Honest Robin is still in development, and nothing here is binding yet. It becomes binding when it goes into our terms of service, which aren’t written yet. Several things this page mentions don’t exist yet either: the company itself, the hosted version, the price list, the status page, the privacy policy, the data processing agreement, our public goals, the page about our tools that read the public web, the rules all our agents share, and the public history of this page. Others are built in Time and reach you with its first release: the Move out button, a changelog, a way to reach a person for help, and the list of companies that handle your data. Each product’s ledger says exactly what’s built: Time’s is PROMISES.md. Where something isn’t decided, the page says so instead of guessing.
This page is the minimum for every Honest Robin product. Each product also has a charter, which can promise more than this page but never less. Products earn money in different ways (Time charges per person; Credits may charge by volume), and every way has to keep these promises.
How a promise is written
A promise is worth what stops us breaking it, and code alone can’t do that: whoever runs a database can remove a check from it. So every promise here and in the charters says three things:
- Guarded by
- The code and tests that stop it breaking by accident. They also mean that breaking it on purpose takes a change anyone can see in the public code, not a quiet switch.
- Binding on us
- What makes breaking it on purpose a breach: the terms of service, the licence, and a change-of-control clause that binds whoever buys us.
- If we break it anyway
- What you can still do. Leave with all your data, run the same software yourself, and point to the dated record.
Where a part doesn’t exist yet, the product says so. Each product keeps a public ledger of every promise it makes and what keeps it today: a named test, code without a test, how we work, or nothing yet. We never call a check in code a guarantee.
1. The deal doesn’t change after you move in
Your price stays the same for as long as your subscription runs. Features you have don’t move to a more expensive plan. When we change a plan, the change applies to new subscriptions; yours stays as it was unless you choose to move.
Nothing you use disappears quietly:
- A feature you use is never removed without 90 days’ notice and a way to keep it: the older version on your own server, or your data in an export.
- Each version of a product’s API keeps working for at least 12 months after the next one comes out.
- Changes to how you work are in the changelog before they ship.
- Guarded by
- Each subscription stores the price and plan it started on, and the product refuses to raise them. Features and the API: a public, dated changelog and the code’s history. The changelog is to build in each product.
- Binding on us
- A price-lock clause in the terms of service, which also hold the notice periods.
- If we break it anyway
- Your own receipts show the locked price, so a rise shows up on your bill. Every older version stays open source, so you can keep running it. Cancel and take everything with you (see “You can always leave”).
2. No surprise bills
- The price list is public and complete, and nobody pays more than it says.
- Special deals can happen, for a nonprofit or a very large team, say, and we’re open that they exist. Anyone can ask for one. Who has one stays private: that’s their business, not other customers’.
- No hidden fees. What we pay a third party on your behalf, such as delivering an e-invoice over a network, is passed on at cost and shown on the bill.
- You see the exact amount before you are charged.
- You never pay for use that hasn’t happened yet. A person counts from the moment they can sign in, not from the invitation, and a price that grows with use charges for what was used.
- If a price grows with use, you can see the meter, you can set a cap, and we never charge past it without asking you first.
- Changes to the price list are announced and dated at least 30 days before they apply.
- Guarded by
- The amount you’re shown and the amount you’re charged come from the same calculation, and caps are checked before a charge.
- Binding on us
- The terms of service and the published, dated price list.
- If we break it anyway
- The itemised bill is your evidence.
3. You get the whole product
The self-hosted edition is the same software, with every feature and no limits. Two-factor sign-in, audit logs, export and the API come with every plan, and are never sold as an upgrade. The same goes for single sign-on, once a product has it. Plans may differ in how much they include, in the infrastructure we run for you and in how fast support answers, but never in what the software can do.
The cloud has one thing self-hosting doesn’t: us running it for you. Everything else is open to both:
- A paid service we contract (such as sending e-invoices over a network): self-hosters plug in their own provider.
- A service that works only by pooling many customers’ data (such as spotting abuse across customers): self-hosted installs can connect to it on the same terms as the cloud. Joining is opt-in, and what’s shared is counts, never people (see “Your data works for you”).
- Guarded by
- A test in each product that fails if the editions differ.
- Binding on us
- The open-source licence (see “You can always leave”), so the self-hosted code is the whole code. The terms of service list what the cloud does for you that self-hosting doesn’t: running it.
- If we break it anyway
- The public code shows anything held back, and anyone may add it to their own copy.
