Recovea SDK & Open-Spec License — Supplemental Terms
Last updated: 2026-06-26
0. About this document and how the licenses fit together
This document is the master licensing statement for the open, public artifacts that Recovea, Inc., a Delaware corporation, publishes so that developers can integrate with, observe, and independently verify Recovea's instrument family without lock-in. It is written so that a developer, an open-source maintainer, a security or compliance reviewer, and an attorney can each find the operative terms that apply to them.
What is genuinely open, and what this document is. The Recovea SDK, CLI, Observer, and Verifier are published as open-source software under permissive, OSI-style licenses contained inside each package (today the only published package, the recovea CLI, is MIT). Those in-package licenses are, and remain, the open-source license for that code, and this document does not add restrictions to them. *This document is a set of supplemental terms* that (a) grants the separate Open-Spec license, (b) reserves the Recovea trademarks and trust marks, (c) states the contribution, warranty-disclaimer, and roadmap-reservation terms, and (d) — only for persons who affirmatively assent to it under Section 22** — adds indemnity (Section 12) and dispute-resolution (Section 15) terms. Because the restriction-bearing supplemental terms bind only on affirmative assent and the underlying packages stay permissively licensed under their own files, nothing here converts the genuinely open packages into non-open software.
Recovea publishes its client tooling and its ledger specification under deliberately permissive terms on purpose: the open ledger format and the Verifier are the substance of an interoperable, vendor-neutral way to prove AI-spend records, and a format that cannot be independently implemented and independently verified earns no trust. Recovea is simultaneously the reference implementation and an operator of that format; publishing the format and the Verifier permissively is how Recovea invites scrutiny, reduces switching costs, and earns trust rather than asserts it.
This document covers, and assigns a license to, the following distinct categories of material (each defined in Section 2 and licensed in Sections 4–6):
- The Open-Source Software (the "OSS") — the Recovea SDK (
@recovea/sdk), the command-line interface (recoveactl), the Observer, and the standalone Verifier binary and its source, in each case licensed under the permissive license file shipped inside that package. - The Open Specification (the "Open Spec") — the
recovea-chain-v1ledger format specification, including its schema, canonicalization rules, hash-chain construction, and conformance/test vectors, licensed by this document (Section 5). - The Recovea Trademarks and Trust Marks (the "Marks") — including
RECOVEAandVERIFIED BY RECOVEA, which are expressly reserved and are not licensed by this document except as narrowly stated in Section 9.
Three things this document is not, and where to find them instead:
- It is not the agreement that governs Your use of Recovea's hosted Service (the in-path gateway at
api.recovea.ai, the dashboard, metering, and related managed services, together with any additional features and capabilities within the Services). That is governed by the Recovea Terms of Service / Master Subscription Agreement, Acceptable Use Policy, Data Processing Addendum ("DPA"), BYO-Key Addendum, and the other documents in the Recovea legal pack (collectively, the "Hosted Service Terms"). See Section 13. - It is not a grant of any right in the Marks. See Section 9.
- It is not a warranty, guarantee, or commitment of any cost savings, output quality, or availability. See Sections 10–11 and the Honesty Boundary in Section 3.
If a provision of this document conflicts with the text of an open-source license file (LICENSE, LICENSE.txt, NOTICE, or an SPDX-License-Identifier header) shipped inside a specific Recovea OSS package, the license file shipped inside that package controls for that package's code, and this document governs the surrounding matters (the Open Spec license, the spec patent and contribution terms, the trademark reservation, the warranty disclaimer, and the relationship to the Hosted Service Terms). See Section 21 (Order of precedence).
1. Parties, entity, and scope
This document is published by Recovea, Inc., a Delaware corporation ("Recovea," "we," "us," "our"). Registered/notice address: 2810 N Church St STE 89986, Wilmington, DE 19802.
Recovea is a bootstrap-funded US company; nothing in this document concerns investment or securities.
"You" and "Your" mean the individual or legal entity exercising rights under this document, whether by downloading, installing, copying, using, modifying, distributing, contributing to, or implementing the OSS or the Open Spec. If You act on behalf of an organization, You represent that You are authorized to bind that organization, and "You" includes that organization.
This document applies worldwide to the OSS and the Open Spec as published. The Recovea hosted Service is offered to business customers only (18+; not for personal, family, or household use), in the United States, and is not licensed by this document; see the Hosted Service Terms.
2. Definitions
Capitalized terms used in this document have the meanings below. Terms defined in the Hosted Service Terms (for example, Service, Customer, Authorized User, Provider, Provider Keys, Inference Content, Usage Data, the Ledger, Customer Personal Data, in-path, and Aggregated/De-identified Data) carry the same meanings here when used in the context of the hosted Service, and are restated below only where this document needs them.
- "OSS" means, collectively, the software components Recovea publishes and identifies as open source, including: the SDK (
@recovea/sdkand any language-specific siblings Recovea publishes under the same brand), the CLI (recoveactl), the Observer (a local-first, metadata-oriented audit/observability tool), and the Verifier (the standalone verifier binary together with its published source), in each case licensed under the permissive license file shipped inside that package, and in each case excluding the Marks and excluding any component Recovea expressly designates as proprietary, hosted-only, or "source-available, not open source."
- "Open Spec" means the
recovea-chain-v1open ledger format, comprising the written specification, the data schema, the canonical-serialization/canonicalization rules, the hash-chain and tombstone/sever rules, the conformance requirements, and the published test vectors, in each case as Recovea publishes them under this document. "Conforming Implementation" means an independent software implementation that reads and/or writesrecovea-chain-v1records in accordance with the Open Spec and passes the published conformance test vectors.
- "the Ledger" means a hash-chained, append-only, offline re-derivable cost-and-event record in the
recovea-chain-v1format. The Open Spec describes the format; the hosted Service produces records in it. Possessing or implementing the format does not make any record "verified" (Section 3).
