InstaBrain Terms of Use for SDK and Integration Partners
Version 2026-09-07. Effective September 7, 2026. Partners accept these terms in the InstaBrain Technical Questionnaire. The version accepted is recorded with the questionnaire response. Unaccepted earlier drafts are withdrawn. A Partner that accepted an earlier version stays on that version until a replacement takes effect under section 12 or its access ends.
1. Who these terms cover and how they are accepted
These terms apply to any company or person ("Partner") that receives InstaBrain API credentials, SDK packages, documentation or sandbox access to build against the InstaBrain platform. InstaBrain Inc. ("InstaBrain") provides the platform.
Acceptance is recorded in the Technical Questionnaire: a required checkbox, the accepting person's name, title and company, the date, the version of these terms accepted, and the version of the developer documentation and the notice contacts in effect at acceptance, stored with the questionnaire response. The person accepting confirms that they are authorized to bind the Partner.
Updates for a Partner that accepted an earlier version are governed by section 12. InstaBrain may condition approval of a Partner-requested material expansion of scope on acceptance of the current version; credential replacement or renewal within the existing scope does not shorten the acceptance period in section 12. Not accepting is not acceptance.
2. Credentials and access
Credentials (API keys, private package access, sandbox and production identities) are issued to the Partner named on the questionnaire. Partner does not share, resell or transfer them, embed them in client-side code, or commit them to source control. Partner uses separate credentials for sandbox and production, rotates credentials when InstaBrain asks, and reports any suspected exposure without undue delay and within the deadline in section 7. InstaBrain may rotate or revoke credentials at any time.
3. Acceptable use and service limits
Partner respects the concurrency and request limits published in the InstaBrain developer documentation at all times and implements retries with backoff for critical calls rather than tight retry loops. Partner uses the APIs only for the purposes described in the questionnaire, does not scrape, load-test or probe production systems without written agreement, and does not attempt to bypass rate limits, authentication or eligibility rules. InstaBrain may change limits with reasonable notice, and without advance notice where needed to protect the platform or applicants.
4. Applicant and customer data
Data returned by the APIs, and data Partner collects in its own interface to submit through them, includes personal, financial and health-related information about insurance applicants ("Applicant Information"). Sensitive Applicant Information includes Social Security numbers, dates of birth, health answers, and financial account and payment data. Secondary use means any use of Applicant Information other than the transaction the applicant requested and the duties of the using party's own role under these terms. Sale means a disclosure of Applicant Information in exchange for money or other valuable consideration, including any disclosure applicable privacy law treats as a sale. A disclosure made solely to perform processing these terms expressly permit for the transaction the applicant requested is not a sale merely because a party pays or is paid for performing that processing, provided the recipient gets no right to sell the information or use it for a secondary purpose and applicable law does not treat the disclosure as a sale.
Partner collects and transmits only the Applicant Information needed for the transaction the applicant requested, protects it in transit and at rest, does not sell it, and does not use or disclose it for any purpose other than that transaction, the legal, servicing and record-keeping duties of Partner's own role, and the disclosure to InstaBrain that the de-identification authorization in section 6 covers. Partner promptly implements lawful deletion and correction requests that InstaBrain passes along and promptly identifies any request it cannot lawfully implement and why. The preservation exceptions in section 5 apply to deletion. Where an original record must be preserved, Partner implements a required correction through an amended record, annotation or other lawful method that keeps the required original.
