AgentsPoppy
What you can growVerifiable updatesManifestoSecurityDevelopersStart vibe-codingDownload

Developer Agreement

Last updated 25 July 2026

This agreement (version 2026-07-25) governs your developer account, listing a poppy in the AgentsPoppy catalogue, and selling through the platform checkout. It complements our Terms of Service; by creating a developer account you accept both. It is written to be read — the same rules, explained at length, live in the developer docs.

1. Who we are

The platform is provided by Olly Digital, Amsterdam, the Netherlands (KvK no. 68745532) — support@agentspoppy.com.

2. Your developer account

  • Provide accurate information and keep your credentials secure. You must be able to form a binding contract.
  • If you sell, you must complete Stripe Connect onboarding — it verifies your identity and routes your payouts.
  • We record the version and time of your acceptance of this agreement. When it changes materially, you will be asked to accept the new version before continuing to use the dashboard.

3. What you may list

A listed poppy must, and you warrant that it does:

  • ship from a public, open repository that contains its complete source, under a license from the accepted list (§5);
  • declare all cloud access in its manifest, follow least privilege, and only ever modify resources it itself created;
  • ship your own code, not a runtime — no language runtime or bundled service binary inside the package; declare what you need and the platform provides it (§7);
  • pass certification that removal leaves no trace, and ship byte-reproducible packages pinned by hash;
  • carry a truthful age rating (from the submission questionnaire) and a truthful data-flow declaration (§6);
  • be your own work that you have the right to distribute, infringing no one's rights and breaking no law;
  • be a real, working app in genuine use — not a placeholder to reserve a name.

4. Originality — clones are rejected

Competing poppies are welcome; copies are not. You may build a poppy that competes with an existing listing, but it must introduce functionality that genuinely distinguishes it. Submitting a copy or trivial re-skin of another poppy's code, name, or icon — in whole or in substantial part — will be rejected; repeat attempts close the account. We do not list multiple poppies that look alike and do substantially the same thing.

5. Licensing

  • Encouraged: MIT (featured and taken in greatest consideration), Apache-2.0, BSD-2-Clause, BSD-3-Clause.
  • Accepted: MPL-2.0, LGPL-3.0, GPL-3.0, AGPL-3.0.
  • Not accepted: licenses that forbid commercial distribution (so the platform checkout could not lawfully sell your poppy), forbid derivatives or auditing, or restrict others from building competing software (non-compete / restricted source-available licenses). Other licenses may be proposed and are reviewed case by case.

6. Data & privacy

  • The default architecture is that user data stays in the user's cloud account. Your submission must declare every flow of user data to any destination outside it: what data, where it goes, for what purpose, and whether you collect or retain any of it.
  • If any user data reaches services you operate — including external clients you monetise — you must maintain a privacy policy covering it, linked from your listing, and on request give us confidential audit access to the receiving service's source as a condition of listing.
  • Undeclared reading, copying, or transmission of user data is a material breach: immediate removal, account closure, blocklisting of the poppy (which warns existing installs), and cooperation with law enforcement where applicable.

7. Dependencies — declare, don't ship

  • Your package must contain your own code and assets — never a bundled runtime or service binary. Compiling a language runtime (Node, Python, a browser engine…) or a third-party service (Redis, Postgres, ffmpeg…) into your package is not permitted, and is rejected mechanically at certification, at review, and at install.
  • Declare what you need; the platform provides it. Runtimes and dependencies are declared in the manifest and supplied by AgentsPoppy from the official upstream, pinned by hash inside the signed app — you never supply the bytes or the source URL. Today the Node runtime is included in the app; any future downloadable dependency is fetched from its official source only after the user approves it.
  • This is a security requirement, not a size preference: a runtime you compile in is opaque bytes nobody can trace to their source, which defeats the open-repo audit users rely on. A poppy that needs, say, a Redis database declares “redis”; the user approves it; AgentsPoppy fetches it from the official source and verifies it — you never touch those bytes.

8. Selling and fees

  • You are the seller and merchant of record on your own Stripe account; you are responsible for your prices, taxes, refunds, and customer support. We charge a flat 5% platform fee on sales processed by the platform checkout. Sales you make outside the platform carry no fee.
  • A listed poppy may not gate its own features behind an external checkout or steer users off-platform to unlock them; when you sell, a visible way to manage billing must always be present.

9. Conduct

  • No malware, no deception, no interference with users, other poppies, or the platform.
  • Keep your contact reachable; abandoned listings may be delisted with notice and the name freed.

10. Review and enforcement

  • Every submission and update is reviewed; we may decline or remove a listing that breaks these terms or puts users at risk. Permission changes always require the user's renewed approval.
  • Ordinary rule breaches get notice and a chance to fix; safety risks and deception are removed immediately. Blocklisting is reserved for poppies that endanger users.
  • Nothing here restricts distribution outside the catalogue: sideloading your poppy directly to users remains available regardless of listing status.

11. Intellectual property

  • Your poppy remains yours. You grant us the non-exclusive right to host, display, and distribute your listing (metadata, icon, packages) for operating the catalogue.
  • Naming follows the trademark policy: your own brand plus the required “…Poppy” suffix; you may not use “AgentsPoppy”, the bare name “Poppy”, or our marks and icons as or in your own.

12. Liability

The platform is provided “as is”; to the extent permitted by law, our liability to you under this agreement is limited to the fees we retained from your sales in the twelve months before the claim. Nothing limits liability that cannot lawfully be limited.

13. Changes and law

We may update this agreement; material changes take effect when you accept the new version, which the dashboard will request. Dutch law governs; disputes go to the competent court in Amsterdam, without prejudice to mandatory consumer or other protections that apply to you.

Version 2026-07-25. Questions? support@agentspoppy.com

Home·Privacy·Terms·Security