Terms of Service

The terms under which Sakura is distributed. What it is, what it does, and where the responsibility for using it ends up.

Also see the Privacy Notice.

Last updated 2026-01-01

Acceptance

By downloading, purchasing, or using Sakura, you agree to these terms. If you do not agree, do not use Sakura. If you use Sakura on behalf of another party, you confirm that you have the authority to bind that party to these terms.

These terms apply to the desktop client, the licensing endpoint, the customer panel, and any documentation distributed alongside them. They do not apply to third-party software you choose to run in parallel.

What Sakura is

Sakura is a research tool for the study of human-computer interaction in rhythm-based games. Its purpose is to explore motor-control modelling, input synthesis, replay analysis, and timing statistics in a controlled environment.

The client runs as a desktop application alongside a game process. It reads state through a read-only handle and synthesizes input through the operating system's user-mode input stack. It does not modify the game, does not inject code, and does not touch network traffic. Everything it does is described in the reference material distributed with the license.

Sakura is licensed on a duration-based access model. Access is granted for the specific term purchased (such as 7, 30, or 90 days), after which the license expires unless renewed. Active licenses receive software updates and support throughout their duration.

A tool, not a policy

Sakura is a tool. Like any tool, its purpose is defined by the person using it, not by the person who made it. We ship a client that models human motor behavior and synthesizes input; we do not ship a stance about where that client should be run, who should run it, or what counts as acceptable in any particular environment.

We do not verify where the client is used, we do not monitor what it is used for, and we do not take a position on the rules of any environment it might be run in. Every environment has its own rules, written or unwritten, and every environment has its own operator who is the sole authority on those rules. Whether your use of Sakura is consistent with those rules is a question that only you and that operator can answer.

The existence of the tool does not imply that any particular use is sanctioned by us. The absence of a stated prohibition from us does not imply that any particular use is permitted by a third party. These two facts are separate, and both matter.

Anonymity

Sakura operates on a no-KYC basis. Anyone can purchase a license without disclosing identity. This is a deliberate design choice: the tool is a research artifact, not a service that profiles its users, and the licensing system is built so that identity is not a prerequisite for access.

Because no identity is required, we cannot and do not verify who is using the tool. We cannot determine the intended use of a given license. We cannot associate a license with a person, a region, an age, a jurisdiction, or a stated purpose. A purchase does not represent any endorsement, permission, or approval by us regarding how or where the tool will be used.

The user accepts that the burden of deciding whether a use is appropriate rests entirely with them. This is not a limitation we impose — it is the natural consequence of not knowing who the user is.

Third-party services

Sakura's infrastructure — payment processing, the customer panel, the licensing endpoint, DNS, and content delivery — runs on third-party providers. These providers may collect and process data such as IP addresses, request timestamps, user-agent strings, and other request metadata as part of their normal operation. We do not control what they collect, how long they retain it, or what they do with it. Their own policies govern that.

This applies to every interaction with our systems, including:

  • a purchase, regardless of the payment rail used;
  • a request to the customer panel;
  • a request to the licensing endpoint from the client.

The customer panel can be accessed in two ways: by signing in with an account (email and password), or by presenting a license file directly. In both cases, the request passes through third-party infrastructure before it reaches us.

If avoiding any third-party involvement is a hard requirement for you, we cannot meet it. The trade-off is explicit: the same infrastructure that lets an anonymous license exist at all is the infrastructure that touches your requests.

Guard your license file as you would a private key. For an anonymous license, the file is the credential. Anyone who has it can act as the license holder — see Ownership below.

Your responsibility

The final responsibility for how Sakura is used rests with the user. Every decision between the moment you install the client and any consequence that follows from it is yours. In practice, this means you are the sole party responsible for:

  • deciding whether a given use is appropriate in the environment you run it in, according to whatever rules that environment has;
  • the consequences of that use, including any action taken by a server operator, a platform, or a third party;
  • complying with the laws and regulations applicable in your jurisdiction;
  • the security of the machine on which Sakura runs;
  • keeping the license file secure, and accepting that possession of the file is the only means by which a license can be recovered, transferred, or acted upon;
  • any content, replay, recording, or derivative work created with Sakura.

We do not monitor how the tool is used, and we cannot intervene on the user's behalf in disputes that arise from its use. The client is designed to be safe and observable — read-only access, user-mode synthesis, no network interaction — but the decision to use it is yours, and the outcome of that decision is yours as well.

