Terms of Service
The agreement between you and IT-Trail GmbH for the hosted Sitebin service at app.sitebin.io. Plain language where the law allows it, precise where it does not.
1. Who we are and what these terms cover
These terms are a contract between IT-Trail GmbH, Schärdinger Straße 15, 4061 Pasching, Austria (FN 642899s, Landesgericht Linz, VAT ID ATU81440503 — "we", "us", "Sitebin") and you, the person or organisation using the service ("you"). Contact: hello@sitebin.io, +43 732 99 71 89; full details in the imprint.
They govern the hosted Sitebin service: the
application at app.sitebin.io, the sites it serves on
*.sitebin.app and on custom domains you attach, the JSON
API, WebDAV, the MCP endpoint, and the marketing site at
sitebin.io. Together: "the service".
They do not govern the Sitebin software itself. The community edition is licensed under the MIT licence and the Enterprise extension under the Elastic License 2.0, both in the public repository. Self-hosting is covered by those licences and, for Enterprise, by a licence key agreement — see section 14.
Where you sign in, your account is held on the IT-Trail SaaS Stack,
the identity and billing platform we operate at
auth.ittrail.cloud. Its own platform terms are shown to
you once at sign-in and apply alongside these; where the two overlap,
these terms decide anything about the Sitebin service.
2. Accounts and eligibility
- You must be at least 16 years old to create an account or to publish a site. If you use the service for a company, association or other organisation, you confirm that you are authorised to bind it, and "you" means that organisation.
- You may sign in with an email address and password, or through any of the social sign-in providers offered on the login page. The credentials, and everything done with them, are your responsibility. Tell us at once if you believe an account has been compromised.
- One person, one account. Creating several accounts to multiply the free caps is not allowed and is a reason for us to close them.
- Business customers who publish other people's personal data through the service also accept our Data Processing Agreement — it is presented at sign-in and is part of this contract for them.
3. The free tiers
Drop — no account
Anyone may publish a site without signing in. A Drop is limited to 25 MB and 200 files, lives for 24 hours from creation and is then removed. It is managed only through its claim ticket (the edit URL and edit password shown once at creation): a lost ticket cannot be recovered, and a Drop cannot be driven through the API or MCP. Anonymous creation is rate-limited per IP address to keep the free lane usable for everyone.
Free — with an account
A Free account may hold 10 sites of up to 100 MB and 500 files each. A Free site lives for 7 days from its last change: every upload, edit or setting change restarts the clock, so a site you keep working on stays online, and a site you stop touching expires seven days later. Free accounts get the full API, CI deploys, WebDAV and the dashboard.
Both free tiers are provided as they are, without a service level and without support obligations beyond what the law requires. We may change their caps and lifetimes for the future; the current figures are always on the pricing page.
4. Paid plans
What you get
- Pro — €6 per month or €60 per year: 100 sites, 1 GB and 5,000 files per site, 5 custom domains, 3 containers, email support.
- Studio — €19 per month or €190 per year: 500 sites, 5 GB and 10,000 files per site, 25 custom domains, 20 containers, priority support.
A container runs a service from our image
catalogue (currently Node.js and MySQL) for one of your sites, as
declared in the site's sitebin-container-compose.yaml. The
number counts the containers running at the same time across all your
sites. Memory, CPU and process limits per container are fixed by us
and published in the documentation. When a plan ends or shrinks,
containers beyond the new allowance are stopped; stopping never
deletes the site's files.
Sites on a paid plan have no tier-imposed lifetime: they stay until you delete them or set an expiry yourself. Caps are checked when you create a site, upload files or attach a domain; a site that is over a cap keeps serving but stops accepting uploads until it is under again.
Prices and VAT
Prices are stated in euro and include VAT for consumers. The VAT rate follows your billing country and is itemised on the invoice. Business customers who provide a valid EU VAT identification number at checkout are charged without Austrian VAT under the reverse-charge mechanism where it applies; the invoice says so. Payment is by the methods offered at checkout, processed by Stripe (Stripe Payments Europe, Ltd., Ireland). We never see or store your card details.
Term and automatic renewal
A plan runs for the period you chose — one month or one year — and renews automatically for the same period at the price in force at renewal, until you cancel. The renewal charge is taken at the start of each new period. Before a yearly plan renews, we remind you by email.
