MSPStuff Terms of Service
Last updated:
These Terms of Service ("Terms") are an agreement between AutomatedMSP, LLC, a Mississippi limited liability company doing business as MSPStuff ("MSPStuff", "we", "us"), and the organization that signs up for or uses the Service ("Customer", "you").
Please read them carefully. By creating an account, accepting an invitation, connecting an AI client to our server, or otherwise using the Service, you agree to these Terms on behalf of your organization. If you do not have authority to bind your organization, do not use the Service.
1. Definitions
1.1 "Service" means Switchboard and the related websites, web app, AI engine, MCP server (at https://www.mspstuff.io/mcp), APIs, sandbox, add-ons and support that we provide.
1.2 "Customer" means the business that holds the MSPStuff organization account. The Service is for businesses, mainly managed service providers (MSPs). It is not for personal, household or consumer use.
1.3 "Member" means a person the Customer invites into its MSPStuff organization, such as an employee or contractor. Members use the Service on the Customer's behalf.
1.4 "Viewer" means a person outside the Customer's organization who is given access to a single shared report or file.
1.5 "Connected System" means a third-party platform the Customer connects to the Service, such as a PSA, RMM, Microsoft 365, Google Workspace, backup, security or billing tool.
1.6 "Customer Data" means data the Service obtains from Connected Systems, and content the Customer and its Members put into the Service, such as questions, chat history, memory notes, saved reports, files, dashboards and schedules.
1.7 "Output" means answers, summaries, reports and other content the Service generates for the Customer.
1.8 "AI Client" means an AI assistant the Customer chooses to connect to the Service, such as Claude, ChatGPT, Microsoft Copilot, Claude Code or Cursor.
2. The Service
2.1 What it does. The Service connects AI assistants to the business systems the Customer already uses, so Members can ask questions about their service desk, devices, clients, billing, security and related data. The Service can be used through the MSPStuff web app or through an AI Client connected to our MCP server.
2.2 Read-only. The Service reads data from Connected Systems. It does not create, change or delete anything in a Connected System. Any action that would change a Connected System is refused by our server. If we ever offer the ability to make changes, it will be off by default, will require the Customer to switch it on, will require explicit approval for each action, and will be covered by an update to these Terms before it is available.
2.3 Integrations. The list of supported Connected Systems is shown on our website and can change. Integrations depend on vendor APIs that we do not control. A vendor may change, limit or withdraw its API, and an integration may stop working or be removed as a result. We will make reasonable efforts to tell you if a supported integration is removed.
2.4 Changes to the Service. We may add, change or remove features. If we remove a feature that is a material part of a paid plan, we will give you reasonable notice, and you may cancel as described in Section 13.
2.5 Beta. The Service is currently offered as a beta by invitation only. Beta features may be incomplete, may change and may contain errors. Section 15 applies with particular force to beta features.
2.6 Sandbox. We may offer a demonstration environment with synthetic data only (for example, "Northgate Managed IT"), including time-limited passes. Do not put real data into the sandbox. We may reset or end sandbox access at any time.
3. Accounts and access
3.1 Eligibility. You must be a business, and each Member must be at least 18 years old.
3.2 Invitations. Signup is by invitation. We may accept or decline any application.
3.3 Account security. The Customer is responsible for its Members, for keeping sign-in details, two-factor devices and API keys (keys beginning "mspk_") secure, and for all activity under its organization. Password users must use two-factor authentication. Each user may have one active session at a time. Tell us promptly at the address in Section 20 if you believe an account or key has been compromised.
3.4 Member permissions. Customer organization admins decide which Connected Systems and data areas each Member can reach. The Service answers a Member's question using only the data that Member is permitted to see. The Customer is responsible for setting these permissions correctly and for removing Members who should no longer have access.
3.5 Viewers. When a Member shares an item with a Viewer, the Viewer signs in with Google or Microsoft and can see and comment on only that item. Viewers must follow Sections 8 and 9 and the parts of these Terms that apply to their use. The Customer is responsible for what its Members choose to share.