4. You can always leave
Move out, in one step. Every product has a Move out button, on every plan and in every state of an account. It asks no questions, and it gets you ready to leave:
- everything you have with us in one download, in open formats, with the documents you must keep (such as your invoices) as files you can open;
- where you can go next: the same software on your own server, and files that other tools can import;
- a list of everything still connected (other services, access tokens, links your own customers use) and how to end each one.
Moving out changes nothing in your account. Cancelling and deleting are separate steps, and you choose them.
- Cancel in the app, in two clicks. Pay monthly or yearly, your choice; no plan is yearly-only.
- A full export in open, documented formats works on every plan and in every state, including free, unpaid and cancelled accounts, for at least 12 months after an account lapses.
- The export imports into a self-hosted instance, so leaving our cloud doesn’t mean starting again.
- The code is open source, with no contributor licence agreement: the AGPL for anything that runs as a server, and the MIT licence for libraries that run inside other people’s software.
- Guarded by
- Export tests that fail when something new isn’t exported, and a test that imports an export into a fresh account. Move out: to build in each product, with a test that it works in every state of an account.
- Binding on us
- The licence: every released version stays open source, whatever happens to us. The terms of service, for export and cancelling.
- If we break it anyway
- Released code can’t be taken back. Anyone can keep running and fixing it.
One limit, stated plainly: while one person holds all the copyright, they could publish future versions under a different licence. That stops being possible once contributors hold copyright in the code, because every one of them would have to agree.
5. Your data works for you
- We collect what the product needs, and nothing more.
- No ads. We never sell your data or share it for anyone’s marketing.
- Your data never trains AI models, ours or anyone else’s. When a feature uses AI, your data goes only to providers who are contractually barred from training on it, and only to do what you asked.
- By default we only count visits: without cookies, without following you to other sites, and never who you are. Anything more, such as how an account uses a product, is off until you turn it on. If you do, it helps us decide what to build next. If you don’t, that’s fine with us, and nothing changes for you. What we count, and every company that handles your data for us, is named in the privacy policy.
- A self-hosted instance sends us nothing unless its owner turns it on.
- You can have your data deleted.
You see all of it. Every number about your account, and about how your team uses the product, is yours. The ones you need day to day are in the product; the rest are in the API and the export. If you need one we haven’t made available, ask, and we’ll get it to you. Then we build it into the product, so everyone has it, not only you: no one-off exceptions, and no numbers kept back for a more expensive plan (see “You get the whole product”). We hold back only what would harm someone: other people’s data, and security details.
- Guarded by
- Tests that the self-hosted edition sends nothing, and that our products load no analytics script, store nothing in your browser to follow you, and send page views that carry neither the account nor the person. Our websites load only Cloudflare’s cookie-free counter; QR’s tests check it, the website’s don’t yet. Export tests that fail when stored data is left out (see “You can always leave”), so nothing we keep about your account is out of reach.
- Binding on us
- The privacy policy and the data processing agreement, and the terms of service for access to your numbers and the ban on training AI.
- If we break it anyway
- Export and delete, or run it yourself. The privacy law where you live may give you more.
6. We tell you the truth
This is what honest means here:
- No lies. What we say is true, and nothing is worded to leave a false impression.
- Nothing shady. No tricks in the product (see “It’s a joy to use”), no hidden fees (see “No surprise bills”), no fake urgency, no invented testimonials, no inflated claims. Comparisons with other products are factual and dated.
- A straight answer to a straight question. Ask us about the product, the price, your data or how the software is made, and you get the plain answer, also when it doesn’t flatter us. What we keep back is what protects your data: nobody learns anything about another customer, and a security problem stays private until it is fixed.
It doesn’t mean listing our weaknesses unasked.
What affects you, you hear from us without asking:
- Prices and limits are stated plainly, with numbers where there are numbers.
- A status page shows real uptime, and every outage gets a public write-up that says what we got wrong.
- Our plans are public: what we’re working on now, next and later, in order but without dates, and our current goals. When a goal ends, we say how it went: reached, missed or dropped, and why. Plans aren’t promises; this page is.
- How our software is made, including the AI that writes most of it (see “You can see how it’s made”).
- No fake accounts. Every reply, review or post about our products comes from a real, named person who says they make them. No other accounts, no paid posts in disguise, no bots posing as people.
- Our tools that read the public web say who they are, and a public page says what they read, keep and never do, before they read anything.
- Guarded by
- Little beyond habit, and we say so. The public record helps: every commit says who wrote it, and the status page is fed by automatic checks, not typed by hand.
- Binding on us
- Nothing beyond the law against misleading customers.
- If we break it anyway
- The public record (code history, status history, write-ups) is where you’d catch us, and “You can always leave” and “If we’re sold or shut down” are what you can do about it.
