Mirrin Pricing, planned

PricingCloud: planned, not on sale

Free is the whole twin. Cloud would be $6 a month.

Every paid convenience already has a free way to do it, available now.

There is nothing to buy today.

Free, and Cloud (planned)

1TiersFree, for goodPlanned · not on sale

Free, Cloud and Supporter

Free is the product: the whole twin, and everything it does. Cloud and Supporter would only add availability and support, for people who'd rather not run their own.

Cloud and Supporter are planned pricing. They may change before Cloud opens, and we'll post a notice in the changelog at least 14 days before it does. Cloud is targeted to open in early 2027.

Free

Free, for good

$0

open source · no account

The whole twin, on your machine, for good.

  • The whole twin: voice that answers to its name, memory you can read, a signed-in browser, routines and personas
  • Eleven messaging channels (ten in the MIT build, which has no WhatsApp), plus voice and the terminal
  • Approvals with a picture of the page, spending limits, an audit log
  • Any model: Claude, OpenAI, Gemini, or one on your machine
  • Your twin exported to one file
  • The presence screen on your other devices, over Tailscale
  • Secure access from any network, through Tailscale, your own certificate or your own relay
  • Encrypted backup to a folder, iCloud Drive or any S3 bucket, locked with 12 words
  • Being tested on phones: a web app you add to your Home Screen (no app store), with a key for each device
  • Being tested on phones: lock-screen approvals, with a passkey (Face ID, a fingerprint or your device PIN) for the dangerous ones

Cloud

Planned

$6 a month

or $60 a year · planned pricing

Availability, not a different twin. A stable address on two relays that only your computer can answer for. 20 GB of encrypted off-site backup with nothing to set up. Your Twilio calls pointed at your address. Email support within two business days.

Supporter

Planned

$20 a month

planned pricing

Everything in Cloud, plus next-business-day support (best effort). We intend it for people who want to fund the free version.

Founding, planned: $48 a year for the first 500 subscribers, kept for as long as you stay subscribed.

Fair use, planned: about 100 GB relayed a month, and up to 20 Mbit/s for your address, shared by all its connections. Past 100 GB you'd get a warning first; if it carried on, the relays would stop serving your address until the next month. An address opened from more than 200 different networks in one day would be paused for seven days, because connection details are the only sign of abuse a relay can see.

Household: later, if people ask for it.

No trial, a 30-day refund, and no lifetime deals. Your twin would never mention Cloud: it would appear only where you ask for the capability, listed last.

Table 1Free, Cloud and Supporter side by side. Free is the longest column on purpose. Cloud and Supporter are planned pricing and not on sale.
Feature Freetoday · open source Cloudplanned pricing Supporterplanned pricing
Price$0. No account, ever.$6 a month or $60 a year. Founding: $48 a year for the first 500, kept while you stay subscribed. 30-day refund, no trial.$20 a month
The whole twin: voice that answers to its name, memory, signed-in browser, approvals, spending limits, routines, personasYes, foreverThe same twin
Text it from anywhere, and approve with a pictureYes, today. Eleven messaging apps (ten in the MIT build), plus voice and the terminal; pictures on seven. Nothing to open on your router.Same as Free
Any model: Claude, OpenAI, Gemini, or one on your machineYes, today. Your key, paid to your provider.Same as Free. Cloud would never touch your model calls.
Export your twin to one fileYes, todaySame as Free
A web app you add to your Home Screen (no app store), one-QR pairing, a revocable key for each deviceBeing tested on phones. In the first release; pairs over any route below.Same as Free
Lock-screen approvals, pushed straight from your machineBeing tested on phones. Your machine sends them itself; no server of ours in between.Same as Free
A passkey (Face ID, a fingerprint or your device PIN) for dangerous approvals from the phoneBeing tested on phonesSame as Free
Reach from any networkYes, today: over Tailscale's private network; or a secure address through Tailscale, your own certificate, or your own open-source relay and domain, with a certificate only your computer holds and the public logs watched for one it didn't ask forA stable address on two relays that only your computer can answer forSame as Cloud
Encrypted backupYes, today: to a folder, iCloud Drive or any S3-compatible bucket, locked with 12 words only you hold, and copied between places byte for byte. Plus a daily copy of your memory file on your own disk.Plus 20 GB off-site with nothing to set up; 90 days to download after your paid period endsSame as Cloud
Calls and texts through your own TwilioAny public address you runPointed at your Cloud addressSame as Cloud
Fair useNo limits of ours: it's your own connectionAbout 100 GB relayed a month (with a warning first); up to 20 Mbit/s for your address, shared by all its connectionsSame as Cloud
SupportCommunityEmail, within 2 business daysNext business day, best effort
LaterA purpose-built wake-word model, and training your own on your computer3 wake-word trainings a year once the training data is licensed for it; your own domain on our relaysNot decided yet
2LicenceAvailable now

