Terms &
Conditions
These Terms govern your access to and use of CohiBox. Please read them carefully before using the Service. By using CohiBox, you agree to be legally bound by these Terms.
Acceptance of Terms
By accessing or using CohiBox ("the Service," "we," "our," or "us"), you agree to be bound by these Terms and Conditions ("Terms"). If you do not agree with any part of these Terms, you must not use the Service. These Terms apply to all users, visitors, and others who access or use the Service, whether from the Philippines or any other jurisdiction worldwide.
Your continued use of CohiBox after any modification of these Terms constitutes your acceptance of the revised Terms. It is your responsibility to review these Terms periodically for changes.
Eligibility & Account Registration
Minimum Age
You must be at least 13 years of age to use the Service. If you are under 18 years of age, you represent that you have obtained parental or guardian consent to use the Service and to these Terms. In the Philippines, use of the Service is subject to Republic Act No. 10175 (Cybercrime Prevention Act) and Republic Act No. 10173 (Data Privacy Act of 2012).
Google Account Requirement
To access the full features of CohiBox, you are required to authenticate via Google Sign-In ("Google OAuth"). We do not offer password-based registration. By signing in with Google, you authorize CohiBox to receive your Google account email address and display name. We do not request, collect, store, or have access to your Google password, other personal profile information, contacts, calendar, or any other Google service data beyond your email address and display name.
Why We Require Google Sign-In
CohiBox executes Java code from GitHub repositories inside a private, isolated sandbox environment hosted on our infrastructure. Because executed code can include scripts and programs with varying degrees of potential system impact, we require authenticated user identity to: (a) associate all executed code and sandbox sessions with a specific verified account; (b) maintain comprehensive audit logs linking execution activity to individual users; (c) prevent anonymous abuse of our computational resources; and (d) enable enforcement of our acceptable use policy through account suspension or termination when violations are detected.
Account Accuracy
You agree to provide accurate and complete information during registration and to keep your account information current. You are responsible for all activity that occurs under your account.
Sandbox Execution Environment & Abuse Prevention
Private Sandbox Architecture
All code execution on CohiBox occurs within an isolated, private sandbox container provisioned exclusively for your session. Sandbox environments are ephemeral: they are created on demand and destroyed after your session ends. No code executed in one user's sandbox can access the data or environment of another user's sandbox.
Activity Tracking & Logging
Because every execution session is linked to your authenticated Google account, all activity within the sandbox — including all code executed, all commands run, all network requests attempted, all files created or modified, and all system calls made — is logged and associated with your user identity. This logging exists for platform security, integrity, and abuse prevention purposes. We retain execution logs for a period sufficient to investigate abuse reports and comply with applicable law, including the Cybercrime Prevention Act of 2012 (RA 10175) of the Philippines.
Malicious Code Tracking
Any attempt to execute malicious code, exploit the sandbox infrastructure, access systems outside your authorized sandbox, perform denial-of-service attacks, circumvent security controls, or otherwise abuse CohiBox's computing resources will be tracked, logged, and directly attributed to your authenticated user account. CohiBox reserves the right to immediately suspend or permanently terminate any account involved in such activity without prior notice. We may also disclose activity logs to law enforcement or regulatory authorities as required by applicable law.
Resource Limits
Your sandbox session is subject to compute resource limits including but not limited to CPU usage, memory allocation, network bandwidth, execution time, and storage I/O. Attempts to exceed these limits, whether deliberate or accidental, may result in session termination and repeated violations may result in account suspension.
No Warranty of Sandbox Isolation
While CohiBox employs industry-standard isolation techniques, we make no absolute guarantee that sandboxes are completely impervious to all forms of attack or escape. You use the Service at your own risk and must not intentionally attempt to break sandbox isolation.
Acceptable Use Policy
Permitted Uses
CohiBox is designed for running, inspecting, and analyzing Java projects fetched directly from public GitHub repositories for educational, development, research, and professional purposes.
Prohibited Uses
You agree not to use the Service for any of the following purposes: (a) executing malware, ransomware, spyware, trojans, or any other malicious software; (b) performing unauthorized access attempts against any system, network, or data; (c) crypto-mining, botnets, or similar distributed resource abuse; (d) generating, hosting, or distributing child sexual abuse material or any content illegal under applicable law; (e) harassment, stalking, threatening, or intimidating any person; (f) violating any applicable national or international law or regulation; (g) impersonating any person or entity; (h) transmitting unsolicited commercial communications (spam); (i) violating the intellectual property rights of third parties; (j) attempting to reverse-engineer, decompile, or otherwise extract the source code of CohiBox's proprietary systems; or (k) any activity that places excessive load on our infrastructure or degrades the service for other users.
