Draft — pending legal review. Not yet binding.
This document was written by the Pronoia engineering team to describe honestly what the product actually does today. It has not been reviewed by a lawyer, and it is not a contract. Items shown in brackets and marked TBD are still unresolved.
Terms of Service
Last updated July 28, 2026
Pronoia pulls your sales data out of the accounts you already have with your trading partners, keeps it in one place, and puts software agents to work on it. To do that, you authorize us to act as your agent and retrieve data using access you control. This page explains what that means, what we will and will not do, and what you are responsible for.
1. Who we are and what this covers
Pronoia is operated by [LEGAL ENTITY NAME — TBD], registered at [COMPANY ADDRESS — TBD] (“Pronoia,” “we,” “us”). These Terms cover pronoid.ai and the Pronoia product.
Pronoia is early software, currently used by a small number of design partners. Features change often. Read section 11 before you rely on it for anything that matters.
By creating an account or using Pronoia, you agree to these Terms and to the Privacy Policy. If you are signing up for a company, you confirm you are allowed to agree on that company's behalf.
2. Your account
You must be 18 or older. You are responsible for keeping your login secure and for what happens under your account. Tell us promptly at [SECURITY CONTACT EMAIL — TBD] if you think someone else has access.
A workspace is the boundary for everything in Pronoia. People you invite into your workspace can see the data in it, according to the roles you give them.
3. You authorize us to retrieve your data — the agency arrangement
This is the most important section on this page. Please read it.
You tell Pronoia which of your accounts to pull data from. You authorize us to retrieve that data on your behalf, acting at your direction, using access that you already hold. We act as your agent. We are not a party to your agreement with the company on the other end — you are.
Before we store any credential for a source, you must accept that authorization in the product. We record the acceptance, the source it covers, the scope you gave, who accepted it, and when. If the authorization has not been accepted, the credential is refused and nothing is stored.
- You represent that the account is yours or your company's, and that you have the right to grant us access to it.
- You represent that letting us retrieve data on your behalf does not breach your agreement with that trading partner or data provider.
- You will tell us if either of those stops being true, and you will remove the connection.
- You can remove a connection at any time. When you do, we delete the stored credential from our vault.
4. Where we get data — and where we refuse to
We only connect to sources we have cleared in advance. Today that list is: UNFI Insights (first-party API), SPINS SDN (first-party API), Target Greenfield (scheduled export from an authorized seat), and SPS/EDI (for the EDI pipe only).
Anything not on the cleared list is refused. The system fails closed: an unrecognized source is treated as forbidden and no credential can be stored for it. Adding a source is a deliberate decision, not something an agent can do on its own.
KeHE is EDI only. Automated login to the KeHE portal is refused outright, by two independent checks in the code. This is a bright line we do not cross.
5. We do not scrape
We do not scrape websites for your data, and we do not build code that defeats a login, a bot check, or multi-factor authentication. Pronoia has no such capability and we are not going to add one.
To be precise about how that is enforced, rather than just asserted: the connection service refuses to store credentials for any source that is not on the cleared list above, and it does not ship browser-automation tooling for those sources at all. It is a refusal at the point where a connection is created, not a filter applied after the fact.
Where a source can only be reached by logging into a portal, that happens under the authorization in section 3 — with your credentials, at your direction, through a normal login you could perform yourself. Never by circumventing one.
6. How your credentials are handled
Credentials you connect are encrypted and stored in a separate vault service. Our software agents do not receive the credential value — they receive a reference to it. When a login is needed, the value is retrieved and entered by the server, and it never passes through the AI model.
Every time a credential is created, changed, delivered, revealed, or deleted, we write an audit record with the action, the actor, the result, and the time.
The Privacy Policy describes the storage and its limits in more detail, including the cases where a credential value does exist outside the vault. Please read that section — we would rather you know.
7. Email you send us
Each workspace gets its own ingestion address so your partners can email reports straight into Pronoia.
Only senders you have approved are imported, and that approved list starts empty — nobody can send data into your workspace until you say so. Messages must also pass standard sender authentication (SPF, DKIM, and DMARC) before we look at them.
Mail from a sender you have not approved is held and never imported. Today there is no in-product queue for reviewing held mail: to bring it in, approve the sender and have them send again. We keep the original message — see the Privacy Policy for what that means.
8. Agents propose, you confirm — and the honest state of that today
Pronoia is built on the rule that software agents propose consequential actions and a human approves them. Actions taken in a browser on a third-party site are classified and routed through a confirmation gate before they run.
Being straight with you about where that stands: whether the gate blocks and waits for you, or simply records what it would have blocked, is a deployment setting. In the current beta it defaults to recording rather than blocking. Do not treat the gate as your only safeguard. Review what agents do, and keep the connected accounts scoped as narrowly as your partner allows.
We will update this section when enforcement is on by default. [CONFIRM-GATE ENFORCEMENT DEFAULT — TBD]
9. Acceptable use
Do not use Pronoia to break the law, to infringe someone's rights, to upload malware, or to attack or disrupt the service.
Specific to what Pronoia does: do not connect an account you do not control or lack permission to use, do not use it to get at data you are not entitled to, and do not use it in a way that breaches your agreement with a trading partner or data provider. If we believe a connection is unauthorized, we may disable it.
10. Your data stays yours
You keep ownership of everything you put into Pronoia — your sales data, files, messages, and knowledge.
You give us permission to store, process, and display that content for the purpose of running Pronoia for you and your workspace. That permission exists so the product can function, and it ends when you delete the content or close your account.
11. Beta software — no warranty
Pronoia is provided “as is,” without warranties of any kind, to the fullest extent the law allows. We do not promise it will be uninterrupted, available, or error-free.
Agents and models get things wrong. Numbers can be stale, incomplete, or misread from a source file. Check the receipts and verify anything before you act on it — especially pricing, ordering, deductions, or anything you send to a trading partner. You are responsible for decisions you make using Pronoia.
12. Limits of liability
To the fullest extent the law allows, we are not liable for indirect, incidental, special, or consequential damages, or for lost profits, revenue, data, or goodwill.
Our total liability for any claim relating to Pronoia is capped at [LIABILITY CAP — TBD]. This figure has not been set; counsel must set it before these Terms are relied on.
13. Ending it, and getting your data out
You can stop using Pronoia at any time. We may suspend or end access if you break these Terms, if a connection appears unauthorized, or if we are required to.
When you leave, we delete the credentials we hold for your connections. Note that where a credential was delivered somewhere outside our systems at your instruction, we remove it on a best-effort basis and cannot guarantee it is gone from a system we do not run.
You can request an export of your workspace data. Today this is handled by contacting us rather than a self-serve download. [DATA EXPORT FORMAT AND TIMELINE — TBD]
14. Changes to these Terms
We may update these Terms. If a change is material, we will post it here with a new date and let account holders know. While this document is marked as a draft, treat any part of it as subject to change.
15. Governing law
[GOVERNING LAW AND VENUE — TBD]. No governing law, jurisdiction, arbitration clause, or class-action waiver has been chosen. This is a decision for counsel and we are not going to invent one here.
16. Contact
Questions about these Terms: [LEGAL CONTACT EMAIL — TBD].
Related: Terms of Service · Privacy Policy