- "Verifier" means the standalone verifier binary (and its published source) that re-derives and checks the integrity of
recovea-chain-v1records offline, independently of any Recovea-hosted system.
- "Marks" means the Recovea names, logos, trade names, trademarks, service marks, trust seals, and badges, including without limitation RECOVEA and "VERIFIED BY RECOVEA," whether registered or unregistered, and any confusingly similar designation. Recovea asserts these as common-law/unregistered marks (™, or ℠ for service marks) until and unless a registration issues; Recovea does not represent ® before registration.
- "Contribution" means any original work of authorship, including any modifications or additions to the OSS or the Open Spec, that is intentionally submitted by You to Recovea for inclusion in or documentation of the OSS or the Open Spec, in any form and through any medium (for example, a pull request, patch, issue attachment, or specification proposal). "Contributor" means a person or entity that makes a Contribution.
- "Patent Claims" means patent claims, now owned or hereafter acquired or controlled by a licensor, that are necessarily infringed by making, using, selling, offering to sell, importing, or otherwise running or distributing the licensed OSS or a Conforming Implementation of the Open Spec, in each case in the form in which it is licensed and excluding any claim that would be infringed only as a result of Your modification or combination with other software.
- "Hosted Service Terms" has the meaning in Section 0 and Section 13.
- "Provider" means a third-party model or inference provider (for example, OpenAI, Anthropic, or OpenRouter). "Provider Keys" means the API credentials issued to You/the Customer by a Provider. "Provider Charges" means amounts a Provider bills directly to You. Recovea does not resell Provider tokens, does not mark up or fund Provider spend, and is not a party to Your agreements with any Provider; see Sections 3 and 13.
- "OTel" means the OpenTelemetry specification and data model. "FOCUS" means the FinOps Open Cost and Usage Specification. Recovea designs its telemetry to be OTel-/FOCUS-compatible (Section 7); references to OTel and FOCUS describe an interoperability objective and are not a claim of certification, endorsement, or affiliation by those projects.
Third-party trademarks. OpenAI, Anthropic, and OpenRouter, and OpenTelemetry and FOCUS/FinOps Foundation, are the trademarks of their respective owners. Their mention in this document indicates compatibility or interoperability only and implies no affiliation, sponsorship, endorsement, or partnership with, or certification by, those owners. All third-party marks remain the property of their respective owners.
3. The Honesty Boundary (controls over every other section)
The following statements are material to every grant in this document and override any contrary implication anywhere in the OSS, the Open Spec, the documentation, or marketing:
- No guarantee of savings, quality, or availability. Nothing in the OSS or the Open Spec guarantees any cost savings, financial outcome, model-output accuracy, fitness, uptime, or availability. Any cost, savings, or efficiency figure produced, displayed, or transmitted by the OSS is an estimate unless Recovea has expressly designated it "verified" in a writing meeting Recovea's criteria. The words "verified," "settled," and "proven" are reserved exclusively for results that Recovea has designated as such in writing.
- The format is not the verdict. Producing, holding, parsing, or re-deriving a
recovea-chain-v1record proves only the integrity of that record (that it has not been altered and chains as claimed). It does not establish that any savings figure is "verified," that any quality bar was met, or that any Recovea attestation has been issued. Attestation, certification, and trust-mark functions, if and when offered, are functions of Recovea's hosted Service and the Marks, not of the open format. See Section 9.
- BYO-Key; client-side keys; no token resale. The SDK and CLI operate on Your own Provider accounts and Provider Keys. In the SDK's and CLI's default and intended operation, Provider Keys are handled client-side and are not stored or transmitted to Recovea by the SDK or CLI; the SDK uses them to call the Provider directly. Where You separately route traffic through Recovea's hosted in-path gateway, You bring and own those keys and pay the Provider directly under the Hosted Service Terms. Recovea does not resell, mark up, sponsor, or fund Provider tokens or Provider spend, and is not a party to Your Provider agreements. Your Providers are Your recipients/processors/independent controllers, not Recovea sub-processors.
- Fail-open, not fail-guaranteed. The SDK is designed to fail over to the Provider (a designed-in resilience objective and a reversible, one-line re-point), and budget/kill controls in the broader instrument family are designed to stop or cap spend. These are design objectives and reversible exits, not warranties of availability, correctness, or a guaranteed hard stop. Use "designed to," not "will."
- Honest streaming boundary. Fallback occurs before the first token is streamed. Once a response begins streaming, a failure surfaces as a clean error, not a silent splice. The OSS does not perform, and Recovea does not claim, mid-stream failover. Cached responses, where used, are byte-identical and are never synthesized by Recovea.
- No claim of maturity or standard-status pre-earned. Neither the OSS nor the Open Spec asserts that Recovea is a platform, authority, standard, verifier-of-record, market leader, or holder of any certification (for example, SOC 2, ISO 27001, or PCI) that Recovea has not actually achieved. Open publication of the format and Verifier is an invitation to interoperate and scrutinize, not a representation that any standard has been adopted.
4. License grant — OSS (copyright)
Each OSS package is licensed to You under the license file shipped inside that package. Subject to Your compliance with that in-package license, Recovea grants You a worldwide, royalty-free, non-exclusive license under Recovea's copyrights to use, reproduce, modify, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute the OSS and derivative works thereof, in source or object form, on the terms of that in-package license. Mere receipt or use of an OSS package binds You only to that package's in-package license; the supplemental indemnity and dispute-resolution terms of this document (Sections 12 and 15) bind only persons who affirmatively assent under Section 22.
OSS license. The license for each OSS package is the one in that package's own LICENSE file and its SPDX-License-Identifier. Today exactly one package is published — the recovea CLI on npm — and it is MIT. Where a future package ships under the Apache License, Version 2.0 ("Apache-2.0"), that license's Section 3 patent grant and Section 6 trademark limitation apply to it. The authoritative license text and SPDX-License-Identifier for each package are the copies shipped inside that package; this Section 4 is descriptive and does not narrow or enlarge them.
