This summary is for orientation only and forms no part of the agreement. Where it differs from the clauses below, the clauses govern.
- Halo is a peer-to-peer marketplace. When you buy inference, you are buying it from an independent operator — not from us.
- We never hold your money or your keys. Your wallet is yours, payments settle directly on Base through a smart contract, and we cannot move, freeze, reverse, or recover your funds.
- The protocol fee is not our revenue. It is withheld on-chain and directed to the protocol, not to ProtoWardo Ltd.
- Encryption is layered, not absolute. By default the relay cannot read your prompt, but the operator serving it can. Read Section 9 before sending anything sensitive.
- Halo is alpha software running on Base mainnet with real USDC. You can lose funds. Nothing here is a warranty.
1Who we are, and what these Terms cover
Access to Halo is provided by ProtoWardo Ltd ("ProtoWardo",
"we", "us"), a company incorporated in the British Virgin Islands with its registered
and head office at Floor 4, Banco Popular Building, Road Town, VG1110 Tortola, British Virgin Islands (LEI 984500477F9C991NE141).
These Terms of Use (the "Terms") are a binding agreement between you and ProtoWardo. They govern your use of the parts of Halo that we operate or publish (together, the "Interfaces"):
- this website,
runhalo.xyz, and its subdomains; - the Halo web application at
app.runhalo.xyz; - the
halocommand-line interface, the Halo SDK, and the Halo agent skill; - the network services we participate in — the relay (which routes requests to operators), the facilitator (which sponsors gas and submits signed authorisations), and the indexer (which records network activity and computes statistics).
By using any Interface you accept these Terms. If you do not accept them, do not use the Interfaces.
These Terms do not govern the Halo smart contracts themselves. Those are autonomous code deployed on the Base network; anyone can interact with them directly without using our Interfaces, and doing so is outside this agreement. Nor do these Terms govern your use of the Halo source code, which is licensed separately (§13), or any token, which is governed by its own documentation (§20).
2What Halo is — and what we are not
Halo is a permissionless, peer-to-peer marketplace for AI inference. It has two sides:
- Consumers
- Users — people, applications, or autonomous agents — who send inference requests and pay for them in USDC on Base.
- Operators
- Independent third parties who serve those requests from their own hardware or their own accounts with upstream model providers, set their own prices, and earn USDC.
You may act as either or both. Consumers reach the network through the web
application, the CLI, the SDK, or an agent; operators run the halo CLI.
Every inference transaction is between a consumer and an operator. We are not a party to it. Specifically, ProtoWardo is not:
- a provider of AI inference. We do not run models, generate outputs, or select what an operator serves. The relay routes; it does not produce.
- a custodian, bank, money transmitter, or payment processor. We never take possession, control, or custody of your USDC, your ETH, or any other asset. Payments settle directly between wallets through a smart contract (§6).
- a broker, exchange, or fiduciary. We do not match on your behalf in any advisory capacity, hold assets for you, or owe you fiduciary duties.
- the employer, agent, partner, or joint venturer of any operator. Operators are independent. They are not authorised to bind us or to make representations on our behalf, and we do not vet, certify, or supervise them.
3Eligibility
By using the Interfaces you represent and warrant that:
- you are at least 18 years old and have full capacity to enter this agreement;
- if you act for an organisation, you are authorised to bind it, and "you" means both you and that organisation;
- you are not a person subject to sanctions administered by the United Nations, the United States (including the OFAC Specially Designated Nationals list), the United Kingdom, the European Union, or any other applicable authority, and you are not acting for or on behalf of such a person;
- you are not located in, ordinarily resident in, or organised under the laws of a country or territory subject to comprehensive sanctions;
- your use of the Interfaces is lawful where you are, and does not breach any restriction that applies to you.
You are responsible for determining whether you may lawfully use Halo in your jurisdiction. We may restrict access from particular jurisdictions at any time, and third-party providers used for funding (§5) apply their own eligibility and screening rules that we do not control.
4Wallets, logins, and keys
Halo has no accounts in the conventional sense. Your wallet is your identity on both sides of the network — there is no password for us to reset and no account for us to restore.
Embedded wallets via Privy
If you sign in to the web application with a social login or an email address, that login and the wallet behind it are provided and maintained by Privy (privy.io), an independent third party. Supported methods include Google, Discord, X, and email, among others. Privy provisions the wallet, secures it, and controls the recovery process.