Upgrades, downgrades and cancellation
- You can upgrade at any time; the new caps apply immediately and the price difference for the rest of the current period is charged pro rata.
- You can cancel at any time in the plan page of your account. Cancelling stops the renewal; the plan and its caps stay in force until the end of the period already paid for, and no further charge is made. Cancelling is not a withdrawal (see section 5) and the current period is not refunded, except where section 17 or mandatory law says otherwise.
- After a downgrade — a cancellation running out, a switch to a smaller plan, or a subscription ending for non-payment — your account returns to the lower caps. Every existing site that is beyond them gets a 30-day grace: its expiry is set to 30 days from the change and shown in the dashboard. Upgrade again within that window and the grace is lifted; otherwise the site expires at the end of it. Sites over the new storage cap stay online but stop accepting uploads. Custom domains already attached keep serving; the domain cap is checked only when you add one.
Failed payments
If a renewal payment fails, we and Stripe retry it for a limited time and email you so that you can update the payment method. If the payment still has not succeeded when the period you already paid for ends, the subscription ends, the account returns to Free and the 30-day grace above applies. You owe nothing for time you were not served.
Price changes
We may change the price of a plan for the future. We give you at least 30 days' notice by email before a new price applies to your subscription, and it applies only from the next renewal after that notice. If you do not agree, cancel before the renewal and nothing more is charged. Prices already paid are never changed retroactively.
5. Right of withdrawal for consumers
If you are a consumer in the EU or EEA, you may withdraw from a paid plan within 14 days of buying it without giving a reason. The details, the model form and how a refund is calculated are in our withdrawal policy.
The checkout asks you to expressly request that the plan starts immediately, before the withdrawal period ends, and to acknowledge the consequence: if you then withdraw, you pay a proportionate amount for the days already provided, and once the service has been fully performed during the withdrawal period the right to withdraw is lost. Without that request the plan would start only after the 14 days.
6. Your content
It stays yours
Everything you upload remains yours. We claim no ownership of it and no right to use it beyond what running the service needs. You grant us a non-exclusive, worldwide, royalty-free licence, for as long as the content is on the service, to store it, copy it for backups and failover, serve it to whoever requests the site's URL, transmit it over the networks between, and produce the derived forms serving requires (compressed transfers, generated directory listings, thumbnails in the file viewer). The licence ends when the content is deleted, subject to the retention periods in the privacy policy.
You are responsible for it
You are the publisher of what you put on the service. You confirm that you hold the rights needed to publish it and that it does not violate any law or anyone's rights. A site is public: anyone who has its URL can read it. The random URL is hard to guess, not secret — set a view password if a site is not for everyone, and do not publish anything you could not lawfully hand to a stranger.
Export at any time
Every site can be downloaded as a ZIP from its edit page, over the API and over MCP, at any time and on any tier. Keep your own copies: the service is a place to publish, not your only archive.
7. Acceptable use
You may not use the service to publish, store, link to or distribute:
- content that is illegal where you are, where we are, or where it is served — including child sexual abuse material, terrorist content and incitement to violence or hatred;
- content that infringes copyright, trademarks, personality rights or other rights of third parties;
- phishing pages, fake login forms, or anything that impersonates another person, brand or service to obtain credentials, payments or personal data;
- malware, exploits, or files intended to compromise other systems;
- spam landing pages, bulk-messaging infrastructure, or content that exists only to manipulate search engines;
- defamation, harassment, or the non-consensual publication of someone's personal data or intimate images.
You also may not attack, probe or overload the service; circumvent quotas, rate limits, expiry or the licence checks; scrape other users' sites in bulk; use the service as a file-distribution or proxy backend for a service you run elsewhere; or resell the service as such. The hosted plans are for publishing websites and files that belong to you or your organisation.
Running code in containers
A container runs code you supply on our infrastructure, with the network access you declare. Everything above applies to it and to whatever it serves. In addition, you may not use a container to:
- mine cryptocurrency, or run any workload that is not part of operating your own site or application;
- scan, probe, attack or overload any system or network — ours or anyone else's — including sending denial-of-service traffic;
- send email or other messages in bulk, or relay mail for others;
- operate an open proxy, VPN, Tor node or any other anonymisation or traffic-forwarding service;
- host services for third parties that you do not operate yourself, or resell container capacity;
- try to break out of the container, reach the host or our internal networks, or access another customer's containers or data.