Each party is responsible for its own compliance with the privacy, insurance and data security laws that apply to the Applicant Information it collects or holds. For Applicant Information collected through Partner's interface, Partner identifies on the Technical Questionnaire the entity on whose behalf the interface operates and the entity responsible for applicant-facing notices and authorizations, and makes sure the required notices are presented and authorizations obtained before collection or transmission. Providing an interface does not, by itself, make Partner the applicant's insurance producer. When InstaBrain processes Partner's submissions to route the transaction to the carrier, it does so under these terms and applicable law. Each party remains independently responsible for its own legal compliance, and InstaBrain processes Applicant Information only for the purposes stated in section 6. The InstaBrain Privacy Policy at instabrain.io/Home/Privacy describes InstaBrain's own practices to applicants; InstaBrain keeps it consistent with section 6, it does not expand InstaBrain's purposes under these terms, and a change to it does not change these terms. Sections 4 through 8 are the data protection and use terms between the parties. Where applicable law requires additional contractual data protection provisions for particular processing, the parties execute a data processing addendum containing them before that processing begins. If such a requirement is identified after processing has started, the parties execute the addendum without undue delay and in any event within 30 days after identification, and sooner where the law requires; in the meantime the affected processing continues only to the extent it is lawful without the missing provisions, and otherwise is paused, apart from processing needed and lawful to secure, preserve or return the affected data. If the addendum is not executed by that deadline, InstaBrain may suspend the affected processing until it is. This remediation period does not authorize processing the law prohibits and does not cure earlier non-compliance. A Partner may also propose an addendum for its own compliance program, and InstaBrain considers it in good faith. A signed addendum supplements sections 4 through 8 and controls on its subject matter.
5. Retention and deletion by Partner
The SDK is built so that Applicant Information is entered in Partner's interface and may sit in Partner's short-term or long-term storage before and after it reaches InstaBrain. Partner therefore keeps a written retention schedule for Applicant Information collected through the SDK and follows it. The following deadlines are outside limits that apply regardless of InstaBrain's own retention practices:
(a) Applicant Information for an application that is abandoned, declined, closed or otherwise ends without a policy is deleted from Partner's production systems no later than 30 days after that outcome, subject to the preservation exceptions below.
(b) For an application that results in an issued policy, Partner deletes the Applicant Information its continuing role does not need within 30 days after policy issuance, and keeps the information its lawful servicing or record keeping does need only for the documented retention period that applies to it.
(c) Subject to the preservation exceptions below, Partner deletes Applicant Information from production systems within 30 days after access ends under section 12, and within 10 business days after a written deletion request from InstaBrain; each deadline applies on its own.
(d) Copies that remain in backups after a production deletion deadline are access restricted and unavailable for ordinary use. They are restored only for documented disaster recovery, security recovery or compliance with law, and Partner reapplies the deletion before restored data returns to ordinary use. Backup copies expire in Partner's ordinary backup cycle and no later than the maximum backup retention Partner states on the Technical Questionnaire, which does not exceed 90 days after the production deletion deadline unless a preservation exception below requires a particular backup copy to be kept; a preserved backup stays access restricted and is deleted when its preservation basis expires. Where a preservation duty can be met by keeping the required records separately, it does not justify keeping an expired backup, and Partner segregates or deletes the portions of a preserved backup that the preservation basis does not cover; where Partner considers that technically infeasible, it documents why and tells InstaBrain within 10 business days after the production deletion deadline; InstaBrain may accept the documentation or propose an alternative method, the whole backup stays access restricted until it expires either way, and a good-faith documented infeasibility determination is not a breach of this section while any disagreement about it is pending under section 13.
(e) Partner confirms in writing, on request no more than once a year unless a security incident or a regulator's inquiry requires more, that it is following this section, and states in the Technical Questionnaire where Applicant Information is stored and for how long.
Preservation exceptions. Nothing in section 4 or this section requires Partner to destroy records that a specifically identified law requires it to keep, records subject to a written legal hold, or records a binding carrier appointment or agreement requires it to keep for lawful servicing or record keeping, including consent records under section 11. Partner identifies the basis, scope and retention end date to InstaBrain in writing within 10 business days of a request, limits the retained records to that purpose, and deletes them when the basis expires. This paragraph survives the end of access.
Applicant Information includes names, email addresses and telephone numbers as well as Sensitive Applicant Information. Neither party uses any retained copy of Applicant Information for marketing, modeling, training or any other secondary purpose. The only exception is InstaBrain's use of de-identified data exactly as section 6 describes; Partner has no secondary-use right under section 6.
