# The Company Company > The company that builds companies ## Home Source: https://www.thecompany.company The Company Company — The company that builds companies --- ## Documentation ### Introduction Source: https://www.thecompany.company/docs The Company Company is a platform for autonomous company operations: AI agents that manage workflows, make decisions, and execute tasks. ## Platform surfaces [#platform-surfaces] Get up and running with The Company Company in minutes. Connect GitHub and work with Co across pull requests, issues, and discussions. --- ### Quickstart Source: https://www.thecompany.company/docs/quickstart Follow these steps to set up The Company Company locally. ## Prerequisites [#prerequisites] * [Bun](https://bun.sh) v1.3 or later * [Docker](https://docker.com) for local services * A PostgreSQL database (provided via Docker Compose) ## Setup [#setup] ```bash git clone https://github.com/the-company-company/comcom.git cd comcom ``` ```bash bun install ``` ```bash source scripts/setup/bootstrap-dev.sh ``` ```bash bun run dev ``` ## Next steps [#next-steps] Once your development environment is running, you can: * Access the dashboard at `http://localhost:3001` * Access the API at `http://localhost:3002` * Access the marketing site at `http://localhost:3000` * Access the admin app at `http://localhost:3008` * Access these docs at `http://localhost:3000/docs` ## Useful commands [#useful-commands] ```bash bun run dev --filter=api bun run dev --filter=app bun run dev --filter=web bun run dev --filter=admin ``` --- ### GitHub Source: https://www.thecompany.company/docs/integrations/github Connect the GitHub App to let Co work with your organization's repositories and follow work from GitHub into the right Co session. ## Connect GitHub [#connect-github] In **Settings → Integrations**, open GitHub and install the GitHub App for your organization. Choose the repositories that Co can access during the GitHub installation flow. Open **Settings → Repositories** to see the repositories synced from the installation. Add or remove access in the GitHub App installation, then use the refresh action on the Repositories page to sync changes immediately. Each member should open **Settings → Connections** and connect their personal GitHub account. Linking identifies who mentioned Co and preserves attribution when Co comments or acts on their behalf. If someone who has not linked their account mentions Co, the GitHub App replies with a link to the Connections settings page instead of starting work. ## Browse and claim pull requests [#browse-and-claim-pull-requests] Open the pull request browser in a Co session to view pull requests across the organization. Filter by repository, state, or author, then use the row menu to: * **Claim for session** to send future feedback from that pull request to the current session. * **Start Co session** to create and claim a dedicated session for the pull request. The first time a session claims a pull request, Co posts an editable control comment with a link to the session. Its **Review** checkbox controls automatic review triggers for that pull request. Its **Auto-fix** checkbox controls ambient feedback turns; untick it to stop those turns while keeping explicit mentions available. The control comment also lists commands you can post on the pull request: * `@co claim` hands the pull request to Co — feedback starts flowing to the session. * `@co mute` pauses all delivery from the pull request. * `@co unmute` resumes delivery. * `@co archive` ends the linked session. ## Mention Co on GitHub [#mention-co-on-github] Mentions work in pull request conversations, inline review threads, review bodies, issues, and discussions. Mention the GitHub App by its username or write `@co` followed by the request. Co adds a 👀 reaction to acknowledge the mention. If the conversation already has a claiming session, the request goes there. Otherwise, Co creates a session and answers in the conversation. Mentioning Co on a pull request does not claim it: Co takes a pull request over only when the request implies ownership — "fix the review comments" leads to a claim, "explain this change" does not — or when you say `@co claim` explicitly. Claiming is what starts the ambient feedback flow and posts the control comment. Start a pull request mention with `@co review` to seed a review-focused session. Add any review instructions after the command. ## Follow feedback in the claiming session [#follow-feedback-in-the-claiming-session] The claiming session receives pull request reviews, conversation and inline comments from people and bots alike, completed CI outcomes — failures and passing runs — and merged or closed events as new turns. Events deliver as they arrive; bursts fold together into a single turn when the session picks them up. ## Use GitHub in the session sandbox [#use-github-in-the-session-sandbox] Sessions with GitHub repositories receive authenticated `git` and `gh` access automatically. Credentials are provided per command and scoped to the session's repositories plus any GitHub conversations bound to the session, so a claimed pull request's repository is covered even when it is not attached to the session. Agents can clone an in-scope repository or use `gh pr checkout` for its pull requests without a separate GitHub login, and can still fetch public repositories outside that scope. Terminals you open yourself in the session sandbox run without GitHub credentials. ## Agent tools and policy [#agent-tools-and-policy] Co's GitHub integration provides a curated set of tools for listing and viewing repositories, issues, and pull requests; creating and closing issues; commenting and replying; creating, reviewing, and merging pull requests; and related GitHub actions. Each member configures tool policy for their own sessions on the GitHub integration page in **Settings → Integrations**. Every tool has three policy choices: * **Always allow** runs the tool without requesting approval. * **Needs approval** pauses for a person to approve the tool call. * **Never** prevents the tool from running. Tools are set to **Always allow** by default. Use the per-tool controls to require approval for higher-impact actions such as merging a pull request while leaving read-only tools available without interruption. ## Auto-review [#auto-review] The organization-level **Auto-review** setting is off by default. When enabled, it reviews catalog pull requests when they become ready for review and after new pushes. The setting is rolling out, and review execution becomes available with review mode. --- ## Legal ### Privacy Policy Source: https://www.thecompany.company/legal/privacy This Privacy Policy describes how The Company Company Inc., a Delaware corporation with its principal