Legal
Terms of Service
The terms governing your use of Weflayr.
Version 1.0 · Last updated 19 August 2026
Previous versions of these terms remain available at weflayr.com/terms/archive.
Weflayr SAS (“Weflayr”, “we”, “us”) operates the Weflayr platform, together with our website at weflayr.com, our APIs, dashboards, documentation and software development kits (the “Service”). These Terms of Service (the “Terms”) are a binding contract between you (“Customer”, “you”) and Weflayr governing your access to and use of the Service.
By ticking the acceptance box at sign-up, or by accessing or using the Service, you agree to be bound by these Terms, our Data Processing Agreement and our Privacy Policy (together, the “Agreement”). If you do not agree, you must not use the Service.
Weflayr SAS is a société par actions simplifiée registered at 12 place Henri Bergson, 75008 Paris, France. RCS Paris 103 332 649. VAT FR24 103 332 649.
The Service is offered to businesses. It is not offered to consumers.
Important principles
Weflayr’s mission is to give you full control over your unit economics and to help you continuously improve your margin per customer. It only works if it can see your real cost and your real revenue. That means trusting us with data that sits close to your business. These principles set out what we do with it, what we never do, and what stays under your control. They summarise sections 3 to 9 and do not replace them.
Your data is yours. You keep all rights to everything you send us. See sections 3 and 4.
You control whether prompt content leaves your application. Capture is on when you install the SDK, so that benchmarking and caching analysis work on your real traffic from day one. See section 5.
Benchmarking sends sampled prompts to third-party model providers. To compare cost and quality, we send samples of your captured prompts to different model providers. We publish which providers, and you can restrict the list or disable capture entirely; each provider applies its own terms. See section 6.
Everything we store, we store in the European Union. Our platform and our analytical database run in the EU. See section 9.
1. The Service
Weflayr is the margin optimization layer for AI companies. It links real revenue to real cost per customer and per feature, and identifies optimizations based on your actual usage. The Service currently includes:
- Observability. Capture of metadata about the AI calls your application makes, as described in section 3, matched against the revenue you upload or connect from your billing provider, and reporting on cost, usage and profitability per customer, per feature and per model.
- Model benchmarking. Comparison of alternative models against samples of your own prompts, evaluated by an automated judge, to show where a different model would preserve quality at lower cost. See section 6.
- Prompt caching. Recommendations on where caching would reduce your cost, and, on the plans where it is included, a managed cache operated by us. See section 7.
You connect your application to the Service through our SDKs.
We improve the Service continuously and may add, modify or discontinue features. Where we describe something as planned, in preview or in beta, it is not a commitment and is provided without warranty.
2. Eligibility and accounts
You must be at least 18 and use the Service lawfully. If you are agreeing on behalf of an organisation, you confirm you have authority to bind it.
To use the Service you must:
- create an account with accurate and complete information
- keep your account credentials and API keys confidential
- tell us immediately at security@weflayr.com if you suspect unauthorised access
- accept responsibility for all activity under your account, including that of your users
You are responsible for who you give access to, for the permissions you grant them, and for removing access when they no longer need it.
3. Your data
“Customer Data” means the data submitted to or generated by the Service under your account. It comprises:
- Call metadata, being the identifier you assign to your customer or user, the feature name or tag you assign, the model and provider used, consumption metadata such as input, output, reasoning and cached token counts, the cost computed from that consumption, and a timestamp.
- Revenue data, being the amounts you attribute to your customers, whether uploaded by you or read from your billing provider.
- Prompt and completion content, as described in section 5.
- Account, user and configuration data.
The authoritative list of fields, and how each is treated, is set out in Annex A of our Data Processing Agreement.
You choose the identifier. The Service does not require a name, an email address or any other direct identifier. You decide what value is passed in the customer identifier field, and we recommend an opaque or pseudonymous value. You are responsible for that choice and for the lawful basis for any personal data it contains.
Connecting your billing provider. You may provide revenue data by uploading it, or by connecting your billing provider. We currently support Stripe. To connect it, you create an API key in your own Stripe account and configure it in the Service.
Records read from your billing provider may contain personal data relating to your own customers, including names and email addresses. You are responsible for the lawful basis for that processing and for informing the individuals concerned where required.
You keep all rights in Customer Data. You grant us a non-exclusive, worldwide, royalty-free licence to host, store, process and transmit Customer Data solely to provide, secure and maintain the Service, to comply with a legal obligation, and as permitted by the Data Processing Agreement. This licence ends when the Agreement ends, subject to the deletion periods in section 9.