6. Data Partner submits, and sharing with carriers
Partner authorizes InstaBrain to use, store and disclose the data Partner submits through the APIs or the questionnaire, including application data, agent and producer identifiers, technical logs and device or origin information, to the insurance carriers whose products are involved and to their service providers, limited to the minimum data reasonably necessary for underwriting, eligibility, compliance, fraud detection, application-related contracting, servicing and security. Before disclosing to a carrier or a carrier's service provider, InstaBrain puts in place, by written terms, the restrictions applicable law requires for that recipient; if it cannot, it does not disclose to that recipient and tells Partner what processing path applies instead. Partner represents that it has, and will keep, the authority to give this authorization, including authority from the entity identified under section 4 on whose behalf Partner's interface operates where that entity is not Partner, together with the lawful bases, notices, consents and authorizations required for its own collection and submission and for disclosure to the carrier and the carrier's service providers as described in the applicant notice under this section; Partner identifies that entity on the Technical Questionnaire where it is not Partner, states the basis for Partner's authority to act for it, and provides that entity's authorization on request. A lack of Partner authority does not expand InstaBrain's rights, and Partner stops the affected submission until the authority exists. InstaBrain does not disclose the authentication secrets issued to Partner to carriers or their service providers; where a recipient needs access, InstaBrain provisions separate, recipient-specific, least-privilege credentials. Security configurations and Technical Questionnaire responses are disclosed only in minimized extracts reasonably necessary for a listed purpose, with authentication secrets removed. InstaBrain may also use and store submitted data as reasonably necessary to operate and secure the platform and to comply with law, and for those purposes and the other processing this section permits may disclose the minimum reasonably necessary data to service providers that process it on InstaBrain's behalf under written duties of confidentiality, appropriate security, processing only on InstaBrain's documented instructions, and no sale or secondary use; that processing stays subject to sections 4 through 8 and any signed addendum. InstaBrain may also disclose submitted data where applicable law requires it.
Before collecting Applicant Information, Partner presents the applicant with disclosures and authorization language that satisfy applicable law, which may include the template language InstaBrain supplies in the SDK documentation, so that the applicant is told that Partner, InstaBrain and the carrier will use and share the application information for those purposes. Partner obtains every consent and authorization that the law requires for its collection and submission, and does not rely on this section as applicant consent. Partner authorizes InstaBrain to de-identify Applicant Information so that it cannot reasonably be used to identify or link information to an applicant, household or device, taking account of reasonably available means, and so that it meets any stricter standard applicable law sets; aggregation alone is not enough unless it meets that standard. InstaBrain's own analytics, model training and other platform-improvement uses rely only on data de-identified that way. InstaBrain keeps reasonable safeguards against re-identification, does not attempt re-identification, and contractually prohibits recipients from re-identifying or allowing re-identification of that data. Fraud detection, compliance and security are listed purposes, and the models, rules and scoring InstaBrain builds and runs for those purposes on the applications and producer activity submitted through the platform may use identifiable Applicant Information, subject to sections 4 through 8. Apart from that, these terms do not authorize identifiable Applicant Information to be used for InstaBrain's own analytics, model training or platform improvement.
7. Security measures and incident notification within 24 hours
Each party maintains reasonable administrative, technical and physical safeguards appropriate to the sensitivity of Applicant Information and the risks of its processing, including access controls, encryption in transit and at rest, vulnerability management and patching, security logging, secure development practices, and malware prevention, detection and remediation. Each party applies these safeguards to the systems under its control and requires appropriate safeguards from service providers that process Applicant Information on its behalf. Partner does not introduce malicious or unauthorized code into InstaBrain systems. InstaBrain may request a summary of Partner's security controls before or after enrollment.
Partner notifies InstaBrain within 24 hours after Partner first becomes aware of facts reasonably indicating a security incident, credential exposure or unauthorized access that involves InstaBrain credentials, InstaBrain systems or Applicant Information. Partner's notice goes by email to the security contact InstaBrain designates in the versioned developer documentation, and InstaBrain's notice under this section goes by email to the Partner security contact stated on the Technical Questionnaire; each states what happened, what data and credentials are affected, what containment is in place, and who to contact. The initial notice includes the information then available, identifies what is not yet known, and is supplemented without undue delay as more becomes known. Partner preserves relevant logs, cooperates with the investigation, and provides the information InstaBrain needs to meet its own notification duties. This is a contractual notice to InstaBrain. It does not replace, delay or shorten any notice that the law requires either party to give to applicants, regulators or others.
