Tome License
This license governs your use of the Tome package library — the block packs, themes, and platform packages distributed through Wabbit's private registry. It is separate from the Terms of Service, which governs your use of the wabbit.com website generally, and separate from any signed contract you have with us for one-off design or development work.
If anything here appears to conflict with your subscription agreement or a signed contract, the more specific document controls.
What You've Installed Is Yours to Keep
When you install a Tome package under an active subscription or entitlement, that specific version is yours to keep using — forever. Installing it into a project and committing it to your own repository does not put a clock on it. We do not reach into a project you have already built and revoke access to code that is already there, and we never will.
What Tome Reports
Two different things get reported, and neither one is a remote control. First, our registry logs the network address and installer identity behind every request against a Credential — routine access logging, kept ninety (90) days, used only to catch Credential sharing and keep the registry secure.
Second, once you deploy, the app itself sends a small Heartbeat at start-up and once a day: a one-way hash of the Deploy Credential it was installed with, its host name, its runtime environment, and the names and versions of the Tome packages running. That is the whole payload.
What It Never Contains
The Heartbeat never carries Credentials themselves, none of your end users' data, and none of your application's content. It reports what is installed and where — nothing about who is using it or what they are doing there.
Our Reply Can't Switch Anything Off
Whatever we send back in response, the app does not act on it. There is no channel by which a reply from us disables, degrades, or gates anything already running in your build — see What You've Installed Is Yours to Keep above.
Air-Gapped or Isolated Deployments
If a deployment genuinely cannot reach us — air-gapped, classified, or otherwise isolated — ask us for a written waiver releasing that Site from the Heartbeat. We grant these on request; disabling it without one is a breach.
What Does Not Count
Development, staging, preview, and continuous-integration environments are not Sites, and none of them count against your Site Allowance — see Sites and Credentials below.
Sites and Credentials
A Site is one deployed app running under one Deploy Credential — for you or your end users, or delivered to a client. How many Sites you get depends on your plan:
- Free — 1 Site, 1 Dev Credential.
- Per-Family plans — 3 Sites, 3 Dev Credentials.
- Full Platform — 10 Sites, 5 Dev Credentials.
- Administrative grants — 3 Sites, 3 Dev Credentials, unless the grant record says otherwise.
Each Deploy Credential is bound to one Site — get a separate one per Site rather than reusing one across several. Dev Credentials are not tied to any Site; they are for development and CI machines, and expire automatically after thirty (30) days.
Vendoring a project into a client's codebase counts as one of your Sites, unless that client holds their own Tome entitlement — see Vendoring Into Client Projects below.
Vendoring Into Client Projects
You may vendor Tome packages into client projects you build and deliver — carry the installed source into a client's codebase as part of the site or app you are shipping them. Once it is vendored into a client's project, that code belongs to the project. What happens to your Wabbit subscription afterward does not matter to it. Your client's build was never renting the code from us in the first place.
What an Active Subscription Buys
An active Tome subscription buys you two things, and only two things:
- New installs — pulling a package you are entitled to for the first time, into a new project.
- Updates — pulling a newer version of a package you already have installed.
Both of those require a live connection to the registry and an active entitlement. Everything else — what you have already installed, what you have already vendored into a client's build — does not need the subscription to keep working.
If You Cancel
Cancelling stops future installs and updates. It does not touch anything already installed or vendored. A site you shipped last year keeps running exactly as it did the day you shipped it — nothing gets remotely disabled and nothing checks whether you may keep running — the only thing a Tome app sends us is a small daily report of what is installed and where (see What Tome Reports), and our reply can't switch anything off. This is a deliberate design decision, not a courtesy we might revisit later: your clients' builds should never be hostage to whether you are still paying us. For what happens if the registry itself ever goes away permanently, see Continuity.
What This License Doesn't Cover
This license covers using Tome packages to build sites and products — yours or your clients'. It does not cover operating a competing package registry built from our source, or reselling the library itself — rather than the sites you build with it — as a standalone product. If your use case sits near this boundary, ask us before you build on an assumption.
How This Fits With the Terms of Service
This license supplements, and does not replace, our Terms of Service — read them together. Refunds, support scope, and the general no-SLA / best-effort posture for the registry are covered there and on the Support and Continuity pages, not repeated here.
About This License
If anything here is unclear, or you are trying to work out whether a specific use case is covered, ask us — see Support. If this license changes, we will flag the change.
This is version 0.3.0, issued by Wabbit, LLC. It is governed by the laws of the United States of America and in the English language only; you hereby consent to binding arbitration in the United States, and in the English language, to resolve any disputes arising under it.
This license has not yet been reviewed by outside counsel, and does not yet name a specific jurisdiction or address indemnification — we will update this page when it does, and before we ever issue it to a first paid external customer.
In force since July 2026.