Account, trial, and subscription
PalCommand uses an account instead of emailed license keys. There is no permanent Free plan in this release model. New customers may start one card-required seven-day trial, then choose the monthly (US$5.99/mo) or annual (US$49.99/yr) subscription shown at checkout. The subscription renews automatically until it is cancelled.
Prices, renewal timing, refund promises, and trial disclosures shown in the product are subject to the Terms of Sale. The legal text is pending counsel approval; live checkout remains disabled until that review is recorded.
Sign in and start a trial
Open Account and choose Sign in. PalCommand opens your normal browser for WorkOS AuthKit; your password, passkey, or email code is never entered into the desktop webview. After the browser returns successfully, this Windows installation occupies one of the account’s three device slots.
Starting a trial opens Polar checkout at palcommand.com. A payment card is required, but
PalCommand never receives or stores the card number. Do not treat the checkout return page as proof
of access: the app waits for the signed billing update. The account page then shows the exact trial
end or next charge date supplied by the billing service.
Manage billing and devices
Use Manage billing on the account page to request a fresh, short-lived Polar customer-portal link. From the portal you can change the plan, payment method, or cancel. Cancellation stops future renewal; the account page is the source of truth for when current access ends.
The account page lists up to three active devices. Revoke a device you no longer use to free a slot. Revoking the current device signs it out. A lost machine can be revoked from another signed- in browser or by contacting support after identity verification.
Safety Mode
If the trial ends, a first charge fails, access is revoked, or a signed entitlement cannot be verified, PalCommand enters Safety Mode. It never automatically stops or deletes a running server. You can still observe status and logs, save and gracefully stop a server, create a verified manual backup, export or delete local data, open account/billing, and use read-only MCP if enabled.
Safety Mode blocks new starts/restarts, create/import/restore, settings and schedule changes, updates, moderation/broadcast, network/mod changes, and MCP mutations. Established paid access may have a signed offline grace boundary; trials never do. Reconnect and open Account to refresh.
Sign out, export, and delete
Sign out revokes the local browser/device credential but does not stop servers or erase local worlds. Export account data creates an authenticated download available for 24 hours. Delete account requires a recent sign-in. If billing is current, first open the customer portal and cancel renewal; PalCommand keeps sign-in and portal access until a signed cancellation, expiry, or refund event arrives, then a repeated deletion request revokes cloud credentials and removes the profile. It never deletes local servers, saves, backups, or settings.
To remove local data, use the explicit local-data action and review every path. Uninstalling alone preserves server folders and backups by design.
Secure storage errors
Account and MCP pairing secrets are stored only in Windows Credential Manager. PalCommand does not fall back to a file. If Credential Manager is unavailable, sign-in or MCP pairing fails closed:
- Install pending Windows updates and restart.
- Confirm the Credential Manager service is available and your Windows profile is writable.
- Sign in again. Do not place tokens in environment variables, command-line arguments, or files.
- If the error persists, send the redacted app log to
[email protected]; never send a credential, checkout URL, or account export.