Skip to content

Security basics

Supabase free plan limits, and what happens at each one

The Supabase free plan limits you to 500 MB of database and 5 GB of egress, with no backups. What happens as you cross each line, and what $25 changes.

Vlad Tkachenko11 min read
A panel of circuit breakers with every switch up except one, which has tripped and sits in an amber band.

In short

  • The Supabase free plan limits are 500 MB of database, 1 GB of files, 5 GB of egress a month and 50,000 monthly active users, and it keeps no automatic backup of your database.
  • Each limit stops something different. At 500 MB your database turns read-only and signups fail. Over the egress allowance, after a grace period, every project in your organization can be restricted.
  • Pro costs $25 a month. The payment that stops the weekly pause also turns on daily backups, and for an app with real users that is usually the reason to move.

Your app runs on a Supabase project, most likely one created on the free plan the day Lovable or Bolt asked you to connect a database. It has worked for months. Then an email arrives saying your organization has gone over its usage quota, or a customer writes in to say the signup button does nothing, and you go looking for what the free plan actually allows.

The Supabase free plan limits are easy to find. What happens when you cross each one is much harder to find, and it is different for every line. One stops your app saving anything while its pages still load. One can switch off every project you have. One trips when nobody has visited for a week.

Here is where the usual comparison goes wrong. They treat Pro as the free plan with bigger numbers, and tell you to upgrade when one of the numbers runs out. For an app with real users, the reason to pay usually arrives first, and it is on no usage graph: the free plan keeps no copy of your database, and the $25 that stops the pausing is the same $25 that starts daily backups.

Think of the free plan as a fuse box. Every limit is a breaker, and the question worth asking about each one is which circuit it cuts when it trips.

Every figure below was read off Supabase's pricing page and documentation on 29 September 2026. They are Supabase's numbers and they move, so read them again there on the day you decide.

What are the Supabase free plan limits?

Five usage limits, a rule about inactivity, a cap on projects, and one thing that is missing altogether. This is the free plan as Supabase lists it, with what each line does when you cross it.

LimitFree planWhen you go past it
Database size500 MB per projectThat project turns read-only: pages load, nothing saves
Egress5 GB a month, plus 5 GB cachedA warning, a grace period, then restrictions
File storage1 GBA warning, a grace period, then restrictions
Monthly active users50,000A warning, a grace period, then restrictions
Inactivity7 daysThe project is paused
Active projects2You cannot start a third
Automatic backupsNoneNo copy exists to restore from

The rows sit on two kinds of breaker. The database limit cuts one circuit on one project, the moment it trips. Egress, storage and users sit on the main switch. Supabase calls it its Fair Use Policy, it covers every project in the organization, and it trips slowly, with an email to your billing address and a grace period first.

What happens when you hit the 500 MB limit?

Your database goes into read-only mode. Visitors can still browse, because reading still works, and everything that saves something fails.

A signup is a write. So is a new order, an edited profile, a sent message and a submitted form. In read-only mode Postgres refuses every one of them, and your app's requests come back with the error cannot execute INSERT in a read-only transaction. In an app made with an AI builder, the person clicking may see that as a spinner, or as nothing at all. The pages that still load are what make it hard to spot. From outside the app looks fine, and it has stopped taking in anything new.

At 500 MB the database keeps answering and stops accepting. Everything a visitor saves is a write.

Three things about the 500 MB catch people out:

  • It counts your data, not the disk. Supabase measures your tables, indexes and materialized views. The free project sits on 1 GB of disk, and the space above 500 MB is not yours to fill.
  • Some of it is used before you start. A new project is already around 40 to 60 MB before your first row, which Supabase puts down to the extensions and schemas it installs.
  • Deleting rows does not hand the space back at once. Postgres marks deleted rows as removed and reclaims the room when a vacuum runs, so a cleanup can look as if it did nothing.

There are two ways out. Upgrade to Pro, where each project gets 8 GB of disk and can grow past it once the spend cap is off. Or make room: Supabase's database size guide shows how to switch read-only off for one session in the SQL Editor, delete what you no longer need, run a vacuum and turn writes back on. Take a copy before you delete anything, because on the free plan nobody else has one. Making one from the dashboard needs no terminal.

There is also a second, slower breaker on database size. Supabase watches the organization's database size averaged across the billing month, and an organization over that quota can be restricted, with every request answered 402. Because it is an average, shrinking the database today does not lift it. The next billing month does, and so does an upgrade.

What counts as egress on the Supabase free plan?

Every byte your projects send out. The free plan's 5 GB a month is shared by the whole organization, and it is a limit you can reach without doing anything unusual.

Supabase counts it across every service: the rows your app reads through its API, sign-ins, files your users download from Storage, Edge Function responses and Realtime updates. Files served from Supabase's cache count against a second 5 GB of their own, and that one applies to Storage only.

Backups count too. Every copy taken from outside Supabase is a download, whichever tool takes it, ours included, and Supabase's own advice on reducing egress lists backing up fewer tables, or less often. A daily copy of a database at the 500 MB limit moves about 15 GB a month. That is three times the free allowance before one visitor has loaded a page. The egress a scheduled backup spends is laid out there by database size, if you are choosing how often to take one.

