POLYMAI STANDARD FORM
Service Terms
Version 2026.07
1. Provider and Agreement
Polymai is a service of CarbMind AB, Swedish company registration number 559494-6203, with registered office in Gothenburg ("CarbMind", "Polymai", "we", or "us"). These terms apply when a person or organization visits Polymai, creates an account, activates or uses the VS Code extension, or purchases a Polymai package.
By using the service, the user ("Customer" or "you") accepts these terms. A person using Polymai for an organization confirms authority to bind that organization. A person who cannot enter a binding agreement may use the service only with permission from a parent, guardian, or other authorized representative.
2. Service
Polymai is an app-building workflow in and around VS Code. It may help prepare briefs, plans, source files, service configuration, previews, checks, coding-agent handoffs, provisioning, publishing, and later scoped updates. Polymai does not operate the Customer's production app unless separately agreed in writing.
Features identified as beta, preview, early access, or experimental are provided for evaluation, may be incomplete, may change or be removed at any time, and have no service-level, continued-availability, backward-compatibility, or production-readiness commitment. The Customer remains responsible for reviewing generated work and must not rely on experimental features for critical production use without appropriate safeguards. Mandatory consumer rights remain unaffected.
3. Free and Paid Packages
The Free package currently permits up to ten new app creations during the applicable usage period. Updates to an existing app may be treated differently. The current account view and package page state the quota that applies. CarbMind may change or withdraw a free package prospectively, with reasonable notice where practical.
Paid packages may be introduced with additional limits or features. Price, tax, renewal interval, cancellation terms, and the included quota will be shown before purchase and form part of the agreement. No unpublished future package description creates a right to a particular price, quota, or launch date.
4. Customer-Controlled Accounts and App Data
The Customer controls its workspace, source repository, generated app, production data, and connected provider accounts. The Customer is responsible for the purposes and means of any personal-data processing performed by the Customer's app and is normally the data controller for that processing.
The standard Polymai account service does not receive raw source files, raw prompts, local chat history, workspace paths, provider API keys, or records held in the Customer's generated app database. Limited account and app-usage metadata is described in the Privacy Notice.
5. Customer Responsibilities
The Customer must provide lawful instructions, secure its devices and provider accounts, review permissions and generated code, maintain suitable backups, and supply required notices and legal bases for its own app users. The Customer must not use Polymai to create, facilitate, or distribute malware, ransomware, phishing, credential theft, spam or unsolicited bulk communications; gain unauthorized access; perform unlawful surveillance or tracking; infringe copyright, privacy, or other rights; evade provider safeguards; or conduct any unlawful, fraudulent, abusive, or deceptive activity.
Secrets and sensitive personal data must not be placed in source files, ordinary prompts, screenshots, logs, project notes, public repositories, or support messages. Sensitive or regulated use cases require the Customer's own legal, security, and specialist review.
6. Third-Party Services
Polymai may connect to Customer-selected services such as OpenAI, Anthropic, GitHub, Supabase, Stripe, Resend, hosting platforms, or other APIs. These services are provided under separate terms between the Customer and that provider. Their fees, availability, regions, security, retention, and acceptable-use rules are outside CarbMind's control.
CarbMind is not responsible for third-party outages, account restrictions, price changes, model behavior, data loss, payment disputes, or configuration selected by the Customer.
7. Intellectual Property
The Customer retains rights in its materials and, as between the parties, owns generated project files created specifically for the Customer, subject to third-party rights, open-source licenses, provider terms, and applicable law. CarbMind retains all rights in Polymai, its extension, workflows, templates, checks, methods, documentation, reusable components, and general know-how.
The Customer grants CarbMind only the rights necessary to provide the Polymai account service and any support or professional service the Customer expressly requests.
8. AI and Generated Output
AI and coding-agent output may be incomplete, inaccurate, insecure, or unsuitable. Checks and previews reduce risk but do not constitute a warranty, legal review, penetration test, accessibility certification, or compliance approval. The Customer decides whether and how to use the output.
CarbMind does not warrant that generated output is free from third-party intellectual-property claims, restrictive licenses, or similarities to third-party material. The Customer must review relevant code, content, dependencies, notices, and licenses before use or distribution.
