How licensing connects
synauson runs on your own servers, and your calls never reach Synauson. Audio, transcripts, synthesized speech and everything else your calls carry stay on your systems. To keep your license current and let all your instances share one pool of AI sessions, each instance checks in with Synauson. This page explains what that connection sends, how often, and what happens if it drops.
The End User License Agreement is the binding text (Sections 3, 9 and 12). This page summarizes it.
A connection is required
Every synauson instance, on every plan including the Free plan, needs to reach Synauson over HTTPS. Each instance sends a small usage report about every 30 seconds, and about once a day the same request also renews its license, so one connection keeps your license current and your pool shared. An instance that hasn't reached us for over 7 days stops taking new calls, including calls without AI, and can't restart until it reaches us again. Licensing never ends a call in progress, whatever happens to the connection. If your systems can't connect at all, see Air-gapped deployments below.
What is sent, and how often
| What | How often | Why |
|---|---|---|
| Usage report | About every 30 seconds, plus one when an instance nears its share and one when it shuts down cleanly | Lets all your instances share one pool of AI sessions |
| License renewal | At startup and about once a day, in the same request | Keeps your signed license file current |
| License check | When an instance starts without a cached license file | Learns which license the key belongs to; sends only the key, the synauson version and what any HTTPS request carries |
| Model download requests | When a model is missing | Fetches the models synauson uses |
| Outage notice check (status.synauson.com) | At most every 5 minutes, only while the instance's reports fail | Tells an outage on our side apart from a problem on yours; sends only the synauson version and what any HTTPS request carries |
A licensing request contains only:
- your license key;
- a usage report: your license ID; a random ID the instance's process creates when it starts; a sequence number; the synauson version; whether it runs as the server or inside your Java app; the AI sessions active now; the peak number of AI sessions in each minute we haven't received yet; the numbers admitted, refused and admitted above your limit since the last report; the share of your pool the instance holds; the time it was sent; and whether the request also renews the license or is the last before the instance stops;
- on renewal, and when an instance starts without a cached license file, the request to validate your key and renew the license file;
- what every HTTPS request carries, such as your public IP address.
It never contains audio, transcripts, synthesized speech, conference or participant IDs, phone numbers or other caller details, host names, user names or a hardware fingerprint. Each usage report an instance sends for itself is written to its log at debug level, so you can see what is sent. Because reports carry per-minute peaks, an instance that was cut off uploads the minutes it missed when it reconnects, including across a restart if it keeps a state directory.
Model downloads send your license key and the ID of the file needed. The file itself comes from our storage at Cloudflare through a short-lived signed link, without your key. We run the licensing server ourselves. Cloudflare, our hosting and network provider, carries requests to it, runs the usage and status services and stores the model files, and handles this data only on our instructions. The usage service keeps each instance's counts for 8 days and your license's hourly peaks for 400 days, for billing. Cloudflare keeps the services' request logs for a few days.
On Windows, the ONNX Runtime library that ships with synauson writes a few startup events to Windows' local event tracing before synauson turns its telemetry off: its version, the start and end of loading its CPU backend, and one event per type of GPU or NPU with the device's name and driver version. After that it writes nothing per session or per call, unless someone on that machine deliberately starts a trace that turns those events back on. synauson sends none of this anywhere; whether Windows passes it on to its publisher depends on your Windows diagnostic-data settings.
Usage reports are part of licensing. They are separate from the model improvement program, a future opt-in program that will give paid plans extra sessions in return for aggregated statistics about how the engine performs, never audio, text or anything about a single call. It isn't available yet, and it stays off unless you turn it on.
Plans
There are no feature tiers. Every plan includes every AI feature (speech-to-text, text-to-speech, voice activity and turn detection) on every AI session, plus conferencing and media with no cap on conferences or participants. Plans differ only in how many AI sessions you can run at once, burst room and support, and paid plans will be able to earn bonus sessions through the model improvement program (above). Every plan includes the Free plan's 2 AI sessions, and a paid plan adds the sessions it buys, so while connected it never gives you less than Free.
The Free plan costs nothing, has no time limit and may be used in production. Each organization, or individual business, can hold one; if you have a paid plan, its license already includes the Free plan's 2 sessions. It has no burst room and no bonus sessions, and it sends the same usage reports as paid plans. Its terms can change in a new version of the agreement; we email you at least 30 days before renewing it requires accepting one. If you don't accept, each instance stops taking new calls, and can't restart, from its next daily renewal after that date; calls in progress finish.
One pool across all your instances
Your plan's AI session limit is a single pool shared by every instance, replica and site under your license key. Capacity follows your traffic, including when one site takes over from another, and you don't have to split it between instances yourself. Any other key we issue you, such as one for your customers' installations, has its own pool unless your order form combines them.
- Burst room. On paid plans, when the pool is full, synauson admits up to 25% of the sessions you bought, rounded up (or more, if your order form says so): with 10 sessions bought, your pool is 12 and you can run up to 15. The Free plan's 2 never burst. The burst is shared across your instances, and a single instance gets all of it. Burst covers peaks: the busiest 5% of hours each month, about 36 hours, are never counted. Regular use above your limit may be billed, as below.