place of business at 1885 Mission St, San Francisco, CA 94103 ("Company," "Co," "we," "us," or "our") collects, uses, discloses, and otherwise processes personal information (also called "personal data" in some jurisdictions) when you: * Access or use our AI-powered business operations platform and related services available at [https://www.thecompany.company](https://www.thecompany.company) (the "Services"); * Visit, interact with, or use our website, marketing pages, or communications; or * Communicate with us through email, support channels, or other means. When we decide how and why to process personal information (for example, for account management, billing, or marketing), we act as a "business" under the California Consumer Privacy Act and "controller" under other privacy laws. When we process Customer Data on behalf of our business customers in order to provide the Services, we act as a "service provider" under the CCPA/CPRA and a "processor" under other applicable laws. Our processing of Customer Data in that capacity is governed by our agreement with the applicable customer, including any Data Processing Agreement ("DPA"). By using the Services, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with this Privacy Policy, please do not use the Services. For information about how we process Customer Data on behalf of our business customers, please see the sections titled "Customer Data" and "Our Role as a Service Provider" below. ### Information We Collect [#information-we-collect] #### Information You Provide [#information-you-provide] * **Account Information**: Name, email address, password, and organization details when you create an account, as well as optional profile information (such as display name, avatar, role, and team membership). If you use Google Single Sign-On (SSO) on eligible plans, we receive your Google profile information (including name, email address, and profile picture) from Google when you authenticate. * **Billing Information**: Billing contact name, email address, billing address, tax identifiers (where applicable), and payment method details. We use third-party providers, including Autumn (which uses Stripe as a sub-processor), to process payments. We do not store full payment card numbers on our servers and only retain tokenized payment references and limited card metadata (such as last four digits and card type) as provided by our payment processors. * **Customer Data**: Any data, content, or information you submit through the Services in connection with your use, including data pulled from third-party tools you connect (for example, Slack, Google Workspace, Linear, GitHub, HubSpot, Mercury, LinkedIn, Twitter/X, and other integrations you authorize). Customer Data may include business records, communications, documents, project and ticket information, financial transaction data, and other information depending on the integrations and agent workflows you configure. You control what Customer Data is submitted to or generated through the Services. * **Communications**: Information you provide when you contact us for support, submit feedback, or otherwise communicate with us, including your name, email address, the content of your messages, and any attachments or files you choose to send. * **Professional and Business Information**: Company name, job title or role, department, team membership, and other professional information you provide when creating or managing a workspace or user account. * **Third-Party Integration Credentials**: When you authorize integrations with third-party services, we receive and store authentication credentials (such as OAuth access and refresh tokens and API keys) in encrypted form. We use these credentials only to connect to and act within those third-party services as necessary to perform the tasks and workflows you configure. #### Information Collected Automatically [#information-collected-automatically] When you use the Services, we automatically collect certain information, including: * **Log Data**: IP address, browser type, operating system, referring URLs, pages visited, timestamps, access times, and information about your interactions with specific features of the Services. * **Device Information**: Device type, unique device identifiers, and operating system version, hardware model, browser type and version, screen resolution, and mobile network information (such as carrier and connection type). * **Usage Data**: Features used, actions taken, frequency and duration of activities, and performance data, including agent execution logs, tool calls, error logs, clickstream data, and other information about how you navigate and interact with the Services. * **Geolocation Data**: Approximate location derived from your IP address (for example, city, state, or region). We use this information to provide the Services, maintain security, comply with regional legal requirements, and understand where our users are located. We do not collect precise geolocation (such as GPS coordinates) unless you explicitly enable a feature that requires it. * **Session Information and Recordings**: We may use product analytics tools to collect information about how you use the Services, including through event tracking and, in some cases, session recordings that capture interactions such as mouse movements, clicks, scrolling, and page transitions. We configure these tools to avoid capturing passwords, payment card numbers, and other fields we designate as sensitive. #### Cookies and Tracking Technologies [#cookies-and-tracking-technologies] We use the following categories of cookies and similar technologies: * **Strictly Necessary**: Required for the Services to function, including authentication and security cookies. These cannot be disabled. Without them, we cannot provide the Services. * **Analytics**: Used to understand how users interact with the Services. We use the following analytics services: * **PostHog**: Product analytics and session recording for understanding user behavior and improving the Services, measuring feature adoption, debugging issues, and improving user experience. * **Vercel Analytics**: Web performance and traffic analytics used to monitor page load times, request volumes, and performance metrics. We do not use advertising or marketing cookies. We also do not use third-party advertising pixels (such as the Meta or TikTok pixel) in the Services. You can manage analytics cookies through your browser settings or by contacting us at [legal@thecompany.company](mailto:legal@thecompany.company). Disabling analytics cookies will not affect the functionality of the Services. Depending on your location, you may see additional cookie controls or banners when you visit our website, and you can use those controls