Palladin Terms of Service

Polish version: Regulamin — the Polish version is legally binding; this English version is provided for convenience.

§1. General provisions

  1. These Terms govern the provision of Palladin — a zero-knowledge password manager for users and the AI agents acting under their authority.
  2. The Service is provided by Patryk Roguszewski, conducting business as Patryk Roguszewski IT Solutions, entered in the Polish Central Register and Information on Economic Activity (CEIDG), service address: ul. Szkolna 11G/1, 05-091 Ząbki, Poland, Tax ID (NIP) 8241804773, REGON 366380826, e-mail: patryk.roguszewski@palladin.io (the “Provider”).
  3. These Terms are available free of charge at palladin.io before contract conclusion, in a form allowing their retrieval, reproduction and storage (Art. 8 of the Polish Act of 18 July 2002 on Providing Services by Electronic Means).

§2. Definitions

TermMeaning
ServicePalladin: the web panel, the mobile application, and the API/CLI interface for Agents
Usera natural person aged 18 or older using the Service in their own name or as an Authorized User of an Organization
Consumera User who is a consumer within the meaning of Art. 22¹ of the Polish Civil Code, including a sole trader entering a contract not directly related to their professional activity
Vaulta logical container of Entries, encrypted with a Vault Key (VK) on the User’s device
Entrya single record in a Vault (e.g. a credential, API key, TOTP secret, script)
Master Passworda password known solely to the User, from which the master key is derived on the User’s device; never transmitted to the Provider
Recovery Keya 24-word phrase (BIP-39) generated on the User’s device, enabling access recovery; known solely to the User
AI Agent (Agent)software (e.g. a coding agent or automation process) enrolled in the Service and acting under the authority and responsibility of a User or their organization
Accessan authorization given by a User for an Agent to read or use specific Entries, limited by time, number of uses, or indefinite until revoked
Organizationa business or other organizational entity using Team Starter or Enterprise for professional or organizational purposes
Customeran Organization that is a party to a Team Starter or Enterprise agreement
Organization Administratora User authorized by the Customer to purchase a Plan and manage membership, roles, billing and company Vaults
Authorized Usera natural person whom the Customer has permitted to use the Service under its Plan
Plana Service tier defining its intended use, scale limits and administrative features: Free, Developer, Family, Team Starter or Enterprise
Price Listthe current information on Plans, prices, billing periods and limits made available in the Service before an order is placed

§3. Types and scope of services

  1. The Provider supplies the following services by electronic means: a) storage of Entries encrypted on the User’s device (zero-knowledge architecture — §5); b) access to Vaults via the web panel and the mobile application; c) controlled disclosure of Entries to Agents on the basis of Access (§6); d) an audit log documenting operations on Vaults, Entries and Access; e) notifications (in-app, push) about events requiring the User’s decision, in particular Agents’ access requests.
  2. The Service is offered under the Free Plan and the paid Developer, Family, Team Starter and Enterprise Plans. Current prices, billing periods and limits are set out in the Price List made available before purchase. The Family Plan is intended solely for private use by members of one household; professional and organizational use requires the Team Starter or Enterprise Plan.
  3. Fees under Team Starter and Enterprise apply to active human users. AI Agents are not paid seats. “Unlimited AI Agents” means no tariff limit on the number of Agents, subject to technical security limits, rate limiting and fair-use rules.
  4. Access security controls — in particular a stated reason, approval, time or usage limits, revocation and available secure usage methods — are not disabled based on the Plan. Plans may differ in scale, audit retention, sharing and administrative features.
  5. Security and fair-use limits protect the availability and integrity of the Service. They may not be used to arbitrarily restrict proper use of a feature advertised as “unlimited”. In the event of unusual load, the Provider first applies proportionate rate limiting and informs the User, unless immediate action is necessary to stop an attack, leakage, automated abuse or a threat to other users.
  6. Throughout the agreement, the Provider supplies updates, including security updates, necessary to keep the Service in conformity with the agreement and informs Users of their availability and the consequences of failing to install them. Users should install updates within a reasonable time.

§4. Technical requirements

  1. Using the Service requires: a) web panel — a current browser version supporting WebAssembly and Web Crypto (Chrome, Firefox, Safari, Edge) and an Internet connection; b) mobile application — iOS or Android in a vendor-supported version; biometric unlock requires a device with the appropriate hardware module; c) Agent interface — an environment able to run the Palladin CLI/MCP client and store the Agent key.
  2. Accounts are created using an e-mail address and Master Password. The client derives separate authentication and encryption data from the Master Password; neither the Master Password nor encryption keys are transmitted to the Provider.

