Terms of Service

Operating Studio is an invitation-only service bought under a written service agreement. These terms describe what you get, how it is billed, what we do not promise, and what the product must not be used for.

Last updated 2 September 2026

Who these terms are with

These terms apply between the people and organizations using Operating Studio (“you”, “your Company”) and the team that operates the Operating Studio service (“we”, “us”). Using Operating Studio means accepting them. How we handle personal data is described separately in the privacy policy, which forms part of these terms.

Each Company’s engagement is also governed by its own written service agreement with us, which names that Company’s service level, setup fee, capacity, service start date, and contacts. These terms describe the service in general; your agreement is the one that states your numbers and dates. Where the two differ for your Company, your agreement wins. Your agreement also records the versions of these terms and of the privacy policy that were in effect when you accepted it, so a later edit to this page does not quietly rewrite what you agreed to.

Access and accounts

Operating Studio is invitation-only. There is no self-serve signup: an administrator of a Company authorizes each person directly by their Google address, and that authorization can be changed or withdrawn by that administrator, or by us, at any time. Google is the only way to sign in; there is no password to set.

An account belongs to the named person and is not to be shared, resold, or used by anyone else. You are responsible for what happens under your account and for keeping your Google account secure. Tell your Company administrator promptly if you believe an account has been compromised.

Operating Studio is a tool for organizations at work. It is not intended for personal use and not intended for anyone under 18.

This is an early service

Operating Studio is an evolving service run for a small number of Companies. Be clear-eyed about what that means:

  • The early platform is provided as is and without a service-level or uptime commitment. A Company’s written service agreement separately commits us to perform managed service with reasonable skill and care.
  • Features, data models, screens, and Workflow behaviour will change, sometimes in ways that are not backwards compatible. We make reasonable efforts to avoid disrupting active work and we tell Company administrators about material changes.
  • Your data is not yet covered by a durability or backup guarantee. A single production environment serves every Company, and a separate environment with isolated credentials is a planned change that has not landed. Keep your own copy of anything you cannot afford to lose. We will describe our actual backup and recovery posture truthfully and will not promise a durability level the system has not demonstrated.
  • We do not hold a security certification such as SOC 2 or ISO 27001, and we do not claim one.

Your Company’s data

The work your Company puts into Operating Studio — Workflow definitions, Projects, Tasks, Runs, Artifacts, transcripts, and the activity record — remains your Company’s. We do not claim ownership of it. We use it to operate the service for you, to keep it secure and working, and for nothing else that is not described in the privacy policy. We do not sell Company data and we do not use it to build generalized AI models.

Administering the Operating Studio platform does not by itself grant access to a Company’s operational content. Our platform administrators have no implicit membership in any Company; reaching a Company’s work requires an explicit membership in that Company, granted the same way as anyone else’s and recorded the same way.

Content you bring in must be content you are entitled to bring in. You are responsible for having the rights and the consents needed for anything your Company uploads, connects, or sends through a Workflow — meeting recordings and transcripts in particular.

What Operating Studio is not for

A Company has three roles — Super Admin, Admin, and Member — and no fine-grained visibility controls. Those roles decide what a person may change: a Super Admin governs Workflow design and who else holds Super Admin, an Admin manages the Company profile, its people, and its connections, and a Member does the work. They do not partition what a person may see. Every active member of a Company can see that Company’s operational work. This is a deliberate, documented product boundary, not an oversight, and it has a consequence you must respect:

  • Do not put data into Operating Studio that every active member of your Company is not permitted to see. That includes client and coaching information, restricted employee material, and anything covered by a confidentiality obligation narrower than your Company.
  • Do not use Operating Studio for regulated categories of data it was not built for — health records, payment card data, government identifiers, or children’s data.

The reference Scribe Workflow shipped with the product is scoped to internal meetings for the same reason. Client sessions, coaching conversations, and restricted employee material are outside it.

Acceptable use

Do not use Operating Studio to:

  • break the law, or infringe anyone’s rights;
  • process data you are not permitted to process, or that you obtained without the consent it required;
  • attempt to reach another Company’s data, escalate your own permissions, or probe the service outside a scope we have agreed in writing;
  • disrupt, overload, or degrade the service for anyone else, including through automated traffic we have not agreed to;
  • reverse engineer, resell, or provide the service to third parties as your own.

If you find a security problem, tell us before telling anyone else. We will not pursue good-faith reports.

Automation, agents, and your judgement

If Agent delegation is made available, your Company may attach an Agent to a role-assigned Template Task. An Agent is optional execution delegation, not the owner of a Task: the responsible Role remains accountable for the work, and your Company chooses the human review required.

Model output can be wrong, incomplete, or confidently mistaken. It is not legal, financial, medical, or professional advice. Your Company remains responsible for the decisions it makes and the documents it publishes, including those an Agent helped prepare. If your Company later permits an Agent to act without human approval, that is your Company’s choice and your Company’s risk.

Connected accounts

A Company admin may connect Operating Studio to third-party tools such as Google Workspace, Slack, and a transcription provider. By making a connection you confirm you are authorized to connect that account, and you accept that Operating Studio will act on that account within the scopes granted.

