Terms of Service
1 hour before launch, because we had to
1. Agreement to these Terms
These Terms of Service ("Terms") are a binding agreement between Phyllis AI Pty Ltd (a company incorporated in Australia; "Phyllis", "we", "us", or "our") and the individual or organisation that accesses or uses Phyllis ("you", "your", or "Customer"). By creating an account, signing in, or otherwise using the Service, you agree to these Terms and to our Privacy Policy. If you are agreeing on behalf of an organisation, you represent that you have authority to bind it. If you do not agree, do not use the Service.
Where you have a signed enterprise agreement or order form with us, that agreement governs and prevails over these Terms in any conflict.
2. The Service
Phyllis is an AI-agent product that helps teams plan, build, and operate ServiceNow workloads, delivered through phyllis.app and the Phyllis platform together with supporting documentation and support channels (the "Service"). We may update, improve, or change the Service over time; if we materially reduce core functionality we will give reasonable notice.
3. Eligibility and accounts
- You must be at least 18 years old and able to form a binding contract.
- You are responsible for the accuracy of your registration details, for safeguarding your credentials, and for all activity under your account. Enable multi-factor authentication where offered.
- You are responsible for your authorised users' compliance with these Terms.
- Notify us promptly at security@phyllis.app of any suspected unauthorised access.
4. Your content and connected instances
"Customer Data" means the prompts, ServiceNow records and metadata, and other material you submit to, or instruct the Service to access. "Connected Instance" means a third-party system — in particular a ServiceNow instance — that you connect and authorise the Service to read from or write to.
- As between you and us, you retain all rights in your Customer Data. You grant us the limited rights needed to operate the Service for you.
- We act as your processor for Customer Data and process it on your behalf and on your instructions, as described in our Privacy Policy and any Data Processing Addendum.
- You are responsible for having the rights and authority to connect each Connected Instance and to authorise the actions you direct the Service to perform on it.
- We access a Connected Instance only within the scope you grant through OAuth, and only to perform the actions you instruct.
5. AI output and your responsibility
The Service uses AI to generate plans, proposed records, code, and configuration changes ("AI Output"). AI Output may be inaccurate, incomplete, or unsuitable for your environment. You are responsible for reviewing AI Output before it is applied, and for any change that is applied to a Connected Instance under your account. We do not warrant that AI Output is correct, and AI Output does not constitute professional, legal, or compliance advice. You should maintain appropriate testing, change-control, and backups for your instances.
6. Acceptable use
You must not, and must not permit anyone to:
- use the Service unlawfully, or to infringe or misappropriate the rights of others;
- attempt to gain unauthorised access to the Service, other customers' data, or our systems, or probe or test our security without authorisation;
- interfere with or disrupt the integrity or performance of the Service, or circumvent usage limits;
- reverse engineer the Service except to the extent that restriction is prohibited by law;
- use the Service to build a competing product, or resell it without our written consent;
- submit malware, or content you have no right to submit.
7. Fees
Paid plans are governed by the order form or plan you select. Unless stated otherwise, fees are payable in advance, are non-refundable except where required by law, and exclude taxes, which you are responsible for. We may suspend the Service for non-payment after reasonable notice.
8. Intellectual property
We and our licensors own all rights in the Service, including its software, models, and documentation. We grant you a non-exclusive, non-transferable right to use the Service during your subscription, subject to these Terms. You own your Customer Data; AI Output generated for you is yours to use, subject to your payment of applicable fees and to any rights in underlying third-party materials. Feedback you give us may be used without restriction.
9. Confidentiality
Each party may receive the other's confidential information. The receiving party will use it only to perform under these Terms, protect it with reasonable care, and not disclose it except to personnel and advisors who need it and are bound by confidentiality. This does not apply to information that is public through no fault of the receiver, independently developed, or required to be disclosed by law (with notice where permitted).
10. Third-party services
The Service interoperates with third-party systems you choose to connect, including ServiceNow. Your use of those systems is governed by your agreements with their providers, and we are not responsible for them. We use sub-processors (principally Amazon Web Services and Anthropic) to provide the Service, under contracts requiring appropriate protection.
11. Warranties and disclaimers
We will provide the Service with reasonable skill and care. Except as expressly stated and to the extent permitted by law, the Service is provided "as is" and we disclaim all other warranties, including merchantability, fitness for a particular purpose, and non-infringement. Nothing in these Terms excludes rights that cannot be excluded under applicable law, including the Australian Consumer Law.
12. Limitation of liability
To the maximum extent permitted by law, neither party is liable for indirect, incidental, special, or consequential damages, or for lost profits, revenue, or data. Our total aggregate liability arising out of or relating to the Service is limited to the fees you paid us for the Service in the 12 months before the event giving rise to the claim. These limits do not apply to your payment obligations, a party's indemnity obligations, or liability that cannot be limited by law.
13. Indemnity
You will indemnify us against third-party claims arising from your Customer Data, your Connected Instances, or your use of the Service in breach of these Terms, except to the extent caused by our breach.
14. Term and termination
These Terms apply while you use the Service. Either party may terminate for material breach not cured within 30 days of notice. You may stop using the Service at any time. On termination, your right to use the Service ends; we will delete or return Customer Data and revoke stored credentials in accordance with our Privacy Policy and any DPA. Sections that by their nature should survive (including 8, 9, 11, 12, 13, and 16) survive termination.
15. Changes to these Terms
We may update these Terms from time to time. We will post the updated version here and update the "last updated" date, and for material changes we will give reasonable notice (for enterprise customers, by email to the billing contact). Continued use after changes take effect constitutes acceptance.
16. Governing law and disputes
These Terms are governed by the laws of New South Wales, Australia, and the parties submit to the non-exclusive jurisdiction of the courts of that state. Before commencing proceedings, the parties will attempt in good faith to resolve any dispute by negotiation.
17. Contact
Phyllis AI Pty Ltd · hello@phyllis.app.
Your data is used strictly to run Phyllis’s debugging, documentation, and optimization features. This includes generating insights, creating AI explanations, and improving your engineering workflow. It is never used to train public models — only private, isolated systems that serve your account.
We may also send product updates, security notices, and extremely occasional jokes hidden in release notes. This is part of our charm and is considered essential communication.
All user data is encrypted in transit (TLS 1.3) and at rest using industry-standard AES-256 encryption. Access to production systems is strictly limited to essential engineering staff, who undergo regular security reviews, ethical training, and occasional lectures titled:
“Why we do not ever open Ariel’s Figma files without emotional preparation.”
Backups are performed daily and stored in secure, geographically redundant environments. None of your code is exposed to the public internet, and no logs containing your intellectual property leave our controlled infrastructure.
We follow SOC2-aligned procedures, including access logging, role-based permissions, environment isolation, and automated security auditing.
You may access, request deletion, export, or modify your personal data at any time. Simply contact our support team, and a human (not an AI) will assist you. If you delete your account, Phyllis permanently removes all personal information, analysis artifacts, and diagnostic logs unless legal retention is required.
We will never punish you for leaving. Ariel might — emotionally — if you stop buying his templates, but Phyllis will respect your decision with grace.
You may also request:
- Removal of specific uploaded files
- Disabling AI processing for sensitive modules
- Limiting Analyze or Maintain to metadata-only mode
- Immediate account purging (the “I pushed secrets to Git again, burn everything” option)
Finally, you retain full ownership of your code, explanations, and insights generated by our platform. Phyllis only processes what you choose to provide, and does not claim any rights to your intellectual property — even if Ariel swears your folder structure looks suspiciously like his.



