Terms of Service
Version 2026-09-11 · Effective 15 September 2026 at 08:00 CEST (Europe/Paris)
These Terms of Service ("Terms") govern access to and use of Carillon, a mobile push notification service published by Exostack SARL, a company registered in France under SIREN 922 481 981 ("Exostack", "we"). They form a contract between Exostack and the business that creates or uses a Carillon account (the "Customer", "you").
Carillon is offered to businesses and professionals only. By creating an account, you confirm that you act for a business purpose and that you have authority to bind the organization on whose behalf you use the service.
1. Definitions
- Service: the Carillon public API, internal API, dashboard, hosted MCP endpoint, command-line tool, SDKs and documentation.
- Organization: the workspace in the dashboard that holds apps, members, keys and billing. Fees, allowances and suspensions apply per organization.
- Customer Data: data you or your apps send to the Service, including device registrations, attributes, notification content, provider credentials and imported files.
- Device Data: the personal data within Customer Data that relates to the users of your apps, described in the Data Processing Agreement.
- MRD (Monthly Reachable Devices): the usage metric defined in the pricing documentation.
2. Documents that form the contract
The contract consists of these Terms, the Data Processing Agreement, the Acceptable Use Policy and the published pricing. The Privacy Policy describes how Exostack processes account data as a controller. A written agreement signed by both parties prevails over these Terms where they conflict.
3. Accounts
You must provide accurate account information and keep it current. Each person uses their own account; sessions and passwords must not be shared.
The owners and administrators of an organization control its members, invitations, apps, API keys, provider credentials and billing. You are responsible for all activity carried out through your organization's accounts, sessions and API keys, including by members you invite and agents you connect through the hosted MCP endpoint or the command-line tool.
Secret keys are shown once, when they are created. Store them in your backend's secret configuration and never ship them in a mobile app. Mobile keys are designed to be embedded in app binaries and are therefore public; they can only register devices and report events for their app. The Acceptable Use Policy sets out what to do when a key is exposed.
4. The Service
Carillon registers your apps' devices, stores the attributes you send, resolves the audiences you target and sends notifications through Apple Push Notification service (APNs) for iOS and Firebase Cloud Messaging (FCM) for Android, using the provider credentials you upload. It records a delivery trace for each notification and the opens your app reports.
APNs and FCM are operated by Apple and Google under your own agreements with them. A provider accepting a notification does not prove that the device displayed it, and Exostack does not control whether, when or how a provider delivers a notification.
Test keys run the pipeline with a simulated provider response and send nothing to Apple or Google.
Exostack may change, improve or discontinue features. Changes to the public API are additive: existing request and response fields keep their meaning. Exostack will give reasonable notice before discontinuing a feature that you actively use, except where security or law requires a faster change.
Unless a separate written agreement states otherwise, Exostack does not commit to a service level or an uptime percentage.
5. Your responsibilities
You are responsible for:
- having a lawful basis, and any consent required, for the notifications you send and the Device Data you send to the Service;
- informing the users of your apps about the processing, including in your app store privacy disclosures;
- complying with the terms of Apple and Google that apply to your apps and to the provider credentials you upload;
- the content of your notifications, tags and external identifiers. Do not send special categories of personal data unless you have a lawful basis to do so and the processing is necessary;
- keeping your credentials, keys and sessions secure and revoking them when exposed.
6. Acceptable use
You must use the Service in accordance with the Acceptable Use Policy. Technical rate limits and abuse protections apply to every organization.
7. Fees and payment
The Service is free for an organization whose MRD, summed across all its apps, stays at or below the free allowance stated in the published pricing. Above it, the published monthly tariff applies to the organization as a whole: one allowance and one base charge for the sum of all apps. Prices are in euros and exclude tax. Billing periods are calendar months in UTC, and usage is charged in arrears.
Paid plans are purchased through Stripe Managed Payments. For these purchases, Stripe acts as the merchant of record: the purchase is sold through Link, and Stripe collects payment, calculates and remits indirect taxes where it covers the territory, and sends receipts and invoices. The payment terms Stripe displays at checkout apply to the payment itself.