Attribution and notices. You must retain, in all copies and substantial portions You distribute, all copyright, patent, trademark, and attribution notices, the applicable in-package license text, and any NOTICE file, and You must state any significant changes You made. You may add Your own notices to Your modifications provided they do not misstate the origin of the OSS or imply Recovea's endorsement.
No trademark rights via the code license. Consistent with Apache-2.0 §6, the OSS license grants no rights in the Marks. See Section 9.
Third-party components. The OSS may include or depend on third-party open-source components licensed under their own terms, identified in the applicable NOTICE, THIRD-PARTY-NOTICES, or dependency manifest. Those components are licensed to You by their respective licensors under their respective licenses, and nothing here modifies them.
5. License grant — Open Spec (copyright + patent), and the standards commitment
Recovea publishes the Open Spec permissively and irrevocably so that anyone may build a Conforming Implementation — including implementations that compete with Recovea — without seeking permission, paying a royalty, or accepting feature-tying. This is the anti-lock-in, neutrality, and standards-seeding commitment.
5.1 Specification copyright license. Recovea grants You a worldwide, royalty-free, non-exclusive, irrevocable (except as stated in Section 5.4) license to read, copy, distribute, and implement the Open Spec, and to prepare and distribute Conforming Implementations and materials that describe the Open Spec. You may reproduce the Open Spec text in full or in part with attribution; You may not present a modified specification as the official recovea-chain-v1 specification or use the Marks to designate a fork (Section 9.4).
5.2 Specification patent grant (the spec patent promise). Recovea grants You a worldwide, royalty-free, non-exclusive, irrevocable (except as stated in Section 5.4) license under Recovea's Patent Claims to make, have made, use, offer to sell, sell, import, and otherwise run and distribute Conforming Implementations of the Open Spec, including the canonicalization and hash-chain mechanics required to read and write recovea-chain-v1 records. This grant extends only to the portions of an implementation that are necessary to conform to the Open Spec, and does not extend to features, optimizations, or combinations beyond what the Open Spec requires.
5.3 Scope and exclusions. The Section 5 grants do not cover: (a) the Marks or any trust seal/badge (Section 9); (b) Recovea's hosted Service, its eval gates, calibration corpora, non-public methodology, or non-public optimization logic; or (c) any third-party rights. Implementing the format never confers the right to issue Recovea-branded attestations or to represent that a record is "Verified by Recovea." Nothing in Section 5 grants any right to use Recovea's hosted-Service outputs, any results Recovea has designated "verified," or Ledger records produced by the hosted Service to train, fine-tune, or develop any machine-learning model or competing service; any such use is governed and restricted by the Hosted Service Terms.
5.4 Defensive termination (patent peace). If You (or Your affiliate) initiate or knowingly participate in a patent claim or other patent proceeding (including a cross-claim or counterclaim) alleging that the Open Spec, the OSS, the Verifier, or a Conforming Implementation distributed by Recovea infringes a patent, then the Open-Spec patent license granted to You under Section 5.2, and any spec-related patent license under Section 8.2, terminate automatically as of the date such proceeding is filed. For the OSS code itself, the patent grant and its defensive termination are governed exclusively by the in-package license (for Apache-2.0 packages, its Section 3); this Section 5.4 does not enlarge, narrow, or duplicate that in-package patent-termination provision, consistent with the order of precedence in Section 21. This Section mirrors the defensive-termination posture of Apache-2.0 §3 for the Open-Spec patent grant and is intended to deter offensive patent assertion against the open ecosystem while preserving Your right to defend Yourself.
5.5 Durability and reservation. Recovea may publish new or successor versions of the Open Spec (for example, a future recovea-chain version); doing so does not retroactively withdraw the license to a previously published version, which remains available under the terms under which it was published. Recovea otherwise reserves all rights not expressly granted, including the right to evolve the format and to offer additional or alternative formats. The Services (as defined in the Hosted Service Terms) may include optimization, additional features and capabilities Recovea may offer, and additional features and capabilities. Any such capability is governed by the terms in effect when Recovea makes it available and is not active or licensed under this document unless Recovea expressly states otherwise. Recovea may offer subscription, usage-based, and savings-/outcome-based pricing models for the Services; any savings-based model applies only on a Customer's separate, affirmative election. Nothing in this document commits Recovea to maintain, support, or continue publishing any particular OSS component or specification version, except that licenses already granted are not revoked except as expressly stated.
6. The Verifier — independent, offline, and permissive (anti-lock-in)
The Verifier is published under the same permissive OSS terms as the rest of the OSS (Section 4) and benefits from the Open Spec patent grant (Section 5). Recovea publishes the Verifier and the conformance test vectors so that You can check Recovea's own records without trusting Recovea's servers and so that third parties can build competing verifiers.
- The Verifier re-derives and checks
recovea-chain-v1record integrity offline, with no network call to Recovea required. - A successful verification establishes record integrity only (Section 3.2). It is not an attestation, certification, or "Verified by Recovea" statement, and it does not validate any savings, quality, or business assertion.
- You may run, fork, embed, and redistribute the Verifier, including in a commercial product, subject to the OSS license and the Marks reservation (Section 9). You must not present Verifier output as a Recovea-issued attestation or use the Marks to imply Recovea endorsement of Your build.
This is the reference-implementation-and-operator posture: Recovea both operates the hosted producer of these records and publishes the means to verify them independently. Any additional features and capabilities within the Services are governed by the Hosted Service Terms in effect when Recovea makes them available; the open Verifier shipping now provides the integrity-checking primitive only, not a Recovea attestation.