to manage your preferences. ### How We Use Your Information [#how-we-use-your-information] We use the information we collect to: * Provide, operate, and maintain the Services. * Process transactions and manage your subscription. * Send transactional communications, including service updates, security alerts, and support messages. * Respond to your requests, comments, and questions. * Monitor and analyze usage patterns and trends to improve the Services. * Detect, prevent, and address fraud, abuse, and security issues. * Comply with legal obligations and enforce our Terms of Service. * Develop new features and functionality. More specifically, we use personal information for the following purposes: * **Providing and operating the Services**: Creating and managing accounts, authenticating users, executing agent workflows, connecting to third-party integrations you authorize, processing transactions, and providing customer support. * **Improving and developing the Services**: Monitoring and analyzing usage patterns, diagnosing, and fixing bugs, conducting research and development, and testing new features and improvements. * **Security and abuse prevention**: Detecting, investigating, and preventing fraudulent, harmful, or unauthorized activity; protecting the security and integrity of the Services, our users, and our infrastructure. * **Communications**: Sending transactional messages, service-related announcements, security alerts, technical notices, and administrative messages; responding to your inquiries and support requests. * **Marketing and engagement**: Sending you marketing emails or in-product messages about new features, offers, and events (where permitted by law). You can opt out of marketing communications at any time. * **Compliance and legal obligations**: Complying with applicable laws, regulations, legal processes, and government requests; enforcing our Terms of Service and other policies; and protecting our rights and the rights of others. * **Business operations**: Performing accounting, auditing, billing, reconciliation, and other internal business operations; planning and forecasting; and evaluating or conducting corporate transactions (such as mergers, acquisitions, or financing). We do not use your Customer Data to train, fine-tune, or improve general-purpose AI or machine learning models, or for purposes unrelated to providing the Services to you. We may use aggregated or de-identified information derived from Customer Data for analytics, benchmarking, and improving the Services, provided that such information cannot reasonably be used to identify you or any individual. ### AI and Automated Processing [#ai-and-automated-processing] Our Services include AI-powered features that process data to provide autonomous agent capabilities. In connection with these features: * **AI Processing**: Customer Data may be processed by AI models to generate outputs, make recommendations, and execute tasks as configured by the Customer. This processing is performed solely to provide the Services. The quality and accuracy of AI outputs depend on the data, prompts, and configurations you provide. * **Third-Party AI Providers**: We use third-party AI model providers (such as Anthropic) to power AI features. Customer Data sent to these providers is subject to our data processing agreements with them and is not used by these providers to train their models. The quality and accuracy of AI outputs depend on the data, prompts, and configurations you provide. * **AI Logs**: We may retain logs of AI inputs and outputs for a limited period to provide the Services, debug issues, and ensure quality. These logs are treated as Customer Data and subject to the same protections. We generally retain AI logs for the periods described in the "Data Retention" section below unless a longer period is required to resolve specific support or security issues. * **Automated Decision-Making**: Our AI features may make automated decisions or take automated actions based on Customer configurations. Customers are responsible for implementing appropriate human oversight as required by their use case and applicable law. You must not use AI-generated outputs as the sole basis for decisions that produce legal or similarly significant effects on individuals (such as employment, credit, housing, or healthcare decisions) without appropriate human review and additional safeguards. * **No Model Training**: We do not use Customer Data to train, fine-tune, or improve general-purpose AI or machine learning models. If we ever propose to use your information for training or fine-tuning our own models beyond providing the Services, we will obtain your explicit consent or provide a clear opt-out mechanism, as required by law. Depending on your location, you may have rights to object to or opt out of certain automated processing or profiling that produces legal or similarly significant effects. See the "U.S. State Privacy Rights" and "California Residents (CCPA/CPRA and Similar Laws)" sections below for more information. ### How We Share Your Information [#how-we-share-your-information] We do not sell your personal information. We may share information in the following circumstances: * **Service Providers**: With third-party vendors who perform services on our behalf (hosting, payment processing, analytics, AI model providers, email delivery), subject to confidentiality and data processing obligations and only for the purposes described in this Privacy Policy or in our agreement with your organization. * **Legal Compliance**: When required by law, regulation, legal process, or governmental request. * **Safety and Rights**: To protect the rights, property, or safety of the Company, our users, or others. * **Business Transfers**: In connection with a merger, acquisition, reorganization, or sale of assets, in which case your information may be transferred as part of the transaction, and we will take reasonable steps to require the recipient to honor this Privacy Policy or notify you of material changes. * **With Your Consent**: When you have given us explicit consent to share your information. We may share aggregated or de-identified information that cannot reasonably be used to identify you with third parties for analytics, research, and similar purposes. ### Our Role as a Service Provider [#our-role-as-a-service-provider] When we process Customer Data on behalf of our business customers, we act as a "service provider" as defined by the CCPA/CPRA. In this capacity, we: * Process Customer Data only for the business purposes specified in our agreement with the Customer. * Do not sell or share Customer Data. * Do not retain, use, or disclose Customer Data for any purpose other than performing the Services. * Do not combine