al.ink
Yiwen AI Limited (億文智能有限公司)

Terms of Service

Last updated: 2026-08-03
This translation is provided for convenience. If it differs from the Chinese version, the Chinese version prevails.

alink gives you a contact point you control. Visitors explain who they are and why they are reaching out; rules and AI triage then route the request to your inbox.

By registering an account, visiting a card page, submitting a request through a card page, or entering an in-site conversation, you confirm that you have read, understood and agree to be bound by these Terms. If you do not agree, please do not use the service. The service is operated by Yiwen AI Limited (億文智能有限公司), a private company limited by shares incorporated in Hong Kong ("alink", "we", "us").

1. Definitions

TermMeaning
Receiver (user)A person who registers an alink account, publishes a card page and uses the Assistant Inbox
RequesterA visitor who converses with a user's AI assistant on their card page, or submits a structured request through it. Submitting needs no signup; once the request is accepted, entering the in-site conversation for the first time opens an account automatically (see Section 2.7)
Card pageA user's public AI contact entrance (al.ink/<xid> or al.ink/<handle>); the same URL is also their protocol identity document
xidA system-generated 20-character permanent identifier — free, non-transferable, never recycled
HandleA human-readable display alias (vanity name) included in paid plans; it points to the xid and is reclaimable
Contact ContractThe machine-executable rules a user declares about how they are willing to be contacted
GatekeeperThe automated pipeline: intercept → anti-abuse → rule filtering → AI triage
Assistant InboxThe interface where the user makes the final human decision on requests
In-site conversation (Thread)The two-way asynchronous conversation opened when a request is accepted: the receiver participates from the Assistant Inbox, the requester via the entry link in the release email
IntentA "what I am looking for" statement a user chooses to publish, shown on their card page and public API according to the visibility they select, taken down automatically on expiry
WorkSomething a user publishes on their own card page: a single web file, or a folder with an index.html entry plus images, video and other assets. Each work has its own public address and is displayed in isolation on a dedicated work page (see Section 7.6)
EncounterOne attempt to cross a card page's boundary: a visit, an intent view, a conversation with the assistant, a request submission, etc.; statistics rules are in Section 3.7 and the Privacy Policy

2. Eligibility and accounts

  1. Age: you must be at least 18 years old with full legal capacity.
  2. Account authenticity: registration information must be truthful; do not mass-register accounts to abuse free quotas or evade limits (see Section 9).
  3. Passwordless authentication: sign-in uses passkeys or email magic links. You are responsible for:
    • safeguarding access to your login email and registered devices;
    • keeping the one-time recovery code generated at signup (we store only its hash and cannot recover it for you);
    • contacting us immediately if you notice anything unusual on your account.
  4. Email changes: changing your login email takes effect after a 7-day delay; both old and new addresses are notified and either can abort the change. This is a fixed anti-takeover safeguard and cannot be waived.
  5. Delegate seats: a Max subscription may grant one delegate seat (e.g. your assistant) to co-manage the Inbox. Seat users sign in with their own credentials; by default they cannot approve requests or modify contracts unless you explicitly grant it (the grant itself requires step-up verification). A seat user's actions inside your account are deemed authorized by you and are your responsibility; every action is audited under the seat user's own identity.
  6. You are responsible for all activity under your account, including the behavior of AI agents you connect (see Section 8).
  7. Automatic account on conversation entry: once a requester's request is accepted, their first entry into the in-site conversation automatically opens an alink account with the reply email they submitted (disclosed in advance in the release email). Entering the conversation constitutes acceptance of these Terms and confirmation of the eligibility requirements in Section 2.1; the mailbox-ownership proof carries the same strength as a magic-link signup. An automatically opened account has exactly the same rights and obligations as a self-registered one and can be deleted anytime. If the email already has an alink account, the conversation is merely linked to it — no sign-in ever occurs this way; signing in always requires the real login ceremony.

