# Opelli

> Opelli is a company-operations platform for lean organizations: projects,
> tasks, resource planning, time tracking, people, a sales pipeline, email
> campaigns, public forms, GDPR compliance and an org-wide audit log in one
> minimal product — with agents inside it that read customer conversations and
> propose the fields, and an MCP server that lets Claude, ChatGPT or any other
> MCP-capable agent — including one running locally — read and write all of it
> through 90+ tools, under the operator's own permissions. That includes building, publishing and hosting microsites
> from the same conversation. Operated by Opelli s.r.o.
> (Czech Republic); hosted at `<company>.opelli.dev` or on the company's own domain.

This file is the agent-readable edition of
https://opelli.dev — the whole site, every page in full, generated from the pages
themselves.

## Contents

Every page below is reproduced IN FULL in this file, in this order — nothing
here needs to be fetched separately. The links are for jumping to a single
page, not for reaching content this file leaves out.

- [Opelli — your company in one system, ready for AI](https://opelli.dev/): Projects, tasks, capacity, time, customers, deals and invoicing share one platform. Connect Claude, ChatGPT or another assistant through MCP and let it work across the company within your permissions.
- [Features — Opelli](https://opelli.dev/features): The seventeen modules of Opelli, grouped into five areas: Projects & work, Planning & people, Sales & finance, Security & control, and AI & assistants.
- [Projects & work — Opelli](https://opelli.dev/features/work): Projects & work in Opelli: a project overview, collaborative project knowledge and a task board that stays focused — team, capacity, time, deadlines and customer context in one place.
- [Planning & people — Opelli](https://opelli.dev/features/time-people): See team capacity, tracked time and approved monthly timesheets in one connected view.
- [Sales & finance — Opelli](https://opelli.dev/features/business): From first contact to order, payment and invoice — with campaigns, sites and forms connected to the same customer data.
- [Security & control — Opelli](https://opelli.dev/features/trust): Permissions, security and audit records for teams that need to know who can see what and what changed.
- [AI & assistants — Opelli](https://opelli.dev/features/agents): The AI layer in Opelli — built-in agents that prepare suggestions from your business context, and an MCP server that connects Claude, ChatGPT or your own AI assistant within your permissions.
- [Pricing — Opelli](https://opelli.dev/pricing): Your first three users are free, forever. Every additional user is €13 per month, with all seventeen modules, the MCP server and guest access to the pages you share with clients. Connected AI assistants do not need a seat; model usage is metered.
- [Opelli company — built to grow with your business](https://opelli.dev/company): Opelli fits growing SMEs today: start with three users free and keep one connected platform as projects, people and processes multiply — with a clear path toward the certifications and integrations larger organizations require.
- [Terms of Service — Opelli](https://opelli.dev/terms): The terms governing your use of Opelli, the company-operations platform operated by Opelli s.r.o.
- [Acceptable Use Policy — Opelli](https://opelli.dev/acceptable-use): What fair use of Opelli means — for accounts inside the free seats, for the volumes we meter, and for the volumes we do not. Written to be checkable: what we enforce today, and what we reserve the right to enforce with notice.
- [Privacy Policy — Opelli](https://opelli.dev/privacy): How Opelli s.r.o. collects, uses and protects personal data in connection with Opelli — including the controller/processor split, sub-processors and your GDPR rights.
- [Connecting an agent (MCP)](https://opelli.dev/index.md#connect-an-agent-to-opelli-mcp): the endpoint shape, both auth paths, the tool catalog and the permission ceilings — appended to the home page below. Each company's instance serves its own MCP endpoint at `https://<company>.opelli.dev/mcp`; there is no central one, because there is no central copy of anyone's data.

_Generated 2026-08-25 from https://opelli.dev. A markdown twin of each page is also served
individually (e.g. https://opelli.dev/pricing.md), and https://opelli.dev/llms-full.txt is this same
content without the contents list. The site also ships a full Czech edition
under https://opelli.dev/cs/ — the same pages, hand-written in Czech, each with its own
markdown twin (e.g. https://opelli.dev/cs/pricing.md); it is not inlined here because it
says in Czech what this file already says._

---

# Opelli — your company in one system, ready for AI

> Projects, tasks, capacity, time, customers, deals and invoicing share one platform. Connect Claude, ChatGPT or another assistant through MCP and let it work across the company within your permissions.

_Markdown edition of https://opelli.dev/ — generated from the page itself on 2026-08-25._

---

_One platform · seventeen modules · 90+ tools for AI assistants_

## Company operations, wired to your assistant.

Opelli

Projects, tasks, capacity, time, customers, deals and invoicing share one platform. Connect Claude, ChatGPT or another assistant through MCP and let it work across the company within your permissions.

### What it covers — Five areas. Shared data.

Seventeen modules share the same projects, people and permissions, so plans, time, invoices and reports stay in sync. Your assistant works with the same connected context.

01

#### Projects & work

Projects, tasks, project knowledge, the data your automations write — and the mini-apps your team runs on it all.

- Projects
- Wiki
- Tasks
- Datasets
- Apps

Learn more →

02

#### Planning & people

Plan capacity, track time and approve monthly timesheets.

- Planning
- Time
- People

Learn more →

03

#### Sales & finance

CRM, orders, invoicing, campaigns, sites and forms.

- Customers
- Orders
- Finance
- Marketing
- Sites
- Forms

Learn more →

04

#### Security & control

Permissions, security, compliance, audit records and signed documents.

- Access
- Security
- Compliance
- Audit
- Signing

Learn more →

05

#### AI & assistants

Opelli agents and MCP for the assistant you already use.

- Agents
- MCP

Learn more →

### Bring your own assistant — Connect Claude, ChatGPT or another AI assistant.

Connect once and let your assistant work with projects, tasks, planning, CRM and other Opelli modules. It can read and write through more than 90 tools, always in your name and within your permissions.

- **Ask across the company** — "Who is over capacity next month, and which deals are waiting on them?" is one question across planning, people and sales.
- **Turn decisions into updates** — Create tasks, log a call, move a deal or record time — every change happens in your name and shows in the record as your work.
- **Create a site from project material** — Ask for a page and get a draft built from what is already in the project. Nothing is published until you approve it.
- **Keep every action within your permissions** — An assistant can only use what you can access, and administrators can limit or revoke a connection at any time.

**One connection, the assistant you already use.** It starts working with your company's real context — projects, time, customers and published pages. [See how it connects →](https://opelli.dev/features/agents.html)

### The project page — "How is it going?" — answered on one screen.

Team and capacity, planned and tracked time, budget, deadlines, wiki and tasks — everything about the project on one screen.

![A project detail page: team and capacity table, budget chart, wiki and task widgets.](https://opelli.dev/img/project.jpg)

[See Projects & work →](https://opelli.dev/features/work.html)

### Readable by people and machines — Your company, in Markdown.

Wiki pages, reports and the documents you publish share one portable format — readable by people, programs and AI assistants alike.

- **Write once, reuse anywhere** — Wiki pages, briefs and reports use a portable format.
- Export your wiki without losing its structure.
- Give your assistant the same material your team already works with.

**Your data stays portable.** What you write in Opelli you can take with you — or hand to an assistant as it is. [See what reads it →](https://opelli.dev/features/agents.html)

### The small things — Fast by default.

##### Keyboard first

Work fast with the same shortcuts in every module.

##### Desktop and mobile

Works across desktop and mobile.

##### Notifications where you work

An assigned task, an approved month or a shared page arrives in Slack or Mattermost, with email as the fallback.

##### Search everything

One search across projects, wiki pages, tasks, people and customers, filtered by your permissions.

##### Your own address

Your company at `you.opelli.dev` minutes after the invite — or on your own domain, certificate included.

### See it on your own operations.

Opelli runs in the cloud on an `opelli.dev` address or your own domain. Leave your email and we will show you how it fits the way your team works.

## Connect an agent to Opelli (MCP)

Every Opelli instance is also an **MCP server** — Model Context Protocol over
Streamable HTTP (JSON-RPC 2.0). It is not a separate product or a read-only
mirror: it is the same API the web app uses, so an agent gets exactly the
permissions its credential carries and nothing beyond them.

- **Endpoint:** `https://<your-company>.opelli.dev/mcp` (or the same path on a
  tenant's own domain). There is no shared or central MCP endpoint — the server
  lives inside each company's instance, next to that company's data.
- **Tools:** ~90 named tools spanning every module — projects and the full
  project wiki, tasks, sprints and initiatives, planning, time tracking and
  approvals, people and time off, the CRM, messaging, marketing, forms,
  compliance and the activity log — plus a generic `list_endpoints` /
  `api_request` pair that reaches the rest of the API through the same walls.
- **Authorization is not re-implemented for agents.** Each `tools/call` is
  dispatched as an internal request to Opelli's own `/api`, carrying the
  caller's credential, so feature levels, project row scope and the hard block
  that keeps external guests out of the CRM all apply unchanged.

### Signing in

**OAuth 2.1** — the path for Claude and ChatGPT custom connectors, which are
OAuth-only, and for any other MCP client that prefers it. Add the endpoint URL as a connector; Opelli is the authorization
server (dynamic client registration per RFC 7591, PKCE mandatory) and delegates
identity to the sign-in the company already uses. Discovery follows RFC 9728:
an unauthenticated request answers `401` with
`WWW-Authenticate: Bearer resource_metadata=…`, and the metadata lives at
`https://<your-company>.opelli.dev/.well-known/oauth-protected-resource`.
No key to paste.

**Bearer token** — for scripts, editor agents and locally run clients (any
MCP-capable agent works; nothing here is specific to one vendor): a personal API key
(`opk_…`), minted by any team member under Settings → Personal → API keys and
scoped to the modules it may reach. Claude Desktop connects through the
`mcp-remote` bridge:

```json
{
  "mcpServers": {
    "opelli": {
      "command": "npx",
      "args": ["-y", "mcp-remote", "https://<your-company>.opelli.dev/mcp", "--header", "Authorization:${OPELLI_KEY}"],
      "env": { "OPELLI_KEY": "Bearer YOUR_KEY" }
    }
  }
}
```

The token rides in `env` rather than inline in `args` because Claude Desktop
mangles the space in `Bearer <token>`.

### Ceilings an agent cannot argue with

A key acts as **its owner** and can never reach further than that person could.
Above every key, admins hold a master on/off switch and a module allowlist for
the whole MCP surface — so an organization can wall the CRM off from every
agent regardless of who holds which permission. External guest accounts cannot
mint keys at all.


---

# Features — Opelli

> The seventeen modules of Opelli, grouped into five areas: Projects & work, Planning & people, Sales & finance, Security & control, and AI & assistants.

_Markdown edition of https://opelli.dev/features — generated from the page itself on 2026-08-25._

---

[Home](https://opelli.dev/../index.html) › Features

_Everything Opelli covers_

## Seventeen modules, five areas.

Seventeen modules over one set of projects, people and permissions: the work, the time it takes, the money it makes, the controls around it, and the AI assistants you connect. Everything one company runs on, under one roof and one login.

01

#### Projects & work

Projects, tasks, project knowledge, the data your automations write — and the mini-apps your team runs on it all.

- Projects
- Wiki
- Tasks
- Datasets
- Apps

Learn more →

02

#### Planning & people

Plan capacity, track time and approve monthly timesheets.

- Planning
- Time
- People

Learn more →

03

#### Sales & finance

CRM, orders, invoicing, campaigns, sites and forms.

- Customers
- Orders
- Finance
- Marketing
- Sites
- Forms

Learn more →

04

#### Security & control

Permissions, security, compliance, audit records and signed documents.

- Access
- Security
- Compliance
- Audit
- Signing

Learn more →

05

#### AI & assistants

Opelli agents and MCP for the assistant you already use.

- Agents
- MCP

Learn more →

### The small things — Fast by default.

##### Keyboard first

Work fast with the same shortcuts in every module.

##### Desktop and mobile

Works across desktop and mobile.

##### Notifications where you work

An assigned task, an approved month or a shared page arrives in Slack or Mattermost, with email as the fallback.

##### Search everything

One search across projects, wiki pages, tasks, people and customers, filtered by your permissions.