7. Your customers get the same deal
Some products help you charge or serve your own customers. Those products make the promises on this page the easy default for your customers too:
- they can see their balance and what they’re being charged for, as it happens;
- every charge can be explained;
- nothing expires or gets more expensive without notice;
- a plan change leaves existing customers where they are unless they choose to move.
We don’t build features whose purpose is to do to your customers what this page forbids us to do to you. It’s your business, and you can choose otherwise; the product makes the honest path the default and says plainly when you leave it.
- Guarded by
- The product’s defaults, and tests on them.
- Binding on us
- The product’s charter and documentation.
- If we break it anyway
- The defaults are in the open code, for anyone to read.
8. If we’re sold or shut down
The reason to distrust a tool like this is simple: the company gets sold, and the new owner raises prices and cuts corners. Here is what would happen to you, your data and the code.
Who we answer to. Who owns Honest Robin and who funds it is public. We take outside money only from someone who agrees to be bound by this page, and we say who it is when it happens.
Released code can’t be taken away. Every product is open source with no contributor licence agreement, so contributors keep their own copyright. Every released version stays available under its licence forever. If we stopped tomorrow, anyone could keep running, fixing and hosting it.
Your data can always leave. A full export works on every plan and edition, including free and lapsed accounts, and imports into a self-hosted instance, so moving off our cloud doesn’t mean starting again.
If a cloud service shuts down:
- We tell every account owner by email, and on the sign-in page, at least 6 months before the service stops.
- Until that date the service runs as normal. After it, accounts stay readable and exportable for 12 months.
- We publish a guide for moving to a self-hosted instance, and paid time not yet used is refunded.
If the company or a product is sold:
- Your locked price stays locked. The price lock is a clause in the terms of service, and the buyer takes on the terms.
- These commitments are part of the terms, with a change-of-control clause, so they survive a sale.
- Released code stays open. A buyer gets the name, the cloud service and the customers’ contracts.
What a buyer could still change: list prices for new customers; the roadmap, the support and how much is invested; the licence of future versions, while one person holds all the copyright; and the name, which goes with the company. If any of that goes badly, the exit is the same: export your data and run the same software yourself, or with someone else.
- Guarded by
- The export, which each product tests in every state of an account, and the open code. Nothing in code can keep a notice period or bind a buyer.
- Binding on us
- The terms of service, with the change-of-control clause, and the licence.
- If we break it anyway
- Export your data and run the same software yourself (see “You can always leave”). Released code can’t be taken back.
9. It’s a joy to use
Work software can be serious and still be a joy to use. Honest Robin products should be quick, clear and friendly, and a little playful: there is a robin for company, and the words sound like a person talking. They are professional tools, never toys. We handle your time, money and data with care. When something goes wrong, our words are plain and serious.
Much of the joy is in what isn’t there:
- No tricks. No fake urgency, no buttons that try to make you feel guilty (“No thanks, I like wasting time”), no pre-ticked boxes, no hidden way out, no repeated requests to upgrade.
- No noise. No emails or notifications that exist only to bring you back to the product. We send only the ones you would want, and you can turn off each kind.
- No corporate language. Short sentences and plain words. When there is humour, it never makes fun of you.
- No AI without a reason. An AI feature has to save you real work. It’s labelled, you can turn it off, and it never writes or sends anything as you before you have seen it.
- Nothing in the way. The most common task takes one step. Everything else takes one step to reach, and never gets in the way of that task.
A person answers. When you need help, a person is one step away.
- An AI assistant may answer first, as a best effort. It says it’s an AI, and you can skip it and go straight to a person, at any time, in one step. We trust you to know when you need one (see “We trust you too”).
- No bot ever pretends to be a person.
- Every request gets an answer: yes, no or later, and why.
- Help with anything we broke is free, on every plan.
- Guarded by
- Mostly taste. Each product’s design review checks new screens against this list. The list is public, so anyone can compare a screen with it. The way to a person: to build in each product, one step from every help screen, with a test that checks it.
- Binding on us
- Nothing beyond the consumer-protection law where you live, which forbids some of these tricks, and the terms of service for help with what we broke.
- If we break it anyway
- Tell us. A trick of this kind is a bug: we remove it, or say publicly why we won’t. “You can always leave” is what you can do if we don’t.
10. We trust you too
You trust us not to change the deal. In return, we make your side of the deal easy to keep. Where the product can keep a limit for you, it does. Where it can’t, it shows you the numbers. Where neither is possible, we trust you.
