01The agreement
These terms are a binding agreement between you and Sarv Webs Pvt. Ltd. ("Sarv", "we", "us"), the operator of SarvCrawl (the "Service"). "You" means the person accepting these terms and, where you are doing so for an employer or client, that organisation — in which case you confirm you are authorised to bind it.
By creating an account, calling the API with a key we issued, or otherwise using the Service, you accept these terms and the privacy policy, which forms part of them.
Where you and we have signed an order form, a master services agreement or a data processing agreement, that document governs to the extent it conflicts with these terms. Everything it does not address is still governed here.
02What the Service does
SarvCrawl takes web pages and documents and turns them into a searchable knowledge base. The pipeline is a fixed sequence: fetch, parse to markdown, index, chunk, embed, search.
Content reaches it six ways — scraping a single URL, crawling from a root URL, mapping a site for its URLs, web search, direct file upload, and scheduled monitoring of a source. What comes back is reachable over the REST API, the Node and Python SDKs, the sarv-kb CLI, the MCP server and the n8n node.
The Service is under active development. Routes, response shapes, console screens and pipeline internals change. We will not remove a documented API route or change its response shape in a breaking way without notice, but everything else may move without one.
What it is not
- It is not a backup. Keep your own copy of anything you cannot re-ingest — the console exports any knowledge base or job to JSONL or CSV at any time.
- It is not a verifier. Parsing, OCR and retrieval are approximations. The conversion audit scores each conversion against its source so you can see how good it was, but a high score is not a warranty of accuracy.
- It is not a licence to content it fetches. We fetch on your instruction; whether you may use what comes back is between you and whoever owns it.
03Accounts, keys and access
You must be old enough to enter into a binding contract where you live, and in any case at least 18. Accounts are for a named person; an organisation gets one account per person rather than one shared login.
You may sign in with an email and password, or with Google or GitHub where we have those enabled. Keep your credentials to yourself, and keep the contact address on the account current — it is where a security notice will go.
API keys
- A
sarv_sk_key authenticates as you and carries your permissions. Treat it as a password: never in a repository, a ticket, a screenshot or a client-side bundle. - We store only a SHA-256 hash of each key and its first twelve characters for masked display. We cannot recover a key you have lost — issue a new one and revoke the old.
- You are responsible for everything done with a key issued to you, including token consumption, up to the point you revoke it. Keys can be paused or revoked from the console at any time, independently of your login sessions.
- Tell us at sales@sarv.com as soon as you believe a key or an account has been compromised.
Roles
There are three roles, all enforced at the API rather than only hidden in the interface. Within your organisation an account is either admin or user, and whoever holds admin decides who else gets it; we do not adjudicate that internally. The third, super admin, belongs to our own platform operators, is not assignable within your organisation, and is subject to the access limits in What we never do in the privacy policy.
04What you may put into SarvCrawl
This is the obligation that matters most, so it gets its own section. When you submit a URL, a domain, a search or a file, you are instructing us to fetch and process it on your behalf, and you confirm that you have the right to do so.
Specifically, for everything you submit you confirm that:
- You own the content, or you have permission from whoever does, or your access is otherwise lawful — including under any applicable copyright, database, contract or computer-misuse law.
- Fetching it does not breach the terms of use, robots directives or access controls of the site or system it comes from.
- It does not require you to bypass a paywall, a login you are not entitled to use, a rate limit or any other technical restriction.
- Where it contains personal data, you have a lawful basis for having it processed, and you are the controller of that data — see Content you ingest in the privacy policy.
- It is not content whose mere possession is unlawful.
We do not review targets before fetching them and we do not police your corpus. The crawler is bounded by the depth, page limit and path excludes you set, and it fetches what those bounds reach. That makes the choice of target yours, and the consequences of a bad choice yours too.
05Acceptable use
You may not use the Service, or let anyone use it through your account or key, to:
- Break any law that applies to you, us, or the systems being fetched.
- Collect personal data you have no lawful basis to hold — including scraping profiles, contact details or biometric data for resale, unsolicited marketing or surveillance.
- Infringe copyright, database rights, trade marks, trade secrets or any other right in someone else's content.
- Circumvent a paywall, licence check, access control, authentication step or rate limit.
- Overload, degrade or interfere with any third-party site or service, or with the Service itself, whether by volume, concurrency or malformed input.
- Probe, scan or test our infrastructure other than under the coordinated disclosure process in our security policy.
- Resell, sublicense or rebrand the hosted Service as your own, or use it to build a substantially similar competing product.
- Reverse engineer the hosted Service, except where the open-source components allow it under their own licences.
- Evade a token allowance, a rate limit, a suspension or a plan restriction — including by registering additional accounts to do so.
- Impersonate anyone, or misrepresent your affiliation with any person or organisation, in your account details or your traffic.
