Part two: CloudPlanned · not on sale
Cloud, planned: an address and backup space, never your twin.
Status: planned. The design is accepted. Nothing is for sale, and there is no waiting list.
- Design accepted. Published in full on GitHub.
- The free route is built. Secure access from anywhere and encrypted backup, for everyone, in the first release. The Home Screen web app, lock-screen approvals and passkeys are in it too, and still being tested on real phones.
- Cloud's code is written, and open. Nothing runs yet, and nothing can be bought.
- Opening. Targeted for early 2027, announced in the changelog at least 14 days before.
Mirrin Cloud will rent you an address and some backup space. It will never hold your twin: its brain, memory, passwords and signed-in browser stay whole on your machine. It will rent only what genuinely needs a server:
- Reach. An address that finds your machine from any network, with the encryption ending on your machine rather than ours.
- Off-site backup. Space for copies that are locked before they leave, with a key made from 12 words we never see.
- Later: training a custom wake word for your twin, once we have training data licensed for it.
Free, and Cloud (planned)
- Available now
Free: the whole twin. Everything it does, on your machine, open source, for good. $0 and no account.
- Planned · not on sale
Mirrin Cloud: availability. It would add an address that reaches your machine from any network, and off-site space for encrypted backups. Planned at $6 a month.
- Pricing, and what we'd see
What we promise before we charge anything
- Free comes first. Every paid convenience has a free, documented route, and the free route ships first.
- Nothing moves behind the paywall. Nothing the open-source version does today will ever need a subscription.
- No account, ever, to use Mirrin. Cloud won't have a sign-up, login, password or email account with us either: you'd be an account number, tied to a key your computer makes for itself.
- We don't host twins. Not yours, not anyone's.
- The twin never pitches Cloud. No persona will mention it. Cloud will appear only where you ask for the capability, such as choosing how your twin is reached or where backups go, and it will be listed last. If a subscription lapses you'd get one calm line, never a push notification.
- No trial, no countdowns. A 30-day refund instead.
- The code stays open. The twin and everything Cloud would run are open source, with the licences explained in plain words.
Free first: already built
Every paid convenience has a free route, and the free route came first. All of these are part of the free, open-source version, in the first release. The parts that run on a phone are still being tested on real phones, and say so.
- Being tested A web app you add to your Home Screen (no app store). Scan one QR code on your computer and watch each step light up as your phone joins. Every device gets its own key, and you can revoke any of them. Each new device is announced on your channels, with a way to revoke it if it wasn't you.
- Being tested Lock-screen approvals. Your machine sends the notification itself, encrypted, straight to Apple's, Google's, Mozilla's or Microsoft's push service. No server of ours in between. Tap it to see the picture and decide.
- Being tested A passkey for the dangerous ones: Face ID, a fingerprint or your device PIN. Approving a payment, a command or a call from the phone needs it, and the web app refuses dangerous approvals until you've set one up. Replying
yes 12in your own chat keeps working as it does today. - Available now Reach from anywhere, your way. Secure access through Tailscale, your own certificate, or your own relay on your own domain. The relay is open source.
- Available now Encrypted backup. To a folder, iCloud Drive or any S3-compatible bucket, locked with 12 words only you hold.
- Text your twin on eleven messaging channels from anywhere, and approve with a picture of the page on seven of them.
- Open the presence screen and chat from your other devices over Tailscale's private network, with a key.
- A copy of your memory file every day, on your own disk, with the last seven kept. It isn't encrypted and doesn't leave your machine.
Planned pricing
Cloud would be $6 a month or $60 a year, and the first 500 subscribers would pay $48 a year for as long as they stay. Supporter would be $20 a month: everything in Cloud, plus next-business-day support, for people who want to fund the free version. Free stays the whole twin.
Fair use would be about 100 GB relayed a month, and up to 20 Mbit/s for your address, shared by all its connections. No trial, a 30-day refund, and no lifetime deals.
This is planned pricing. It may change before Cloud opens, and we'll post a notice in the changelog at least 14 days before it does. There is nothing to buy today.
The tiers side by side, with Free as the longest column, the licences in plain words, and what we would and couldn't see with a command to check each line, are on the pricing page.
How reach will work, in plain English
Your computer will connect out to two relays we'd run, with two different hosting providers. When your phone opens your address, a relay will read only the name on the envelope and pass the still-sealed connection through to your computer. The encryption will end on your computer, with a certificate only your computer holds. The relays will never hold a key that could open it.
The relay is the same program you can run yourself, free, today: mirrin reach use relay points your twin at it, with no MavrkAI server involved.
Your address will be set up so that only your own computer can get a security certificate for it, so someone who broke into a relay still couldn't impersonate it. Your twin will check the public certificate logs every six hours for anything issued in your address's name.
If an unknown certificate ever appears, your twin will pause remote approvals, replace the keys of any device that connected since, and warn you on your phone, on the presence screen and in your own chat.
