OpenE2EE Relay
Limits, billing, and operations
Exact plan meters, retention, overages, drain behavior, deletion, and operating boundaries.
Every production plan contains the same protocol features. Plans differ by capacity, support, service terms, and approved operational controls.
Each project also gets a hosted development environment. It includes 25 test accounts, 25,000 delivery units, 25,000 attachment operations, and 250 MB of exact live encrypted storage each month. It is an environment, not a production plan or paid tier.
| Tier | Monthly price | Relay MAU | Delivery units | Attachment operations | Exact live encrypted storage |
|---|---|---|---|---|---|
| Free production | $0 | 100 | 100,000 | 100,000 | 1 GB |
| Starter | $99 | 1,000 | 500,000 | 500,000 | 10 GB |
| Growth | $299 | 5,000 | 2,500,000 | 2,500,000 | 50 GB |
| Business | $899 | 25,000 | 12,500,000 | 12,500,000 | 250 GB |
| Enterprise | Custom | Negotiated | Negotiated | Negotiated | Negotiated |
One Relay MAU is one canonical account with qualifying authenticated production activity during one UTC calendar month. Multiple devices for one account count once.
Paid plans can enable explicit overage with a spend limit. Delivery overage is $55 per million units. Exact live storage overage is $0.50 per GB-month. Excess Relay MAU costs $0.05 on Starter, $0.03 on Growth, and $0.02 on Business. Attachment operations remain a hard cap.
Retention
Production ciphertext retention is configurable up to 30 days. The development environment defaults to 24 hours and allows no more than seven days. Reducing retention does not delete ciphertext that a destination device already pulled and decrypted.
Plan and billing authority
Relay owns exact usage, quotas, included allowances, overage reservations, spend limits, and drain decisions. Console owns Stripe and maps one opaque billing-project handle to provider objects. Stripe is not on the Relay delivery path and never authorizes a message.
At a hard cap or spend limit, Relay refuses new billable work. It preserves receive, pull, acknowledgment, deletion, revocation, usage export, and billing access. A failed payment uses the same safe drain shape after its approved grace policy.
Operating evidence
Authoritative usage lives in concept-owned Durable Objects. A bounded period-close workflow exports only closed aggregate values. Analytics and operational logs can report latency, errors, queue lag, capacity, and cost signals. They cannot authorize work or produce invoice values.
The public pricing page is the display summary. The product contract and the Relay service terms control the exact operational and legal boundary.