Bolvrk
DocsFeaturesPricingSecuritygithub-logo
Sign in Open app
Legal

Terms of service

Last updated 2 September 2026

Parties

These terms are a contract between Simon ApS, CVR DK38213458, Gersonsvej 40, 1., 2900 Hellerup, Denmark ("Bolvrk", "we") and the organisation on whose behalf a team is created ("you", the "customer"). The person who creates a team confirms they are authorised to bind that organisation.

The hosted service is offered to businesses, public bodies and other organisations, and to individuals acting in the course of their trade or profession. By creating a team you confirm you are not acting as a consumer. Consumer protection rules — including the 14-day right of withdrawal — do not apply.

The privacy policy and the data processing agreement form part of these terms.

The service

Bolvrk analyses Postgres migrations for operations that are dangerous to run against production databases. The hosted service adds CI integration, team history, live-schema checks, the team run log, notifications, and optional AI review. The open-source CLI is licensed separately under the MIT licence; these terms cover the hosted service and the proprietary rule corpus it runs.

What Bolvrk is — and is not

Bolvrk verifies; it does not guarantee. A clean check means our rule corpus found nothing. It does not mean a migration is safe, and you remain responsible for reviewing, testing and running your own migrations. Findings are advisory. We engineer for silence over false alarms, which by design means we do not flag what we cannot prove.

AI review output is machine-generated advisory commentary. It is never part of the safety verdict, cannot pass or fail a check, and should be weighed like any colleague's opinion. The deterministic findings are the product's claims; the review is not.

Your account and acceptable use

  • Sign in through GitHub; you are responsible for what happens under your account.
  • Keep your team tokens secret; anything done with a valid token is attributed to your team.
  • Only connect databases you are authorised to connect. Use a shadow or replica, not your primary.
  • Do not probe, overload, or attempt to break the service outside our disclosure process.
  • Do not use the service to build a competing rule corpus, and do not resell or share access to it.
  • Do not submit content you have no right to submit, or content that is unlawful.
  • Avoid submitting personal data inside migration SQL; the service is built for schema changes, not data.

Your content

You keep ownership of the migration SQL, schema structure and anything else you submit. You grant us a licence to store and process it only to the extent needed to provide the service to your team — running checks, keeping your history, producing insights, sending notifications you configure, and sending a review to our model provider when you ask for one. We claim no other rights in it and do not use it to train AI models. Personal data in your content is handled under the data processing agreement.

Fees, VAT and refunds

  • Paid plans are billed monthly in advance through Stripe, in US dollars, flat-priced per team. Prices are exclusive of VAT.
  • VAT is calculated by Stripe Tax at checkout. Customers in the EU with a valid VAT number are invoiced under the reverse-charge mechanism; otherwise VAT is added where applicable. You are responsible for the accuracy of the billing details and VAT number you provide.
  • You can cancel any time from the billing page; access runs to the end of the paid period. We do not refund partial months.
  • We may change prices with at least 30 days' notice by email or in the app. The new price applies from your first billing period after the notice period ends; if you do not accept it, cancel before then.

Suspension and termination

You can leave any time by deleting your team from the app where available, or by writing to hello@bolvrk.com. We may suspend a team when a payment is 14 days overdue, or immediately on abuse of the service or a breach of these terms; we lift a suspension for non-payment as soon as the balance is settled. We may terminate with 30 days' notice, or without notice for a serious breach.

On termination the team drops to the free tier or, on deletion, is removed. We delete the team's stored checks, findings, reviews, connections, tokens and notification channels within 30 days after deletion, and backups roll over within a further 30 days, unless the law requires us to keep something longer (bookkeeping records, for example).

If we ever discontinue the hosted service, we will give at least 90 days' notice. The CLI remains available under its open-source licence regardless.

Warranty disclaimer

The service is provided "as is" and "as available". We give no warranty that a migration is safe to run, that the service will be uninterrupted or error-free, or that it will meet your requirements. Any warranty implied by law is excluded to the extent the law allows.

Liability

To the extent Danish law allows, our total liability for all claims arising from or in connection with the service in any 12-month period is limited to the fees you paid us in the 12 months before the claim arose, and we are not liable for indirect or consequential loss — including lost data, lost profits, downtime, or the cost of a migration that a check did not flag. Nothing here limits liability that cannot lawfully be limited, such as liability for gross negligence or intent.

Indemnity

You will defend and indemnify us against third-party claims arising from content you submit — including claims that you had no right to submit it, or that it contained personal data you were not entitled to share — and from your use of the service in breach of these terms.

Confidentiality

We treat your migration SQL, findings, schema structure and connection details as confidential. We disclose them only to the sub-processors listed in the privacy policy to provide the service, or where the law requires it. This obligation survives termination for as long as we hold the information.

Changes to these terms

We may update these terms. For material changes we give at least 30 days' notice by email or in the app before they take effect; continuing to use the service after that date means you accept the new terms. If you do not, delete your team before they take effect.

Governing law and venue

These terms are governed by Danish law, excluding its conflict-of-law rules and the UN Convention on Contracts for the International Sale of Goods. Disputes are brought before the Copenhagen City Court (Københavns Byret) as the court of first instance.

Contact

Simon ApS, Gersonsvej 40, 1., 2900 Hellerup, Denmark · hello@bolvrk.com · bolvrk.com/contact.

Bolvrk

The bulwark between your migrations and production.

Bolvrk is a product of Simon ApS · CVR DK38213458 · Gersonsvej 40, 1. · 2900 Hellerup · Denmark

ProductFeaturesPricingSecurityChangelogRoadmap
ResourcesGetting startedRule referenceGitHubnpmReport a vulnerability
CompanyAboutContactJobs
LegalPrivacyTermsData processing
© 2026 Bolvrk. Free CLI, hosted corpus.