3. The service and AI disclosure

  1. The core service includes: a public card page with protocol identity endpoints, Intent publishing, the card page AI assistant conversation, the structured request form, the Gatekeeper pipeline (including AI triage), the Assistant Inbox, in-site conversations, relationship records, Encounter signals, audit logs, and data export and deletion.
  2. AI is involved: requester submissions are first triaged and summarized by AI; replies generated and sent automatically by AI carry a clear AI identity label — alink never impersonates a human. Every AI verdict includes a human-readable reason.
  3. Humans make the final call: high-stakes actions such as approving a request or granting agent authority always require human confirmation.
  4. AI can be wrong: triage may produce false rejections (good requests declined) and false approvals (harassment let through). Built-in safeguards exist (auto-decline suspends itself when the false-rejection rate exceeds the threshold; declined requests can be overturned; false approvals can be flagged), but we do not guarantee perfect filtering and accept no liability for lost opportunities arising from it (see Section 13).
  5. Service evolution: we may add, change or retire features. Features labeled Beta/preview are provided as-is and may change at any time. Material adverse changes to core functionality will be announced reasonably in advance.
  6. Card page AI assistant conversation: visitors may converse asynchronously with a user's AI assistant. The assistant replies using only what that card page has already made public (the public profile — including any public Q&A (FAQ) the user wrote for the assistant — public intents, the behavioral boundary declared by the Contact Contract); every reply carries an AI identity label and a "this is not a commitment by the person" footer that cannot be turned off — nothing the assistant outputs constitutes a commitment, offer or authorization by the user or by us. Conversation transcripts are stored encrypted for no more than 30 days and are never visible to the card page owner (they serve anti-abuse auditing only); only a structured request the visitor confirms enters the gateway pipeline. See Section 1.9 of the Privacy Policy.
  7. Intents and Encounter signals: intents a user publishes are shown on their card page and principal document (the public API response) according to the visibility they select, are taken down automatically on expiry, and can be paused, completed or deleted at any time; intent display — and any future directory search — is ordered by time and relevance, never by payment. We provide users with Encounter signal statistics for their card page; what is counted, and how deeply, is identical for every visitor and independent of paid tier — payment only affects how much detail the user gets to see. The privacy rules of signal collection (anonymous visitors counted but never identified, the stealth-visit toggle, retention and deletion) are governed by Section 1.10 of the Privacy Policy.

4. Identity and handle rules

This is alink's most important product covenant — please read it carefully.

4.1 xid: your permanent identity

  • Registration gives you an xid (e.g. al.ink/d8ftedhpqhsusbg001tg). It is your canonical identity root: free, permanent, non-transferable, never recycled, and entirely unaffected by your subscription status.
  • All protocol objects (credentials, relationship records, audit events) anchor to the xid only, never to a handle.

4.2 Handle: a reclaimable display alias

  • Custom handles are part of paid plans and are not sold separately. The name length you may bind depends on your subscription tier (see the pricing page).
  • A handle is merely a redirect alias to your xid — the xid is your permanent identifier, the handle a vanity name. Registering, releasing or reassigning a handle does not affect your identity, credentials or relationship data.
  • You may not transfer, gift, rent out or trade handles, nor hoard them or squat on other people's names or brands (see Section 9). System route words and well-known person/brand names are on reserved and protected lists; claiming a protected name requires identity verification.

4.3 Handle lifecycle

StageRule
BindingHeld for 15 minutes during checkout and bound on successful payment; at most 1 handle per user at a time; at most 2 rebinds per calendar year
Grace (30 days)After non-payment or cancellation the handle enters a grace period of at least 30 days and keeps resolving; renewing restores it
Cooldown (90 days)After grace expires the handle is unbound and enters a cooldown of at least 90 days, returning 410 externally; during cooldown only you can redeem it by resuming your subscription — no public competition
ReleaseAfter cooldown the name becomes publicly registrable. On reassignment your relationship counterparties receive a one-time change notice; we provide no "previous holder" lookup
Rebind / account deletionThe old handle goes straight into cooldown (so "delete to free the name" cannot be abused by squatters)
DowngradeIf your current handle's length exceeds the new tier's entitlement, it enters a 30-day grace during which you may upgrade back or rebind a compliant length

4.4 Trial restriction

Custom handles cannot be bound during a free trial (prevents "trial name-grabbing").