7. Telemetry interoperability (OTel / FOCUS) and client-side data behavior
7.1 Open, interoperable telemetry. The SDK and observer are designed to emit spans, metrics, and cost/usage records that are OTel-compatible and that map to FOCUS-aligned cost-and-usage fields, so that You can route Recovea telemetry into Your existing observability and FinOps tooling without lock-in. Compatibility is an engineering objective; it is not a certification by, endorsement by, or affiliation with the OpenTelemetry or FinOps Foundation projects, and field mappings may evolve as those specifications evolve.
7.2 Client-side and local-first behavior. The SDK runs in Your environment; the Observer is local-first and oriented to metadata rather than request/response bodies. In the SDK's default and intended operation, Provider Keys used by the SDK are handled client-side and are not stored or transmitted to Recovea by the SDK (Section 3.3). Where You configure the SDK or observer to send telemetry to Recovea's hosted Service, that transmission and any resulting Processing are governed by the Hosted Service Terms, the DPA, and the Privacy Notice, not by this document. You are responsible for configuring redaction/sampling appropriate to Your data, and for not transmitting content You are not permitted to transmit. You must not transmit, through the OSS to Recovea's hosted Service, any protected health information (HIPAA), PCI cardholder data, biometric identifiers, government-issued identifiers, children's data, or other special-category or regulated data, unless separately agreed with Recovea in a signed writing. Recovea is not a HIPAA Business Associate, and the Service is not HIPAA- or PCI-validated.
7.3 No affirmative monitoring duty. The OSS is observability and cost tooling; it imposes no content-monitoring or moderation obligation on Recovea, and routing/telemetry does not, by itself, constitute individual automated decision-making producing legal or similarly significant effects on any person.
8. Contributions and intellectual-property terms (inbound IP)
8.1 Inbound = Outbound (license of Contributions). Unless a separate signed Contributor License Agreement ("CLA") applies, You agree that each Contribution You submit is licensed to Recovea and to all downstream recipients under the same license as the component to which it is contributed — the applicable OSS license (Section 4) for OSS Contributions and the Open Spec license (Section 5) for Open Spec Contributions — including the corresponding copyright and patent grants. This is the Apache-2.0 §5 "inbound=outbound" model.
8.2 Contributor patent grant. To the maximum extent of the rights You have, You grant Recovea and downstream recipients a worldwide, royalty-free, non-exclusive, irrevocable (except for defensive termination under Section 5.4 as to the Open-Spec patent grant, and except as to the OSS code under the in-package license's own patent-termination provision) patent license under Your Patent Claims that read on Your Contribution alone or in combination with the component to which You contributed it, to make, use, sell, offer to sell, import, and otherwise run and distribute that component.
8.3 Contributor representations. You represent that: (a) each Contribution is Your original creation or You have sufficient rights to submit it under these terms; (b) Your Contribution does not knowingly violate any third party's IP or other rights; (c) if Your employer has rights to IP You create, You have authority to submit the Contribution or Your employer has waived such rights; and (d) You will disclose any third-party license, patent, or other restriction of which You are aware that applies to a Contribution.
8.4 No obligation to use; assent for Contributors. Recovea is not obligated to accept, use, or maintain any Contribution and may modify, decline, or remove Contributions at its discretion. You retain ownership of Your Contribution's copyright; this Section grants licenses, not an assignment, unless a separate signed CLA provides otherwise. Submission of a Contribution requires a Developer Certificate of Origin ("DCO") sign-off (Signed-off-by) on each commit for routine Contributions, and a signed CLA for substantial Contributions where Recovea so requests. A DCO sign-off or CLA is a manifestation of affirmative assent to this document under Section 22, including its supplemental indemnity (Section 12) and dispute-resolution (Section 15) terms.
8.5 Feedback. Suggestions, feature requests, and other feedback You provide about the OSS, the Open Spec, or the Service are non-confidential, and You grant Recovea a perpetual, irrevocable, worldwide, royalty-free license to use them without restriction or compensation.
8.6 Methodology and trade-secret carve-out. Nothing in this Section, and no Contribution, grants You any right in, or obligates Recovea to publish, Recovea's non-public methodology, eval gates, calibration corpora, or other trade secrets, which are expressly reserved (Sections 5.3 and 11). Such reserved materials are Recovea's confidential information and trade secrets for purposes of the injunctive-relief carve-out in Section 15.4.
9. Trademark and trust-mark reservation (code permissive, Marks reserved)
This is the deliberate split: the code and the format are permissive; the Marks are reserved.
9.1 No license to the Marks. Except for the narrow nominative use permitted in Section 9.3, this document grants You no right, license, or interest in the Marks. The OSS copyright/patent license (Section 4) and the Open Spec license (Section 5) do not license the Marks (Apache-2.0 §6). All goodwill in the Marks inures solely to Recovea.
9.2 "Verified by Recovea" is reserved. "VERIFIED BY RECOVEA" is reserved by Recovea as a Recovea trademark/service mark denoting a Recovea-issued result, and is not offered, held out, or registered as a third-party certification mark. Recovea does not currently offer a certification or attestation program; any such program is available only under a separate written program agreement with Recovea governing that Mark. No one may apply, display, or imply "Verified by Recovea," issue a Recovea-branded attestation, or represent that any record, model, deployment, or savings figure is "Verified by Recovea," except under such a separate written agreement. Running the Verifier, producing a recovea-chain-v1 record, or building a Conforming Implementation does not confer this right (Sections 3.2 and 6).