ProtoWardo has no access to your Privy account, your embedded wallet, or its private key. We cannot sign on your behalf, recover your login, export your key, or move your funds. You can export your own private key from within the application; once you do, keeping it safe is entirely your responsibility.
Your use of Privy is governed by Privy's own terms and privacy policy, directly between you and Privy. If you lose access to the social account or email you signed in with, recovery is a matter between you and Privy, subject to whatever recovery mechanism Privy offers.
External wallets and CLI wallets
You may instead connect an external wallet, or — when running the halo
CLI — use a wallet generated and stored locally on your own machine. In both cases the
keys never leave your control and we never see them.
Session keys
To avoid a wallet prompt on every request, Halo uses a session key: a delegated key, authorised by your wallet, that signs payment receipts and tool payments autonomously within the limits you set. Your main wallet keeps custody of the funds; the session key only authorises spending against the deposit you have already made.
Registering a session key is your decision and your risk. Anything signed by a session key you registered is treated as authorised by you.
Loss of keys
If you lose your private key or your recovery method, your funds are permanently and irreversibly lost. No one — not ProtoWardo, not Privy, not any operator — can recover them. This is an inherent property of self-custodied wallets, not a limitation of our service.
You are solely responsible for the security of your devices, credentials, keys, seed phrases, and session keys, and for every transaction signed with them, including by an agent or script you have authorised.
5Adding funds
To consume inference you need USDC on Base in your wallet. You can transfer it there yourself, or use the funding options offered inside the web application.
Card, bank, and other fiat top-ups are provided by independent third-party payment providers and on-ramps, made available through Privy, including Stripe and others. Crypto-to-crypto funding routes are likewise operated by third parties.
ProtoWardo is not a party to those transactions. We do not process payments, hold fiat, issue refunds, or handle chargebacks. Identity verification (KYC), anti-money-laundering checks, sanctions screening, supported countries and currencies, limits, fees, exchange rates, and settlement times are set and applied by the relevant provider under its own terms — not by us.
A funding attempt may fail or be declined for reasons entirely outside our control, including verification requirements, unsupported geography, unsupported assets, sanctions screening of a wallet address, or a provider's own availability. Disputes about a fiat payment are between you and that provider.
Funds arrive in your wallet. At no point do they pass through an account we control.
6How payments work, and the protocol fee
All inference payments settle peer-to-peer, on-chain, in USDC on
Base mainnet (chain ID 8453), through the Halo Vault
— an immutable smart contract published at 0x3907F660B257560883E891fbbB9F997Eff70E40E.
The settlement flow
- Deposit. A consumer deposits USDC into the Vault once and registers a session key. The deposit remains attributable to that consumer.
- Reserve. Before a request is routed, the consumer signs an authorisation earmarking part of that deposit for a specific operator, with an expiry.
- Serve. The operator reads the on-chain reservation and serves only if it covers the request's cost ceiling.
- Settle. The consumer signs a cumulative receipt for what has actually been served. Redeeming it moves exactly that amount from the reservation to the operator.
- Expiry. Reservations that go unused expire and return to the consumer's free balance, which the consumer can withdraw at any time.
ProtoWardo never takes custody of these funds. The Vault is a smart contract; the deposit is yours until you spend or withdraw it. We hold no key that can move it. Our facilitator pays the network gas for certain transactions and submits authorisations you have already signed — it is a relayer and gas sponsor, not a custodian, and it cannot move USDC that you have not authorised.
Pricing
Operators set their own prices — either as a margin over the upstream provider's published per-token rate, or as a flat rate per thousand tokens. Prices, model availability, and capability claims are declared by operators. We do not set, approve, or guarantee them.
You are charged for actual usage as reported at settlement, within the limits you authorised. Pre-request estimates are estimates: the amount finally charged may differ, and Halo's consumer-side guards (per-request ceilings, cumulative budget caps, model allowlists) are the mechanism by which you bound that exposure. Setting them is your responsibility.
The protocol fee
A protocol fee is withheld from the operator's side at settlement and enforced on-chain by the Vault, so it cannot be bypassed: the consumer pays the operator's quoted price, and the operator nets that price less the fee. It currently stands at 10%, is subject to a hard cap of 50% written into the contract, and can only be changed through the contract's timelocked governance path.