9. Availability, Changes, and Termination
The service is provided on an "as available" basis. CarbMind may update features, supported providers, models, technical requirements, or these terms. Material changes apply prospectively. The Customer may stop using the Free service at any time and may request account closure.
CarbMind may restrict or terminate access for misuse, security risk, unlawful activity, non-payment, material breach, or discontinuation of the service. Where reasonable, CarbMind will provide notice and an opportunity to remedy a remediable breach.
10. Warranties and Liability
To the maximum extent permitted by law, Polymai is provided without warranties of uninterrupted operation, error-free output, fitness for a particular purpose, non-infringement, revenue results, production readiness, or regulatory compliance. For business Customers, CarbMind's aggregate liability arising from the service is limited to fees paid to CarbMind for the affected service during the twelve months before the event giving rise to the claim. Neither party is liable for indirect loss, lost profit, lost revenue, or loss caused by a third-party provider, except where such limitation is prohibited by law.
Nothing in these terms limits liability that cannot legally be limited, including mandatory consumer rights or liability for intent or gross negligence where applicable.
11. Consumer Rights
A consumer retains all mandatory rights under applicable consumer law. Before any paid consumer purchase, Polymai will present the total price, package content, duration, renewal and cancellation information, and any applicable withdrawal information. If these terms conflict with mandatory consumer law, the mandatory rule prevails.
12. Export Controls and Sanctions
Each party is responsible for complying with applicable export-control, sanctions, and trade-restriction laws. The Customer must not make Polymai or generated output available to a sanctioned person or in a prohibited territory, or use it for a restricted end use, where doing so would violate applicable law. CarbMind may restrict or suspend the affected service where reasonably necessary to comply with such obligations.
13. Force Majeure
Neither party is liable for delay or failure to perform caused by an event beyond its reasonable control, including a widespread internet or utility outage, third-party cloud or provider failure, natural disaster, epidemic, war, terrorism, civil disorder, governmental action, trade restriction, labor dispute, or cyberattack that could not reasonably have been prevented or overcome through appropriate measures.
The affected party must give notice when practical, take reasonable steps to reduce the impact, and resume performance as soon as reasonably possible. This clause does not excuse amounts already due or a failure caused by that party's lack of reasonable security, continuity, or mitigation measures. If the event materially prevents a paid service for more than sixty days, either party may terminate the affected service, subject to mandatory consumer law.
14. Governing Law and Disputes
Swedish law governs these terms. Business disputes are subject to Gothenburg District Court as the court of first instance. A consumer may also bring a claim before the competent court under mandatory law and may refer an eligible dispute to the Swedish National Board for Consumer Disputes (ARN).
15. Company Information and Contact
CarbMind AB, company registration number 559494-6203. Company address: BrÀnnemysten 21 B, 436 55 HovÄs, Sweden. Additional electronic contact details may be provided in the Polymai account or purchase flow.
POLYMAI STANDARD FORM
Privacy Notice
Version 2026.07
1. Controller
CarbMind AB, company registration number 559494-6203, is the data controller for personal data processed to provide polymai.com, Polymai accounts, extension activation, quota management, security, support, and billing. CarbMind has assessed that it is not currently required to appoint a data protection officer. Privacy requests may be sent using the Company Information and Contact details in section 15 of the Service Terms or through an electronic contact channel provided in the service.
2. Data We Process
We may process identity and account data such as email address, authentication identifier, account name, membership, role, package, and timestamps. We process extension-access data such as an activation-token hash, token prefix and last characters, scope, bound client identifier, status, expiry, revocation, and last-use time. The raw activation token is not retained by the account backend.
For quota and account history, we may process an app key, display name, build status, source label, internal project identifier, file count, timestamps, and shortened hashes derived from the workspace path and prompt. We may also process support communications, security events, and, when paid packages are enabled, subscription, invoice, transaction-status, and Stripe customer identifiers. Payment-card numbers are handled by the payment provider and are not stored by CarbMind.