5. Subscriptions, billing and refunds

  1. Tiers and pricing: subscriptions come in four tiers — Free / Plus / Pro / Max — plus the Event Gatekeeper Pack for event organizers. Entitlements, quotas and current prices are as shown on the pricing page; prices are in USD, with payment and automatic tax handled by Stripe.
  2. Auto-renewal: paid subscriptions renew monthly or yearly. You may cancel anytime in the subscription portal (Stripe Portal); cancellation takes effect at the end of the current period.
  3. Upgrades and downgrades: upgrades take effect immediately with prorated charges; downgrades take effect at the end of the period.
  4. Trial: a 14-day no-card Pro trial is available; it falls back to Free on expiry with no charge.
  5. Refunds:
    • Annual plans: full no-questions refund within 14 days of payment; any handle bound under that subscription is unbound and enters cooldown;
    • Monthly plans: the current period is non-refundable (except where the law mandates otherwise); after cancellation, service continues until period end;
    • Initiating a chargeback instead of the refund process triggers a risk review and may restrict the account.
  6. Downgraded on arrears, never disarmed: after a failed payment:
    • Days 0–7: full functionality; automatic payment retries and reminders;
    • Days 8–30: AI triage drops to the Free quota, the handle enters grace, value reports pause; rule-layer filtering, the Inbox, approvals and export all keep working;
    • Day 31+: the subscription is canceled and the account falls back to Free entitlements; the handle is unbound into cooldown (redeemable by you for 90 days upon resuming).
    • Payment at any point restores everything. We never switch off protection or wave requests through because of arrears.
  7. Quotas and fair use: per-tier AI triage quotas are on the pricing page. When a quota is exhausted, requests fall back to rule-layer filtering with a notice in your digest — protection never disappears. Large quotas on higher tiers assume normal personal use; reselling, account sharing, or burning quota through automation is a breach. Targeted request floods do not count against your quota — they are handled by anti-abuse measures.
  8. Requesters never pay: we charge requesters nothing and offer no mechanism whatsoever to "pay for a better chance of getting through".
  9. Price changes apply to new billing periods; existing subscribers get at least 30 days' notice.

6. Referrals and achievements

  1. Your card page / identity link doubles as your referral link. When someone you referred signs up and becomes an established paid subscriber (14 days after their first payment, with both of you still subscribed), you earn +1 conversion.
  2. Conversion counts are achievements, not money or property: no exchange rate, not purchasable, not transferable, not withdrawable, no cash value; they never expire and are never clawed back once granted. They also serve as the claiming credential for milestone perks (see item 5); perks not yet announced constitute no promise.
  3. Self-referrals, mass fake signups and fraudulent inducement lead to withheld counts, reset achievements, or account termination.
  4. Conversion counts never influence gateway decisions: nobody's request gets a better pass rate because of who referred them.
  5. Milestone perk · permanent handle: for every full rung of cumulative conversions (currently 1,000 per rung — claim N requires a cumulative count of at least N × 1,000), you may make your currently bound custom handle permanent: for at least 99 years from the claim it no longer enters the grace or cooldown reclaim flow when your subscription ends. Claiming does not reduce your conversion count; each rung is usable once. If you later change your handle yourself, permanence lapses with the old name and the claim is not refunded; the benefit ends with account deletion and is non-transferable and non-redeemable for cash. Where conversions are determined to be fraudulent we may withhold counts and revoke the corresponding claim. The per-rung price may change — changes affect only future unclaimed rungs, never completed claims.

7. Your content and license

  1. Content you create in alink (card profile, contracts, relationship records, conversation messages) is yours.
  2. You grant us a worldwide, non-exclusive, royalty-free, limited license to host, store, process, transmit and display that content solely to operate and provide the service (for example rendering your public card page to visitors, or running AI triage on requests). The license ends when the content or account is deleted (except statutory retention and backup cycles).
  3. You represent that you hold the necessary rights to what you submit and that it does not infringe third-party rights.
  4. Feedback and suggestions you volunteer may be used by us to improve the product, without compensation.
  5. Material locker (file distribution): files you upload and hand out through the material locker are likewise your content, with these additional rules — (a) only upload files you have the right to distribute; do not use the handout channel to spread malware, infringing, illegal or fraudulent content; (b) file titles and descriptions are content that may be shown to visitors and fall under platform content review; (c) for reported violations we may take a file down immediately (revoking all issued links and removing the file) and terminate the account under Section 15; (d) every handout is recorded in a ledger — we log only the recipient and the download count, and do not monitor reading behavior (see Privacy Policy Section 1.11).
  6. Works (user content): works you publish on your card page are your content, and you are responsible for them. These additional rules apply:
    • The content is yours; so is the responsibility. Publish only what you have the right to publish. A work's title, summary, cover and the work itself are public content; anyone with the address can open it. Do not put anything in a work that you do not want public — including keys, passwords, other people's contact details, or material of your own you intend to keep private.
    • alink does not endorse a work's content. Every work page carries a fixed attribution line (for example "A work by Yan · Content does not represent alink"). Works are provided by their publishers, do not represent our position, and we make no warranty as to their accuracy, legality or availability. A work runs in an isolated browser environment: it cannot read your alink sign-in state, and it cannot send anything a visitor types inside it to any third party.
    • The red lines for works are the same as in Section 9, and in particular: no malicious code, mining scripts or programs that abuse a visitor's device; no imitating any website, brand or login screen to solicit accounts, passwords, payment details or other credentials; no content that infringes copyright, trademarks, likeness rights or privacy; no unlawful content.
    • Reporting and takedown. Every work page has a report entry anyone can use without registering. For abuse, infringement or copyright matters (including DMCA notices) you can also email [email protected] — state the matter in the subject and include the work's address, the basis of your claim and your contact details. We review reports; for works found in violation we may take the work down immediately (its public address stops working) and suspend or terminate the account under Section 15. When a work is taken down, the publisher sees the status and reason in their console but cannot restore it themselves.
    • Takedown takes a few minutes to propagate. To keep works fast to open, we cache their content on edge nodes worldwide. After a takedown, deletion or unlisting, some visitors may still see the old content from cache for up to about 5 minutes; we clear caches on takedown as best we can, but cannot guarantee it is instantaneous. The same applies when you delete a work yourself — treat it as normal propagation, not a failed takedown. Likewise, a work's address is bound to its version: replacing the content invalidates the old version's address, and changing the short name (slug) means links you have already shared stop working — we do not redirect.
    • Downgrading your plan does not unpublish works. If you exceed the new plan's quota, we only block new uploads and replacements; published works and the links other people hold keep working — until you delete them, or they are taken down under this section.

