PaperPony

Terms of Service

The agreement between you and the company that runs PaperPony. Written in the same plain terms as the rest of the site, because a document you cannot read is one you have not agreed to.

Version 1.0, in effect from 28 July 2026. Section 18 says how these change and how much warning you get.

1. Who this is between

These terms are an agreement between you and YTI Digital OÜ, a private limited company registered in Estonia under registry code 17298015, VAT EE102925876, at Loitsu tn 5-166, 13622 Tallinn, Estonia. In these terms it is called we or us, and you are the customer.

The Service means the API at api.paperpony.dev, the dashboard at app.paperpony.dev, the site at paperpony.dev including its documentation, and the free invoice generator. Using any of them means these terms apply. If you do not agree with them, do not use the Service.

2. What the service is

An API that turns HTML or a stored template into a PDF, and a free invoice generator built on the same renderer. You create an account and a key yourself at app.paperpony.dev. Plans, allowances and prices are on the plans page, and section 5 says what happens when you buy one.

3. Who may use it

You must have the legal capacity to enter into this agreement, and you must not be barred from using the Service by any law that applies to you. If you are agreeing on behalf of a company, you confirm you are allowed to bind it.

The Service is meant for professional use and these terms are written on that basis. You do not have to be a company to sign up and we do not ask. The person who integrates an API is often not the person who pays for it, and a freelancer is as much the reader of this page as a finance department is.

If you are in fact a consumer, nothing here removes or limits any right you have under mandatory consumer law in the country you live in, and where these terms conflict with such a right, that right wins.

4. Your account and your keys

A live key spends your credits, and anything shipped to a browser is readable. Keep keys on your own servers. If one leaks, write to us and it is revoked immediately, with no grace window. We store keys as a keyed hash and a twelve-character prefix and never the key itself, which is why a lost key is replaced rather than recovered.

Rate limits count per account rather than per key, so issuing more keys does not raise them. They are 10 requests a minute on Free, 60 on Starter, 300 on Growth and 1,000 on Scale.

You are responsible for what is done with your keys, including by anyone you give them to. Keep the address on the account working: it is where a failed payment, a suspension and a sign-in link are sent, and section 17 gives you seven days to act on the first of those.

5. Plans, payment and renewal

Free needs no card. The paid plans are monthly subscriptions and they renew automatically until you cancel. Payment is taken on the day you subscribed and on the same date each month after that, and your credit allowance resets on that date rather than on a calendar month, so the two never drift apart.

Prices are in US dollars and are shown before you pay: $29 a month for Starter, $99 for Growth and $299 for Scale. We may change prices, and a change never applies to a period you have already paid for. Section 18 is how you hear about one.

Those prices exclude tax. Stripe works out what applies from the billing address and any VAT number you enter, and shows the total before you pay.

Payment is processed by Stripe. Card details are typed on their page and go to them, never to us, and there is no field for a card anywhere in this system. Stripe collects the billing address and, where you have one, the VAT registration number, computes the tax on that basis, and issues the invoice. We hold a reference to it and no copy of any figure on it. The privacy page says exactly what is stored.

Changing plan takes effect immediately and Stripe prorates the difference against the period you have already paid for. You can change plan, change the card, download an invoice and cancel from the billing page in the dashboard, which hands you to Stripe for all four.

6. What a credit is, and where renders stop

One credit is one page of PDF, with a minimum of one per render. A render that fails or times out costs nothing. A render made with a test key runs the whole pipeline, marks the output with a watermark and charges nothing.

Each plan includes an allowance: 100 credits a month on Free, 2,000 on Starter, 10,000 on Growth and 50,000 on Scale.

On Free the allowance is the end of it. Renders answer 402 insufficient_credits and stop until the period resets. Nothing is charged and nothing is queued to be charged later.

On a paid plan renders carry on past the allowance and each further credit is billed at the rate for your plan, which appears on your next invoice. Usage is aggregated once a day from the record written at the moment of each render, and that record is what any question about a figure is answered from.