InstaBrain gives Partner initial notice on the same terms, within 24 hours after InstaBrain first becomes aware of facts reasonably indicating a security incident involving Partner's credentials, Partner's own data, or Applicant Information submitted by or on behalf of Partner, and supplements it as more becomes known. Neither party's notice waits for the investigation to finish.
8. Logs, investigations and audits
When required for an investigation or for troubleshooting, Partner shares technical logs of access and processing, redacting or tokenizing personal information where that can be done without impairing the investigation. Partner also makes available, within 10 business days of a request, or within the shorter time that an active security investigation or a regulator's deadline reasonably requires and that InstaBrain states in the request, documents that may be required for a compliance or regulatory audit, including the licensing evidence described in section 11 and evidence that the retention schedule in section 5 is being followed. InstaBrain may review licensing evidence before production access and on request afterward; review or the absence of review does not excuse Partner's compliance or make InstaBrain responsible for Partner's licensing.
9. InstaBrain's rights on security issues or non-compliance
InstaBrain may disable, reduce or change the service provided to Partner, including suspending credentials without prior notice, when it detects a security issue, a breach of these terms, or conduct that risks applicants, carriers or InstaBrain. InstaBrain gives Partner the reason for the suspension within 3 business days, and the steps that restore access promptly after it determines that the issue can be safely addressed.
10. Confidentiality and intellectual property
Nonpublic SDK code, nonpublic documentation, nonpublic rate and product information, and nonpublic information about unreleased features are confidential and are used only for the permitted purpose. Partner may show applicants the quotes, rates and product information the permitted transaction requires. Confidentiality does not apply to information Partner can show is lawfully public, already known to it without restriction, independently developed, or lawfully received from someone else without restriction. Partner may disclose confidential information to personnel and contractors who need it for the permitted purpose and are bound by equivalent confidentiality duties, and when the law compels disclosure, with advance notice to InstaBrain where the law allows. InstaBrain grants Partner a limited, non-exclusive, non-transferable, non-sublicensable, revocable license to install and use the SDK and documentation only to build and operate the integration described in the questionnaire, and only while access is active. No other rights are granted. Partner does not reverse engineer, modify for redistribution, sublicense, or remove notices from the SDK. InstaBrain, the Brain marks and related names remain InstaBrain's property.
The SDK may include open source components governed by their own licenses, identified in the SDK documentation or in a notice file included with the distribution. Those components remain under their own licenses, and nothing in these terms restricts the rights those licenses grant.
11. Insurance regulatory responsibility and consumer contact
Partner is responsible for holding the licenses, appointments and authorizations that the functions it performs require in each jurisdiction where it performs them, including producer licenses and carrier appointments where Partner solicits, sells or services insurance. A Partner that provides software only states that on the questionnaire, undertakes not to solicit, sell, negotiate or service insurance through the integration, and before any change in that role gives InstaBrain 30 days' prior written notice, obtains the licenses and appointments the new role requires, and pauses production use until InstaBrain re-approves production access for the new role. Partner provides evidence of its licenses and appointments, or of its software-only role, with the questionnaire and on request.