Philippine Law Compliance
Users accessing the Service from the Philippines are additionally bound by: Republic Act No. 10175 (Cybercrime Prevention Act of 2012), which criminalizes illegal access, data interference, system interference, and other computer-related offenses; Republic Act No. 8792 (Electronic Commerce Act of 2000); and Republic Act No. 10173 (Data Privacy Act of 2012), as enforced by the National Privacy Commission (NPC).
Data Collection, Privacy & Data Processing Agreement (DPA)
Data We Collect
CohiBox collects the following categories of data: (a) Account data: your Google-provided email address and display name, and your GitHub public profile metadata (username and avatar URL) if you connect your GitHub account; (b) Usage data: repository URLs and commit SHAs you submit or select, commit date/time filter parameters, interactive terminal and execution session logs, user chat prompts submitted to the AI code inspector, and AST analysis outputs; (c) Technical data: IP addresses, browser type and version, operating system, session identifiers, and referral URLs; (d) Communication data: any messages you send to us through support channels.
Data We Do Not Collect
We do not collect or store your Google or GitHub passwords. We do not collect payment information (as CohiBox does not currently offer paid tiers). We do not sell, rent, or commercially trade your personal data to third parties. We do not collect sensitive personal data as defined under RA 10173 (e.g., racial or ethnic origin, political opinions, religious beliefs, health data) unless you voluntarily provide such information in submitted code or communications.
Repository & Commit Knowledge Caching
When a repository is analyzed at a specific commit SHA, CohiBox indexes and securely caches structural repository knowledge (including file tree hierarchies, symbol graphs, and Abstract Syntax Tree facts) partitioned by the repository owner, name, and commit SHA. This deterministic caching ensures consistent and reproducible analysis, accelerates subsequent inspections, and minimizes unnecessary upstream API calls to GitHub. No private repository contents or uncommitted user files are stored.
Legal Basis for Processing (Philippines & International)
Under RA 10173 (Data Privacy Act of 2012), we process your personal data on the following lawful bases: your consent (given by agreeing to these Terms and signing in with Google or connecting GitHub), the performance of our service contract with you, and our legitimate interests in platform security and abuse prevention. For users in the European Economic Area, processing is additionally governed by the General Data Protection Regulation (GDPR), with data processed under Article 6(1)(b) (contract performance) and Article 6(1)(f) (legitimate interests).
Data Rights
You have the right to: access a copy of the personal data we hold about you; request correction of inaccurate personal data; request restriction of processing; request erasure of your data; and lodge a complaint with the National Privacy Commission (Philippines) at www.privacy.gov.ph, or with the relevant data protection authority in your jurisdiction. Exercise these rights by contacting us at kent@cohibox.tech.
International Data Transfers
Your data may be processed and stored on cloud servers located outside the Philippines (e.g., AWS, Supabase). Where such transfers occur, we implement appropriate safeguards in accordance with RA 10173 and applicable international data protection frameworks.
Third-Party AI Services & Intelligence Processing
Integration with Third-Party AI Model Providers
CohiBox integrates leading third-party artificial intelligence and foundation model providers—including Google Gemini (Google LLC), AWS Bedrock (Amazon Web Services), Anthropic Claude, Mistral AI, Qwen (Alibaba Cloud), and OpenAI / Bedrock Mantle / OpenRouter—to power code analysis, architectural questioning, semantic code search, and contextual assistance features.
Data Transmission Scope & Purpose
When you interact with the CohiBox AI Code Inspector, your prompts and relevant code context (such as Abstract Syntax Tree nodes, symbol hierarchies, method signatures, file snippets, and compilation outputs) are transmitted securely to these third-party AI providers via encrypted TLS connections strictly for generating real-time analysis, citations, explanations, and answers.
Zero Model Training on User Code & Queries
Neither CohiBox nor its third-party AI provider enterprise agreements retain, store, or use your submitted code, private repository structures, or conversational prompts to train, fine-tune, or improve public AI foundation models. Data processing is transient and stateless for the duration of inference.