One limit, stated plainly: on our shared domain, a certificate wrongly issued through us or our DNS provider would be detected, not prevented. Use your own domain and it is prevented. That is free with your own relay today, and would come to our relays in a later version.
What we would see, and what we couldn't
We would see
- Your account number, plan and billing status, and the payment provider's customer number
- Your address
- Your machine's public keys
- When your machine connects, and your home IP
- For each connection: the rough network it came from, bytes and duration
- How many backups you keep, with their sizes and times
- When your machine last checked in, and refreshed its pass
We couldn't see
- Anything inside the connection: messages, screens, approvals, cookies, memory, voice
- What's in your backups, or even their file names
- Your 12 words
- Your passwords, API keys and signed-in browser
- Your email address, which would stay with the payment provider
- Your notifications, which would never pass through us
- What your twin does, or which model you use
We wouldn't store your email address. It would stay with the payment provider that handles checkout.
Raw connection records would be kept in memory for 72 hours, then only as hourly totals for 30 days. We'd never log what's inside a connection. mirrin cloud me would show every field we store about you. Each line, with why we couldn't see it and a command to check, is on the pricing page.
Check it yourself
Promises should come with a way to check them. You can check a download, your address and your backups today, for free. The Cloud checks would answer once Cloud opens.
- Available now Every release after 0.2.0 lists its files' checksums in
SHA256SUMS, signed with Sigstore by the release workflow, and the installers check them. To check a download yourself, open a terminal in the folder you downloaded it to. On a Mac or Linux, this checks the signature (withcosigninstalled) and then the checksums:On Windows, put the name of the file you downloaded on the first line. The last line printswf='^https://github\.com/MavrkAI/Mirrin/\.github/workflows/release\.yml' cosign verify-blob SHA256SUMS --bundle SHA256SUMS.sigstore.json \ --certificate-oidc-issuer https://token.actions.githubusercontent.com \ --certificate-identity-regexp "$wf@refs/tags/v" shasum -a 256 -c SHA256SUMS --ignore-missingTruewhen the file matches its checksum:$f = 'mirrin-windows-amd64.exe' $want = (-split (Select-String -SimpleMatch $f SHA256SUMS).Line)[0] (Get-FileHash $f).Hash -eq $want - Available now
mirrin reach verifyandmirrin reach fingerprintshow the key your address presents. Compare it with what the rest of the world sees:openssl s_client -servername <your address> -connect <your address>:443 - Today Search for your address on crt.sh, a public log anyone can read, to see every certificate ever issued for it.
- Available now
mirrin backup key --ageprints your backup key, so you can decrypt a copy with the standardagetool, without us. - Available now The relay is open for you to read, on GitHub: about 4,200 lines of code.
- Planned · not on sale
mirrin cloud mewill show every field we store about you. The command is already built; it has nothing to ask until Cloud opens. - Planned · not on sale
mirrin cloud egresswill list every request your machine has sent us: method, path and size, never the contents.
An automated test already checks that a default install sends nothing to Cloud.
Leaving
You should be able to leave in an afternoon, without asking us. The way out is ready today:
mirrin backup migrate --from cloud --to <place>copies every backup, byte for byte, to a folder, iCloud Drive or a bucket of yours.- Run your own relay. It is one container.
mirrin reach use relaypoints your twin at it.- Pair your phone again. A new address means adding the web app again, and setting up notifications and your passkey again.
- Cancel with
mirrin cloud billing, andmirrin cloud delete-accountif you want the record gone.
Your twin carries on after you cancel. Your address would keep working for up to seven days past the end of your paid period, then your free route takes over. New backups wouldn't be stored after the paid period ends, but for 90 days after it you could still list and download every backup. Your address would never be passed to anyone else. Delete your Cloud record and you'd have seven days to change your mind; after that the records, DNS entries and stored backups would be removed.
If we ever shut Cloud down
90 days' notice, and your backups stay downloadable.
Cloud will only ever sell availability, so a shutdown would take nothing from your twin. It keeps running on your computer. Your backups will be in a standard encrypted format (age) that your 12 words unlock without us. Everything Cloud runs is open source, so anyone could run the same thing. Your computer's Cloud pass will be a signed token it checks itself, valid for up to 35 days: if the servers that manage subscriptions went quiet, you wouldn't notice for weeks.
Questions
When can I buy Cloud?
Not yet. The design is accepted, and Cloud is targeted to open in early 2027, with a notice in the changelog at least 14 days before. Early on, new activations will be paced at about 40 a week because of certificate limits. To follow along, watch releases on GitHub or add their feed to a feed reader; neither needs an account.
Why is it free?
Your twin runs on your machine, so it costs us nothing when you use it. We run no server for it, so there's nothing to charge for. Its source is MIT licensed (the default downloads, which include WhatsApp, are GPL-3.0, and an MIT build comes without it), it needs no account, and nothing it does today will move behind a paywall. The planned Cloud will charge only for what genuinely needs a server of ours: an address and off-site storage. If you'd like to fund the free version, we intend the planned Supporter plan for exactly that.
What happens if MavrkAI disappears?
