Terms of Service
The agreement between you and Gheima: what we provide, what you pay, and how either side can end it.
Version 0.1 · Last updated September 19, 2026
These documents are a first published draft. They describe what the platform actually does today, but they have not yet been reviewed by a lawyer. We are publishing them because billing customers with no terms at all is worse; expect the wording to change once counsel has been through it.
1. Who these terms are between#
These Terms of Service (the “Terms”) are the agreement between you — the person or organisation holding a Gheima account (“you”) — and Gheima (“we”, “us”). They apply every time you create an account, deploy a service, or pay an invoice.
Gheima is operated by Omar BAABOUJ, an auto-entrepreneur registered in Morocco under Loi 114-13 in the Registre National de l'Auto-Entrepreneur, ICE / RNAE no. 003706803000143. An auto-entrepreneur is a natural person, not a company, and is not entered in the Registre de Commerce — so there is no RC number to quote. A postal address for formal notice is available on request at hello@gheima.ma.
If you are agreeing to these Terms for a company, a school or any other organisation, you confirm you are allowed to bind it, and “you” means that organisation.
2. What Gheima provides#
Gheima is a platform-as-a-service. You connect a Git repository, we build it into a container image and run it on our infrastructure behind HTTPS on a subdomain of gheima.ma or on a custom domain you control. Around that we provide managed Postgres, MySQL, MongoDB, Redis, object storage, search and queue instances, cron jobs, preview environments, logs, metrics and alerts.
We may add, change or withdraw individual features. Where a change removes something you are actively relying on, we will tell you before it takes effect and, where we reasonably can, give you a way to move off it.
Features marked “beta” or “private preview” in the dashboard — including the Morocco region — are exactly that. They may change, be rate-limited, or be withdrawn, and they carry no availability commitment.
3. Your account#
- You must give an accurate email address and keep it reachable. It is how we send sign-in links, invoices and incident notices.
- You are responsible for everything done under your account, including by team members you invite and by API keys you issue.
- Keep your credentials to yourself. We strongly recommend enabling two-factor authentication; on team accounts an owner can require it.
- Tell us promptly if you believe an account, an API key or a deploy token has been compromised so we can revoke it.
Accounts have roles. Owners and admins can see billing, manage members, reveal environment variables and delete resources; the audit log records who did what and when, and those records are kept as accountability evidence.
4. Acceptable use#
You may run essentially any lawful workload on Gheima. You may not use it to:
- break Moroccan law, or the law that applies to you or to the people your service reaches;
- host or distribute malware, phishing pages, or content that impersonates a person or an organisation;
- send unsolicited bulk email, or use our outbound mail relay for anything you do not have consent to send;
- attack, scan or attempt to gain unauthorised access to other tenants, our infrastructure, or third parties;
- mine cryptocurrency, run distributed proxy or VPN exit nodes, or otherwise consume shared capacity in a way that degrades other customers;
- circumvent plan limits, metering, or the isolation between accounts.
We do not routinely inspect the contents of your containers, databases or buckets. We do act on abuse reports, on automated signals such as sustained outbound scanning, and on lawful orders.
5. Your code and your content#
Your code, your data and everything your application produces remain yours. Nothing here transfers ownership.
To run your service we need a narrow, practical licence: permission to fetch your repository, build it, store the resulting image in our registry, run it, replicate it for scaling and previews, back it up, and show it back to you in logs and consoles. That licence exists only so the platform can do its job, lasts only as long as you keep the resource, and covers nothing else. We do not use your code or your data to train models, and we do not share it with anyone except the sub-processors listed in our Sub-processors page.
6. Plans, prices and billing#
Prices are published on our pricing page in Moroccan dirhams (MAD), and the published price is the amount charged — nothing is added at checkout. Gheima is operated by an auto-entrepreneur, which sits outside the scope of Moroccan VAT (TVA): invoices carry no TVA line, and no TVA is reclaimable on them. If that ever changes — for instance if the business converts to a company — we will say so here first, and it will apply to invoices issued from that date onward, never retroactively.
- A plan is billed in advance for its period — monthly or annually, as you chose at checkout.
- Annual plans are billed once for the year at the discounted annual rate.
- Usage beyond what your plan includes is metered and billed in arrears, on the meters described in section 7.
- Invoices are issued to the billing email on the account and are available in the dashboard.
If a payment fails we will retry and notify you. If an invoice stays unpaid past the grace period shown in the dashboard, we may downgrade the account, stop new deployments, and eventually suspend running services. We will always send at least one notice before a suspension that would take a service offline.
