Skip to content
ObiquityObiquity

Legal

Terms of Service

Last updated September 1, 2026

Free-tier beta — provided AS IS

Obiquity is an experimental, pre-general-availability service. There is no SLA, no warranty, no support obligation, and no liability. Do not use it as the only path to production images. Read the beta terms.

These Terms of Service ("Terms") are a legally binding agreement between you and Obiquity ("Obiquity," "we," "us"), including any individual who operates, hosts, or develops the service. By creating an account, clicking to accept, or using the service, you agree to them and to the Privacy Policy and Acceptable Use Policy, which are incorporated by reference. If you use Obiquity on behalf of an organization, you represent that you have authority to bind it, and "you" includes that organization.

1. Free-tier beta — as-is, assumption of risk, and release

The service is in a free-tier beta / pre-GA period. It is experimental software offered without charge so you can try custom-domain redirects. It is not a generally available, supported, or production-grade product. Marketing copy, dashboards, and documentation describe current intent; they are not warranties or a promise that any feature will keep working.

During the beta, to the maximum extent permitted by law:

  • the service is provided AS IS and AS AVAILABLE, with all faults, and with no warranties of any kind (see §13);
  • there is no uptime, availability, latency, or support SLA, and no duty to provide support at all;
  • we may change, throttle, suspend, or permanently discontinue the service, any hostname, or your account, at any time, with or without notice, and without liability or migration assistance;
  • data, configuration, certificates, DNS verification, logs, and analytics may be lost, delayed, or wrong; we have no duty to back them up for you;
  • "Free" describes the current price ($0). It is not a promise that the service will remain free, remain available, or remain offered;
  • you assume all risk of use, including if you point Kubernetes, CI, or production image pulls at an Obiquity hostname.

If you cannot accept a total loss of the service, do not use it. Keep a working pull path that does not depend on Obiquity.

You hereby release, waive, and forever discharge Obiquity and its operators, developers, contractors, hosts, and any individual acting for them, in any capacity (including personal capacity), from any and all claims, damages, and liabilities arising out of your use of the beta, to the maximum extent permitted by law. If you are a California resident, you waive California Civil Code §1542 (and similar laws) to the extent that waiver is permitted. You will not bring a claim against any individual operator personally for beta use.

2. The service

Obiquity lets you serve container image pulls from a hostname you control. We implement a small slice of the OCI Distribution API and respond to manifest and blob requests with HTTP 307 redirects to an upstream registry you configure (for example Docker Hub, Quay, GHCR, Artifact Registry, or ECR Public).

We are not a container registry. We do not store, cache, scan, sign, or transmit image bytes. After the redirect, the client talks to the upstream directly, using the upstream's own authentication and rate limits. We do not operate a pull-through cache or a content delivery network for layers. We do not resell, pool, or replace any upstream's free or anonymous pull tier.

These Terms cover redirect mode only. Authenticated proxy mode (Obiquity's servers pulling private upstreams with stored credentials on your behalf) is not offered. If it ships, it will have a separate legal review and separate terms — it is not an extension of this agreement.

Push, tag listing, catalog, and upload endpoints are not supported. Redirecting manifest requests is widely implemented by common clients but is not formally sanctioned by the OCI Distribution Spec for every endpoint; we do not warrant that every client or future client version will follow our redirects.

3. Eligibility and accounts

You must be at least 18 years old and able to form a binding contract. You are responsible for the accuracy of your account information, for keeping credentials and API keys confidential, and for all activity under your account. Notify us promptly if you believe your account has been compromised. We may refuse, suspend, or terminate accounts at our discretion, including where we suspect abuse, fraud, or a violation of these Terms or the Acceptable Use Policy.

4. Custom domains, DNS, and TLS

You may only add hostnames you own or are authorized to use. You must complete DNS ownership verification (the TXT record we issue) before we will serve traffic or obtain a TLS certificate for that hostname. Pointing DNS at Obiquity's address without verification, or for a domain you do not control, is prohibited.

Certificates are issued on demand (currently via Let's Encrypt) when a verified hostname first receives HTTPS traffic. Issuance is subject to the certificate authority's rate limits, policies, and availability. We do not guarantee that a certificate will be issued, renewed, or remain trusted by every client. You must not use Obiquity to obtain certificates for hostnames you do not own. Abuse on a customer hostname can affect Obiquity's IP and hosting reputation; we may refuse or revoke certificate approval for that reason.

You are responsible for DNS records at your registrar. If you remove records, let them expire, or point them elsewhere, pulls through that hostname will fail. We do not control third-party DNS.