8. Agents and API access

  1. You may connect your own AI agents via MCP and similar interfaces. Whatever an agent does within its authorized scope counts as your action.
  2. Guard your access tokens and credentials; grant scopes on a least-privilege basis; agent authority (ConsentGrant) can be revoked at any time.
  3. Agent identity is based on keys you hold yourself. alink will never ask you to upload a private key; any request for your private key is phishing.
  4. The open API for third-party developers is not yet commercially launched and interfaces may change; the stability commitments published in the developer docs govern.

9. Acceptable use (red lines)

When using alink — including as a requester — you must not:

  1. harass, threaten, defraud, impersonate others, or submit unlawful content;
  2. use the service for bulk spam outreach, to circumvent other people's filtering rules, or to systematically probe decline outcomes (a declined request may be retried once with additional context, when invited);
  3. squat on, hoard, or imitate other people's names or brands as handles;
  4. mass-register accounts to farm free quota, or scrape card pages and other users' data with crawlers or automation;
  5. attempt unauthorized access to other accounts, data or system components, or disrupt the service (for security research, use the responsible disclosure channel — see Support);
  6. resell the service or share a paid account (delegate seats excepted);
  7. circumvent quotas, billing, or any security mechanism.

Additional requester obligations: provide truthful identity and context when submitting; acknowledge AI processing and data retention; keep your status link and conversation entry link safe (both are authorization links — do not forward them; the entry link can be re-sent from the status page at a limited rate, invalidating the previous one). The card page assistant conversation is for approaches genuinely related to contacting that user — do not abuse it as a general-purpose AI service (conversations are quota-limited and fall back to the form when exceeded). Red lines 1–7 apply equally to conversations with the card page assistant and to messages in the in-site conversation; the receiver may close a conversation at any time, and the requester cannot reopen it.

The red lines above apply equally to works you publish (Section 7.6) — a work is public content, and running in an isolated environment does not exempt it from this section.

For violations we may warn, rate-limit, remove content, or suspend or terminate accounts depending on severity; egregious cases are terminated immediately without refund.

10. Data and privacy

How personal data is handled — including export, deletion, the 7-day deletion cooling-off period, and cryptographic erasure — is governed by the Privacy Policy, which forms part of these Terms. Key point: data sovereignty is not tiered — export and deletion are fully available on every tier, including Free.

11. Intellectual property

alink's software, interfaces and brand assets (including the "alink" name and logo) belong to us or our licensors. You receive no rights beyond those expressly granted in these Terms. Do not use our brand to impersonate us or imply endorsement without written permission.

12. Third-party services

Payments are provided by Stripe and infrastructure by Cloudflare, each under their own terms. For third-party outages or changes we accept no liability beyond Section 13.

