Skip to policy
AttackDeskBack to AttackDesk ↗

POLICIES & INFORMATION

Terms of service

The agreement for using AttackDesk accounts, managed services, and related services.

Draft prepared September 25, 2026 · Version 2026-09-25.7

Policy preview · Prepared for launch review. These drafts have not been published as live service terms.

On this page

  1. Who these terms cover
  2. Accounts, teams, and access
  3. Software, customization, and client work
  4. Customer content and processing
  5. Agents, AI models, and automated actions
  6. Calls, texts, email, and recording
  7. Acceptable use
  8. Connected services and editable deployments
  9. Managed services, support, and backups
  10. Billing, cancellation, and service restrictions
  11. Changes and discontinuation
  12. Warranties and responsibility
  13. Limits on liability
  14. Claims arising from your use
  15. Governing law and court venue
  16. Class-action waiver and 30-day opt-out
  17. General terms

1. Who these terms cover

AttackDesk is operated by FlashCat LLC, a Wyoming limited liability company (“AttackDesk,” “we,” “us”). These terms apply to our websites, account hub, APIs, managed services, and work we agree to provide. “You” means the person accepting and, when acting with authority for a business, that business. You must be at least 18 and legally able to enter this agreement.

An order or signed agreement controls its specific scope and price; a signed data processing agreement controls its subject matter; the purchase policy controls billing; these terms apply otherwise. The downloadable software has a separate license included with its release; that license governs software permissions, restrictions, termination, and reinstatement. These service terms do not expand those rights. A demo, roadmap, sales illustration, or future feature is not a service commitment.

These terms include a class-action waiver and a 30-day right to opt out in section 16. Please read that section before accepting these terms.

2. Accounts, teams, and access

Give accurate account and business information and keep it current. Protect your sign-in methods, API keys, devices, and integrations. Use individual team accounts, appropriate permissions, and prompt removal of access when someone leaves. Tell us promptly about suspected misuse. You are responsible for activity you authorize through your people, agents, and credentials, subject to applicable law and our own responsibilities.

Organization owners and authorized administrators can manage team access, connected copies, services, and business data. Use a work account with the understanding that the organization may control that workspace. Account access does not transfer ownership of another business or its information.

Each business must create and own its own AttackDesk account. A client signs up itself and may then invite a developer or agency to its team, with access the client can revoke. An agency may join multiple client teams but may not hold unrelated client businesses under its own organization account. A person may maintain accounts for multiple businesses they own.

3. Software, customization, and client work

You keep your rights in your business data and your original custom code. We keep our rights in AttackDesk and its branding. Downloading or paying for services grants only the rights in the applicable license or agreement; it does not transfer ownership of our software or make all of it open source.

The release license permits free download, use, and customization for your own business. You may change the visible name, logo, colors, and interface of your installation, including through an authorized developer, without a white-label contract. Keep required legal notices. This does not grant rights to use our trademarks to market another product or imply our endorsement.

A client may authorize a developer, consultant, or agency to set up, customize, deploy, manage, and support its own installation, including on infrastructure the client owns or controls. The provider may charge for that work, whether the client uses the free software or paid managed services. No affiliate or partner agreement is required for this authorized client work. Code may be shared with the provider and returned or deployed for that client under the client’s license and authorization.

Unless a separate written agreement with FlashCat LLC expressly permits it, you may not sell, sublicense, rent, or redistribute AttackDesk or modified copies outside the permitted client-work arrangement, or repackage it as a software platform offered to other businesses, including a hosted or white-label offering. This restriction does not prohibit authorized work on a client’s own installation or changing that installation’s branding. Direct other businesses to our official signup and download.

Anyone may recommend AttackDesk. Earning referral commissions requires acceptance of the affiliate terms and compliance with their attribution, eligibility, and payment conditions. A free signup earns no commission; a later eligible paid subscription may qualify under those terms. Affiliate enrollment does not itself grant resale or redistribution rights.

