OpenE2EE Relay
Groups and attachments
Shared encrypted group bodies, bounded fan-out, and private encrypted attachment lifecycle.
Relay treats group bodies and attachments as ciphertext. Devices create the encrypted content and retain the keys needed to open it.
Group fan-out
A group send stores one encrypted shared body in private object storage. Each accepted destination mailbox receives only a bounded encrypted reference and recipient prefix. Fan-out uses asynchronous Queue pages with stable retry identifiers and a dead-letter queue. Queue delivery is at least once. Mailbox acceptance remains delivery authority.
The group body limit is 96 KiB. Each destination prefix is at most 512 bytes. One send supports up to 5,000 destination devices and uses 100-destination fan-out pages. Relay records an accepted delivery unit only for each destination that accepts its reference.
Attachments
An attachment operation is one accepted upload authorization for one stable SDK request identifier. An exact retry does not count again. Attachment operations are a hard plan cap and have no overage.
The upload capability authorizes one exact private object key, expected size, and digest. Its URL is valid for no more than 15 minutes. An incomplete upload expires after 24 hours. Completion succeeds only when exact size and digest metadata match.
A completed attachment has a 30-day maximum retention. The project can select a shorter value. Relay deletes the private object on the owning lifecycle transition. The provider lifecycle rule is only a cleanup backstop and does not extend billable retention.
Storage accounting
Exact live storage includes retained mailbox ciphertext, group ciphertext, and completed attachment bytes. It excludes internal identifiers, indexes, usage rows, and bookkeeping. Paid storage usage integrates exact byte changes over time, including objects that cross a UTC month boundary.