##### Your own address

Your company at `you.opelli.dev` minutes after the invite — or on your own domain, certificate included.

### See it on your own operations.

Opelli runs in the cloud on an `opelli.dev` address or your own domain. Leave your email and we will show you how it fits the way your team works.


---

# Projects & work — Opelli

> Projects & work in Opelli: a project overview, collaborative project knowledge and a task board that stays focused — team, capacity, time, deadlines and customer context in one place.

_Markdown edition of https://opelli.dev/features/work — generated from the page itself on 2026-08-25._

---

[Home](https://opelli.dev/../index.html) › [Features](https://opelli.dev/index.html) › Projects & work

_Area 01_

## Projects & work

A project overview, collaborative knowledge and a task board that stays focused.

### Ask for it — Turn meeting notes into connected tasks.

Your assistant reads the note, creates tasks in the right project and links each one back to the decision it came from.

### Projects — The whole project on one page.

See the team, capacity, time, deadlines, tasks, customer context and project knowledge in one place.

Compare planned and tracked time before the project runs over budget.

![A project detail page: a team and capacity table, planned against tracked time, and wiki and task widgets.](https://opelli.dev/../img/project.jpg)

### The project wiki — Where the work gets written down.

Every project has a wiki for meeting notes, decisions and product briefs — written together, connected to tasks and shared only where you choose.

![A wiki page in reading view: page tree with nested subpages, breadcrumbs, an embedded interactive flow chart, and linked task pills.](https://opelli.dev/../img/wiki-page.jpg)

![The wiki editor on a meeting note: attendee chips, the Markdown text and an insert menu offering a task, a page, an image and a flow chart.](https://opelli.dev/../img/wiki-editor.jpg)

_Everyone edits the same page at once_

_Diagrams and tables directly in the page_

_A linked task, straight from the note_

- **Collaborative project knowledge** — Edit pages together and keep meeting notes, decisions and product briefs in one place.
- **Turn decisions into work** — Create linked tasks directly from meeting notes.
- **Share only what a client needs** — Give guests access to selected pages without exposing the rest of the project.
- **Discuss work in context** — Comment on exact passages and keep the conversation with the source material.
- **Use rich content without lock-in** — Add diagrams, tables and files, then import or export in Markdown.

### Tasks — A board that stays small.

Types, six statuses — "Won't do" is an answer too — one assignee and one level of subtasks. Small enough that the board stays a view of the work.

![The Tasks board: status columns with typed task cards, assignees and due dates.](https://opelli.dev/../img/tasks.jpg)

![A task opened read-first: the description up front, a P0–P3 priority control and quick status and owner selects in the sidebar, and the Weekly sync meeting note it came from linked below.](https://opelli.dev/../img/task-detail.jpg)

Compact mode fits the whole sprint on one screen.

![The same board in compact mode: one line per card with the key, the title, a due date and the owner's avatar, and every status column visible at once.](https://opelli.dev/../img/tasks-compact.jpg)

- **A focused task board** — Track status, priority, ownership and deadlines without turning the board into a second job.
- **Plan in sprints** — Keep current work together and carry unfinished items forward.
- **Connect code and work** — Link GitHub activity to the tasks it belongs to.
- **Keep the context** — Files, comments and linked wiki pages stay with the task.

### Datasets — A row a day, next to the roadmap.

Some of the numbers a team lives by are written by machines — the app's store figures every morning, a monitor checking the site every five minutes, an assistant reporting what it read overnight. Each gets a dataset under its project, appends one row at a time, and the wiki shows the history as a live table or chart.

![A dataset of the mobile app's daily store metrics: one profile card per column with a histogram or the most common values, the sortable table of rows beneath, and the ingest token with its ready-made curl snippet beside it.](https://opelli.dev/../img/datasets.jpg)

![A wiki page with the same dataset embedded as a live chart of daily actives and a filtered table of Android stability beneath a paragraph of commentary.](https://opelli.dev/../img/wiki-dataset.jpg)

```
POST /datasets/12/rows
Authorization: Bearer opds_…
Idempotency-Key: ios-2026-08-22
Content-Type: application/json

{ "timestamp": "2026-08-22T06:30:00+02:00", "platform": "ios",
  "installs": 113, "dau": 3359, "crash_free_pct": 99.8, "rating": 4.4 }

→ 201  { "inserted": 1, "duplicates": 0, "ids": [4471] }
```

- **Append, never re-upload** — Every record is one row added with one request — there is no file to fetch, edit and put back, so two writers can never overwrite each other. Send an Idempotency-Key and a retried request is stored once.
- **A token that can do one thing** — Each dataset has its own ingest token, and all it can do is append rows to that dataset. Rotate or revoke it from the dataset page, which also hands you the curl, RouterOS and Python snippets ready to run.
- **Free-form, or declared** — Rows are JSON. Declare the columns and their types and a malformed record is refused with the key named; leave them undeclared and the dataset takes what comes — an uptime monitor's status and response time, say.
- **Profiled, charted, in the wiki** — The dataset opens on a column profile — type, count, a histogram or the most common values — above a table that sorts and filters on any column and a time range, a chart of the numeric columns, and JSONL, CSV or JSON exports. Save a sort, filters and a chart as a named view, then type `/dataset` in a page to embed it: it reads the current rows every time the page opens, and stays as private as the page.
- **Written by an assistant, too** — A scheduled assistant that scans the news, social media and research papers each morning appends what it found — source, title, relevance — and the team reads the table in the wiki. The same goes for a CI job, a router or a sensor: anything that can make one request can keep a dataset.
- **Bounded on purpose** — A dataset keeps up to 100 000 rows and ages old ones out on the retention you choose. A secret download link for a dashboard outside Opelli is off until you switch it on, and says plainly what holding it means.

### Ask for it — From the day's rows to a chart on the page.

Your assistant finds the dataset, reads the month out of it, saves what it read as a named view and puts that view on the wiki page — as a live chart that keeps growing with each morning's row.

### Apps — The tool your team built, running inside Opelli.

Some tools are yours alone — a retro board, an estimator, a dashboard over the datasets above. Upload the built app, or let your assistant write it, and it opens for signed-in members right in Opelli: versions, rollback, storage and sign-in already taken care of.

![An app's detail page: the numbered version history with one version live, the app's saved state — shared keys and the viewer's own — and the ready-made CI workflow snippet beside them.](https://opelli.dev/../img/apps.jpg)

![The same app open in Opelli: a retrospective board with three shared columns and the viewer's private draft, running full width under the top bar.](https://opelli.dev/../img/app-runner.jpg)

- **Versions, never edits-in-place** — An upload is a numbered version and nothing changes for the team until you press Publish. Every earlier version keeps a Roll back button, so a bad release is one click old.
- **Project-wide or org-wide** — An app belongs to a project and opens for its members — or to the whole organization. External guest accounts never see it either way.
- **Runs as the person using it** — An app runs with each viewer's own sign-in, so what it can read and change is exactly what that person could anyway — a dashboard over a dataset shows each member their own permitted slice, with no credentials anywhere in its code. Publishing asks for one consent in return: publish only what you wrote or reviewed. Every publish is recorded in the security trail.
- **State without a backend** — Apps that need to remember things get built-in storage: per-person state for drafts and preferences, shared state for a board everyone sees — saved on the server, with concurrent updates handled safely.
- **From GitHub on every push** — The app page hands you a ready-made CI snippet: push to main, and the build lands as a new version — published only when the workflow says so, with an API key that can touch apps and nothing else.
- **Your assistant builds it end to end** — A connected assistant can create an app, read its source, make edits, stage a version and publish — the same loop it uses for microsites, now for internal tools.

### Ask for it — From a sentence to a tool the team opens.

Your assistant creates the app, writes its files and publishes the first version — a retro board whose columns live in shared state, ready on the project page before the meeting starts.

### See it on your own operations.

Opelli runs in the cloud on an `opelli.dev` address or your own domain. Leave your email and we will show you how it fits the way your team works.

Next

Planning & people →


---

# Planning & people — Opelli

> See team capacity, tracked time and approved monthly timesheets in one connected view.

_Markdown edition of https://opelli.dev/features/time-people — generated from the page itself on 2026-08-25._

---

[Home](https://opelli.dev/../index.html) › [Features](https://opelli.dev/index.html) › Planning & people

_Area 02_

## Planning & people

See team capacity, tracked time and approved monthly timesheets in one connected view.

### Ask for it — From calendar to timesheet.

Your assistant turns calendar events into project time entries and compares the result with the plan.

### Planning — Who works on what, at a glance.

See capacity and conflicts across the team, then adjust the plan directly in the schedule.

- Plan in hours, days or FTE while Opelli keeps one consistent view of capacity.
- Use monthly limits for flexible contractors without forcing artificial project splits.

![The Planning schedule: each person's allocations across a two-month timeline.](https://opelli.dev/../img/planning.jpg)

![The Time week calendar with time entries laid out across the week.](https://opelli.dev/../img/time-calendar.jpg)

![The Time list view: a stacked per-project volume chart above day-grouped entries with totals.](https://opelli.dev/../img/time-list.jpg)

### Time — Track the week, close the month.

A calendar for the week's work and a list for the numbers. Turn approved time into [an invoice](https://opelli.dev/business.html#finance) without retyping.

- Log time manually or turn calendar events into project entries with your assistant.
- Compare planned and tracked time by person, project and month.
- Submit monthly timesheets for approval and lock approved periods.
- Connect calendars and Toggl, or export the month for further processing.
- Keep time correct for teams working across time zones.

### People — A directory connected to real work.

See each person's projects, capacity, tasks and tracked time together.

![The People list: titles, skills, projects, load today and month-to-date utilization per person.](https://opelli.dev/../img/people.jpg)

![A person's page: five projects stacked into one utilization bar for the month, each in its project color, with the per-project table below.](https://opelli.dev/../img/person-detail.jpg)

- View the team as a list, by project or in an org chart.
- Manage profiles and time off where the team already works.

### See it on your own operations.

Opelli runs in the cloud on an `opelli.dev` address or your own domain. Leave your email and we will show you how it fits the way your team works.

Previous

← Projects & work

Next

Sales & finance →


---

# Sales & finance — Opelli

> From first contact to order, payment and invoice — with campaigns, sites and forms connected to the same customer data.

_Markdown edition of https://opelli.dev/features/business — generated from the page itself on 2026-08-25._

---

[Home](https://opelli.dev/../index.html) › [Features](https://opelli.dev/index.html) › Sales & finance

_Area 03_

## Sales & finance

From first contact to order, payment and invoice — with campaigns, sites and forms connected to the same customer data.

### Ask for it — Turn a campaign brief into a page ready for review.

Create a draft from material already in the project. The published site changes only when you approve a new version.

### Customers — A pipeline that remembers.

Keep every customer, conversation and opportunity in one place, with a clear next step for each deal.

- See pipeline conversion, time in stage and win rate without rebuilding the report in a spreadsheet
- Look up Czech companies through ARES when creating a customer
- Amounts are shown only to users with the right permission

![The Customers pipeline: deal cards in Lead, Prospect, Qualified, Proposal and Won columns with values, next steps and owners.](https://opelli.dev/../img/crm.jpg)

![A customer's page: headline figures across the top, the deals table, the day-by-day history of notes, calls and emails, with contacts and customer details down the side.](https://opelli.dev/../img/crm-account.jpg)

### Orders — Sell it, and take the money for it.

Share an order page where customers can choose, enter billing details and pay without creating an account.

![One paid order opened as a page: the lines and frozen totals, the address the buyer chose, the card payment with its fee, and the fulfilment recorded beside the billing details.](https://opelli.dev/../img/orders-detail.jpg)

![The public order page: a themed card with the price per seat and term, the team size, billing period and address the buyer chooses, two add-ons, and the live total above Continue.](https://opelli.dev/../img/orders-page.jpg)

- **Payments through your Stripe** — Payments go directly to your connected Stripe account.
- **From order to delivery** — Track orders, delivery and subscriptions in one place.
- **Financial details stay protected** — Access to financial data is controlled by permissions.

What is still being billed, grouped by customer — seats and add-ons on one card even when they run on different periods.

