Subscription Model

How OmegaSafe Cloud subscriptions work.

Registration for OmegaSafe Cloud free trials and permanent free accounts is currently closed while launch compliance work is completed. When registration opens, initial availability will be limited to the European Economic Area, United Kingdom, United States, Switzerland, Australia, Japan, South Korea, and Israel. Paid self-service subscriptions are currently available only to individual consumers resident in the United Kingdom. OmegaSafe Cloud pricing covers encryption key slots in 30-day and 365-day periods. The minimum subscription size is 3 key slots. Subscription size beyond 3 keys can be increased by 1, up to as many keys as you need.

CurrencyMin. 3-key subscriptionEach additional key
30 days365 days30 days365 days
GBP3.7537.501.2512.50
USD4.9549.501.6516.50
EUR4.3543.501.4514.50
CHF3.9039.001.3013.00
PLN18.45184.506.1561.50

Key slots provide safe synchronisation of key utilisation across devices, automated renewals, and sharing with other users. The cryptographic operations themselves — encrypting and decrypting files — are not measured or billed for. You can share your keys with as many devices and users (including free users) as you need. To start a subscription, sign in to OmegaSafe Cloud, open My Account, go to Billing & Subscription, and complete the purchase there.

1. Decryption Is Always Available
#

Decryption and Delta retrieval remain fully available even after billing expires. This is a permanent design guarantee, not a grace period. In most cases OmegaSafe CLI does not require connectivity to perform a decryption. However, if it needs to pull a Delta generated by a different device, it will still be able to do so after billing for the relevant key expires.

OmegaSafe API — POST /deltas/download_url has no billing check and requires only key access (any role). Any user with access to a key can always download Deltas and decrypt files regardless of their subscription status. As a result, OmegaSafe CLI — pull-missing-deltas also works after billing expires, because it uses the same download route internally.

Only OmegaSafe API — Step 1: POST /deltas/upload_url and OmegaSafe API — PATCH /deltas/claim return 403 Forbidden when billing for a key is expired. These are the only operations gated on active billing for a key.

With Bring Your Own Storage — Recommendation and Keys Management — CLI Key Actionability Gate, you retain control over both the Delta files and the local Alpha key material needed to use them. If OmegaSafe Cloud is unavailable, OmegaSafe CLI — import-key-delta provides an emergency-only recovery path for manually importing a trusted encrypted Delta file and bypassing OmegaSafe Cloud when necessary. It should be reserved for exceptional situations only, because it bypasses ECS authority checks and can introduce local and ECS divergence that requires manual recovery.

2. Free Trial - No Payment Details Required
#

New accounts automatically enter a trial period for:

  • 3-key slots
  • 30-day period

After trial expiry, the account can continue on the free tier and use full functionality on keys that are billed for and shared by another account. You can keep your keys created during the free trial and resume full features for them if you decide to create a subscription later.

3. Slot-Based Sharing Model
#

OmegaSafe billing is based on key slots. One user can purchase multiple key slots and share keys with other users, who can use those keys for free. There is no limit on the number of users or devices sharing any key. The only limit on sharing is the user’s own security posture.

Free-tier accounts — accounts with no active subscription of their own — have no functional limit when working with keys paid for by other accounts. Billing checks on upload, claim, and renewal routes are performed against the key’s billing user, not the requesting user. A free-tier account can encrypt, decrypt, and use any shared key indefinitely as long as the key’s billing user has an active subscription. Decryption stays available for all users of a key, regardless of the key’s billing and ownership status.

4. Storage Limits
#

Using Bring Your Own Storage — Recommendation removes OmegaSafe’s aggregate per-key upload-count and download-count limits. OmegaSafe internal storage has those aggregate limits to protect the service from abuse. Both storage models retain the universal 10 MiB per-Delta upload limit and write-once, checksum-enforced upload safeguards. See Bring Your Own Storage — Delta Upload Safeguards and Bring Your Own Storage — Internal Storage Limits.

5. Billing In The Web App
#

Eligible UK consumers complete subscription purchase, renewal, and cancellation in the OmegaSafe Cloud web interface. Open My Account, then go to Billing & Subscription to review pricing, start a paid plan, inspect your current renewal setup, or manage a pending change.

Businesses and organisations cannot use self-service checkout, even if they are in the UK. Contact sales@omega-safe.com for individual review and a separate written agreement. Account holders outside the UK can continue using the free tier but cannot start a paid consumer subscription yet.

6. Subscription Status
#

Open My Account > Billing & Subscription to see whether billing is active, whether the account is still on trial, the current expiry date, slot usage, pending renewal changes, renewal status, and any subscription issue that needs user action.

If you need the same billing summary programmatically, see OmegaSafe API — Subscription Status.

7. Purchase Flow
#

Self-service purchases start in My Account > Billing & Subscription. They are available only to individuals acting as consumers who are resident in the UK. Choose the required slot count, select either a 30-day or 365-day billing period, then choose a PayPal-account subscription or a card payment with automatic renewal. The PayPal-account option redirects you to PayPal for approval. The card option uses PayPal Card Fields within the checkout page.