AI Output Disclaimers & Developer Discretion
Responses, explanations, and code suggestions generated by AI models are produced algorithmically and provided on an advisory and educational basis. While CohiBox incorporates automated symbol verification and AST grounding citations, artificial intelligence may produce incomplete, outdated, or inaccurate outputs. You retain sole responsibility for evaluating, testing, and verifying any code before incorporating it into production systems.
Fair Use, Rate Limiting & Prompt Safety
To protect computing resources and platform availability, AI interactions are subject to automated rate limits (including sliding-window quotas and burst limits) and automated content moderation. Attempting to bypass AI rate limits, perform prompt injection/jailbreak attacks, or submit malicious prompts is strictly prohibited under our Acceptable Use Policy.
GitHub Integration, OAuth Sync & Repository Content
GitHub Account Connection & OAuth Scope
CohiBox offers an optional GitHub integration that enables you to browse and import your GitHub repositories with one click. When you connect your GitHub account, CohiBox requests authorization using the minimal scope "public_repo, read:user". This grants CohiBox read-only access to your public profile and public repository listing. CohiBox does not request or possess access to your private repositories or private organization assets.
GitHub Token Security & Handling
Your GitHub access token is stored securely in an encrypted, HTTP-only browser cookie ("cohibox_github_token") and is used exclusively on your behalf to communicate with the official GitHub REST API. Your GitHub token is never stored in persistent third-party databases, never transmitted in client-side script contexts, and never shared with other users or commercial third parties.
Commit History Retrieval & Version Selection
CohiBox queries the GitHub REST API to retrieve public commit history metadata (including commit SHAs, commit messages, author names, and timestamps) and provides temporal filtering tools to locate specific historical points. This metadata is retrieved on-demand to enable reproducible version selection. All author metadata displayed originates from publicly available git commit logs published on GitHub.
Commit-Level Sandbox Execution
When you execute a repository at a chosen commit SHA, CohiBox checks out the precise repository tree corresponding to that commit snapshot inside your isolated sandbox. You acknowledge that code execution occurs at that specific historical point and remains fully subject to our sandbox abuse prevention, compute limits, and acceptable use policies.
Disconnecting & Revoking GitHub Access
You can disconnect your GitHub account from CohiBox at any time by clicking the "Disconnect" button in the repository picker, which immediately clears your stored token. You may also permanently revoke CohiBox's OAuth authorization at any time directly through your GitHub account settings at github.com/settings/applications.
Third-Party Content & Intellectual Property
CohiBox fetches and executes code from GitHub repositories specified or imported by you. CohiBox does not own, curate, moderate, or endorse the content of any GitHub repository. You are solely responsible for choosing which repositories to execute on our platform and represent that you have the legal right or open-source license to execute such code. You agree to indemnify CohiBox against any claims arising from your execution of third-party code.
Intellectual Property
All rights, title, and interest in and to the CohiBox platform, including its design, source code, software, trademarks, service marks, logos, documentation, and all related materials, are owned exclusively by CohiBox and are protected by applicable intellectual property laws, including the Philippines Intellectual Property Code (Republic Act No. 8293).
These Terms do not grant you any ownership rights in the Service. You are granted a limited, non-exclusive, non-transferable, revocable license to use the Service solely for its intended purpose and in accordance with these Terms.
You agree not to copy, modify, distribute, sell, lease, reverse-engineer, or create derivative works based on the Service or its components without our express written permission.
Account Deletion & Data Removal
Instant Self-Service Account Deletion
You may permanently delete your CohiBox account at any time using the self-service "Delete Account" button in your account menu, or via the interactive Delete Account action below. Once confirmed, all account deletion procedures execute immediately and automatically.
Complete & Irreversible Data Removal
Upon account deletion, CohiBox will permanently and irreversibly delete all personal data associated with your account from our active systems and databases. This includes: your email address and display name; your GitHub connection tokens and synced repository records; all chat history and AI conversation messages; your session history and execution logs; all preferences and settings associated with your account; and all saved repositories and custom folder structures.
No Data Retention After Deletion
We will not retain any copy of your personal data after account deletion is processed. No backup copies, archival records, or shadow profiles will be maintained with your identifiable information after the deletion request has been fulfilled. Once deleted, this data cannot be recovered.