![The Subscriptions tab grouped by customer: a past-due alert at the top, and one account billing yearly seats and monthly add-ons on a single card, expanded to its items and period.](https://opelli.dev/../img/orders-subscriptions.jpg)

**It closes the loop the rest of this page opens.** The deal is won in Customers, the order is placed and paid here, and Finance issues the invoice for it — over one set of customers, one set of permissions and one audit trail.

### Finance — The month's hours, as an invoice.

Turn approved project time into a ready-to-issue invoice with Czech tax details and a payment QR code.

- Use the right historical rate automatically and see revenue, cost and margin by project
- Create recurring drafts for retainers and review them before issue

![The invoice builder: the customer, period and lines on the left — two of them drawn from approved months — and the finished invoice on the right with the letterhead, VAT, totals and a payment QR code.](https://opelli.dev/../img/finance-invoice.jpg)

Billing and cost are separate permissions — a bookkeeper can run invoicing end to end while cost rates and margins stay with the people who set them.

![The Rates table: each person's cost and bill rate with the months it applies to, one rate overridden for a single project, and the margin beside them.](https://opelli.dev/../img/finance-rates.jpg)

### Marketing — Campaigns, from the same context.

The people you'd write to are already in the CRM, and the voice you'd write in is already on file.

![The campaign editor: Markdown source and recipient lists on the left, the live-rendered email in the Studio theme on the right.](https://opelli.dev/../img/marketing.jpg)

- **Campaigns in context** — Build messages from the contacts and brand material already in Opelli.
- **Personalize before you send** — Preview the subject and message with real recipient data.
- **Reusable designs** — Create a consistent email style without editing code.
- **Clear results and lasting opt-outs** — Follow campaign performance and respect an unsubscribe across every list.

### Sites — The page your campaign points at.

A small marketing site sits beside the project it belongs to — a launch page, a webinar sign-up, a one-pager for a customer.

- Create a campaign page from the material already in the project.
- Preview every version and publish only when it is ready.
- Use your own domain and connect sign-ups directly to the project's forms.
- Return to an earlier version whenever you need to.
- See how many people the page reached — counted without cookies, so nobody is identified.

![The site assistant: a rendered landing page in the preview pane marked “Previewing version 5 — not published”, and a chat beside it where two instructions each came back with a summary of what changed.](https://opelli.dev/../img/sites-assistant.jpg)

Every answer is a new version. Publishing is one button — and so is going back to the one before.

![A microsite in Opelli: the version list — five versions, three written by the assistant, one marked Live, with Preview, Publish and Roll back beside the others — a picture of the page each version is, the last thirty days of visits, and a box to point your own domain at it.](https://opelli.dev/../img/sites.jpg)

### Forms — Ask the outside world.

Questionnaires, polls and sign-up pages. Build the questions, share the link.

![The Forms results view: per-question charts for the rating and choice questions, latest text answers, and the response table under the public link.](https://opelli.dev/../img/forms.jpg)

![The public form page: a studio-themed card with rating, choice and long-text questions, the company name on top and an accent Submit button.](https://opelli.dev/../img/form-public.jpg)

- **Ask it your way** — Choose from six question types and match the form to your brand. Mark any question as required and change its order.
- **You control intake** — Open and close intake when you choose.
- **Results as they arrive** — Collect responses without requiring an account and see results as they arrive.
- **No visitor tracking** — No visitor tracking is stored with responses.

### See it on your own operations.

Opelli runs in the cloud on an `opelli.dev` address or your own domain. Leave your email and we will show you how it fits the way your team works.

Previous

← Planning & people

Next

Security & control →


---

# Security & control — Opelli

> Permissions, security and audit records for teams that need to know who can see what and what changed.

_Markdown edition of https://opelli.dev/features/trust — generated from the page itself on 2026-08-25._

---

[Home](https://opelli.dev/../index.html) › [Features](https://opelli.dev/index.html) › Security & control

_Area 04_

## Security & control

Permissions, security and audit records for teams that need to know who can see what and what changed.

### Ask for it — Your assistant can only use what you can access.

Connected assistants follow the user's permissions and the modules allowed for that connection. Requests outside that scope are refused.

### Access — Share the work without oversharing.

Every feature carries a permission level — none, read, write, delete — set per role or per person. Access can be limited to records from the projects a person is a member of.

![The Access console: features × roles grid with per-level pickers and an expanded 'what each level allows' capability matrix.](https://opelli.dev/../img/access.jpg)

- **Documented, not implied** — Each feature spells out what every permission level allows, right where you assign it.
- **Roles & overrides** — Admin, manager, member and guest out of the box; custom roles and per-person exceptions when you need them.
- **The guest boundary** — Customer-side guests are labelled everywhere, see only the wiki pages shared with them and can never enter CRM or Finance — no permission grant can change that.
- **Two money permissions** — What you pay someone and what you charge for their time are granted separately, so invoicing can be delegated without opening cost data.
- **Locked months** — An approved timesheet locks its month — no silent edits after sign-off.
- **Personal connections** — Scripts and assistants connect through personal, module-scoped keys that act only as their owner. Revoke any connection at any time.

### Security — Built for audits.

The commitments that matter when you buy: where your data lives, how it is protected and how sign-in works.

- **Isolated by organization** — Each customer's data is kept in a separate environment.
- **Protected in transit and at rest** — Application data and files are encrypted and processed in the EU.
- **Use your identity provider** — Sign in with Google, or Microsoft Entra under an enterprise arrangement, and keep 2FA under your control.
- **Recoverable by design** — Automated backups support recovery from accidental loss.

The GDPR machinery you'd ask about — consent records, subject requests on a 30-day clock, a map of where personal data sits — is in the product itself.

### Compliance & Audit — Everything on the record.

Two modules for the questions customers, auditors and investors eventually ask: what your legal texts say and who agreed to which version — and what actually happened here last month.

#### Compliance — Your GDPR posture, run like the rest of the company.

Terms, a privacy policy, consent texts — drafted in Markdown and published as immutable versions to a Privacy Center at your own address. The exact text someone agreed to stays reproducible forever, and old versions stay linkable.

- A consent ledger: who agreed to what, which version, when — every consent with its own withdraw link
- Data-subject requests with the 30-day clock counting down, from the public portal or logged by hand
- A locator that finds a person's email across CRM contacts, mailing lists, form responses and accounts
- "Manage my data": a private link listing someone's consents and requests — no account, no way to probe who's in the system
- Each document belongs to a project and picks the look of its public page

![A published privacy policy on the Privacy Center: the document title and version, a sticky table of contents built from its headings, and numbered sections.](https://opelli.dev/../img/privacy-center.jpg)

#### Audit — What happened, and the report of it.

Every notable thing lands in one org-wide activity log — tasks closed, deals moved, people added to projects, pages published, campaigns sent. Read it as a day-by-day stream, or render the same range as one Markdown document and mail it.

- Everyone sees their own slice, filtered by the permissions they hold and the projects they belong to
- Lose access to a project and its history goes with it, immediately
- Summaries name things, never values — no deal amounts, no phone numbers
- An admin-only security trail: roles, permission changes, keys minted and revoked
- A delivery record of everything Opelli sent, in the same stream
- The same document a connected assistant asks for when it wants to know what changed

![The Audit activity stream: events grouped by day with a module label per row, range and module filters, and a security-trail toggle.](https://opelli.dev/../img/audit.jpg)

…and the same range, rendered as one Markdown document you can copy or mail.

![The Report view: a summary with per-module tallies and tracked hours, then the detail grouped by project, above Copy markdown and Email report buttons.](https://opelli.dev/../img/audit-report.jpg)

### Signing — Counter-sign the contract they sent.

Sign a PDF with your own certificate, including one the other side has already signed — their signature stays valid, and Opelli never holds your key.

- **Their signature survives** — A signed document is only ever appended to, never rewritten, so a qualified signature the other party put on it stays intact — the check every recipient's reader makes.
- **Nothing is stored** — The document, your .p12 certificate and its passphrase travel through one request and the signed PDF comes straight back. No key ever rests on the platform, so a hijacked session has nothing to sign with.
- **Timestamped, optionally visible** — Every signature carries a trusted RFC 3161 timestamp, and you can place a "Signed by … via Opelli" mark on the page of your choice.
- **Inspect before you sign** — The screen first lists the signatures already on the document and whether each is still intact. What remains afterwards is an audit entry — the document's fingerprint and the certificate's identity, never key material.

### Ask for it — It can read the signatures. It cannot sign.

Ask your assistant to counter-sign and it checks the signatures already on the document, then hands it over: the certificate and its passphrase never pass through an assistant or the platform, so the one who signs is you.

### See it on your own operations.

Opelli runs in the cloud on an `opelli.dev` address or your own domain. Leave your email and we will show you how it fits the way your team works.

Previous

← Sales & finance

Next

AI & assistants →


---

# AI & assistants — Opelli

> The AI layer in Opelli — built-in agents that prepare suggestions from your business context, and an MCP server that connects Claude, ChatGPT or your own AI assistant within your permissions.

_Markdown edition of https://opelli.dev/features/agents — generated from the page itself on 2026-08-25._

---

[Home](https://opelli.dev/../index.html) › [Features](https://opelli.dev/index.html) › AI & assistants

_Area 05_

## AI & assistants

Opelli gives AI the same connected business context your team works with: projects, tasks, time, customers, finance and published content. Use Opelli's built-in agents for focused suggestions, or connect your own assistant through MCP.

Every action follows the user's permissions, and connected apps can be revoked at any time.

### Ask for it — The reply came in. Where does the deal stand?

Every mail, call and note on a customer sits on one timeline, with the deal on top of it. Ask what happened and your assistant reads the whole thread; ask for the next move and the deal is updated as your work, in the stage the whole team sees.

### Context in Markdown — An assistant is only as good as what it can read.

Opelli writes in Markdown from the start — wiki pages, meeting notes, briefs and reports. The material an assistant needs is the material your team already wrote, in a format a model reads well.

- Export your wiki without losing its structure — and import it back the same way
- Give your assistant the same material your team already works with
- Nothing is locked in: your content stays portable

![The Audit module's Report view: a time range rendered as a Markdown document, grouped by module and project, with copy and email actions.](https://opelli.dev/../img/audit-report.jpg)

### Opelli agents — AI prepares. You decide.

Opelli's built-in agents read what is already in the system — a customer conversation, project material — and come back with a suggestion next to the thing it came from. Nothing changes until you accept it.

![A forwarded customer email on the customer timeline with a 'Read this' button and, below it, the suggestions: summary, next step, due date, signal, the amount the message mentioned, and the two people it named — one with an Add button, one already a contact.](https://opelli.dev/../img/crm-reader.jpg)

- **Read a conversation** — Get a summary, the next step with its date, the amounts mentioned and the people named — ready to file on the customer.
- **Suggestions, not changes** — No record is edited and no deal is moved for you. A drafted page is saved as an unpublished version — the live site changes only when you approve it.
- **Under your control** — Sensitive credentials are removed before content is sent to a model, and administrators can disable individual agents or the entire AI layer.

Administrators see a record of every model call.

![The Agents activity log: one card per model call with the model and token counts, one payload unfolded to show what actually left, a run blocked by the private-key rule, and one whose password was removed before sending.](https://opelli.dev/../img/agents-runs.jpg)

### Ask for it — Last night, as one document.

Everything notable is recorded in one activity log across modules. Ask for a range and you get a single Markdown document with only the rows you are allowed to see — a ready starting point for a stand-up or a status update.

### MCP server — Or connect your own AI assistant and just ask.

Opelli speaks the Model Context Protocol. Add Opelli as a connector in Claude, ChatGPT or another MCP-capable assistant and work with projects, tasks, planning, time, customers and published content — more than 90 tools, in plain language.

**You:** Catch me up on the latest customer conversation and update the opportunity when I ask.

_Tool calls: `search_customers`, `update_deal`_

**You:** Turn a meeting note into linked tasks without copying decisions by hand.

_Tool calls: `get_wiki_page`, `create_task`_

**You:** Create a draft launch page from project material; the published version changes only when you approve it.

_Tool calls: `create_site`, `publish_site`_

**You:** And update the Globex opportunity while you're at it.

_Tool calls: `customers · refused`_

**Assistant:** This connection does not have access to CRM, so I cannot update that opportunity.

Every tool call follows your own permissions: feature permissions, access limited to specific projects, and the rules for guest accounts. How to connect an assistant, and the full security rules, are covered in the documentation.