The protocol fee is not a fee payable to ProtoWardo, and is not our revenue. It accrues to the protocol and is directed on-chain to protocol-controlled destinations. We do not receive, hold, or control it in the course of settlement, and no clause of these Terms should be read as ProtoWardo charging you for inference.
Irreversibility
On-chain transactions are final and cannot be reversed. There are no refunds, chargebacks, or cancellations once a transaction is confirmed. We cannot undo a payment, recover funds sent to a wrong address, or reverse a settlement — no matter the cause, including your own error, a compromised key, or a fault in software you chose to run.
Certain one-off charges — for example paid tool calls made by an agent — settle through the x402 standard rather than the Vault. The same principles apply: the payment is yours to authorise, it settles on-chain, and it is irreversible.
You are solely responsible for any tax arising from your use of Halo, including income, capital-gains, sales, VAT, and withholding obligations. We do not provide tax advice, withhold tax, or issue tax documentation.
7Consuming inference
When you consume inference through Halo, you accept that:
- No availability is promised. There may be no operator serving a given model at a given moment, at a price you find acceptable, or at all. The network is permissionless and its composition changes continuously.
- Outputs are generated by third parties. The operator, and any upstream provider it uses, produce the output. We do not generate, review, moderate, or endorse it.
- Outputs may be wrong. AI-generated content can be inaccurate, incomplete, biased, offensive, or entirely fabricated, and can infringe third-party rights. Verify anything you rely on.
- Outputs are not advice. Nothing produced through Halo is legal, medical, financial, tax, or other professional advice, and must not be used as a substitute for it.
- You are responsible for your inputs and your use of outputs — for having the right to submit what you submit, and for the consequences of acting on what comes back.
- An operator may fail to serve, or serve poorly. Your recourse for the quality of an inference is against that operator; the protocol's protection is economic — you pay for what is reported as served, within the limits you authorised — not a guarantee of quality.
If you connect an autonomous agent to Halo, every request and payment it makes with your keys is your responsibility. Set the spending guards accordingly.
8Operating
Running an operator is permissionless: no approval, licence, or stake is required from us. If you operate, you additionally agree that:
- You act on your own account. You are an independent participant, not our employee, agent, contractor, or partner. You bear your own costs — hardware, electricity, bandwidth, upstream API charges — and your own risk.
- You are responsible for your upstream. If you serve by fronting a third-party model provider, you must have the right to do so and must comply with that provider's terms, including any restriction on resale, redistribution, or sublicensing of its models. Breaching them is a matter between you and that provider. If you serve open-weights models, you must comply with their licences.
- Your declarations must be honest. Announced models, prices, capabilities, privacy characteristics, provider identity, and confidentiality claims must accurately describe what you actually serve. Announcing a capability you do not have — including a confidentiality or attestation property — is a material breach of these Terms.
- You must serve what you were paid for. Do not degrade, substitute, truncate, cache-substitute, or fabricate outputs; do not route to a cheaper model than the one announced; do not manipulate reported token usage.
- You must not game the network. No self-dealing between wallets you control, no artificial volume, no manipulation of statistics, rankings, or any incentive programme.
- You handle consumer content responsibly. In the default routing path you can read the prompts you are served (§9). Use them only to serve the request and to comply with law. Do not retain, publish, sell, or train on them beyond what your declared retention policy states and applicable law permits.
- You are responsible for your own legal compliance — including any licensing, data-protection, export-control, consumer-protection, or tax obligation that applies where you operate.
Settlement risk
Serving work does not guarantee payment. A settlement can fail or remain uncollected — for example if a reservation expires, an authorisation is not confirmed on-chain, a consumer never advances a receipt, or your own process loses unredeemed receipts. You bear that risk. ProtoWardo does not guarantee, underwrite, or indemnify operator earnings, and has no obligation to compensate you for work served but not collected.
Earnings are paid by consumers, not by us. We do not employ you, guarantee you volume, or promise any level of income.
9Prompt content, encryption, and confidentiality
Halo offers layered protection for request content. The layers are different, and none of them is unconditional. Read this clause before sending anything sensitive.
End-to-end encryption (relay-blind)
By default, supported clients encrypt the request body to the selected operator, so the relay forwards ciphertext and cannot read it. Routing fields — such as the model name — remain in clear text because the relay needs them to route.