Exceptions
Notwithstanding the above, we may retain certain data where required by applicable law or regulation, including but not limited to: data subject to active legal proceedings, law enforcement requests, or regulatory investigations; anonymized or aggregated statistical data that does not identify you; and data necessary for the resolution of disputes relating to your account or enforcement of these Terms. Such retained data will be stored securely and will not be used for any other purpose.
Effect of Deletion on Ongoing Investigations
If your account is the subject of an ongoing abuse investigation or has been identified in a law enforcement request at the time of your deletion, we reserve the right to retain relevant records until the investigation or legal process has concluded, after which data will be deleted in accordance with this policy.
Account Termination by CohiBox
In the event CohiBox terminates your account due to Terms violations, the same data deletion principles apply to personal identification data. However, anonymized records of the abuse event may be retained for platform security purposes.
Self-Service Account Deletion
Permanently erase your account, all session history, saved folders, and all associated personal data from CohiBox immediately.
Disclaimers & Limitation of Liability
Service Provided "As Is"
The Service is provided on an "as is" and "as available" basis without any warranties of any kind, either express or implied, including but not limited to implied warranties of merchantability, fitness for a particular purpose, or non-infringement. CohiBox does not warrant that the Service will be uninterrupted, error-free, or secure.
Third-Party Infrastructure & Database Hosting
CohiBox utilizes third-party infrastructure, database hosting, cloud compute providers, and authentication services to operate the Service. To the maximum extent permitted by applicable law, CohiBox is not liable for any service outages, technical failures, security incidents, data breaches, unauthorized access, or compromises that occur within or are caused by these third-party services and infrastructure providers.
User Notification Commitment
Notwithstanding the above limitation regarding third-party providers, in the event of a verified security incident or data compromise affecting third-party infrastructure that impacts user account information or personal data, CohiBox is dedicated to promptly investigating the incident and notifying affected users via their registered email address and/or public service notice without undue delay, in accordance with applicable data privacy laws including Republic Act No. 10173 (Data Privacy Act of 2012).
Limitation of Liability
To the maximum extent permitted by applicable law, CohiBox and its developers and affiliates shall not be liable for any indirect, incidental, special, consequential, or punitive damages, including but not limited to loss of data, loss of profits, or business interruption, arising out of or in connection with your use of or inability to use the Service, even if CohiBox has been advised of the possibility of such damages.
Philippine Consumer Protection
Nothing in these Terms limits any rights you may have under applicable consumer protection laws in the Philippines, including Republic Act No. 7394 (Consumer Act of the Philippines). Statutory rights granted to consumers under Philippine law remain unaffected by these Terms.
Governing Law & Dispute Resolution
Governing Law
These Terms shall be governed by and construed in accordance with the laws of the Republic of the Philippines, without regard to its conflict of law provisions.
Dispute Resolution
Any dispute, controversy, or claim arising out of or relating to these Terms or the Service shall first be attempted to be resolved through good-faith negotiation. If negotiation fails within 30 days, disputes shall be submitted to the appropriate courts of the Philippines, specifically in the courts of Metro Manila, with both parties submitting to the exclusive jurisdiction of such courts. For users outside the Philippines, the preceding jurisdiction clause applies to the fullest extent permitted by the user's local law.
Class Action Waiver
To the extent permitted by applicable law, you agree to bring any claim against CohiBox only in your individual capacity, and not as a plaintiff or class member in any purported class or representative proceeding.
Changes to These Terms
CohiBox reserves the right to modify these Terms at any time. When we make material changes, we will update the "Effective Date" at the top of this page and, where appropriate, notify you via email to the address associated with your account. Non-material corrections or clarifications may be made without notice.
Your continued use of the Service after the effective date of any modification constitutes your acceptance of the updated Terms. If you do not agree to the updated Terms, you must discontinue use of the Service and may request account deletion as described in Section 10.
Contact Information
If you have any questions, concerns, or requests relating to these Terms, your personal data, or your account, please contact CohiBox at:
Email: kent@cohibox.tech Service: CohiBox — www.cohibox.tech Operating Jurisdiction: Republic of the Philippines
For data privacy concerns specifically, you may also contact the National Privacy Commission of the Philippines
By using CohiBox, you accept these Terms
These Terms were last updated on August 28, 2026. Questions? Email kent@cohibox.tech.