§5. Zero-knowledge architecture and responsibility for keys

  1. Encryption and decryption of Entry contents happen exclusively on the User’s device. The Provider’s servers receive only encrypted data and keys in wrapped (encrypted) form, protected by keys the Provider does not possess.
  2. The Provider does not know and has no technical ability to reconstruct: the Master Password, the Recovery Key, the User’s private keys, or the contents of Entries.
  3. Loss of both the Master Password and the Recovery Key means permanent, irreversible loss of access to Vault contents. The Provider cannot restore access or recover the data — this is a consequence of the zero-knowledge architecture, not a defect of the Service. The User acknowledges this when creating an account.
  4. The User must protect the Master Password and the Recovery Key from third-party access.
  5. Beyond Entry contents, the Service processes in plaintext the metadata necessary to operate the Service (including Entry names, descriptions, domains and timestamps) — details in the Privacy Policy.

§6. AI Agents and Access

  1. An Agent acts solely under the authority and at the responsibility of the User (or the organization the User belongs to). An Agent’s actions within the Service are attributed to the User who enrolled it or authorized its Access.
  2. An Agent’s access to Entry contents requires the User’s prior authorization. Access may be created after an Agent submits a reasoned request which the User approves, or proactively by the User. It may cover a whole Vault or a single Entry and may be: (a) time-limited, (b) usage-limited, or (c) indefinite — active until manually revoked. Indefinite Access is clearly identified before approval and may be revoked at any time.
  3. Agents enrolled in an organization can see — without approved Access — only the public metadata of Entries (name, description, domain, and fields the User explicitly marked as visible). Entry contents (passwords, keys, secrets) are disclosed solely under Access, one Entry at a time, encrypted for the specific Agent.
  4. The Service offers usage modes limiting secret exposure (executing a command with the secret in an environment variable, injecting into a login form). Choosing the get mode (returning the secret into the Agent’s context) and its consequences — including transmission of the secret to an external LLM provider — are the User’s responsibility.
  5. Every use of Access is recorded in the audit log together with the reason stated by the Agent.
  6. The User must revoke Access and deactivate any Agent over which they have lost control.

§7. Acceptable use

  1. Supplying unlawful content through the Service is prohibited.
  2. In particular, the following are prohibited: storing unlawfully obtained data in the Service; attempting to access accounts, Vaults or third-party systems without authorization; reverse engineering, vulnerability probing or disrupting the Service without the Provider’s consent (except reports under the published responsible-disclosure policy); reselling the Service; using the Service to distribute spam or malware.
  3. The Provider may suspend or restrict account access in the event of gross violation of these Terms, after a prior demand to cease the violation, unless the nature of the violation requires immediate action.
  4. Notices concerning unlawful content or conduct may be sent to patryk.roguszewski@palladin.io. A notice should identify the location or identifier of the information, explain why it is unlawful, provide the notifier’s contact details and include a good-faith statement. Where contact details are available, the Provider acknowledges receipt and communicates its decision.
  5. When restricting an account or removing data for a violation, the Provider gives the affected User a statement of reasons on a durable medium, including the factual and legal basis and the available appeal route. A statement is withheld only where the Provider does not know the User’s electronic contact details, the exception for deceptive high-volume commercial content under Article 17(4) DSA applies, or disclosure is prohibited by binding law or an order of a competent authority; in the latter case the Provider provides information to the extent legally permitted.
  6. A decision under paragraph 5 may be appealed within six months using the address in paragraph 4. Where organizationally possible, the appeal is reviewed by a person who did not make the original decision.
  7. Where the Provider becomes aware of credible information giving rise to a suspicion of a criminal offence involving a threat to a person’s life or safety, it follows a procedure for notifying the competent authorities under Article 18 of Regulation (EU) 2022/2065 (DSA). The zero-knowledge architecture prevents the Provider from independently reading Entry contents.
  8. Security vulnerability reports are accepted at patryk.roguszewski@palladin.io. Good-faith activity limited to the minimum necessary test on the researcher’s own account, without access to another person’s data, will not be treated as a violation of the vulnerability-testing restriction. Social engineering, availability disruption, data destruction and disclosure before a reasonable remediation period are prohibited.
  9. The DSA point of contact for recipients of the Service and the single electronic point of contact for Member State authorities, the European Commission and the European Board for Digital Services is patryk.roguszewski@palladin.io; recipients may also use +48 517 777 441. Communication does not rely solely on automated tools. The Provider accepts authority communications in Polish and English.
  10. Due to the zero-knowledge architecture, the Provider does not conduct general monitoring or automated analysis of plaintext Entry contents. Illegal-information notices and final decisions affecting the availability of an account or data are assessed by a human on the basis of the notice, available metadata and applicable law. Automated security measures may detect technical abuse and temporarily restrict traffic or access to stop an immediate threat, but they do not independently make a final decision to permanently remove data or terminate an agreement.