Keep the applicable software license and copyright notices with copies, including those shared for authorized client work, and identify changed files as changed. Do not remove or bypass license keys, account checks, protected or sealed components, or required notices. The release license governs the consequences of a license breach and any opportunity to cure it; restrictions on access to our managed services are also governed by these terms.

Third-party components retain their own licenses, identified in the notices supplied with the software. These terms and our license restrictions do not take away rights granted directly under those third-party licenses. Preserve applicable notices.

4. Customer content and processing

You are responsible for having the rights and lawful basis needed to collect, import, store, use, publish, and share the information you put into AttackDesk. That includes leads, uploaded files, website content, recordings, prompts, and personal information. Give the notices and obtain the permissions your use requires.

You grant us and the providers used to deliver your requested services a limited right to host, transmit, process, and reproduce that content to operate the services, respond to support requests, secure accounts, meet legal obligations, and enforce this agreement. This is not a transfer of ownership or a license to sell your private customer lists.

The privacy policy explains our handling of account and service data. When we process personal information on your business’s behalf, you determine its business purpose. If applicable law requires a data processing agreement or international transfer terms, those must be put in place before the affected processing begins. This general agreement is not a substitute for an executed DPA.

5. Agents, AI models, and automated actions

AI can produce incorrect, incomplete, biased, insecure, or non-unique outputs. It can also act on misleading instructions in websites, files, or messages. Review important outputs and code before using or publishing them. AI output is not legal, financial, medical, or other professional advice, and we do not guarantee accuracy, rights clearance, business results, rankings, leads, or revenue.

You choose which agents and tools to enable, the data and credentials they can access, and the actions they may take. An authorized agent may send messages, spend credits, publish content, change records, or modify code. Use limited permissions, budgets, approval steps, and independent backups appropriate to the task. We do not promise to catch every unintended action.

Hosted model use sends the data needed for the request to the selected provider. Model availability, context limits, retention, permitted uses, and output rights vary. Your own coding-agent subscription or provider account is a separate agreement and does not include AttackDesk usage. Local operation does not make separately connected services offline.

6. Calls, texts, email, and recording

Use communications services only for lawful, permitted traffic. You are responsible for recipient consent and evidence of it, sender identification, opt-outs, suppression lists, do-not-call requirements, permitted contact times, email disclosures, and restrictions on automated or AI-generated calls. A purchased or scraped lead is not permission to contact that person. Carrier registration or approval does not establish consent.

Obtain all notices and permissions required for recording, transcribing, analyzing, or sharing a call, including every participant’s consent where required. Do not impersonate another sender or use deceptive caller identification. Honor withdrawal of consent and provider rules, including the policies applicable to Twilio-backed services.

Numbers, registrations, delivery, and portability depend on providers, carriers, location, and eligibility. We do not guarantee approval, delivery, inbox placement, uninterrupted calling, or continued availability of a number. AttackDesk is not a replacement for an emergency telephone service; do not rely on it to reach emergency services.

7. Acceptable use

Do not use the services for unlawful activity, fraud, spam, harassment, exploitation, malware, unauthorized access, deceptive impersonation, or infringement. Do not bypass access restrictions, spending controls, service limits, license checks, or security protections. Do not resell our credentials or let unauthorized parties use our provider accounts.

Research, enrichment, scraping, advertising, and content publishing must respect applicable law, intellectual property, access permissions, platform terms, and privacy rights. Having a tool capable of an action does not establish permission to perform it. Do not use agents to evade these restrictions.

AttackDesk is not HIPAA compliant out of the box. Do not create, upload, store, or transmit protected health information (PHI) through our services unless you have separately requested HIPAA support, we have agreed to the use in writing and signed a Business Associate Agreement (BAA) with you, and we have confirmed that the specific services, configuration, and required safeguards are in place. An inquiry, add-on request, plan purchase, or BAA alone does not activate or establish a compliant configuration. We may decline a request or exclude features and providers from the approved scope.

Do not submit payment-card security codes, government secrets, or similarly restricted data unless we have expressly agreed in writing to support that data and the required safeguards. You must also comply with applicable law and the rules of connected providers.

