06 — Monetisation Strategy
Two tiers. Two rails. One rule.
The rule is that safety is never behind money. Text messaging is free for life, for everyone, forever — and it is free because it is nearly free for us to carry. Everything with a real marginal cost sits behind one price.
The plans
Free
₹0 · for life
Unlimited end-to-end encrypted text messaging, one-to-one and in groups. The full identity model, the full cryptography, sealed sender, post-quantum — none of it is a paid feature and none of it ever will be.
Costs us almost nothing: sealed, delete-on-delivery, no retention, no relay leg for media.
Premium
/yr in India · /yr elsewhere
Media and files, voice and video calls, multi-device, continuity and export, view-once, the richer surface. Priced per region by our server, not by the app.
Everything here has a real marginal cost, and it is paid for by the people using it.
Two tiers, not three. We collapsed a middle tier in September 2026 because it made the decision harder without making the product better. The price is served from a price book on our own server — the app asks, it does not decide — which means we can change a country's price without shipping a build, and cannot accidentally ship two different prices in two places.
In trust markets, cheapest is a bad position. A price too low invites exactly the question we want to answer cleanly — then how are you really funded? Threema charges once and is taken seriously. Session is free, donation-funded, and came within days of shutting down in July 2026. Our position is "sustainably priced, and here is the arithmetic". The durability argument is the marketing.
The two rails, and why the difference is most of our margin
A subscription bought inside the app pays an app store fifteen per cent of the first million dollars a year and thirty per cent after that. The same subscription bought on our own web rail pays a payment gateway about three per cent. Same product, same price to the customer, wildly different economics for us.
| Rail | What it costs us | What the customer does |
|---|---|---|
| Our own web rail | ~3% | Pays by UPI or card on our site, gets an anonymous voucher, redeems it in the app. The blind signature happens on their device. |
| App store | 15% → 30% | Taps buy inside the app. Simpler, and it is the path most people will take, so we built it and we pay for it. |
We do not model everyone moving to the cheap rail. Our base case assumes of sales go through our own rail and the rest through the stores, and the calculator on The Pitch lets you set it to whatever you think is realistic. It is the most consequential dial on this site after conversion.
Why we can carry free users forever
This is the part that is easy to state and hard for anyone else to copy. Our marginal cost to serve a free user is close to zero, so a free tier is not a loss leader we tolerate — it is a permanent, sustainable position. That matters strategically because most of our users will never pay us anything by design: safety is never paywalled, and the people who need safety most are often the people least able to pay for it.
Put the other way: it is not that we refuse advertising and must therefore charge. It is that our cost structure is the only reason refusing advertising is survivable at all.
On advertising, and why refusing it costs us less than it looks
Advertising has the highest ceiling of any model in this industry and it is structurally unavailable to us. That is usually framed as a constraint. It is closer to the opposite.
Ad monetisation needs three things we cannot have by construction: identity resolution, so you know who this is across sessions; behavioural signal, so you know what they want; and attribution, so you know whether it worked. We hold none of the three. Untargeted inventory clears at a small fraction of targeted rates, so the honest statement is not that advertising is distasteful to us — it is that advertising would pay us almost nothing even if we were willing.
And there is a second-order benefit: our promise is credible because we cannot quietly renege on it. A company that could switch on ads tomorrow is a company that might. We would have to rebuild the product to do it.
What comes next, in order
- Add-ons priced on top of Premium — longer retention, capture alerts, peer-to-peer large-file transfer. Each carries its own cost and therefore its own meter.
- Business messaging where confidentiality is the product — not "chat for everyone", which the world already has in abundance, but the specific verticals where a platform that cannot read the conversation is the reason to buy. Our first is whistleblower and vigil-mechanism channels, where anonymity is legally expected, the budget already exists under Indian company law and listing obligations, and the sales line writes itself: we could not identify the whistleblower if we wanted to, because there is no author field.
- Echoes — public conversation, with its own economics. That has a page of its own.
In a product that cannot meter people, you must meter resources. The one place with a real marginal cost reachable without paying is relayed call bandwidth on a free trial. We have modelled the abuse case properly — a rotating-identity user costs us tens of terabytes a day at scale, which would be genuinely existential — and the control is a relay minute budget per entitlement, enforced on our server rather than trusted to the app. The enforcement point already exists in our code. The counter does not, yet. We would rather you heard that from us.