9.3 Permitted nominative use. You may use the word marks RECOVEA and recovea-chain-v1 solely in a truthful, nominative manner to: (a) state that Your software is compatible with, implements, reads/writes, or interoperates with the recovea-chain-v1 format or the Recovea OSS; (b) accurately reference Recovea as the source of the OSS or Open Spec; and (c) comply with the attribution requirements of the applicable OSS license. Such use must: (i) be plain word use, not Recovea logos, badges, seals, or stylized marks; (ii) not state or imply sponsorship, endorsement, certification, partnership, or affiliation with Recovea; (iii) not be used in Your product name, company name, domain name, logo, or as a source identifier for Your goods/services; and (iv) include, where reasonably possible, a notice that RECOVEA and "VERIFIED BY RECOVEA" are marks of Recovea, Inc. and that Your product is not endorsed or certified by Recovea.
9.4 Forks and modified specs. If You distribute a modified version of the OSS or a modified specification, You must rename it so as not to use the Marks in a way that suggests it is the official Recovea OSS or the official recovea-chain-v1 specification, and You must clearly state it is an unofficial, modified version not provided or endorsed by Recovea.
9.5 Reservation; guidelines. Except for Section 9.3, Recovea reserves all rights in the Marks and may publish separate trademark-usage guidelines, which, once published, govern permitted use and may be updated by Recovea.
10. Warranty disclaimer (OSS and Open Spec)
THE OSS, THE VERIFIER, THE OPEN SPEC, THE TEST VECTORS, AND ALL RELATED DOCUMENTATION ARE PROVIDED "AS IS" AND "AS AVAILABLE," WITH ALL FAULTS AND WITHOUT WARRANTY OF ANY KIND. TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, RECOVEA AND ITS LICENSORS AND CONTRIBUTORS EXPRESSLY DISCLAIM ALL WARRANTIES AND CONDITIONS, WHETHER EXPRESS, IMPLIED, STATUTORY, OR OTHERWISE, INCLUDING WITHOUT LIMITATION ANY IMPLIED WARRANTIES OR CONDITIONS OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, ACCURACY, QUIET ENJOYMENT, AND NON-INFRINGEMENT, AND ANY WARRANTIES ARISING FROM COURSE OF DEALING, COURSE OF PERFORMANCE, OR USAGE OF TRADE. (UCC § 2-316.)
Without limiting the foregoing, Recovea does not warrant that: (a) the OSS or Open Spec will meet Your requirements, be uninterrupted, timely, secure, or error-free; (b) any defect will be corrected; (c) the OSS is free of harmful components; (d) any cost, savings, or efficiency figure produced by the OSS is accurate or will be achieved (all such figures are estimates unless expressly designated "verified" in writing per Section 3); (e) any model output obtained through a Provider is accurate, lawful, or fit for any purpose; or (f) the failover, budget, or control behaviors will operate without interruption or will guarantee any availability, correctness, or hard stop (Section 3.4). You bear the entire risk as to the quality, performance, and results of the OSS and Open Spec.
Some jurisdictions do not allow the exclusion of certain warranties, so some of the above exclusions may not apply to You; in that case, such warranties are limited to the minimum scope and duration required by applicable law.
11. Limitation of liability
TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW:
11.1 Exclusion of indirect damages. IN NO EVENT WILL RECOVEA OR ITS LICENSORS OR CONTRIBUTORS BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, EXEMPLARY, OR PUNITIVE DAMAGES, OR FOR ANY LOSS OF PROFITS, REVENUE, DATA, GOODWILL, BUSINESS, OR ANTICIPATED SAVINGS, OR FOR PROVIDER CHARGES, OVERAGES, OR RUNAWAY SPEND, ARISING OUT OF OR RELATED TO THE OSS, THE VERIFIER, OR THE OPEN SPEC, WHETHER BASED ON CONTRACT, TORT (INCLUDING NEGLIGENCE), STRICT LIABILITY, WARRANTY, OR ANY OTHER THEORY, AND WHETHER OR NOT RECOVEA HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.
11.2 Aggregate cap. THE TOTAL AGGREGATE LIABILITY OF RECOVEA AND ITS LICENSORS AND CONTRIBUTORS ARISING OUT OF OR RELATED TO THE OSS, THE VERIFIER, AND THE OPEN SPEC UNDER THIS DOCUMENT WILL NOT EXCEED ONE HUNDRED U.S. DOLLARS (US $100). Because the OSS and Open Spec are provided free of charge under this document, this nominal cap reflects the no-fee nature of the grant. Liability arising from Your use of the hosted Service is governed and capped by the Hosted Service Terms, not by this Section; the hosted-Service liability architecture (trailing-12-month Fees with a fixed-dollar floor, an enhanced cap for confidentiality and data-protection/security breaches, and uncapped carve-outs for indemnity, payment, IP/AUP breach, and fraud/willful misconduct, with gross negligence remaining subject to the caps to the fullest extent permitted by applicable law) lives in the MSA/DPA and is not modified here.
11.3 Essential basis. The disclaimers in Section 10 and the limitations in this Section 11 are an essential basis of the bargain and the consideration for providing the OSS and Open Spec at no charge, and apply even if a limited remedy fails of its essential purpose.
11.4 Statutory floor. Some jurisdictions do not allow the exclusion or limitation of certain damages, so some of the above may not apply to You. Nothing in this document excludes or limits liability that cannot be excluded or limited under applicable law (for example, liability for fraud or willful misconduct, for death or personal injury caused by negligence, or, where and only to the extent applicable law does not permit gross negligence to be limited, gross negligence).
12. Indemnification
This Section 12 binds only persons who affirmatively assent to this document under Section 22 (for example, by DCO/CLA sign-off, click-through acceptance, or an account). A person who merely receives, downloads, or uses an OSS package without manifesting such assent is bound solely by that package's in-package license and is not subject to this Section.
