Legal center
The fine print, in plain language.
Prello is an AI orchestration platform from Vallgaard. It runs on your own machine, your own keys, or our managed cloud, so a lot of our legal terms come down to one idea: your code and your data stay yours. These documents explain how that works.
These documents are working templates written for the Prello product. They are not legal advice. Before you publish or rely on them, have them reviewed by qualified counsel for your jurisdiction and business, and replace every [bracketed placeholder] with your real details.
What's here
Terms of Service
The agreement between you and Vallgaard for using Prello: accounts, plans, your responsibilities, and ours.
Acceptable Use Policy
What you may and may not do with autonomous agents, runners and connectors.
Billing & Refunds
How credits, plans, usage windows and top-ups work, and when money comes back.
Privacy Policy
What we collect, what we deliberately don't, and the rights you have over your data.
Cookie Policy
The small number of cookies and local-storage keys Prello uses.
Data Processing Addendum
For business customers: GDPR-aligned terms covering data we process on your behalf.
Subprocessors
The third parties that may process data when you use Prello Cloud.
Security
How we protect keys, sandboxes and your account.
Who we are
Vallgaard ("Vallgaard", "we", "us") is the team behind the Prello product ("Prello", "the Service"), based in Finland. Vallgaard is the name we build Prello under; it is not yet a registered company, so there is no company number, and we keep our operating address private. The best way to reach us is email: legal@prello.dev.
Agreement
Terms of Service
Effective 4 June 2026Version 2.0Governing law: Finland
These Terms are a contract between you and Vallgaard governing your use of Prello. By creating an account, installing the app, or running a loop, you agree to them.
1The Service
Prello lets you orchestrate AI agents to research, build, and ship software. It runs in three modes, and the mode you choose changes who holds your data:
- Local / self-hosted: agents run on your own machine. Your code never leaves it unless you tell it to.
- Bring your own key (BYOK): Prello calls AI providers using keys you supply, stored encrypted on your device. We never see them.
- Prello Cloud: managed runners execute loops on our infrastructure on your behalf, under the Data Processing Addendum.
2Accounts
You must be at least 16 and able to form a binding contract. You're responsible for your account, for anything done under it, and for keeping your credentials and any connected runners secure. Tell us promptly at security@prello.dev if you suspect unauthorized access.
3Plans, credits & payment
Prello is offered on the BYOK Limited (free), BYOK, Premium, Power User, Professional, Ultra and Enterprise plans. Every plan includes every feature; plans differ in infrastructure: monthly credit allowance, fair-use windows, cloud sessions and seats, described in Billing & Refunds. In short:
- Plans grant a monthly credit allowance, paced by nested fair-use windows (6-hour and weekly). Each larger window constrains the smaller.
- When a window is used up, loops pause until it refills. There's no overage billing.
- Fees are billed in advance and are non-refundable except as set out in Billing & Refunds or required by law.
- If you use your own keys, you pay your providers directly and are responsible for those costs.
4Your content & your output
You own what you bring and what you build. Code, prompts, data and projects you create with Prello are yours. We claim no ownership over them. You grant us only the limited licence needed to operate the Service for you, for example, to transmit a prompt to a model on Prello Cloud, or to display your project back to you.
You're responsible for having the rights to the content you feed into Prello and for how you use what comes out.
5AI output: no guarantees
⚑Agents write and run code autonomously. Output can be wrong, insecure, or unsuitable for your purpose, and quality gates reduce but do not eliminate that risk. You are responsible for reviewing, testing and approving anything before you ship or rely on it. Prello is a tool, not a warranty of correctness.
6Connectors & third-party services
When you connect a service (Gmail, Microsoft 365, Slack, GitHub, AI providers, and others), you authorize Prello to act within the scopes you grant, and your use of that service remains subject to its own terms. We are not responsible for third-party services, and a connector can be revoked by you at any time.
7Acceptable use
Your use must follow the Acceptable Use Policy. We may suspend or limit access to protect the Service, other users, or to comply with law.
8Intellectual property
Prello, its name, brand and software are owned by Vallgaard and licensed to you, not sold. The license is non-exclusive, non-transferable, and lasts only as long as you comply with these Terms.
9Disclaimers
The Service is provided "as is" and "as available" to the fullest extent permitted by law. We disclaim implied warranties of merchantability, fitness for a particular purpose, and non-infringement. Some jurisdictions don't allow these exclusions, so parts may not apply to you.