§8. Contract formation, subscriptions and termination

  1. The Service agreement is concluded upon account creation and acceptance of these Terms. A paid Plan is purchased by placing an order with an obligation to pay through the sales channel indicated in the Service.
  2. Prices and currency may differ by country, billing period and purchase channel. Before placing an order, a Consumer receives the total price including taxes. A business price may be stated net only where it is clearly marked that applicable tax will be added.
  3. A paid Plan is a monthly or annual subscription, paid in advance and automatically renewed for the same period until cancelled by the User. Web purchases are processed by the Paddle entity identified at checkout — Paddle.com Market Limited for most buyers outside North America, Paddle.com Inc. for US buyers, or Paddle.com (Canada) Ltd. for Canadian buyers — as Merchant of Record and reseller of the Plan. Paddle is the seller in the payment transaction, collects payment and issues the sales document under the terms shown at checkout. Mobile purchases are processed by the Apple App Store or Google Play under the applicable store terms. The Service agreement and responsibility for operation of the Service remain with the Provider.
  4. The User may cancel automatic renewal at any time through the channel where the subscription was purchased. Cancellation takes effect at the end of the paid period; access to the paid Plan continues until that date, after which the account moves to the scope of the then-current Free Plan unless the User deletes the account.
  5. Developer, Family and Team Starter include one 14-day trial per User or organization. Starting the trial requires a payment method. The first charge date and post-trial price are shown before the order is placed. Unless the User cancels before the trial ends, the fee for the selected monthly or annual billing period is charged.
  6. A Consumer may withdraw from a distance contract within 14 days without stating a reason. Notice is submitted through the purchase channel: Paddle’s procedure for a web purchase, the Apple App Store for an iOS purchase, or Google Play for an Android purchase. The applicable operator acknowledges receipt and handles settlement in accordance with law and its channel rules. Where, at the Consumer’s express request, performance of the paid Service began before that period ended, settlement takes place only to the extent permitted by mandatory law. This provision does not limit statutory remedies concerning conformity of a digital service with the contract.
  7. The User may terminate the agreement at any time by deleting their account in the Service or by request sent to patryk.roguszewski@palladin.io; account deletion includes deletion of Vaults and account data as described in the Privacy Policy.
  8. The Provider may terminate the agreement for important reasons (discontinuation of the Service, gross violation of these Terms) with at least 30 days’ notice, allowing the User to export their data (§11).
  9. Team Starter is offered only to Customers for professional or organizational purposes. By ordering the Plan, the Organization Administrator represents that they are authorized to act for the Customer. The Customer is responsible for its Authorized Users, role assignment and the lawfulness of processing in its Vaults. The standard Data Processing Agreement forms part of the Team Starter agreement. Enterprise is supplied under an individually negotiated agreement, which prevails in the event of conflict with these Terms.
  10. Following a downgrade, resources above the new limit are not automatically deleted. The account enters a restricted-growth mode: existing data may be read and exported and Access may be revoked, but no new resources may be created above the limit. Security controls remain active. Detailed limits and the calculation of active Team seats are set out in the Price List.
  11. Refunds and payment corrections are handled through the purchase channel. This does not limit a Consumer’s statutory withdrawal or conformity rights. Where the Provider terminates a paid agreement without a breach by the User, it provides a proportionate refund for the unused period, directly or through the sales operator.

