---
title: "Terms of use"
description: "What is allowed through the API, how the data processing agreement applies and when Bodo suspends a key. The consent dialog for “API on” in Bodo links here."
lang: en
url: https://developers.bodo-app.com/en/terms/
apiVersion: 2026-11-01
---

# Terms of use

What is allowed through the API, how the data processing agreement applies and when Bodo suspends a key. The consent dialog for “API on” in Bodo links here.

> **Draft for the preview** This version applies to the preview. Bodo releases the binding wording before the API becomes stable; we announce any change in the changelog.

## Acceptable use

- Access only within the rights of the principal and the scope.
- Do not pass keys on, do not put them in code or repositories.
- Production integrations through service accounts, not through personal keys.
- Apps of other vendors only through OAuth with the user’s consent, never with a handed-over key.
- Do not work around limits, for example with many keys for one purpose.

## Data protection and DPA

- The organization stays the controller, Bodo processes on its behalf. The existing data processing agreement covers the API too.
- The request log holds no bodies and no record ids. The full IP stays 7 days, after that only the network.
- Raw log 90 days, aggregates 13 months. The organization can shorten both.

## When Bodo suspends

| Occasion | Consequence |
| --- | --- |
| Key found in public (report to `POST /v1/secret-scanning/report`) | revoked at once, email, bell, record history |
| Firing on after a 429 | locked for 5 minutes |
| Delete budget reached | deleting paused |
| Personal key unused for 90 days | paused, email and bell 7 days before, re-enable with one click |
| Service account key unused beyond its account’s threshold (90 to 400 days, default 400) | paused, email and bell 7 days before, re-enable with one click |
| Webhook endpoint answers no 2xx for 3 days | endpoint disabled, email to the owner |
| Organization switches the API off | all keys, webhooks and app tokens off |
| Operator pulls the emergency stop | every call [503 API_PAUSED](/en/problems/API_PAUSED/) |
