Terms of Service
Last updated: 7 August 2026
This is a working draft. It has been written by the people building Cairnbase and has not yet been reviewed by a solicitor. It is published so that operators considering early access can read our position before they ask for it. A reviewed version will replace it before anyone pays us anything. The company now exists, so the entity details below are real; the operational values in sections 15 and 17 are our chosen positions and are marked provisional until a solicitor has been through them.
1. Who this agreement is between
Cairnbase is built by Cairnbase, Inc., a Delaware corporation (incorporated 3 August 2026, file number 10720934), whose registered office is at 251 Little Falls Drive, Wilmington, New Castle County, Delaware 19808, registered agent Corporation Service Company. In these terms "we" and "us" mean Cairnbase, Inc. "You" means the person or the company using the website or taking part in early access.
An earlier version of this page said plainly that no incorporated entity existed yet. It does now, and these terms are issued in its name.
2. What this document covers
Three things, and it is worth being clear which is which:
- The website at cairnbase.ai. It has no accounts and no cookies, and the only measurement on it is anonymous page counting that cannot identify you. There is one form on it, the early-access form on the home page, and writing to us is the only other way to make contact. What that form collects and how long it is kept is set out in the privacy policy. These terms govern your use of the site today.
- Early access. Cairnbase is at v0.5 and runs locally on a single machine. There is no hosted service, there are no customer accounts and there are no paying customers. Early access means working with us directly — sending us documents, looking at what comes back, telling us what is wrong. Sections 5 to 14 govern that relationship where it applies.
- The hosted service, when it exists. The rest of this document sets out the terms we intend to run it on, so that an operator can judge them now rather than after they have handed over twenty years of site guides. Anything written in the future tense is a statement of intent, not a description of a system that is already running.
3. What Cairnbase is
Cairnbase is a record of what your company knows: landing sites, anchorages, routes, visits, hazards, species notes and the documents those things came from. It is a filing system with a map on it. It is not a chart, not a planning authority, and not a substitute for anybody's judgement. Section 6 says more about that, and it is the most important section in this document.
4. Your content is yours
Everything you upload or create in Cairnbase — documents, reports, site guides, tracks, photographs, notes, the catalogue built from them — remains yours. We do not acquire ownership of it by hosting it, by parsing it, or by structuring it. Nothing in these terms transfers any intellectual property in your content to us, and no amount of processing on our side changes who owns the underlying record.
It is stated first because everything below has to be read in its light.
5. The licence you give us, its limits, and our duty of confidence
To run the service for you we need permission to handle your content. You grant us a non-exclusive licence, for as long as your content is in the service, to do only these things:
- Store it, back it up and transmit it between the systems that make up the service.
- Send it to the subprocessors listed on our data-handling page for parsing and structuring.
- Index it, structure it and display it to the people you have authorised in your own workspace.
- Produce exports for you on request.
That is the whole licence. We do not sell your content. We do not license it to other customers. We do not use it to train AI models, and we do not permit our subprocessors to do so — see section 11. We do not put your content in front of another company's workspace. If we ever want to do something with your content that is not on the list above — for example, contributing anonymised site information to a shared industry layer — we will ask you first, in writing, and a "no" costs you nothing.
The licence ends when the content is deleted. Ordinary technical exceptions apply: a backup that has not yet rotated out, or a copy retained by a subprocessor for the period described on the data-handling page.
Confidentiality, running from us to you. Owning a document is not the same as nobody reading it. The licence above limits what we may do with your files; this limits what we may do with what is in them. We treat your content, and anything we learn from it, as confidential. In practice:
- A person here opens your documents to run the service, to fix a fault, or to answer something you have asked us about. Not to browse.
- We will not use what we learn from your material for our own benefit or anyone else's. Cairnbase is built by people who also work in the field, and that cuts close to the bone, so we will say it in the specific: if one of us reads your anchorage notes or your bear history in here, that does not turn up in another operator's briefing, in another operator's site guide, or in our own expedition work. This is an obligation on the knowledge, not only on the file.
- Anyone working for us, employed or contracted, is bound by the same duty before they are given access, and we stay answerable for them.
- The duty survives the end of the agreement, and it does not stop when your content is deleted.
Three limits, so it is not read wider than it is. It does not cover information that is already public, that we held before you sent it to us, or that we work out independently without using your material. It does not cover the subprocessors in section 11: Anthropic's systems read document content, and that is the trade the import feature makes. And it does not stop us doing what sections 10 and 13 already say we will do — telling an uploading account that a takedown claim has been made about their upload, and giving both sides a copy of a contested record and its history.
6. Safety, and who is in command
Cairnbase is a knowledge record. It is not a navigational, safety or regulatory-compliance authority, and it must never be the sole basis for a safety-critical decision.
