TL;DR
Retool is a builder for internal tools: you drag components onto a canvas, connect them to your databases and APIs and write custom code wherever you need it and since 2026 you can also generate apps from a prompt or ship full React apps. What Retool doesn't give you is the backend underneath, the data model, the API, the permissions on your data and the business logic still live in systems you build and run yourself. pylo is a backend platform where data model, typed API, permissions, flows, admin UI, forms, events and AI access through pylo MCP are one system. If you already have a solid backend and need custom UIs on top, Retool is a good choice. If you would otherwise build a database, an API and a permission layer first, just to put Retool on top, pylo gives you all of it from day one.
What is pylo?
pylo is a Backend-as-a-Service platform from Germany, which you can use to build the operating system for your company. You model entities, fields and relations in the admin panel or through the API and pylo generates a typed GraphQL API with great developer experience automatically. The same permission model governs data, the admin UI, forms, flows and the MCP server. So with pylo you build apps, automations and products on one coherent base across your whole team.
What is Retool?
Retool is a US company from San Francisco whose product is a platform for building internal software. Its core is a drag-and-drop app builder with a large component library that connects to almost any database or API, with custom code in queries and transformers. Around that, Retool offers Workflows for scheduled and event-driven jobs, Retool Database as managed Postgres, Agents for AI work with tools and approvals, native mobile apps and an AI app builder that generates apps from a prompt or deploys React apps on Retool's runtime. With more than 10,000 companies use Retool, the ecosystem is very solid.
At a glance
Retool | pylo | |
|---|---|---|
What you get | An UI builder for internal tools on top of your databases and APIs, plus Workflows, Agents and Retool Database | A finished backend with everything to build tools and automations on top: data model, API, permissions, flows, admin UI, forms, analytics |
Data model | Lives in your own databases, or in Retool Database: managed Postgres with 5 GB | Entities, fields and relations across your whole workspace, visual or through the API |
API to your data | No generated API for Retool Database, external access through a Postgres connection string | Typed GraphQL, schema generated per user, unlimited API requests |
Permissions | Access per app, folder and resource on Business and Enterprise, row-level filtering written into your queries, no field-level permissions | Tenant isolation plus configurable ARO/ACO with hierarchy and field-level access, on every plan |
Auth for your own app | Retool users, external users on Business and Enterprise | Email/password, Microsoft and Google SSO, API keys |
Business logic | Workflows with JavaScript and Python blocks, 500 to 5,000 runs per month included | Visual flow engine with cron, webhook and event triggers, pre-defined integrations plus TypeScript custom actions |
UI for non-devs | Apps that developers build with drag and drop, custom code or a prompt | Configurable list/detail views with state-based field visibility and different components for different datatypes |
Forms | Built from components inside an app | Built in, powerful editor, public or authenticated, directly mapped to entities |
Analytics | Charts inside your apps, audit logs on Business and Enterprise | Every change emitted as an event with before/after values, you can bring your own events and build dashboards on everything with deeply integrated permissions |
AI access | Agents with optional approval per tool call, MCP server for building apps and managing the organization | MCP with the user's permissions; writes become proposals you approve |
Pricing model | Per builder and per user per month | Per usage (flows, records, storage), unlimited users |
Hosting | AWS in the US, self-hosting on Enterprise only | Hetzner, Germany |
A backend with an admin UI instead of a UI without a backend
Retool is built to sit on top of data that already lives somewhere else, a Postgres database, a REST API, Salesforce or Stripe. That's its biggest strength when the backend exists, but if it doesn't, someone has to design the schema, write the migrations, build and host the API and keep all of it running before the first Retool app makes sense. Retool Database helps for small cases, it's managed Postgres with 5 GB of data, but Retool itself says it is not designed to be a highly available, scalable database service and there is no generated API for it, other software connects through a Postgres connection string.
In pylo you add an entity, a field or a relation in the admin panel and the typed GraphQL API updates at once, without any migrations or redeployments. Possible field types include relations, enums, JSON, public or private files, rich text, dates, booleans and number/text formatters, with validation built in. Relations work across your whole workspace, you filter across them and group aggregations by any field and API requests are unlimited on every plan. The admin UI, forms and flows work on that same model from the start, so there is nothing to wire up between a database and a UI layer. The database and the whole backend are made to scale and handle millions of records with ease.
Permissions that follow the data everywhere
Retool controls who can open which app, folder, resource or workflow, with custom permission groups on Business and Enterprise; Free and Team only have the default groups. What a user may see inside the data is up to you: you filter rows in each query with the current user's details and access policies on the resource exist only for Postgres on Enterprise. There are no field-level permissions, and every new query is one more place where a filter can be missing. Good enough when a handful of admins use a tool, risky as soon as many roles work on the same data or if you wanna share an app with a big organization.
pylo separates tenants at the row level, inside a single tenant, any entity can act as the requester (ARO) and any entity as the requested object (ACO), with hierarchies and field-level rules. The permissions live in the data layer, not in the queries, and every path into the data is GraphQL, so the same rules apply to every part of pylo: the API, the admin panel, forms, flows and MCP. pylo also handles login for the people who use your apps, with email/password, SSO through Google and Microsoft accounts and API keys.
pylo flows instead of Retool Workflows
Retool Workflows run on a schedule or through webhooks and chain queries with custom code JavaScript and Python blocks, with access to all your Retool resources. They are flexible and developer-friendly.