### See it on your own operations.

Opelli runs in the cloud on an `opelli.dev` address or your own domain. Leave your email and we will show you how it fits the way your team works.

Previous

← Security & control


---

# Pricing — Opelli

> Your first three users are free, forever. Every additional user is €13 per month, with all seventeen modules, the MCP server and guest access to the pages you share with clients. Connected AI assistants do not need a seat; model usage is metered.

_Markdown edition of https://opelli.dev/pricing — generated from the page itself on 2026-08-25._

---

[Home](https://opelli.dev/index.html) › Pricing

_Pricing_

## Your first three users are free. Forever.

Every additional user is €13 per month. All seventeen modules, the MCP server and guest access to the pages you share with clients are included. Connected AI assistants do not need a seat.

**3** seats

**€0** / month

free, forever

- **2** published sites
- **2** free guest accounts
- **5 GB** of storage
- **200** campaign recipients a month
- **€0** of model usage a month
- **Community** support
- **Unlimited** projects, tasks and wiki pages
- **Unlimited** customers, deals and invoices
- **Unlimited** time entries, forms and documents
- **Unlimited** audit history, kept for every account

**10** seats

**€91** / month, billed annually

€9.10 per person · 7 paid seats

- **9** published sites
- **16** free guest accounts
- **19 GB** of storage
- **1 600** campaign recipients a month
- **€3.50** of model usage a month
- **Next business day** support
- **Unlimited** projects, tasks and wiki pages
- **Unlimited** customers, deals and invoices
- **Unlimited** time entries, forms and documents
- **Unlimited** audit history, kept for every account

**50+** seats

**Quoted**

sized with you on the call

- Allowances sized to how you use them
- Onboarding and import handled with you
- A named contact and a response time

Seat four onward: €13 a month billed annually, €16 monthly. No seat minimum. All prices exclude VAT.

### The list — Included metered features and what's extra.

| What | Included | More of it |
| --- | --- | --- |
| In every account |
| All seventeen modules | Every account, including the free one | — |
| MCP server | ~90 tools, in every instance | — |
| Agents, API keys, MCP connections | **Unlimited**, and none of them takes a seat | — |
| Projects, tasks, wiki, customers, finance, time, forms | **Unlimited** | — |
| Audit log and its history | Kept in full, for every account | — |
| GDPR centre, audit trail | Every account | — |
| What meters, and what more of it costs |
| Guests | 2 + 2 per paid seat | A seat, for anything more |
| Storage | 5 GB + 2 GB per paid seat | +100 GB for €19 |
| Published sites | 2 + 1 per paid seat each site keeps its last 10 versions (the live one always stays) | +5 for €19 |
| Campaign recipients | 200 + 200 per paid seat | +2 500 for €29 |
| Model usage — the agents Opelli runs | €0.50 per paid seat a month | Set a budget; metered at cost + 15% |
| What changes as you grow |
| Seats | First 3 free, then €13 each | 50+ quoted |
| Single sign-on | Google | Microsoft for 50+ seats |
| Signed DPA | Paid accounts | — |
| Support | Community; on a paid account, e-mail answered by the next business day | Within 4 business hours, on a support retainer — quoted |

**You pay only for active seats.** Deactivate a user and reuse the seat without losing their work.

### Guests can access only the pages shared with them.

Free accounts for the people outside your company — a client reading a brief, a reviewer approving a draft.

| What | Guest | Member |
| --- | --- | --- |
| Wiki Pages | Read, comment and co-author only shared pages | Complete project wiki |
| Projects | Only shared wiki | Their projects |
| Tasks, time tracking, planning, project chat | — | Yes |
| CRM, invoices, campaigns, forms, microsites, privacy centre | — | Per permission |
| The team directory | Themselves, and whoever wrote what they can read | Project members |
| API keys and the MCP server | — | Yes |
| What they count against | The guest allowance | A seat |

### FAQ — Frequently asked questions.

#### Are three users really free forever?

Yes. Three seats, every module, the MCP server and 2 guest accounts, for as long as the account exists. The fourth user costs €13 a month. Because we know how hard the beginning is. The one thing we ask is that a free account's use looks like three people's work — the [Acceptable Use Policy](https://opelli.dev/acceptable-use.html) says what that means, with numbers.

#### Do the agents cost extra?

Connecting one costs nothing — an agent is never a seat, and your own assistant over MCP runs on your own model subscription. What meters is the model usage of the agents Opelli runs for you: €0.50 per paid seat a month is included, past that it is billed at cost plus 15%, and every organization sets a ceiling it stops at.

#### How are seats billed when someone joins or leaves?

Pro-rated to the day. Deactivating a user releases the seat immediately and leaves their work where it is: on monthly billing the charge stops that day, and on a prepaid year the seat becomes capacity you can activate somebody else into at no extra cost for the rest of the term. Either way you never pay twice for one seat.

#### Can we move our data out?

Export your wiki in Markdown and access the rest of your data through the API at any time.

#### Who do we sign with?

The operating company is Opelli s.r.o. The [Terms](https://opelli.dev/terms.html), the [Acceptable Use Policy](https://opelli.dev/acceptable-use.html) and the [Privacy Policy](https://opelli.dev/privacy.html) are the current ones, and a Data Processing Agreement comes with a paid account.

### See it on your own operations.

Opelli runs in the cloud on an `opelli.dev` address or your own domain. Leave your email and we will show you how it fits the way your team works.


---

# Opelli company — built to grow with your business

> Opelli fits growing SMEs today: start with three users free and keep one connected platform as projects, people and processes multiply — with a clear path toward the certifications and integrations larger organizations require.

_Markdown edition of https://opelli.dev/company — generated from the page itself on 2026-08-25._

---

[Home](https://opelli.dev/index.html) › Company

_Company_

## For the company you run today—and the one it can become.

Opelli began as an internal system for a company coordinating work across employees, specialists and clients. You can start with three users free, then keep the same connected platform as projects, people and processes multiply. It fits growing SMEs today, with a clear path toward the certifications and enterprise integrations larger organizations require.

### Why it exists — The spreadsheet at the end of the month.

A plan in one tool, hours in another, a pipeline in a third, and a person exporting all three into a spreadsheet to find out whether the month worked. Every number is right in its own tool and no two agree, because nothing shares a definition of a project, a person or a month. The problem appears early and becomes more expensive with every new team and process.

Opelli's answer is one platform where projects, time, customers and finance share the same data. The project overview, the month-end invoice and the report for an investor therefore show the same numbers. The assistant you already use can work with the same connected context.

- Start with three users free; add paid users as the team grows.
- One platform and seventeen modules; use what you need without rebuilding the stack later.
- Work across employees, specialists and client guests with one connected context.
- Keep data portable and permissions consistent as the organization becomes more complex.

#### Legal identity

Operator

Opelli s.r.o.

Registered seat

Nové sady 988/2, Staré Brno, 602 00 Brno, Czech Republic

IČO

29850762

DUNS

351787000

Registration

Commercial Register kept by the Regional Court in Brno, Section C, File 153188

Governing law

Czech Republic

Legal contact

legal@opelli.dev

The [Terms of Service](https://opelli.dev/terms.html) and [Privacy Policy](https://opelli.dev/privacy.html) are the binding documents; a Data Processing Agreement reflecting Article 28 GDPR is available on request.

### Built to grow — Start lean. Add structure when you need it.

A small team should be able to prove a better way of working without a rollout project. A growing company should not have to migrate again just because the first approach worked.

- **Start — Three users free** — All seventeen modules are available from the beginning, so a small team can validate the whole workflow before making a larger commitment.
- **Grow — One connected platform** — Add people, projects and client collaboration without splitting the company back across separate tools.
- **Ahead — A deliberate path upward** — Certifications and enterprise integrations extend the size of deployment without changing the connected model underneath.

### How we build — Foundations that should not change with company size.

When a company runs core work in one system, its foundations need to hold as the organization grows.

- **Connected context** — Projects, time, customers and finance share one source of truth. People and connected assistants work with the same context.
- **Progressive adoption** — Start with the workflow you need today and add more without moving the company to another platform.
- **Consistent control** — One permission model applies across the product, including connected assistants.
- **An open path** — Open formats and the API keep data portable and future options open.

### Where we are going — Enterprise is a capability set, not a label.

Today, Opelli is ready for growing SMEs. We do not treat enterprise as a label: larger deployments require independently verified security, enterprise identity and deeper integrations. We are adding those capabilities in stages while keeping the fast start and direct product experience that make Opelli useful to smaller teams.

### Get in touch — Talk to a person.

- **Book a demo** — See how Opelli fits your company today and what it can take on as you grow.
- **Legal & privacy** — [legal@opelli.dev](mailto:legal@opelli.dev) — DPAs, sub-processors, data-subject requests.
- **For AI systems** — Product information is available in [Markdown](https://opelli.dev/llms.txt), and every Opelli workspace can connect through MCP.

### Start with the workflow that matters now.

Start with three users free, or book a demo and map how Opelli can grow with your company.


---

# Terms of Service — Opelli

> The terms governing your use of Opelli, the company-operations platform operated by Opelli s.r.o.

_Markdown edition of https://opelli.dev/terms — generated from the page itself on 2026-08-25._

---

_Legal_

## Terms of Service

These terms govern your access to and use of Opelli, the company-operations platform operated by Opelli s.r.o. Please read them carefully — by using Opelli you agree to them.

**Effective:** 6 August 2026 · **Last updated:** 6 August 2026 · **Version:** 1.1

Opelli is operated by **Opelli s.r.o.** (“we”, “us”, “our”), a company incorporated in the Czech Republic. Opelli is a platform for lean organizations that consolidates projects, tasks, planning, time tracking, people, a sales pipeline, email campaigns, public forms, compliance tooling and an agent-facing API into one service. These Terms of Service (the “Terms”) form a binding agreement between you and Opelli s.r.o. If you use Opelli on behalf of an organization, you confirm you are authorized to bind that organization, and “you” means that organization.

### 1. Who we are and these terms

The Service (defined below) is provided by **Opelli s.r.o.**, registered seat at Nové sady 988/2, Staré Brno, 602 00 Brno, Czech Republic; Company ID (IČO): 29850762; DUNS: 351787000; registered in the Commercial Register kept by the Regional Court in Brno, Section C, File 153188. You can reach us at [legal@opelli.dev](mailto:legal@opelli.dev).

These Terms, together with our [Privacy Policy](https://opelli.dev/privacy.html) and — where the Service is used to process personal data on your behalf — our Data Processing Agreement, govern your use of the Service. If you do not agree with them, you must not use the Service.

Opelli is intended for use by businesses and professionals in the course of their trade or profession. It is not directed at consumers.

**Language versions.** These Terms are published in English and in [Czech](https://opelli.dev/cs/terms.html). Both versions are equally authentic, each for its own audience: for Customers with their registered seat or principal place of business in the Czech Republic, the **Czech version** governs; for all other Customers, the **English version** governs. The two versions state the same terms, and a reference to these Terms means the version that governs for you.

### 2. Definitions

- **“Service”** means the Opelli software-as-a-service platform, including the web application, the API and MCP (Model Context Protocol) server, the marketing site at opelli.dev, and any related documentation, made available at opelli.dev, on tenant subdomains (e.g. `your-org.opelli.dev`) or on a custom domain.
- **“Account”** means the tenant workspace provisioned for your organization and the individual user accounts within it.
- **“Authorized User”** means an individual you invite to your Account (an administrator, team member, contractor, or an external guest with limited access).
- **“Customer Content”** means all data, text, files, and other material that you or your Authorized Users submit to, or generate within, the Service — including projects, tasks, wiki pages, time entries, CRM records, orders and their payment records, mailing lists, form responses and compliance records.
- **“Personal Data”** has the meaning given in the EU General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR”).