Cairnbase holds hazard information: where a bear has come through camp before, which anchorage holds in a southerly, where the crevasse field starts, which landing only works on a falling tide. That information is contributed by people, recorded on a date, and describes conditions as they were then. Ice moves. Bears move. Wrack lines move. Regulations change between seasons.
The master retains command of the vessel and the expedition leader retains responsibility for the operation ashore and afloat. Nothing in Cairnbase displaces either. Charts, notices to mariners, permits, national and site-specific regulations, operator procedures, and the judgement of the people on scene all take precedence over anything shown in Cairnbase, without exception and without our needing to be consulted.
A record in Cairnbase may also be wrong. Documents are parsed by an AI system that can misread a table, mistake one site for another, or attach a hazard to the wrong beach. That is exactly why nothing reaches your catalogue without a person reviewing and confirming it (section 12), and why every record carries who contributed it and when. Treat the catalogue the way you would treat a well-kept logbook written by colleagues: valuable, and still to be checked against what is in front of you.
And it runs the other way. We do not check your documentation, and we will not tell you it is wrong. Cairnbase reads what you uploaded and shows it back to you: what it says, who wrote it, when it was last reviewed. It does not assess whether a figure in your guide is correct, whether a procedure satisfies a permit condition, or whether your documents describe what your operation actually does. We hold no reference standard to measure your material against, and we do not compare it to published regulations or to industry guidelines. Where two of your own documents disagree, we will show you both, with their dates and their sources, and leave the decision where it belongs. Keeping your documentation aligned with your permits, your regulator and what happens on the beach is yours, and it stays yours.
7. Early access, and that it may change or end
Early access is experimental. Features will appear, change shape and be removed. Data models will change. We may need to reimport or reprocess your material. We may pause early access, change who is in it, or end it altogether, at any time and without cause. If we end it, we will tell you and give you your content back in an exportable form before anything is deleted, per section 15.
Early access is provided free of charge unless we have agreed otherwise with you in writing. Nothing in early access is a commitment to launch a product, to launch it at a particular price, or to launch it at all.
8. Accounts, and who may use them
When accounts exist, each account will belong to one named person. Accounts are not to be shared, and passwords are not to be passed around the guide team at the start of a season. A workspace administrator decides who has an account in that workspace and what they can do with it.
You are responsible for what happens under an account you control, including what the people you invite upload. Tell us promptly at hello@cairnbase.ai if you think an account has been compromised.
You must be old enough to enter a contract in your jurisdiction, and if you are accepting these terms for a company you must have authority to do so.
9. The three tiers, and who decides
Content in Cairnbase sits in one of three tiers:
- Personal. A guide's own field records. They belong to that guide.
- Company. Everything contributed to an operator's workspace. It belongs to that operator.
- Industry. A shared layer that does not exist yet. When it does, nothing will move into it without the consent of whoever owns the record.
The tier of a record is decided by the account that uploads it. It is never decided by branding found inside the document.
Guides routinely hold guidelines from operators they work with now, worked with last season, or wrote parts of themselves. Seeing another company's name on a page does not assign that page to that company, and our software will not treat it as if it did. If a guide uploads a document to their personal tier, it is personal. If a company account uploads it to the workspace, it is company-tier. The uploading account carries the responsibility for that choice, which is why section 10 exists.
10. Material you did not write
By uploading anything to Cairnbase you confirm that you have the right to upload it and to have it stored, parsed and shown to the people in that workspace. Most of what an expedition professional holds was written by somebody, and some of it was written by somebody else, so this one is worth reading twice.
If a third party brings a claim against us because of material you uploaded, you agree to cover our reasonable costs and any damages arising from that claim, provided we tell you about it promptly, let you take the lead in dealing with it if you want to, and do not settle it without asking you.
If you believe material of yours has been uploaded to Cairnbase by somebody who had no right to upload it, write to hello@cairnbase.ai with enough detail to identify the material and say what your interest in it is. We will acknowledge it, look at it, and where the claim holds up we will remove the material or restrict access to it while it is sorted out. We will tell the account that uploaded it what has happened and why. We are not a court and we will not pretend to adjudicate a dispute between two operators, but we will not sit on a well-founded complaint either.
11. AI processing, and who else touches your documents
Documents you upload are sent to Anthropic PBC for parsing. Anthropic is a subprocessor of ours, their systems read your document content, and there is no way to use the document import feature without that happening.
Two things to know before you upload anything sensitive. Both are true as at the date above.
- Parsing does not happen in the EU. Anthropic's API offers inference in the United States or on its global infrastructure. There is no EU option, and storage on Anthropic's side is in the United States. We do not promise EU-only processing of document content, because we cannot deliver it.
