GENREG
Terms of use
Last updated 23 August 2026.
This is written in plain language by the people who run the lab, not
by a lawyer. It says honestly how the service behaves and what we will
and will not do. If you need something that holds up in a particular
jurisdiction, have a solicitor look at it.
1. What this is
GENREG (genreg.tech) is a small, invitation-only collaborative lab.
Accounts are created from an invitation and there is no public sign-up. We
may decline or withdraw an invitation without giving a reason.
2. Your account
- You are responsible for what happens under your account.
- Two-factor authentication is required. If you choose to trust a
browser, that browser can sign in with your password alone until the
trust expires or you revoke it — do not do that on a machine other
people use.
- Keep your recovery codes somewhere safe. If you lose both your
authenticator and your codes, an operator can reset your account, and
that reset invalidates every session and trusted browser you had.
- Do not share an account. Ask for an invitation for the other person
instead.
3. Your AI tools and your keys
You bring your own AI. Claude, Codex and Gemini are installed in your
container and you sign in to them yourself with your own subscription or
API key.
- We do not read, log, monitor, store or use anything inside your
container — not your code, not your files, not your prompts, not
your conversations with an AI, not your credentials. The lab records only
that a session was opened, when, and which tool it was, so a project page
can say who is working.
- We cannot promise the impossible, so we will not. The person who
runs this server has root on it, and root can technically read any file on
the machine, including your container. We do not do this, and nothing in
the software does it for us. Treat that as the honest boundary: do not
store anything you would not be willing to entrust to the operator.
- Your use of Anthropic, OpenAI, Google or any other provider is governed
by their terms, and their charges are yours. We never spend on your
key, and we hold no key of our own to fall back on.
- Anything an AI produces here is subject to that provider's terms. We
make no claim about whether AI output is accurate, original, or fit for
any purpose.
4. What we do hold
So that the above is not misread as "we hold nothing", here is what the
service actually stores:
- Your email address, display name, and a hash of your password.
- Your two-factor secret and hashed recovery codes.
- An audit log of authentication events — sign-ins, failures,
invitations, role changes — with timestamps and IP addresses.
- Project registries, page modules, run records, chat messages, and any
files you place in a project directory.
- If you add a provider API key through the web interface, it is encrypted
at rest and never shown back to you beyond its last four characters.
Screen-share frames are held in memory-backed temporary storage for the
moment they are on screen and are not recorded.
5. Your content
- You keep ownership of what you upload or create. We claim no
rights over your work beyond storing and displaying it so the service can
function.
- You are responsible for what you upload. We do not review it in
advance and we are not responsible for it.
- You must have the right to upload it. Do not put anything here that
infringes someone else's copyright, breaches a confidence, or contains
personal data you are not entitled to hold.
- We will remove anything that breaks these terms when we become
aware of it, and we may suspend or close the account responsible. Tell us
if you find something that should not be here.
- Any member of a project can read that project. Every signed-in member
of the lab can see that a project exists, its name and description, and
whether it is active. Do not put anything in a project name you would not
show the whole lab.
6. Acceptable use
Do not use the lab to:
- break the law, or help anyone else do so;
- attack, scan, or disrupt other systems, or mine cryptocurrency;
- attempt to reach another member's container, workspace, files or
account, or to escape your own sandbox;
- host malware, phishing pages, or content designed to deceive;
- store material that is illegal, or that targets or harasses a person;
- resell access, or run someone else's production service on it.
Your container has network access so that installing packages and reading
documentation work. Using it to attack anything else ends your account.
7. What we do not promise
- The service is provided as is. There is no uptime guarantee, no
support commitment, and no warranty of any kind.
- Keep your own backups. This runs on a single small server. Data
can be lost to hardware failure, a mistake, or a bug. An idle container is
stopped after a day and its temporary state goes with it; your files and
your tool sign-ins survive that, but do not treat this as the only copy of
anything you care about.
- We may change, suspend or discontinue any part of the lab. We will give
notice where we reasonably can.
- To the fullest extent the law allows, we are not liable for lost work,
lost data, lost profit, or any indirect loss arising from your use of the
service.
8. Ending it
You can stop using the lab at any time and ask for your account and content
to be deleted. We may suspend or close an account that breaks these terms,
and will say why unless there is a good reason not to.
9. Changes
We may update these terms. The date at the top changes when we do, and
material changes will be announced in the lab. Continuing to use the service
after that means you accept the revised terms.
10. Contact
Raise it with the operator of this lab — the person who invited you
— or through the contact address they gave you.