Legal
Operator Agreement — Verein edition (DRAFT v0.1, 2026-09-05)
DRAFT — NOT LEGAL ADVICE. REQUIRES COUNSEL REVIEW BEFORE ACTIVATION. Supersedes
operator-agreement.md(draft-2026-07-05, Block Lab GmbH as controller) once the Verein is registered. Until then the old draft applies. Counterparty: [Decent Render Verein], [seat], Switzerland (the “Verein”). Technical operator under Statutes Art. 24: Block Lab GmbH (the “Executor”). Network: Decent Render (the “Network”). 🟧 = counsel to confirm.Shown and accepted in the device pairing flow on decent-render.farm/devices. German version to follow for CH members; English is the working text.
1. Who you are dealing with
1.1 You (“Operator”) make a computing device you already own available to the Network to render jobs for the Network’s customers (“Tenants”).
1.2 Your contract is with the Verein. The Executor runs the Network’s servers and software on the Verein’s instructions. The Executor is not your counterparty and cannot change these terms.
1.3 Accepting these terms does not make you a member of the Verein. Membership is separate and voluntary (Statutes Art. 5). Members and non-members are treated alike as Operators. 🟧 Q9
1.4 You are an independent operator, not an employee, agent, or partner of the Verein or the Executor. You decide when your device is online.
2. What the software does on your device
2.1 The decent supervisor is open-source (Apache-2.0, Statutes Art. 4 no. 2).
It receives jobs, renders them headlessly, uploads the output, and deletes the
working directory. You may read the code at any time.
2.2 Updates are opt-in. If you enable auto-upgrade, the supervisor upgrades itself only when idle and never interrupts a running render. If you keep it off, you upgrade by hand. The Network may stop assigning jobs to versions it no longer supports.
2.3 The Executor can never push code to your device outside the published release channel. Every release is signed and public. 🟧 (payload signing pending, N-21)
3. No data retention (the purge rule)
3.1 Tenant content exists on your device only for the duration of a job. On completion or failure the working directory is deleted automatically (Statutes Art. 4 no. 1). You must not disable, delay, or work around this.
3.2 You must not copy, cache, back up, or inspect Tenant content, inputs, or outputs. The process is automated; there is nothing for you to look at.
3.3 If you ever find residual Tenant data (for example after a crash), delete it and report it to [security@decent-render.farm] within 24 hours.
4. Confidentiality and security
4.1 Everything that passes through your device on behalf of a Tenant is confidential. Do not disclose, share, or transmit it.
4.2 Keep your device reasonably secure: current OS patches, no shared administrator accounts, disk encryption on. The Verein may set minimum requirements in the Network Rules and may refuse devices that fail them.
4.3 Do not attempt to influence job assignment, verification, or accounting other than through the published protocol. Doing so is a serious breach (Statutes Art. 8).
5. Verification and honest settlement
5.1 Completed work is verified under published rules (Statutes Art. 4 no. 3). Only verified work is paid.
5.2 Jobs that fail because of your device (crash, offline, wrong version) are not paid. Jobs that fail because of the Network or the Tenant do not count against you.
5.3 Verification results and your earnings ledger are visible to you on decent-render.farm/devices.
6. Payment
6.1 You are paid for verified render time under the Verein’s Compensation Rules, published at [decent-render.farm/rules]. The current split of each Tenant payment is: Operator [70 %], Executor [20 %], Verein [10 %], after a small network fee that is burned. The Verein may change the split by published rule with at least [30] days’ notice; changes never apply to work already done. 🟧 Q1/Q6
6.2 Payment is made by transfer of the Tenant’s paid network token (DRF) to a wallet you control, or, if you choose, as closed-loop credits usable in the [driffs] application. Nothing is minted to pay you; you receive part of what the Tenant paid (Statutes Art. 23).
6.3 The Verein holds nothing for you. Tokens go to your own wallet under your control. Keep your keys safe; lost keys cannot be recovered by the Verein.
6.4 Until the token exists, your earnings are recorded as points in the Network ledger. Points convert to DRF at launch at a single flat rate published in advance. Points have no cash value and are not transferable. 🟧 (transition clause; tokenomics r5)
6.5 Tokens are payment for compute you delivered. They are not a share in the Verein, carry no vote, and are not an investment. The Verein makes no statement about their future value and operates no market for them.
6.6 You are responsible for your own taxes and social contributions on what you earn. The Verein does not withhold. Amounts are reported in the ledger.
7. The paid pool is opt-in
7.1 Your device joins the paid pool only when you switch consent on in the Devices page. Off means no jobs and no earnings.
7.2 You can leave at any time by switching consent off, revoking the device, or uninstalling the supervisor. Running jobs finish first; nothing is cancelled mid-render.
8. Suspension and revocation
8.1 The Verein may suspend or revoke a device at any time for breach of these terms, the Network Rules, or the Statutes, for security reasons, or for legal or sanctions reasons (Statutes Art. 8). Revocation invalidates the device token immediately; no new jobs are assigned.
8.2 You keep verified earnings already credited, unless they are the subject of the breach (for example manipulated verification).
8.3 You may ask the Vorstand to review a revocation within [30] days.
9. No warranty, limited liability
9.1 The Network is provided as is. The Verein does not guarantee any volume of jobs or level of earnings.
9.2 The Verein is not liable for damage to your device, data, or electricity costs from rendering, except where caused by its gross negligence or intent. Mandatory law is not affected.
9.3 You are liable to the Verein for damage caused by your intentional or grossly negligent breach of sections 3, 4, or 4.3.
10. Identity and eligibility
10.1 The Verein may require identity verification before paying out, as its Compliance Rules require. Devices from sanctioned jurisdictions or persons are not eligible. 🟧 Q7/Q12
10.2 One person, one identity. Multiple devices per person are fine; multiple identities are not.
11. Changes to these terms
11.1 The Verein may update these terms by published rule with at least [30] days’ notice, shown in the Devices page. Continuing to run the paid pool after the notice period means acceptance. You can leave at any time (7.2).
11.2 Changes never reduce payment for work already verified.
12. Governing law
Swiss law. Courts at the seat of the Verein, subject to mandatory forums and non-waivable consumer rights. 🟧
By enabling the paid pool in the device pairing flow you confirm that you have read and accept these terms, the Network Rules, and the Compensation Rules.
Changes from the 2026-07-05 draft (for counsel)
| Section | Change | Why |
|---|---|---|
| 1 | Counterparty Verein, Executor named, non-member clarified | Statutes Art. 24, 25 |
| 2 | Open-source + opt-in auto-upgrade + signed releases | Statutes Art. 4 no. 2; feature shipped 2026-09-04 |
| 5 | Verification / honest settlement explicit | Statutes Art. 4 no. 3 |
| 6 | Real payment: DRF transfer or credits, points transition, tax | economics-model transfer model; old draft said “no payout” |
| 7 | Consent to paid pool explicit | Devices page feature |
| 10 | Identity / sanctions | Compliance Rules, Q7/Q12 |
| 12 | Forum = seat of Verein (was Zürich) | placeholder until seat decided |