You confirm that you have the rights and the lawful basis necessary to send us Customer Data and to authorise the processing described in the Agreement.
You must not send us payment card data, government identifiers, children’s data, special category data within the meaning of Article 9 of the GDPR, or criminal conviction data within the meaning of Article 10.
4. What we do with your data
We use operational metadata, being consumption, cost, latency, model and outcome data, to operate, secure and improve the Service. We may also produce aggregated statistics from usage across our customers, for example benchmarks of cost per feature by category of application, to improve the Service and to publish market insights. Such statistics never identify you, your customers or any individual, and are never presented in a way that could.
We never sell, rent or licence Customer Data, including the content of your prompts and completions. We disclose Customer Data only to the providers we use to operate the Service, which are listed at weflayr.com/subprocessors, and where the law requires it.
Prompt and completion content is disclosed to model providers solely for the benchmarking described in section 6.
5. Prompt and completion content
The Service captures metadata about your AI calls. Capture of the text of your prompts and of the completions returned to you is on when you install the SDK, so that model benchmarking and caching analysis operate on your real traffic from day one rather than on samples you construct.
You control this, and the control runs in your own application. Setting capture_message_content to false in your SDK configuration strips prompt and completion content before anything is exported from your servers, ensuring it never reaches us. In that configuration, we receive metadata only.
You decide whether to leave capture enabled and what your application sends. You are responsible for the lawful basis for that content, for informing the individuals concerned where required, and for assessing whether a data protection impact assessment is needed.
You may change the setting at any time. Changes apply to subsequent calls. Content already captured is deleted in accordance with section 9.
6. Model benchmarking and third-party model providers
Model benchmarking compares alternative models using samples of your own prompts. It operates on the prompt content captured under section 5, and therefore does not operate where you have disabled capture.
What we send. We send samples of captured prompts to model providers, receive their outputs, and evaluate those outputs with an automated judge to compare quality and cost.
Which providers. Benchmarking runs on Amazon Bedrock, within the European Union. Some models are not available there. We reach those through our gateway provider, and we publish which ones. The models we benchmark against, their hosting region and their provider position on retention and training are published at weflayr.com/subprocessors.
Transfers outside the European Union. Where a permitted provider is established outside the European Union, transfers are covered by Standard Contractual Clauses or by an adequacy decision. To keep benchmarking within the European Union, restrict your list to providers published as EU-hosted.
Benchmark results are estimates based on samples. They do not guarantee that a change of model will reduce your cost or preserve your quality in production. You remain responsible for deciding which model to use.
7. Prompt caching
On all plans, the Service identifies where caching would reduce your cost and reports those opportunities. Acting on a recommendation is your decision, and you are responsible for the effect on your application.
On the plans where a managed cache is included, we store cache entries and serve them in response to matching requests. Cache entries are stored in the European Union, expire automatically, and can be disabled by you at any time. A cached response reflects the state of the model and the prompt at the time the entry was created. You are responsible for deciding whether cached responses are appropriate for your use case, and no managed cache is created while prompt capture is disabled.
8. Availability and support
We monitor the Service continuously and work to keep it available. We do not guarantee uninterrupted availability unless a service level agreement is agreed in writing with you.
We may carry out maintenance and will give notice where it is likely to affect you.
Support is available at support@weflayr.com. We aim to respond within one business day.
9. Where we store your data, and for how long
All Customer Data stored by us is stored in the European Union. The table below matches Annex A of our Data Processing Agreement.
| Category | Retention |
|---|---|
| Telemetry, cost and revenue data | For the term of your subscription, then deleted within 30 days of its end |
| Prompt and completion content, unless you disable capture | For the term of your subscription, then deleted within 30 days of its end |
| Benchmark samples, provider outputs and judge results | For the term of your subscription, then deleted within 30 days of its end |
| Managed cache entries, where included in your plan | Until the cache entry expires |
| Account, configuration and user information | For the term, then deleted within 30 days of its end |
| Security and access logs | 12 months |
| Billing records and accounting documents | 10 years, as required by article L123-22 of the French Commercial Code |
Encrypted backups are retained for 30 days and replicated within the European Union. Where content is stored, it can persist in backups for up to 30 days after the retention period above has expired, and for up to 30 days after deletion on termination.
Where prompt capture is disabled we hold no prompt or completion content and are therefore unable to search for, extract, rectify or delete such content.
10. Sub-processors
The providers we use to operate the Service are listed at weflayr.com/subprocessors, with their location and role.
Adding or replacing a provider. We will give you at least thirty days notice before we engage a new provider or replace an existing one. If you reasonably object on data protection grounds, you may tell us within that period, and we will either propose an alternative or you may terminate the affected part of the Service without penalty.