8. Connected services and editable deployments

You can use your own compatible providers subject to their separate fees and terms. You authorize us to communicate with providers when you connect a service or request managed setup. Their outages, changes, approvals, quotas, and account restrictions can affect the features available to you.

Managed services are optional. For an installation on your infrastructure using your own providers, you may manage your own CRM users and sign-in methods; those users do not need individual AttackDesk accounts or incur managed-service seat fees merely for using that installation. Official downloads and account services remain tied to the business’s AttackDesk account. People accessing our account hub or a managed workspace must use their own authorized accounts. Our portal controls managed-service permissions, billing, keys, and seats under the applicable order. Editing the software does not permit bypassing those controls or obtaining services without payment.

For copies you run or modify, you are responsible for deployment, device security, dependencies, access controls, migrations, backups, and testing unless an order expressly assigns a task to us. Customizations may need maintenance and may conflict with updates. Support does not automatically include fixing every customization or restoring every prior version.

An account-connected copy can report installation information and aggregate usage counts as described in the privacy policy. Integrity checks can restrict managed services for incompatible or altered protected components. This does not grant us unrestricted access to your computer.

9. Managed services, support, and backups

Your order identifies the services you purchase. Activation can require your information, DNS changes, provider approval, account verification, payment, and other setup steps. Availability varies by feature and configuration. A payment confirmation does not mean all external services have been provisioned.

Implementation, custom development, reviews, migrations, and ongoing support have the scope, charges, and estimated timing agreed for that work. Unless expressly stated in a signed service agreement, there is no uptime SLA, guaranteed response time, completion deadline, recovery time, or recovery point commitment.

A backup benefit applies only to the resources and retention actually included in your order and enabled for your account. It does not cover unconnected local databases, external services, or every file automatically. Backups can be incomplete or fail; keep appropriate independent exports and recovery plans. We do not guarantee that every deletion, modification, or outage can be reversed.

10. Billing, cancellation, and service restrictions

The purchase policy and checkout describe subscription fees, credits, usage, optional services, and cancellation. You authorize the charges you approve, including disclosed recurring charges. Your own customers’ purchases and invoices are separate: you remain responsible for your offerings, refunds, taxes, and payment-provider obligations.

We may limit or suspend services for nonpayment, insufficient balance, credible security or abuse concerns, legal obligations, provider restrictions, or material breach. We will give notice and an opportunity to address the issue when reasonably appropriate; urgent situations may require immediate action. Restrictions do not eliminate valid accrued charges or non-waivable rights.

Cancel renewal through account Settings or contact us if you cannot access that control. Export what you need before ending a hosted service. Cancellation, account closure, and deletion of data are different actions; the purchase policy and applicable order explain their effects.

11. Changes and discontinuation

We may maintain or change the services. Material changes affecting an existing paid commitment, prices, or these terms will be communicated with the notice and consent required by law. Changes apply prospectively, not to turn previously authorized usage into a new charge. We will explain available cancellation options for a material paid-service change.

Previews and experimental features can change or end and should not be relied on for critical operations. If we permanently end a prepaid service without your breach, contact us about the unused affected service; any refund required by law or your order remains available.

12. Warranties and responsibility

AttackDesk may experience bugs, interruptions, or compatibility issues. We don’t guarantee that the software will operate without errors or meet every business’s particular needs.

To the maximum extent permitted by law, services and software are provided “as is” and “as available.” We disclaim implied warranties of merchantability, fitness for a particular purpose, title, and non-infringement. We do not warrant uninterrupted, error-free, completely secure, or universally compatible operation.

Nothing in these terms excludes a warranty, remedy, duty, or liability that applicable law does not allow to be excluded. General disclaimers do not cancel an express obligation we make in a signed agreement.

13. Limits on liability

To the maximum extent permitted by law, neither FlashCat LLC nor its suppliers or personnel will be liable for indirect, incidental, special, consequential, exemplary, or punitive damages, or lost profits, revenue, goodwill, anticipated savings, or data arising from the services, even if advised of the possibility.

