LAUNCH30, until 5 October 2026.Pricing · Self-hosted
Self-hosted
Free to run in production. Notifuse never charges per email, per contact or per seat. Five capabilities need a licence key, from $290 a year — everything else is free, and stays free.
Studio
$290
per year
For a company and its brands.
- Included:
- 5 workspaces
- Granular permissions
- Amazon SES tenant isolation
- Template translations
Agency
$890
per year
For an agency and its clients.
- Included:
- 15 workspaces
- Granular permissions
- Amazon SES tenant isolation
- Template translations
Enterprise
$1990
per year
For SSO and compliance requirements.
- Included:
- 15 workspaces
- Granular permissions
- Amazon SES tenant isolation
- Template translations
- Single sign-on (OIDC)
- Audit logs coming soon
One key covers one deployment — one PostgreSQL database, whatever the number of API containers. Need something else? Talk to us about a Custom licence.
14-day refund, no questions asked. The key you receive at purchase is valid for 30 days; your one-year key is emailed automatically once the refund period has passed. Nothing to do on your side.
The five capabilities that need a key
Version 1 — last updated September 4, 2026
This list is written into the licence itself, in the Additional Use Grant of the LICENSE file, so its scope is fixed by the version you downloaded and cannot be changed under you afterwards. Everything else in Notifuse runs without a key.
-
1.More than three workspaces
Creating a fourth workspace on one deployment. Nothing is done to the workspaces you already have — an installation holding eight keeps all eight and simply cannot create a ninth.
Refused at: Creating a workspace
-
2.Granular permissions
Writing a permission set that is not full access: setting a member's permissions, inviting a member with a restricted set, or creating an API key with a restricted scope. Permissions already granted stay enforced in every licence state — the authorization engine never consults the licence — and removing a member is always allowed, because that is what revokes a leaked API key.
Refused at: Saving permissions, inviting with a restricted set, creating a scoped API key
-
3.Amazon SES tenant isolation
Provisioning a new SES tenant. A tenant provisioned earlier keeps sending through its own reputation forever after: the send path contains no licence check of any kind.
Refused at: Enabling tenant isolation on an SES integration
-
4.Template translations
Adding a language to a template, or editing the content of one already there. Translations already saved keep being sent in every licence state, editing the rest of a template that carries them is never refused, and removing one is always allowed.
Refused at: Saving a template that adds or changes a translation
-
5.Single sign-on (OpenID Connect)
Signing in through SSO. Without a licence that covers it the SSO button is not offered, and everyone signs in with a login code instead — nobody is locked out, and sessions already open are unaffected.
Refused at: The sign-in page stops offering the SSO button
What a refusal does, and does not do
- It refuses one action, at the moment you take it. Nothing is deleted, hidden, disabled or made read-only, and no part of the console is walled off.
- The send path contains no licence check of any kind. Scheduled broadcasts, transactional email, webhooks and API keys keep working in every licence state, including one with no key at all.
- A key that reaches its expiry keeps granting everything it ever granted for a further 30 days before the installation falls back to the free tier.
- An installation that already exceeds a limit keeps everything it has. Eight workspaces stay eight; it simply cannot create a ninth.
Install a key under Settings › Licence as the root user, or set NOTIFUSE_LICENSE_KEY. Verification is offline against a signature compiled into the binary: no
phone-home, no account, nothing about your installation leaves it.
What a licence never covers
A list of what you must pay for is a price list. This is a commitment, and it is only a commitment because it is dated, versioned, and hard to walk back. Every line below can be checked against a running instance in ten minutes.
Nothing that is free in v40 will ever be moved out of this list. Any change to it carries 90 days' notice, with the previous version left visible — and the version and date above are how you hold us to that.
- ✓ No per-email fee, ever. No sending cap, no throughput tier, no volume meter.
- ✓ No contact meter: unlimited stored contacts, active contacts, timeline events, custom events and pageviews, with no retention expiry when you self-host.
- ✓ Unlimited team members, invitations and user accounts. No seat cap, in any build, at any size.
- ✓ Permissions already granted stay enforced in every licence state, and removing a member is always allowed.
- ✓ Three workspaces on every installation, each with its own isolated PostgreSQL database. The isolation architecture itself is never licensed — only the count beyond three.
- ✓ Login-code sign-in always works, on every installation, licensed or not, and no session in progress is ever ended.
- ✓ Full read and export of your data, at any time. The application never blocks a read, never deletes a row, and never stops a transactional email or a broadcast in flight.
- ✓ Every release becomes AGPL-3.0-or-later four years after it ships, on a clock that runs per version.
The licence
Notifuse is open source on a delay: every release is published under BSL 1.1 and becomes AGPL-3.0 four years later. You may run it, modify it, and make it available to third parties — including hosting it for other people, and charging them for it — provided you do not use one of the five capabilities above in production without a valid key.
The four-year clock runs per version, and it does not depend on us still being here.
The authoritative text is the LICENSE file in the repository, with the map in LICENSING.md. Where this page and those files disagree, the files govern — this page exists to explain them, not to replace them.