In pylo you build automations in a visual workflow engine called pylo flows, where any event in pylo can start a flow, in addition you can use cron triggers or webhooks. Because the flows run on your own data model, a new or changed record starts a flow the moment it happens, without polling a database. pylo flows include retries, custom rate limiting, error handling and full event logs and everything is statically typed, so each node knows exactly what input and output it needs. pylo ships integrations for email sending and a range of third-party systems, for anything else you want to extend your flows with, write a custom flow action in TypeScript.
Admin views and forms built on the same permissions
Retool's app builder is one of the most flexible ways to build internal UIs and we won't pretend otherwise. You get a large component library, apps generated from a prompt and, since 2026, full React apps on Retool's runtime. The flip side: every screen is something a developer builds and maintains, and when the data model changes, the apps change with it.
pylo's admin UI has a different focus; it is there from the moment you create an entity. You compose list and detail views from predefined components, decide who sees what and show or hide fields depending on a record's state. The views use the same permission model as the API, so nobody sees data through a view that they couldn't read anyway. With pylo forms, you can create forms that are public or authenticated, with hidden fields, conditional rendering, direct mapping to your entities, including relations, and submission limits per form or per user.
Events and dashboards built in with pylo analytics
In Retool you build charts into your apps from whatever your queries return, and Business and Enterprise add audit logs of what users did in Retool. Tracking how your business data changed over time means building audit tables and triggers in your own database or moving the data into an analytics tool.
Every create, update and delete in pylo emits an event with the full before and after state, which you can combine with external events you bring in through the API, stored for unlimited time on every plan. You can then build visualizations and custom dashboards on top of both, internal and external data and events.
AI and MCP with guardrails
Retool takes AI seriously: Agents can use your resources, workflows and external MCP servers as tools, you can require human approval for each tool call and you get evals, run replays and cost metrics. Retool's own MCP server is made for developers: it builds and inspects apps and manages users and the organization, it is not a way to work with your business data.
pylo's MCP server is made for both, developers who use agentic coding and team members who wanna analyze their data. You connect it as a specific user and the AI gets exactly that user's read permissions, nothing else. pylo never applies an AI's writes directly, they always arrive as proposals that a human accepts or declines, no matter which AI client or agent sends them. That makes it safe to let an assistant work on production business data without giving up writes altogether.
File handling
Retool shows and uploads files through components, where the files are stored depends on the resource you connect, like S3 or your own database. Retool Storage exists as an alternative for smaller cases.
pylo stores files in EU-hosted object storage with public or private links, no file size limit and any file type, as fields on your entities with the same permissions as the rest of the record.
Agencies and multi-tenant work
With pylo, agencies can run many client workspaces from one user account, where each workspace is its own tenant and permissions and one login switches between them. The database separates tenants with row-level security.
In Retool every builder and every internal user is a paid seat, and external users for client portals need the Business plan. Separating clients inside one Retool organization means separate resources, permission groups and query filters per client, which you build and maintain yourself.
Pricing
Retool | pylo | |
|---|---|---|
Free | $0, up to 5 users, 500 workflow runs per month, Retool Database, production environment only | 0€, 5,000 records, 500 flow actions, 1 GB files, unlimited users and API requests |
Entry paid | Team $10 per builder and $5 per internal user/month billed annually, 5,000 workflow runs, staging and production | Starter 49€ per workspace/month, 100k records, 5k flow actions |
Larger | Business $50 per builder and $15 per internal user/month billed annually, custom permission groups, audit logs, external apps; Enterprise for SSO, source control and self-hosting | Business 999€/month, 2M records, 250k flow actions |
Users | Every builder and internal user is a paid seat, external users from the 51st on from $8 down to $4 per user/month | Unlimited on every plan |
Metered | Seats, workflow runs above the included amount at $75 per 5,000, Agents by the hour | Only flow actions, records, and file storage/traffic are billed |
Retool charges per builder and per user, so a team with 3 builders and 20 internal users pays $130 a month on Team and $450 on Business, billed annually. That price covers the UI layer; the database, API and hosting underneath are on top of it, plus the time your developers spend building and running them.
pylo has a different approach with usage-based pricing, so every plan includes unlimited users and API calls, which means the price stays the same when your team grows or when you give a client's staff access. Its price already includes the backend, pylo flows, the full admin UI, forms, analytics and personal onboarding, every pylo plan has every feature, the plans differ only in included usage for flow runs, stored records and used file storage size. You per for overages on records, pylo flow runs and stored files.
Hosting, compliance and reliability
All pylo content data, data models and databases live in data centres in Germany, our subprocessor list is public and names every non-EU parent company openly. A GDPR data processing agreement is part of the terms and we never use customer data to train AI models. Paid plans come with a 99.5% availability SLA, hourly encrypted backups kept for 30 days at a separate German location and support from the team that builds the product.