You are responsible for the software you run in a container, for keeping it secure, and for the credentials in your compose file. We may stop a container immediately and without notice when we reasonably believe it breaches this section, endangers the service or third parties, or when its site exceeds its storage cap; where we reasonably can, we tell you why. Stopping a container never deletes your files.
Abuse reports and takedowns
Report abuse to hello@sitebin.io with the site URL and what is wrong; the operations documentation describes what we can act on. We may set a site to expire, take it offline or delete it, and may suspend or close an account, when we have a reasonable belief that this section is being breached, when a competent authority or court requires it, or when a site is causing damage to the service or to third parties. Where we reasonably can, we tell the owner and give them the chance to respond; for phishing, malware and content that is illegal on its face we act first. Our content-security headers detect a common phishing pattern (a form on a hosted site posting to a foreign host); reports of that pattern are reviewed by a person before a site is removed.
8. Claim tickets, passwords and API tokens
- The claim ticket — edit URL and edit password — is what confers control over a site. We store only a hash of the edit password and cannot recover it. A site owned by your account can be managed from the dashboard and its password rotated there; an anonymous site whose ticket is lost is simply lost.
- API tokens issued in your account act on your sites in place of the edit password. A token acts on sites, never on the account: it cannot change the plan, rotate passwords or delete the account. Tokens are shown once and stored as a hash; revoke a token you suspect is exposed. Up to 25 per account.
- Anything done with your credentials counts as done by you. Do not share tickets or tokens beyond the people and systems that need them, and do not put them in public repositories.
9. API, MCP and AI agents
The JSON API, the deploy tooling and the MCP endpoint let scripts and AI agents publish and manage sites for you. An agent connected with an API token, or through an OAuth authorisation you grant at sign-in, can do exactly what a script holding that credential can do — no more, no less. What an agent publishes under your account is published by you: these terms, the acceptable-use rules and your responsibility for content apply to it in full. Review what an agent has put online, restrict it to the read scope when it does not need to publish, and revoke its access in your account or in the agent's own settings when you stop using it. Sites created through MCP are recorded as such so that abuse can be traced.
Automated use is subject to the same rate limits as everything else. Do not build a product whose core function is to publish third-party content through your Sitebin account; that is what the Enterprise Platform licence is for.
10. Custom domains
Pro and Studio plans may attach custom domains to sites, up to the plan's cap. You must control every domain you attach and be entitled to use it. Point its DNS at the service as documented; we obtain and renew a TLS certificate for it from a publicly trusted certificate authority, which means the domain name is recorded in public certificate-transparency logs. We may detach a domain whose DNS no longer points at the service, that is used in breach of these terms, or whose certificate cannot be issued. Domains attached before a downgrade keep serving; only adding a new one is checked against the cap.
11. Availability, maintenance and changes
We run the service with care and aim for it to be available around the clock, but the Drop, Free, Pro and Studio tiers come without a service-level guarantee. Maintenance, updates and incidents can interrupt the service; we schedule planned maintenance outside European business hours where we can and announce it in the dashboard or by email when it is expected to last more than a few minutes. Containers are restarted when their site's compose file changes and may be restarted for maintenance; design what they run to survive a restart. We keep operational backups for disaster recovery; they are not a substitute for your own export — in particular, a database a container is writing may not be captured in a consistent state, so export it yourself.
We develop the service continuously and may add, change or retire features. Changes that remove a feature a paid plan is advertised with, or that materially reduce what you paid for, are announced by email at least 30 days ahead, and you may cancel with a pro-rata refund of the unused period if you do not want them. A feature marked "soon" or "beta" is not a promise.
12. Data protection
How we process personal data is described in the
privacy policy, which is part of this
contract. Where you, as a business, publish personal data of other
people through the service, we process it on your behalf under the
Data Processing Agreement. Your sites are served
from a separate registrable domain (sitebin.app) so that
published content cannot read or set anything on the application
itself, and the hosting infrastructure is in the EU.
13. Intellectual property
The Sitebin software is open-core: the community edition is available under the MIT licence and the Enterprise extension under the Elastic License 2.0, each as published in the repository. Those licences govern the code; nothing in these terms narrows them. The name "Sitebin", the logo, the claim-ticket design and the content of sitebin.io are ours; using them to suggest that a site, product or service is operated or endorsed by us is not allowed. Your content is yours (section 6). If you send us suggestions, we may use them without obligation to you.
