Olywork
Catalog Use cases Workflows Agents Docs Pricing Start free โ†’
Trust, Legal & Support Hub

Transparent Terms. Zero Secrets Stored.

Everything you need to know about our 0% markup commitment, security architecture, privacy boundaries, and customer support.

โšก
The 0% Markup Guarantee (ยง08)

olywork never inflates upstream API prices. Calls on our catalog keys are metered at exact provider cost in micro-USD. Calls on your own team keys (BYOK) are always 100% free with zero platform fee.

01

Scope and Agreement

olywork ("we", "us", "our") provides an agent tooling registry and credential orchestration proxy at olywork.com (the "Service"). These Terms of Service govern your access to and use of our hosted platform, API, CLI, and associated tools.

Self-hosted installations: If you deploy the open-source olywork engine on your own private infrastructure, your use is governed exclusively by the Apache 2.0 / MIT Source License. We retain no data and assume no operational obligations for self-hosted instances.

02

Accounts and Identity

You access the Service via authentication tokens or OAuth sign-in. You must maintain the confidentiality of your credentials and are fully responsible for all calls and actions initiated under your account tokens, including actions performed by autonomous AI agents operating on your behalf.

  • Access tokens are hashed via SHA-256; raw tokens are never persisted in plaintext.
  • You may revoke active tokens instantaneously via the dashboard or CLI at any time.
03

Team Workspaces & Role-Based Access

Accounts can create and join multiple team workspaces. Team owners and administrators maintain administrative control over member roles, tool assignment, daily spend caps, and credential configuration.

Members never see or export raw secret values stored by the team. Stored credentials are injected strictly server-side during proxied upstream execution.

04

Credential Vault & Encryption

We treat credential custody with zero-trust architecture:

  • All API keys, secrets, and OAuth refresh tokens are encrypted at rest with Fernet authenticated encryption (AES-256-CBC + HMAC-SHA256).
  • Secrets are never written to disk unencrypted, never returned to client endpoints, and never rendered in browser interfaces.
  • In-flight calls decrypt secrets directly into memory exclusively to inject required authorization headers before transmitting requests upstream.
05

Upstream APIs & Provider Terms

When you execute calls to third-party providers (including Google, LinkedIn, Slack, X, Hunter, and others), you remain bound by the respective terms of service, acceptable use policies, and rate limits of those upstream services. olywork acts as a transport and authorization proxy and does not alter upstream terms.

YouTube API Services: Use of YouTube integrations is subject to the YouTube Terms of Service and Google Privacy Policy. Access may be revoked via Google Security Settings.

06

Acceptable Use & Sandbox Boundaries

You agree not to use the Service for malicious activities, including credential harvesting, denial-of-service attacks, cryptocurrency mining, unsolicited bulk messaging (spam), or attempts to circumvent tenant isolation and server sandboxes.

07

Prepaid Balances & Metered Billing

Catalog endpoints served through olywork-managed provider keys deduct funds from your team's prepaid balance in micro-USD. All deductions match the exact advertised per-call rate card with 0% platform markup. Balances are prepaid and non-refundable except where required by law.

08

Limitation of Liability

The Service is provided "AS IS" and "AS AVAILABLE". To the maximum extent permitted by applicable law, olywork shall not be liable for indirect, incidental, special, consequential, or punitive damages, or loss of profits, data, or goodwill.

๐Ÿ” Fernet AES-256

All API keys and OAuth tokens encrypted at rest with authenticated cipher suites.

๐Ÿšซ Zero Body Storage

Payload bodies pass directly through memory to upstream providers and are never logged.

๐Ÿ›ก๏ธ No AI Training

Your data, skills, prompts, and tokens are never used to train machine learning models.

01

Information We Collect

We believe in minimal data footprint:

  • Identity: Email address for authentication and team role assignment.
  • Credentials: Encrypted secret strings and OAuth tokens stored for proxy execution.
  • Metadata: Call timestamps, method, status code, latency, and spend micro-USD for team audit trails.

We do not collect physical addresses, telephone numbers, payment card numbers (handled directly by Stripe), or government IDs.

02

In-Flight Request Data (Zero Body Logging)

When an agent sends a payload through /call/, the request body is relayed directly to the upstream destination. Response streams are returned verbatim. Neither request nor response bodies are written to databases, log aggregators, or permanent disks.

03

Google API Services User Data Policy & Limited Use

olywork's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements:

  • Google user data is utilized strictly to provide user-facing features and execute authorized API calls requested by your agents.
  • We do not transfer Google user data to third parties, unless necessary to provide or improve features, comply with applicable law, or as part of a merger/acquisition.
  • Google user data is never used for advertising, profiling, or machine learning model training.
  • No human employees access your Google user data unless explicitly authorized by you for customer support resolution.
04

Cookies and Attribution

We utilize essential first-party session cookies to maintain your signed-in state. For marketing attribution on public landing pages, we use a first-party click capture cookie (olywork_ad) to measure advertising effectiveness without third-party cross-site trackers.

05

Data Retention & Deletion Rights

You have the absolute right to export or delete your data at any time. Removing a credential destroys its ciphertext instantly. You can request complete account deletion by contacting support@olywork.com.

๐Ÿ“จ
Direct Support
Reach our core engineering team directly for help with integrations, catalog endpoints, or custom setups.
Email support@olywork.com โ†’
๐Ÿ›ก๏ธ
Security & Vulnerabilities
Report security concerns or responsible disclosure findings directly to our security team.
Contact security@olywork.com
๐Ÿ™
GitHub & Community
Explore open-source releases, submit feature requests, or report issues on GitHub.
Open GitHub Repository

Frequently Asked Questions

Q1

I cannot sign in or didn't receive a magic code.

olywork offers GitHub, Google, and magic-code authentication. If your email code hasn't arrived within 2 minutes, check your spam folder for messages from no-reply@olywork.com or try signing in via GitHub or Google.

Q2

Why was my API call refused with a 402 Payment Required?

Calls made using olywork's managed catalog keys deduct from your team's prepaid balance. Run olywork balance or visit the Billing dashboard to inspect your ledger and add funds via Stripe. Every new workspace includes $1.00 free credits.

Q3

How do I delete stored API credentials?

Deleting a tool or secret in the web dashboard instantly erases the encrypted ciphertext. You can also run olywork secret remove <key> via CLI.

Q4

Can I use olywork with Claude Desktop, Cursor, or Cline?

Yes! olywork exposes a native MCP server. Run olywork mcp install or visit Docs to connect your desktop AI assistants with a single command.

olywork

The OpenRouter for AI Agent Tools.
One token for 2,800+ endpoints. Zero key management.

Explore
Catalog Pricing Use casesWorkflowsAgents
Build
API Reference Tutorial llms.txt
Resources
Workflows Use CasesAgents
Company
Blog Support Terms & policies Privacy policy
© 2026 Olywork. All rights reserved.
Pay-per-call ยท Zero markup ยท One API key