### 3. The Opelli service

Opelli is a modular company-operations platform. Its modules — Projects, the project Wiki, Tasks, Planning, Time, People, Customers (CRM), Orders, Finance, Marketing, Sites, Forms, Compliance and Audit — operate over a shared set of projects, people and permissions, with project chat and notifications alongside them. The Service also exposes a permission-scoped API and an MCP server so that scripts and AI assistants you connect can act within the Service on your behalf, bounded by the same permissions that govern the web application.

**Microsite version history.** Each site published from the Service keeps its most recent ten (10) versions, together with the version currently published, which is always retained regardless of age. Older versions, including their files, are deleted automatically — from the Service and from its hosting and storage providers alike. The currently published version of a site is never deleted by this rule.

We may add, change, or remove features over time. We aim to give reasonable notice of material changes that reduce core functionality, but the Service is provided on an evolving basis and we do not guarantee that any specific feature will remain available.

### 4. Availability and changes

Opelli is an actively developed product. We add, change and occasionally retire features, and we maintain and update the Service. Where a change would materially reduce functionality you rely on, we will give you reasonable advance notice.

- the Service is provided without a specific service-level or uptime commitment, unless we have agreed one with you in writing;
- we may modify, suspend or discontinue all or part of the Service, with such notice as is reasonably practicable, and we schedule planned maintenance to limit disruption where we can;
- you should retain your own copies of any Customer Content that matters to you, and use the Service's export tools — markdown export for wiki content, and the API for the rest.

Where we make an evaluation, trial or other free access available, we may change or end it at any time.

We value your feedback; how we may use it is described in section 11.

### 5. Accounts and eligibility

Access to the Service requires signing in with a Google or Microsoft account (OAuth / OpenID Connect), as enabled for your Account; we do not operate a separate password system. Only email addresses that have been invited to an Account may sign in. You are responsible for:

- ensuring the accuracy of the information in your Account;
- maintaining the security of the sign-in accounts and any API keys or access tokens used to reach the Service, and for all activity that occurs under them;
- promptly notifying us of any unauthorized access or use.

Each Account has at least one administrator who manages Authorized Users, roles and permissions. You are responsible for the acts and omissions of your Authorized Users as if they were your own.

**Service communications.** The Service sends Authorized Users operational messages about activity in their Account — for example a task assigned to them, a comment on their work, a time statement awaiting their review, or a page shared with them — as a chat message where the Account has a chat platform connected, and otherwise by email to the address they sign in with. These messages are part of the Service and are not marketing; they are on by default, and each user can switch them off — by category or entirely, including whether email may carry them at all — under Settings → Personal → Notifications. We may also email Account administrators about the Service itself, such as releases, planned maintenance and security notices; those are administrative notices under section 20, not marketing.

### 6. Your content and your responsibilities

As between you and us, **you retain all rights in your Customer Content**. You grant us a worldwide, non-exclusive licence to host, store, process, transmit and display Customer Content solely as necessary to provide and maintain the Service, to prevent or address technical or security issues, and as otherwise instructed by you.

You are responsible for your Customer Content and for how you use the Service. In particular, you represent and warrant that:

- you have all rights, consents and lawful bases necessary to submit Customer Content — including Personal Data about your team members, contacts, mailing-list recipients and form respondents — to the Service and to have it processed as described in these Terms and our Privacy Policy;
- your use of the Service, and your Customer Content, comply with all applicable laws, including data-protection, marketing and anti-spam laws (e.g. you have a lawful basis to send the email campaigns you create, and you honour unsubscribe requests);
- your Customer Content does not infringe the rights of any third party.

Where you use the Service to process Personal Data, you act as the **controller** and we act as a **processor** on your behalf. That relationship is governed by our Data Processing Agreement and described in our [Privacy Policy](https://opelli.dev/privacy.html).

### 7. Acceptable use

You agree not to, and not to permit any Authorized User or third party to:

- use the Service for any unlawful, harmful, deceptive, or infringing purpose, or to send unsolicited or unlawful communications;
- upload malware, or attempt to gain unauthorized access to the Service, other accounts, or the systems or networks connected to the Service;
- probe, scan, or circumvent the Service's security, authentication, permission or rate-limiting mechanisms, including via the API or MCP server;
- reverse-engineer, decompile, or attempt to derive the source code of the Service, except to the extent this restriction is prohibited by applicable law;
- resell, sublicense, or provide the Service to third parties except to your own Authorized Users, or use it to build a competing product;
- use automated means (including connected AI agents) in a way that places an unreasonable load on the Service or exceeds documented rate limits.

Our [Acceptable Use Policy](https://opelli.dev/acceptable-use.html) sets this out in full and **forms part of these Terms**. It states what is prohibited, what volumes of use are fair — including for an Account inside its free seats — which limits the Service enforces today, which limits we reserve the right to apply with notice, and the order in which we act. Where that Policy and this section differ on a point it covers specifically, that Policy governs.

We may investigate suspected violations and may suspend or limit access to protect the Service, our users, or third parties.

### 8. Third-party services and integrations

The Service interoperates with third-party services, some at your option — including Google (sign-in and email relay), Microsoft (sign-in, where your Account enables it), Toggl (time-tracking sync you connect per user), Mattermost or Slack (the chat platform your organization runs), GitHub (repository webhooks), and public registries such as the Czech ARES business register. Your use of any third-party service is governed by that provider's own terms and privacy policy. We are not responsible for third-party services, and their availability or behaviour is outside our control. Where you connect a third-party integration, you authorize the Service to exchange data with it as needed to provide the feature.

### 9. Fees and payment

Fees for the Service are those set out in the plan you select or otherwise agreed with you in writing, and are invoiced for the billing period you choose. Unless stated otherwise, fees are exclusive of applicable taxes (including Czech VAT where applicable).

**Seats.** Opelli is sold per seat. A **seat** is an Authorized User whose account is in the `Active` state at the time of the daily billing check, and the **first three seats of every Account are free, for as long as the Account exists**. There is no separate free plan to sign up for and no upgrade step: an Account with three people pays nothing and has every module, and the fourth person is charged at the published rate. External guest accounts never count as seats. **Deactivating a user releases their seat immediately**, and that person's work — their tasks, time entries, comments and everything recorded under their name — stays in your Account untouched, so you can reactivate them for the next engagement.

**What “releases” means depends on your billing period, and we would rather say so than let you find out.** Adding a seat is billed pro rata from the day it becomes active, on either period. Releasing one is not symmetrical: on **monthly** billing, a released seat stops being charged for from that day, pro rata; on a **prepaid annual term**, the seats you have paid for are yours for the term, so releasing one produces no refund or credit — it makes the seat **immediately reusable capacity that you can activate somebody else into, at no extra cost, for the rest of the term**. Either way you never pay twice for one seat, and either way the released seat is available the moment you deactivate, not at the next billing date.

**Add-ons.** Where you need more than your seats include — extra storage, extra published sites, extra campaign recipients, or unlimited audit retention — you can buy an add-on. **Add-ons are priced monthly, and only monthly.** Buying one is a separate order and a separate monthly subscription: it is not a line on your seat subscription, whatever billing period that runs on, and it renews each month until you cancel it. **Cancelling an add-on takes effect at the end of the month you have already paid for, never part-way through one** — you paid for that month and you keep it — and the allowance it provides drops from the next period.

**A payment method is required, including where nothing is payable.** Every Account provides a valid payment card when it is created, and that includes an Account that expects to pay nothing because it stays within its free seats. You authorize us and our payment processor to charge that card for all fees that fall due — automatically, for each billing period, from the point the Account uses more than its free seats, buys an add-on, or incurs metered usage — and you agree to keep a valid card on file for as long as the Account exists.

**Payments are processed by Stripe.** Card details are collected and held by Stripe; **we never receive or store your card details**. Your payment is also subject to Stripe's own terms, and Stripe handles the payment data under its own privacy terms for that purpose. If Stripe declines or reverses a payment, the amount remains due.

**We issue the tax document ourselves.** Your invoice is issued by Opelli s.r.o. as a Czech tax document (_daňový doklad_), with the identifiers a Czech accountant needs. Any receipt or confirmation email sent by the payment processor confirms that a payment was taken and is not the tax document. **No invoice is issued for a billing period whose total is zero** — an Account inside its free seats simply receives none.

**Price changes.** If we change our pricing, we will give you advance notice and the opportunity to review the applicable pricing and terms before any change applies to you; continued use after a change takes effect, or express acceptance of a paid plan, constitutes agreement to pay. Where an evaluation, trial or other free access is provided, no fees apply for that access and we may change or end it at any time.

**Questions about an invoice** can be raised with us at [legal@opelli.dev](mailto:legal@opelli.dev) within 30 days of its date. We will not suspend an Account under section 10 over an amount you have disputed in good faith while we are still working it out with you.

### 10. Non-payment, suspension and reinstatement

If a payment fails, nothing is deleted. What happens instead is set out below, in order, and you will hear from us at each step. Notices go by email to the Account's administrators and to any billing contact you have given us.

1. **We tell you, and the payment is retried.** We notify you that the charge failed, and the payment processor retries it over the following days. You can update the card at any time; a successful payment ends the process here and nothing further happens.
2. **After 14 days the Account is suspended.** If the amount is still outstanding **14 days** after the first failed payment, we suspend the Account. Nobody can sign in; API keys and connected agents stop working; the Account stops serving, including public pages published from it such as forms, microsites and the privacy centre. **All Customer Content is retained, intact and unchanged.** Suspension is not deletion, and nothing is removed at this step.
3. **Paying reinstates the Account.** Once the outstanding amount is paid, we resume the Account and it is exactly as you left it — the same data, the same users, the same permissions, the same address. Suspending and resuming an Account are ordinary operations of the platform, not a restore from backup: there is nothing to reconstruct and nothing that is reconstructed approximately.
4. **Deletion is last, and it is announced.** We may delete a suspended Account and its Customer Content no earlier than **90 days** after suspension, and only after giving the Account's administrators at least **30 days'** written notice at the addresses we hold for them. Until deletion has actually happened, everything above still stands: paying reinstates the Account.

**You can take your data out at any point before deletion**, including while the Account is suspended. Ask us at [legal@opelli.dev](mailto:legal@opelli.dev) and we will either provide an export or restore access for long enough for you to run the exports yourself: wiki content exports as markdown, and everything else through the API. The same applies to an Account you have cancelled.

**Cancelling.** You may cancel a paid plan at any time. Cancellation takes effect at the end of the period you have already paid for, and fees already paid are not refunded for the unused part of that period unless we agree otherwise or the law requires it. At the end of that period the Account does not disappear. If it is within its free seats by then, it carries on using them at no charge; if it still has more seats than that and no valid payment, it is an Account with an amount outstanding and the steps above apply to it in the same way. An add-on subscription is cancelled separately, and on the same terms — end of the month you have paid for, allowance from the next period — as set out in section 9. You may also close the Account outright at any time under section 14.

Suspension for reasons other than non-payment — a security risk, a breach of these Terms, or a legal requirement — is dealt with in section 14.

### 11. Intellectual property and feedback

The Service, including all software, design, text, and trademarks (other than Customer Content), is owned by Opelli s.r.o. or its licensors and is protected by intellectual-property laws. We grant you a limited, non-exclusive, non-transferable, revocable right to access and use the Service in accordance with these Terms. No rights are granted to you other than those expressly set out here.

If you give us feedback, suggestions, or ideas about the Service, you grant us a perpetual, irrevocable, worldwide, royalty-free licence to use them without restriction or obligation to you. Feedback is given voluntarily and is not your Confidential Information.

### 12. Confidentiality

Each party may receive non-public information of the other that is marked or reasonably understood to be confidential (“Confidential Information”). The receiving party will use the other's Confidential Information only to perform under these Terms and will protect it with at least reasonable care. Customer Content is your Confidential Information. These obligations do not apply to information that is or becomes public through no fault of the receiving party, was already known to it, is independently developed, or is rightfully received from a third party; and either party may disclose Confidential Information where required by law, giving reasonable notice where lawful.