Partner is responsible for the accuracy and completeness of the information it enters, edits, maps or transforms, and for transmitting applicant-provided information without unauthorized alteration; InstaBrain transmits submitted information and may perform automated formatting, validation, routing and carrier-authorized rule application, without independently verifying the truth or completeness of applicant-provided facts. As between the parties, Partner decides whether any call, text message, email or other contact with an applicant or consumer that Partner starts or that the platform sends at Partner's direction occurs, and determines its triggers, recipients and content; InstaBrain supplies the software facility Partner uses to send it. For any message the platform sends on its own trigger or at a carrier's direction rather than Partner's, the versioned developer documentation states which party performs the trigger, recipient and content tasks and which party performs the consent and opt-out tasks, and as between the parties each party performs the tasks assigned to it and the consent and opt-out duties allocated to it; to the extent the documentation does not allocate a task for a message, Partner performs that task if Partner started the message, configured, requested or enabled it through the platform, or directed the platform to send it, and otherwise InstaBrain performs that task, including for a message sent on the platform's own trigger or at a carrier's direction. Partner obtains, keeps and honors every consent, disclosure and opt-out that the Telephone Consumer Protection Act, the Telemarketing Sales Rule, CAN-SPAM and similar state laws require Partner to obtain, keep or honor for the contacts described in this section, including prior express written consent where the law requires it, and performs the consent and opt-out tasks the documentation assigns to it; InstaBrain performs the consent and opt-out tasks the documentation assigns to InstaBrain. Each party keeps the consent records the law requires for its responsibilities; those record duties survive the end of access. Whether either party is an initiator, sender or other regulated actor under those laws is determined by applicable law and that party's actual conduct, and this allocation does not transfer or exclude either party's statutory duties. Acceptance of these terms does not authorize InstaBrain to initiate marketing or sales contact on Partner's behalf. The transaction-related system messages available through the platform are described, by channel, trigger, the party that determines each of those, and consent responsibility, in the versioned developer documentation; that description allocates tasks between the parties and does not determine statutory status, and calling a message transactional does not exempt it from applicable law.
InstaBrain does not approve, issue, decline or insure; the carrier does. The carrier determines underwriting approval, declination, policy issuance and coverage under its own processes. InstaBrain's platform transmits carrier decisions and applies carrier-provided rules on the carrier's instructions, within the technical permissions the carrier grants it, as an independent contractor under section 14.5 and not as the carrier's agent, as a producer or as an insurer; these terms do not expand those permissions.
12. Term, changes and termination
These terms apply from acceptance until access ends. InstaBrain may update these terms by publishing a new dated version at this address and giving notice to Partner. A change is material if it materially affects either party's rights or duties, including privacy, retention, data use, security duties, applicant notice language, licensing, intellectual property, fees, access, termination, liability or dispute resolution; a material change to the documentation these terms incorporate is treated the same way for a Partner when it would apply to that Partner, while a change of a designated contact is made by notice under section 14.1 and is not a material change. Routine changes to operational limits under section 3 do not require acceptance unless they materially impair Partner's existing permitted production use; a materially impairing change follows the material-change procedure in this section, except that InstaBrain may impose an immediate restriction reasonably necessary to address a security threat or protect platform availability or applicants, with prompt notice of the restriction and its reason; InstaBrain removes or narrows it as soon as reasonably practicable and follows the material-change procedure in this section for any restriction that continues beyond 14 days. A material change takes effect for a Partner when the Partner accepts it through the Technical Questionnaire; if a Partner has not accepted within 60 days after the notice takes effect under section 14.1, or within the shorter period the notice states where applicable law or a carrier requirement reasonably requires it, InstaBrain may suspend production access until it does, and the version the Partner last accepted governs in the meantime; if access stays suspended for 30 more days without acceptance, access ends and the post-termination duties in these terms apply. Other changes take effect on the later of the stated effective date and delivery of notice. Either party may end access on written notice. Sections 4, 5, 6, 7, 8, 10, 11 (record duties), 13 and 14, and any obligation that accrued before access ended, survive.
13. Warranties, liability, indemnity, disputes and law
13.1 Disclaimer of warranties. The platform, APIs, SDKs, documentation, sandbox and production services are provided as is and as available. InstaBrain disclaims all warranties, express or implied, including merchantability, fitness for a particular purpose, non-infringement, accuracy, uptime and availability. InstaBrain does not warrant that the services will be uninterrupted, error free, secure or free of delay, or that any application submitted through the platform will be approved, issued or bound by any carrier. InstaBrain does not approve, issue, decline or insure; the carrier does, and InstaBrain gives no warranty as to any carrier decision, quote, rate or servicing action.
