Terms of Service
The Cinder Project Effective Date: June 27, 2025 Last Updated: June 29, 2025
1. Acceptance of Terms
By accessing or using any website, tool, software, or service provided by The Cinder Project (collectively, “the Services”), you agree to be bound by these Terms of Service (“Terms”). If you do not agree, please do not use the Services.
These Terms apply to all projects under The Cinder Project umbrella, including but not limited to:
- CPAC — the Cinder Package Auditing CLI
- CPAC Trust DB — the crowd-sourced package trust database
- The Cinder Project website at
thecinderproject.qd.jeand any associated subdomains
2. Nature of the Services
The Cinder Project provides free, open-source software and associated web services. Nothing in these Terms creates a paid subscription, service-level agreement, or commercial relationship between you and The Cinder Project.
All software is provided under its respective open-source license(s), which govern your rights to use, modify, and distribute the software. These Terms govern your use of the hosted website and web services only — not your rights under the open-source licenses themselves.
3. Eligibility
You may use the Services if you are legally capable of entering into a binding agreement under applicable law. If you are under 18 years of age, you represent that you have parental or guardian consent to use the Services.
4. Acceptable Use
You agree not to:
- Use the Services to upload, submit, or distribute malicious, fraudulent, or deceptive content
- Attempt to gain unauthorized access to any part of the Services or their underlying infrastructure
- Submit false, fabricated, or misleading package data to CPAC Trust DB
- Use automated means to scrape, crawl, or overload the Services in a way that disrupts availability for others
- Impersonate any person or entity or misrepresent your affiliation with The Cinder Project
The CPAC Trust DB is crowd-sourced. You are responsible for the accuracy of any data you contribute. Knowingly submitting false hashes, fabricated PKGBUILDs, or misleading trust records is a violation of these Terms.
Volunteers who submit advisories are subject to a reputation system. Repeated rejected submissions may result in account suspension. Volunteers with zero submissions for 30+ days may also be suspended. Suspended accounts have a 7-day appeal window via Discord.
Email addresses collected for notification purposes are used solely for weekly advisory reports and account-related communications. You may request account deletion at any time.
5. Third-Party Services
The Services load resources from third-party providers. By using the Services, you acknowledge that your browser will make requests to:
- Google Fonts (
fonts.googleapis.com) — for font loading on all pages - Unpkg CDN (
unpkg.com) — for the Lucide icon library - jsDelivr CDN (
cdn.jsdelivr.net) — on the donate page only - Supabase (
supabase.co) — for read-only access to the CPAC Trust DB
These third parties may collect standard HTTP metadata (IP address, User-Agent, Referrer) as part of normal network requests. The Cinder Project does not control how these third parties handle that data. Please refer to their respective privacy policies for details.
Additionally, email notifications are sent via Resend (resend.com) from no-reply@thecinderproject.qd.je. Resend receives your email address and the content of the email. Please refer to Resend’s Privacy Policy for details.
6. CPAC Install Scripts
CPAC install scripts may check whether build dependencies are already present on your machine. This check is performed locally only — the result is never transmitted to The Cinder Project or any third party. No telemetry is sent back from install scripts.
7. Intellectual Property
The Cinder Project name, logo, and brand identity are the property of The Cinder Project. The underlying software is open source and governed by its respective license(s) as published in each project’s repository.
You may not use The Cinder Project’s name or branding in a way that implies official endorsement without prior written permission.
8. Disclaimer of Warranties
THE SERVICES ARE PROVIDED “AS IS” AND “AS AVAILABLE” WITHOUT ANY WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, OR NON-INFRINGEMENT.
THE CINDER PROJECT DOES NOT WARRANT THAT:
- THE SERVICES WILL BE UNINTERRUPTED OR ERROR-FREE
- ANY PACKAGE DATA IN CPAC TRUST DB IS ACCURATE, COMPLETE, OR SAFE
- THE SERVICES ARE FREE FROM SECURITY VULNERABILITIES
USE OF ANY SOFTWARE OR DATA FROM THE CINDER PROJECT IS AT YOUR OWN RISK.
9. Limitation of Liability
TO THE FULLEST EXTENT PERMITTED BY APPLICABLE LAW, THE CINDER PROJECT AND ITS CONTRIBUTORS SHALL NOT BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES ARISING OUT OF OR RELATED TO YOUR USE OF THE SERVICES, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.
THIS INCLUDES, WITHOUT LIMITATION, DAMAGES ARISING FROM RELIANCE ON PACKAGE TRUST DATA, SYSTEM CHANGES MADE BY INSTALL SCRIPTS, OR ANY SECURITY INCIDENT RELATED TO PACKAGES AUDITED THROUGH CPAC.
10. Governing Law
These Terms are governed by the laws of India. Any disputes arising out of or relating to these Terms shall be subject to the exclusive jurisdiction of the courts located in India.
11. Changes to These Terms
We may update these Terms from time to time. When we do, we will update the “Last Updated” date at the top of this document. Continued use of the Services after any update constitutes acceptance of the revised Terms.
12. Contact
For questions about these Terms, please open an issue on the relevant project repository or reach out via the contact information listed on the website.
The Cinder Project is an open-source project. These Terms exist to set clear expectations — not to be adversarial. Build cool things.