For a card payment, use the billing address held by your card issuer. The billing-country selector contains every country currently allowed for free-account registration. Your browser supplies this address directly to PayPal Card Fields; OmegaSafe does not receive it in the order-creation request, compare it with your residence, or store it. PayPal returns the card brand, last four digits, and expiry month/year so OmegaSafe can display and identify the saved renewal card. OmegaSafe also stores the PayPal payment token needed for future charges, but does not store the full card number or card security code. Replacing the card, cancelling card auto-renewal, an applicable full refund or reversal, or final account deletion removes the local saved-card details and queues deletion of the PayPal payment token.

Invoice fields are collected in the same checkout flow when tax or invoice rules require them.

After PayPal completes an initial payment, OmegaSafe records the completed charge before sending the required purchase confirmation. Paid access starts only after that confirmation has been handed off successfully, that exact purchase’s access activation has completed, and the purchase has no country-evidence issue. This normally completes during checkout. If confirmation delivery or the separate access-activation step is temporarily unavailable, checkout returns to Billing & Subscription while OmegaSafe tracks that captured order, shows that it is still being finalised, and retries only the unfinished step automatically. Do not submit the payment again; refresh the billing status later or contact support if the pending state continues.

8. Pending and Subscription Change Rules
#

Only one unfinished PayPal subscription change can exist on an account at a time. If My Account > Billing & Subscription already shows a pending PayPal draft or return state, finish or cancel that pending flow before starting another one.

You can increase slots immediately when the selected new billing period is at least as long as the paid or trial time remaining on the account. If the remaining time is longer than the selected period, choose a longer billing period or wait until the remaining time fits that period. Cancelling auto-renewal does not remove paid time and does not bypass this rule. Keeping the same slot count or reducing it remains available, subject to the minimum slot count required for the keys you bill.

For example, with 300 days remaining on a 3-slot subscription, changing to 100 slots for 30 days is blocked, while changing to 100 slots for 365 days is allowed and the higher slot count applies immediately after payment confirmation. Once 30 days or less remain, the 30-day change is also available.

When PayPal confirms a successful payment for a subscription change:

  • the new slot count applies immediately
  • the purchased 30-day or 365-day period is added after the existing paid or trial expiry
  • no remaining days are lost

If the previous paid or trial period has already expired, the purchased period starts from the payment confirmation time. When an active PayPal subscription is replaced, the new subscription becomes the renewable plan and the old subscription is cancelled without removing any OmegaSafe access time already on the account.

Automatic renewals do not wait for an ordinary receipt email before extending otherwise valid access. If receipt delivery is temporarily unavailable, the renewed paid period remains active; contact support if you need a missing receipt or download it from the web interface.

9. UK Paid Eligibility and Country Evidence
#

The self-service paid launch is limited to UK consumers. A purchase is rejected unless both required signals are present and identify the United Kingdom:

  • the UK country of residence selected by the user in the checkout flow
  • the country returned by a runtime IP-based network lookup during checkout

A request marked as a business or organisational purchase is also rejected and must be discussed with sales. Card billing-address fields are sent directly from the browser to PayPal Card Fields as transient payment inputs, but OmegaSafe does not receive them in its order-creation request, retain them, compare them with the residence country, or use the card billing country as a third country-evidence signal.

Both required signals must return GB before a PayPal subscription or card order is created. OmegaSafe saves the resulting two-signal country evidence for paid-market eligibility and applicable accounting or tax records; it does not save the lookup IP in the financial evidence snapshot. Automated renewals reuse the evidence accepted for the initial purchase and do not perform a fresh network-country lookup for every charge.

If you stop being resident in the UK, cancel automatic renewal before the next charge and contact support if you need help. Your account continues on the free tier after paid access expires.

10. Cancellation
#

To cancel, follow the instructions in Help — Billing And Account Changes. Cancelling auto-renewal stops future renewals but keeps the already-paid period active until the displayed expiry date. For card auto-renewal, OmegaSafe removes the card from local renewal use immediately and queues removal of the corresponding PayPal payment token; temporary PayPal failures are retried automatically. For the cancellation business rules, see Terms and Conditions — 4.6 Cancellation.

After billing expires, Subscription Model — 1. Decryption Is Always Available continues to apply. Decryption and Delta retrieval remain available for every user with access to the key.

Once billing has expired, the only blocked operations are new encryptions and key renewals for keys billed by the user who cancelled the subscription. If you do not have active billing of your own but you have OWNER or MAINTAINER permission on a key billed by another user whose billing remains active, you keep full functionality for that role on that key as described in Subscription Model — 3. Slot-Based Sharing Model.

11. Receipts and Invoices
#

Signed-in users can open My Account > Billing & Subscription to download billing documents for completed orders. Receipts are available for completed sales, and invoices are available when the order has an invoice snapshot.

If you need the bearer-authenticated document download endpoints for automation, see OmegaSafe API — Billing Documents.