Those third-party services have their own terms with you; we do not control them and are not responsible for them. What Operating Studio does with the data it receives from each connection is set out in the privacy policy, including the Limited Use commitments that govern Google user data. Any connection can be disconnected at any time.

Your service agreement

An engagement starts with an agreement we prepare for your Company and send to a named signer over a private link. The link needs no Operating Studio account and shows only that document. The signer reads the agreement, types their full name, confirms they are authorized to accept for the Company, and selects Accept agreement.

Acceptance is what activates the Company. We record the version accepted, the signer’s name and email, the time, and the technical evidence of the acceptance, and we issue a PDF of the completed agreement to the signer. That record is not an electronic notarization, an identity check, or a qualified digital signature; it is a clear, attributable business acknowledgement.

Our decision to prepare and send an agreement is our acceptance of it. No separate countersignature from us is required.

The signed proposal identifies which offer and schedule govern an engagement: whether the engagement uses the Fractional Chief AI Officer offer or the Managed AI Operating System offer and which commercial schedule governs.

Status. As of the date on this page, the private-link acceptance flow described here is not yet live and no Company agreement has been issued through the product. This section states what applies from the moment the first agreement is sent through it.

Fees and billing

Fractional Chief AI Officer offer

Operating Studio is a paid service. Your Company’s agreement names a one-time setup fee and a fixed monthly service fee from the published service levels — $5,000, $10,000, $15,000, or $20,000 per month, each with a setup fee of three times the monthly service — or a custom amount agreed in writing on the same three-times-setup basis. The service levels and what each includes are published on the home page.

  • Billed in advance, from your service start date. Each service month begins on the day of the month your agreement names, not the first of the calendar month, and is invoiced for the month ahead. Where a start date is the 29th, 30th, or 31st, shorter months use their final day.
  • Codex capacity is fixed, not metered. Capacity is billed as whole units at $200 per unit per month, in advance with the service month. There is no token counter, usage threshold, or variable AI charge. If the work needs more capacity we will notify your Company and may add units in $200 monthly increments; adding a unit does not require a new agreement, and the new quantity appears on later invoices. Changing the $200 unit price would require new commercial terms and a new agreement.
  • The first invoice is paid before kickoff. It contains the setup fee, the first month’s service, and the first month’s capacity. Every invoice is reviewed by a person here before it is sent; nothing is charged automatically on acceptance.
  • Stripe handles payment. Invoice delivery, payment details, receipts, and payment status run through Stripe. We do not store your payment-card details.
  • Other services are passed through at actual cost and only after we agree on them, with a spending ceiling agreed beforehand where that is practical.

If an invoice is still unpaid seven days after its due date, we may place the account on a billing hold — pausing active improvement work and automatic execution until the account is current. A billing hold does not delete your data, cancel your agreement, remove manual access, or change your ownership of anything. When Stripe confirms the account is current, a person here clears the hold and the record shows who did it and when.

If we suspend a material part of managed service for a reason within our control, we provide a reasonable pro-rata credit for the affected period. That credit does not apply to a Company-caused hold, nonpayment, an unlawful instruction, a serious safety or security risk, planned maintenance, or an external outage outside our reasonable control.

During the initial outcomes-discovery period, every amount paid is refundable if we do not reach an approved plan. Once both sides approve that plan, the setup fee is non-refundable because it pays for work already performed and the implementation that follows. Monthly service fees already paid are otherwise non-refundable except under the 90-day promise below.

Status. As of the date on this page, no Stripe integration is live and no invoice has been issued through the product. The service levels, capacity units, and billing dates above are the commercial terms we contract on; the invoicing, payment, and billing-hold mechanics are what we commit to as they come into service.

Managed AI Operating System offer

Managed Core and standard modules use four company bands. The higher applicable band governs when the people count and trailing revenue fall in different bands. For a Company with up to 10 people or up to $3M trailing revenue, Managed Core is $5,000 per month with $15,000 installation, and each standard module is $1,000 per month with $3,000 installation. For up to 20 people or up to $6M trailing revenue, Managed Core is $10,000 per month with $30,000 installation, and each standard module is $2,000 per month with $6,000 installation. For up to 30 people or up to $9M trailing revenue, Managed Core is $15,000 per month with $45,000 installation, and each standard module is $3,000 per month with $9,000 installation. For up to 40 people or up to $12M trailing revenue, Managed Core is $20,000 per month with $60,000 installation, and each standard module is $4,000 per month with $12,000 installation. Core installation and module installation are each three times their corresponding monthly fee.

  • Annual band review. The Company’s band is set at signing and reviewed annually. It moves to a higher band only at an annual review when the relevant threshold has been exceeded for two consecutive quarters.
  • AI-model usage is itemized at actual cost with no markup. Before go-live, we agree a monthly usage budget and notification threshold. We alert the Company at 80% and obtain approval before materially exceeding the budget, except where needed to complete an already approved action safely.
  • Third-party business software remains client-owned. Required licenses are paid directly by the client.