Our total aggregate liability for claims arising out of or relating to the services or this agreement will not exceed the greater of US $100 or the fees you paid us for the service giving rise to the claim during the twelve months before the event giving rise to liability. These limits apply across legal theories to the extent permitted by law.

These exclusions and limits do not apply to fraud, willful misconduct, or any liability that cannot lawfully be limited. A different liability provision expressly agreed in a signed contract controls its subject matter.

14. Claims arising from your use

If you use AttackDesk for a business, that business will defend and indemnify FlashCat LLC against third-party claims and reasonable associated costs arising from its unlawful communications, infringement by its supplied content or customizations, unauthorized processing of personal information, or material violation of these terms.

This obligation does not apply to the extent a claim results from our breach, negligence, or willful misconduct. We will promptly notify you of a claim, reasonably cooperate, and let you control a competent defense. You may not settle a claim by admitting fault for us or imposing non-monetary obligations on us without our written consent.

15. Governing law and court venue

The laws of the State of Arizona, without its conflict-of-law rules, govern these terms and disputes arising out of or relating to these terms or the services, subject to applicable federal law and mandatory protections that cannot lawfully be excluded.

Except where applicable law requires otherwise, the parties agree to the exclusive jurisdiction and venue of the state courts located in Maricopa County, Arizona, or, where federal subject-matter jurisdiction exists, the United States District Court for the District of Arizona, Phoenix Division. Each party consents to personal jurisdiction in those courts. This provision does not remove mandatory consumer protections or a right to bring a claim in another court where that right cannot lawfully be waived.

You may contact support@attackdesk.com to try to resolve a dispute informally. Doing so is not a prerequisite to bringing a claim and does not change a filing deadline. These terms do not require arbitration.

16. Class-action waiver and 30-day opt-out

To the fullest extent permitted by applicable law, you and FlashCat LLC agree to bring claims arising out of or relating to these terms or the services only in an individual capacity. Neither party will bring or participate as a class representative or class member in a class, collective, or representative action against the other. This is a mutual class-action waiver; it does not waive an individual claim or an otherwise available right to a jury trial.

You may opt out of this waiver by sending an email to support@attackdesk.com within 30 calendar days after you first accept a version of these terms containing this waiver. Use the subject “Class-action waiver opt-out” and include your name, the email associated with your account, the organization name if applicable, and a clear statement that you opt out of the class-action waiver. An opt-out on behalf of a business must be sent by someone authorized to act for that business. No postal letter or opt-out fee is required.

If you timely opt out, neither you nor FlashCat LLC is bound by this waiver for claims between us. Opting out does not affect your account, pricing, services, or the remaining terms. A valid opt-out remains effective through later renewals or updates. If we materially change this waiver, you receive a new 30-calendar-day opt-out period beginning on the later of our notice of the change or your acceptance of the changed waiver; a previous valid opt-out remains effective.

This waiver does not restrict complaints to regulators, participation in government investigations, or claims, representative proceedings, or public injunctive relief that applicable law does not allow to be waived. If a court finds any part of this waiver unenforceable for a particular claim or remedy, that part is severed only to the extent necessary and that claim or remedy may proceed as permitted by law; the remaining terms continue to apply.

This waiver applies prospectively to disputes arising from events after you accept it, and does not alter an already-filed proceeding. A court, rather than an arbitrator, decides the waiver’s applicability and enforceability.

17. General terms

Neither party is responsible for delay caused by events reasonably beyond its control, except for payment obligations already incurred. Invalid provisions are limited or severed only as needed, and the remainder continues. Failure to enforce a provision is not a waiver.

You may not transfer this agreement without our consent except as applicable law permits. We may assign it in connection with a merger, reorganization, or sale of the relevant business, subject to privacy obligations. Provisions that by their nature should survive termination do so. These terms, incorporated policies, applicable license, and agreed orders form the agreement for their subject matter.

Questions? support@attackdesk.com

Terms of servicePrivacy policyPurchase policyAccessibility

© 2026 FlashCat LLC · AttackDesk