Terms of Service
These terms govern your use of nitpik, an AI-powered code review CLI tool, and the nitpik.dev website. By using nitpik, you agree to these terms.
1. The Tool
nitpik is a command-line tool that performs AI-powered code reviews. It runs locally on your machine or in your CI pipeline. It connects to a large language model (LLM) provider of your choice using your own API key. The review tool itself does not operate as a hosted service — it is a locally-executed binary.
We additionally operate the nitpik.dev website (account management, billing, and entitlement verification) and an optional GitHub App that, when you install it, triggers reviews inside your own CI. These hosted components never receive, read, or store your source code — reviews always run on your own infrastructure against your own model. See our Privacy Policy for details.
2. License
The nitpik source code is licensed under the Business Source License 1.1 (BSL 1.1). The key terms are:
- Personal and open-source use is free — no subscription required.
- Commercial use (use in a for-profit context, including internal business use) requires a paid commercial subscription. See Section 5.
- Each release automatically converts to the Apache License 2.0 three years after its release date, at which point it becomes fully open source.
The complete license text is available at github.com/nsrosenqvist/nitpik/blob/main/LICENSE.
The commercial subscription described in Section 5 unlocks the editor integration (LSP) and MCP server surfaces of the CLI, which require an active entitlement to run. The standalone nitpik review command works for free under the personal/open-source terms above.
3. AI-Generated Output
nitpik's review findings are generated by third-party large language models. This output:
- May be incorrect, incomplete, misleading, or hallucinated
- May fail to identify bugs, security vulnerabilities, or other issues present in your code
- Does not constitute a guarantee of code quality, security, or correctness
- Should be treated as suggestions, not authoritative verdicts
You are solely responsible for reviewing and validating all AI-generated output before acting on it. nitpik is an assistant, not a replacement for human code review, security audits, or professional quality assurance. A clean or favorable report from nitpik does not mean your code is free of defects or vulnerabilities.
We accept no liability for any loss or damage arising from your reliance on AI-generated output, including but not limited to decisions to merge, deploy, or ship code based on nitpik's findings or lack thereof.
3.1 Secret & Threat Scanning
nitpik includes optional secret scanning and threat scanning features that use pattern-matching rules and heuristics to detect leaked credentials, obfuscated payloads, backdoors, and other potentially harmful code patterns. These features:
- May fail to detect secrets, credentials, malicious code, or other threats present in your codebase
- May produce false positives — flagging benign code as suspicious
- Do not guarantee that your code is free of leaked secrets, vulnerabilities, or malicious content
- Are not a substitute for dedicated security tools, penetration testing, or professional security audits
A clean scan result does not mean your code is free of secrets or threats. You are solely responsible for the security of your code and infrastructure, including the detection and remediation of leaked credentials and malicious code, regardless of whether nitpik's scanning features identified them.
4. Your Responsibilities
- LLM provider choice: You select which LLM provider processes your code. You are responsible for reviewing and agreeing to that provider's terms of service and privacy policy.
- API key security: You are responsible for securing your LLM-provider API keys and your nitpik license key. nitpik does not store or transmit your LLM-provider keys to anyone other than your chosen provider.
- Account security: If you have a dashboard account at nitpik.dev/account, you are responsible for protecting access to the email address registered with that account, since sign-in is via single-use magic links sent to that address. You are responsible for the actions taken by anyone using API keys you have created.
- Compliance: You are responsible for ensuring your use of nitpik and your chosen LLM provider complies with applicable laws and regulations.
5. Commercial Subscriptions
5.1 Tiers and pricing
Commercial use is offered as a recurring subscription in two tiers:
- Solo — for a single individual developer. €30/month or €300/year.
- Team — for any team size, flat fee. €100/month or €1000/year.
All prices are exclusive of any applicable taxes; Polar (Section 5.4) collects and remits VAT and equivalent sales tax in its own name. Both tiers are a flat fee — there are no per-seat or usage-based charges.
Tier selection is largely on the honor system: the CLI does not meter your reviews or technically distinguish a Solo from a Team subscriber for ordinary review usage, and you agree to select the tier that accurately describes your situation. Certain capabilities are, however, reserved for the Team tier — currently air-gapped / offline deployment (offline entitlement tokens, see Section 5.6), which is available only to Team subscribers.
5.2 Automatic renewal and cancellation
Subscriptions renew automatically at the end of each billing period (monthly or yearly, depending on the cadence you chose). You may cancel at any time via the self-serve customer portal accessible from nitpik.dev/account.
When you cancel, your subscription remains active until the end of the current billing period and is not renewed. No prorated refund is issued for the unused portion of the current period unless required by applicable consumer-protection law.
5.3 Free tier and compatibility verification
The standalone nitpik review command, as well as the local secret and threat scanning features, are available for free under the personal/open-source terms in Section 2. nitpik's LLM provider integrations and CI integrations rely on third-party libraries, and behaviour may change due to upstream updates outside our control.