This protects your content from the relay, not from the operator. The operator decrypts the request in order to run it, and forwards it to whatever upstream provider it uses. Assume the operator and its upstream can read your prompt.
Confidential (TEE) mode
Where an operator advertises it, confidential mode encrypts message content directly to a hardware trusted execution environment, so the operator relays ciphertext it cannot read. Supported clients verify the enclave's attestation before trusting it.
We do not warrant confidentiality in any mode. Confidentiality in TEE mode depends on hardware, firmware, and enclave software operated by third parties, on the specific verification your client performs, and on the correctness of the attestation chain — none of which we control or can independently guarantee. Privacy and confidentiality labels announced by operators are routing metadata, not proof, and not a warranty by us or by anyone. Not every path supports confidential mode: image generation, in particular, is encrypted to the operator but is not TEE-confidential, so the operator and its upstream provider see the prompt and the image.
What this means for you
Do not submit personal data of others, special-category or regulated data, credentials, trade secrets, or anything whose disclosure would harm you, unless you have independently satisfied yourself that the path you are using is adequate for it. If you are subject to data-protection obligations, you are the controller of what you submit, and you must satisfy yourself that routing it through a permissionless network of independent operators is lawful for your purposes.
Where an operator does receive personal data through your request, that operator — not ProtoWardo — determines what happens to it. Operator-declared retention policies are declarations, not guarantees, and we do not verify or enforce them.
10Network records, statistics, and programmes
Our indexer records signed records of completed work — such as the operator and consumer wallet addresses, the model, token counts, amounts, timestamps, and transaction hashes — in order to compute network statistics, operator reputation, and league standings. These records do not contain prompt text, completion text, or encrypted request bodies.
Blockchain transactions are, separately and inherently, public and permanent. Anything settled on Base is visible to anyone and cannot be deleted by us or by you.
We may run points, league, ambassador, or similar programmes. Unless a programme's own published rules say otherwise:
- participation is discretionary and the rules may change, and the programme may be suspended or ended, at any time;
- points, scores, ranks, and badges have no monetary value, are not property, are not redeemable, and are not transferable;
- they confer no entitlement to any payment, token, or future distribution;
- we may adjust, withhold, or reset them where we reasonably believe a programme is being gamed or abused.
11Acceptable use
You must not use the Interfaces to:
- break the law, or facilitate anyone else in doing so — including money laundering, terrorist financing, sanctions evasion, or fraud;
- generate, solicit, or distribute child sexual abuse material, non-consensual intimate imagery, or content that sexualises minors;
- create malware, ransomware, exploits, phishing content, or instructions for weapons capable of mass casualties;
- harass, threaten, defame, or impersonate any person, or generate synthetic media of a real person intended to deceive;
- infringe intellectual property, misappropriate trade secrets, or process personal data unlawfully;
- attack, overload, probe without authorisation, or attempt to gain unauthorised access to the relay, facilitator, indexer, any operator, or any other user;
- circumvent rate limits, spending controls, version requirements, or access restrictions, or misrepresent client or operator identity or capabilities;
- manipulate settlement, reported usage, statistics, rankings, or any incentive programme, including through wallets you control on both sides of a transaction;
- scrape or resell the Interfaces in a way that degrades the network for others, or misrepresent Halo as your own service.
These restrictions bind you as a user of our Interfaces. They are not a claim that we monitor, filter, or can prevent any of the above across a permissionless network — §15 sets out what we can actually do.
12Third-party services, models, and outputs
Halo depends on services we neither own nor control: Privy and its funding partners, fiat on-ramps and card processors, the Base network and its RPC providers, wallet software, and the upstream model providers that operators front — among them commercial API providers and open-weights model publishers.
Your use of any of those is governed by that party's own terms, and any dispute about them is between you and that party. We are not responsible for their acts, omissions, availability, pricing, security, or data handling, and we do not endorse them.
Rights in the content you submit remain yours as between you and us. Rights in the outputs you receive are determined by the terms of the model and provider that produced them, which may restrict commercial use, redistribution, or use in training. You are responsible for checking those terms for the models you use, and we make no representation that any output is free of third-party rights or is yours to use for any particular purpose.
