On this page
Navigate every Terms section with clarity and speed.
This page is organised for fast access to the legal topics that matter most. Tap any tile to jump directly to the section you need, from privacy and billing to security, intellectual property, and termination.
Quick navigation
Use the cards below to jump straight to the numbered section you want.
Total sections
17
Key focus
Security
Access style
Direct jump
Design
Modern
Jump to topic
Tap a topic to skip ahead
This table of contents lives at the top so you can move quickly through the full Terms without scrolling through every section first.
Agreement to terms
These Terms and Conditions ("Terms") constitute a legally binding agreement between you ("User", "you", or "your") and CoconutDB ("we", "us", or "our"), governing your access to and use of the CoconutDB platform, including all associated features, APIs, automation tools, and services (collectively, the "Platform").
By registering an account, joining a workspace, or otherwise accessing any part of the Platform, you confirm that you have read, understood, and agree to be bound by these Terms, together with our Privacy Policy, which is incorporated herein by reference.
If you do not agree to these Terms, you must not access or use the CoconutDB platform. If you are accepting these Terms on behalf of an organisation, you represent and warrant that you have authority to bind that organisation to these Terms.
These Terms apply to all users of the Platform, including Global Administrators, Workspace Admins, Editors, and Viewers, regardless of how access was obtained.
Platform description
CoconutDB is a collaborative backend platform that enables teams to design and manage structured data tables, control access permissions, track data changes through version history, automate workflows, manage file storage via the Document Vault, and expose REST APIs — all through a single unified browser-based interface.
The Platform is designed for use by technical developers and non-technical administrators working together in shared workspaces. Key capabilities include:
- Data Tables Create and manage structured data tables with auto-generated REST APIs for every table.
- Document Vault Workspace-level secure file storage backed by PostgreSQL binary storage.
- Automation Workflows Serverless JavaScript functions triggered by webhooks and platform events.
- Access Control Role-based (RBAC) and row-level (RLS) security policies for fine-grained data access.
- Webhooks Event-driven HTTP notifications to external systems on record and system events.
- Developer API Keys Long-lived static keys for server-to-server integrations and automation scripts.
CoconutDB reserves the right to modify, enhance, or discontinue any feature of the Platform at any time, with or without notice, subject to the notification obligations described in Section 16.
Account registration & eligibility
Eligibility
You must be at least 18 years of age to register for and use the CoconutDB platform. By creating an account, you represent and warrant that you meet this age requirement. The Platform is intended for business and professional use only.
Registration process
To access the Platform, new users must register through the login page using a valid Workspace ID provided by an existing workspace administrator. The registration process requires:
- A valid, working email address that you own and control.
- Your full name as you wish it to appear in the platform.
- A strong, unique password of your own choosing.
- A Workspace ID, obtained from an authorised workspace administrator.
Account security obligations
You are solely responsible for maintaining the confidentiality of your login credentials. You agree to:
- Keep your password confidential and never share it with any other person.
- Enable two-factor authentication (2FA) immediately — this is mandatory for all Global Admin accounts and strongly recommended for all other accounts.
- Notify CoconutDB immediately at admin@coconutdb.com if you suspect any unauthorised access to your account.
- Ensure that you log out of the Platform at the end of each session, particularly on shared devices.
- Not create accounts on behalf of another person without their express authorisation.
CoconutDB will never ask for your password via email, chat, or any other communication channel. If you receive such a request, treat it as a phishing attempt and report it to security@coconutdb.com immediately.
One Global Admin per installation
Each CoconutDB installation supports exactly one Global Admin account. This account is created automatically during the initial installation. Additional Global Admin accounts cannot be created. The Global Admin is responsible for platform-wide governance, including user management, workspace oversight, and security configuration.
Acceptable use
CoconutDB grants you a limited, non-exclusive, non-transferable, revocable licence to access and use the Platform strictly in accordance with these Terms and for your organisation's legitimate business purposes.
Permitted uses
- Creating and managing data tables to store and organise your organisation's business data.