- Limits are kept at the moment you act. Where the product can check a limit when you do something, it checks it then. For example, when you add a person beyond your plan, the product asks you to move to a bigger plan first and shows the price. Moving takes one step. Nothing you already have ever stops working.
- You can always see your use and your limits. The product measures every limit a plan sets and shows it to you, live, from the same numbers we bill on. It warns you when you get close. A limit the product can’t measure doesn’t go in a plan. Nobody should break an agreement because they could not see the limit.
- Where keeping a limit would cause harm, we trust you. Some limits could only be kept by stopping something that is already running, such as the service your own customers use. We never keep a limit that way. When you pass one, nothing stops working, and nothing is charged that you didn’t choose. We tell you once, with the numbers and the plan that fits; after that it’s shown plainly where you manage billing, and nothing reminds you (no repeated requests: see “It’s a joy to use”). Moving to a bigger plan takes one step, and we never charge extra for the time before you moved. If it goes on for three months, a person writes to you, never a bot, and there is never a series of reminders.
- The last resort, if it still goes on after that conversation: we may end the cloud service for you with 90 days’ notice, and help you move to self-hosting, which is free and has every feature (see “You get the whole product”). Nothing is cut off before then, and your export works throughout (see “You can always leave”).
- Not covered here: what happens when you stop paying for a plan. “You can always leave” and “If we’re sold or shut down” say what happens then.
- Guarded by
- The limits and the measurements are in code: each product keeps what it can at the moment you act, and shows use against the plan from the numbers it bills on. The trust is not in code. Each product counts how many accounts outgrow their plan and how many move up (counts, never people), so we can see whether trust works.
- Binding on us
- The terms of service, which also say what each plan covers, so the trust rests on a clear agreement.
- If we break it anyway
- Self-hosting is free and complete, so leaving costs you only the work of moving.
11. Your data’s home is Europe
Honest Robin is made in Europe, for everyone. Our products are global; the data they hold lives here.
- Stored in Europe. Your data is stored on servers in the European Union, run by a European company.
- Every company that touches your data is listed. Each product publishes the list, with each company’s country and what it does, including the ones that aren’t European and why we still use them. Nothing touches your data that isn’t on the list.
- Where we’re heading: no American company in the path of your data, because American law can require an American company to hand over data wherever it’s stored. We aren’t there yet, and each product’s list says exactly how far we are. We replace a provider when a European one serves you as well, and say so when we do.
- Your choice, completely: self-hosting runs everything where you decide, with the providers you choose (see “You get the whole product”).
- Guarded by
- Each product’s list is checked against the outside hosts its code is allowed to reach, so a new provider can’t be added quietly. To build in each product.
- Binding on us
- The privacy policy and the data processing agreement, which name the same companies.
- If we break it anyway
- The list is public and dated, so you can see the change; export your data, or self-host (see “You can always leave”).
12. You can see how it’s made
Claude, Anthropic’s AI, writes most of our code. Software made by AI is easy to hide and hard to check, so we make ours easy to check.
- Every product says it’s made with AI.
- The standing rules our AI agents work by are public, word for word: the instructions every agent is given before it starts work. What we keep back is what protects people: customers’ data, security details and personal details.
- Every change in the code says who or what wrote it.
- Each product’s ledger says what keeps each of its promises today, and a check fails when a test it names disappears.
- Before every release, a named person says what they checked and what they didn’t.
A rule is what an agent is given, not proof of what it does. That’s what the checks are for.
- Guarded by
- The public repositories. The rules are files the agents read, and every commit names its author. To publish: the rules every product shares; today only Time’s own are public.
- Binding on us
- Nothing beyond habit, and we say so.
- If we break it anyway
- The code and its history are public, so anyone can see what changed and who wrote it. Then take everything with you (see “You can always leave”).
Changing this page
- Every change is dated and kept in a public history.
- A change may add protections at any time.
- A change that removes or weakens a protection applies only to people who join after it, and is announced at least 30 days before it applies. Everyone else keeps the version they joined under.
- A product charter can add promises. It can’t weaken an article.
What we can’t promise
- That list prices for new customers never change.
- That a cloud service runs forever. “If we’re sold or shut down” says what happens if it doesn’t.
- That our cloud runs exactly the public code. We can build it from the public repository and show which version runs, but you’d still be taking our word for it. Lying about it would be a deliberate act, and a provable one.
- That we never get things wrong. When a mistake of ours affects you, we tell you.
Products
- Honest Robin: Time
- Version 1 is built. A test instance runs; it isn’t open to testers yet. More about Time