7. Usage metering#
Some resources are metered rather than flat-rated: container memory-hours above your plan's allowance, object storage, outbound bandwidth, managed database storage, and — for workloads placed in the Morocco region — Moroccan egress on its own meter. Meters are read from the platform's own telemetry, aggregated per billing period, and shown in the dashboard before they are invoiced.
You can set a spend cap. When usage would take you past it we notify you, and depending on the cap's setting we either stop provisioning new resources or suspend the ones driving the spend. A spend cap is a safety net, not a billing guarantee: usage already incurred is still payable.
8. Cancelling and refunds#
You can cancel at any time from the dashboard. Cancellation takes effect at the end of the period you have already paid for; we do not pro-rate a partial month, and we do not refund a period you have used.
If we suspend or terminate your account for a reason that is our fault — for example we withdraw a feature you had paid for — we will refund the unused part of the period. If we terminate it for a breach of section 4, we will not.
9. Regions and the data-residency add-on#
Every resource you create belongs to one region and stays in it. The region is chosen at creation and never changes: moving a workload across a border is a redeploy plus a data migration, not a setting.
The data-residency add-on places your workloads in a specific country. What it covers is precise, and we would rather be precise than impressive: it covers your customer data at rest in that region — application containers, managed databases, object-storage buckets, snapshots and build inputs. It does not today cover the control plane, which is the dashboard, the platform database that holds resource metadata and encrypted configuration, and the audit log. Those run centrally, and where they run is stated in our Privacy Policy and in the Data Processing Agreement.
We do not claim that a residency region keeps one hundred percent of everything about your account inside one country, because that is not true while the control plane is central. If that matters to your procurement, read the residency section of the Data Processing Agreement before you buy the add-on.
The add-on is priced on top of a plan and may carry an expiry date. When it lapses, nothing moves: resources already placed in the region keep running there. What stops is your ability to place new ones.
10. Availability and support#
We publish live platform health on our status page. We aim for high availability and we design for it, but we do not currently offer a contractual uptime SLA with service credits. If and when we do, it will be a separate document referenced here.
We perform maintenance that can cause brief interruptions, and we try to schedule anything disruptive outside Moroccan business hours. Support is by email, in Arabic, French or English.
11. Suspension and termination#
We may suspend a service, or an account, where there is a serious and immediate problem: an active attack coming from your workload, a legal order, a payment that has gone unpaid past its grace period, or a breach of section 4. Where the situation allows it we contact you first; where it does not — an in-progress attack, for instance — we act first and explain immediately afterwards.
When you close an account, we soft-delete it and destroy live credentials straight away: sessions are revoked, connected Git tokens and two-factor secrets are cleared. The account then sits in a grace window of thirty days during which we can restore it. After that it is hard-purged: managed databases, buckets, search and queue instances and their volumes are deprovisioned for real, and the account record is deleted. Encrypted backups can still contain the data for up to fourteen more days before they age out.
12. Third-party services#
Gheima connects to services we do not control. GitHub is reached through a GitHub App you install; GitLab through an access token you paste for your own instance. Payments run through our payment provider. Email is sent through our relay. Using those connections means accepting their providers' terms too, and we are not responsible for their acts or outages — though we will tell you when one of them is why something of ours is broken.
13. Warranties#
We provide the platform with reasonable skill and care. Beyond that, and to the extent the law allows, we provide it “as is”: we do not warrant that it will be uninterrupted, error-free, or fit for a purpose you have not told us about. Nothing in this section limits rights you have as a consumer that cannot be limited.
14. Limitation of liability#
Neither side limits liability for death or personal injury caused by negligence, for fraud, or for anything else that cannot lawfully be limited.
Subject to that, and to the extent the law allows: neither side is liable to the other for indirect or consequential loss, loss of profit, loss of goodwill, or loss of data that the affected party could have prevented by keeping its own backups; and our total liability to you in any twelve-month period is capped at the amount you paid us in that period.
We take backups and we test restores, including an automated restore drill. They are our insurance, not yours. Keep your own copies of anything you cannot afford to lose.
15. Changes to these terms#
We will update these Terms as the platform changes. Every version carries a version number and a date, and the current one is always at this address. For a change that materially reduces your rights or increases your obligations, we will notify you by email at least thirty days before it takes effect; continuing to use the platform after that date means you accept the new version.
16. Governing law#
These Terms are governed by Moroccan law. Any dispute we cannot settle between us goes to the competent courts of Casablanca, Morocco. If you are a consumer resident elsewhere, this does not deprive you of the protection of mandatory rules of your own country.
17. Contact#
Write to hello@gheima.ma. For anything about personal data specifically, see the Privacy Policy, which sets out the same address and the process we follow.