- Inviting team members to workspaces and assigning appropriate roles to control their access.
- Building and consuming the auto-generated REST APIs to power your own applications.
- Storing business documents, reports, and supporting files in the Document Vault.
- Configuring webhooks to integrate CoconutDB events with your external systems.
- Writing automation workflows to process data and trigger business logic in response to platform events.
- Generating and using Developer API keys to connect server-side applications and scheduled jobs.
- Using the Email Dispatcher to send transactional emails from your applications.
Rate limits & fair use
To maintain platform stability and fair access for all users, CoconutDB enforces automatic rate limiting. Any user account that makes 30 or more API calls within a 30-second window will be automatically blocked for 5 minutes. Sustained or repeated rate limit violations may result in permanent account suspension at the discretion of the Global Admin or CoconutDB.
You agree not to design or operate any system that intentionally approaches, probes, or circumvents these rate limits. Attempting to do so is a breach of these Terms.
Prohibited conduct
The following activities are strictly prohibited on the CoconutDB platform. Engaging in any of these activities may result in immediate account suspension or permanent termination, and may expose you to legal liability.
Security violations
- Attempting to gain unauthorised access to any workspace, account, or system component that you are not explicitly authorised to access.
- Probing, scanning, or testing the vulnerability of the Platform or any related system without CoconutDB's prior written consent.
- Attempting to bypass, disable, or circumvent any authentication, security, or access control mechanism.
- Sharing your API keys, session tokens, or login credentials with unauthorised parties.
- Intercepting, monitoring, or recording other users' data or communications without authorisation.
Data misuse
- Storing, processing, or transmitting any data that violates applicable laws, including data protection and privacy regulations.
- Using the Platform to store, distribute, or process illegal content of any kind.
- Uploading malicious files, malware, ransomware, or any code designed to damage or interfere with systems.
- Using the Document Vault or table attachments to distribute unauthorised copies of copyrighted material.
- Processing sensitive personal data (health records, financial data, government IDs) without the appropriate safeguards and consent required by applicable law.
Platform abuse
- Using automation workflows or API calls to generate excessive load that degrades performance for other users.
- Using the Email Dispatcher to send spam, unsolicited bulk email, or messages that violate applicable anti-spam laws.
- Configuring webhooks to transmit platform data to systems engaged in unlawful activity.
- Reverse engineering, decompiling, or disassembling any part of the Platform's source code or infrastructure.
- Reselling, sublicensing, or otherwise commercialising access to the Platform without CoconutDB's prior written authorisation.
CoconutDB reserves the right to immediately suspend any account that is found to be engaged in prohibited conduct, without prior notice. Accounts suspected of malicious activity may be reported to relevant law enforcement authorities.
Workspaces & your data
Data ownership
You retain full ownership of all data, content, records, and files that you create, upload, or store within your CoconutDB workspace ("Your Data"). CoconutDB does not claim any intellectual property rights over Your Data. By storing data on the Platform, you grant CoconutDB a limited, non-exclusive, royalty-free licence to host, store, process, and display Your Data solely as necessary to provide the services described in these Terms.
Data responsibility
You are solely responsible for the accuracy, legality, and appropriateness of all data stored in your workspace. This includes:
- Ensuring that you have all necessary rights, consents, and permissions to store and process any personal data in your workspace tables.
- Complying with all applicable data protection laws (including GDPR, CCPA, and other regional regulations) with respect to the personal data you process.
- Keeping your workspace data accurate, up to date, and free from content that is unlawful, harmful, or offensive.
- Managing workspace member access and ensuring that role assignments reflect each member's actual business need for access.
Workspace isolation
Each workspace operates within a logically isolated database schema. Data from one workspace cannot be accessed by users of another workspace, regardless of role. CoconutDB's engineers may access workspace data only when necessary to provide technical support, investigate security incidents, or comply with legal obligations, and only to the minimum extent required.
Recycle Bin & hard deletion
Records deleted from the Active Catalog are moved to the Recycle Bin and can be restored by Editors or Admins. Permanent (hard) deletion is irreversible and is restricted to Workspace Admins. Once a record is hard-deleted, CoconutDB cannot recover it. You are responsible for ensuring that permanent deletion is intentional and authorised.