### 13. Privacy and data protection

Our handling of Personal Data is described in our [Privacy Policy](https://opelli.dev/privacy.html). Where we process Personal Data on your behalf as a processor, the **Data Processing Agreement** applies and forms part of these Terms; it sets out the subject-matter and duration of processing, our obligations under Article 28 GDPR, the sub-processors we use, the security measures in place, and how we assist you with data-subject requests and breach notification. If you require a signed copy of the Data Processing Agreement, contact [privacy@opelli.dev](mailto:privacy@opelli.dev).

### 14. Term, suspension and termination

These Terms apply for as long as you use the Service. You may stop using the Service and close your Account at any time. Suspension, reinstatement and deletion where an amount is unpaid are governed by section 10; this section covers everything else.

We may suspend or terminate your access, in whole or in part, if: (a) you materially breach these Terms and, where the breach is capable of cure, do not cure it within a reasonable period after notice; (b) your use poses a security risk to, or may adversely affect, the Service or others; or (c) we are required to do so by law. Where practicable and lawful, we will give notice before suspending or terminating.

On termination, your right to use the Service ends. For a limited period after termination (unless prohibited by law or our legitimate interests require otherwise), we will make Customer Content available for export; after that period we will delete or de-identify Customer Content in accordance with our Privacy Policy and Data Processing Agreement, subject to routine backup rotation. Sections that by their nature should survive termination (including intellectual property, confidentiality, disclaimers, limitation of liability, indemnification and governing law) will survive.

### 15. Disclaimers

To the maximum extent permitted by law, the Service is provided **“as is” and “as available”**, and we disclaim all warranties, whether express, implied or statutory, including any implied warranties of merchantability, fitness for a particular purpose, non-infringement, and any warranties arising from course of dealing or usage. We do not warrant that the Service will be uninterrupted, error-free, or secure, or that it will meet your requirements.

### 16. Limitation of liability

To the maximum extent permitted by applicable law:

- neither party will be liable for any indirect, incidental, special, consequential or punitive damages, or for any loss of profits, revenue, goodwill, or data, arising out of or relating to the Service or these Terms, even if advised of the possibility;
- Our total aggregate liability arising out of or relating to the Service or these Terms will not exceed the greater of (a) the total fees you paid to us for the Service in the twelve months before the event giving rise to the claim, or (b) EUR 100.

Nothing in these Terms limits or excludes either party's liability for death or personal injury caused by negligence, for fraud or fraudulent misrepresentation, or for any liability that cannot be limited or excluded under applicable law.

### 17. Indemnification

You will defend, indemnify and hold harmless Opelli s.r.o. from and against any third-party claims, damages, liabilities, costs and expenses (including reasonable legal fees) arising out of or related to: (a) your Customer Content; (b) your use of the Service in breach of these Terms or applicable law; or (c) your breach of your data-protection obligations as controller. We will notify you of the claim, give you control of the defence (with our right to participate through our own counsel), and reasonably cooperate; you may not settle a claim in a way that imposes obligations on us without our consent.

### 18. Changes to the service and these terms

We may update these Terms from time to time. If we make material changes, we will provide reasonable notice — for example, by posting the updated Terms with a new effective date at this address, or by notifying Account administrators. Changes take effect on the stated effective date. Your continued use of the Service after that date constitutes acceptance of the updated Terms. If you do not agree, you must stop using the Service before the changes take effect. Prior versions are superseded but remain identifiable by their version number and date.

### 19. Governing law and disputes

These Terms, and any dispute or claim arising out of or in connection with them (including non-contractual disputes or claims), are governed by the laws of the **Czech Republic**, without regard to its conflict-of-laws rules and excluding the United Nations Convention on Contracts for the International Sale of Goods. The parties submit to the exclusive jurisdiction of the courts of the Czech Republic, with the court competent for the registered seat of Opelli s.r.o. having local jurisdiction where permitted by law. Nothing in this section deprives a party of protection afforded by mandatory provisions of the law applicable to it.

### 20. General

**Entire agreement.** These Terms, together with the Privacy Policy and (where applicable) the Data Processing Agreement, are the entire agreement between you and Opelli s.r.o. regarding the Service and supersede any prior agreements on that subject.

**Assignment.** You may not assign or transfer these Terms without our prior written consent. We may assign these Terms to an affiliate or in connection with a merger, acquisition, or sale of assets, on notice to you.

**Severability.** If any provision is held unenforceable, it will be modified to the minimum extent necessary, and the remaining provisions will stay in effect.

**Waiver.** A failure to enforce a provision is not a waiver of it.

**Force majeure.** Neither party is liable for any delay or failure to perform (other than payment obligations) due to causes beyond its reasonable control.

**Notices.** We may give notice by email to your Account administrator or by posting within the Service; you may give notice to us at the contact address below.

### 21. Contact

**Opelli s.r.o.**

Nové sady 988/2, Staré Brno, 602 00 Brno, Czech Republic

Company ID (IČO): 29850762 · DUNS: 351787000 · Regional Court in Brno, Section C, File 153188

General & legal: [legal@opelli.dev](mailto:legal@opelli.dev)

Privacy: [privacy@opelli.dev](mailto:privacy@opelli.dev)

Web: [opelli.dev](https://opelli.dev)


---

# Acceptable Use Policy — Opelli

> What fair use of Opelli means — for accounts inside the free seats, for the volumes we meter, and for the volumes we do not. Written to be checkable: what we enforce today, and what we reserve the right to enforce with notice.

_Markdown edition of https://opelli.dev/acceptable-use — generated from the page itself on 2026-08-25._

---

_Legal_

## Acceptable Use Policy

What fair use of Opelli means — for an account that stays inside its free seats, for the volumes we meter, and for the volumes we do not. Written so you can check it rather than trust it.

**Effective:** 6 August 2026 · **Last updated:** 6 August 2026 · **Version:** 1.1

This Acceptable Use Policy (the “Policy”) sets out how Opelli, operated by **Opelli s.r.o.**, may and may not be used, and what volumes of use are fair. It forms part of, and is incorporated by reference into, our [Terms of Service](https://opelli.dev/terms.html) — see section 7 of the Terms. Capitalized terms have the meaning given in section 2 of the Terms. Where this Policy and the Terms differ on a point this Policy covers specifically, this Policy governs.

### 1. What this policy is

Opelli gives every Account the whole product. There is no free plan to leave and no module behind a purchase order: the **first three seats of every Account are free, for as long as the Account exists**, and an Account of three people has all seventeen modules, the MCP server, guest accounts and the API. That is a deliberate commitment, and it only survives if it is not abused.

This Policy exists so that the boundary is written down rather than improvised. It has two jobs:

- to say plainly what is **prohibited** — the things nobody may do with Opelli whatever they pay;
- to say plainly what is **disproportionate** — volumes of ordinary, legitimate use that are so far past what an Account pays for that we may have to limit them.

It applies to every Account, on every plan, including Accounts inside their free seats, evaluation Accounts and self-hosted deployments we operate for you. It applies equally to a person clicking in the web application, a script holding an API key, and a connected AI agent acting over MCP: **an agent is bound by this Policy exactly as the person whose credential it carries is.**

**Language versions.** This Policy is published in English and in [Czech](https://opelli.dev/cs/acceptable-use.html), and follows the Terms' rule on language: the version of the [Terms](https://opelli.dev/terms.html) that governs for you decides which version of this Policy does too.

### 2. Two kinds of limit, and we do not blur them

A published limit nobody applies is a promise we are not keeping. A published limit that is applied but was never written down is worse. So the limits below are split into two lists and the difference is stated, not implied:

- **Limits we enforce today** (section 5). These are applied by the software, right now, on every Account. If you exceed one, the request is refused and you are told why. You can rely on these numbers.
- **Limits we reserve the right to apply** (section 6). These are ceilings on things the platform does **not** currently meter. Nothing counts them today and nothing will refuse a request because of them. They are published so that the boundary is knowable in advance, and so that if we do have to start applying one, you were told the number before it mattered rather than after.

**We will not begin enforcing a reserved limit against your Account without notice**, on the terms set out in section 9. Where a reserved limit becomes an enforced one for everybody, we will publish it in section 5 with a new effective date and give reasonable advance notice as required by section 18 of the Terms.

A note on measurement, in the interest of not overstating what we know: Opelli's request counters are a live gauge that each server keeps in memory for its own diagnostics, not a billing meter and not a quota. When we say a dimension is unmetered, we mean it — there is no counter behind it to appeal to.

### 3. Free seats and fair use

The free seats are the first three seats of an ordinary Account, not a separate product. Everything in the Terms applies to them: the same modules, the same API, the same guarantees about your data.

**Allowances attach to paid seats, not to headcount.** This is the design rule that makes free seats affordable, and it is worth stating outright because it is what stops a three-person Account running a fifty-thousand-recipient campaign for nothing. The metered allowances — published sites, storage, campaign recipients, guest accounts and managed model spend — are calculated as a base amount _plus_ an amount per **paid** seat. An Account inside its free seats therefore receives the base amount and nothing more: **2 published sites, 5 GB of storage, 200 campaign recipients a month, 2 guest accounts, and no included managed model spend.** Audit history is kept for every Account and is never metered. The current figures are on the [pricing page](https://opelli.dev/pricing.html), which is generated from the same code that bills Accounts.

The base allowance is deliberately small but not token: a free Account has to be able to genuinely use every module, or the offer means nothing.

#### What is disproportionate

Beyond the allowances, we ask one thing of an Account that pays nothing: that its use looks like three people doing their own work. **We reserve the right to limit or suspend the Service for use that is grossly disproportionate to a free Account.** In practice that means, for example:

- sustained automated traffic — API or MCP requests, or agent runs — at a volume that would be unusual for a large paying Account;
- using the Account primarily as a mail relay, a file host, a content-delivery origin or a scraping target rather than to run an organization;
- storage or object counts that plainly do not correspond to three people's work;
- publishing microsites whose traffic is the purpose of the Account rather than a by-product of the work in it;
- operating many Accounts to keep each of them inside the free seats (section 8).

**The remedy for disproportionate use is never deletion.** It is notice, then a limit, then — only if it continues — suspension, in that order and with your Customer Content untouched at every step. Section 9 sets this out. Nothing in this Policy allows us to delete your data as a fair-use remedy.

The straightforward way out of a fair-use problem is also the honest one: an Account that has grown past three people's work is an Account that should be paying for the seats doing it.

### 4. Allowances, and what happens past one

Allowances are a billing matter, not a gate. Published sites, storage and campaign recipients are **measured and billed**: the platform does not refuse a publish or a send the moment you pass an allowance. Where you need more than your seats include, you buy the add-on that covers it, on the terms in section 9 of the Terms. Guest accounts are the one exception and are described in section 5 below.

**Managed model spend is genuinely metered in money, and can be capped.** An organization can set a monthly ceiling for what the agents Opelli runs may spend, and an administrator can set one per person; a run that would pass a ceiling is refused and recorded as refused. Two honest caveats: **a ceiling only applies if it has been set** — leaving the setting blank means no ceiling, not a default one — and because a run is checked before it starts and priced after it finishes, a ceiling can be passed by at most the cost of one run. Connecting your own model subscription over MCP costs nothing and is not metered by us at all.