Retool Cloud runs on AWS with its primary region in the US. Frankfurt is available as an outbound region, which only changes the IP address your queries come from; Retool's docs say queries still run through the primary region in the US, even if your database sits in Europe. Retool documents no EU option for Retool Database. If your data must stay in Europe, the way to get there is self-hosting, which requires the Enterprise plan. Retool holds SOC 2 Type 2 and ISO 27001 and offers a DPA.
Where Retool is the better choice
We would rather tell you than have you find out later:
More flexible UIs: a large component library, apps generated from a prompt and full React apps. pylo's admin UI is configured from predefined components.
It connects to almost any database or API you already run, without moving your data.
Native mobile apps on every plan.
Self-hosted, VPC and air-gapped deployments on Enterprise, while pylo can't be self-hosted.
Retool has a larger eco-system and it holds SOC 2 Type 2 and ISO 27001, and it has open signup
If you already have a solid backend and want maximum freedom for internal UIs on top, Retool is excellent. pylo is for teams that need the backend itself and want the back office to come with it.
Where pylo is a great Retool alternative
We think these are the main reasons to pick pylo over Retool:
The backend comes with the admin UI. Data model, typed GraphQL API, permissions, flows, admin views, forms, events and MCP are one product. You don't build and host a database and an API first, just to put a UI layer on top.
Schema changes without a deploy. Add an entity or field and the API and admin views are live immediately. There is no migration to write and no app to rebuild for it.
Permissions in the data layer, down to the field. API, admin panel, forms, flows and MCP all go through the same permission layer, with hierarchies and field-level rules, on every plan. You don't repeat filters in every query and hope none is missing.
Login for your own users. Build portals and apps on your data with pylo's auth, without paying per external user.
Flows on your own data. Events on your records start flows the moment they happen, with retries, rate limiting, typed actions and full logs. Custom actions are plain TypeScript.
Non-developers can work without you. Admin views, state-dependent fields and a full form builder are configured, not coded, so operations teams can handle their own changes.
Analytics you don't have to instrument. pylo records every change as an event with before and after state and custom dashboards sit right next to the data.
AI access that's safe for production. MCP runs with the connected user's exact read permissions, and every write goes through human approval as a proposal, whatever client or agent sends it.
No per-seat pricing. Unlimited users and API requests and all features on every plan, only three meters are billed: flow actions, records, and file storage/traffic.
Built for agencies. You can run many client workspaces with separate tenants and permissions, switch between them with one login and give client teams access without paying per seat.
German hosting from a German company. pylo hosts user data in Germany on every plan and the DPA is part of the terms. You get a 99.5% SLA from the first paid plan, hourly backups with 30-day retention and personal support from the people who build the product.
FAQs - Questions and answers about pylo
Is pylo's admin UI as flexible as Retool? No, pylo's views are configured from predefined components, which covers most back office work without code. For fully custom frontends you use the Next.js SDK or the typed GraphQL API and build any kind of functionality you want.
Can I use Retool on top of pylo? Yes, Retool connects to GraphQL APIs, so you can build custom Retool apps on pylo's typed API with an API key whose permissions you define in pylo, while flows, events and the admin UI keep running in pylo.
Is pylo open source? No, but you can export all data at any time as CSV or JSON or through the API. The data models, flow definitions and generated SDK code are yours to keep, even after you leave.
Can I self-host pylo? No, but if you need specific hosting options, we can discuss them as part of the Enterprise plan.
Where exactly is my data? Content data is in data centres in Germany and backups are kept at a different German location.
Can I get access now? pylo is currently in private beta, you can just request access and we will set up your first entities with you on a call and onboard you personally for your first project.
The short answer
Pick the one that fits the team you have.
Pick Retool if…
Choose Retool if you already run a solid backend and want maximum freedom for internal UIs on top of it: a large component library, custom code, AI-generated and React apps, native mobile apps and connections to almost any database or API, and you are fine with per-user pricing and US hosting unless you self-host on Enterprise.
Pick pylo if…
Choose pylo if you need the backend itself and want the back office to come with it: a live data model with a typed API, permissions in the data layer down to the field, flows, admin views and forms your non-developers can use, login for your own users, built-in event analytics and AI access with approval. It is also the better fit if you want unlimited users and hosting in Germany on every plan.
Moving over
Bring your schema, keep your data.
Retool apps sit on top of your data sources, so moving to pylo is mostly about the data. Model your tables as entities in pylo first: tables become entities, columns become fields and foreign keys become relations. Data in Retool Database is standard Postgres, so you can export it with pg_dump or as CSV, the same goes for your own databases. Then load it with pylo's import profiles. Profiles let you map columns to fields, use any field as the matching key and apply regex transformations during import, the import handles Gigabytes of data and you can re-run an import until the mapping is right.
Most back office apps become pylo admin views and forms, permission groups and query filters become pylo permissions, and Retool Workflows become pylo flows with custom code blocks rewritten as TypeScript custom flow actions. Screens that need a fully custom UI can keep running in Retool against pylo's GraphQL API. Talk to us before you start and we will go through your apps and data sources with you and help you make the migration from Retool to pylo as smooth as possible.
Keep comparing
See all comparisons