Security and privacy decision

Userbase

Because Userbase is open-source and exposes a small browser SDK with server-side storage needs, a competent developer can self-host a minimal replacement in a few weeks and maintain it; keep paying only if you want the hosted convenience and managed support.

Visit website
You pay

$7.42/mo

$89/yr

Read off the official pricing page.

You’d pay instead

$20one-off6 h to build

$35/mo6 h/mo upkeep

On cash alone, building overtakes the subscription at 5 seats.

What a replacement has to do

  • Add user accounts and encrypted client-side persistence to a static site: client-side signup/signin with key derivation, client-side encryption/decryption of user data, client APIs to open/insert/update/delete encrypted items, server endpoints to store/retrieve encrypted blobs and handle Stripe subscriptions and file upload proxies.

What it still won’t have

  • Hosted uptime, SLA and managed scaling
  • Vendor-run maintenance, security patching, and support
  • One-click Stripe + billing convenience and hosted backups
  • Operational telemetry, analytics, and team-managed incident response

What remains hard

  • Product polish and ongoing maintenance
Read the build prompt

First-year cost

Keep paying

Paying is—cheaper in year one.

On cash alone, building overtakes the subscription at 5 seats.

Paid seatsseats

Money you would actually spend

Keep paying
—

Subscription price × seats × 12

Build it
—

AI build —APIs + hosting —

Time you would spend

—

—

What you would spend

What we assumed

The verdict above measures whether you could build it. This one is only about money.

Runnable build prompt

Not run yet
Build a minimal self-hosted Userbase-compatible service: use Node.js + Express for the API server, PostgreSQL for metadata, S3-compatible object storage for encrypted blobs, and a small JavaScript SDK for the browser. Implement: init, signUp, signIn, signOut, openDatabase, insertItem, updateItem, deleteItem, uploadFile/getFile; client-side key derivation and AES-GCM encryption/decryption stored in IndexedDB; server endpoints to store/retrieve encrypted blobs and handle Stripe webhooks (purchaseSubscription/cancelSubscription). Out of scope: real-time sync, multi-region scaling, and admin UI. Include error handling, input validation, automated tests for core endpoints, and deployment scripts (Docker + docker-compose).
How we checked5 sources · 2/3 runs agreed · evidence score 99

How the score was reached

  • Self-host verdict base92
  • An open-source build was found+5
  • 5 cited sources+3
  • Price verified on pricing page+3
  • Evidence score99

The base comes from the verdict. Everything under it is a check that either happened or did not, and each one is a fact frozen in this record rather than a judgement made at render time - so the same evidence always produces the same number.

How scoring works →

Cited sources · 5

Every page the run actually retrieved.

Integrity checks

What held up, and what did not.

✓ Price read off the page! 2 of 3 runs agreed; the verdict is the majority✓ Citations limited to fetched pages! 1 moat recorded