10Limitation of liability
To the maximum extent permitted by law, Vallgaard will not be liable for indirect, incidental, special or consequential damages, or for lost profits, data, or business. Our total liability for any claim is capped at the greater of the fees you paid in the 3 months before the claim or [USD 100]. Nothing limits liability that cannot be limited by law.
11Indemnity
You'll defend and indemnify Vallgaard against claims arising from your content, your use of the Service, or your breach of these Terms.
12Termination
You can stop using Prello and close your account at any time. We may suspend or terminate access if you materially breach these Terms or use the Service unlawfully. Because Prello is local-first, your local projects remain on your machine after termination; we'll delete account data per the Privacy Policy.
13Changes
We may update these Terms. For material changes we'll give reasonable notice (in-app or by email). Continuing to use Prello after changes take effect means you accept them.
14Governing law & disputes
These Terms are governed by the laws of Finland, excluding conflict-of-law rules. Disputes go to the courts of Finland, unless mandatory consumer law gives you another venue. Prello is built in Finland and our documents are written in English; if we provide a Swedish or Finnish translation and it conflicts, the English version governs.
Agreement
Acceptable Use Policy
Effective 4 June 2026
Prello hands real autonomy to agents: they run code, hit APIs, and act through your connectors. This policy keeps that power safe for you and everyone else on the platform.
1Don't do harm
You may not use Prello to build, run or distribute anything that:
- breaks the law or facilitates illegal activity;
- creates malware, exploits, spam, or tooling for unauthorized access to systems;
- infringes someone else's IP, privacy or other rights;
- generates content that sexualizes minors, incites violence, or harasses;
- attempts to deceive people about being AI-generated where the law requires disclosure.
2Connectors & data you reach
Only connect accounts you own or are authorized to use, and only point agents at data and systems you're allowed to access. Automated actions taken through a connector (sending mail, opening PRs, posting messages) are your responsibility.
3Fair use of the platform
Credit windows exist to keep Prello fast and fair. You may not circumvent rate limits or usage windows, share one account across an organization to dodge seats, or run loops whose only purpose is to consume resources. Enterprise plans exist for higher-volume needs.
4Security testing
Don't probe, scan or load-test Prello's own infrastructure without written permission. To report a vulnerability, see the Security page.
⚑We'd rather warn than ban. Where we can, we'll flag a problem and give you a chance to fix it, but serious or repeated violations can lead to immediate suspension.
Agreement
Billing & Refunds
Effective 4 June 2026
Prello bills in credits. One credit is a unit of model work; smart routing picks the cheapest model that still clears your gates, so credits stretch as far as the task allows.
1Plans
| Plan | Price | Credits / mo | Weekly window | Cloud sessions |
| BYOK Limited | Free | — (your key) | — | none (on-device only) |
| BYOK | $7 / mo | — (your key) | — | 200 MB |
| Premium | $20 / mo | 30,000 | 7,500 | 3 GB |
| Power User | $60 / mo | 90,000 | 22,500 | 5 GB |
| Professional | $120 / mo | 180,000 | 45,000 | 10 GB |
| Ultra | $240 / mo | 360,000 | 90,000 | 20 GB |
| Enterprise | Custom | Volume | Custom | 25 GB |
Every plan includes every feature: all loop types, unlimited agents, the full Builder / Code / Design toolset. Plans differ in infrastructure, not features. On BYOK Limited that means: sessions live only on your device, loops run only while the app is open (nothing runs while you're away), and one loop is active at a time. Weekly windows on credit plans are sized so steady use reaches the full monthly allowance. Yearly billing saves about 17%.
2Usage windows
- The 6-hour window is a rolling soft cap. It smooths bursts so a single session can't drain your week, and it refills continuously.
- The weekly window paces the month. It's sized generously, so steady use still reaches the full monthly allowance.
- The monthly allowance is the outer limit. Each larger window constrains the smaller ones.
- When a window is used up, loops pause until it refills; there's no overage billing and no surprise charges. With your own keys as fallback, work carries on uninterrupted.
◷Your live balance and pace are always visible in Settings → Plan & usage so there's never a mystery about where you stand.
3Top-ups
Need more before your reset? Top-up credits are priced at the same rate as your plan, with no premium for buying more. They never expire and are only spent after your plan allowance runs out.