5. Image rights and your content

You are solely responsible for the container images, names, tags, and metadata reachable through your domains and routes. By adding a domain or configuring a route, you represent and warrant that:

  • you own the images, or you have all licenses, permissions, and rights necessary to make them pullable through that hostname;
  • distributing or facilitating access to those images through your domain does not infringe copyright, trademark, trade secret, publicity, or other rights;
  • you will not use Obiquity to impersonate another project, company, or registry, or to pass off upstream images as originating from a brand you do not control;
  • the images and your use of them comply with applicable law, including export controls and sanctions, and with the upstream registry's own terms.

We do not review, approve, or endorse images behind your routes. A working redirect is not an opinion that you have the rights to distribute the image. You grant Obiquity a limited, non-exclusive license to use your hostnames, routing configuration, and image names solely as needed to operate the service (redirects, TLS, logs, quotas, and the dashboard).

6. Acceptable use

You must follow the Acceptable Use Policy, which is incorporated into these Terms. Among other things, you will not use the service for malware, phishing, typosquatting, illegal content, or attacks on Obiquity, other tenants, or upstream registries. Report violations at /abuse or abuse@obiquity.io. We enforce the AUP with the same admin suspend, domain-delete, and signup kill-switch mechanisms used for other abuse.

7. Upstream registries and trademarks

Pulls complete against third-party registries. Those parties' terms, rate limits, availability, and authentication apply to the person or machine running the pull. Obiquity's own monthly pull quota (for example 500 pulls on the free tier) is separate and does not replace Docker Hub anonymous limits or any other upstream policy. We are not responsible for upstream outages, 429s, takedowns, or license changes.

Docker, Docker Hub, Quay, GitHub, GHCR, Google, Artifact Registry, Amazon, ECR, and related names are trademarks of their respective owners. Obiquity is not affiliated with, endorsed by, sponsored by, or a partner or reseller of Docker, Inc., Red Hat, GitHub, Google, Amazon, or any other upstream. Naming those products describes compatibility of a redirect target, not a commercial relationship. You will not use their marks, or ours, in a way that implies such a relationship.

If an upstream or rights holder objects to a route, we may disable the route or domain without notice.

8. Plans, reliability, and paid tiers

During the beta the only self-serve plan is the free tier: one domain and 500 metered pulls per month, as described on the pricing page, provided under §1. A pull for metering purposes is a GET or HEAD of a tagged manifest, not each layer or digest. We may change or remove limits, metering, or the free tier itself at any time.

Pro, Max, and Enterprise prices and limits shown on the site are marketing descriptions of a possible roadmap. They are not an offer, a commitment to build those features, or a contract to sell them at the displayed price. Waitlist signups are interest only.

The beta runs on a single virtual machine with no high availability. Outages may take every customer's pulls down at once. Container pulls can be part of a production path (including Kubernetes kubelet image pulls). Do not use Obiquity as a production dependency. If you do anyway, you do so solely at your own risk under §1.

When paid tiers become purchasable, additional billing terms will apply before you are charged. Until billing exists, those terms are reserved and not live, and nothing in a future paid SLA applies to beta use.

9. Logs, privacy, and API keys

The Privacy Policy describes what we collect. In short: we log pull metadata (image name, reference, status, user-agent, and a salted hash of the client IP, not the raw address) plus daily aggregates. Raw events are retained about 90 days. A hash of an IP is still generally treated as personal data (pseudonymized, not anonymized) under GDPR.

Those logs often describe your end users and CI systems — people and machines that never signed up with Obiquity. You acknowledge that pulls through your domain are logged, you will not represent otherwise, and you are responsible for any notice or lawful basis your users or jurisdiction require. Formal DPAs are not available on the free tier.

API keys are shown once at creation. You are responsible for keys issued to your account and for rotating them if they leak. Do not send us secrets in hostnames, image names, or user-agents.

10. Our intellectual property

The service, dashboard, documentation, and Obiquity name and marks are ours (or our licensors'). These Terms do not grant you a license to copy the product, use our marks, or suggest an endorsement. Feedback you submit may be used without obligation to you.

12. Suspension, termination, and changes

You may stop using the service and delete domains at any time. We may suspend or terminate access, disable a domain, refuse a certificate, delete your data, or change or discontinue the service — including ending the beta — immediately and without liability, for any reason or no reason. On termination, your right to use the service stops; we have no duty to export your configuration. Provisions that should survive (including 1, 5, 9–11, 13–17) do survive.

We may update these Terms by posting a new version. Continued use after the stated effective date constitutes acceptance. If you do not agree, stop using the service and delete your domains.