13.2 Limitation of liability. To the maximum extent permitted by law, neither party is liable to the other for indirect, incidental, special, consequential, punitive or exemplary damages, or for loss of profits, revenue, business, goodwill or data, even if advised of the possibility. To the maximum extent permitted by law, InstaBrain's total aggregate liability arising from or related to these terms or the platform is limited to the platform fees Partner paid to InstaBrain in the 12 months before the event giving rise to the claim, or USD 1,000, whichever is greater. Platform fees exclude premiums, commissions and other amounts that pass to or from carriers. These limits do not apply to a party's willful misconduct, to a party's sale or secondary use of Applicant Information in breach of sections 4, 5 or 6, to a party's breach of the confidentiality duties in section 10, to misuse of credentials, to InstaBrain's first-party incident response costs caused by Partner's breach of section 7, or to amounts payable to third parties under section 13.3 for those categories or arising from Partner's breach of sections 4, 5, 6 or 7; those categories stay uncapped, and no cap in this section applies to them, even where the same conduct is also gross negligence or a breach of another section. For liability outside those categories that arises from a party's gross negligence or its breach of sections 2, 4, 5, 6 or 7, that party's aggregate liability is capped at three times the greater of the platform fees Partner paid in the 12 months before the event giving rise to the claim and USD 1,000, and other amounts payable under section 13.3 for such a breach count toward that cap. Except for the uncapped categories, the damages exclusion in the first sentence applies whether liability is capped or uncapped; it does not exclude amounts otherwise recoverable under section 13.3 merely because the third party's own damages fall within a category listed in the first sentence, and amounts recoverable under section 13.3 remain subject to the applicable cap and the uncapped categories stated in this section. The ordinary aggregate cap stated above applies only to InstaBrain; nothing in this section caps Partner's other liability.
13.3 Partner indemnity. Partner will defend, indemnify and hold harmless InstaBrain and its affiliates, officers, directors, employees and agents from and against third-party claims, and the resulting damages, losses, fines, penalties, costs and reasonable attorneys' fees, to the extent arising from: (a) Partner's misuse of credentials or Applicant Information, including unauthorized access, disclosure, sale or secondary use; (b) Partner's breach of sections 4, 5, 6 or 7; (c) Partner's violation of insurance, privacy, data security, licensing or consumer contact law; (d) claims by applicants, producers, carriers or regulators arising from Partner's acts or omissions, Partner's interface, Partner's submissions or Partner's contact with applicants; and (e) Partner's use of the SDK outside the license in section 10. InstaBrain gives Partner prompt notice of the claim and reasonable cooperation, and Partner does not settle a claim that imposes any obligation or admission on InstaBrain without InstaBrain's written consent. Partner's defense and indemnity duties apply only to the extent the claim is attributable to the covered Partner conduct and exclude amounts attributable to an indemnified party's own fault. Fines and penalties are covered only to the extent the law permits their indemnification.
13.4 Arbitration. Any dispute, claim or controversy arising from or relating to these terms or the platform, including their formation, interpretation, breach, termination, enforceability or validity, is resolved by binding arbitration administered by the American Arbitration Association under its Commercial Arbitration Rules then in effect, except as stated in section 13.6. The Federal Arbitration Act governs this section. There is one arbitrator. The seat is Phoenix, Arizona, proceedings are in English, and at either party's request the arbitrator conducts hearings by video conference. The arbitrator has exclusive authority to decide the scope, applicability and enforceability of this section, except that a court decides the enforceability of section 13.5. Judgment on the award may be entered in any court of competent jurisdiction. The arbitrator may allocate administrative fees, arbitrator compensation, and reasonable attorneys' fees and costs between the parties as the rules and applicable law permit.
13.5 No class, collective or representative proceedings. Each party brings claims only in its own capacity and not as a plaintiff or member in any class, collective, consolidated or representative proceeding. The arbitrator may not consolidate the claims of more than one Partner or preside over any form of representative proceeding. If this section is held unenforceable for a claim or remedy, that claim or remedy proceeds in court under section 13.7, and section 13.4 remains in force for every other claim that remains arbitrable.
13.6 Court exceptions. Either party may seek temporary, preliminary or permanent injunctive or other equitable relief in court for a breach or threatened breach of sections 2, 4, 5, 6, 7 or 10, without first arbitrating and without posting a bond beyond what the law requires. Either party may bring an individual claim that qualifies there in a small claims court in Maricopa County, Arizona.