Version history
CoconutDB maintains a full audit trail of all record changes, capturing the user, timestamp, and field-level delta for every update. This version is retained for the lifetime of the record and is accessible to users with appropriate read permissions on the table.
API keys & integrations
API key responsibilities
Developer API keys generated within CoconutDB carry Admin-level privileges for the workspace. By generating and using an API key, you accept the following obligations:
- Store API keys exclusively in secure environment variables or an approved secrets management system. Never hardcode keys in source files.
- Never commit API keys to any source code repository, public or private. If a key is exposed in any repository, revoke it immediately.
- Restrict API key usage to the specific application or service for which it was generated.
- Revoke any API key as soon as it is no longer required or if you have any reason to believe it has been compromised.
- You are fully liable for all actions taken using API keys generated under your workspace, whether by you or by any system or person you have shared a key with.
Webhooks
You are responsible for the security and reliability of all webhook endpoints you configure. CoconutDB will transmit event payloads to the URLs you specify without validating the security of those endpoints. You must ensure that webhook-receiving systems authenticate incoming requests and do not expose sensitive data.
Email Dispatcher
By registering SMTP credentials with the Email Dispatcher, you confirm that you are authorised to use the email account in question and that emails sent through the Dispatcher will comply with all applicable anti-spam laws (including CAN-SPAM, CASL, and GDPR email provisions). CoconutDB is not liable for any consequences arising from email campaigns sent through your Dispatcher configuration.
Automation Workflows
Automation Workflows execute JavaScript code that you author. You are solely responsible for the correctness, security, and legal compliance of all code you deploy as a workflow. CoconutDB does not review workflow code before execution. By deploying a workflow, you warrant that the code does not violate these Terms, applicable laws, or the rights of any third party.
Workflow code runs with access to your workspace's data and APIs. A misconfigured or malicious workflow can modify or delete workspace data. CoconutDB accepts no liability for data loss or unintended consequences resulting from workflow execution.
Subscription & billing
Access to CoconutDB may be subject to a subscription fee depending on the plan selected by your organisation. The specific pricing, billing cycle, and included features are described on the CoconutDB pricing page and in any order form or agreement executed between your organisation and CoconutDB.
Payment terms
All fees are quoted and charged in the currency specified in your subscription agreement. Subscription fees are billed in advance on a monthly or annual basis, as selected at signup. Payments are due within the timeframe specified in your invoice. Overdue accounts may have access suspended. All fees are non-refundable except where expressly stated or required by applicable law.
Plan changes & upgrades
You may upgrade your subscription plan at any time. Downgrades or cancellations take effect at the end of the current billing period. No partial refunds are issued for unused portions of a billing period unless required by law.
Taxes
All quoted prices are exclusive of applicable taxes, levies, and duties. You are responsible for paying all taxes applicable to your subscription in your jurisdiction. Where CoconutDB is required by law to collect tax, it will be added to your invoice.
If you are operating under a self-hosted or enterprise licence agreement, the billing terms in that agreement supersede this section. Contact admin@coconutdb.com for enterprise pricing enquiries.
Intellectual property
CoconutDB's intellectual property
The CoconutDB platform, including its software, source code, user interface, design, documentation, trademarks, logos, and all related intellectual property, is owned exclusively by CoconutDB or its licensors. Nothing in these Terms transfers any ownership of CoconutDB's intellectual property to you.
You are granted only the limited licence described in Section 4. You may not copy, modify, distribute, sell, sublicense, or create derivative works from any part of the Platform without CoconutDB's prior written consent.
Your intellectual property
As described in Section 6, you retain ownership of Your Data. You also retain ownership of any automation workflow scripts, RLS policy expressions, and other custom configurations you create within the Platform. CoconutDB does not claim ownership over any of these.