13Open-source software and self-hosting
The Halo protocol software is published as open source under the Apache License 2.0. Your use of that source code — reading it, modifying it, running your own copy — is governed by that licence, not by these Terms. The licence's own warranty disclaimer and liability limitation apply to it.
These Terms apply when you use the services we operate. If you run your own relay, facilitator, or indexer, or point the software at infrastructure we do not run, you do so at your own risk and outside this agreement.
Software we distribute may update itself, and we may require a minimum client version to interact with our services in order to preserve payment safety. Running a modified, outdated, or unofficial client is at your own risk, and we may refuse to serve it.
14Intellectual property
"Halo", "Warden", "ProtoWardo", the Halo mark, and the visual design of this site and the web application are ours or our licensors'. Except for the rights granted by the open-source licence in §13, nothing in these Terms transfers any right in them to you.
You may refer to Halo descriptively and truthfully — for example, to say that your application uses it. You may not use our names or marks in a way that suggests endorsement, affiliation, or that your service is operated by us.
You keep all rights in the content you submit. You grant us only the limited, non-exclusive licence needed to route, transmit, and process your request in order to operate the Interfaces, and to store the non-content settlement records described in §10.
If you believe material accessible through an Interface infringes your rights, contact us at legal@runhalo.xyz with enough detail to identify the material and your rights in it.
15Availability, changes, and suspension
The Interfaces are provided on an "as available" basis. We may change, suspend, restrict, or discontinue any of them, in whole or in part, at any time and without notice. We do not promise any level of uptime, latency, throughput, or capacity.
We may block or restrict your access to the Interfaces we operate — including the relay, the facilitator, and the web application — at our discretion, and in particular where we reasonably believe you have breached these Terms, where we are required to by law, or where doing so is necessary to protect the network or its users.
What we cannot do is equally important. We cannot freeze your wallet, seize your funds, reverse your transactions, or stop you interacting directly with the Halo smart contracts. Blocking access to our Interfaces does not affect your on-chain balances, and your ability to withdraw from the Vault does not depend on our permission.
You may stop using Halo at any time. Withdraw any Vault balance and stop running the software; there is no account to close. Clauses which by their nature should survive termination — including §§6, 9, 12, 14, 17, 18, 19, and 21 — do survive it.
16Alpha status and assumption of risk
Halo is alpha software running on Base mainnet with real funds. Interfaces, contracts, pricing, and economics may change. You should not commit funds you cannot afford to lose.
You acknowledge and accept, in particular, the risk of:
- Smart-contract risk — bugs, economic flaws, or exploits in the Vault or related contracts, which could cause partial or total loss of deposited funds. Auditing reduces this risk; it does not remove it.
- Key and wallet risk — loss, theft, or compromise of your keys, recovery method, or session key, and any resulting unauthorised spending.
- Settlement risk — failed, delayed, unconfirmed, or uncollected settlements, and transactions that behave differently from what an interface predicted.
- Counterparty risk — operators that serve poorly, misdeclare their capabilities, disappear mid-session, or mishandle your prompts.
- Infrastructure risk — outages, congestion, reorganisations, or failures of the Base network, RPC providers, Privy, on-ramps, or upstream model providers.
- Asset risk — depegging, freezing, blacklisting, or issuer action affecting USDC or any other asset you hold or use.
- Regulatory risk — changes in law that restrict or prohibit your use of Halo, decentralised AI marketplaces, or digital assets.
You use Halo at your sole risk, and you assume these risks knowingly.
17Disclaimers
The Interfaces are provided "as is" and "as available", without warranty of any kind. To the fullest extent permitted by law, we disclaim all warranties, express, implied, or statutory, including any warranty of merchantability, fitness for a particular purpose, title, non-infringement, accuracy, and any warranty arising from a course of dealing or usage of trade.
Without limiting that, we do not warrant that: the Interfaces will be uninterrupted, timely, secure, or error-free; any defect will be corrected; any operator will be available, competent, or honest; any output will be accurate, lawful, or fit for your purpose; any confidentiality, encryption, or attestation property will hold; any settlement will succeed; or that the software, the contracts, or any third-party component is free of vulnerabilities.
Some jurisdictions do not allow the exclusion of certain warranties. Where that is so, the exclusions above apply to the maximum extent permitted, and nothing in these Terms excludes liability for fraud, fraudulent misrepresentation, death or personal injury caused by negligence, or any other liability that cannot lawfully be excluded.