13. Disclaimers

THE SERVICE IS PROVIDED "AS IS" AND "AS AVAILABLE," WITH ALL FAULTS, WITHOUT WARRANTIES OF ANY KIND, WHETHER EXPRESS, IMPLIED, STATUTORY, OR OTHERWISE, INCLUDING MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, NON-INFRINGEMENT, QUIET ENJOYMENT, AND ANY WARRANTY ARISING FROM COURSE OF DEALING OR USAGE OF TRADE. WE AND OUR OPERATORS (INCLUDING ANY INDIVIDUAL WHO OPERATES, HOSTS, OR DEVELOPS THE SERVICE) DISCLAIM ALL SUCH WARRANTIES.

WITHOUT LIMITING THE FOREGOING, WE DO NOT WARRANT THAT REDIRECTS WILL SUCCEED, THAT ANY CLIENT WILL FOLLOW THEM, THAT CERTIFICATES WILL ISSUE OR REMAIN VALID, THAT UPSTREAMS WILL SERVE YOUR IMAGES, THAT THE SERVICE WILL BE UNINTERRUPTED, SECURE, OR ERROR-FREE, THAT DEFECTS WILL BE CORRECTED, OR THAT THE SERVICE IS SUITABLE FOR PRODUCTION, CI, OR KUBERNETES IMAGE PULLS. YOU USE THE SERVICE AT YOUR SOLE RISK.

14. Limitation of liability

TO THE MAXIMUM EXTENT PERMITTED BY LAW, OBIQUITY, ITS OPERATORS, DEVELOPERS, CONTRACTORS, HOSTS, AND ANY INDIVIDUAL ACTING FOR THEM, IN ANY CAPACITY (INCLUDING PERSONAL CAPACITY), WILL NOT BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, EXEMPLARY, OR PUNITIVE DAMAGES, OR ANY LOSS OF PROFITS, REVENUE, DATA, GOODWILL, BUSINESS INTERRUPTION, CLUSTER OR PRODUCTION OUTAGE, SUBSTITUTE SERVICES, OR PROCUREMENT COSTS, EVEN IF ADVISED OF THE POSSIBILITY, AND EVEN IF A REMEDY FAILS OF ITS ESSENTIAL PURPOSE.

DURING THE FREE-TIER BETA YOU PAY NOTHING. OUR TOTAL LIABILITY FOR ALL CLAIMS IN THE AGGREGATE WILL NOT EXCEED THE AMOUNTS YOU PAID US FOR THE SERVICE IN THE TWELVE MONTHS BEFORE THE CLAIM, WHICH IS ZERO U.S. DOLLARS (US$0). YOU AGREE THIS ALLOCATION OF RISK IS A FUNDAMENTAL PART OF THE BARGAIN AND THAT THE SERVICE WOULD NOT BE OFFERED FREE WITHOUT IT.

Any claim arising out of the service must be filed within one (1) year after it arose, or it is permanently barred. Some jurisdictions do not allow certain limitations; in those places, liability is limited to the maximum extent permitted, and nothing here excludes liability that cannot legally be excluded (for example fraud or willful misconduct where that bar is mandatory).

15. Indemnification

You will defend, indemnify, and hold harmless Obiquity and its operators, developers, contractors, hosts, and any individual acting for them, in any capacity (including personal capacity), from any claim, damage, loss, and expense (including reasonable attorneys' fees) arising out of: (a) your domains, routes, and the images they expose; (b) your alleged infringement or misappropriation of third-party rights; (c) your violation of these Terms, the AUP, or of law; (d) your use of upstream registries through the service; (e) claims by your end users or anyone pulling through your domain; or (f) your decision to use a beta service in a production path.

16. Governing law

These Terms are governed by the laws of the State of Delaware, USA, without regard to conflict-of-law rules, except that the Federal Arbitration Act governs the interpretation and enforcement of any arbitration agreement to the extent one is later added. Courts located in Delaware shall have exclusive jurisdiction over disputes that are not otherwise resolved, except that we may seek injunctive relief in any forum for unauthorized use of the service or our marks. You waive class actions and jury trial to the extent waivable.

17. Miscellaneous

These Terms, the Privacy Policy, and the Acceptable Use Policy are the entire agreement for the service and supersede prior terms for it. You are not relying on any representation not in those documents. If a provision is unenforceable, the rest remains in effect. Failure to enforce is not a waiver. You may not assign these Terms without our consent; we may assign them in connection with a reorganization or sale. Headings are for convenience only. Notices to you may be sent to your account email or posted in the product. Notices to us: legal@obiquity.io. Abuse: abuse@obiquity.io. Copyright: dmca@obiquity.io. There are no third-party beneficiaries, except that operators and individuals named in §§1, 13–15 may enforce those sections. We are not liable for delays or failures caused by events beyond our reasonable control, including upstream registries, certificate authorities, DNS, or network providers. You consent to receive notices electronically.