Feedback
If you provide CoconutDB with suggestions, feedback, or ideas regarding the Platform ("Feedback"), you grant CoconutDB a perpetual, irrevocable, royalty-free, worldwide licence to use, implement, and incorporate that Feedback into the Platform without any obligation to compensate you or acknowledge the contribution.
Confidentiality
Each party may have access to confidential information of the other party in connection with these Terms. "Confidential Information" means any non-public information disclosed by one party to the other that is designated as confidential or that reasonably should be understood to be confidential given the nature of the information and circumstances of disclosure.
Your obligations
You must not disclose CoconutDB's Confidential Information (including platform architecture, API specifications, pricing, and security mechanisms) to third parties without CoconutDB's prior written consent. You must use CoconutDB's Confidential Information only for the purposes of using the Platform as permitted under these Terms. You must apply at least the same standard of care to protect CoconutDB's Confidential Information as you use to protect your own confidential information of similar sensitivity.
CoconutDB's obligations
CoconutDB will treat Your Data as confidential and will not disclose it to third parties except as described in the Privacy Policy or as required by applicable law. CoconutDB employees and contractors who access workspace data in the course of providing support are bound by confidentiality obligations.
Disclaimers
THE COCONUTDB PLATFORM IS PROVIDED "AS IS" AND "AS AVAILABLE" WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED. TO THE FULLEST EXTENT PERMITTED BY APPLICABLE LAW, COCONUTDB DISCLAIMS ALL WARRANTIES, INCLUDING IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, AND NON-INFRINGEMENT.
Without limiting the foregoing, CoconutDB does not warrant or represent that:
- The Platform will be available at all times, uninterrupted, or error-free.
- Any errors, bugs, or defects in the Platform will be corrected within any particular timeframe.
- The Platform will meet your specific business requirements or be fit for any particular purpose.
- Data stored on the Platform will never be lost, corrupted, or subject to unauthorised access.
- The results obtained from using the Platform (including auto-generated APIs, automation workflows, and data outputs) will be accurate, complete, or reliable.
CoconutDB makes reasonable efforts to maintain platform uptime and data integrity, but you acknowledge that no software system can guarantee 100% availability or data preservation. You are responsible for maintaining adequate backups of critical data stored in your workspace.
Limitation of liability
TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, COCONUTDB SHALL NOT BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, PUNITIVE, OR EXEMPLARY DAMAGES, INCLUDING LOSS OF PROFITS, LOSS OF DATA, LOSS OF GOODWILL, BUSINESS INTERRUPTION, OR ANY OTHER INTANGIBLE LOSSES, ARISING OUT OF OR IN CONNECTION WITH YOUR USE OF OR INABILITY TO USE THE PLATFORM.
In all cases, CoconutDB's total aggregate liability to you for any claims arising out of or relating to these Terms or your use of the Platform shall not exceed the greater of (a) the total fees paid by you to CoconutDB in the twelve months preceding the claim, or (b) one hundred US dollars (USD $100).
Specific exclusions
CoconutDB is not liable for any loss or damage arising from:
- Your failure to secure your API keys, passwords, or session tokens.
- Data loss or corruption resulting from hard deletions performed by authorised Workspace Admin accounts.
- The actions of automation workflows, webhook transmissions, or Email Dispatcher sends that you have configured.
- Third-party systems that receive data via webhooks or integrations you have set up.
- Rate limiting enforcement that temporarily blocks your account or API access.
- Any downtime, maintenance windows, or service interruptions.
Some jurisdictions do not allow the exclusion or limitation of liability for consequential or incidental damages. In such jurisdictions, CoconutDB's liability is limited to the maximum extent permitted by law.
Indemnification
You agree to defend, indemnify, and hold harmless CoconutDB, its officers, directors, employees, contractors, and agents from and against any and all claims, damages, losses, liabilities, costs, and expenses (including reasonable legal fees) arising out of or relating to:
- Your access to or use of the Platform in violation of these Terms.
- Your Data — including any claim that Your Data infringes the intellectual property rights, privacy rights, or other rights of any third party.
- Your violation of any applicable law or regulation, including data protection laws.