18Limitation of liability
To the fullest extent permitted by law:
- ProtoWardo, its affiliates, and their respective directors, officers, employees, and contributors will not be liable for any indirect, incidental, special, consequential, exemplary, or punitive damages, or for any loss of profits, revenue, data, goodwill, business opportunity, or anticipated savings, however caused and on any theory of liability, even if advised of the possibility;
- we will not be liable for any loss of digital assets, loss of or unauthorised access to keys, failed or unconfirmed transactions, smart-contract exploits, the acts or omissions of any operator, third-party provider, on-ramp, wallet, or network, or the content or consequences of any AI output;
- our total aggregate liability arising out of or relating to these Terms or your use of the Interfaces will not exceed one hundred United States dollars (USD 100).
This cap is not measured against fees, because we do not charge you for inference: the protocol fee described in §6 is not our revenue, and no part of what you pay for inference is received by us.
These limits apply in aggregate, not per claim, and reflect a reasonable allocation of risk for a service provided without charge to you over a permissionless network. Where a jurisdiction does not allow a limitation of this kind, our liability is limited to the least amount permitted by law.
19Indemnity
You will indemnify and hold harmless ProtoWardo, its affiliates, and their respective directors, officers, employees, and contributors from and against any claim, demand, loss, liability, damage, cost, or expense (including reasonable legal fees) arising out of or related to: your use of the Interfaces; your breach of these Terms or of any applicable law; the content you submit or the use you make of any output; your activity as an operator, including your relationship with any upstream provider; or your infringement of any third-party right.
20No offer, and no advice
Nothing in the Interfaces or in these Terms is an offer or solicitation to buy or sell any security, financial instrument, or investment; investment, legal, tax, or financial advice; or a recommendation to enter any transaction.
These Terms do not govern any token. Any token issuance, offering, or distribution is governed exclusively by its own documentation and terms, which are separate from this agreement. Nothing here creates an entitlement to any token or to any future distribution.
21Governing law and disputes
These Terms, and any dispute arising out of or in connection with them or with your use of the Interfaces (including non-contractual disputes), are governed by the laws of the British Virgin Islands, without regard to conflict-of-laws principles.
Before commencing formal proceedings, you agree to contact us at legal@runhalo.xyz and attempt in good faith to resolve the dispute informally for at least thirty (30) days.
Any dispute not resolved that way will be referred to and finally resolved by arbitration administered by the BVI International Arbitration Centre under its rules. The seat of arbitration is Road Town, Tortola; the language is English; and the tribunal will consist of one arbitrator.
Individual claims only. You and we each agree to bring claims only in an individual capacity, and not as a claimant or class member in any purported class, collective, consolidated, or representative proceeding. The arbitrator may not consolidate claims or preside over any form of representative proceeding.
Nothing in this clause prevents either party from seeking urgent injunctive or other interim relief from a court of competent jurisdiction, or affects any right you may have under mandatory law in your country of residence to bring proceedings in your local courts or to rely on mandatory local consumer protections.
22Changes to these Terms
We may update these Terms. When we do, we will change the version and effective date at the top of this page, and for material changes we will give reasonable notice through the Interfaces before they take effect.
Continuing to use the Interfaces after a change takes effect means you accept the updated Terms. If you do not accept them, stop using the Interfaces and withdraw any Vault balance.
These Terms are the entire agreement between you and us about the Interfaces, and replace any earlier version. If any provision is held unenforceable, it is severed or narrowed to the minimum extent necessary and the rest remains in force. Our failure to enforce a provision is not a waiver of it. You may not assign your rights under these Terms; we may assign ours to an affiliate or successor. Nothing in these Terms creates a partnership, joint venture, agency, or employment relationship, and no third party may enforce them except the indemnified persons named in §19. Neither party is liable for a failure to perform caused by events beyond its reasonable control.
23Contact
ProtoWardo Ltd
Floor 4, Banco Popular Building, Road Town, VG1110 Tortola, British Virgin Islands
LEI 984500477F9C991NE141
legal@runhalo.xyz
These Terms are published in English. Any translation is provided for convenience only; in the event of a conflict, the English version governs. Halo's protocol source is public at github.com/warden-protocol/run-halo, and the technical behaviour described above can be verified there.