12.1 By You. To the maximum extent permitted by applicable law, You will defend, indemnify, and hold harmless Recovea and its Contributors and licensors, and each of their respective officers, directors, employees, and agents (the "Recovea Indemnified Parties"), from and against any third-party claims, demands, suits, or proceedings, and any resulting losses, liabilities, damages, costs, and reasonable attorneys' fees, arising out of or related to: (a) Your use, modification, or distribution of the OSS, the Verifier, or a Conforming Implementation of the Open Spec; (b) Your Contributions, including any allegation that a Contribution infringes or misappropriates a third party's rights; (c) Your breach of this document, including any misuse of the Marks (Section 9) or any false or unauthorized "Verified by Recovea" or attestation claim; (d) Your handling of Provider Keys, Provider Charges, or data You process with the OSS; or (e) Your violation of any law or third-party right.
12.2 No indemnity by Recovea under this document. Given the no-fee, permissive nature of the OSS and Open Spec, Recovea provides no defense or indemnity under this document, including no IP indemnity for the OSS or Open Spec. Any indemnities Recovea offers exist solely under the Hosted Service Terms and apply only to the hosted Service as stated there. Under the Hosted Service Terms, Recovea's IP indemnity for the Service as provided is narrow, subject to standard exclusions (Provider outputs/models, Customer Content/Data/keys, unauthorized combinations or modifications, and use outside the documentation or in breach), offers a sole "procure/modify/replace/refund" remedy, and is subject to the general liability cap — never uncapped.
12.3 Procedure. The indemnified party will give reasonably prompt notice of the claim, reasonable cooperation (at the indemnifying party's expense), and sole control of the defense and settlement, except that no settlement imposing a non-monetary obligation or admission on the indemnified party may be entered without its consent (not unreasonably withheld).
13. Relationship to the hosted Service Terms (cross-reference)
This document governs the OSS and the Open Spec only. Your access to and use of the Recovea hosted Service — the in-path gateway at api.recovea.ai (OpenAI-compatible /v1, Anthropic /anthropic, and OpenRouter long-tail routing), the dashboard/console, metering/observability, optimization/routing, spend control, reporting/analytics, and related managed services, together with any additional features and capabilities Recovea makes available within the Services (collectively, the "Services") — is governed by the Hosted Service Terms, including the Terms of Service / Master Subscription Agreement, the Acceptable Use Policy, the Data Processing Addendum (DPA), the BYO-Key Addendum, the Privacy Notice, the Security Statement, and any Order Form. Any optimization, additional feature or capability is governed by the terms in effect when Recovea makes it available and is not active or licensed under this document unless Recovea expressly states otherwise.
Key boundaries:
- Keys and Providers. In the hosted Service, You bring and own Your Provider accounts and Provider Keys and pay the Providers directly; Recovea is a neutral in-path conduit and is not a party to Your Provider agreements, and does not resell or take custody of Provider tokens (Section 3.3). The same BYO-Key posture applies to SDK/CLI use, except that in the SDK's default and intended operation the keys are handled client-side and are not stored or transmitted to Recovea by the SDK.
- Data and privacy. Where Recovea Processes Customer Personal Data on Customer's behalf through the hosted Service, the DPA is automatically incorporated into and forms part of the Hosted Service Terms and governs that Processing, together with the Privacy Notice; Recovea acts as processor/service provider of Customer Personal Data within Inference Content and as controller of its own account/marketing/personnel data. The OSS, run locally, processes data in Your environment under Your control; this document is not a data-processing agreement.
- Verification and attestation. Open-format integrity (Section 6) is not a Recovea attestation; any "Verified by Recovea" designation or certification is a function of the hosted program under the Marks and the Hosted Service Terms (Section 9.2).
- No training on Service outputs or the Ledger. Nothing here grants any right to use Recovea's hosted-Service outputs, any results Recovea has designated "verified," or Ledger records produced by the hosted Service to train, fine-tune, or develop any machine-learning model or competing service; such use is restricted under the Hosted Service Terms.
- No merger. Accepting this document does not create a hosted-Service subscription, and accepting the Hosted Service Terms does not narrow the open licenses granted here. Where both apply, each governs its own subject matter; Section 21 states precedence.
14. Term and termination
14.1 Term. This document applies from the moment You exercise any right in the OSS or Open Spec and continues until terminated as provided here. The licenses in Sections 4, 5, and 6 are intended to be durable and, for any version of the OSS or Open Spec already published, are not revoked by Recovea except as expressly stated (Sections 5.4, 5.5, and 14.2).
14.2 Termination for breach; trademark and patent triggers. Your rights under this document terminate automatically if: (a) You materially breach this document (including the Marks reservation in Section 9) and, where the breach is curable, fail to cure within thirty (30) days of becoming aware of it; or (b) the defensive patent-termination trigger in Section 5.4 applies (in which case the Open-Spec patent license terminates as stated there; the OSS code patent grant terminates only as its in-package license provides). Termination of copyright licenses under (a) does not, by itself, terminate the copyright rights of Your downstream recipients who are in compliance, consistent with the applicable in-package OSS license.
14.3 Effect of termination. On termination of Your rights, You must stop exercising the terminated rights and, for the Marks, immediately cease all use (including nominative use under Section 9.3). Sections 2, 3, 5.3, 5.4, 8.5, 8.6, 9, 10, 11, 12, 13, and 15–24 survive termination, as do any licenses expressly stated to be irrevocable for already-published versions.
14.4 Reinstatement. Consistent with Apache-2.0 and common OSS practice, if Your license terminated for a curable breach and You cure it and notify Recovea, Recovea may, in its discretion, reinstate Your license; reinstatement is not automatic for a repeat or willful violation.
15. Dispute resolution; arbitration; class-action waiver
This Section 15 binds only persons who affirmatively assent to this document under Section 22. A person who merely receives, downloads, or uses an OSS package without manifesting such assent is bound solely by that package's in-package license and is not subject to this Section. Non-contracting third parties (for example, security reporters or DMCA complainants not in privity under this document) are likewise not bound by this Section.
