# booklint Terms of Service **Version:** 30 September 2026 **Governing law:** England and Wales **Seller:** booklint (a sole trader shop in England and Wales operated under the trading name booklint) **Contact:** hello@booklint.com **Address:** Booklint, London, United Kingdom **Service:** booklint.com (Verification Desk) These Terms of Service (“Terms”) govern use of the booklint Verification Desk shop and its HTTP interface at booklint.com (and any MCP interface if one is later offered; availability of any future MCP interface will be published on booklint.com). By using the service you agree to these Terms. If you do not agree, do not use the service. --- ## 1. Who we are The seller is **booklint** (a sole trader shop in England and Wales operated under the trading name booklint). Contact: **hello@booklint.com**. booklint is a **separate shop**. It has **no access** to the operator’s live trading book or other operator systems. Isolation is intentional and must stay true in how the service is described and operated. --- ## 2. What booklint is (linter, not adviser) booklint is an **external verification desk** for trading agents. It offers two tools. **check_book** runs the rules in your rulebook that your plan includes against a submitted snapshot and, where supplied, a broker export and journal. **audit_claims** compares journal claims against a broker export. Access is over **HTTPS**: `POST /v1/check` runs check_book. audit_claims currently runs only as the `claims_match_broker` rule inside check_book on the Desk plan and has no separate endpoint. An MCP interface is not yet offered; if one is later offered, its availability will be published on booklint.com. booklint is a **linter**, not an adviser. It produces **deterministic flags only**: rule breaches and ledger / file discrepancy flags against **rules and facts you supply** (not a booklint policy book). It does not interpret markets, recommend strategies, assess suitability, or approve trades. --- ## 3. What booklint is not booklint: - never provides **investment advice**; - never assesses **suitability**; - never tells you to **buy, sell, trim, or hold**; - never **executes orders**; - never certifies that a book, strategy, or trade is safe; - never implies that incomplete coverage, a withheld check, or a zero-flag **NOT_VERIFIED** result is approval. A standing notice appears on every verification response, including refusals (see section 4). Absence of flags is not a certificate of safety. Output is rule / ledger discrepancy signalling only. --- ## 4. Standing notice Every verification response from `POST /v1/check`, including refusals, carries this standing notice in its `notice` field: > Flags test the customer's stated rules only and are never a trade instruction. The operator does not give advice, does not execute and holds no discretion. The landing page (`/`, `/llms.txt`), `/health` and `/v1/plans` carry this coverage notice: > A zero-flag result with verdict NOT_VERIFIED is not a pass, and a response with coverage_complete false is not full coverage under any verdict; read coverage.not_ran before the flag count. Absence of flags is not a certificate of safety. You must not strip, truncate, reorder to obscure, hide, or misrepresent either notice when you relay booklint output. In agent-to-agent or agent-to-human relay, the notice must appear in the primary output channel alongside the verdict, not solely in metadata, headers, or logs. --- ## 5. Verdicts Each verification run returns one of these verdicts: | Verdict | Meaning | | --- | --- | | **FLAGGED** | One or more requested checks that ran produced a flag. Checks that did not run may still be listed in `coverage.not_ran`; read `coverage_complete`. | | **CLEAN** | Every requested check ran **and** none flagged. Covers **requested checks only**; does not cover unlicensed, unsubmitted, or `not_in_plan` checks. | | **NOT_VERIFIED** | No check that ran produced a flag, but one or more requested checks did not run (status `not_in_plan`, `not_licensed`, `unavailable`, `missing_input`, `tape_skew`, `disabled` or `no_rule`) — never a pass regardless of flag count. | | **REFUSED** | The request was refused before any check ran: a stale input (a snapshot more than 15 minutes old), an input that fails the schema, or a malformed request. A refusal carries no flags. | **CLEAN** is available only when every requested check ran and none flagged. **Zero flags alone is never a pass.