4Bring your own key
If you power Prello with your own provider keys, those calls don't consume Prello credits and aren't billed by us; you pay your provider directly. You can also use your keys as a fallback so loops keep running when a usage window is exhausted.
5Renewals & cancellation
Subscriptions renew automatically each period until cancelled. Cancel any time in Settings; you keep access until the end of the paid period, and you won't be charged again.
6Refunds
- Subscriptions: within 14 days of a first purchase or upgrade, email us for a full refund if you've used only a minimal amount of credits.
- Consumed credits (model work already performed) are non-refundable.
- Top-ups are refundable for the unused balance within 14 days of purchase.
- Where consumer law gives you stronger rights, those apply.
Taxes may apply based on your location and are shown at checkout.
Privacy & data
Privacy Policy
Effective 4 June 2026Controller: Vallgaard
Prello is local-first by design, so the most honest summary is short: most of your work never reaches us at all. This policy covers the data we do handle, and why.
1What we deliberately don't collect
- Your API keys, on your machine. BYOK keys you add in the desktop app are encrypted on your device and stay there.
- Your local code & projects when you run locally; they stay on your machine.
- Your prompts and model traffic on a local BYOK run: those go straight from you to your provider. On Prello Cloud they pass through our runners, because that is what executes your loop.
2What we do collect
| Data | Why |
| Account: name, email, password hash | To create and secure your account. |
| Billing: plan, credit usage, invoices | To run subscriptions and metering. Card data is handled by our payment processor, not stored by us. |
| Prello Cloud content: code & prompts processed on managed runners | Only when you choose Cloud, and only to execute your loop. Covered by the DPA. |
| Product telemetry: feature events, errors, device type | To keep Prello working and improve it. Minimised and, where feasible, aggregated. |
| BYOK keys you add for Prello Cloud | Stored with us, encrypted at rest (AES-256-GCM), so our runners can call your provider on your behalf. Never written to logs, never shown back to you in full, and deleted when you remove the key. |
| Support: what you send us | To answer you. |
3How we use it
To provide and secure the Service, process payments, respond to support, meet legal obligations, and improve Prello. We do not sell your personal data, and we do not train models on your code or prompts.
4Legal bases (GDPR)
We rely on contract (to provide the Service), legitimate interests (security, product improvement, balanced against your rights), consent (optional analytics cookies), and legal obligation (tax, accounting).
5Sharing
We share data only with the subprocessors listed on the Subprocessors page, with authorities where legally required, and in a business transfer (with notice). Each subprocessor is bound by data-protection terms.
6Retention
Account data is kept while your account is active and for a limited period after closure for legal and accounting needs. Prello Cloud execution data is retained only as long as needed to run and debug your loop, then deleted or anonymised.
7Your rights
Access & portability
Get a copy of your data in a portable format.
Correction & deletion
Fix it, or ask us to erase it.
Object & restrict
Object to processing based on legitimate interests.
Withdraw consent
Turn off optional analytics any time.
Exercise any of these at privacy@prello.dev. You can also complain to your local data-protection authority.
8International transfers
Where data moves outside your region, we use safeguards such as Standard Contractual Clauses.
9Children
Prello isn't for anyone under 16, and we don't knowingly collect their data.
Privacy & data
Cookie Policy
Effective 4 June 2026
Prello uses very few cookies, and several "cookies" are really just local-storage keys that stay on your device, for example remembering your theme or which loop you were viewing.
1What we use
| Type | Purpose | Needs consent? |
| Essential | Sign-in session, security, load balancing. | No; required to work. |
| Preferences | Theme, layout, last-open project (kept in local storage). | No. |
| Analytics | Aggregated, privacy-respecting product usage. | Yes; off until you opt in. |
2Managing them
You can clear or block cookies in your browser, and toggle optional analytics in Settings. Blocking essential cookies may break sign-in.
3No ad-tracking
We don't use third-party advertising or cross-site tracking cookies.
Privacy & data
Data Processing Addendum
Effective 4 June 2026For business customers
This DPA forms part of the Terms for customers who use Prello Cloud to process personal data. Where you are the controller, Vallgaard acts as your processor.
1Roles & scope
You determine the purpose and means of processing (controller); we process personal data only on your documented instructions (processor), namely to provide Prello Cloud as described in the Terms.
