Terms & Security
Last updated August 2026
1. Acceptance of Terms
By joining the BashIn waitlist, using the BashIn overlay, or otherwise accessing this site, you agree to these Terms. If you don't agree, please don't use the product or site.
2. Early Access / Beta Status
BashIn is in active early-access development. Features change, break, and get removed without notice. The product is provided "as is" and "as available," without warranty of any kind, express or implied — including fitness for a particular purpose or non-infringement.
3. Waitlist & Account Data
Joining the waitlist requires only an email address. We use it to:
- Notify you about early access and product updates
- Understand demand and prioritize development
We do not sell or rent your email to third parties. You can ask to be removed at any time by emailing us (see Section 7).
4. Acceptable Use
Don't use BashIn or this site to violate any law, attempt to gain unauthorized access to our systems, scrape or bulk-extract data, or interfere with the service's normal operation.
5. Intellectual Property
The BashIn name, logo, product design, and site content belong to BashIn. Nothing in these Terms transfers ownership of that to you.
6. Limitation of Liability
To the maximum extent permitted by law, BashIn is not liable for indirect, incidental, or consequential damages arising from your use of (or inability to use) the product or site, including during the early-access period described in Section 2.
7. Changes & Contact
We may update these Terms as the product evolves; the "last updated" date above will reflect that. Questions or requests (including data removal): aranyabandhu2004@gmail.com.
Security & Data Scrutiny
A concrete look at how BashIn handles data today, not a generic policy template:
- Transport: all traffic to bashin.live and its API runs over HTTPS/TLS.
- Waitlist data: only an email address and signup timestamp are stored — no passwords, no payment details, nothing else.
- Admin dashboard: gated by a password known only to the BashIn team; sessions use short-lived signed tokens (12h) verified server-side on every request, not stored in a cookie or long-lived session.
- Least exposure: only the "Watch It Work" project list is publicly readable; waitlist signups and dashboard write actions require a valid admin token.
- Local-first product design: the BashIn overlay itself keeps learning and pattern data on your machine by default — nothing leaves your device without an explicit export, independent of this website's own data handling above.
Found a security issue? Please report it responsibly to aranyabandhu2004@gmail.com rather than disclosing it publicly — we'll respond as quickly as we can.