- No dropped calls. Licensing never ends a call in progress. Once the burst room is used up, new AI sessions are refused until room frees up; calls without AI are unaffected.
- Sustained overage is never a breach. For each hour we take the highest number of AI sessions running at once across all your instances, counting every hour of the month (an hour with no reports counts as zero), then leave out the busiest 5% of the month's hours. If the highest of the remaining hours is above your limit, we tell you first, with the figures. Nothing is billed for the month we tell you or earlier. From the next month we may invoice any excess at your plan's per-session rate (your order form's, or else our price list's), prorated for the month, unless you move to a larger limit. After three months without excess, we tell you again before invoicing. Free plan use is never invoiced.
If the connection drops
Each instance keeps working for 7 days without contact, within the share of the pool it held. When our licensing service goes down, we post a signed outage notice on status.synauson.com, which runs separately, and we clear it when the outage ends. For now we post and clear it ourselves when we learn of an outage, rather than by an automatic monitor. An instance whose reports fail checks for it at most every 5 minutes. While a notice is up, an instance that can read it, and whose clock is within 10 minutes of the right time, doesn't run out of its 7 days. Once it's cleared, the 7 days run from whichever is later: the instance's last successful contact or the clearing. A license file lasts 30 days from its last renewal and a notice can't extend it, so the pause covers up to 30 days from an instance's last successful renewal. An instance that can't read the notice, because its own network is down too, say, still has only its 7 days, and recovers in full at its next successful contact: the first one always starts the 7 days again. The pause also doesn't apply to a suspended key (see below).
A new instance, or one restarted without its state directory, needs to reach us once before it can start, even during an outage of ours. Keep the state directory on persistent storage so restarts don't depend on the connection.
| Time without contact | What happens |
|---|---|
| From the first hour | A warning in the logs every hour |
| From day 3 | An error in the logs every day |
| Throughout | Calls run normally, and each instance keeps the AI capacity it had, with the exceptions below |
| After 7 days (or, after an outage notice of ours, 7 days from the later of the last contact and the clearing) | On every plan, calls in progress finish. New calls, including ones that use no AI, aren't accepted, and the instance can't restart, until it reconnects; then everything resumes at once |
How capacity works while an instance is offline. While connected, each instance holds a share of your pool as a lease of about 10 minutes, renewed with each report, and the shares add up to your limit (an unlimited license has no shares). If an instance stops reporting, its share stays reserved for it until the lease ends, since it may still be taking calls, and then passes to the instances that still report, so a failover site picks up the capacity within about 10 minutes. The same goes for an instance that stops without a clean shutdown: if it restarts within those 10 minutes, it may have less capacity until the old lease ends. Because each instance admits against its own share, one may briefly refuse a new AI session while another holds unused room, until its next report rebalances the shares. The instance that lost contact keeps the share it last held (and remembers it across restarts if it keeps a state directory, as the deployment docs describe), plus burst on the purchased sessions in that share on a paid plan, and sends its counts when it reconnects. So during an outage each instance keeps the capacity it had. If that means more sessions in total than your limit, which can last until the offline instance reconnects or reaches day 7, those hours are left out of the overage measure entirely. An instance that has a license file but has never received a share starts no AI sessions until it does; conferencing and media work regardless. And an instance that's offline when a paid plan expires starts no new AI sessions until it reconnects (see below).
If we ever stop running the licensing service for good, we'll first give you a release or license that keeps your paid plan working without it for the rest of your term, and the Free plan working after that.
Allow usage.synauson.com, license.synauson.com and status.synauson.com through your firewall (without status.synauson.com, outage notices can't reach your instances), plus the Cloudflare storage address model downloads are sent to, which the deployment docs give. Keep each host's clock synchronised (NTP): a clock several minutes off can't renew.
When a paid plan ends
You get warnings from at least 14 days before your paid plan expires. If it isn't renewed, your license moves to the Free plan automatically. Calls and AI sessions in progress finish, new AI sessions fit within the Free plan's 2, and conferencing and media keep working, including after a restart, as long as the instance stays in contact. An instance that's offline when the plan ends starts no new AI sessions until it reconnects and picks up its Free plan share. Renewing brings your plan back at each instance's next daily renewal or restart.
If a key is suspended
We suspend a key only if it leaks or someone not entitled to it uses it, for a material breach (other than unpaid fees) you haven't fixed within 30 days of our notice, or because the law requires it (Section 9.8 of the license). We email you before suspending for a breach, and as soon as we can in the other cases. If a key leaks, we send you a replacement at once (unless you shared or misused it yourself) and keep the old key working for 7 days while you switch over, unless someone is using it to cause harm. A suspension takes effect at each instance's next daily renewal: calls in progress finish, but new calls and restarts under that key are refused. We never suspend a key for unpaid fees: if fees stay unpaid more than 30 days, and 10 days after we've written to you, we may end your paid plan, and your license moves to the Free plan, just as when a plan ends.
Air-gapped deployments
If your systems can't connect to the internet at all, we offer fully air-gapped deployments by individual arrangement. Contact us and we'll agree a license for that deployment, including how its AI sessions are counted, in an order form. Air-gapped instances never contact Synauson, so they download no models: you import them from a folder you copy in.