### 5. Limits we enforce today

These are applied by the software on every Account. Exceeding one produces an error, not a charge.

| What | Limit | Applies to |
| --- | --- | --- |
| Free seats | The first 3 seats of every Account | Every Account |
| Guest accounts | 2, plus 2 per paid seat. This is the one allowance the platform refuses rather than bills: creating a guest past it fails and says so. | Every Account |
| File attachment upload | 16 MB per file | Wiki pages, task descriptions, microsite files |
| Image upload | 10 MB per image, and only PNG, JPEG, WebP or GIF — the file's actual bytes are checked, not the type it claims | Wiki, tasks, campaigns |
| Avatar and organization logo | 1 MB, same formats | Every Account |
| Image pulled in from a URL | 10 MB, 10-second fetch | Campaign images |
| HTML prototype import | 16 MB per document | Project wiki |
| Flow-chart data | 200 kB per chart | Project wiki |
| Microsite deploy | 500 files and 100 MB in total per deploy, 16 MB per file | Microsites |
| Site assistant context | 28 kB per text file and 100 kB per site, plus at most 6 linked wiki pages of 20 kB each. Past that the assistant _refuses with a reason_ rather than working from part of the site. | The microsite assistant |
| Dataset rows | 8 kB per row, 500 rows per request, 100 000 rows per dataset — an append past the cap fails and says so; older rows age out on the retention the dataset sets | Datasets |
| App versions & state | An app keeps its newest 10 versions plus whatever is live; saved app state is capped at 64 kB per value | Apps |
| PDF signing | 16 MB per document; the document, certificate and passphrase are processed in one request and nothing is retained | Signing |
| Calendar feed | 5 MB per feed, refreshed on a cache | Time tracking |
| Public form submission | 200 kB per submission | Published forms |
| Outbound webhook delivery | 10-second timeout; 6 attempts spread over roughly 8 hours, then the delivery is abandoned; the delivery log is kept 30 days | Outbound webhooks |
| Campaign send pace | Roughly four messages a second, regardless of list size | Email campaigns |
| Managed model spend | The monthly ceilings your organization sets, per Account and per person — enforced only where a ceiling has been set | Agents Opelli runs |
| Anti-abuse rate limits | Sign-in, connector authorization, public form submissions, dataset ingest tokens, privacy-centre requests and business-registry lookups are rate-limited per IP address and per Account. We do not publish the thresholds — they are a security control, and they are set well above ordinary use. | Public and sign-in surfaces |

Some of these are protective rather than commercial — they exist so that one request cannot exhaust the memory of a server other Accounts are sharing. We may adjust them for the same reason, and where an adjustment would reduce something you rely on, section 18 of the Terms applies.

### 6. Limits we reserve the right to apply

**Nothing in this section is metered today.** No counter runs against these dimensions and no request is refused because of them. They are the ceilings we consider fair, published in advance so that the boundary is knowable — and so that we are held to a number rather than to a judgement call.

Each is stated per calendar month unless said otherwise, and each scales the way everything else in Opelli scales: a base amount plus an amount per paid seat, so an Account inside its free seats gets the base.

| Dimension | Ceiling we reserve | Why this number |
| --- | --- | --- |
| **API and MCP requests** | 10 000 requests per seat per day, and never less than 30 000 per Account per day | A person working all day in the application generates a small fraction of this, and an agent doing real work on their behalf still does. It is set to be unreachable by use and reachable by a loop. |
| **Egress** — everything served out of Opelli, including the content-delivery traffic of microsites published from your Account | 100 GB per Account per month, plus 20 GB per paid seat | Twenty times the base storage allowance, every month. A team re-reading its own attachments and running a few modest microsites is nowhere near it; a site whose audience is the point of the Account is. |
| **Outbound webhook deliveries** | 100 000 deliveries per Account per month | Deliveries follow the activity log, so this is many times what a busy Account of any size produces. It bounds a misconfigured endpoint or a subscription loop, not real integration traffic. |
| **Outbound notification and system mail** (everything except email campaigns) | 1 000 messages per Account per day, and 200 per user per day | Several times the busiest plausible day of notifications for a large Account. The per-user figure is the one that matters: it bounds what a single compromised account can send in our name before anyone notices. |
| **Campaign recipients in a single send** | 50 000 recipients | Campaign volume is otherwise a billing matter (section 4). This is a ceiling on one send, so a mistake or a compromised account cannot become a very large one at four messages a second. |
| **Agent runs whose model cost is not billed through us** — chiefly runs on your own model subscription | 500 runs per seat per month, and never less than 1 500 per Account per month | Roughly four times the usage we model for a heavy seat. Managed model spend is already capped in money, so this covers only the path where money is not the meter. |
| **Stored objects** — files, images, attachments, microsite files, counted as objects rather than bytes | 250 000 objects per Account, plus 25 000 per paid seat | Storage is billed by size, and a very large number of very small files costs almost nothing in bytes while costing a great deal to keep. This bounds the shape that billing by size does not see. |

If your legitimate use needs more than one of these — a genuinely high-volume integration, a microsite with real traffic behind it, an agent workload that is the point rather than the overhead — that is a conversation, not a violation. Write to [legal@opelli.dev](mailto:legal@opelli.dev) and we will agree a figure in writing. An agreed figure overrides this section for your Account.

### 7. What you must not do

The following are prohibited on every Account, at every volume, and are not a matter of fair use. They restate and expand section 7 of the Terms.

#### Sending

- **No unsolicited mail.** You may only send email campaigns to recipients from whom you hold a lawful basis to send, and you must honour unsubscribe requests. Opelli adds a working one-click unsubscribe to every campaign and applies it across your Account's lists; you must not remove it, defeat it, or re-add a recipient who has used it.
- **No purchased, scraped, harvested or rented lists**, and no importing a list you cannot account for.
- **Nothing that damages the reputation of the platform's sending infrastructure**, which every Account shares. Sustained hard-bounce or complaint rates are grounds for us to limit sending under section 9.
- No forged, disguised or misleading sender identity, headers, or reply paths.

#### Published pages

- **No phishing or impersonation.** Published forms, microsites, the privacy centre and any other page served from your Account must not imitate another organization, collect credentials or payment details under false pretences, or present fabricated records as genuine.
- No malware, no distribution of exploit code, and no use of a published page to redirect visitors into either.
- No content that is unlawful, that infringes someone's rights, or that you have no right to publish.

#### The platform

- **No reselling.** You may not resell, sublicense, rent or otherwise make the Service available to third parties except as Authorized Users of your own Account, and you may not use it to operate a service for others or to build a competing product.
- **No circumventing the limits.** You may not evade, or attempt to evade, seat counting, allowances, permissions, rate limits or any other control described in this Policy or the Terms — including by splitting one organization across Accounts (section 8), by rotating credentials to reset a limit, or by using guest accounts in place of seats for people who are in fact part of your organization.
- No probing, scanning or penetration-testing of the Service without our prior written agreement; no attempting to reach another Account's data; no reverse-engineering, except where that restriction is void under applicable law.
- No use that knowingly places an unreasonable load on the Service, whether by a person, a script or a connected agent.

Suspected illegal activity, and anything that puts other Accounts at risk, may be acted on immediately under section 14 of the Terms rather than through the graduated steps below.

### 8. One organization, one account

Free seats are given per organization, not per Account. **You may not split a single organization across several Accounts in order to keep each of them inside its free seats**, and you may not create Accounts on behalf of people who are in substance part of your own organization for the same purpose.

Where several Accounts are plainly one organization — the same people, the same customers, the same body of work, the same billing entity or the same beneficial owner — we may treat them as a single Account for the purpose of counting seats and allowances. We will tell the administrators of the Accounts concerned before we do, and give you the chance to explain or to consolidate them yourself.

This is not aimed at the ordinary cases, and those are worth naming so nobody has to guess. A holding company and a genuinely separate operating subsidiary are two organizations. An agency and its client are two organizations, even when the same person administers both. A single organization running a second Account to keep one client's work walled off is one organization — and that is what projects, permissions and external guests are for, at no extra cost.

### 9. How we act

Where use is disproportionate rather than prohibited, we act in order, and you hear from us at each step. Notices go to **every active administrator of the Account**, by email to the address they sign in with — and, where your organization has connected a chat platform, there as well. These are operational notices about the Account: they are not marketing and cannot be switched off.

1. **We tell you.** We describe what we are seeing, which dimension it concerns, and what would resolve it — usually paying for the seats the work is being done by, buying the add-on that covers the volume, agreeing a higher figure with us, or simply changing what is running. You get at least **14 days** to respond before anything is limited, unless the use is actively degrading the Service for other Accounts.
2. **We apply a limit.** If it continues, we may rate-limit or cap the specific dimension concerned — API and MCP request volume, sending, publishing, webhook delivery — leaving the rest of the Account working normally. A limit is targeted at the behaviour, not at the Account, and it is lifted when the behaviour stops.
3. **We suspend.** Only where a limit has not resolved it, or where the use is causing harm we cannot contain, do we suspend the Account under section 14 of the Terms. **Suspension retains all Customer Content, intact and unchanged.** Nobody can sign in and the Account stops serving; nothing is removed. Suspending and resuming are ordinary operations of the platform, not a restore from backup.
4. **Resolving it reinstates the Account**, exactly as you left it — the same data, the same users, the same permissions, the same address. Where the resolution is commercial, paying for what the Account is using reinstates it, on the same footing as section 10 of the Terms.

Data is never a remedy.

Nothing in this Policy permits us to delete Customer Content in response to a fair-use problem. Deletion happens only on the separate, announced timetable in section 10 of the Terms — no earlier than 90 days after suspension and only after 30 days' written notice — and you can export your data at any point before it, including while an Account is suspended.

If you think we have this wrong, say so at [legal@opelli.dev](mailto:legal@opelli.dev). We would rather be corrected than right.

### 10. Changes and contact

We may update this Policy as the platform changes — in particular, to move a limit from section 6 to section 5 once the software actually measures it. Material changes are notified and take effect on the stated effective date, in accordance with section 18 of the Terms. Prior versions are superseded but remain identifiable by their version number and date.

**Opelli s.r.o.**

Nové sady 988/2, Staré Brno, 602 00 Brno, Czech Republic

Company ID (IČO): 29850762 · DUNS: 351787000 · Regional Court in Brno, Section C, File 153188

Fair use, limits & abuse reports: [legal@opelli.dev](mailto:legal@opelli.dev)

Privacy: [privacy@opelli.dev](mailto:privacy@opelli.dev)

Web: [opelli.dev](https://opelli.dev)


---

# Privacy Policy — Opelli

> How Opelli s.r.o. collects, uses and protects personal data in connection with Opelli — including the controller/processor split, sub-processors and your GDPR rights.

_Markdown edition of https://opelli.dev/privacy — generated from the page itself on 2026-08-25._

---

_Legal_

## Privacy Policy

How Opelli s.r.o. collects, uses, shares and protects personal data in connection with Opelli — and the rights you have over your data under the GDPR.

**Effective:** 6 August 2026 · **Last updated:** 6 August 2026 · **Version:** 1.1

This Privacy Policy explains how **Opelli s.r.o.** handles personal data in connection with Opelli — the marketing site at opelli.dev, the demo request form, and the Opelli application itself. A key distinction runs through this policy: for some data we decide the purposes and means of processing (we are the **controller**); for the data our customers put into Opelli about their own people and contacts, we act only on their instructions (we are the **processor**). Section 2 explains which is which.

### 1. Who we are

The controller responsible for the personal data described in this policy (except where we act as a processor — see section 2) is:

**Opelli s.r.o.**

Nové sady 988/2, Staré Brno, 602 00 Brno, Czech Republic

Company ID (IČO): 29850762 · DUNS: 351787000 · Regional Court in Brno, Section C, File 153188

Privacy contact: [privacy@opelli.dev](mailto:privacy@opelli.dev)

We have not appointed a statutory Data Protection Officer, as we are not required to. You can reach our privacy team at the address above for any question about this policy or your personal data.

**Language versions.** This Policy is published in English and in [Czech](https://opelli.dev/cs/privacy.html), and both say the same thing. If your relationship with us is governed by the Czech version of the [Terms of Service](https://opelli.dev/terms.html) — Customers seated in the Czech Republic — the Czech version of this Policy is the authoritative one for you; for everyone else it is the English version.

### 2. When we are the controller vs the processor

Opelli is a platform our customers use to run their operations. That creates two roles:

- **We are the controller** for the personal data we handle to run our business and provide the Service — for example, the details of the people who create and administer accounts, sign in, contact support, or ask us for a demo, and the technical logs the Service generates. Sections 3–5 and 8–15 describe this data.
- **We are the processor** for the personal data our customers choose to put into Opelli about _their_ team members, contractors, CRM contacts, mailing-list recipients, form respondents and similar (“Customer Content”). Here the customer is the controller; we process it only on their documented instructions under a Data Processing Agreement. Section 6 describes this data. If you are a data subject whose personal data appears in a customer's workspace and you want to exercise your rights over it, please contact that customer (the controller); we will assist them as our agreement requires.

### 3. Personal data we collect (as controller)

#### Account and profile data

When you are invited to and sign in to Opelli, we receive from your sign-in provider — Google or Microsoft (via OAuth/OpenID Connect) — your name, email address, a stable account identifier, and profile picture. Within your profile you or your administrator may add further details such as job title, contact details, skills and reporting lines.

