Opelli
Terms Privacy ← opelli.dev

Legal

Acceptable Use Policy

What fair use of Opelli means — for an account that stays inside its free seats, for the volumes we meter, and for the volumes we do not. Written so you can check it rather than trust it.

Effective: 6 August 2026 Last updated: 6 August 2026 Version: 1.1

Contents

  1. What this policy is
  2. Two kinds of limit
  3. Free seats and fair use
  4. Allowances, and what happens past one
  5. Limits we enforce today
  6. Limits we reserve the right to apply
  7. What you must not do
  8. One organization, one account
  9. How we act
  10. Changes & contact

This Acceptable Use Policy (the “Policy”) sets out how Opelli, operated by Opelli s.r.o., may and may not be used, and what volumes of use are fair. It forms part of, and is incorporated by reference into, our Terms of Service — see section 7 of the Terms. Capitalized terms have the meaning given in section 2 of the Terms. Where this Policy and the Terms differ on a point this Policy covers specifically, this Policy governs.

What this policy is

Opelli gives every Account the whole product. There is no free plan to leave and no module behind a purchase order: the first three seats of every Account are free, for as long as the Account exists, and an Account of three people has all seventeen modules, the MCP server, guest accounts and the API. That is a deliberate commitment, and it only survives if it is not abused.

This Policy exists so that the boundary is written down rather than improvised. It has two jobs:

  • to say plainly what is prohibited — the things nobody may do with Opelli whatever they pay;
  • to say plainly what is disproportionate — volumes of ordinary, legitimate use that are so far past what an Account pays for that we may have to limit them.

It applies to every Account, on every plan, including Accounts inside their free seats, evaluation Accounts and self-hosted deployments we operate for you. It applies equally to a person clicking in the web application, a script holding an API key, and a connected AI agent acting over MCP: an agent is bound by this Policy exactly as the person whose credential it carries is.

Language versions. This Policy is published in English and in Czech, and follows the Terms' rule on language: the version of the Terms that governs for you decides which version of this Policy does too.

Two kinds of limit, and we do not blur them

A published limit nobody applies is a promise we are not keeping. A published limit that is applied but was never written down is worse. So the limits below are split into two lists and the difference is stated, not implied:

  • Limits we enforce today (section 5). These are applied by the software, right now, on every Account. If you exceed one, the request is refused and you are told why. You can rely on these numbers.
  • Limits we reserve the right to apply (section 6). These are ceilings on things the platform does not currently meter. Nothing counts them today and nothing will refuse a request because of them. They are published so that the boundary is knowable in advance, and so that if we do have to start applying one, you were told the number before it mattered rather than after.

We will not begin enforcing a reserved limit against your Account without notice, on the terms set out in section 9. Where a reserved limit becomes an enforced one for everybody, we will publish it in section 5 with a new effective date and give reasonable advance notice as required by section 18 of the Terms.

A note on measurement, in the interest of not overstating what we know: Opelli's request counters are a live gauge that each server keeps in memory for its own diagnostics, not a billing meter and not a quota. When we say a dimension is unmetered, we mean it — there is no counter behind it to appeal to.

Free seats and fair use

The free seats are the first three seats of an ordinary Account, not a separate product. Everything in the Terms applies to them: the same modules, the same API, the same guarantees about your data.

Allowances attach to paid seats, not to headcount. This is the design rule that makes free seats affordable, and it is worth stating outright because it is what stops a three-person Account running a fifty-thousand-recipient campaign for nothing. The metered allowances — published sites, storage, campaign recipients, guest accounts and managed model spend — are calculated as a base amount plus an amount per paid seat. An Account inside its free seats therefore receives the base amount and nothing more: 2 published sites, 5 GB of storage, 200 campaign recipients a month, 2 guest accounts, and no included managed model spend. Audit history is kept for every Account and is never metered. The current figures are on the pricing page, which is generated from the same code that bills Accounts.

The base allowance is deliberately small but not token: a free Account has to be able to genuinely use every module, or the offer means nothing.