Customer Data with personal information received from other sources, except as permitted by the CCPA. * Certify that we understand and will comply with these restrictions. ### Data Security [#data-security] We implement commercially reasonable technical and organizational measures to protect your information, including: * Encryption of data in transit (TLS) and at rest * Access controls and authentication mechanisms * Regular security reviews * Incident response procedures However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security. If we become aware of a security incident that affects your personal information, we will notify you and/or your organization as required by applicable law and in accordance with our incident response procedures. ### Data Retention [#data-retention] We retain personal information as follows: * **Account Information**: For the duration of your account plus 30 days after account deletion. * **Billing Records**: For 7 years after the transaction, as required by tax and financial regulations. * **Log and Usage Data**: For 12 months from collection. * **AI Logs**: For 90 days from generation unless longer retention is required to provide the Services or resolve issues. * **Support Communications**: For 3 years from resolution. * **Aggregated/Anonymized Data**: Indefinitely, as it cannot be used to identify you. When data is no longer needed, we securely delete or anonymize it. In some cases, we may need to retain certain information for longer periods to comply with legal, tax, accounting, or security requirements, even after you close your account or we no longer provide Services to you. ### U.S. State Privacy Rights [#us-state-privacy-rights] If you are a resident of a U.S. state with a comprehensive consumer privacy law, you may have some or all of the following rights over your personal information, subject to certain exceptions and limitations under applicable law. Similar rights may also be available to residents of other states if additional privacy laws come into effect. * **Right to Know / Access**: The right to confirm whether we are processing your personal information and to request access to that information, including the categories of personal information, the categories of sources, the purposes for processing, and the categories of third parties to whom we disclose it. * **Right to Data Portability**: The right to obtain a copy of certain personal information in a portable and, to the extent technically feasible, readily usable format so that it can be transmitted to another entity. * **Right to Delete**: The right to request that we delete personal information we collected from or about you, subject to certain exceptions (for example, when we must retain data to comply with law, to detect security incidents, or to protect against fraudulent or illegal activity). * **Right to Correct**: The right to request that we correct inaccurate personal information about you, taking into account the nature of the personal information and the purposes of the processing. * **Right to Opt Out of Certain Processing**: Depending on your state, the right to opt out of our processing of personal information for: (a) "targeted advertising," (b) the "sale" of personal information, and/or (c) "profiling" in furtherance of decisions that produce legal or similarly significant effects concerning you. We do not "sell" your personal information or engage in "targeted advertising" as those terms are defined in most state laws. If our practices change in the future, we will update this Privacy Policy and provide you with any required notices and choices (including any "Do Not Sell or Share" mechanisms). * **Right to Limit Use and Disclosure of Sensitive Personal Information**: In some states, the right to limit our use and disclosure of certain "sensitive" personal information. We collect limited sensitive personal information (such as account login credentials) as described in this Privacy Policy and use it only as reasonably necessary to provide the Services, maintain security, and comply with law. We do not use or disclose sensitive personal information for additional purposes that would give rise to a right to limit in most states' laws. * **Right to Non-Discrimination / Non-Retaliation**: The right not to be discriminated or retaliated against for exercising your privacy rights. We will not deny you goods or services, charge you different prices or rates, or provide you a different level or quality of services solely because you exercised your privacy rights. ### Exercising Your U.S. State Privacy Rights [#exercising-your-us-state-privacy-rights] You or your authorized agent can submit a request to exercise your applicable privacy rights by emailing us at [legal@thecompany.company](mailto:legal@thecompany.company) with a clear description of your request and the state where you reside. We may need to verify your identity (and, where applicable, your agent's authority) before we act on your request. We will respond within the timeframes required by applicable law (typically 45 days, with the ability to extend once where permitted). If we decline to act on your request, we will explain our decision. If your state law gives you the right to appeal our decision, you may do so by replying to our response or emailing us at [legal@thecompany.company](mailto:legal@thecompany.company) with "Privacy Rights Appeal" in the subject line. We will review your appeal and respond within the timeframe required by your state law (typically 45-60 days), explaining our decision. If additional states adopt similar privacy laws in the future, we will treat residents of those states in a manner consistent with this section and update this Privacy Policy as needed. ### California Residents (CCPA/CPRA and Similar Laws) [#california-residents-ccpacpra-and-similar-laws] If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), in addition to the rights described above. Residents of some other states (such as Virginia, Colorado, Connecticut, and similar "Virginia-model" states) have substantially similar rights, although the terminology and scope may differ. * **Right to Know**: You have the right to request that we disclose: (a) the categories of personal information we have collected about you; (b) the categories of sources from which the personal information is collected; (c) the business or commercial purpose for collecting or disclosing personal information; (d) the categories of third parties to whom we disclose personal information; and (e) the specific pieces of personal information we have collected about you. * **Right to Delete**: You have the right to request that we delete personal information we have collected from you, subject to certain exceptions (for