§9. Liability

  1. The Provider renders the Service with the due diligence required of a professional in the field of information security.
  2. The User or Customer retains all rights in data submitted to the Service. It grants the Provider only a limited, non-exclusive authorization to store, transmit and technically process that data as necessary to provide the Service; the authorization ends when the data is deleted, subject to backup retention and legal obligations.
  3. The Provider is not liable for: the consequences of losing the Master Password and Recovery Key (§5(3)); the consequences of the User sharing login data, devices or keys with third parties; acts and omissions of Agents and of the systems in which the User runs them (§6(1)); Service unavailability caused by force majeure or infrastructure provider failures which the Provider could not prevent despite due care.
  4. Towards Users who are not Consumers, the Provider’s liability is limited to actual damage and capped at the fees paid by the User in the 12 months preceding the damaging event; liability for lost profits is excluded.
  5. The limitations in paragraphs 3–4 do not apply to intentional misconduct or gross negligence, breaches of confidentiality or data protection, or liability that cannot be excluded or limited towards Consumers under applicable law.

§10. Complaints

  1. Complaints may be submitted to patryk.roguszewski@palladin.io or by telephone at +48 517 777 441, with a description of the issue and data identifying the account. For security reasons, instructions affecting an account, data or Access require authentication and are not carried out solely on the basis of a telephone call.
  2. The Provider handles complaints within 14 days of receipt and replies to the e-mail address the complaint was sent from (or one indicated in the complaint).
  3. Consumers may use out-of-court complaint and redress mechanisms, including consumer ombudsmen and the Trade Inspection.

§11. Switching and data export (Data Act)

  1. The User may export data at any time in the JSON and CSV formats described in the public specification. Plaintext Entry contents are exported only after local decryption on an unlocked device; the Provider does not receive them in plaintext.
  2. Irrespective of the Service’s ultimate classification under Regulation (EU) 2023/2854 (the Data Act), the Provider voluntarily adopts this standard. The User or Customer may request switching to another provider, porting data and digital assets to its own infrastructure, or erasure without migration. The maximum notice period preceding the process is two months and the standard transitional period does not exceed 30 calendar days.
  3. During the transitional period the Provider supplies reasonable assistance, continuity of core functions, information about known continuity risks and data security. If 30 days is technically unfeasible, within 14 working days of the request the Provider gives reasons and identifies an alternative period not exceeding seven months. Independently, the Customer may extend the transitional period once for a period it considers appropriate for its own purposes.
  4. The agreement terminates and the Provider sends confirmation upon successful switching or, for erasure without migration, at the end of the notice period. Data remain available for retrieval for at least 30 days after the agreed transitional period. After the retrieval period or a later agreed date the Provider erases exportable data and digital assets except where retention is required by law; backups are erased within the period stated in the Privacy Policy and are not actively used in the meantime.
  5. The Provider charges no switching fees. The exhaustive exported and excluded categories, procedures, formats, schemas, technical limitations, integrity safeguards, infrastructure jurisdiction and measures against unlawful third-country governmental access are described at https://palladin.io/export-and-switching.

§12. Personal data protection

The processing of personal data — categories, purposes, legal bases, recipients and data-subject rights — is described in the Privacy Policy; the use of cookies and similar technologies in the Cookie Policy.

§13. Amendments to the Terms

  1. The Provider may amend these Terms for important reasons: changes in law, changes to the scope or manner of providing the Service, security reasons, changes in technology or providers necessary to supply the Service, or changes to Plans or prices.
  2. Users are notified of material amendments at least 14 days before they take effect, by e-mail or another durable medium. Where a modification of a digital service materially and negatively affects a Consumer’s access to or use of the Service, notice is given reasonably in advance and contains the information and remedies required by the Polish Consumer Rights Act.
  3. A modification necessary to keep the digital service in conformity with the agreement is supplied without additional cost. Where another modification materially and negatively affects a Consumer’s access to or use of the Service, the Consumer may terminate without notice or cost within 30 days of receiving the information or the modification taking place, whichever is later, unless the negative impact is minor or the Provider allows the unchanged Service to be retained without additional cost.
  4. A price change does not affect a period already paid for. A new price for a Consumer’s renewable subscription requires the Consumer’s active and unambiguous acceptance before the next charge. If the Consumer does not accept, the subscription does not renew after the paid period and the account moves to Free. For B2B Customers, the new price may apply from the next renewal following notice unless an individual agreement states otherwise.
  5. The amendment history is public and available in the legal changelog.

§14. Final provisions

  1. These Terms are governed by Polish law. The choice of law does not deprive a Consumer of the protection afforded by the law of their habitual residence.
  2. Disputes with Users who are not Consumers are resolved by the court competent for the Provider’s registered office.
  3. The binding version of these Terms is the Polish version (Regulamin); this English version is for convenience only.
  4. These Terms enter into force on the date stated when they are published in the Service.