Privacy policy
Last updated: 17 August 2026
Prialo creates an encrypted private network between the devices the user authorises. This policy explains what information the service processes to provide that function.
Information we process
- Account identifiers provided by Apple or Google to authenticate the user, such as the provider identifier, the verified email address and the name when available.
- If you join the early access list, the email address, the chosen language and the dates the consent was given and updated. We do not store the IP address, the user agent or advertising identifiers for this list.
- Preferences the user chooses to synchronise, such as language, device name, default SSH user and automatic connection.
- Technical data about enrolled devices: name, operating system, public key, assigned private address, connection addresses and last activity.
- Diagnostic and security data needed to operate, protect and troubleshoot the service.
Purpose and basis of processing
We use this data to authenticate users, coordinate the devices in a network, establish direct or relayed connections, enforce access policies, show device status and keep the service secure. The processing is necessary to provide the requested service and to protect it against abuse.
The email address and language on the early access list are processed with your consent to notify you when public access becomes available and of updates directly related to the launch. Joining does not create an account or grant automatic access.
Traffic content
Traffic between devices travels end-to-end encrypted using WireGuard. Prialo does not use the content of that traffic for advertising, tracking or profiling. When a relay is needed, it forwards encrypted packets and does not hold the devices' private keys.
Sharing and sale of data
We do not sell personal data or use it for third-party advertising. It is only disclosed to providers necessary to host and operate the service, bound by confidentiality obligations, or when required by law.
Retention and security
We keep the information while the account or the devices remain active and for as long as reasonably necessary for security, incident resolution and legal compliance. Early access data is kept until you withdraw your consent or it is no longer necessary to inform you about the opening; it is then deleted or anonymised. Account sessions expire and their credentials are stored in protected form. We apply access controls, encryption in transit and technical measures intended to limit access to the information.
Rights
The user may request access, rectification, erasure, restriction or objection regarding their data, and may withdraw consent where applicable. They can delete their account and preferences directly from the app's settings; they can also remove devices using the service's tools. To leave the early access list before an automatic unsubscribe link exists, simply write to the contact below from the email address you want removed.
Contact
For privacy enquiries or to exercise your rights, write to [email protected].
Changes
We may update this policy to reflect technical or legal changes. We will publish the current version at this same address.