4. Your responsibilities for Connected Systems
4.1 Authority. By connecting a system, the Customer confirms that it has the right to connect it and to allow MSPStuff to read the data in it for the purposes in these Terms. This includes systems and tenants belonging to the Customer's own clients (for example, a client's Microsoft 365 or Google Workspace tenant) that the Customer manages. The Customer is responsible for having the agreements, permissions and notices with its own clients that this requires.
4.2 Credentials and permissions. The Customer creates the API keys, app registrations and permissions in its vendors' consoles. We recommend read-only credentials with the narrowest permissions that work. The Customer is responsible for the scope of the credentials it provides and for revoking them when no longer needed. We store connection credentials in a secrets vault and do not show them to the AI.
4.3 Vendor terms. The Customer remains responsible for following the terms of each Connected System vendor.
4.4 Sensitive data. The Service is not designed for, and the Customer must not use it to deliberately collect or store, payment card numbers, government identification numbers, or health information that is regulated under health-privacy laws such as the U.S. Health Insurance Portability and Accountability Act ("Regulated Health Information"). We do not sign business associate agreements. If Connected Systems may contain Regulated Health Information, the Customer is responsible for deciding whether it may connect them and for limiting the data and permissions accordingly.
5. AI processing and Output
5.1 How answers are made. The Service uses large language models to answer questions from Customer Data. The in-app engine runs on our servers using third-party AI model providers listed at https://www.mspstuff.io/subprocessors, which process the questions and the data needed to answer them on our behalf.
5.2 Verify before you act. Output is generated by AI. It can be wrong, incomplete or out of date, including because cached data has not yet refreshed. The Customer must review Output and confirm it against the source system before relying on it or acting on it.
5.3 Not professional advice. Output, health reports, security alerts and the results of any compliance-check tool are information to help you do your work. They are not legal, regulatory, security, compliance, financial or other professional advice, and they are not an audit, attestation or guarantee that any person or system meets any law or standard. Responsibility for those decisions stays with the Customer and its clients.
5.4 Ownership of Output. As between the parties, Output generated from Customer Data belongs to the Customer, subject to Section 7.
6. Third-party AI Clients
6.1 When the Customer connects an AI Client to the Service, the questions Members ask and the data the Service returns go to that AI Client's provider. That provider processes them under the Customer's own agreement with that provider, not under these Terms.
6.2 We are not responsible for AI Clients, how they handle data, or what they do with Output. The Customer chooses which AI Clients to connect and is responsible for reviewing their terms and data settings.
7. Data ownership and license
7.1 Your data is yours. The Customer owns Customer Data and everything the Service learns about its business, such as memory notes and saved work. We claim no ownership of it.
7.2 Our license to use it. The Customer gives us a limited, non-exclusive license to access, copy, store and process Customer Data only as needed to provide, secure, support and maintain the Service for the Customer, to prevent abuse, and as required by law.
7.3 No model training. We do not use Customer Data to train AI models, and our agreements with our AI model providers do not allow them to train their models on Customer Data.
7.4 No selling. We do not sell Customer Data or personal data.
7.5 Export. The Customer may export its data at any time during the subscription, and for 30 days after it ends, by using in-app tools where available or by request to the address in Section 20. We will provide the export in a common machine-readable format within a reasonable time.
7.6 Usage data. We may collect technical and usage information about how the Service is used (for example, feature usage, error reports and performance data) and use it to run and improve the Service. We will only share it outside MSPStuff in aggregated or de-identified form that does not identify the Customer, its clients or any person.
7.7 Our property. We own the Service, including the software, servers, models of our own, designs and documentation. Except for the rights expressly granted in these Terms, no rights are transferred to you. The Service is provided as a hosted service only. We do not provide software for installation on your premises.
7.8 Feedback. If you send us ideas or feedback, we may use them without obligation to you.
8. Acceptable use
The Customer, its Members and Viewers must not:
- (a) use the Service to access any system, tenant or data that they are not authorized to access;
- (b) resell, sublicense or provide access to the Service to anyone other than Members and Viewers, unless we agree in writing;
- (c) attempt to bypass or disable the read-only controls, permission controls, usage limits or any security measure;
- (d) probe, scan or test the Service for vulnerabilities, except as described in Section 18;
- (e) attempt to access another customer's data, or interfere with or disrupt the Service;
- (f) reverse engineer, decompile or copy the Service, except to the extent the law allows despite this restriction;
- (g) use the Service to build a competing product, or use automated means to extract data or Output from the Service other than through the access methods we provide;
- (h) upload malicious code, or use the Service in violation of any law, any Connected System vendor's terms, or any AI model provider's usage policies that we make available to you; or
- (i) share API keys or accounts between people.