14. Enterprise self-hosting licences
Enterprise licences (Team, Business and Platform, priced per year as shown on the Enterprise page) are sold to businesses on request through hello@sitebin.io. A licence is a signed key that entitles a self-hosted Enterprise instance to create sites past the built-in 90-day trial and to the custom-domain allowance of the tier bought; the Platform tier additionally grants the right to offer Sitebin to third parties as a hosted service, which the Elastic License 2.0 otherwise forbids. The code stays under the Elastic License 2.0; the key never phones home to run, and an expired key never restricts anything but the creation of new sites. Licences renew yearly unless cancelled before the renewal date; the order confirmation states the term, the cap and the price, and sections 16 to 18 apply to them.
15. Term and termination
- This contract runs for as long as you use the service. You can end it at any time by deleting your account in the account console; a paid plan should be cancelled first, and sites you want to keep exported first, because deletion removes your sites and cannot be undone. Anonymous Drops end by themselves after 24 hours.
- We may end the contract with 30 days' notice by email — for example if we discontinue the service — and refund the unused part of any prepaid period pro rata.
- We may suspend or end it without notice if you materially breach these terms (section 7 in particular), if we are required to by law or an authority, or if your account is used to attack the service. In that case no refund is due for the current period.
- Sections that by their nature should survive — content responsibility, intellectual property, liability, governing law — survive termination.
16. Warranty and liability
Consumers
Your statutory warranty rights, including those for digital services under the Austrian Verbrauchergewährleistungsgesetz (VGG), apply in full and are not limited by these terms. We are liable to you under the statutory rules. For damage other than personal injury we are liable only where it was caused intentionally or by gross negligence; liability for slight negligence is excluded to the extent §6 KSchG and other mandatory law allow. Nothing in these terms limits liability that cannot be limited by law.
Business customers
We are liable for damage caused intentionally or by gross negligence, and without limit for personal injury. Liability for slight negligence is excluded, as is liability for lost profit, indirect and consequential damage, loss of data that you could have exported, and third-party claims. For each contract year our total liability is limited to the amount you paid us for the service in the twelve months before the event; for the free tiers it is limited to €100. Warranty claims must be raised within six months of delivery of the affected service; §924 ABGB (presumption of defect) and §1298 ABGB (reversal of the burden of proof) do not apply. You indemnify us against third-party claims arising from content you publish or from your breach of section 7.
Both
We are not liable for the content of sites published by users, for the availability of networks, DNS or certificate authorities outside our control, or for damage resulting from credentials you did not keep safe. Free tiers are provided as they are.
17. Changes to these terms
We may change these terms when the service, the law or our business changes. A new version is identified by its date. For changes that affect your rights or obligations we email account holders at least 30 days before the new version takes effect, and it is presented to you at your next sign-in, where you accept or decline it. Purely editorial changes — corrections, clarifications, updated references — may take effect without that notice. If you decline a material change you can no longer sign in under the old terms; you may cancel, and we refund the unused part of a prepaid period pro rata. Your sites keep serving until they expire or you delete them. Each version you accepted, with its date and time, is recorded and can be exported from your account.
18. Governing law, venue and disputes
These terms are governed by Austrian law, excluding its conflict-of-law rules and the UN Convention on Contracts for the International Sale of Goods. If you are a consumer, the mandatory consumer-protection rules of the country where you habitually reside remain in force and the statutory venues apply. For business customers the exclusive place of jurisdiction is the competent court in Linz, Austria.
The European Commission provides a platform for online dispute resolution at ec.europa.eu/consumers/odr. We are neither obliged nor willing to take part in dispute-resolution proceedings before a consumer arbitration board; we do answer every complaint sent to hello@sitebin.io.
19. Final provisions
- If a provision of these terms is invalid, the rest remains in force. For business customers an invalid provision is replaced by the valid one that comes closest to its purpose.
- These terms are written in English and the English text is authoritative. Contract language is English.
- You may not transfer this contract or an account to someone else without our consent; we may transfer it to a company that takes over the service, and will tell you if we do.
- Notices to you go to the email address of your account; notices to us go to hello@sitebin.io or to the postal address in the imprint.
Version 2026-09-23, in force from 23 September 2026. Changes from version 2026-09-08: containers for Pro and Studio (sections 4, 7 and 11). Related documents: withdrawal policy · data processing agreement · privacy policy · imprint.