3. Data We Do Not Receive in Standard Use
The Polymai account backend does not receive provider API keys, database passwords, webhook secrets, raw prompts, raw workspace paths, local source files, local chat history, generated-app database records, or production end-user data through the standard extension workflow. Such material may leave the device only when the Customer directs the extension or a coding agent to send it to a Customer-selected provider, publishes it, or intentionally supplies it for support.
4. Purposes and Legal Bases
Account, activation, quota, and requested support data is processed to perform the agreement or take requested pre-contract steps. Security, abuse prevention, service integrity, troubleshooting, and limited service improvement are based on CarbMind's legitimate interests, balanced against the individual's rights. Billing and accounting data is processed to perform an agreement and comply with legal obligations. Optional marketing is based on consent or another lawful basis identified when collected.
5. Customer App Data
The Customer determines the purposes and means of processing in its generated app and connected provider accounts. CarbMind is not the controller or processor for production data merely because the app was planned or generated with Polymai. If CarbMind separately agrees to process Customer Personal Data on the Customer's behalf, the DPA applies to that defined Processor Service.
6. Recipients and Providers
Supabase supports Polymai account authentication, database records, and server-side functions. Resend may deliver account or system email. Stripe will process checkout, subscription, and invoice data when paid packages are enabled. GitHub Pages hosts the public website. Google Fonts currently delivers the website font and may receive browser and network information such as IP address. These providers process data under their own applicable roles and agreements.
Customer-selected AI, repository, database, payment, email, and hosting providers receive data directly from the Customer's device or account when the Customer uses them. CarbMind does not select their independent purposes or control their terms.
7. International Transfers
Some providers may process data outside Sweden or the EEA. Where CarbMind is responsible for a transfer, it uses an applicable legal mechanism such as an adequacy decision, standard contractual clauses, or another lawful safeguard. Customer-controlled provider transfers are governed by the Customer's provider configuration and agreement.
8. Retention
Account and usage data is retained while needed to provide and document the account, quota, security, and service history, and is deleted or anonymized when it is no longer needed, subject to legal claims and mandatory retention. Revoked or expired token metadata and security events may be retained for a limited period to investigate abuse and protect the service. Billing and accounting records are retained for the period required by Swedish law. Support communications are retained while needed to resolve the matter and document the relationship.
Local extension data and data in Customer-selected providers is controlled by the Customer and remains until removed under the applicable local or provider settings.
9. Browser Storage
The website uses app-scoped browser storage for functions such as theme preference, authentication state, and limited interface or gallery state. This storage is not used to place provider secrets in the website. Provider authentication may use technically necessary storage to keep the user signed in.
10. Rights
Subject to applicable law, individuals may request access, correction, deletion, restriction, objection, and data portability, and may withdraw consent where consent is used. An objection may make it impossible to continue a feature that depends on the processing. Individuals may complain to the Swedish Authority for Privacy Protection (IMY) or another competent supervisory authority.
11. Changes
CarbMind may update this notice as the service, providers, or law changes. Material changes are identified by a new effective date and retained in the version history.
POLYMAI STANDARD FORM
Data Processing Addendum
Version 2026.07
1. Conditional Applicability
This DPA applies only to the extent CarbMind processes personal data on behalf of a business Customer as a processor ("Customer Personal Data") in a specifically agreed service ("Processor Service"). Standard Polymai account, licensing, quota, security, and billing processing is performed by CarbMind as an independent controller and is outside this DPA.
The standard local extension, direct use of Customer-selected provider accounts, and production operation of a generated app do not by themselves make CarbMind a processor. If no Customer Personal Data is made available to CarbMind for a Processor Service, this DPA creates no processing obligation.
2. Roles and Instructions
The Customer is controller and CarbMind is processor for the defined Processor Service. CarbMind will process Customer Personal Data only on documented Customer instructions, including the agreement, enabled service settings, and lawful written instructions consistent with the service. CarbMind will notify the Customer if an instruction appears to infringe applicable data-protection law and may suspend the affected processing.
3. Processing Details
The subject matter is the support, diagnostic, managed build, or other Processor Service expressly activated by the Customer. Processing lasts for the service period and any short return, deletion, backup, security, or legal-retention period. The nature may include receiving, viewing, organizing, troubleshooting, transmitting, returning, or deleting the data needed for that service.