Open source, in plain words

  • The source is MIT. Read it, change it, fork it and share it, in open or closed projects, keeping the copyright notice.
  • The default downloads are GPL-3.0. They include WhatsApp, whose encryption library (libsignal) is GPL-3.0, so those downloads are GPL-3.0 as a whole. If you pass one on, whoever gets it gets the same rights, and every release carries its complete source.
  • An MIT build comes without WhatsApp. Every release also has an MIT build of the program without WhatsApp. It contains one MPL-2.0 library (yamux, which carries reach through a relay), whose own files stay MPL-2.0. To install it, set MIRRIN_BUILD=nowhatsapp before the one-line install.
  • Running it asks nothing of you. Using Mirrin on your own machine isn't distribution, so neither licence asks anything of you for it.
  • What you contribute. Anything you contribute to the Mirrin repository, from code and docs to a protocol or a registry entry, is MIT like the rest, with no contributor agreement to sign. A pack of protocols in your own repository is yours, under the licence you give it there; listing it in the registry doesn't change that, so add a licence before you share it.
  • Cloud's code is open too. Everything Cloud would run is in the same repository, under the same MIT source licence, so anyone could run the same thing.
3VisibilityPlanned · not on sale

What we would see, what we couldn't, and how to check

Cloud isn't running, but its code is in the repository, so this is what that code would do, not a promise about code nobody can read. Nothing here applies to a twin that never linked: until you run mirrin cloud link, your machine sends Cloud nothing at all. Commands that start with mirrin run on the computer your twin lives on; the Cloud ones will have something to show once Cloud opens.