** A zero-flag **NOT_VERIFIED** result is **not** a pass and must not be read as approval. Incomplete coverage (including `not_licensed` or `unavailable`) must never be treated as an all-clear. --- ## 6. Plans, checks, and pricing ### 6.1 Free tier The free tier includes: - schema validation and stale-input refusal on every request; - cash floor (`cash_floor`); - buying-power floor (`buying_power_floor`); - single-symbol concentration (`max_concentration_pct`); - position count (`max_positions`); - stop coverage for stock positions (`require_stop`). There is **no same-day fix promise** on the free tier. Free API keys are issued at once through POST /v1/keys with {"plan":"free"}, without payment or email. Free use is capped per key per day and in total, and per client per day without a key; the current caps are published on the landing page and at GET /health, and booklint may change them. Over a cap booklint refuses the check and points to the paid Desk plan. Counting “distinct” free users or agents is **imperfect** (Sybil / shared / recycled keys are possible). The shop does **not** promise verified unique agents. Once free keys exist, rate-limiting or suspension may also apply where abuse of free keys is detected. ### 6.2 Desk (paid) Desk includes every free check plus tracker-vs-broker structure (`structure_matches_broker`), journal-claims-vs-broker (`claims_match_broker`) and the opt-in covered-call policy (`covered_call_required`). The expiry-window check (`expiry_window_days`) is not built and returns `unavailable`. Desk cannot be purchased until paid checkout is live (section 12). **Price while calendar is not commercially licensed:** USD **$20 per month**. Desk remains at **$20/mo only until a commercial calendar licence exists**. When a commercial calendar licence is live, the Desk price becomes USD **$30 per month**, taking effect no earlier than **30 days after notice** on booklint.com and by email to paid-account holders. ### 6.3 Watch and calendar coverage (not live) **Watch is withheld** until a commercial calendar licence exists. Until then, Watch is **not sold**. Calendar-dependent coverage (including any earnings, ex-dividend, or similar calendar checks) is **not** offered as a live product today. A calendar rule in your rulebook returns **`not_in_plan`** on the free tier and **`not_licensed`** on Desk. It never runs and is never counted as run. These Terms do **not** promise earnings or ex-div checks, and do **not** imply that any particular calendar data vendor is live or licensed for the shop. When calendar data is later licensed from a commercial vendor, dates from that licence **may not be copied out** beyond what the published interface returns for the check. Until then, related checks are not sold. ### 6.4 Operator control of checks The operator may switch individual checks off, or take the service offline, rather than sell a bad all-clear. That is an intended operational right, not a breach of these Terms by itself. A check switched off this way reports status `disabled`; it is not a refusal. --- ## 7. Sample books (`sample:true`) If a request is marked `sample:true`, booklint uses the **public sample book only**. The response body carries `"sample": true`. Sample runs use the Desk plan on the public sample book so you can see paid output; nothing you send is checked. Sample runs are **not** verification of your (or any customer’s) book. Agents and operators must check for `"sample": true` before treating a response as verification of a real book. A sample-marked response must not be acted on as real verification. --- ## 8. Submitting books, including third-party books You may submit books that belong to third parties. booklint **cannot tell** whether a book is yours and **does not try** to find out. **You warrant** that you have the right to submit each book (and related materials) you send to booklint, including authority from any third party whose book you submit. You remain responsible for that submission. --- ## 9. How we process data (summary) **Process-and-discard:** raw customer books are processed and **not kept**. booklint does not retain the customer’s book as a stored book file. booklint keeps **no record of a check's content**: no Delivery Log exists. booklint does keep a record per API key, paid or free (including when the key was last used and, for a free key, its check counts), a count of authenticated checks per plan, the operational logs and aggregate traffic counts with a daily-rotating hash of IP address and User-Agent; the Privacy Notice (sections 2, 2A, 4 and 10) says exactly what they hold and for how long. When a Delivery Log is introduced, the Log will hold only hashes / digests of inputs, the rulebook version, finding codes, key hashes, timestamps, check statuses and rule ids, **never the raw book**. It will be kept for 90 days (free) and 13 months (paid), and these Terms and the Privacy Notice will be updated before that happens. Email addresses arrive only at **paid conversion via Stripe**. Email is **not stored on the free tier**. After Stripe payment, a post-payment email / plan mapping exists (see section 12 and the Privacy Notice). Further detail is in the Privacy Notice at **/privacy**. --- ## 10. Coverage and support model booklint is **vending-machine software**: automated verification over HTTPS. - The service is **monitored around the clock** for whether it is up; it is **staffed on UK working days** for operator maintenance. - The human shop mailbox **hello@booklint.com** is for **account, billing, and documentation** questions only. - These Terms do **not** name other operator tools or agents as