10. Plans, fees and billing
10.1 Plans. Plans, prices and included usage are described on https://www.mspstuff.io/pricing or in an order form. If an order form conflicts with these Terms, the order form wins for that order.
10.2 Trial. Eligible new customers receive a 14-day trial covering seats and the database. Unless you cancel before the trial ends, your subscription begins at the end of the trial and you will be charged. A dedicated server add-on is billed from the date it is activated and is not covered by the trial.
10.3 Billing. Subscriptions are billed monthly in advance through our payment processor, Stripe, and renew automatically each month until cancelled. You authorize us to charge your payment method for each renewal, add-on and applicable tax.
10.4 Taxes. Prices do not include taxes. You are responsible for applicable sales, use, value-added and similar taxes, other than taxes on our income.
10.5 Refunds. You may cancel at any time. Cancellation takes effect at the end of the current billing period, and you keep access until then. Fees already paid are non-refundable, and we do not give credits for partial months, except where the law requires otherwise or where we decide to issue one.
10.6 Late payment. If a payment fails, we will notify you. If it is not resolved within 14 days of that notice, we may suspend the Service until it is.
10.7 Price changes. We will give at least 30 days' notice of a price increase. The new price applies from your next billing period after the notice period ends.
11. Usage limits
Plans include limits, such as the number of connections, questions per day, concurrent questions and data refresh rates. The current limits are described on our pricing page or in the app. We may enforce limits technically, for example by queuing or declining requests, and we may change limits with notice.
12. Service availability and support
12.1 During the beta, the Service is provided without a service level agreement or uptime commitment. We will make reasonable efforts to keep it available and to schedule maintenance at low-use times.
12.2 Support is provided by email at the address in Section 20 on a reasonable-efforts basis.
12.3 The dedicated server and dedicated database add-ons provide separate resources as described on our pricing page. They do not include an uptime commitment unless an order form says so.
13. Term, suspension and termination
13.1 Term. These Terms apply from when you first use the Service until your subscription ends and any remaining obligations are complete.
13.2 Cancellation by you. You may cancel at any time in the app or by email. See Section 10.5.
13.3 Suspension. We may suspend access, in whole or for particular Members, keys or connections, if we reasonably believe it is necessary because of non-payment, a breach of Section 8, a security risk to the Service or to others, or a legal requirement. Where practical, we will tell you in advance and restore access once the issue is resolved.
13.4 Termination by us. We may terminate these Terms for material breach that is not cured within 30 days of notice, immediately for serious or repeated breach of Section 8, or for any reason with at least 30 days' notice. If we terminate without cause, we will refund any prepaid fees for the period after termination.
13.5 After termination. Access ends. Connected System credentials are deleted promptly. You may request an export for 30 days as described in Section 7.5. After that 30-day period we delete Customer Data from active systems, and remaining copies in backups and logs are deleted as they expire under our normal cycles, as described in our Privacy Policy. We may keep limited records where required by law, such as billing records.
13.6 Survival. Sections 7, 10 (for amounts owed), 13.5, 14 through 17, and 19 continue after termination.
14. Confidentiality
Each party will protect the other's non-public information that it receives in connection with the Service using reasonable care, and use it only to perform under these Terms. Customer Data is the Customer's confidential information. This does not apply to information that is public through no fault of the receiving party, was already known to it, is independently developed, or is lawfully received from someone else. A party may disclose confidential information if required by law, after giving notice where legally allowed.
15. Disclaimer
EXCEPT AS EXPRESSLY STATED IN THESE TERMS, THE SERVICE, OUTPUT AND ANY BETA OR SANDBOX FEATURES ARE PROVIDED "AS IS" AND "AS AVAILABLE." TO THE FULLEST EXTENT ALLOWED BY LAW, WE DISCLAIM ALL WARRANTIES, WHETHER EXPRESS, IMPLIED OR STATUTORY, INCLUDING WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE AND NON-INFRINGEMENT. WE DO NOT WARRANT THAT THE SERVICE WILL BE UNINTERRUPTED OR ERROR-FREE, THAT OUTPUT WILL BE ACCURATE OR COMPLETE, OR THAT ANY CONNECTED SYSTEM OR AI CLIENT WILL CONTINUE TO WORK WITH THE SERVICE.