Your twin keeps working, because it never needed us. There's no account and no server of ours in the loop, and the source is MIT on GitHub for anyone to fork. The only MavrkAI addresses your twin ever contacts are on GitHub: a pack from the community list that you choose to install or update, and our releases when you run
mirrin update. Search already uses the copy of the list built into your twin, so it would carry on; packs from that list couldn't be installed or updated until you point your twin at another list in its settings. The routines you already have would keep running.We've designed Cloud to fail gently too. The pledge is 90 days' notice and backups that stay downloadable. Backups would be in a standard encrypted format (
age) that your 12 words unlock without us, and the relay is open source so you can run your own. A Cloud pass will be checked on your computer and last up to 35 days, so even a sudden outage on our side would give you weeks.Do you see my data?
On the free version there is nothing for us to see. We run no server, and there's no tracking of any kind. Your AI provider sees what you send it. Choose Ollama and the model runs on your machine too, so your conversations never leave it, beyond the chat app you have them in. The screen's weather still asks Open-Meteo, with your time zone's city, unless you set
ui.weather: false.With the planned Cloud we would see connection details: your address, when your machine connects, your home IP, the rough network your phone connects from, bytes and duration, and backup sizes and times. We could not see inside the connection: messages, screens, approvals, memory, voice. The full list, with a command to check each line, is on the pricing page.
Can I self-host the relay?
Yes. The relay is in the first release, as its own program and container. Run it on a small server, point your twin at it with
mirrin reach use relay, use your own domain, and MavrkAI isn't involved at all. If you use Tailscale, the presence screen and chat already work over it, and a secure address over Tailscale (mirrin reach use tailscale) is in the same release.Do I need Cloud to use it from my phone?
No. Today you can text your twin on WhatsApp, Telegram, Signal and eight other messaging apps from anywhere, and approve with a reply like “yes 12”. Secure access through Tailscale, your own certificate or your own relay is free and available now. The Home Screen web app, lock-screen approvals and passkeys are free too: built, in the first release, and still being tested on real phones. Cloud would only save you the setup.
Is there a free trial?
No trial and no countdowns. There will be a 30-day refund instead. The free version is the whole twin, so you can live with everything that matters before paying for anything.
Will free features ever move behind the paywall?
No. Nothing the open-source version does today will move behind a paywall, and every paid convenience has a free, documented route that ships first. The Cloud code is kept separate, and an automated test checks that a default install sends nothing to Cloud.
Will my twin try to sell me Cloud?
Never. Your twin doesn't do sales. An automated test keeps the words “Mirrin Cloud” out of the twin's screen, personas, prompts and channels. Cloud will appear only where you ask for the capability, such as choosing how your twin is reached or where backups go, and it will be listed last. If a subscription lapses you'd get one calm line, never a push notification.
What happens if I stop paying for Cloud?
Your twin carries on as before. Your Cloud address would keep working for up to seven days past the end of your paid period, then stop routing, and your free route takes over. New backups wouldn't be stored after the paid period ends, but for 90 days after it you could still list and download every backup. Your address would never be given to anyone else.
Do I need an account?
Not for Mirrin, ever. Cloud won't have a sign-up, login, password or email account with us either. You'd be an account number, tied to a key your computer makes for itself. Your email and card would stay with the payment provider that handles checkout.
What does Cloud cost to run?
Not much would run: two relays with different providers, one small control server, DNS, and storage for backups. There's no admin website. The rest is people and care: answering support email, a weekly review of abuse, costs and dependencies, a restore drill every quarter, and new keys every year.
Which models does it use?
You choose, and you can switch from the menu bar: Claude (the default), OpenAI, Google Gemini, any OpenAI-compatible service, or a local model through Ollama. You bring your own key and pay the provider directly. We don't resell tokens, and Cloud would never touch your model calls. A fair warning: small local models are private, but they make more mistakes with tools than the big hosted ones.
Does it work without the internet?
The core does. With Ollama, the AI model, memory, listening and voice all run on your computer. You'll need a connection once to download the voice models (about 850 MB) and your Ollama model. Anything that is the internet by nature needs a connection: the chat apps, web browsing, email, Google and the weather.
Does it run on Windows and Linux?
Yes, the same program runs on all three: as a background service with a menu bar icon on a Mac, as a background service on Linux (
mirrin trayadds an app indicator), and in the system tray on Windows, started when you sign in, with no administrator needed. macOS is the most polished: it has the floating character, and iMessage is Mac-only. On Windows, for voice you'll install whisper.cpp and sox yourself for now. There are ready-made builds for Macs with Apple silicon or Intel, and for Linux and Windows on x86-64 and ARM64.
Follow along
Cloud isn't for sale. There's no waiting list and no email sign-up. To follow along, watch the releases on GitHub, or add their feed to any feed reader; neither needs an account. Cloud is targeted to open in early 2027, and the changelog will carry a notice at least 14 days before. The terms, acceptable use policy, privacy policy and data processing agreement will be final before then; the drafts are here for anyone to read.