Data subjects and data categories are determined by what the Customer lawfully supplies for the defined service. The Customer must not provide special-category data, criminal-offence data, payment-card data, government identifiers, children's data, credentials, or other highly sensitive data unless the parties expressly approve the data type and safeguards in writing.
4. Confidentiality and Security
CarbMind ensures that persons authorized to process Customer Personal Data are subject to confidentiality and access it only as necessary. CarbMind applies appropriate technical and organizational measures described in the Security Schedule, taking account of processing risk and the nature of the service.
5. Subprocessors
The Customer grants general authorization for CarbMind to use subprocessors necessary for a Processor Service. A provider is a subprocessor only when it actually processes Customer Personal Data on CarbMind's behalf. Customer-controlled providers used directly under the Customer's own agreement are not CarbMind subprocessors.
CarbMind will impose materially equivalent data-protection duties on subprocessors and remains responsible for their performance as required by law. Before a material new subprocessor begins processing Customer Personal Data, CarbMind will provide reasonable notice where required. The Customer may object on documented data-protection grounds. If the parties cannot resolve a reasonable objection, either party may terminate the affected Processor Service before the new subprocessor begins that processing.
6. Assistance and Incidents
Taking account of the nature of processing and information available, CarbMind will reasonably assist the Customer with data-subject requests, security obligations, breach notifications, impact assessments, and supervisory-authority consultations. CarbMind will notify the Customer without undue delay after becoming aware of a personal-data breach affecting Customer Personal Data.
7. International Transfers
CarbMind will not transfer Customer Personal Data to a third country except on documented instructions or under a lawful transfer mechanism. Where required, the parties incorporate applicable standard contractual clauses and supplementary safeguards.
8. Return and Deletion
At the end of the Processor Service, CarbMind will delete or return Customer Personal Data at the Customer's choice, unless law requires retention. Data in backups may remain until the backup is overwritten or securely retired and remains protected during that period.
9. Information and Audit
CarbMind will provide information reasonably necessary to demonstrate compliance. Audits must be proportionate, protect other customers and confidential systems, avoid unreasonable disruption, and normally rely first on documentation, questionnaires, or independent reports. The Customer bears extraordinary audit costs unless an audit identifies a material breach by CarbMind.
10. Order of Precedence
If this DPA conflicts with the Service Terms on processing of Customer Personal Data, this DPA controls. Mandatory data-protection law and applicable standard contractual clauses prevail over conflicting terms.
POLYMAI STANDARD FORM
Security Schedule
Version 2026.07
1. Security Model
Polymai is designed around local project control and Customer-owned provider accounts. Security measures are risk-based and do not constitute a certification, penetration test, or guarantee that generated software is free from vulnerabilities.
2. Secret Storage
Private provider credentials entered in the extension are stored through VS Code SecretStorage rather than ordinary extension settings or generated frontend files. SecretStorage uses the operating system's credential protection. Device compromise, malicious local software, or insecure operating-system access can still expose secrets.
The Polymai activation token is stored locally as a secret. The account backend retains a SHA-256 hash and limited token metadata rather than the raw activation token. Public values such as a Supabase URL, publishable key, Stripe publishable key, Price ID, or OAuth client ID are kept separate from private credentials.
3. Direct Provider Connections
When used, AI, GitHub, Supabase, Stripe, email, and other provider credentials are sent over encrypted HTTPS connections directly to the selected provider for the requested operation. They are not routed through the Polymai account backend for ordinary provider calls. Generated-app runtime secrets are placed in Customer-controlled server-side environments such as Supabase Edge Function secrets.
4. Local Project Data
Prompts, source files, project plans, screenshots, checks, logs, local chat history, working memory, snapshots, and indexes may be stored locally in the VS Code workspace or extension storage. They are not secret-vault storage. The Customer controls workspace access, backups, source control, device security, and deletion.
5. Polymai Account Boundary
The account service receives only the account, activation, entitlement, app-record, and usage metadata described in the Privacy Notice. Workspace paths and prompts are represented by shortened hashes in app-usage records; raw values are not sent in those records.