What is disproportionate

Beyond the allowances, we ask one thing of an Account that pays nothing: that its use looks like three people doing their own work. We reserve the right to limit or suspend the Service for use that is grossly disproportionate to a free Account. In practice that means, for example:

  • sustained automated traffic — API or MCP requests, or agent runs — at a volume that would be unusual for a large paying Account;
  • using the Account primarily as a mail relay, a file host, a content-delivery origin or a scraping target rather than to run an organization;
  • storage or object counts that plainly do not correspond to three people's work;
  • publishing microsites whose traffic is the purpose of the Account rather than a by-product of the work in it;
  • operating many Accounts to keep each of them inside the free seats (section 8).

The remedy for disproportionate use is never deletion. It is notice, then a limit, then — only if it continues — suspension, in that order and with your Customer Content untouched at every step. Section 9 sets this out. Nothing in this Policy allows us to delete your data as a fair-use remedy.

The straightforward way out of a fair-use problem is also the honest one: an Account that has grown past three people's work is an Account that should be paying for the seats doing it.

Allowances, and what happens past one

Allowances are a billing matter, not a gate. Published sites, storage and campaign recipients are measured and billed: the platform does not refuse a publish or a send the moment you pass an allowance. Where you need more than your seats include, you buy the add-on that covers it, on the terms in section 9 of the Terms. Guest accounts are the one exception and are described in section 5 below.

Managed model spend is genuinely metered in money, and can be capped. An organization can set a monthly ceiling for what the agents Opelli runs may spend, and an administrator can set one per person; a run that would pass a ceiling is refused and recorded as refused. Two honest caveats: a ceiling only applies if it has been set — leaving the setting blank means no ceiling, not a default one — and because a run is checked before it starts and priced after it finishes, a ceiling can be passed by at most the cost of one run. Connecting your own model subscription over MCP costs nothing and is not metered by us at all.

Limits we enforce today

These are applied by the software on every Account. Exceeding one produces an error, not a charge.

WhatLimitApplies to
Free seatsThe first 3 seats of every AccountEvery Account
Guest accounts2, plus 2 per paid seat. This is the one allowance the platform refuses rather than bills: creating a guest past it fails and says so.Every Account
File attachment upload16 MB per fileWiki pages, task descriptions, microsite files
Image upload10 MB per image, and only PNG, JPEG, WebP or GIF — the file's actual bytes are checked, not the type it claimsWiki, tasks, campaigns
Avatar and organization logo1 MB, same formatsEvery Account
Image pulled in from a URL10 MB, 10-second fetchCampaign images
HTML prototype import16 MB per documentProject wiki
Flow-chart data200 kB per chartProject wiki
Microsite deploy500 files and 100 MB in total per deploy, 16 MB per fileMicrosites
Site assistant context28 kB per text file and 100 kB per site, plus at most 6 linked wiki pages of 20 kB each. Past that the assistant refuses with a reason rather than working from part of the site.The microsite assistant
Dataset rows8 kB per row, 500 rows per request, 100 000 rows per dataset — an append past the cap fails and says so; older rows age out on the retention the dataset setsDatasets
App versions & stateAn app keeps its newest 10 versions plus whatever is live; saved app state is capped at 64 kB per valueApps
PDF signing16 MB per document; the document, certificate and passphrase are processed in one request and nothing is retainedSigning
Calendar feed5 MB per feed, refreshed on a cacheTime tracking
Public form submission200 kB per submissionPublished forms
Outbound webhook delivery10-second timeout; 6 attempts spread over roughly 8 hours, then the delivery is abandoned; the delivery log is kept 30 daysOutbound webhooks
Campaign send paceRoughly four messages a second, regardless of list sizeEmail campaigns
Managed model spendThe monthly ceilings your organization sets, per Account and per person — enforced only where a ceiling has been setAgents Opelli runs
Anti-abuse rate limitsSign-in, connector authorization, public form submissions, dataset ingest tokens, privacy-centre requests and business-registry lookups are rate-limited per IP address and per Account. We do not publish the thresholds — they are a security control, and they are set well above ordinary use.Public and sign-in surfaces

Some of these are protective rather than commercial — they exist so that one request cannot exhaust the memory of a server other Accounts are sharing. We may adjust them for the same reason, and where an adjustment would reduce something you rely on, section 18 of the Terms applies.