License

A purchase grants a non-exclusive, non-transferable, revocable license to run Sakura on the number of machines permitted by the tier purchased. The license is bound to a machine identifier derived from the hardware, as described in the privacy notice.

The license does not grant ownership of the software, the source code, the documentation, or any trademark. All rights not expressly granted are reserved.

The following are not permitted:

  • reverse engineering, decompilation, or disassembly of the client binary, in whole or in part;
  • modifying, patching, or otherwise altering the client binary or any of its dependencies;
  • bypassing, disabling, or circumventing any licensing check, authentication step, or hardware-binding mechanism;
  • extracting, reusing, or republishing any portion of the documentation or reference material without written permission.

These restrictions protect the integrity of the licensing system and the research work behind the client. They are enforced at the licensing endpoint and, where applicable, by law.

Ownership

For a license that has no account associated with it, ownership is determined by possession of the license file. Anyone who can present the file is treated as the license holder and can, on that basis:

  • request a hardware (HWID) transfer;
  • open a support request;
  • request a refund, subject to the conditions in Refunds;
  • associate the license with an account, thereby changing its mode of ownership.

This is a deliberate consequence of the no-KYC policy. The file is the credential. If the file is lost, the license is lost. If the file is shared, everyone who holds a copy can act as the holder. We have no way to distinguish a legitimate holder from anyone else who presents the file, and we do not attempt to.

Registering an account (optional, and not required) changes this: an account-bound license can only be acted upon while signed in to that account, which provides a stronger ownership signal than possession of the file alone.

Immutability

Every license carries two kinds of fixed data: fields whose values never change after issuance, and collections that may only grow. Both are enforced by the licensing endpoint, and neither can be rewritten, rolled back, or truncated.

Fields fixed at issuance:

  • the license identifier;
  • the issuance date;
  • the license end date;
  • the associated account, if any (see below).

The only mutable field on a license is the linked HWID — the HMAC-derived hardware identifier that the license is currently bound to. It is the field that a transfer modifies, and it is the field that determines which machine the license will authenticate on. Everything else listed above is fixed for the life of the license.

Collections that may only grow:

  • the HWID transfer history — an append-only log of every approved hardware binding change, each entry carrying a timestamp and the hardware identifier it was transferred to.

An append-only collection is not the same as a mutable field. New entries may be added when a transfer is approved, but existing entries are never modified, removed, or reordered. The history is complete by construction: the most recent entry is not a summary of past transfers, it is the last entry in a list that has never been truncated.

Storage

The link between a license and its HWID is stored on our servers. The stored form is the HMAC-derived identifier — a fixed-length digest that carries no information about the underlying hardware and cannot be reversed. No raw hardware value ever reaches the server, and no raw hardware value is stored. The link is anonymous by construction: a stored HWID identifies a machine to the licensing system, and to nothing else.

Relink process

A relink is initiated by the client, not by the user through the panel. The process works as follows:

  • the client is started on a machine whose HWID does not match the license's linked HWID;
  • before doing anything else, the client asks whether you want to request a relink to this machine;
  • if you decline, the client closes and no request is made;
  • if you accept, the client sends a relink request to the licensing endpoint, which validates it automatically — status, monthly quota, HWID history, and abuse signals are checked in the same call;
  • on a successful validation, the relink is applied immediately. The linked HWID is updated to the new machine, a new entry is appended to the transfer history, and the license is usable on the new machine from that point on.

The client never relinks silently. A user who starts the client on a new machine and does not explicitly accept the prompt leaves the license untouched.

Special cases

The automatic relink is the only way a transfer is applied. If you need a transfer outside the automatic rules — for example, because you have already used your two transfers for the current month, or because the new machine shares no overlap with the old one — do not initiate a relink request. Doing so will consume a quota slot, will be recorded in the transfer history, and may be declined by the automatic check.

Reach out through the customer area instead. Explain the situation before the client has been asked to relink. A moderator can handle the case manually, and the manual path does not go through the automatic quota.

Consequences of this design

  • the duration of a license cannot be extended;
  • purchasing additional licenses does not add time to an existing one — each license has its own independent end date;
  • the license identifier cannot be reissued or renamed;
  • the linked HWID is the only field a transfer may change;
  • the HWID transfer history cannot be cleared, rewritten, or shortened — not by the user, not by a moderator;
  • the automatic relink is the only path that applies a transfer, and it is always user-initiated from the client;
  • a license cannot be disassociated from an account once it has been associated with one.

