AppGuard licence terms
Last updated 2026-08-17. This page governs use of the AppGuard Gradle plugin and the AppGuard Android library (together, the "Software"), and any Licence Key issued for it.
1. Parties
These terms are an agreement between Andreas Paphitis, of 9 Riga Fereou, Akaki, 2720 Nicosia, Cyprus, trading as AppGuard ("AppGuard", "we", "us") and the individual or entity that requests, purchases, or otherwise uses a Licence Key ("you", "Customer").
2. Definitions
| Software | The AppGuard Gradle plugin (pro.paphitis.appguard) and the AppGuard Android library AAR, together. |
|---|---|
| Licence Key | The signed, time-limited credential — format AG1.… — that the Software verifies offline at build time. |
| Application ID | The Android applicationId a Licence Key names as covered, together with any environment suffixes (for example .qa, .uat) named on that key. |
| Tier | Development, Startup, or Enterprise — see Pricing. Each Tier carries its own term and, for the paid Tiers, price. |
3. Licence grant
Subject to these terms and payment of any applicable fee, we grant you a non-exclusive, non-transferable, worldwide licence to integrate the Software into applications you develop, and to compile and distribute those applications, for each Application ID your Licence Key names as covered, for the Term that key carries.
A Licence Key is issued to one Customer for one base Application ID and its named
environment suffixes. It does not cover any other Application ID. A build whose resolved
applicationId is not named on the key fails at configuration time — this is
enforced by the Software itself, not manually.
4. Restrictions
You may not, and may not permit a third party to:
- decompile, reverse engineer, or otherwise attempt to derive the source of the Gradle plugin, in particular the licence-verification logic;
- remove, disable, or circumvent the licence check, or distribute a modified build of the plugin that does so;
- share, sublicense, resell, or otherwise make a Licence Key available for use with an Application ID it does not name;
- use the Software to build an application intended to defeat, evade, or misrepresent the integrity signals the Software itself is designed to report.
The Software's own source is not distributed — see the sources/javadoc artifacts published alongside it, which are placeholders by design, and why.
5. Term, expiry and renewal
Each Licence Key carries a fixed expiry date, set at issuance from its Tier: three months for Development, twelve months for Startup and Enterprise. The Software verifies this offline, at build time, with no network call to us — which means it also works with no network access, and an outage on our side never blocks your release. The consequence is symmetric: there is no grace period. A build performed after the expiry date fails at configuration time, immediately, regardless of whether you have since paid for a renewal.
Paid Tiers do not renew automatically — the Stripe purchase is a one-off charge for one Term, not a subscription. Renew before your key's expiry date to avoid an interruption; renewing issues a new Licence Key with a new expiry date.
There is no revocation mechanism. Once issued, a Licence Key remains valid, exactly as issued, until its stated expiry — including if your Customer relationship with us ends before then. This is a deliberate consequence of offline verification, not an oversight; see the design notes linked above.
6. Fees and payment
Prices are quoted in EUR, exclusive of VAT, per Application ID, and charged through Stripe at the time of purchase. Stripe Tax determines the applicable VAT rate from the billing address supplied at checkout and adds it to the quoted price. EU business customers who supply a valid VAT number at checkout are charged under the reverse-charge mechanism where applicable.
Development-tier Licence Keys are issued at no charge, subject to review, and are not an entitlement — repeated or abusive requests for the same Application ID may be refused.
7. Refunds and cancellation
Because a Licence Key is a digital credential you can use immediately on issuance, and because issuing one is the service being purchased, fees are non-refundable once a key has been issued, except where required by applicable law.
submitRequest.
8. Intellectual property
The Software, and all intellectual property rights in it, remain ours. This licence grants you the right to use it under these terms; it does not transfer ownership of anything. Applications you build using the Software, and their own source code, remain entirely yours.
9. Disclaimer of warranty
The Software does not make your application secure, and no software can. AppGuard is provided "as is." It is one layer that raises the cost and difficulty of tampering, repackaging, running an application on a rooted device, or attaching a debugger or a hooking framework — it does not make any of that impossible. A sufficiently capable attacker with control of the device can still defeat individual checks, and an application that integrates AppGuard can still be compromised, exactly as an application without it can. Using AppGuard is not a certification, warranty, or guarantee — express, implied, or otherwise — that your application is secure, that it is free from vulnerabilities of any kind, or that it will not be breached.
AppGuard checks for specific techniques known to us at the time of each release — signals associated with named rooting tools, hooking and instrumentation frameworks such as Frida, Xposed and LSPosed, repackaging, emulation, and attached debuggers. It is necessarily reactive: new bypass tools and techniques are discovered on an ongoing basis, and we update the checks as they become known to us, but there is inevitably a gap between a technique appearing and a check for it existing, and no commitment that every technique, present or future, will ever be covered. A check passing is evidence of the absence of what it looks for, at the moment it ran — nothing more.
To the fullest extent permitted by law, we disclaim all other warranties, express or implied, including merchantability, fitness for a particular purpose, and non-infringement. You are solely responsible for the overall security of your application — server-side validation, secure coding practice, and your own security testing — of which AppGuard is at most one part.
10. Limitation of liability
To the fullest extent permitted by law, we are not liable for any security breach, unauthorised access, data loss, or compromise of your application or its users — whether or not AppGuard was integrated at the time, whether or not the underlying technique was one AppGuard checks for, and regardless of whether a check ran, was configured off, or failed to detect what caused it. Our total liability arising out of or relating to the Software or these terms, for this or any other claim, is limited to the fees you paid for the Licence Key giving rise to the claim in the twelve months before the event, and we are not liable for indirect, incidental, special, or consequential damages, including lost profits or lost data, even if advised of the possibility.
11. Data and privacy
Requesting a Licence Key means giving us your company name, a contact email, and the Application ID you want covered; a paid request also passes through Stripe, which collects billing details directly. See our privacy policy for what we collect, why, who it is shared with, and your rights over it.
12. Termination
We may refuse to issue, or decline to renew, a Licence Key at our discretion — most commonly for abuse of the free Development tier, or a breach of the Restrictions above. Because verification is offline with no revocation, terminating the relationship does not itself invalidate a Licence Key already issued; see Section 5.
13. Changes to these terms
We may update these terms from time to time; the version in force is the one published here at the time. Material changes affecting a Licence Key you already hold will not reduce the rights that key already carries for its remaining Term.
14. Governing law and disputes
These terms are governed by the laws of the Republic of Cyprus, without regard to conflict of law principles. The courts of Cyprus have exclusive jurisdiction over any dispute arising from these terms, save where applicable consumer-protection law grants you the right to bring proceedings in your own jurisdiction instead.
15. Contact
Questions about these terms, or about a specific Licence Key — quote the licence id from your issuance email: andreaspaph@gmail.com.