You are strongly encouraged to verify that your specific combination of LLM provider, model, CI platform, and code-hosting vendor works to your satisfaction using the free tier before subscribing. We do not guarantee compatibility with any particular provider, vendor, or CI integration. No refunds will be issued due to compatibility issues with third-party platforms.
5.4 Merchant of Record
Subscription payments are processed by Polar.sh, which acts as the Merchant of Record for the sale. This means:
- Polar — not Niklas Rosenqvist — is the merchant of record on your invoice and on your bank statement
- Polar issues the invoice in its own name and under its own VAT or tax identification number
- Polar is responsible for the collection and remittance of VAT, GST, US sales tax, and equivalent taxes in supported jurisdictions
- Chargeback, refund, and payment-dispute processes are administered by Polar
By completing checkout you also agree to Polar's terms of service and Polar's customer-facing terms. We remain responsible for the nitpik product and these terms of service; Polar is responsible for the payment transaction.
5.5 EU consumer right of withdrawal
For consumers located in the European Union, EU law would ordinarily grant a 14-day right of withdrawal for distance contracts for digital services. By completing checkout you expressly request that the digital service begin immediately and acknowledge that, in doing so, you waive the right of withdrawal under Article 16(m) of Directive 2011/83/EU (as implemented in your jurisdiction).
This waiver does not affect any non-waivable consumer protection rights you may have under local law.
5.6 GitHub App and air-gapped deployment
The optional GitHub App (Section 1) requires an active commercial subscription; App-triggered reviews are associated with your subscription. The App is dispatch-only — it triggers reviews in your own repository's CI and never receives your source code. You remain responsible for the workflow it runs, the model it calls, and the repository token it uses, on the same terms as any other CI usage of nitpik.
Air-gapped / offline deployment — the issuance of long-lived, period-aligned offline entitlement tokens for environments that cannot reach nitpik.dev — is a Team-tier capability. An offline token cannot be revoked before it expires; you are responsible for safeguarding it and for downloading a replacement before expiry. Solo subscriptions use the online entitlement flow, which tolerates short outages automatically but requires periodic connectivity to nitpik.dev.
6. Limitation of Liability
nitpik is provided "as is" without warranties of any kind, express or implied, including but not limited to warranties of merchantability, fitness for a particular purpose, or non-infringement. We do not warrant that AI-generated output will be accurate, complete, or fit for any purpose.
To the maximum extent permitted by applicable law, we shall not be liable for any indirect, incidental, special, consequential, or punitive damages, or any loss of profits, data, or business opportunities arising from your use of the tool — including any reliance on AI-generated review findings or the absence of findings.
You assume all risk associated with the use of AI-generated output. Under no circumstances shall our total aggregate liability exceed the amount you paid for your nitpik subscription in the 12 months preceding the claim, or €100, whichever is greater.
7. Support
Support is provided on a best-effort basis via GitHub Issues. We do not offer guaranteed response times or a service level agreement (SLA). Active subscribers may receive prioritized support.
8. Discontinuation & Availability
We reserve the right to discontinue, suspend, or cease development of nitpik at any time, for any reason or no reason, with or without notice. This includes, but is not limited to, situations involving:
- Personal circumstances of the developer(s)
- Economic infeasibility or lack of sustainability
- Legal, regulatory, or compliance concerns
- Technical limitations or architectural constraints
In the event of discontinuation:
- We will stop billing your subscription on the next renewal date.
- Your subscription remains active until the end of the current billing period; the editor integration and MCP server entitlement remains valid until that date.
- We are under no obligation to provide continued updates, support, bug fixes, or security patches.
- No prorated refund will be issued for the unused portion of the final billing period unless required by applicable consumer-protection law.
9. Third-Party Dependencies
nitpik relies on third-party services, technologies, and providers — including but not limited to LLM APIs, package registries, hosting platforms, payment processors, and open-source libraries. We do not control these third parties and make no guarantees regarding their continued availability, compatibility, pricing, or terms of service.
If a third-party dependency is removed, discontinued, deprecated, or altered in a way that impairs nitpik's functionality, we are not obligated to find an alternative, implement a workaround, or maintain compatibility. Such events may result in reduced functionality or full discontinuation of nitpik without liability on our part.
You acknowledge that your use of nitpik is subject to the availability and terms of these third-party services, and you assume all risk associated with changes to or removal of such services.
10. Changes
We may update these terms from time to time. The effective date at the top of this page will be updated accordingly. Continued use of the tool after changes constitutes acceptance.
11. Governing Law
These terms are governed by the laws of Sweden. Any disputes shall be resolved in the courts of Sweden, without prejudice to mandatory consumer-protection rights you may have under the law of your country of habitual residence.
12. Contact
Niklas Rosenqvist
contact@nitpik.dev