In the console (hosted plans, or self-hosted Enterprise): Settings, then “My plan”, the “Take your Kastel with you” section.
On the command line (free self-host): kastel export, which writes a portable, verifiable archive, and kastel backup for the continuity backup.
The way out is always open
At any moment, unconditionally and without asking permission, you can take your whole Kastel with you: your data, the engine, and the licence to host it yourself. It is free, including when you are leaving.
The archive carries a manifest listing every file with its fingerprint and size: it is verifiable, not merely downloadable. When the database is reachable, your sealed audit chain travels with it, as a separate artefact.
From the console the archive takes about a minute to prepare; the download link expires after 24 hours and works once. It is emailed to you as well. You can start a new export as many times as you want.
What “read-only” means
The freeze is an instance state: it keeps serving what it knows, and accepts nothing new. It applies the same way to a hosted Kastel whose subscription has ended and to any instance an operator deliberately puts into read-only.
| Keeps working | Stops |
|---|---|
| Asking, searching, opening a page, navigating | Every write: dropping a document, editing a page, approving |
| Connected AIs, for reading | Connector syncs |
| Signing in to the console | The six functions that run on their own |
| The export, in full | The weekly check and its notifications |
| Cutting an AI's access | Any spend on your AI keys at the instance's own initiative |
One important point: the freeze changes nothing. No setting, no connection, no queued job is deleted or altered. A job already queued stays queued, unstarted, without failing, without burning its attempts. On unfreeze, everything resumes exactly as it was.
A failed payment is not an ending
If a payment fails on a hosted subscription, you get an email straight away: the payment did not go through, retries continue for seven days, the service keeps running throughout, and the card is updated from your console. Only after those seven days, if nothing succeeded, does the subscription end and the rest of this page apply.
When a hosted subscription ends
Your workspace goes read-only the same day. Nothing is erased: your data is intact, and you have thirty days to take it with you or resume the subscription. The whole console is replaced by one screen saying three things, in this order: export, resume, view your invoices. Export comes first, deliberately - the way out never hides behind the sales action.
The date shown is the date enforced. You are warned five times before deletion, then once after:
| When | What the notice says |
|---|---|
| Same day | The subscription has ended, your workspace is read-only; export or resume before the stated date |
| 10 days later | The number of days left, the same two exits |
| 20 days later | The number of days left, the same two exits |
| 27 days later | Deletion is scheduled for a stated date; resuming cancels it |
| 29 days later | Last reminder before deletion |
| 30 days later | The workspace was deleted as announced; the encrypted backup archive is kept for thirty more days, then destroyed |
Resuming the subscription at any point in those thirty days cancels the deletion and switches your Kastel back on exactly as you left it: your people, your sources and your settings are still there. Nothing was re-provisioned, nothing has to be redone.
Carrying on without us
Kastel's free plan is hosted by you, with no size limit, no account to create, and nothing that has to call our servers to keep working. You restore your archive into a fresh install and carry on: same engine, same context, same rules.
What you lose by leaving the hosted service is the operations - the instance run for you, continuous updates, the infrastructure. What you do not lose is your context: it was never ours in any sense that would stop you taking it back.
What each plan includes, and what the free plan covers, are on the Pricing page.
See pricing