Exostack may change the published tariff with at least 30 days’ notice by email to organization owners before the start of the billing period in which it applies. Tariffs negotiated in a signed agreement are not changed by a change to the published tariff.
8. Suspension
Non-payment and unpaid usage. When an organization exceeds the free allowance without an active paid plan, or when an invoice payment fails, its owners and administrators are notified and a grace period of seven days starts. Payment retries do not extend it. When it expires without an active paid plan or a settled invoice, new live sends and the resumption of live campaigns are refused for every app of the organization. Device registration, traces, test sends and campaigns already accepted remain available. Access to sending is restored once the plan is activated or the invoice is paid.
Abuse, security and law. Exostack may suspend API keys, apps, accounts or an organization without prior notice where necessary to stop a breach of the Acceptable Use Policy, to protect the Service, other customers, the users of your apps or third parties, or to comply with the law or a request from a competent authority. Exostack will limit the suspension to what the situation requires, tell the organization's owners what happened when it can do so, and lift the suspension once the cause is resolved.
9. Customer Data and data protection
You keep all rights in Customer Data. You grant Exostack the rights needed to host, process and transmit it to provide the Service.
For Device Data, you act as controller (or as processor on behalf of your own customer) and Exostack acts as your processor under the Data Processing Agreement, which forms part of these Terms. For the data of the people who use the dashboard, Exostack acts as controller, as described in the Privacy Policy.
You can export devices and read delivery traces through the API at any time, and delete devices through the API.
10. Intellectual property
Exostack retains all rights in the Service. The SDKs and the command-line tool are licensed under the licence stated in their own repositories. If you send suggestions or feedback, Exostack may use them without obligation to you.
11. Confidentiality
Each party keeps confidential the non-public information it receives from the other in connection with the Service, uses it only to perform the contract, and protects it with at least reasonable care. This does not apply to information that is public, already known to the recipient, independently developed, or that must be disclosed by law.
12. Warranties
The Service is provided as described in its documentation. To the extent permitted by law, Exostack gives no other warranty, express or implied, including of fitness for a particular purpose or of uninterrupted operation.
13. Liability
Neither party is liable for indirect damage, loss of profit, loss of revenue, loss of business or loss of reputation.
Each party's total liability arising out of or in connection with the contract is limited to the fees paid by the Customer in the six months preceding the event giving rise to the claim. This calculation also applies to free organizations: if no fees were paid in that period, the cap is zero.
These limits do not apply to gross negligence, wilful misconduct, the Customer's payment obligations, or any liability that cannot be limited under applicable law.
14. Term and termination
The contract starts when you create an account and continues until terminated.
You may stop using the Service at any time. A paid subscription can be cancelled from the billing portal; cancellation takes effect as scheduled by the portal, and usage already incurred remains payable. To close an account or an organization, write to support@carillon.dev.
Either party may terminate the contract for a material breach that is not remedied within 30 days of written notice. Exostack may terminate with 30 days’ notice for convenience.
After termination, you have read-only access for 30 days to export your data through the available API and dashboard features. New sends, registrations, imports and other changes are disabled. Exostack deletes Customer Data from active systems within 30 days after that export window ends, unless the law requires its retention. Residual copies in database backups expire within a further 14 days.
15. Changes to these Terms
Exostack may update these Terms at any time. Each version is dated and states when it takes effect. Exostack will notify organization owners by email of changes that reduce their rights. The version accepted at sign-up is recorded on each account.
16. Governing law and jurisdiction
These Terms are governed by French law.
Where both parties have contracted in their capacity as traders (commerçants), the competent courts of Paris, France have exclusive jurisdiction over disputes that the parties cannot settle amicably, to the extent permitted by applicable law.
In all other cases, jurisdiction is determined by the applicable rules of law.
17. General
If a provision is held invalid, the remaining provisions stay in force. You may not assign the contract without Exostack's prior written consent. These Terms are written in English.
Contact: support@carillon.dev. Legal information about Exostack is in the legal notice.