- Any automation workflow, webhook, or integration you have configured that causes harm to a third party.
- Any misuse of API keys, Developer tokens, or access credentials under your account.
- Your breach of any representation, warranty, or obligation made in these Terms.
CoconutDB reserves the right, at your expense, to assume exclusive defence and control of any matter for which you are required to indemnify us. You agree to cooperate fully with CoconutDB's defence of any such claims.
Termination
Termination by you
You may stop using the Platform at any time. To close your account permanently, contact admin@coconutdb.com. Workspace Admins can remove members from a workspace at any time via the Project Members panel. The Global Admin can delete user accounts platform-wide from the User Management console.
Termination or suspension by CoconutDB
CoconutDB may suspend or terminate your account or access to the Platform at any time, with or without notice, for any of the following reasons:
- Breach of any provision of these Terms.
- Engagement in any prohibited conduct described in Section 5.
- Non-payment of applicable subscription fees.
- Request by law enforcement or government authority.
- Extended periods of account inactivity, where applicable under the plan terms.
- Where CoconutDB reasonably believes that continued access poses a security risk to the Platform or other users.
Effect of termination
Upon termination or expiry of your account:
- Your access to the Platform and all associated workspaces will be revoked immediately.
- All Developer API keys associated with your account will be invalidated.
- Your Data will be retained for a reasonable period (typically 30 days) after which it may be permanently deleted, unless required to be retained by law.
- You will lose access to all version history, audit logs, and vault documents in workspaces you administered.
Provisions of these Terms that by their nature should survive termination (including Sections 9, 10, 11, 12, and 13) will continue to apply. You are responsible for exporting any data you wish to retain before account closure. CoconutDB is not responsible for any data loss resulting from account termination.
Governing law
These Terms shall be governed by and construed in accordance with applicable law. The specific governing jurisdiction will be identified in your subscription agreement or enterprise contract. In the absence of such an agreement, these Terms shall be governed by the laws of the jurisdiction in which CoconutDB is incorporated, without regard to its conflict of law provisions.
Dispute resolution
In the event of any dispute, claim, or controversy arising out of or relating to these Terms or your use of the Platform, the parties agree to first attempt to resolve the dispute informally by contacting CoconutDB at legal@coconutdb.com. CoconutDB will use reasonable efforts to resolve the dispute within 30 days of receiving written notice.
If informal resolution is not achieved within 30 days, either party may pursue formal legal remedies in accordance with the applicable governing law.
Class action waiver
To the extent permitted by applicable law, you agree that any dispute arising out of these Terms will be resolved on an individual basis and not as part of any class, collective, or representative action.
Changes to terms
CoconutDB reserves the right to modify these Terms at any time. We recognise that changes to these Terms may affect your obligations and rights, and we are committed to giving you adequate notice.
Notification of changes
- The "Last updated" date at the top of this page will be revised whenever changes are made.
- For material changes — those that meaningfully alter your rights, obligations, or how we use your data — we will notify active workspace administrators via in-platform notification or email at least 14 days before the changes take effect.
- For significant changes that introduce new fees or materially restrict your use of the Platform, we will provide at least 30 days' prior written notice.
Acceptance of changes
Your continued use of the Platform after the effective date of any revised Terms constitutes your acceptance of the updated Terms. If you do not agree to the revised Terms, you must cease using the Platform before the effective date of the changes and contact us to arrange account closure.
Contact us
If you have any questions about these Terms, wish to report a violation, or need to discuss your account or subscription, please contact CoconutDB through the following channels.
General & legal enquiries
legal@coconutdb.com
Platform administrator
admin@coconutdb.com
Security & abuse reports
security@coconutdb.com
Response time
We aim to respond to all legal and compliance queries within 5 business days.
For urgent security concerns or suspected platform abuse, email security@coconutdb.com with the subject line [URGENT]. We treat such reports as highest priority and aim to respond within 24 hours.
These Terms and Conditions constitute the entire agreement between you and CoconutDB regarding the use of the Platform and supersede all prior agreements or understandings.