- Batched documents are retained by Anthropic for 29 days. A document is parsed by one of two paths, and the person uploading chooses which one at the point of upload. The batch path uses Anthropic's Batch API, which is not eligible for zero data retention and holds the request for 29 days; we recommend it at three or more documents because it costs less, but any upload of any size can be sent that way, including a single document. The other path uses the Messages API, which is eligible, but that arrangement is granted per organisation on request and we have not requested or obtained it. We intend to pursue it. Until the data-handling page says otherwise, assume it is not in place.
Anthropic commits that data retained through the API is not used to train their models without express permission. We have given no such permission and will not. Content that Anthropic's automated trust and safety systems flag may be retained by them for up to two years regardless of anything above, and that is not something we can contract away.
We have not yet executed a data-processing agreement with Anthropic. That is on our list, not a thing already done.
Our other subprocessors are Cloudflare (website hosting, DNS and email routing) and Google (the mailbox that receives hello@cairnbase.ai). There is no hosting provider for customer data yet, because there is no hosted service yet.
The data-handling page is the authority on all of this. It carries the current subprocessor list, the retention detail, where data sits, and what is and is not in place on security. Check it rather than this section, because it changes more often. Our privacy policy covers personal data reaching us through the website.
12. Nothing is written to your catalogue without a person confirming it
When a document is parsed, the result is held for review. A person in your workspace sees what the parser extracted — which sites it matched, which visits it found, which hazards it read — and confirms, corrects or discards it before anything is written to the catalogue. Unconfirmed extractions are not part of your record and are not shown as if they were.
We will not remove that step to make imports faster.
13. Guides, companies, and what happens when somebody moves
Guides and companies are different parties with different interests. This is what happens to a record when somebody changes employer.
- A guide's personal records stay with the guide. Working for an operator does not transfer a guide's own field records to that operator, and a guide who moves employer keeps them, including the ability to export them.
- The company catalogue stays with the company. Anything contributed to a company workspace belongs to the operator. A guide leaving cannot take the workspace catalogue with them, cannot export it, and loses access to it when their account is removed.
- Content promoted from personal to company stays promoted. If a guide chooses to contribute a personal record into the company tier, that copy belongs to the operator from then on and remains there after the guide leaves. The guide keeps their own underlying record, and their authorship stays attached to the company copy. Attribution is not stripped when somebody leaves.
- Disputes. If a guide and an operator disagree about which tier a record belongs in, we will keep the record intact and unchanged, provide both parties with a copy of the record and its history, and leave the substance to them. We will not delete contested material to make the argument go away.
14. Acceptable use
Do not use Cairnbase to:
- Upload material you have no right to upload, or content that is unlawful, defamatory or harassing.
- Upload a file whose subject is a person: a guest or passenger manifest, a medical or insurance form, a crew personnel or disciplinary file. Cairnbase is for operational knowledge about places, and files about people do not belong in it.
- Get at another workspace's content, or attempt to.
- Resell access, scrape the service in bulk, or use it to assemble a competing catalogue.
- Interfere with the service, its security, or anyone else's use of it.
People inside operational documents, which is a different thing. A post-voyage report is an operational document and it will still have people in it. Staff names appear as a matter of course — who led the landing, who saw the bear — and that is expected. Across twenty years of reports, some incident entries will also describe a guest: a slip on wet rock at the top of a beach, a laceration in the Zodiac, something the doctor dealt with on board. We are not asking you to hold those reports back, and we are not going to write a rule you would breach on your first archive import.
What we ask instead is that you keep it to what the record needs. Redact a guest's name and any clinical detail where you reasonably can before you upload — the useful part is that a guest went over on the greasy rock at the north end at low water, and that rarely needs the name attached. Health information about an identifiable person attracts extra protection under European data protection law, and neither of us wants it sitting here without a reason. If it arrives inside a document anyway, it is handled like everything else you upload: parsed, reviewed by your own staff, held in your workspace, and deleted when you say so. Section 11 is why the redaction is worth the two minutes rather than being a formality — the document goes to Anthropic to be read, and on the batch path a copy sits there for 29 days.
If something here is being used in a way that puts the service or other customers at risk, we may suspend access while we work out what has happened. We will tell you why, and we will restore access as soon as it is reasonable to.
15. Export, and leaving without a fight
Full export any time, and no lock-in. Those are commitments we make on the home page, and this is what they mean:
- You can export your workspace content at any time during the term, in open, documented formats — tracks as GPX, the structured catalogue as machine-readable data files, and the original documents you uploaded, as you uploaded them.
- Export is not a paid extra, is not gated behind a plan, and is not something you have to ask permission for. Nothing is withheld to make leaving harder.