The first 90 days

Fractional Chief AI Officer offer

We sign the service agreement before pretending we already know the right outcomes. During the first 30 days from the mutually agreed kickoff date, we work with the Company to define the initial outcomes, how both sides will recognize completion, priorities, and expected timing. Both sides approve that plan in writing before managed execution begins.

If we do not agree on the plan within those 30 days, unless both sides extend the discovery period in writing, the engagement ends. We refund every amount paid, including the setup fee, within 10 business days. The Company keeps its data and Company-specific discovery materials.

The 90-day outcome period begins on the date in the approved plan, regardless of an earlier administrative or billing date. If we do not deliver the agreed outcomes in that period, the Company may end the engagement and have the monthly managed-service fees covered by that promise returned.

Managed AI Operating System offer

Before kickoff, we write a one-page First 90 Days Plan for Managed Core and any initial modules. It names three to five measurable outcomes, the objective evidence for each one, the responsible people, the installation schedule, and the written go-live date.

The outcome period begins on the written go-live date, after installation is complete. Installation is scheduled for no more than 30 calendar days unless the proposal names a longer dependency before kickoff. Delays caused by missing client access, data, or decisions move the go-live date by the documented delay.

At day 90, we review the agreed objective evidence. If Operating Studio has not delivered every committed outcome, the Company may end the engagement and receive the Managed Core and module service fees paid for the outcome period back. Installation fees cover completed setup work and are non-refundable once that work begins.

Ending the engagement

Fractional Chief AI Officer offer

Your Company may end managed service with 30 days’ written notice. Managed-service billing stops on the effective termination date, apart from amounts already due.

If we end or do not renew managed service for our convenience, we give at least six months’ written notice. During that runway we keep the existing operation running at the protected price and let the Company use its existing capacity to prioritize transition and handoff work.

We may suspend or end access sooner — for an individual or for a Company — for serious misuse, a security risk to other Companies, non-payment after the seven-day grace period, or a substantial breach of these terms. We will give reasonable notice where the circumstances allow.

Shared exit and export obligations

When an engagement ends, we will:

  • stop automatic execution safely;
  • disconnect the integrations we control;
  • provide a usable export of your Company’s data, and the operating documentation and SOPs for the processes and decisions we developed together;
  • leave the underlying workflows available for manual use through the end of the paid service period, where the product supports it; and
  • delete the remaining Company data on request, apart from the limited audit and payment records we have to keep — see retention and deletion.

Export and deletion are carried out by a person on request today; there is no self-serve export or delete button in the product yet, and we would rather say so than imply a button that does not exist. Removed memberships keep their attribution in the Company’s activity history so the record of who did what stays intact.

After managed service ends, the Company receives 60 days of free read-only access and export capability. After those 60 days, hosted access closes unless the Company affirmatively chooses Manual Mode in writing. Manual Mode costs $1,000 per month and never begins automatically.

Managed AI Operating System offer

The initial term runs through the 90-day outcome period. After that, service continues month to month and either party may end it with 30 days’ written notice.

Resolving disputes

A Company’s service agreement is governed by California law. If a dispute arises, we start by talking directly. If that does not resolve it within 30 days after written notice, either side may begin mediation. If mediation does not resolve it within 45 days after a mediator is appointed, the dispute goes to final and binding arbitration administered by the American Arbitration Association under its Commercial Arbitration Rules, before one neutral arbitrator.

The Company and Operating Studio each pay half of the mediator, arbitration administrator, and arbitrator fees. Each side pays its own lawyers while the dispute is pending. The arbitrator must award reasonable legal fees and ordinary case costs to the prevailing side, but may decide neither side prevailed when the result is genuinely mixed. Shared mediation and arbitration fees remain shared.

Arbitration is remote unless both sides agree otherwise. Either side may still ask a court for a temporary order needed to protect confidential information, data, intellectual property, or service security, and a court with jurisdiction may enforce the final award. Where a Company’s service agreement is more specific, that agreement controls.

Liability

We commit to perform managed service with reasonable skill and care. Apart from that written commitment, the service is provided as is and we disclaim implied warranties to the extent the law allows.

Neither side is responsible to the other for indirect or consequential losses. For ordinary claims, each side’s total liability is capped at the fees paid or payable under the service agreement in the twelve months before the claim.

Claims involving confidentiality, our data-security or privacy obligations, third-party intellectual-property infringement, or a party’s gross negligence have a separate cap of two times those twelve-month fees. Reasonable costs of responding to a confirmed data incident and amounts owed to a third party under a covered claim count as direct loss, but remain inside that separate cap.

No cap applies to a party’s own fraud or willful misconduct, or to fees the Company owes under its service agreement. A prevailing-side legal-fee award is separate from, and does not reduce, those liability caps.

Nothing in these terms excludes liability that cannot lawfully be excluded.

Changes to these terms

We may update these terms as the product changes. The date at the top of this page always reflects the current version, and we will tell Company admins about material changes. Continuing to use Operating Studio after a change means accepting the updated terms.

Contact

Questions about these terms can be raised through the person who invited you, through your Company admin, or through the request form on the home page.