Terms of Use

Last updated: April 17, 2026

Acceptance

By installing or using the Byoky browser extension, mobile apps, SDK, or the optional vault sync service at vault.byoky.com (together, the “Service”) you agree to these Terms of Use. If you do not agree, do not use the Service.

Eligibility

You must be at least 18 years old, or the age of majority in your jurisdiction, whichever is greater, to use the Service. By using the Service you represent that you meet this requirement and have the legal capacity to enter into these Terms.

Export controls and sanctions

The Service routes requests to LLM providers that are primarily based in the United States and other jurisdictions with export-control rules. You represent that you are not located in, under the control of, or a national or resident of any country or region subject to comprehensive U.S., EU, or UN sanctions, and that you are not on any restricted-party, denied-persons, or specially-designated-nationals list. You agree not to use the Service to export, re-export, or transfer any technology or content in violation of applicable export-control or sanctions law.

Beta and experimental features

Certain parts of the Service — currently including the Vault sync, gifting, alias groups, and any feature explicitly labelled “beta” or “experimental” — are under active development. They may change, regress, or be removed without notice. They are provided for testing and feedback and should not be relied on for production use without additional safeguards on your side.

What Byoky is

Byoky is an open-source bring-your-own-key (BYOK) wallet for LLM API keys. You supply your own keys to providers such as Anthropic, OpenAI, and Google. Byoky stores them encrypted on your device and proxies requests to those providers on your behalf. An optional cloud sync feature (the “Vault”) lets you use the same keys across devices, with keys stored encrypted using a password-derived key.

Byoky is not an LLM provider. We do not sell, resell, broker, or lease access to any LLM provider's API or subscription. Byoky is a technical forwarding tool that acts on your instructions and on your credentials. All billing for LLM usage happens directly between you and the provider whose key you supply.

Your account and credentials

  • You are responsible for the API keys you add to Byoky, including any charges those keys incur with their issuing provider.
  • If you enable vault sync, you are responsible for keeping your password safe. Because encryption keys are derived from your password on your device, we cannot recover your data if you lose it.
  • You must not share your account credentials or use someone else's keys without their permission.
  • You must not add to Byoky any credential whose issuing provider's terms prohibit use of that credential through third-party software, including (without limitation) OAuth tokens or session tokens obtained from consumer subscription plans such as Claude Free / Pro / Max, ChatGPT Free / Plus / Pro, or similar plans where the provider's terms restrict use to its official clients. You are solely responsible for knowing whether a given credential is eligible.

Acceptable use

You agree not to:

  • Use the Service to violate any law or any LLM provider's terms of service
  • Use the Service to generate, distribute, or facilitate illegal content, including CSAM, targeted harassment, or content that infringes others' rights
  • Attempt to reverse, bypass, or interfere with the encryption, authentication, or rate limits of the Vault
  • Attempt to access accounts, credentials, or data belonging to other users
  • Use the Service to attack, probe, or disrupt Byoky or any third-party system
  • Resell, rebrand, broker, or lease the hosted Vault or any LLM-provider access obtained through it as a commercial product

Gifting API keys

Byoky lets you share access to one of your own API keys with another person by creating a “gift” — a shareable link backed by a token budget and an expiration date. When the recipient uses the gift, requests are proxied through a relay and counted against the budget you set. Your underlying key is never delivered to the recipient in the clear; they only get metered access to it.

When you create a gift you agree that:

  • It's your key, your bill. You remain fully responsible for any charges the gifted key incurs with the upstream provider, including any usage within the token budget you granted.
  • You must have the right to share it. You represent and warrant that the key you are gifting is yours to share and that permitting the recipient to consume tokens against it is not prohibited by the issuing provider's terms, usage policy, account-sharing policy, or any other applicable agreement between you and that provider. Many providers — including Anthropic, OpenAI, Google, xAI, Mistral, and Groq — restrict or forbid sharing API keys or letting other persons use your account. It is your responsibility to know whether your provider permits what you are doing.
  • You control the limits. Each gift carries a token budget and expiration. You can revoke a gift at any time, after which the relay will stop serving requests for it. Byoky enforces the limits you set but is not responsible for upstream provider actions (rate limits, bans, billing disputes).
  • No resale or commercial gifting. Gifting is intended for personal, team, and community sharing. You may not use gifts — whether through the hosted Vault or a self-hosted deployment — to resell, lease, broker, or otherwise monetize third-party LLM API access. Self-hosting Byoky under the MIT license does not exempt you from the upstream provider's terms; any commercial offering built on Byoky must independently comply with each provider's commercial-use policy and obtain any permissions that policy requires.
  • Recipient responsibility. When you accept a gift, you agree to use it only within the budget and time window provided, and to comply with the upstream provider's terms. Abuse of a gift (e.g., scraping, illegal content, probing the relay) is grounds for revocation of that gift and termination of your account.
  • System limits. A single user may hold at most 50 active outgoing gifts at any time. Expired gifts are removed automatically.