#### Billing data

When an Account is created we collect what we need to bill it — the billing entity's name and address, company and VAT identifiers, and a billing contact — together with the record of the invoices we issued and the payments taken against them. A valid payment card is required for every Account, including one that expects to pay nothing because it stays within its free seats. Payments are processed by Stripe (see section 7): card details are collected and held by Stripe; **we never receive or store your card details**. The invoice itself is issued by us, as a Czech tax document; any receipt from the payment processor is only a confirmation that a payment was taken.

#### Demo request data

If you request a demo through the form on opelli.dev, we collect the email address you provide. (The form also contains a hidden “company” field that is a spam honeypot — genuine visitors never fill it, and submissions that do are discarded.)

#### Communications and support

If you contact us by email or through the Service, we keep your messages and the information you choose to include, so we can respond and keep records.

#### Usage, device and log data

When you use the Service, our systems automatically record technical information such as IP address, browser and device type, timestamps, the pages or API endpoints requested, and diagnostic and security logs. The Service also maintains internal activity and audit logs of actions taken within an account (for traceability and security).

The Opelli marketing site at opelli.dev sets

no cookies

, runs

no analytics or advertising trackers

, and loads no third-party scripts. The only network request it makes on your behalf is submitting the demo request form when you choose to.

### 4. How and why we use personal data — and our legal bases

As controller, we process personal data for the following purposes, each with a legal basis under Article 6(1) GDPR:

| Purpose | Data used | Legal basis |
| --- | --- | --- |
| Providing, operating and maintaining the Service and your account | Account/profile, usage/log data | Performance of a contract (Art. 6(1)(b)); legitimate interests (Art. 6(1)(f)) for users acting for an organizational customer |
| Authenticating sign-in and securing accounts | Sign-in provider account identifier, session data, API-key/token metadata | Contract; legitimate interests in security |
| Billing an account, taking payment, and issuing and keeping invoices | Billing entity and contact details, company/VAT identifiers, payment and invoice records | Performance of a contract (Art. 6(1)(b)); legal obligation (Art. 6(1)(c)) for accounting and tax records |
| Responding to your demo request and arranging the demo | Demo request email | Consent (Art. 6(1)(a)) / steps prior to a contract (Art. 6(1)(b)) |
| Providing support and communicating about the Service (including important service notices) | Contact and communication data | Contract; legitimate interests |
| Securing the Service, preventing abuse, and keeping audit/activity logs | Usage, device and log data | Legitimate interests (Art. 6(1)(f)) in the security and integrity of the Service |
| Improving and developing the Service | Aggregated/technical usage data; feedback | Legitimate interests |
| Complying with legal obligations and enforcing our terms | As relevant | Legal obligation (Art. 6(1)(c)); legitimate interests in establishing or defending legal claims |

Where we rely on legitimate interests, we have balanced them against your rights and freedoms. You may object to processing based on legitimate interests as described in section 12. Where we rely on consent, you may withdraw it at any time.

### 5. Cookies and similar technologies

The Opelli application uses a single **strictly necessary** cookie: a signed, `HttpOnly`, `SameSite=Lax` session cookie that keeps you signed in. It is essential to the Service and cannot be switched off while you are using the app. We do not use advertising, profiling or third-party analytics cookies. As noted above, the marketing site sets no cookies at all. Because we use only strictly necessary cookies and no tracking, no cookie-consent banner is required.

### 6. Data we process on behalf of our customers (as processor)

When our customers use Opelli, they submit Customer Content that may contain personal data about their own team members, contractors, customers and contacts, mailing-list recipients, and people who respond to their public forms. Depending on how the customer configures the Service, this can include names, email addresses and phone numbers, job titles, project and task assignments, time entries, CRM notes and deal information, marketing-list membership, form answers, and GDPR-compliance records (such as consent logs and data-subject requests) that the customer maintains within the Service.

For all such data, the customer is the controller and we are the processor. We process it only to provide the Service and on the customer's documented instructions, under a Data Processing Agreement that reflects Article 28 GDPR. On those instructions the Service also notifies a customer's own users about activity in their workspace, by chat message or email, and each of them can switch those notifications off in their personal settings. We do not use Customer Content for our own purposes, and we do not sell personal data. If your personal data is held in a customer's Opelli workspace and you wish to access, correct or delete it, please contact that organization directly; Opelli also provides customers with tools (a privacy centre, a personal-data locator and consent ledger) to help them respond.

### 7. Sub-processors and service providers

We rely on a small number of trusted providers to deliver the Service. They process personal data on our behalf under contracts that impose appropriate data-protection obligations. Our current sub-processors are:

| Sub-processor | Purpose | Location of processing |
| --- | --- | --- |
| Amazon Web Services (AWS) | Cloud hosting, database, file/object storage, and transactional & campaign email delivery (Amazon SES) | European Union (Frankfurt, `eu-central-1`) |
| Stripe (Stripe Payments Europe, Ltd.) | Payment processing — the payment card, the billing contact and company details on the account, and the record of payments taken. Card details are collected and held by Stripe; we never receive or store your card details | EU (Ireland) with possible transfer to the US (Standard Contractual Clauses) |
| Google (Google Ireland Ltd) | Sign-in (OAuth / OpenID Connect) and outbound email relay via Workspace SMTP | EU with possible transfer to the US (Standard Contractual Clauses) |
| Microsoft (Microsoft Ireland Operations Ltd) | Sign-in (OAuth / OpenID Connect) — only where an organization enables Microsoft sign-in | EU with possible transfer to the US (Standard Contractual Clauses) |
| Cloudflare, Inc. | DNS, edge/CDN network and hosting of the marketing site | Global edge network; US-based provider (Standard Contractual Clauses) |
| BunnyWay d.o.o. (bunny.net) | Content delivery and edge storage for websites your organization publishes from Opelli — the published files and the visitor request logs of those sites | European Union (Slovenia); global edge network for delivery |
| Toggl OÜ | Time-tracking synchronisation — only if an individual user connects their own Toggl account | European Union (Estonia) |

Some features integrate with services that _you_ operate or connect, and which are not our sub-processors — for example, a Mattermost server or Slack workspace you run, a GitHub repository whose webhooks you configure, or a public lookup to the Czech ARES business register. Data exchanged with those services is governed by your own arrangements and their terms.

We may update our sub-processors as the Service evolves. For customers, our Data Processing Agreement sets out how we give notice of new sub-processors and how objections are handled. To receive sub-processor change notices, contact [privacy@opelli.dev](mailto:privacy@opelli.dev).

### 8. When we share personal data

We do not sell personal data or share it for third-party advertising. We disclose personal data only:

- to the sub-processors and service providers listed above, to provide the Service;
- within your organization's account, according to the roles and permissions its administrators configure (Opelli enforces per-user, per-project access controls);
- where required by law, regulation, legal process, or a lawful governmental request, or to protect the rights, property or safety of Opelli s.r.o., our users or others;
- in connection with a merger, acquisition, financing or sale of assets, in which case we will require the recipient to honour this policy, and will notify you of any change of controller.

### 9. International data transfers

Our primary hosting and storage of application data — including Customer Content and account data — takes place within the **European Union** (AWS Frankfurt, `eu-central-1`). Websites you publish from Opelli are delivered by bunny.net, whose company and storage are in the **European Union** (Slovenia) and whose delivery network is global — only the files you have chosen to publish, and the request logs of the people who visit them, reach it. Some sub-processors (such as Google, Stripe and Cloudflare) are established in, or may process data in, countries outside the European Economic Area. Where personal data is transferred outside the EEA, we rely on an appropriate transfer mechanism under Chapter V GDPR — in particular the European Commission's Standard Contractual Clauses, together with supplementary measures where needed. You can request more detail about the safeguards in place by contacting us.

### 10. How long we keep personal data

We keep personal data only as long as necessary for the purposes described in this policy:

- **Account and profile data** — for as long as the account exists, **including while it is suspended**, and for a reasonable period afterwards to wind down the relationship, resolve disputes and meet legal obligations.
- **Customer Content** (as processor) — for as long as the customer's account exists. **Suspending an account deletes nothing**: Customer Content is retained intact and unchanged, and remains available to the customer for export on request throughout. Where an account is deleted for non-payment, that happens no earlier than **90 days** after suspension and only after at least **30 days'** written notice to its administrators (see [section 10 of the Terms](https://opelli.dev/terms.html#non-payment), which governs that timeline). On termination it is made available for export for a limited period and then deleted or de-identified in line with our Data Processing Agreement, subject to routine backup rotation.
- **Billing records and issued invoices** — for the retention period required by Czech accounting and tax law, which may outlast the account itself.
- **Demo request email** — until we have responded and any follow-up is complete, or you ask us to remove it, whichever is earlier.
- **Security and system logs** — for a limited period appropriate to their security and diagnostic purpose.
- **Backups** — encrypted backups are rotated on a regular cycle, so residual copies may persist for a short time after deletion from the live systems.

We may retain certain information longer where required to comply with legal obligations or to establish, exercise or defend legal claims.

### 11. How we protect personal data

We implement appropriate technical and organizational measures to protect personal data, including:

- authentication through Google or Microsoft OAuth with PKCE and server-side verification of ID tokens; accounts are pinned to a stable provider identifier, and there is no password store and no authentication bypass;
- encryption in transit (TLS) and encryption of data and backups at rest through our cloud provider;
- signed, `HttpOnly`, `SameSite=Lax` session cookies, an origin/CSRF check on state-changing requests, and a strict content-security policy;
- a granular permission model (per-feature access levels and per-project row scope) that governs the web app, the API and connected AI agents identically, so no integration can exceed the access of the person using it;
- API keys stored only as SHA-256 digests (never retrievable after creation), scoped to specific modules, and revocable/rotatable;
- strict per-tenant data isolation, secrets held in a managed secrets store, and least-privilege access for our systems.

No method of transmission or storage is completely secure, but we work to protect personal data and to detect and respond to incidents. Where we act as processor and become aware of a personal-data breach, we will notify the affected customer without undue delay so they can meet their own obligations.

### 12. Your rights

Subject to the conditions and exceptions in applicable data-protection law, you have the right to:

- **access** the personal data we hold about you and receive a copy;
- **rectify** inaccurate or incomplete data;
- **erase** your data (the “right to be forgotten”);
- **restrict** or **object** to certain processing, including processing based on our legitimate interests;
- **data portability** — receive certain data in a structured, commonly used, machine-readable format;
- **withdraw consent** at any time where we rely on consent, without affecting processing already carried out.

To exercise these rights in relation to data for which we are the controller, contact [privacy@opelli.dev](mailto:privacy@opelli.dev). We will respond within the timeframes required by law (generally within one month). We may need to verify your identity before acting. If your data sits in a customer's Opelli workspace, the customer is the controller — please direct your request to them, and we will support them as required.

### 13. Children

Opelli is a business tool intended for use by professionals. It is not directed at children, and we do not knowingly collect personal data from children. If you believe a child has provided us personal data, please contact us and we will take appropriate steps to delete it.

### 14. Changes to this policy

We may update this Privacy Policy from time to time. When we make material changes, we will revise the “Last updated” date and, where appropriate, provide additional notice (for example, within the Service or by email to account administrators). We encourage you to review this page periodically. The current version is always available at this address.

### 15. How to contact us and your right to complain

**Opelli s.r.o.**

Nové sady 988/2, Staré Brno, 602 00 Brno, Czech Republic

Company ID (IČO): 29850762 · DUNS: 351787000 · Regional Court in Brno, Section C, File 153188

Privacy: [privacy@opelli.dev](mailto:privacy@opelli.dev)

Web: [opelli.dev](https://opelli.dev)

If you have a concern about how we handle your personal data, please contact us first — we will do our best to resolve it. You also have the right to lodge a complaint with a supervisory authority. In the Czech Republic this is the **Office for Personal Data Protection** (Úřad pro ochranu osobních údajů, [uoou.gov.cz](https://uoou.gov.cz)), Pplk. Sochora 27, 170 00 Praha 7. You may also contact the supervisory authority in your country of residence or work.