15.1 Informal resolution first. Before initiating a formal proceeding, the parties will attempt in good faith to resolve any dispute arising out of or relating to this document by negotiation, beginning with written notice to the other party (to legal@recovea.ai for Recovea) describing the dispute. If not resolved within thirty (30) days, either party may proceed as provided below.
15.2 Binding arbitration. Except for the carve-outs in Section 15.4, any dispute arising out of or relating to this document, the OSS, the Verifier, or the Open Spec will be resolved by final and binding arbitration administered by the American Arbitration Association ("AAA") under its Commercial Arbitration Rules, before a single arbitrator, seated in Wilmington, Delaware. The OSS and Open Spec are business-property tools and not consumer goods or services, and the parties intend the AAA Commercial Arbitration Rules to apply, subject to the Agreement's Consumer-Rules fallback (Terms of Service §24.2 / MSA §23.2): if the AAA or a court of competent jurisdiction determines that the AAA Consumer Arbitration Rules apply to a dispute involving an individual, those rules govern that dispute and Recovea pays the filing, administrative, and arbitrator fees the AAA consumer fee schedule assigns to the business. Judgment on the award may be entered in any court of competent jurisdiction. The arbitrator may award only individualized relief and may not consolidate claims absent all parties' consent, except as provided in the mass-arbitration protocol in Section 15.6.
15.3 Class-action and jury waiver. TO THE MAXIMUM EXTENT PERMITTED BY LAW, DISPUTES WILL BE BROUGHT ONLY IN AN INDIVIDUAL CAPACITY, AND NOT AS A PLAINTIFF OR CLASS MEMBER IN ANY PURPORTED CLASS, COLLECTIVE, OR REPRESENTATIVE PROCEEDING. THE PARTIES WAIVE ANY RIGHT TO A JURY TRIAL. If this class/collective waiver is held unenforceable as to a particular claim, that claim (and only that claim) will proceed in court, severed from any arbitration.
15.4 Carve-outs to court. Notwithstanding the above, either party may: (a) bring an individual claim in small-claims court within that court's jurisdiction; and (b) seek injunctive or other equitable relief in the state or federal courts located in Wilmington, Delaware for actual or threatened infringement or misuse of its intellectual property or the Marks, or breach of confidentiality (including Recovea's confidential information and trade secrets under Section 8.6, and to stop unauthorized use of the Marks or a false "Verified by Recovea" claim), without first arbitrating. Disputes with non-contracting third parties (Section 15 introduction) lie in the state or federal courts located in Wilmington, Delaware.
15.5 Fees. Each party bears its own attorneys' fees and costs, and the parties share the arbitrator's compensation and AAA administrative fees as allocated by the AAA Commercial Arbitration Rules, except that the arbitrator may reallocate fees and costs to the extent authorized by applicable law for a claim or defense found to be frivolous or brought for an improper purpose.
15.6 Mass-arbitration (batching / bellwether) protocol. If twenty-five (25) or more demands for arbitration raising substantially similar claims are filed by or with the coordination or assistance of the same or coordinated counsel or organizations, the parties agree that: (a) the demands will be administered under the AAA Mass Arbitration Supplementary Rules (including their Process Arbitrator provisions), which the parties expressly elect; (b) as an initial bellwether stage, claimants' counsel and Recovea each select up to ten (10) demands (up to twenty (20) total) to proceed to merits arbitration first; the remaining demands are stayed, and no filing or administrative fees are due on a stayed demand until it proceeds; (c) after the bellwether awards issue, the parties will engage in a good-faith global mediation informed by those awards before further batches (selected the same way) proceed; (d) any applicable statute of limitations and any contractual deadline are tolled for a demand from the date it is first presented until it is permitted to proceed; (e) any claimant whose demand has been stayed for more than one hundred twenty (120) days after presentation may elect instead to proceed in small-claims court on an individual basis; and (f) if any part of this protocol is held unenforceable, that part is severed and the remainder of this protocol — and the remainder of this Section — remains in full force. This Section 15.6 is intended to be enforced by the arbitrator and, if necessary, by the courts identified in Section 16.
16. Governing law and venue
This document is governed by the laws of the State of Delaware, USA, excluding its conflict-of-laws rules and excluding the U.N. Convention on Contracts for the International Sale of Goods. Subject to Section 15 (arbitration), the exclusive venue for any permitted court action is the state and federal courts located in Wilmington, Delaware, and the parties consent to personal jurisdiction there. References elsewhere in this document to courts of the governing-law state mean those Wilmington, Delaware courts.
17. Export, sanctions, and U.S. government rights
17.1 Export/sanctions compliance. The OSS and Verifier may be subject to U.S. export-control and sanctions laws (including the Export Administration Regulations and OFAC programs). You represent that You are not located in, organized under, or ordinarily resident in any country/region subject to U.S. embargo, are not on any U.S. restricted-party list, and will not export, re-export, or use the OSS in violation of applicable export or sanctions laws. You are responsible for compliance with the export and sanctions laws applicable to Your use and distribution.
17.2 U.S. Government end users. The OSS is "commercial computer software" and "commercial computer software documentation" under FAR 12.212 and DFARS 227.7202. Any use, duplication, or disclosure by the U.S. Government is subject solely to the terms of this document and the applicable in-package license, and is provided with only those rights granted to all other end users.
18. Assignment
You may not assign or transfer this document or any rights or obligations under it without Recovea's prior written consent, except that the in-package OSS license's distribution rights run with the OSS to downstream recipients as that license provides. Recovea may assign this document, in whole or in part, without restriction, including to an affiliate or in connection with a merger, acquisition, reorganization, or sale of assets. Any prohibited assignment is void. Subject to this Section, this document binds and benefits the parties and their permitted successors and assigns.
19. Force majeure
Recovea is not liable for any delay or failure to perform (other than payment obligations, of which there are none under this no-fee document) caused by events beyond its reasonable control, including acts of God, natural disasters, war, terrorism, civil unrest, labor disputes, governmental action, internet or utility failures, Provider or third-party outages, supply-chain failures, and security incidents. This Section does not create any performance obligation that this document does not otherwise impose.