- Generate or distribute malware, phishing content, or content that sexually exploits a minor.
- Automate abuse against people — harassment, doxxing, or building a dossier on an individual without their knowledge.
We may investigate a suspected breach and, where we must, cooperate with a lawful request from a court or a competent authority. Where the breach is causing active harm to a third party we may act first and tell you afterwards.
06Your content and your corpus
You keep ownership
Everything you submit and everything the pipeline derives from it — the markdown, the chunks, the embeddings, the audit scores — is yours. We claim no ownership of any of it.
The licence we need to run the Service
To operate the Service we need permission to do the things the Service does. You grant us a worldwide, non-exclusive, royalty-free licence to fetch, store, copy, convert, index, chunk, embed, search, transmit and display your content solely in order to provide, secure and support the Service to you. It ends when the content is deleted or your account closes, whichever is later. It covers nothing else.
No training, no exceptions
We do not train, fine-tune, evaluate or improve any model on your content, and we do not permit a third party to. There is no training step in the pipeline — it is retrieval end to end. Embeddings are computed for search and stored beside your chunks; they are not aggregated into anything that outlives your knowledge base.
Getting it out, and getting it deleted
- Chunks and markdown are readable in the console and export to JSONL or CSV whenever you want them.
- Deleting a knowledge base or a job removes its rows, its stored objects and its search index entries. Backups age out on their own retention cycle — see data retention.
- On account closure you have 30 days to export before we begin deletion.
Feedback
If you send us a suggestion, a bug report or a feature idea, we may act on it without owing you anything for it. That is not a licence to anything else you own — it is limited to the feedback itself.
07Tokens, plans and payment
The Service meters one thing: tokens, consumed by parsing, chunking and embedding. A dense 40-page PDF costs more than a thin HTML page. Reading results does not consume tokens, and there is no per-seat charge for people who only read.
Every new account gets one billion tokens free, with no card. The free allowance does not expire; it sits on the account until it is spent.
When an allowance is exhausted, ingest jobs stop being accepted. Nothing is deleted and search keeps working on what you already have.
Paid plans
- Paid plans and token packs are quoted in an order form or on the pricing page in force at the time you subscribe. Those terms — price, allowance, billing period, currency, tax treatment — govern the commercial relationship and are read together with this agreement.
- Prices are exclusive of GST and any other applicable tax, which is added at the prevailing rate.
- Fees already paid are not refundable except where the law requires it, or where we withdraw the Service mid-term — in which case you get the unused portion of the current period back pro rata.
- We may change prices with at least 30 days' notice. A change takes effect at your next renewal, never mid-term.
- Where an invoice is overdue we may suspend ingest after notice. We will not delete a corpus for non-payment without giving you a chance to export it.
08Availability, support and changes
We aim to keep the Service up and we watch it, but we do not commit to an uptime figure unless one is written into an order form. Ingest is asynchronous by design: jobs queue, and a queue can be slow without anything being broken.
- Planned maintenance is announced in advance where it will interrupt ingest.
- Support runs on the channels published for your plan. On the free allowance that is best effort.
- We may add, change, deprecate or remove features. A documented API route gets notice and, where we can, a deprecation period before it changes in a way that would break a caller.
09Confidentiality
Each of us may learn things about the other that are not public — your corpus and configuration on our side, our non-public technical and commercial detail on yours. Neither of us will disclose the other's confidential information except to people who need it to perform this agreement and who are under a duty of confidence, or where the law compels disclosure.
Where disclosure is compelled, whoever is compelled will tell the other as far in advance as the law permits.
10Intellectual property
The Service, its interfaces, its documentation and the SarvCrawl and Sarv names and marks belong to us or our licensors. These terms grant you a limited, revocable, non-transferable right to use the hosted Service as it is intended to be used, and nothing more.
If you believe content in the Service infringes your rights, write to sales@sarv.com identifying the work, where it appears, and your authority to act. We will investigate, and we may remove content or disable an account while we do.
11Self-hosted deployments
SarvCrawl can be run on your own infrastructure. When you do, these terms do not apply to that deployment — your rights come from the open-source licences the code ships under, and those licences are the whole of the arrangement.
- The first-party stack is licensed under Apache-2.0; the crawling engine is a fork of Firecrawl and is AGPL-3.0. The NOTICE file that ships with the source states which is which.
- A self-hosted deployment is yours to secure, back up and operate. We provide no uptime, no support and no data handling for it unless a separate agreement says otherwise.
- We hold no data from a self-hosted deployment. Nothing in it reaches us.
- The defaults ship hardened. If you change them — exposing a data service, disabling the SSRF guard, weakening the queue admin allowlist — the consequences are yours.
12Third-party services and content
The Service fetches from sites and systems we do not control, and it can be driven by clients we do not control — an MCP-speaking AI client, an n8n workflow, your own code. We are not responsible for third-party content the pipeline returns, nor for what a client you connect does with it.