2Our obligations
- Process only on your instructions, and tell you if an instruction appears unlawful.
- Ensure people authorized to process are bound by confidentiality.
- Apply appropriate technical and organizational security measures (see Security).
- Engage subprocessors only under equivalent terms, with notice of changes (see Subprocessors).
- Assist you with data-subject requests, breach notification, and impact assessments.
- Delete or return personal data at the end of the service, except where law requires retention.
3Sub-processing
You give general authorization for the subprocessors listed on the Subprocessors page. We'll give reasonable notice before adding a new one, and you may object on reasonable data-protection grounds.
4International transfers
Transfers outside the EEA/UK rely on Standard Contractual Clauses or another valid mechanism.
5Breach notification
We'll notify you without undue delay after becoming aware of a personal-data breach affecting your data, with the information you need to meet your own obligations.
6Audits
We'll make available the information needed to demonstrate compliance and support audits, subject to reasonable confidentiality and frequency limits.
⛁Need a signed copy for procurement? Email
legal@prello.dev and we'll countersign.
Privacy & data
Subprocessors
Last updated 4 June 2026
When you use Prello Cloud, these third parties may process data on our behalf. If you run locally or BYOK, most of these never enter the picture.
| Subprocessor | Purpose | Region |
| [Cloud host] | Managed runner compute & storage | [EU] |
| [Payment processor] | Subscriptions & card processing | [EU / US] |
| [Email provider] | Transactional email | [EU] |
| [Error monitoring] | Crash & error reporting | [EU] |
| AI model providers | Model inference for Prello-credit loops (not used for BYOK) | [US / EU] |
⇄Using your own keys? Model traffic goes directly from you to your chosen provider, so the AI-provider row above doesn't apply to you.
We'll post changes here and, for DPA customers, give advance notice before a new subprocessor starts handling your data.
Trust
Security
Last updated 4 June 2026
Prello's architecture is itself a security feature: local-first execution means the most sensitive things (your keys and your code) can stay on your machine.
1Keys & secrets
- BYOK keys you add in the desktop app are encrypted on your device and stay there. A key you add for Prello Cloud is stored with us, encrypted at rest (AES-256-GCM), never written to logs and never shown back to you in full.
- The local sandbox can be locked behind Touch ID / your OS password.
- Connector tokens use OAuth scopes you control and can revoke at any time.
2Account protection
- Two-factor authentication available on all accounts.
- Live session management: see and sign out every device.
- Passwords are hashed; we never store them in the clear.
3Prello Cloud
- Encryption in transit (TLS) and at rest.
- Isolated, ephemeral runner containers per loop.
- Least-privilege access and audit logging on Enterprise.
4Sandbox & agent safety
Agents run inside a configurable sandbox. You set the security level, choose whether actions outside a project root need approval, and decide whether passing builds auto-deploy. Quality gates must pass before a loop reports success.
5Reporting a vulnerability
⚿Found something? Email
security@prello.dev, ideally with steps to reproduce. We investigate promptly, won't pursue good-faith research, and will credit you if you'd like.
Help
Help & Support
Stuck, curious, or hit a wall? Here's how to get unblocked, fastest route first.
1Get help
📘 Documentation
Guides for loops, runners, packages, connectors and the Pareto router.
docs.prello.dev
💬 In-app support
Open the help menu in Studio or the phone app and send us a message; context attached automatically.
◈ Community
Trade patterns and templates with other builders in the Prello community.
2Common questions
Where does my code run?
Wherever you choose: your machine (local), a paired device, or Prello Cloud. You pick per loop, and it's shown on every runner badge.
Do you train on my code?
No. We don't train models on your code or prompts, and we don't sell your data. See the Privacy Policy.
What happens when I hit a usage window?
The 6-hour window refills continuously; the weekly and monthly windows reset on their own schedules. A paused loop resumes by itself when the window refills, or turn on BYOK fallback to keep going on your own keys. See Billing.
Can I use my own AI provider?
Yes: add OpenRouter, Anthropic, or any OpenAI-compatible provider in Settings, set a budget, and the router works within it. See Security for how keys are protected.
How do I cancel or get a refund?
Cancel any time in Settings; refunds follow the Billing & Refunds policy.
3Service status
◉Live status and incident history are at status.prello.dev. Enterprise customers can subscribe to incident notifications.
4Report a problem