20. Notices and designated contacts
Notices to Recovea under this document must be in writing and sent to legal@recovea.ai, with a copy to the registered/notice address at 2810 N Church St STE 89986, Wilmington, DE 19802. The following Recovea channels (each on the single @recovea.ai domain) are designated for the indicated purpose:
- Legal / licensing / trademark / "Verified by Recovea" inquiries:
legal@recovea.ai - Security vulnerability reports (governed by Recovea's separate Vulnerability Disclosure Policy; security reporters are non-contracting third parties under Section 15):
security@recovea.ai - Copyright/DMCA notices concerning Recovea-hosted material (governed by Recovea's separate DMCA Policy; the designated agent and the canonical address are stated there):
dmca@recovea.ai - Privacy inquiries:
privacy@recovea.ai
Notices to You may be given via the repository, package registry, the email/contact associated with Your account or Contribution, or a notice posted in the OSS distribution channel.
21. Order of precedence
If there is a conflict among the documents that may apply to You, the following order controls, from highest to lowest, each only as to its own subject matter:
- A signed Order Form (for the hosted Service), where it so states;
- The Master Subscription Agreement / Terms of Service (Hosted Service Terms), as to the hosted Service;
- The DPA, as to Processing of Customer Personal Data;
- The BYO-Key Addendum, as to Provider Key handling, Provider Terms, Provider Charges, and runaway-spend allocation;
- The in-package OSS license file (e.g.,
LICENSE/SPDX-License-Identifier), as to that package's code copyright and patent terms (including patent termination); - This document, as to the Open Spec license, the spec patent grant, contribution/IPR terms, the Marks reservation, the OSS warranty disclaimer, and the relationship to the Hosted Service Terms;
- Any other incorporated policy (e.g., trademark-usage guidelines, Vulnerability Disclosure Policy).
For clarity: nothing in this document displaces the DPA or the liability/indemnity architecture of the Hosted Service Terms; the BYO-Key carve-out does not displace the DPA; and the in-package license, not this document, governs each package's code patent grant and its termination.
22. Electronic acceptance, signatures, and assent gating
22.1 What binds a bare recipient. Mere downloading, installing, copying, or using an OSS package binds You only to that package's in-package license. The Open Spec license in Section 5 binds anyone who reads, copies, distributes, or implements the Open Spec, on the permissive terms stated there.
22.2 What requires affirmative assent. The supplemental contractual terms of this document — specifically the indemnity obligations in Section 12 and the dispute-resolution, arbitration, and class-action-waiver terms in Section 15 — bind only persons who affirmatively manifest assent to this document by one of the following: (a) a DCO sign-off or signed CLA accompanying a Contribution (Section 8.4); (b) a click-through or other affirmative acceptance of this document; or (c) creating or holding a Recovea account under terms that incorporate this document. A person who does none of these is not bound by Sections 12 or 15, and Recovea will not assert those Sections against such a person.
22.3 Electronic transactions. Where You assent under Section 22.2, You consent to transact electronically, and electronic records and signatures (including click-through acceptance, a CLA/DCO sign-off, or a commit/pull-request submission) have the same legal effect as handwritten signatures and paper records to the maximum extent permitted by the U.S. ESIGN Act and the Uniform Electronic Transactions Act (UETA).
23. Modification of this document
Recovea may update this document from time to time. The version that applies to a given copy of the OSS or Open Spec is the version published with, or referenced by, that copy at the time You obtain it; updates apply to versions of the OSS/Open Spec You obtain after the update. No update revokes a license already granted for a previously published version except as expressly stated in this document (Sections 5.4, 5.5, 14.2). Material changes will be reflected by updating the "Last updated" date and, where practicable, a changelog in the repository. Your continued use after an update constitutes acceptance of the updated terms for materials obtained thereafter; the supplemental terms in Sections 12 and 15 apply to You only as provided in Section 22.
24. General
24.1 Entire agreement. This document, together with the in-package OSS license files and any policy expressly incorporated by reference, is the entire agreement between You and Recovea regarding the OSS and the Open Spec, and supersedes all prior or contemporaneous understandings on that subject. It does not supersede the Hosted Service Terms, which govern their own subject matter.
24.2 Severability. If any provision is held unenforceable, it will be modified to the minimum extent necessary to make it enforceable, or if it cannot be, severed, and the remaining provisions remain in full force. The class-action waiver in Section 15.3 is subject to the specific severance rule stated there.
24.3 No waiver. No failure or delay in exercising any right is a waiver, and no waiver is effective unless in writing and signed by the waiving party.
24.4 Independent parties. The parties are independent contractors. This document creates no partnership, joint venture, agency, fiduciary, employment, or franchise relationship, and no third-party beneficiary rights except as expressly stated (for example, downstream recipients under the in-package OSS licenses, and Recovea's Contributors and licensors as beneficiaries of Sections 10–12).
24.5 Reservation of rights. All rights not expressly granted in this document are reserved to Recovea and its licensors. No license is granted by implication, estoppel, or otherwise, except as expressly set out here.
24.6 Interpretation. Headings are for convenience only. "Including" means "including without limitation." References to a document include its updates as published. The terms of this document apply equally to all forms of distribution (source, object, container, package registry, or otherwise).
24.7 Survival. Provisions that by their nature should survive termination (including Sections 2, 3, 5.3, 5.4, 8.5, 8.6, 9, 10, 11, 12, 13, and 15–24) survive.
Recovea, Inc. — a Delaware corporation. Recovea is a bootstrap-funded US company; nothing in this document concerns investment or securities. RECOVEA and "VERIFIED BY RECOVEA" are marks of Recovea, Inc. (™/℠ as applicable; ® only upon registration).