example, when we must keep information to comply with a legal obligation, to detect or prevent security incidents, or to protect against malicious or illegal activity). * **Right to Correct**: You have the right to request that we correct inaccurate personal information about you, taking into account the nature of the personal information and the purposes of the processing. * **Right to Opt Out of Sale/Sharing**: We do not "sell" or "share" your personal information for cross-context behavioral advertising as those terms are defined in the CCPA/CPRA. If our practices change in the future, we will update this Privacy Policy and provide you with appropriate notice and choices, including any required "Do Not Sell or Share My Personal Information" mechanisms. * **Right to Limit Use and Disclosure of Sensitive Personal Information**: We collect certain "sensitive personal information" (such as account login credentials) as described above. We use this information only as reasonably necessary to provide the Services, secure your account, and comply with law, and not for additional purposes that would trigger the CCPA right to limit. If that ever changes, we will provide you with a way to exercise your right to limit such use or disclosure. * **Right to Non-Discrimination**: We will not discriminate against you for exercising any of your CCPA/CPRA rights. This means we will not deny you goods or services, charge you different prices or rates, or provide you a different level or quality of services solely because you exercised your privacy rights. To exercise any of these rights, contact us at [legal@thecompany.company](mailto:legal@thecompany.company). We will verify your identity before processing your request and respond within 45 days as required by law. If we need more time (up to an additional 45 days), we will let you know. If we deny your request, you may have the right to appeal; you can email us with "California Privacy Appeal" in the subject line, and we will respond within the timeframe required by California law. Where other state laws provide similar appeal rights, we will handle those appeals in a manner consistent with this process and applicable law. **Categories of Personal Information Collected** (as defined by the CCPA): | Category | Examples | Collected | Sources | Business Purpose | | ------------------------------ | -------------------------------------------- | --------- | ------------------------------------------------- | ------------------------------------------------ | | Identifiers | Name, email, IP address | Yes | Directly from you; automatically from your device | Account creation, authentication, communications | | Commercial information | Subscription records, billing history | Yes | Directly from you; from payment processors | Billing, subscription management | | Internet activity | Browsing history, interactions with Services | Yes | Automatically from your device and our Services | Service improvement, security, analytics | | Geolocation data | Approximate location from IP address | Yes | Automatically from your device | Service delivery, security | | Professional information | Company name, job title | Yes | Directly from you | Account setup, personalization | | Sensitive personal information | Account login credentials | Yes | Directly from you | Authentication, account security | ### Do Not Track Signals [#do-not-track-signals] Some browsers include a "Do Not Track" ("DNT") setting that can send a signal to the websites you visit, indicating that you do not want to be tracked. There is currently no common industry standard for how to interpret DNT signals, and we do not respond to DNT signals at this time. You can manage most tracking technologies used by the Services as described in the Cookies and Tracking Technologies section. Certain U.S. state privacy laws (including in California and Colorado) require businesses to recognize browser- or device-level opt-out preference signals or universal opt-out mechanisms, such as Global Privacy Control ("GPC"), when those businesses "sell" or "share" personal information or engage in "targeted advertising" as defined by those laws. We do not currently sell personal information, share it for cross-context behavioral advertising, or use it for targeted advertising as those terms are defined under these laws. However, to the extent required by applicable law, when we detect a valid GPC or similar recognized opt-out signal from your browser or device, we will treat that signal as a request to opt out of any sale, sharing, or targeted advertising that may apply to our future data practices. Because we do not currently engage in those activities, honoring such signals will have limited practical effect today but may impact certain non-essential analytics or tracking if our practices change. ### International Data Transfers [#international-data-transfers] Our Services are hosted in the United States. If you access the Services from outside the United States, your information will be transferred to and processed in the United States. By using the Services or providing us with information, you understand that your personal information may be transferred to, stored in, and processed in the United States and in other countries where our service providers operate, which may have different data protection laws than those in your country. We do not currently market or offer the Services to individuals located in jurisdictions that impose additional data transfer or localization requirements (such as the European Economic Area, the United Kingdom, or Switzerland), and we do not represent that the Services comply with all laws of any non-U.S. jurisdiction. If you choose to access the Services from outside the United States, you do so on your own initiative and are responsible for compliance with any local laws that apply to you. If, in the future, we intentionally expand to serve users in jurisdictions that require specific cross-border transfer mechanisms (such as Standard Contractual Clauses or participation in a Data Privacy Framework), we will implement appropriate transfer mechanisms to the extent required by applicable law and update this Privacy Policy accordingly. ### Third-Party Links and Services [#third-party-links-and-services] The Services may contain links to third-party websites or services that are not operated by us. We are not responsible for the privacy practices of these third parties. We encourage you to review the privacy policies of any third-party services you access. Your use of third-party services is governed by those services' own terms and privacy policies. ### Changes to This Policy [#changes-to-this-policy] We may update this Privacy Policy from time to time. We will notify you of material