Limits we reserve the right to apply

Nothing in this section is metered today. No counter runs against these dimensions and no request is refused because of them. They are the ceilings we consider fair, published in advance so that the boundary is knowable — and so that we are held to a number rather than to a judgement call.

Each is stated per calendar month unless said otherwise, and each scales the way everything else in Opelli scales: a base amount plus an amount per paid seat, so an Account inside its free seats gets the base.

DimensionCeiling we reserveWhy this number
API and MCP requests 10 000 requests per seat per day, and never less than 30 000 per Account per day A person working all day in the application generates a small fraction of this, and an agent doing real work on their behalf still does. It is set to be unreachable by use and reachable by a loop.
Egress — everything served out of Opelli, including the content-delivery traffic of microsites published from your Account 100 GB per Account per month, plus 20 GB per paid seat Twenty times the base storage allowance, every month. A team re-reading its own attachments and running a few modest microsites is nowhere near it; a site whose audience is the point of the Account is.
Outbound webhook deliveries 100 000 deliveries per Account per month Deliveries follow the activity log, so this is many times what a busy Account of any size produces. It bounds a misconfigured endpoint or a subscription loop, not real integration traffic.
Outbound notification and system mail (everything except email campaigns) 1 000 messages per Account per day, and 200 per user per day Several times the busiest plausible day of notifications for a large Account. The per-user figure is the one that matters: it bounds what a single compromised account can send in our name before anyone notices.
Campaign recipients in a single send 50 000 recipients Campaign volume is otherwise a billing matter (section 4). This is a ceiling on one send, so a mistake or a compromised account cannot become a very large one at four messages a second.
Agent runs whose model cost is not billed through us — chiefly runs on your own model subscription 500 runs per seat per month, and never less than 1 500 per Account per month Roughly four times the usage we model for a heavy seat. Managed model spend is already capped in money, so this covers only the path where money is not the meter.
Stored objects — files, images, attachments, microsite files, counted as objects rather than bytes 250 000 objects per Account, plus 25 000 per paid seat Storage is billed by size, and a very large number of very small files costs almost nothing in bytes while costing a great deal to keep. This bounds the shape that billing by size does not see.

If your legitimate use needs more than one of these — a genuinely high-volume integration, a microsite with real traffic behind it, an agent workload that is the point rather than the overhead — that is a conversation, not a violation. Write to [email protected] and we will agree a figure in writing. An agreed figure overrides this section for your Account.

What you must not do

The following are prohibited on every Account, at every volume, and are not a matter of fair use. They restate and expand section 7 of the Terms.

Sending

  • No unsolicited mail. You may only send email campaigns to recipients from whom you hold a lawful basis to send, and you must honour unsubscribe requests. Opelli adds a working one-click unsubscribe to every campaign and applies it across your Account's lists; you must not remove it, defeat it, or re-add a recipient who has used it.
  • No purchased, scraped, harvested or rented lists, and no importing a list you cannot account for.
  • Nothing that damages the reputation of the platform's sending infrastructure, which every Account shares. Sustained hard-bounce or complaint rates are grounds for us to limit sending under section 9.
  • No forged, disguised or misleading sender identity, headers, or reply paths.

Published pages

  • No phishing or impersonation. Published forms, microsites, the privacy centre and any other page served from your Account must not imitate another organization, collect credentials or payment details under false pretences, or present fabricated records as genuine.
  • No malware, no distribution of exploit code, and no use of a published page to redirect visitors into either.
  • No content that is unlawful, that infringes someone's rights, or that you have no right to publish.