16. Limitation of liability
16.1 TO THE FULLEST EXTENT ALLOWED BY LAW, NEITHER PARTY WILL BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL OR PUNITIVE DAMAGES, OR FOR LOST PROFITS, REVENUE, GOODWILL OR DATA, EVEN IF ADVISED OF THEIR POSSIBILITY.
16.2 TO THE FULLEST EXTENT ALLOWED BY LAW, EACH PARTY'S TOTAL LIABILITY ARISING OUT OF OR RELATING TO THESE TERMS WILL NOT EXCEED THE AMOUNTS THE CUSTOMER PAID TO US FOR THE SERVICE IN THE 12 MONTHS BEFORE THE EVENT GIVING RISE TO THE CLAIM, OR US $100 IF GREATER.
16.3 These limits do not apply to the Customer's payment obligations, to either party's obligations under Section 17, or to liability that cannot be limited by law.
17. Indemnity
17.1 By the Customer. The Customer will defend MSPStuff against third-party claims arising from (a) the Customer's connection of, or lack of authority over, any Connected System or data, including claims by the Customer's own clients; (b) the Customer's use of AI Clients; (c) what the Customer or its Members share; or (d) the Customer's breach of Section 8. The Customer will pay resulting damages, costs and reasonable attorneys' fees finally awarded or agreed in settlement.
17.2 By MSPStuff. We will defend the Customer against third-party claims alleging that the Service, as we provide it, infringes that third party's intellectual property rights, and pay resulting damages, costs and reasonable attorneys' fees finally awarded or agreed in settlement. This does not apply to claims arising from Customer Data, Connected Systems, AI Clients, Output, or use of the Service in breach of these Terms.
17.3 Process. The party seeking defense must notify the other promptly, give it control of the defense and settlement (no settlement may impose obligations on the defended party without its consent), and provide reasonable cooperation.
18. Security reporting
If you find a security vulnerability, please report it as described at https://www.mspstuff.io/.well-known/security.txt and on https://www.mspstuff.io/security. Please do not access data that is not yours, degrade the Service or disclose the issue publicly before we have had a reasonable chance to fix it. Good-faith testing within those limits is not a breach of Section 8(d).
19. General
19.1 Third-party names. MSPStuff is not affiliated with, endorsed by or sponsored by any Connected System vendor or AI provider named in the Service or on our website. Their names and marks belong to their owners and are used only to identify compatible products.
19.2 Governing law and venue. These Terms are governed by the laws of the State of Mississippi, without regard to its conflict-of-laws rules. Any dispute will be brought only in the state or federal courts located in DeSoto County, Mississippi, and each party consents to their jurisdiction. Either party may seek urgent injunctive relief in any competent court. The United Nations Convention on Contracts for the International Sale of Goods does not apply.
19.3 Changes to these Terms. We may update these Terms. We will post the new version with a new "Last updated" date and, for material changes, notify the Customer's admins by email or in the app at least 30 days before they take effect, unless the change is required by law or is needed to address a security issue. Continued use after the effective date means acceptance. If you do not agree, you may cancel before the change takes effect.
19.4 Notices. We will send notices to the email address of the Customer's organization admins. You may send notices to us at the address in Section 20.
19.5 Assignment. Neither party may assign these Terms without the other's consent, except to a successor in a merger, acquisition or sale of substantially all of its relevant business or assets, with notice.
19.6 Force majeure. Neither party is liable for delays or failures caused by events beyond its reasonable control, including failures of Connected Systems, AI providers, hosting providers or the internet. This does not excuse payment obligations.
19.7 Export and sanctions. You will not use the Service in violation of U.S. export control or sanctions laws, or from a sanctioned country.
19.8 Entire agreement. These Terms, any order form and the Privacy Policy are the entire agreement on this subject. If any provision is unenforceable, the rest remains in effect. A failure to enforce a provision is not a waiver. The parties are independent contractors.