Last updated 17 September 2026
Terms of service
Plain terms for a tool that writes code. Using Rivet means accepting these. If something here does not work for you, say so before you install it , [email protected].
Who you are agreeing with
The service is operated by [LEGAL ENTITY NAME] (“we”), at [REGISTERED ADDRESS]. These terms are governed by the law of [GOVERNING LAW / JURISDICTION]. Those brackets are gaps the operator has to fill; nothing has been invented to fill them.
What the service does
Rivet reads repositories you have given it access to, checks their dependencies against public advisory databases, and, when you ask it to, or when you have put a repository in watch mode, upgrades packages in a sandboxed copy, edits code the upgrade breaks, runs your tests, and opens a draft pull request.
- It never merges anything. There is no code path that merges.
- It never pushes to your default branch. Work lands on its own branch.
- It acts on a repository only when asked, or when that repository is in watch mode.
- If it cannot produce a green result, it opens no pull request and says why.
Your responsibilities
- You must have the right to grant access to the repositories you connect, and to let their contents be processed as described in the privacy notice.
- You review every diff. A passing test suite is evidence, not a guarantee. Rivet opens drafts precisely so a person decides.
- Keep your account secure, and do not use the service to attack anyone, to process repositories you have no right to, or to evade the limits on it.
What we do not promise
The service is provided as is. We do not warrant that it will find every vulnerability, that an upgrade it produces is correct, that it will be available continuously, or that a result will be reproducible. A report that finds nothing is not a certificate that a repository is safe, Rivet says so on the report itself, and it is true here too.
To the fullest extent the law allows, we are not liable for indirect or consequential loss, lost profits, or lost data arising from your use of the service. Where liability cannot be excluded, it is limited to [LIABILITY CAP, e.g. fees paid in the previous 12 months].
Cost and limits
Runs cost real money to execute, so they are bounded: a limited number of attempts per run, caps on how much a run may spend, and a cap on how many repositories one batch may start. Current pricing is on the pricing page. [CONFIRM BILLING, REFUND AND PLAN-CHANGE TERMS BEFORE CHARGING ANYONE]
Ending it
Uninstall the GitHub App at any time and everything stops immediately. We may suspend an account that is abusing the service or costing far more than its plan allows, and will say why. Pull requests already opened are yours: they stay in your repository until you close or merge them.
Changes
These terms may change as the product does. The date at the top is the version in force. Continuing to use the service after a change means accepting it.