changes by: * Posting the updated policy on our website with a revised "Last updated" date * Sending notice to the email address associated with your account, where practicable Your continued use of the Services after the effective date of any changes constitutes acceptance of the updated policy. If you do not agree to the updated Privacy Policy, you must stop using the Services and may request that we delete your account. ### Contact Us [#contact-us] If you have any questions about this Privacy Policy or wish to exercise your privacy rights, please contact us at: * Email: [legal@thecompany.company](mailto:legal@thecompany.company) * Address: The Company Company Inc., 1885 Mission St, San Francisco, CA 94103 You may also have the right to lodge a complaint with your local data protection authority or attorney general if you believe we have violated applicable privacy laws. However, we encourage you to contact us first so we can address your concerns. --- ### Website Terms of Service Source: https://www.thecompany.company/legal/terms These Website Terms of Use ("Terms") govern your access to and use of our public marketing website at [https://www.thecompany.company](https://www.thecompany.company) and any related subdomains we operate (the "Website"). These Terms cover: * Your browsing and use of the Website, including viewing content, signing up for a waitlist or newsletter, and submitting inquiries or contact forms; and * Your creation of a free account through the Website or Application sign-in page (at [https://www.app.thecompany.company/sign-in](https://www.app.thecompany.company/sign-in)) using Google Single Sign-On, Enterprise Single Sign-On, or email-based authentication, solely for the purpose of accessing marketing content, requesting demos, or receiving product updates. These Terms do NOT govern your use of the Company's AI-powered business operations platform (the "Application"), which is subject to a separate set of terms (the "Application Terms of Service"). If you use the Application, including configuring or running AI agents, submitting Customer Data, or accessing any paid features, the Application Terms of Service apply in addition to these Terms. In the event of a conflict, the Application Terms of Service control with respect to your use of the Application. These Terms are a legally binding agreement between you and The Company Company Inc. ("Company," "we," "us," or "our"). By accessing or using the Website or creating an account through any sign-in method offered on the Website or Application sign-in page, you agree to be bound by these Terms. If you do not agree, please do not access the Website or create an account. ### Definitions [#definitions] * "Agreement" means these Website Terms of Use together with our Privacy Policy (available at [https://www.thecompany.company/legal/privacy](https://www.thecompany.company/legal/privacy)) and any supplemental terms we may provide. * "Account" means a user account you create through the Website or the Application sign-in page, which may provide you with access to waitlist registration, demo requests, newsletter subscriptions, product updates, and other marketing-related features. An Account does not by itself grant you access to the Application or any paid features of the Website. * "Authorization Mechanisms" means the methods available for creating an Account, including: (a) Google Single Sign-On (SSO), which uses OAuth 2.0 to authenticate via your Google account; (b) Enterprise Single Sign-On (SSO), which uses Security Assertion Markup Language (SAML) or similar protocols to authenticate via your organization's identity provider; and (c) email-based authentication, which may use passwordless links, one-time verification codes, or other email-based verification methods. * "Website Content" means the text, graphics, images, videos, blog posts, code samples, and other materials made available on or through the Website. ### Eligibility and Account Registration [#eligibility-and-account-registration] You must be at least 18 years old and have the legal authority to enter into these Terms on behalf of yourself or the entity you represent. You represent that you are not a minor under the age of 18 and that your use complies with any applicable age-gating or parental consent requirements under laws such as COPPA (as amended). We do not knowingly collect data from children under 13. By creating an account, you represent and warrant that: * All registration information you provide is truthful, current, complete, and accurate. * You are signing up for the purpose of learning about our products and Website, receiving marketing communications, or requesting a demo or trial access, and not for any competing, malicious, or fraudulent purpose. * If you create an Account through Google SSO, you represent and warrant that: (a) your Google account is valid and in good standing; (b) you have the authority to grant the permissions requested by the Website to access your Google profile information (including name, email address, and profile picture); and (c) your use of the Website through your Google account does not violate any agreement or policy governing your use of the Google account. * If you create an Account through Enterprise SSO, you represent and warrant that: (a) your organization has authorized your use of the Website through SSO; (b) you have the authority to grant the permissions requested by the Website within your organization's identity provider; and (c) your use of the Website through SSO does not violate any agreement or policy governing your use of your organization's systems. * If you create an Account through email-based authentication, you represent and warrant that: (a) the email address you provide belongs to you or has been authorized for your use; (b) you have the sole control over that email address; and (c) you will promptly notify us if the email address is compromised, no longer accessible, or if your role with respect to any associated account changes. * You are responsible for: (a) all activities conducted through your Account, whether authorized by you or not; (b) maintaining the confidentiality of your authentication credentials and any third-party accounts (Google, your organization's identity provider, or your email account) used to access the Website; and (c) promptly notifying us at [legal@thecompany.company](mailto:legal@thecompany.company) if you become aware of any unauthorized access to your Account or authentication credentials. We may, at our discretion, assign roles or access levels to your Account (for example, as a "waitlist member," "demo requester," "subscriber," or similar designation). These roles are for administrative and marketing purposes only and do not confer any rights