Show the workings

Free should come with a plan.

Official hosting is being built to stay modest, legible, and cheap to operate. This page is where the limits, costs, and funding model will be kept in public.

What does not change

  • The complete self-hosted product stays free and open source under the AGPL.
  • There will be no ads and no selling household data.
  • The official app will not deliberately cripple self-hosting.
  • Export and account deletion remain available; your data is not leverage.

How hosting stays small

The hosted stack is one server in a data centre in the Netherlands running the Go API, the web app, and PostgreSQL, with Cloudflare in front of it and Cloudflare R2 for attachments. The expensive path is bounded at the household level: 1 GB of file storage, atomic quota reservations, and cleanup of abandoned uploads.

Receipt, list, and recipe text recognition runs on the device. No AI service is called, so a scan never creates a model bill.

Other services in the loop: Amazon SES in Frankfurt for transactional email, Firebase for push notifications and app attestation, Cloudflare Turnstile for guest sign-up on the web, and a self-run GlitchTip for crash reports. The privacy policy lists each one with what it receives.

How the money works

Households of up to four members use official hosting for free. Larger households pay for Premium, a flat subscription per household that unlocks nothing else: no feature gates, no ads, no upsells. Web subscriptions run through Polar; in-app subscriptions through the App Store and Google Play. The terms spell out renewal and cancellation.

Premium pays for infrastructure first. As the hosted service settles, this page will publish the monthly compute, storage, email, and monitoring totals rather than inventing numbers in advance.

If Premium cannot cover growth, the first response is tighter fair-use limits, announced here at least 30 days ahead — not feature locks in the open-source app.