Third-party providers

When you use Byoky to call an LLM provider (for example Anthropic, OpenAI, Google, xAI, Mistral, DeepSeek, Groq, or any other provider you configure), your prompts, completions, and any other data flow to that provider under its own terms of service, usage policy, and privacy policy. Byoky is not a party to that relationship and is not responsible for provider behavior, availability, billing, or content-moderation decisions.

You agree that you will comply with all applicable terms, usage policies, acceptable-use policies, and documentation of each LLM provider whose credentials you use with the Service. Provider terms change over time and you are solely responsible for monitoring those updates and for ensuring that your use of the Service — including any keys you add, any gifts you create, and any application you build on the SDK — remains in compliance with them.

We may add, remove, restrict, throttle, or disable support for any individual LLM provider at any time and without prior notice, including in response to a request or notice from that provider, a change in that provider's terms, or a good-faith determination that continued support exposes Byoky or its users to legal risk.

Trademarks and no affiliation

“Anthropic,” “Claude,” “OpenAI,” “ChatGPT,” “Google,” “Gemini,” “xAI,” “Grok,” “Mistral,” “DeepSeek,” “Groq,” and other product and company names used in Byoky's documentation or interface are trademarks of their respective owners. Byoky is not affiliated with, endorsed by, sponsored by, or certified by any of these providers. Their names are used solely to identify the services with which Byoky is interoperable, under the nominative-fair-use doctrine.

Open source license

Byoky's source code is released under the MIT license. The MIT license governs your rights to the code itself. These Terms govern your use of the hosted Vault service and the distributed binaries (Chrome, Firefox, iOS, Android).

Fair use of the hosted Vault

The hosted Vault at vault.byoky.com is offered free of charge to individual users for personal and small-team use. To keep it available for everyone we may apply rate limits, throttle abusive traffic, cap the number of active sessions, credentials, or gifts per account, and suspend accounts whose traffic pattern is inconsistent with normal wallet use (for example, sustained automated proxy traffic unrelated to an interactive app). If you expect heavy or commercial traffic, self-host the open-source Vault so you can size it to your own needs.

Indemnification

You agree to defend, indemnify, and hold harmless Byoky, its maintainers, and contributors from and against any claims, liabilities, damages, losses, and expenses (including reasonable legal fees) arising out of or in any way connected with: (a) your use of or access to the Service; (b) the API keys and OAuth credentials you add, use, or share through the Service, including gifts you create; (c) your violation of these Terms or of any law or third-party right; or (d) any content you transmit through the Service.

Feedback

If you send us suggestions, bug reports, feature requests, or other feedback about the Service (for example, by opening a GitHub issue or pull request), you grant us a worldwide, royalty-free, perpetual, irrevocable license to use and incorporate that feedback into the Service and our open-source projects without obligation to you.

Service availability

The Vault is provided on a best-effort basis with no uptime guarantee. We may modify, suspend, or discontinue the hosted Vault at any time. Because Byoky is open source, you can self-host the Vault to run it on your own terms.

Termination

You may stop using the Service and delete your vault account at any time from the extension Settings. We may suspend or terminate accounts that violate these Terms, abuse the Service, or put other users at risk. On termination, the account and all data associated with it are deleted as described in the Privacy Policy.

No warranty

The Service is provided “as is” and “as available” without warranties of any kind, express or implied, including merchantability, fitness for a particular purpose, and non-infringement. We do not warrant that the Service will be uninterrupted, error-free, or secure against every possible threat.

Limitation of liability

To the fullest extent permitted by law, Byoky and its contributors are not liable for any indirect, incidental, special, consequential, or punitive damages, including loss of data, loss of API credits, loss of profits, or charges incurred with third-party LLM providers, arising from your use of the Service.

Governing law and venue

These Terms and any dispute arising out of or in connection with them or the Service are governed by the laws of the Republic of Austria, excluding its conflict-of-laws rules and the United Nations Convention on Contracts for the International Sale of Goods (CISG). The exclusive place of jurisdiction for all disputes is Vienna, Austria, to the extent permitted by law.

If you use the Service as a consumer (Verbraucher) resident in the European Union, nothing in this section deprives you of the protection afforded by the mandatory consumer-protection laws of your country of residence.

Severability and entire agreement

If any provision of these Terms is held to be unenforceable or invalid, that provision will be limited or eliminated to the minimum extent necessary and the remaining provisions will remain in full force and effect. These Terms, together with the Privacy Policy, constitute the entire agreement between you and Byoky regarding the Service and supersede any prior agreements on the same subject matter. You may not assign these Terms without our prior written consent; we may assign them in connection with a merger, acquisition, or sale of assets.

Changes to these terms

We may update these Terms from time to time. When we do, we will update the “Last updated” date above. Continued use of the Service after changes take effect means you accept the revised Terms.

Contact

Questions or notices regarding these Terms can be filed as an issue on GitHub.