13. Disclaimers and limitation of liability

  1. As is: to the maximum extent permitted by law, the service is provided "as is" and "as available", without express or implied warranties (including merchantability, fitness for a particular purpose, and non-infringement).
  2. No perfect filtering: we do not guarantee that AI triage makes no mistakes, that you will miss no opportunity, or that harassment is fully blocked.
  3. Availability targets are not warranties: published availability objectives (SLOs) are engineering targets and, absent a separate written SLA, are not contractual guarantees.
  4. No indirect damages: to the maximum extent permitted by law, we are not liable for indirect, incidental, special or consequential losses (including lost profits, goodwill, opportunities, or data).
  5. Liability cap: our total cumulative liability to you is capped at the fees you actually paid us in the 12 months before the event giving rise to the claim, or USD 100 if you have paid nothing.
  6. Some jurisdictions do not allow certain exclusions or limits; they then apply to the maximum extent permitted.
  7. Nothing in these Terms excludes or limits liability that cannot be excluded by law (including liability arising from our fraud or gross negligence).

14. Indemnity

You will indemnify and hold us harmless against third-party claims, losses and reasonable costs (including attorney fees) arising from your breach of these Terms (especially Section 9) or your infringement of third-party rights.

15. Term and termination

  1. You can leave anytime: cancel your subscription, export all your data, and delete your account (cancelable within the 7-day cooling-off period).
  2. Our termination rights: we may suspend or terminate your access if you breach these Terms. For curable breaches we will make reasonable efforts to notify you and allow correction first; egregious cases (fraud, abuse, endangering others) may be terminated immediately.
  3. Service shutdown: should we permanently discontinue alink, we will give at least 60 days' notice and keep data export available throughout. Your identity documents and credentials follow the open Agent Protocols specifications and are portable at the protocol level.
  4. Effects of termination: after termination, data is handled per Section 6 of the Privacy Policy; handles enter cooldown; billing and audit data retained by law are excepted. Sections 7, 11, 13, 14 and 16 survive termination.

16. Governing law and disputes

These Terms are governed by and construed under the laws of the Hong Kong Special Administrative Region (excluding its conflict-of-law rules). Disputes should first be resolved through good-faith negotiation; failing that, they are submitted to the non-exclusive jurisdiction of the Hong Kong courts.

17. Miscellaneous

  1. Entire agreement: these Terms, together with the Privacy Policy and your order page, form the entire agreement about the service.
  2. Severability: an invalid clause does not affect the rest.
  3. No waiver: our not exercising a right is not a waiver of it.
  4. Assignment: you may not assign these Terms without our written consent; we may assign them upon merger, acquisition or asset transfer, with notice to you.
  5. Force majeure: neither party is liable for delay or failure caused by events beyond reasonable control (including large-scale upstream infrastructure failures); we will make reasonable efforts to restore service.
  6. Changes to these Terms: we may update these Terms. Material changes will be notified at least 14 days in advance by email or in-product notice; continued use constitutes acceptance. If you disagree, stop using the service before the effective date — you may delete your account.
  7. Language versions: these Terms are authored in Chinese, currently the only binding version; this English text is a convenience translation. Unless stated otherwise, the Chinese version prevails.

18. Contact us

  • Email: [email protected] (for legal or privacy matters, please say so in the subject line)
  • Operating entity: Yiwen AI Limited (億文智能有限公司), a private company limited by shares incorporated in Hong Kong; the registered address is available on request and via the Hong Kong Companies Registry.

19. Organizations and collaboration

This section covers an organization's handling of member data and requires a dedicated legal review before paid beta.
  1. An organization is not a separate login or a substitute for a legal entity. It is an identity and authorization container. Whether a statement made in its name binds anyone depends on the parties' underlying legal relationship.
  2. Creator responsibility. By creating an organization and inviting members, you confirm that you may process their data and will meet applicable notice and rights-request duties. For rosters, organization audit records, and collaboration records, you and the organization's controllers decide the purpose; alink hosts the data under your instructions.
  3. Member rights. Members may leave, export their own records, inspect their permissions, and refuse public attribution. Publishing a member's name requires separate approval from the organization and that member.
  4. Membership does not equal authority. Actual permissions control; a role title alone grants none. Commitments made for an organization must also follow its internal approval rules.
  5. Collaboration approval. Each party must confirm its own commitments. AI may draft but may not confirm. Joining does not create a contact relationship or grant access to another party's private data.
  6. Leaving and removal. A party may leave at any time. Removal follows the collaboration's agreed rules. Existing shared records are not rewritten when a party leaves.
  7. Security freeze. If we reasonably believe an organization seat is compromised, we may temporarily suspend its write access and record the event. A controller must re-establish control before access is restored.
  8. Our limits. We do not dissolve organizations, accept invitations or commitments for members, use organization permissions to read members' private data, or provide member rosters to third parties.