6. Generated-App Controls
Polymai may generate app-scoped schemas, row-level security, server-side functions, validation, and provider configuration. The Customer must review generated authorization, public keys, secrets, dependencies, deployment settings, backups, logging, and monitoring before production use.
7. Incident Responsibilities
CarbMind investigates incidents affecting Polymai-controlled systems and provides legally required notices. The Customer is responsible for incidents in its device, workspace, repository, provider accounts, generated application, production users, and deployments, except to the extent caused by CarbMind's breach of an applicable obligation.
POLYMAI STANDARD FORM
AI Processing Addendum
Version 2026.07
1. Customer-Directed AI
Polymai prepares context and handoff artifacts for AI and coding agents selected by the Customer. In the standard extension workflow, requests use Customer-supplied provider credentials or a Customer-controlled coding-agent session and are sent directly to that provider. CarbMind does not receive the raw request merely because Polymai prepared or initiated the local workflow.
2. Provider Terms
The Customer chooses the provider, account, model, region, retention controls, and commercial plan. Provider use is governed by the Customer's agreement with that provider. CarbMind does not promise that every provider offers the same privacy, training, residency, availability, or retention settings.
3. Data Minimization
The Customer should provide only context needed for the task. Credentials, payment-card data, special-category personal data, government identifiers, children's data, and unrelated confidential information must not be placed in prompts. Where personal data is necessary, the Customer is responsible for a lawful basis and appropriate provider configuration.
4. Hosted or Managed AI
If CarbMind later offers a hosted AI feature or expressly processes Customer content through a CarbMind-controlled provider account, the feature description will identify that data flow before activation. The DPA applies where CarbMind acts as processor, and the Provider List will identify applicable subprocessors.
5. Output Review
AI output can hallucinate, omit requirements, introduce insecure code, reproduce common patterns, or conflict with law and third-party rights. The Customer must review output before use and obtain specialist review for regulated, safety-critical, legal, medical, financial, employment, credit, or other high-impact uses.
6. No Autonomous Production Authority
Unless separately agreed and configured by the Customer, Polymai's AI workflow does not independently operate the Customer's production app, access production records, make decisions about individuals, execute live payments, or publish changes without a Customer-controlled action.
POLYMAI STANDARD FORM
Provider and Subprocessor List
Version 2026.07
1. Three Different Provider Roles
CarbMind uses service providers for Polymai's own account and website operations. A provider becomes a DPA subprocessor only when it processes Customer Personal Data on CarbMind's behalf for an activated Processor Service. Providers selected and controlled directly by the Customer are the Customer's providers and are not CarbMind subprocessors.
2. Polymai Operational Providers
Provider
Purpose
Typical Polymai data
Supabase
Account authentication, database, and server-side functions
Email, account, token metadata, package, quota, app records, and service events
Resend
Transactional account and system email when enabled
Recipient address, message content, and delivery metadata
Stripe
Checkout, subscriptions, invoices, and payment status when paid packages are enabled
Customer and billing identifiers, transaction status, and invoice metadata
GitHub Pages
Public website hosting and delivery
Website requests and related network metadata handled by the provider
Google Fonts
Website font delivery
Browser request and network metadata such as IP address
3. DPA Subprocessors
The standard local extension has no standing subprocessor for Customer production-app data because CarbMind does not receive that data. If a Processor Service is activated, an operational provider listed above is a subprocessor only to the extent it processes Customer Personal Data for that service. CarbMind will identify any additional applicable subprocessor before processing begins or through the change-notice procedure in the DPA.
4. Customer-Selected Providers
OpenAI, Anthropic, GitHub, Supabase, Stripe, Resend, hosting providers, local model runtimes, and other integrations connected with Customer credentials are governed by the Customer's own provider agreements. The same company may therefore be CarbMind's provider for one limited purpose and the Customer's independent provider for another.
5. Changes
CarbMind may change operational providers as the service develops. Material privacy changes will be reflected in this list. Where the DPA requires advance notice for a new subprocessor, CarbMind will provide notice and the objection process stated in the DPA.