They do stop somewhere. A paid account stops at 10 times its allowance in one period, again with 402 insufficient_credits. That limit is on the account rather than part of the plan, and it exists because a metered price has no state in which it stops: a key that ends up somewhere public would otherwise spend money as fast as the rate limit allows. You are emailed as you approach it and again if you reach it, and it is raised on request. Raising it is not a charge and not a plan change.

7. Cancelling, and what happens to your data

You can cancel at any time from the billing page. Cancellation takes effect at the end of the period you have already paid for, not on the day you press the button, and the account keeps its plan until then. After that it moves to the free plan.

Nothing is deleted when you cancel. Your keys keep working, your stored templates are untouched, and your render history stays. What changes is the allowance, the rate limit, the retention on new output, and that output is watermarked again. Credits that were included in a period do not carry over into the next one, on any plan.

Cancelling does not produce a refund. It ends the subscription at the end of a period you have already paid for and you keep the plan until then, so there is no unused part to give back, and credits left in that period are not refunded either. A plan change is the different case: Stripe prorates that against the period you are in.

If you think a charge is wrong, write to hello@paperpony.dev. Those are read and settled one at a time by a person. That is a description of how it works rather than a promise about the outcome.

You can ask us to delete the account and everything on it, and that is one email to hello@paperpony.dev. What we keep afterwards is the accounting record of what you were charged, for seven years, which is the retention we apply to the books of an Estonian company. That record is the invoice and the payment: no document you rendered, no template, no key. Stripe holds its own copy of the invoices under its own obligations.

8. Your documents, and what you promise about them

What you send stays yours. We claim no licence over it beyond what rendering it requires, we do not use it for anything else, and we delete it on the schedule in section 11.

Rendering is the whole of what happens to it, and it is worth being precise about what that means: the renderer executes the HTML you send, in a real browser, including whatever that document loads. So you confirm that you hold the rights to what you send, including any text, images, fonts and other material it pulls in, and that rendering it does not infringe anybody else's rights or break a law that applies to you. Section 15 is what follows if that turns out not to be so.

9. What you must not send

Every render opens your HTML in a real browser, so the renderer is built to assume the document is hostile: outbound requests are validated at connect time, private address ranges are refused, and a set of attacks is attempted against it in CI on every change. Do not send documents designed to test that. If you want to probe it, write to us and we will talk about it, which is a much faster route to an answer than a rate-limited guess.

Do not use the Service to produce documents that impersonate somebody, or content that is illegal where you are. Do not attempt to work around a rate limit, a credit limit or any other control by using more than one account. An account doing any of this loses its key.

10. The invoice generator

Free, with no account and no watermark, and it stays that way. The invoices you make with it are yours, for any purpose, with nothing to attribute. Downloads are limited to ten an hour from one connection so that one caller cannot spend the shared budget the tool runs on. Sections 8, 9, 13 and 14 apply to it as they do to the API.

11. Availability, performance and retention

There is no uptime commitment and no guaranteed latency. We do not promise a service level, and these terms do not contain one. What we do instead is publish what was measured: a thousand consecutive renders of a twelve-line invoice carrying Cyrillic and Arabic came out at 590 ms median and 608 ms at the 95th percentile, with no failures, on the machine that serves this API. That is a measurement of one document on one day and not a promise about yours.

Free-plan output is watermarked and free-plan renders run with JavaScript switched off.

Rendered files are deleted after 24 hours on Free, 7 days on Starter and 30 days on Growth and Scale. Files made by the invoice generator are deleted after an hour. Those numbers are enforced by a sweep rather than promised by a table, which also means output is genuinely gone when it expires. Keep your own copy of anything you need to keep.