Models used for benchmarking. We reach model providers through Amazon Bedrock and, for models not available there, through a gateway provider. Both are listed as providers and covered by the notice above. The individual models we benchmark against sit behind them. We publish them and keep the list current, and we may add or remove a model without individual notice, since doing so engages no new provider and changes only which models a sample is compared against.
You may restrict benchmarking to a subset of the published models, or disable prompt capture entirely, at any time.
11. Security
We maintain an information security management system aligned with ISO/IEC 27001 and SOC 2 Type 2 and implement the technical and organisational measures set out in Annex C of our Data Processing Agreement.
This includes encryption in transit and at rest, role-based least-privilege access with multi-factor authentication, logical isolation of customer data, storage of any credentials you provide for a connected integration in a managed secret store, continuous control and threat monitoring, dependency scanning on every change, and an annual application penetration test by an independent third party, with a summary available under a non-disclosure agreement.
Our current security posture, our certification and audit status, and the position of each sub-processor are published at trust.weflayr.com. We make no representation of certification beyond what is stated there.
No system is completely secure, and we cannot guarantee absolute security.
12. Security incidents
If we become aware of a personal data breach or of a security incident affecting your data, we will notify you without undue delay and in any event within forty-eight hours of becoming aware of it.
We notify your registered account email address. Our notification will describe the nature of the incident, the categories of data affected, the likely consequences and the measures taken or proposed, to the extent then known, and will be supplemented as the investigation progresses. We will cooperate with you and with the relevant authorities and provide reasonable assistance with your own notification obligations.
13. Data protection
Our Data Processing Agreement is incorporated by reference into and forms part of these Terms. It applies to every customer in the version current at the time of your use, and it does not require separate signature to be binding. We do not negotiate amendments to it other than as part of a master services agreement signed by us. Where the Data Processing Agreement and these Terms conflict on a data protection matter, the Data Processing Agreement prevails.
Where you have signed a separate data processing agreement with us that agreement applies in place of our standard Data Processing Agreement for as long as it remains in force.
Our Privacy Policy explains how we handle personal data for which we are the controller, including the data of your administrators and of visitors to our website.
14. Plans, trial and fees
Plans, prices, usage allowances and billing frequency are those published on our pricing page and shown in the Service when you select your plan, or those agreed in writing between us.
Free trial. Where we offer a free trial, it is limited to one per organisation, may be subject to verification, and may be modified or withdrawn at any time. At the end of the trial your plan converts to the paid plan you selected, or your access ends.
Monthly plans. Monthly plans renew automatically and you may cancel at any time with effect from the end of the current billing period. Cancellation stops future billing; fees already paid for the current period are not refunded.
Annual plans. Annual plans renew unless either of us gives notice before the end of the current period.
Payments are processed by Stripe, whose own terms apply to that processing. Fees are exclusive of VAT and other applicable taxes.
Late payment. In accordance with article L441-10 of the French Commercial Code, any sum unpaid on its due date bears interest at the European Central Bank refinancing rate plus ten percentage points, applied automatically and without prior notice, together with a fixed indemnity for recovery costs of forty euros per invoice. Where recovery costs exceed that amount, we may claim the excess on production of supporting evidence. If an invoice remains unpaid after we have notified you, we may suspend the Service after reasonable notice.
15. Usage limits
We may apply technical limits to protect the Service and other customers, and we will tell you before applying a limit that materially affects you, except where immediate action is needed.
You must not circumvent usage limits, including by creating multiple accounts.
16. Acceptable use
You must not use the Service to break the law, to infringe anyone’s rights, to send data you have no right to send, to attempt to access another customer’s data, to probe, scan or disrupt the Service or its security measures without our permission, to circumvent usage limits, or to resell access without our written consent.
You must not use the Service, or the data and benchmarks it produces, to develop a competing product.
You are responsible for the acts and omissions of your users. We may suspend an account that puts the Service or other customers at risk, and we will tell you why.
17. Our intellectual property
The Service, including its software, models, design and documentation, is owned by Weflayr or its licensors. You may use it while your subscription is active, and not otherwise. We reserve all rights not expressly granted.
You must not copy the Service, reverse engineer or attempt to derive the source code or logic of our routing, benchmarking, evaluation or optimization models, or systematically extract our benchmark data or cost intelligence.