- During early access, where the export tooling is not yet built, "export" means we hand you your files and the underlying data on request, and we do it within a reasonable time.
- On termination, your content stays available for export for 90 days. After that we delete it from live systems within 30 days, and from backups as those backups rotate. Ask for deletion sooner and we will do it and confirm when it is done. (Both periods are our chosen positions, provisional until reviewed; see section 21.)
- Anything already sitting with a subprocessor ages out on that subprocessor's clock, not ours. Section 11 and the data-handling page say how long that is.
- Personal-tier content and company-tier content export separately, to the party each belongs to under section 13.
Either side can end the relationship by telling the other. You do not need a reason.
16. What we do not promise
Plainly, because an early-stage product that promises everything is telling you something about itself:
- No uptime commitment. There is no service level agreement, no availability figure, and no maintenance window guarantee.
- No support response time. We answer email as fast as we can. Some of the time we are at sea.
- No security certifications. We hold no SOC 2 report, no ISO 27001 certificate, and no other third-party security or privacy certification. We are not going to imply otherwise with a badge.
- No contractual data location, yet. We intend to keep the hosted service's own storage — your workspace database and your uploaded files — in the EU. That is an intention, not a term of this agreement, because there is no hosted service and no infrastructure to point at. When there is, we will name the region on the data-handling page and it will become a commitment here. Where you see us say we intend to host in the EU, read it as being about storage. It has never covered parsing, and section 11 explains why it cannot.
- No warranty on content. The service is provided as it is. We do not warrant that it will be uninterrupted, error-free, or that any record in it is accurate, current or fit for any particular voyage.
To the extent the law allows, we exclude implied warranties. Where the law does not allow that, the law wins.
17. Limitation of liability
Neither of us is liable to the other for indirect or consequential loss, lost profits, lost bookings, or loss of business opportunity.
Our total liability arising out of or in connection with these terms is limited to the fees you have paid us in the twelve months before the event giving rise to the claim. During early access, where nothing is being paid, that cap is one hundred US dollars. (Both caps are our chosen positions, provisional until reviewed; see section 21.)
Nothing in these terms limits or excludes any liability that cannot lawfully be limited or excluded, including liability for death or personal injury caused by negligence, and for fraud.
Section 6 is the practical point here. Cairnbase is a record of what people wrote down. Decisions about where to land, where to anchor and where to walk remain with the people qualified to make them.
18. Changes to these terms
We will change this document as the product changes, and we expect to change it substantially when the entity is formed and a solicitor has been through it. The date at the top always shows the current version. Where a change materially affects your rights and we have a way to reach you, we will email you before it takes effect. If a change does not suit you, you can export and leave under section 15.
19. Governing law
These terms are governed by the law of the State of Delaware, United States, and the courts of the State of Delaware have exclusive jurisdiction over any dispute arising from them. Delaware is where the company is incorporated, which is why it is the natural home for both; if the solicitor review lands somewhere different, this section and the date at the top will change.
20. Contact
hello@cairnbase.ai. That address reaches a person, not a queue. Takedown requests under section 10, export requests under section 15, and questions about anything above all go to the same place.
21. What was filled in, and what remains provisional
An earlier version of this page carried seven square-bracket placeholders and listed them here so it could be handed to a solicitor. The company now exists, so they are filled, but honesty requires saying which kind of answer each one got:
- Settled by the incorporation — the entity name (Cairnbase, Inc.), the registered address, and the governing law and courts (Delaware, section 19). These are facts from the certificate, not choices.
- Our chosen positions, provisional until a solicitor has reviewed them — the 90-day export window and 30-day deletion period (section 15), and both liability caps (section 17). We picked positions we believe are fair and common rather than leave brackets on a live page, and the solicitor review may move them. If it does, the date at the top changes and section 18 applies.
These are missing too, and were left out rather than invented:
- Fees, invoicing, renewal and price changes. There is nothing to charge for yet, so there is nothing honest to write.
- The usual contract machinery — force majeure, assignment, notices, severability, entire agreement, no waiver, insurance. Left out to keep this readable, not because anyone decided against them.
- A data-processing agreement, the transfer safeguard for the parsing step, and how data-subject requests are handled. Those are a separate document. Section 11 and the data-handling page describe the position in the meantime.
- Anything jurisdiction-specific, including consumer rights. That cannot be written until section 19 has an answer.
Five positions in here are ours rather than a lawyer's, and can be changed by deciding to: the duty of confidence and its three carve-outs under section 5; asking for redaction rather than banning personal detail outright under section 14, which is a deliberate choice because a flat ban would be broken on the first archive import; suspension under section 14; emailing before a material change under section 18; and how a guide-versus-operator dispute is handled under section 13.