Billing
Terms and DPA acceptance
Enterprise terms without the sales call. Both agreements are industry-standard Common Paper documents with our cover page in front, you read them in the product, an admin clicks accept, and you get a receipt with the exact text that was accepted, who accepted it and when.
The two documents
| Document | Key | What it is |
|---|---|---|
| Engram Cloud Service Agreement | terms | The contract the service is sold under: an Engram cover page carrying every business term, followed by the Common Paper Cloud Service Agreement Standard Terms, reproduced in full and unchanged. |
| Engram Data Processing Agreement | dpa | How we handle personal data in your documents, as the Common Paper Data Processing Agreement Standard Terms with our cover page. It is where the deletion promise in Data lifecycle and deletion is written down. |
Both are free to use under CC BY 4.0 and the attribution travels in the heading of the served text and on every receipt. Standing on a published standard is the point: your counsel has read these clauses before, so the only thing to study is our cover page and the prices.
The public summaries live at Terms of Service and Privacy Policy. The API serves the operative text.
Versions, and why they matter
An acceptance is a statement about one exact text, so text and version move together. The rule is bump, never edit: a published version is never reworded in place, because a receipt re-renders from the stored text and would otherwise start quoting words nobody agreed to. A new version asks the workspace to accept again, and the history of what you agreed to over time stays readable.
Both documents are currently version 2026-09-11-commonpaper-4, effective 2026-09-11.
Reading a document
Public, no account needed. A legal document that needs a login to read is not much of a legal document.
curl -s https://api.engramdynamics.org/legal/terms
curl -s https://api.engramdynamics.org/legal/dpa
{
"document": "terms",
"title": "Engram Cloud Service Agreement",
"version": "2026-09-11-commonpaper-4",
"effective_date": "2026-09-11",
"draft": false,
"text": "Engram Cloud Service Agreement\nVersion 2026-09-11-commonpaper-4. Effective 2026-09-11.\n..."
}
Accepting
Acceptance binds the whole workspace, so only a workspace admin can do it: a member cannot bind their employer. In the app it is Settings, Legal. Over the API, send the version you actually displayed:
curl -s -X POST https://api.engramdynamics.org/legal/accept \
-H "Authorization: Bearer <your key>" \
-H "Content-Type: application/json" \
-d '{"document": "terms", "version": "2026-09-11-commonpaper-4"}'
Sending a stale version is a 409 legal_version_stale naming the current one, so a page that has been open since before a bump cannot accept new text by accident. Accepting twice is idempotent and returns the acceptance that already exists rather than writing a second row.
To see where a workspace stands, including the one flag a banner should key off:
curl -s https://api.engramdynamics.org/legal/status \
-H "Authorization: Bearer <your key>"
{
"documents": [
{ "document": "terms", "title": "Engram Cloud Service Agreement",
"current_version": "2026-09-11-commonpaper-4",
"accepted_version": "2026-09-11-commonpaper-4",
"accepted_at": "2026-09-12T14:22:05Z", "accepted_by": "dana@acme.com", "current": true },
{ "document": "dpa", "title": "Engram Data Processing Agreement",
"current_version": "2026-09-11-commonpaper-4",
"accepted_version": null, "accepted_at": null, "accepted_by": null, "current": false }
],
"all_current": false
}
Any member can read the status. It carries no personal data beyond the name of whoever clicked.
The purchase gate
A workspace must have accepted the current version of every document before it can buy or change a paid plan. Both are part of what a plan is sold under, so accepting only the terms is not agreeing to the deal. Checkout and change-plan refuse with:
{
"detail": {
"error": "legal_acceptance_required",
"message": "A workspace admin needs to accept the Engram Data Processing Agreement first.",
"document": "dpa",
"version": "2026-09-11-commonpaper-4",
"accept_url": "/settings/legal"
}
}
The refusal names the first outstanding document so a client can send the admin straight to something to read. The billing portal is deliberately not gated, so an existing customer can always manage or cancel what they already bought.
Receipts
The receipt is what a signed copy would have been, and it is more useful: the same facts, as data you can diff, render or print.
curl -s https://api.engramdynamics.org/legal/terms/receipt \
-H "Authorization: Bearer <your key>"
It carries the accepted text in full, the version, the effective date, who accepted it and their email, the timestamp, the workspace name, and the IP address and user agent the acceptance came from. Tenant admin only, because it names an individual and the address they acted from. Every acceptance also writes a legal.accept row to the audit log.
Next
Checkout, portal and changing plans is the purchase itself, and Audit log is where the acceptance receipt lands alongside everything else that happened to your workspace.