JSON files, subject to configured type, size, schema and quality limits.
Uploaded data may be validated, normalized and converted into an analytics-friendly representation such as Parquet before it becomes queryable.
The SQL service is intended for read-only analytics. The Service may reject statements or capabilities that create, modify, attach, install, load, delete or externally access resources.
The Service may enforce SQL length, query runtime, result-row, result-size, concurrency, rate and storage limits to protect security, reliability and cost.
Each execution may create a persistent query record containing SQL text, dataset reference, status, timestamps, duration, row count, result locations and safe error information.
You must not use the Service to violate law, infringe rights, process data you are not authorized to use, distribute malware, or facilitate abusive or deceptive activity.
You must not attempt to bypass ownership checks, access another principal's datasets or query history, exploit the SQL engine to reach arbitrary files or networks, defeat execution limits, or interfere with Service security.
You must not probe, scan or test the vulnerability of the Service except under an authorized security-testing program.
You must not intentionally submit workloads designed primarily to exhaust compute, queue, storage or network resources, or circumvent rate/concurrency limits.
You are responsible for the legality and accuracy of any data you upload and for decisions you make from query or chart outputs.
Exports may include CSV, JSON, PNG, SVG, configuration files, PDF where supported, and read-only standalone HTML.
Exports are generated from the current resolved data/chart state. You are responsible for reviewing exports before sharing them and for ensuring recipients are authorized to receive the included data.
Standalone HTML is designed for read-only viewing. It should not contain SQL execution, DuckDB, chart-authoring controls, dataset-upload controls, authentication tokens, guest tokens, pre-signed URLs or internal service secrets.
An exported file may contain the data necessary to render a chart or reproduce the selected result. Downloading or sharing an export is an intentional disclosure by you to the destination or recipient you choose.
The Service may impose technical limits and may change supported file types, chart types, query features, retention, storage, execution limits or export capabilities over time.
Asynchronous query processing means completion times may vary due to queue depth, dataset size, query complexity, service limits or cloud-provider conditions.
The operator does not guarantee uninterrupted or error-free availability and may conduct maintenance, suspend features or discontinue preview/beta capabilities.
The Service is designed with owner-scoped authorization, restricted SQL execution, server-side storage controls and cloud security measures, but no system can guarantee absolute security.
You must use reasonable measures to protect credentials, guest access codes, downloaded datasets and exported files.
You must not publish Guest IDs together with any guest access credential or other authentication secret.
The operator and its licensors retain all rights in the Service software, design system, documentation, trademarks and other operator-created materials, excluding your content.
Unless expressly licensed, these Terms do not grant you rights to copy, resell, reverse engineer or create derivative commercial services from protected operator technology beyond what applicable law permits.
Any separately published npm package or open-source component is governed by its own package/license terms.
The Service relies on third-party infrastructure, including Amazon Web Services components such as Cognito, API Gateway, Lambda, DynamoDB, SQS, S3 and CloudWatch. Third-party outages or policy changes may affect the Service.
The operator may add or replace service providers where reasonably necessary. Material privacy-related changes should be reflected in the Privacy Policy or subprocessor disclosures.
The operator may suspend or terminate access if reasonably necessary to protect the Service or other users, respond to security incidents, enforce these Terms, comply with law or address non-payment under a future paid plan.
You may stop using the Service at any time. Registered users should be provided an account-deletion process before production launch.
Guest access may expire or become unrecoverable if the guest session or enabled access credential is lost or expires.
Dataset, query-result, query-history, account and log retention are subject to the Privacy Policy and configured lifecycle/TTL rules.
Before publication, the operator must define production retention periods and deletion behavior, including treatment of backups, logs, guest audit mappings and linked Guest IDs.
Deletion may not immediately remove information from transient caches, disaster-recovery backups or security logs where retention is necessary and lawful.
The Service is an analytics tool and does not provide legal, financial, medical, compliance or other professional advice.
Query results, visualizations and exports depend on user-provided data, SQL, configuration and software behavior. You are responsible for validating important outputs before relying on them.
TO THE MAXIMUM EXTENT PERMITTED BY LAW, THE SERVICE IS PROVIDED "AS IS" AND "AS AVAILABLE" WITHOUT WARRANTIES NOT EXPRESSLY STATED IN A SIGNED AGREEMENT.
TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, THE OPERATOR WILL NOT BE LIABLE FOR INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL OR PUNITIVE DAMAGES, OR FOR LOSS OF PROFITS, REVENUE, BUSINESS, GOODWILL OR DATA, ARISING FROM USE OF THE SERVICE.
Any overall liability cap, exclusions and mandatory consumer-law carve-outs must be finalized for the operator's jurisdiction before publication. Suggested placeholder: [LIABILITY CAP / COMMERCIAL TERMS].
To the extent permitted by applicable law, you agree to be responsible for claims arising from your unlawful use of the Service, infringement by data you submit, or violation of these Terms. Consumer users may have non-waivable rights that override this clause.
The operator may update these Terms. Material changes should be communicated through the Service, email, or another reasonable channel before they take effect where required by law.
The document should display the effective/last-updated date.
These Terms are governed by [GOVERNING LAW / JURISDICTION], subject to any mandatory consumer or privacy rights that cannot be waived.
Dispute venue, arbitration, mediation or court-jurisdiction provisions should be added only after legal review for the intended markets.
Operator: [OPERATOR / COMPANY LEGAL NAME]
Address: [REGISTERED / BUSINESS ADDRESS]
Support: [SUPPORT EMAIL]
Legal notices: [LEGAL EMAIL]
See also the Privacy Policy.