The platform

  • No reselling. You may not resell, sublicense, rent or otherwise make the Service available to third parties except as Authorized Users of your own Account, and you may not use it to operate a service for others or to build a competing product.
  • No circumventing the limits. You may not evade, or attempt to evade, seat counting, allowances, permissions, rate limits or any other control described in this Policy or the Terms — including by splitting one organization across Accounts (section 8), by rotating credentials to reset a limit, or by using guest accounts in place of seats for people who are in fact part of your organization.
  • No probing, scanning or penetration-testing of the Service without our prior written agreement; no attempting to reach another Account's data; no reverse-engineering, except where that restriction is void under applicable law.
  • No use that knowingly places an unreasonable load on the Service, whether by a person, a script or a connected agent.

Suspected illegal activity, and anything that puts other Accounts at risk, may be acted on immediately under section 14 of the Terms rather than through the graduated steps below.

One organization, one account

Free seats are given per organization, not per Account. You may not split a single organization across several Accounts in order to keep each of them inside its free seats, and you may not create Accounts on behalf of people who are in substance part of your own organization for the same purpose.

Where several Accounts are plainly one organization — the same people, the same customers, the same body of work, the same billing entity or the same beneficial owner — we may treat them as a single Account for the purpose of counting seats and allowances. We will tell the administrators of the Accounts concerned before we do, and give you the chance to explain or to consolidate them yourself.

This is not aimed at the ordinary cases, and those are worth naming so nobody has to guess. A holding company and a genuinely separate operating subsidiary are two organizations. An agency and its client are two organizations, even when the same person administers both. A single organization running a second Account to keep one client's work walled off is one organization — and that is what projects, permissions and external guests are for, at no extra cost.

How we act

Where use is disproportionate rather than prohibited, we act in order, and you hear from us at each step. Notices go to every active administrator of the Account, by email to the address they sign in with — and, where your organization has connected a chat platform, there as well. These are operational notices about the Account: they are not marketing and cannot be switched off.

  1. We tell you. We describe what we are seeing, which dimension it concerns, and what would resolve it — usually paying for the seats the work is being done by, buying the add-on that covers the volume, agreeing a higher figure with us, or simply changing what is running. You get at least 14 days to respond before anything is limited, unless the use is actively degrading the Service for other Accounts.
  2. We apply a limit. If it continues, we may rate-limit or cap the specific dimension concerned — API and MCP request volume, sending, publishing, webhook delivery — leaving the rest of the Account working normally. A limit is targeted at the behaviour, not at the Account, and it is lifted when the behaviour stops.
  3. We suspend. Only where a limit has not resolved it, or where the use is causing harm we cannot contain, do we suspend the Account under section 14 of the Terms. Suspension retains all Customer Content, intact and unchanged. Nobody can sign in and the Account stops serving; nothing is removed. Suspending and resuming are ordinary operations of the platform, not a restore from backup.
  4. Resolving it reinstates the Account, exactly as you left it — the same data, the same users, the same permissions, the same address. Where the resolution is commercial, paying for what the Account is using reinstates it, on the same footing as section 10 of the Terms.
Data is never a remedy. Nothing in this Policy permits us to delete Customer Content in response to a fair-use problem. Deletion happens only on the separate, announced timetable in section 10 of the Terms — no earlier than 90 days after suspension and only after 30 days' written notice — and you can export your data at any point before it, including while an Account is suspended.

If you think we have this wrong, say so at [email protected]. We would rather be corrected than right.

Changes and contact

We may update this Policy as the platform changes — in particular, to move a limit from section 6 to section 5 once the software actually measures it. Material changes are notified and take effect on the stated effective date, in accordance with section 18 of the Terms. Prior versions are superseded but remain identifiable by their version number and date.

Opelli s.r.o.

Nové sady 988/2, Staré Brno, 602 00 Brno, Czech Republic

Company ID (IČO): 29850762 · DUNS: 351787000 · Regional Court in Brno, Section C, File 153188

Fair use, limits & abuse reports: [email protected]

Privacy: [email protected]

Web: opelli.dev

Opelli Opelli s.r.o. · © 2026 Terms Privacy Home