customer support, and do **not** imply that any person or system beyond the shop mailbox provides customer support. - **Free tier:** no same-day fix promise; no SLA beyond “best effort vending machine”. - **Paid tier:** If, in a paid month, the operator scales the service to zero for more than 4 hours beyond a published maintenance window, the unused prepaid period for that paid month is refunded or credited, confirmed via hello@booklint.com (no separate public status page at launch). No broader uptime SLA is promised. --- ## 11. Discontinuation / review window (soft public language) booklint may be operated as an experiment. After a **review window** following paid-open (the first day paid checkout is live), the operator may **discontinue** the service, change scope, or stop selling paid plans. Exact internal thresholds and scoreboard rules (if any) are kept in the operator’s internal listing notes only. **They are not published in these customer Terms** and are not a public scoreboard. Customer-facing commitments are limited to: the operator may discontinue after that review window, with reasonable notice where practicable for paid customers then on risk. The public `/health` endpoint reports raw operating counters; they are not thresholds or a scoreboard, and counting distinct agents from keys is imperfect. --- ## 12. Stripe, billing, and paid accounts Paid plans are billed through **Stripe** when paid checkout is enabled on booklint.com. Until paid checkout is enabled, only the free tier is available. After successful payment: - Stripe provides the email and plan mapping used for the paid account; - that post-payment email / plan mapping is separate from free-tier privacy handling (free tier does not store email). You must keep payment details current in Stripe once paid checkout is live. Failed payment may suspend paid checks until resolved. --- ## 13. Cancellation and refunds - You may **cancel anytime** once paid plans exist. - Cancellation **ends renewals**. The **current paid period is not prorated** unless Stripe’s rules or a published fault credit require otherwise. - If, in a paid month, the operator scales the service to zero for more than 4 hours beyond a published maintenance window, the unused prepaid period for that paid month is refunded or credited, confirmed via hello@booklint.com (no separate public status page at launch). - Otherwise, no refund of the current period applies solely because you cancelled mid-period. --- ## 14. Liability To the fullest extent permitted by law applicable to a sole trader SaaS offering under the law of England and Wales: - booklint’s total liability arising out of or in connection with the service in any claim period is capped at the **fees you paid in the last month** before the claim arose (and is **nil** if you are on the free tier and have paid no fees); - booklint has **no liability for trading losses**, missed trades, opportunity cost, or decisions you (or your agents) make after seeing or not seeing flags; - nothing in these Terms excludes or limits liability for death or personal injury caused by negligence, fraud, or any other liability that cannot be limited by law. booklint output is verification signalling only. You remain solely responsible for trading decisions and agent behaviour. --- ## 15. Acceptable use You must not: - misuse the service to harm systems, bypass rate or plan limits, or reverse-engineer beyond what the published interfaces allow; - strip, truncate, reorder to obscure, hide, or misrepresent the standing notice or the `"sample": true` marker; in agent-to-agent or agent-to-human relay, the notice must appear in the primary output channel alongside the verdict, not solely in metadata, headers, or logs; - present booklint output as investment advice, suitability assessment, trade approval, or a safety certificate; - treat **NOT_VERIFIED**, withheld Watch, or `not_in_plan` / `not_licensed` / `unavailable` calendar coverage as approval; - treat a response marked `"sample": true` as verification of a real book; - submit unlawful content or books you have no right to submit. The operator may refuse, suspend, or terminate access for breach, abuse, or to avoid selling a bad all-clear. --- ## 16. Changes We may update these Terms. Material changes will be notified via the site or email where we hold a paid-account email. Continued use after the effective date constitutes acceptance, except where law requires otherwise. Price change for Desk (from $20/mo to $30/mo when a commercial calendar licence is live) requires **30 days’ notice** as stated in section 6.2. --- ## 17. Governing law and disputes These Terms are governed by the law of **England and Wales**. Courts of England and Wales have exclusive jurisdiction, subject to any mandatory rights you have as a consumer if you are contracting as a consumer. --- ## 18. Contact Account, billing, and documentation: **hello@booklint.com**. --- *End of Terms of Service — version 30 September 2026 (Rev E). Operator-written for booklint.com. Not investment advice.*