to access the Application or its features unless and until a separate agreement is entered into. ### Use of Website [#use-of-website] #### Acceptable Use [#acceptable-use] You may use the Website only for lawful business purposes and in accordance with these Terms. You agree not to: * Violate any applicable law, regulation, or third-party right. * Transmit any malicious code, viruses, or harmful components. * Attempt to gain unauthorized access to any systems or networks connected to the Website. * Interfere with, disrupt, or create an undue burden on the Website or related infrastructure. * Use any AI features or outputs from the Website in a manner that could cause harm, including without limitation generating or disseminating misleading, discriminatory, or unlawful content; or circumventing safety guardrails in any linked AI systems. * Use the Website to develop a competing product or service. * Reverse engineer, decompile, or disassemble any aspect of the Website. * Use the Website for any fraudulent, deceptive, or illegal purpose. * Resell, sublicense, or redistribute the Website without our prior written consent. * Access or use the Website in any manner that exceeds normal human use or volumetric thresholds, including through scraping, data mining, robot harvesting, or any automated data collection method, without our prior written consent. * Impersonate or attempt to impersonate the Company, any employee of the Company, another user, or any other person or entity, including through the use of a false name, credentials, or other information. #### Service Availability [#service-availability] We will use commercially reasonable efforts to make the Website available, but we do not guarantee uninterrupted or error-free operation. The Website is provided on an "as available" basis, and we may modify, suspend, or discontinue any part of the Website at any time with or without notice. #### Regulatory Compliance [#regulatory-compliance] You are solely responsible for ensuring that your use of the Website and any decisions you make based on Website Content comply with all applicable laws, regulations, and industry standards. ### Intellectual Property [#intellectual-property] #### Ownership of Website Content [#ownership-of-website-content] All Website Content, including but not limited to text, graphics, images, videos, audio, blog posts, code samples, documentation, logos, trademarks, trade dress, and other materials, is owned by the Company or its licensors and is protected by applicable intellectual property laws. Nothing in these Terms grants you any right to use our trademarks, trade names, service marks, logos, or other branding without our prior written consent. #### Limited License to Access the Website [#limited-license-to-access-the-website] Subject to your compliance with these Terms, we grant you a limited, non-exclusive, non-transferable, non-sublicensable, revocable license to access and view the Website and Website Content solely for your own personal or internal business purposes, for the purpose of evaluating the Company and its products and services and not for any commercial exploitation, training of competing AI models, or public dissemination of Website Content or any AI-generated outputs derived therefrom. You may not reproduce, distribute, modify, create derivative works of, publicly display, publicly perform, republish, download, transmit, or sell any Website Content, except as expressly permitted in writing by us. #### Feedback [#feedback] If you submit ideas, suggestions, comments, questions, or other feedback regarding the Website or our products and services ("Feedback"), you agree that: (a) the Feedback is non-confidential and non-proprietary; (b) you have no expectation of compensation for the Feedback; and (c) we may use, disclose, and exploit the Feedback in any manner for any purpose without obligation or compensation to you. You grant us a perpetual, irrevocable, royalty-free license to use, modify, and incorporate Feedback into our products and services, including AI models, without attribution or compensation. ### Confidentiality [#confidentiality] Each party agrees to keep confidential any non-public information disclosed by the other party that is designated as confidential or that reasonably should be understood to be confidential. This obligation does not apply to information that is publicly available, independently developed, or rightfully received from a third party without restriction. ### Account Suspension and Termination [#account-suspension-and-termination] We reserve the right, in our sole discretion, to suspend, restrict, or terminate your access to the Website (including your Account) at any time, with or without notice and without liability, for any reason or no reason, including if we believe you have violated these Terms, engaged in fraudulent or illegal activity, or used the Website in a manner that threatens the security, integrity, or availability of the Website. You may discontinue your use of the Website at any time. You may also request deletion of your Account by contacting us at [legal@thecompany.company](mailto:legal@thecompany.company). We will process such requests within a reasonable timeframe. Upon suspension or termination of your Account, your right to access the Website's account features ceases immediately. Provisions that by their nature should survive termination, including Intellectual Property, Disclaimers, Limitation of Liability, Indemnification, Governing Law, and any other provisions that expressly survive, shall survive any termination or expiration of these Terms. ### Disclaimers [#disclaimers] THE WEBSITE AND ALL WEBSITE CONTENT ARE PROVIDED "AS IS" AND "AS AVAILABLE" WITHOUT WARRANTIES OF ANY KIND, WHETHER EXPRESS, IMPLIED, STATUTORY, OR OTHERWISE. WE SPECIFICALLY DISCLAIM ALL IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, AND NON-INFRINGEMENT. WE DO NOT WARRANT THAT THE WEBSITE WILL BE UNINTERRUPTED, ERROR-FREE, SECURE, OR FREE OF HARMFUL COMPONENTS. NO ADVICE OR INFORMATION OBTAINED FROM US OR THROUGH THE WEBSITE CREATES ANY WARRANTY NOT EXPRESSLY STATED HEREIN. We make no representations regarding the accuracy, completeness, or reliability of any AI-generated content, summaries, or recommendations on the Website. Any reliance on such content is at your sole risk. AI outputs may contain errors, biases, or hallucinations. WEBSITE CONTENT IS PROVIDED FOR GENERAL INFORMATIONAL AND MARKETING PURPOSES ONLY AND DOES NOT CONSTITUTE PROFESSIONAL ADVICE OF ANY KIND, INCLUDING LEGAL, FINANCIAL, TAX, MEDICAL, OR COMPLIANCE ADVICE. YOU ARE SOLELY RESPONSIBLE FOR ANY DECISIONS YOU MAKE BASED ON WEBSITE CONTENT. ### Limitation of Liability [#limitation-of-liability] TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW: * IN NO EVENT SHALL WE BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, EXEMPLARY, OR PUNITIVE DAMAGES, INCLUDING BUT NOT LIMITED TO LOSS OF PROFITS, DATA, BUSINESS OPPORTUNITIES, REVENUE, OR GOODWILL, REGARDLESS OF THE CAUSE OF ACTION OR THEORY OF LIABILITY, EVEN IF WE HAVE BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES. * OUR TOTAL AGGREGATE LIABILITY ARISING OUT OF OR RELATED TO THESE TERMS SHALL NOT EXCEED ONE HUNDRED DOLLARS (US $100.00). Because the Website is provided free of charge and without any payment obligation, no per-period fee-based cap applies. * THE FOREGOING LIMITATIONS APPLY REGARDLESS OF WHETHER THE DAMAGES ARE BASED ON WARRANTY, CONTRACT, TORT (INCLUDING NEGLIGENCE), STRICT LIABILITY, OR ANY OTHER LEGAL THEORY. ### Indemnification [#indemnification] You agree to indemnify, defend, and hold harmless the Company, its officers, directors, employees, agents, and affiliates from and against any and all claims, damages, losses, liabilities, costs, and expenses (including reasonable attorneys' fees) arising from or related to: * Your use of the Website, including any content you submit through contact forms, feedback forms, or other user-submission features. * Your breach of these Terms. * Your violation of any applicable law or third-party right. * Your misuse or misrepresentation of your Account, including any actions taken by other individuals accessing the Website through your Account. * Any dispute between you and a third party relating to your use of the Website. ### Dispute Resolution and Arbitration [#dispute-resolution-and-arbitration] #### Binding Arbitration [#binding-arbitration] Any dispute, controversy, or claim arising out of or relating to these Terms or the Website shall be resolved by binding arbitration administered by JAMS under its Streamlined Arbitration Rules and Procedures. The arbitration shall be conducted in San Francisco, California, by a single arbitrator. The arbitrator's decision shall be final and binding and may be entered as a judgment in any court of competent jurisdiction. To the extent permitted by law, you waive any right to a jury trial. #### Class Action Waiver [#class-action-waiver] YOU AND THE COMPANY AGREE THAT EACH MAY BRING CLAIMS AGAINST THE OTHER ONLY IN YOUR OR ITS INDIVIDUAL CAPACITY, AND NOT AS A PLAINTIFF OR CLASS MEMBER IN ANY PURPORTED CLASS, CONSOLIDATED, OR REPRESENTATIVE PROCEEDING. #### Injunctive Relief [#injunctive-relief] Notwithstanding the foregoing, either party may seek injunctive or other equitable relief in any court of competent jurisdiction to prevent the actual or threatened infringement or misappropriation of intellectual property rights or breach of confidentiality obligations. #### Small Claims Exception [#small-claims-exception] Notwithstanding the foregoing, either party may bring an individual action in small claims court for disputes within the court's jurisdictional limits. #### Opt-Out [#opt-out] You may opt out of the arbitration provision by sending written notice to [legal@thecompany.company](mailto:legal@thecompany.company) within 30 days of first accepting these Terms. If you opt out, disputes will be resolved in the courts specified in the Governing Law section. ### Governing Law [#governing-law] These Terms are governed by the laws of the State of Delaware, without regard to its conflict of law provisions. For any disputes not subject to arbitration, the exclusive jurisdiction and venue shall be the state and federal courts located in San Francisco, California, and each party consents to the personal jurisdiction of such courts. ### General Provisions [#general-provisions] #### Force Majeure [#force-majeure] Neither party shall be liable for any failure or delay in performing its obligations where such failure or delay results from circumstances beyond the party's reasonable control, including but not limited to acts of God, natural disasters, pandemics, war, terrorism, labor disputes, government actions, internet or infrastructure failures, or third-party service provider outages. #### Severability [#severability] If any provision of these Terms is found to be unenforceable or invalid by a court of competent jurisdiction, that provision will be enforced to the maximum extent permissible, and the remaining provisions will remain in full force and effect. #### Entire Agreement [#entire-agreement] These Terms, together with our Privacy Policy (available at [https://www.thecompany.company/legal/privacy](https://www.thecompany.company/legal/privacy)), constitute the entire agreement between you and the Company with respect to your use of the Website and your Account, and supersede all prior or contemporaneous agreements, understandings, or representations, whether written or oral. If you enter into a separate agreement for use of the Application (such as the Application Terms of Service or a Data Processing Agreement), that agreement governs your use of the Application and shall supplement, not replace, these Terms with respect to the Website. #### Assignment [#assignment] You may not assign or transfer these Terms without our prior written consent. We may assign these Terms in connection with a merger, acquisition, reorganization, or sale of all or substantially all of our assets without your consent. Any attempted transfer or assignment in violation hereof shall be null and void. #### No Waiver [#no-waiver] Our failure to enforce any right or provision of these Terms shall not constitute a waiver of such right or provision. #### Notices [#notices] All legal notices to us must be sent to [legal@thecompany.company](mailto:legal@thecompany.company) or by mail to: The Company Company Inc. 1885 Mission St San Francisco, CA 94103 ### Changes to Terms [#changes-to-terms] We reserve the right to modify these Terms at any time. We will provide notice of material changes by posting updated Terms on the Website with a revised "Last Updated" date. Where practicable, we may also send notice of material changes to the email address associated with your Account. Your continued use of the Website after the effective date of any modifications constitutes acceptance of the updated Terms. If you do not agree to the modified Terms, you must stop using the Website. Material changes may include changes to our data practices, our dispute resolution procedures, or the scope of the license granted to you. We will provide at least 30 days' notice for material changes via email and prominent Website posting. Continued use constitutes acceptance. ### Contact Us [#contact-us] If you have any questions about these Terms, please contact us at: * Email: [legal@thecompany.company](mailto:legal@thecompany.company) * Address: 1885 Mission St, San Francisco, CA 94103 ---