Our SDKs are open source and licensed separately under the Elastic License 2.0, which has only three high-level limitations. You cannot:
- provide the products to others as a managed service
- circumvent the license key functionality, or remove or obscure features protected by license keys
- remove or obscure any licensing, copyright or other notices
18. Feedback
If you give us suggestions or feedback about the Service, you grant us a perpetual, irrevocable, royalty-free licence to use and incorporate it without restriction or obligation to you.
19. Confidentiality
“Confidential Information” means non-public information disclosed by one of us to the other that is identified as confidential or that a reasonable person would understand to be confidential. Our Confidential Information includes the non-public aspects of the Service and our product plans.
Each of us will protect the other’s Confidential Information with at least reasonable care, use it only in connection with the Agreement, and limit access to those who need it and are bound by equivalent obligations. This does not apply to information that is or becomes public without breach, was already lawfully known, is lawfully received from a third party, or is independently developed. Either of us may disclose where compelled by law, giving prior notice where legally permitted.
20. Warranties and disclaimers
We provide the Service with reasonable skill and care.
Beyond that, and to the fullest extent permitted by law, the Service is provided as is and as available, without other warranties, express or implied.
We do not warrant that the Service will be uninterrupted or error-free, that any benchmark, recommendation or estimate will be accurate or will produce a saving, or that any output obtained from a model provider will be accurate or fit for any purpose. You are solely responsible for evaluating recommendations and for deciding what to change in your production systems.
Nothing in the Agreement excludes or limits liability that cannot be excluded or limited by law, including for fraud, for wilful misconduct, or for death or personal injury caused by negligence.
21. Limitation of liability
Neither of us is liable for indirect or consequential loss, or for loss of profits, revenue, data, goodwill or business opportunity, however caused.
Our total aggregate liability arising from or in connection with the Agreement, whether in contract, tort or otherwise, shall not exceed the greater of five hundred euros and the fees you paid us in the twelve months preceding the event giving rise to the claim.
The limits in this section are aggregate limits covering all claims under these Terms and under any data processing agreement between us, whether our standard Data Processing Agreement or one signed separately, taken together. Neither a data processing agreement nor any separately agreed pricing creates a separate, additional or increased cap unless expressly agreed in a master services agreement signed by us.
These limitations reflect the allocation of risk between us and form an essential part of the bargain.
22. Indemnity
You will defend us against claims arising from your use of the Service in breach of the Agreement, from Customer Data that infringes third-party rights or breaches applicable law, and from your users’ acts and omissions.
We will defend you against claims that the Service infringes a third party’s intellectual property rights, provided you tell us promptly, let us control the defence, and give us reasonable cooperation. This does not cover claims arising from Customer Data or from a model provider’s output.
23. Term, termination and deletion
The Agreement runs from your acceptance until terminated in accordance with this section.
You may close your account at any time from the dashboard or by emailing support@weflayr.com. Either of us may terminate for material breach that is not remedied within thirty days of written notice. We may suspend or terminate where required by law.
Fees are payable for the full billing period in which termination takes effect. On a monthly plan, cancellation takes effect at the end of the current month and the fees for that month are not refunded or prorated. On an annual plan, cancellation takes effect at the end of the current annual period and the fees for that period are not refunded or prorated, whether paid upfront or in instalments. You retain access to the Service until the end of the period you have paid for. This does not apply where you terminate for our material breach, or where a refund is required by law.
On termination, your access ends and we delete Customer Data within thirty days, with encrypted backups rolling off within a further thirty days. If you ask us before that period expires, we will export your data in a commonly used machine-readable format, and we will confirm deletion in writing on request. We retain data beyond these periods only where the law requires it, in particular the accounting records referred to in section 9.
24. Changes to the Service and to these Terms
We may update the Service or these Terms. Where a change materially affects you, we will give you at least thirty days notice by email or in the product before it takes effect, and we will state at the top of these Terms what has changed. Continuing to use the Service after the effective date means you accept the change. If you object, you may terminate under section 23.
25. General
The Agreement, comprising these Terms, the Data Processing Agreement, the Privacy Policy and any pricing separately agreed in writing between us, is the whole agreement between us and supersedes all prior agreements on its subject matter. Where you have signed a master services agreement with us, that agreement prevails over these Terms in the event of a conflict.
If a provision is held unenforceable, the rest continues to apply. A failure to enforce a provision is not a waiver of it.
Neither of us is liable for delay or failure caused by events beyond reasonable control.
26. Governing law
The Agreement, and any dispute or claim including non-contractual disputes, is governed by French law. The competent courts of Paris, France have exclusive jurisdiction.
27. Contact
Weflayr SAS, 12 place Henri Bergson, 75008 Paris, France
Our current security and certification status is published at trust.weflayr.com.