12. Our intellectual property

The Service itself, its software, its documentation, the site and the PaperPony name and marks are ours or our licensors'. Nothing in these terms transfers any of that to you, and you may not copy, adapt or redistribute it beyond what using the Service requires. This says nothing about your documents, which are covered by section 8 and remain yours.

13. Disclaimer of warranties

To the fullest extent the law allows, the Service is provided as is and as available, with no warranty of any kind, whether express, implied or statutory. We specifically disclaim any implied warranty of:

  • merchantability;
  • fitness for a particular purpose;
  • non-infringement;
  • uninterrupted or error-free operation.

This does not affect any right you have under mandatory law that cannot be disclaimed, including the consumer rights preserved by section 3.

14. Limitation of liability

To the fullest extent the law allows, we are not liable for indirect, incidental, special or consequential loss, for lost profit, revenue, data or business, or for the cost of obtaining a substitute service.

Our total liability for all claims arising out of or relating to these terms or the Service, taken together, is limited to the amount you actually paid us in the twelve months immediately before the event that gave rise to the claim. On the free plan that amount is nothing, and we would rather say so here than leave you to work it out later.

Nothing in these terms excludes or limits our liability for:

  • intentional wrongdoing;
  • gross negligence;
  • death or personal injury caused by our negligence;
  • anything else that cannot be excluded or limited under applicable law.

15. Indemnity

You will indemnify and hold us and our officers, directors and employees harmless against any claim, damage, loss, liability, cost or expense, including reasonable legal fees, arising out of your breach of these terms, your misuse of the Service, or your violation of any law or of anybody else's rights, including in the documents you send us to render.

16. Circumstances outside our control

We are not liable for any failure or delay in performing our obligations where it results from circumstances beyond our reasonable control, including natural disaster, epidemic, war, terrorism, civil unrest, government action, industrial action, the failure of a telecommunications network, an internet service provider or another supplier, a cyberattack, a system failure, a power outage, or a change in the law. Our obligations are suspended for as long as that lasts.

17. Suspension and termination

If a payment fails, the account moves to past_due and keeps working for seven days, measured from the first failure and not restarted by the retries after it. We email you when that starts. After seven days the account is suspended and renders answer 403 account_suspended until a payment succeeds, at which point it is active again on its own. Nothing is deleted at any point in that sequence, including through a suspension.

We may also suspend or end your access, without notice, if you breach these terms, if we reasonably believe your use is fraudulent or is harming other customers or the Service, or if the law requires it. If we withdraw a key without cause, we will say why.

You can stop using the Service at any time. Sections 8, 12, 13, 14, 15, 19 and 20 survive the end of this agreement.

18. Changes to these terms

We may change these terms. A change that materially affects you is emailed to the address on your account at least fourteen days before it takes effect, and the version on this page is always the current one. Continuing to use the Service after a change takes effect means you accept it. If you do not, cancel before then and stop using the Service.

Version 1.0 is the first version to carry the sections above on liability, governing law and payment, and it takes effect on 28 July 2026. The fourteen days apply to changes made from that date on. An account that existed before it accepts this version by signing in after it.

19. Governing law and where disputes go

These terms are governed by the law of the Republic of Estonia, without regard to its conflict of law rules. The United Nations Convention on Contracts for the International Sale of Goods is excluded. The courts of Estonia have exclusive jurisdiction over any dispute arising out of them, subject to section 3 where you are a consumer.

Write to us first. Most things are settled faster by an email to hello@paperpony.dev than by anything in this section.

20. Severability and the whole agreement

If any part of these terms is found invalid or unenforceable, it is narrowed to the least extent that makes it enforceable, or removed if that is not possible, and the rest stays in force.

These terms and the privacy page are the whole agreement between us about the Service, and they replace anything said before. Failing to enforce a term on one occasion does not waive it.

21. Contact

YTI Digital OÜ, trading as PaperPony. Registry code 17298015, VAT EE102925876. Loitsu tn 5-166, 13622 Tallinn, Estonia. hello@paperpony.dev, which reaches a person.