13.7 Governing law and venue. These terms are governed by the laws of the State of Arizona without regard to its conflict of laws rules. Except for proceedings to confirm or enforce an arbitration award, which may be brought in any court of competent jurisdiction, and except for small claims under section 13.6, any court proceeding under these terms is brought in the state courts located in Maricopa County, Arizona, or in the United States District Court for the District of Arizona sitting in Phoenix, and each party consents to personal jurisdiction and venue there.
13.8 Limitations period and jury waiver. To the maximum extent permitted by law, a claim for breach of these terms must be filed within one year after the claiming party discovers, or reasonably should have discovered, the breach, or it is permanently barred. This period does not apply to claims to enforce the defense and indemnity duties in section 13.3, which follow the accrual rules and limitations periods the law provides, and it does not shorten any limitations period that the law does not allow the parties to shorten. Each party waives trial by jury in any court proceeding arising from or relating to these terms, to the maximum extent permitted by law.
14. General
14.1 Notices. Notices to InstaBrain go to the notice email address recorded with Partner's accepted Technical Questionnaire response, with a copy to the postal address recorded there; at publication these are the notice contact stated in the developer documentation and the address shown at instabrain.io/Home/Contact. Receipt at the notice email address is enough for effectiveness; the postal copy is a courtesy and does not condition it. Notices to Partner go to the email address on the Technical Questionnaire. Either party may change its notice, security or other designated contact by notice under this section, and InstaBrain may do so by a versioned documentation update delivered to Partner by notice; a change to a webpage or to the documentation alone is not enough. A notice is effective when received. Absent a bounce or delivery failure, an emailed notice is presumed received on the next business day in Phoenix, Arizona after it is sent, and earlier actual receipt counts from the earlier time; if a bounce or delivery failure is received, the notice is effective only when successfully resent or delivered another permitted way. Security incident notices follow section 7.
14.2 Force majeure. Neither party is liable for delay or failure caused by events beyond its reasonable control. This does not excuse payment obligations, security obligations, or the incident notice duty in section 7.
14.3 Severability and waiver. Except as section 13.5 provides for the class waiver, if any provision of these terms is held unenforceable, the remaining provisions stay in effect and the unenforceable provision is reformed to the minimum extent needed to make it enforceable. A party's failure to enforce a provision is not a waiver of it.
14.4 Entire agreement and assignment. These terms and the Technical Questionnaire response that accepts a specific dated version are the entire agreement between the parties about the SDK and API access, and replace earlier discussions on that subject. Developer documentation is incorporated only for technical specifications, the operational limits section 3 provides for, the designated security and notice contacts, the list of transaction-related system messages and the allocation of trigger, recipient, content and consent tasks for them under section 11, and the template applicant notice language under section 6, each as versioned and in effect at acceptance and recorded with the questionnaire response; it does not change legal rights or duties unless these terms expressly say so. For an existing Partner, a later change to incorporated documentation takes effect only under section 3 as limited by section 12 (operational limits), section 14.1 (designated contacts), for a message-allocation change that is not material under section 12, a notice under section 14.1 that states the allocation for a new or changed platform message (which takes effect for that message on the later of its effective date and receipt, with the default rule in section 11 applying until then), or section 12 (everything else, including any material message-allocation change). A written agreement signed by both parties that expressly modifies these terms controls over them. Partner does not assign these terms or its access without InstaBrain's written consent. InstaBrain may assign these terms to an affiliate or a successor to its business.
14.5 Order of precedence. If provisions of these terms conflict, the uncapped categories in section 13.2 control over any cap; the default rule in section 11 controls over incorporated documentation that is silent or internally inconsistent; a material change takes effect only under section 12 regardless of any other route; and these terms control over the developer documentation and the Technical Questionnaire except for the fields those documents are expressly incorporated to supply.
14.6 Independent parties. The parties are independent contractors. Nothing in these terms creates a partnership, joint venture, agency, franchise or employment relationship, and neither party may bind the other.
Version 2026-09-07. Effective September 7, 2026. Questions about these terms go to the contact on the InstaBrain Contact page.