Table 2What we would see. Each line names who holds it, for how long, and how you can look.
WhatHeld byFor how longSee it yourself
Your account number, plan, billing status and paid-through date, and the payment provider's customer numberThe control planeWhile you're subscribed; removed 7 days after mirrin cloud delete-accountmirrin cloud me
Your handle (your address)The control plane, public DNS and public certificate logsFor good in the logs; the name is never given to anyone elsemirrin cloud status
Your machine's public keys: its device key, the recovery key your 12 words make, and the certificate account its address is pinned toThe control plane, public DNS (the CAA record)While you're subscribedmirrin cloud me, mirrin reach fingerprint
The day your machine last checked in, and when it refreshes its pass (about daily)The control planeWhile you're subscribedmirrin cloud me, mirrin cloud egress
Your home IP address, and when your machine connects to the relaysThe relaysWhile the tunnel is up; logs keep only the /24 or /48 networkmirrin reach status names the relays it connects to
For each connection to your address: the network it came from (/24 or /48), your address name, bytes and durationThe relays72 hours in memory, then hourly totals for 30 daysThe relay's source
How many backups you keep, their sizes, and when each was madeThe control plane and the storage providerUntil the backup is pruned or you delete the accountmirrin backup list, mirrin cloud me
Your email address, card and billing countryThe payment provider (merchant of record), never usUnder the provider's own policymirrin cloud billing
Table 3What we couldn't see. Each line says why we can't, which is how the code works rather than a promise, and a command to check it.
WhatWhy we can'tCheck it with
Anything inside a connection to your twin: messages, the screen, approvals, cookies, memory, voiceTLS ends on your machine, with a key only your machine holds. The relay reads the name on the envelope (the SNI) and passes the still-encrypted bytes through; it has no code path that loads a certificate for your name, and a test proves it sees only ciphertextmirrin reach verify, mirrin reach fingerprint, and the openssl check below
A certificate for your address, obtained quietlyYour address's CAA record names your machine's own Let's Encrypt account and the TLS-ALPN-01 method, so a relay, a stolen signing key or a hijacked route can't get one. We can rewrite that record, so on the shared zone a certificate we (or our DNS provider) caused would be detected, not prevented: every certificate lands in public logs, and your twin checks them every 6 hoursmirrin reach verify, mirrin reach alarm, and your address on crt.sh
What's in your backups, or the names of the files inside themEach backup is encrypted on your machine with age, to a key made from your 12 words. The words are never stored, not even on your machine. Objects are named by time and a random tag onlymirrin backup key --age, then stock age -d; mirrin backup verify
Your 12 wordsThey are shown once, on your screen, for you to write down. Only public keys made from them are keptmirrin backup status shows only a Kit ID; mirrin backup verify asks you to type the words, because they appear nowhere on disk (a test scans for them)
Your passwords, API keys and signed-in browserThey never leave your machine. Backups leave out the browser profile altogether, and the rest travels only inside the encrypted backupDecrypt a backup with mirrin backup key --age and age -d, then list it with tar -tz: there is no browser profile. The Trust page lists everything that leaves
Your notificationsYour machine encrypts them and sends them straight to Apple's, Google's, Mozilla's or Microsoft's push service. No server of ours is in the pathmirrin cloud egress shows no notification ever sent to Cloud; the Trust page names the push service as their only destination
Your email addressThe control plane has no email column. It fetches the address from the payment provider for one mirrin cloud me answer and doesn't keep itmirrin cloud me (its schema-coverage test fails if a stored field is missing)
Your IP address, in our databaseNo table has an address column. Rate limits hold addresses in memory onlymirrin cloud me
What your twin does, or which model you useNone of it goes through us. The only requests your machine sends to Cloud are signed calls carrying public keys, your handle and backup sizesmirrin cloud egress lists every request sent: method, path and size, never the body
Anything at all from a twin that never linkedThe Cloud client is inert until mirrin cloud link. Only three packages may import it (a test enforces that), and a test runs a default twin for two days of simulated time and sees no request to a Cloud or relay hostmirrin cloud status ("sends nothing") and mirrin cloud egress (empty)

We wouldn't store your email address. It would stay with the payment provider that handles checkout, which would also be the only place your card goes. There is no login: your account number is a record keyed to your machine's own key, not an account you sign in to.

The openssl check: from any computer, ask your address which key it presents. It should print the “Current key” from mirrin reach fingerprint (or the “Next key”, just after a renewal). Your twin's Trust page shows the same command with your address filled in.

Any computer with OpenSSL
h=your-address.example
openssl s_client -connect "$h:443" -servername "$h" </dev/null 2>/dev/null \
  | openssl x509 -pubkey -noout | openssl pkey -pubin -outform der \
  | openssl dgst -sha256 -binary | openssl base64 | tr '+/' '-_' | tr -d '='
4ExitAvailable nowPlanned · not on sale

Leaving, and if we ever shut Cloud down

Our pledge

90 days' notice, and your backups stay downloadable.

You should be able to leave in an afternoon, without asking us, and the way out is ready today: copy your backups to a place of your own, run your own relay, pair your phone again and cancel. Your twin carries on after you cancel. Your address would keep working for up to seven days past the end of your paid period, and for 90 days after it you could still list and download every backup. A shutdown would take nothing from your twin either, and your backups are in a standard encrypted format (age) that your 12 words unlock without us.

Each step, with its command, is in Leaving on the Cloud page, and the whole pledge in If we ever shut Cloud down.

5LegalDrafts · not in force

Terms and privacy, in draft

The terms of service, acceptable use policy, privacy policy and data processing agreement for Cloud will be final and published before Cloud opens. The drafts are public now so you can read what we intend to promise. They are drafts for legal review, not legal advice, and not yet in force.

The free, open-source twin needs none of these. It comes under its licence: the source is MIT, the default downloads (with WhatsApp) are GPL-3.0, and an MIT build comes without WhatsApp (section 2).