Where you sign in with Google or GitHub, that provider's terms and privacy policy govern their side of it. The current list of providers we rely on is in the privacy policy, and it is kept short on purpose.
13Suspension and termination
You may close your account at any time, through delete your account. We confirm the request by email — a link to the address on the account — and act on it 24 hours later, so there is a window in which you can still stop it. Closing an account ends the paid term you are in; it does not refund it.
We may suspend or terminate access where:
- you breach these terms, and materially so, or fail to fix a fixable breach within a reasonable notice period;
- your use is harming a third party, our infrastructure or another customer, in which case suspension may be immediate;
- we are required to by law; or
- an invoice remains unpaid after notice.
On termination your right to use the Service stops immediately. You have 30 days to export your corpus before deletion begins — measured from the moment the account is deactivated, not from when you asked — unless the law forbids us from giving you that window. Sections on your content, confidentiality, intellectual property, disclaimers, liability, indemnity and governing law survive termination.
14Warranties and disclaimers
We warrant that we will provide the Service with reasonable skill and care.
Beyond that, and to the fullest extent the law allows, the Service is provided as is. We do not warrant that it will be uninterrupted or error-free, that a crawl will reach every page, that a conversion will be faithful, that OCR will be correct, that a search will surface the right chunk, or that it will meet a requirement you have not told us about. All implied warranties of merchantability, fitness for a particular purpose and non-infringement are excluded so far as the law permits.
Output from the Service is material for you to evaluate, not advice to act on unchecked. Do not use it as the sole basis for a decision with legal, financial, medical or safety consequences.
15Limitation of liability
To the extent the law allows, neither of us is liable to the other for indirect or consequential loss, or for lost profits, lost revenue, lost goodwill, or the cost of substitute services — even where the loss was foreseeable.
Our total liability arising out of or relating to this agreement is capped at the greater of the fees you paid us in the twelve months before the claim arose and ₹10,000. Where you use the Service on the free allowance and have paid us nothing, the second figure is the cap.
Nothing here limits liability that cannot lawfully be limited — including liability for death or personal injury caused by negligence, or for fraud or fraudulent misrepresentation.
The cap does not apply to your obligation to pay fees due, or to the indemnity below.
16Indemnity
You will defend and indemnify us against third-party claims, and the reasonable costs and damages that come with them, arising from:
- content you submitted or instructed us to fetch, including a claim that fetching or processing it infringed a right or breached a duty you owed;
- your breach of What you may put into SarvCrawl or Acceptable use; or
- your breach of a law applicable to your use of the Service.
We will tell you promptly about any claim we want indemnified, let you control the defence of it, and cooperate at your expense. You will not settle a claim in a way that admits fault on our part or binds us to anything without our consent.
17Governing law and disputes
This agreement is governed by the laws of India, without regard to conflict-of-laws rules. The courts of Jaipur, Rajasthan, India have exclusive jurisdiction, and each of us submits to it.
Before either of us starts proceedings, we will try to resolve the dispute directly: write to sales@sarv.com setting out what the dispute is and what you want, and we will engage in good faith for 30 days. This does not stop either of us seeking urgent injunctive relief.
18Changes to these terms
We may update these terms. When a change materially affects your rights or obligations, we will give at least 30 days' notice by email to the address on your account or a notice in the console before it takes effect.
Continuing to use the Service after a change takes effect is acceptance of it. If you do not accept it, close your account before the effective date and export your corpus.
The date at the top of this page is when it last changed.
19General
- Entire agreement. These terms, the privacy policy and any order form are the whole agreement about the Service and replace anything said before.
- Assignment. You may not assign this agreement without our written consent. We may assign it to an affiliate or as part of a merger, acquisition or sale of assets, on notice to you.
- No waiver. Not enforcing a term once does not waive it.
- Severability. If a provision is unenforceable, it is narrowed to the minimum extent needed to make it enforceable, and the rest stands.
- No partnership. Nothing here creates a partnership, agency or employment relationship.
- Notices. Notices to you go to the address on your account. Notices to us go to sales@sarv.com.
- Force majeure. Neither of us is liable for a delay caused by something genuinely outside our control, provided we tell the other and work to limit it.
20Contact
Where to write, depending on what you need:
- Questions about these terms · Security reportssales@sarv.com
- Questions about the Servicesupport@sarv.com
Privacy policy
What SarvCrawl collects, why, who else ever sees it, how long we keep it, and how to make us delete it. Written to be read rather than skimmed past.
Read itSomething here unclear?
A clause that does not fit how you plan to use SarvCrawl, or a commitment your security or procurement team needs in writing — ask before you sign up, not after.
- Terms and contracts · Privacy and data requests · Vulnerability reports — sales@sarv.com