If a change outside these fields is needed, it is handled as a new license, not as an edit to the existing one.

Hardware binding

A license is bound to the machine identifier (HWID) it was activated on. Changing that binding requires an explicit transfer, which is subject to review.

Rules for HWID transfers:

  • a transfer must be approved by a moderator before it takes effect;
  • a license may be transferred to a new HWID at most twice per calendar month;
  • requests beyond the monthly limit are refused, regardless of the reason;
  • the timestamp of each approved transfer is recorded on the license, as described in Immutability.

The limit exists because frequent HWID changes are the primary signal of a shared or leaked license. Users who legitimately change hardware more often than twice a month should reach out through the customer area before the change, so the request can be handled outside the automatic rule.

License lock. If a license is suspected of having leaked — for example, because it is being presented from an unusually large number of distinct machines, or because it appears in a public listing — the license may be locked. A locked license stops authenticating. Unlocking requires a manual review, and the license may be re-bound to a single HWID at that point.

Resale and distribution

Resale of a license is permitted. A license that has been legitimately obtained may be sold or given to another party, subject to the hardware-binding rules above. If you intend to resell licenses in volume, reach out through the customer area; special pricing may be available.

Purchasing a license from anywhere other than the official website is possible, but it means we cannot verify the license's origin. Licenses obtained through third parties are not covered by official support. Concretely, this means:

  • support requests for such licenses may be declined;
  • refund requests for such licenses will be declined;
  • HWID transfers may be declined if the origin cannot be verified;
  • if the license turns out to be stolen, revoked, or duplicated, the license will be locked and the loss is not recoverable through us.

Purchasing from the official website is the only way to guarantee that a license will be honored. Reselling a license you legitimately own is fine; buying one from an unauthorized source carries the risks described above.

Refunds

Because purchases are anonymous, refunds are limited to what can be verified by the license file alone. This means:

  • a refund can only be issued if the request is accompanied by the license file;
  • a refund cannot be issued if the license has been distributed, published, or shared;
  • a refund cannot be issued after the license has been bound to more machines than the tier allows;
  • a refund cannot be issued if the license has been flagged for abuse or locked;
  • a refund cannot be issued for a license obtained from a source other than the official website.

These limitations follow from the anonymity policy. Users who want a broader refund path may optionally register an account, which associates a license with an email address and provides a channel for verification. Registration is not required.

Acceptable use

The license may not be used to:

  • interfere with a server's operations, including its networking, authentication, or scoring systems;
  • forge, alter, or falsify a replay, a score, or any record submitted to a third party without that party's consent;
  • circumvent an access control mechanism on a system the user is not authorized to access;
  • operate in a jurisdiction where the tool is prohibited by law.

Nothing in Sakura's design is intended to facilitate any of the above. The client reads state and synthesizes input; it does not modify, forge, or interfere. The list is provided as a boundary on what the license covers, not as a statement about any specific environment.

Warranty and liability

Sakura is provided "as is", without warranty of any kind, express or implied, including but not limited to the warranties of merchantability, fitness for a particular purpose, and non-infringement.

We do not warrant that the client will be compatible with any particular version of a game, operating system, or hardware configuration; that any specific timing, accuracy, or behaviour will be achieved; or that use of the client will be uninterrupted or error-free.

To the maximum extent permitted by applicable law, we are not liable for any indirect, incidental, special, consequential, or punitive damages arising out of or relating to the use of Sakura, including loss of data, loss of access to a game account, loss of reputation, or loss of opportunity.

Where liability cannot be excluded, it is limited to the amount paid for the license in question.

Termination

A license may be revoked if these terms are violated. Revocation is typically applied for abuse of the licensing endpoint, distribution of the client, reverse engineering, repeated HWID changes beyond the monthly limit, or documented interference with a third party.

Because purchases are anonymous, revocation is enforced at the licensing endpoint by rejecting the license file. No user account is required for revocation, and no personal data is retained to enforce it.

The user may stop using Sakura at any time. Licenses expire automatically at the end of their term with no automatic recurring charges.

Changes

These terms may be updated to reflect changes in the client, the licensing server, or applicable law. The date at the top of the page reflects the most recent revision. Continued use of Sakura after a revision constitutes acceptance of the revised terms.

Contact

Reach out through the customer area if you have an account, or through the channel you used to purchase if you do not. Requests are handled on a best-effort basis.