Going over does not cut anything off that day. Supabase emails your billing address and starts a grace period. Stay over, and the restrictions its billing FAQ lists are pausing projects, switching databases to read-only, and answering every API request with a 402 status code, and they generally apply to every project in the organization. They lift when the next billing cycle begins, or at once if you upgrade. The grace period is also a one-off. After it, a second overshoot is restricted straight away, until you have stayed under the limits for several billing cycles.

Why does the free plan pause a quiet project?

Because nobody used it. A free project with too little database activity over seven days is paused, which makes it the one breaker in the box that trips when nothing happens.

Supabase emails a warning about a week before and a confirmation when it pauses. Your pages usually carry on loading, because your builder serves those, while everything behind them stops answering. A seasonal shop, an app between launches, a tool a client opens once a month: each looks inactive to this rule. You have a year to press Resume, and what to do when a project is already paused is its own article.

Projects on a paid plan are never paused for inactivity.

How much does Supabase Pro cost, and what does it add?

$25 a month for the organization, which includes $10 of compute credits covering one project on Supabase's default Micro instance.

FreePro
Database500 MB, then read-only8 GB of disk, more with the spend cap off
Egress5 GB a month250 GB a month
File storage1 GB100 GB
Monthly active users50,000100,000
PausingAfter a quiet weekNever
Automatic backupsNoneDaily, kept for 7 days
SupportCommunityEmail

For a small app with real users, two rows in that table are the ones that decide it. The pausing stops and the daily backups start, for the same $25. An app with a few hundred users can sit far under every limit on the free plan and still lose a week of work to one bad migration, with no copy to go back to.

The backups Pro turns on are kept inside your Supabase account, they cover the database, and they reach back seven days. Does Supabase back up my database? goes through what that copy survives. To rewind to a particular minute rather than to last night, Supabase sells point-in-time recovery as an add-on at $100 a month on top of Pro, and what that add-on buys has the detail.

Pro also changes what a limit does. It comes with a spend cap, switched on by default, and with the cap on Pro works like the free plan at a higher ceiling: go past a quota and you get the same grace period and the same restrictions. Switch the cap off and the breakers become meters. Nothing stops, and the overage is billed at the rates on Supabase's pricing page. Choose by which would hurt you more, a larger bill or an app that stops.

With the spend cap on, crossing a quota stops things. With it off, crossing one adds to the bill.

Does upgrading one Supabase project upgrade all of them?

Yes. The plan belongs to the organization, and every project in it moves together.

Supabase does not let you mix free and paid projects in one organization. If your live app shares one with a test project you forgot about, upgrading puts both on Pro, and the second adds about $10 a month of compute on top of the $25, because the included credits cover one project.

The fix costs nothing. Before you upgrade, move the project that should stay free into an organization of its own. Supabase calls this a project transfer, and you start it from that project's general settings.

The plan is set on the organization. A project that should stay free needs an organization of its own.

What does no Supabase plan copy for you?

The files your users uploaded, your Edge Functions, and your project's settings. Every plan's backups are a copy of the database, and Supabase's backup documentation says plainly that they do not include objects stored through the Storage API.

When Supabase restores a backup into a new project, its list of what has to be set up again by hand includes Storage files and bucket settings, Edge Functions, Auth settings and API keys. That holds on the free plan, on Pro and on everything above it. The avatars and PDFs in your buckets need their own copy, and how to back up Supabase Storage covers the ways to take one.

Where Reeve Care fits

Care keeps a copy of your Supabase database outside your Supabase account, on a schedule, whichever Supabase plan you are on.

  • Daily on Care, and more often on the plans above it. A copy that fails sends you an email, which is how a paused project gets noticed the night it stops answering.
  • The copy lives outside your Supabase account. Encrypted, on storage we hold, so a pause, a restriction or a lost login leaves your backups where they were.
  • Every copy is read back before it counts. The date on your dashboard is the last copy that passed that check.
  • Restoring is a button, and it takes a snapshot of the current state first, so the restore has an undo of its own.
  • The files your users uploaded come too, once you connect a Storage credential. That is a second key, asked for separately, because the key Supabase issues for Storage can write as well as read.

Care starts at $49 a month for one app. That is a list price, and the pricing page is sometimes below it and never above. On Pro, keep Supabase's own daily backups switched on as well, so there are two copies in two places. The copy, the check and the restore are drawn step by step on the Supabase backups page.

What to do this week

What to do

  • Open your organization's Usage page in the Supabase dashboard and read three numbers: database size, last month's egress and file storage. Each one is a row in the first table above.
  • If the database is getting close to 500 MB, choose between upgrading and cleaning up now, before read-only mode chooses for you.
  • Before you upgrade, check which projects share the organization, and move any that should stay free into an organization of their own.
  • If you stay on the free plan, keep your own copy of the database somewhere outside Supabase, as Supabase's own documentation recommends.
  • If you move to Pro, look under Database, then Backups, the next day and confirm the first daily copy is there.

Before you close this tab, open the Usage page and find the number sitting closest to its limit. That is the breaker nearest to tripping. The 10-minute security checklist covers backups alongside the rest of what is worth confirming on an app people rely on.

FAQ

How much does Supabase cost?

The free plan costs nothing. Pro starts at $25 a month for the organization, and that includes $10 of compute credits, enough for one project on the default Micro instance. Each further project on a paid plan adds about $10 a month of compute. Team and Enterprise sit above Pro for companies that need things like single sign-on and compliance reports. Read the figures off Supabase's pricing page on the day you decide, because they are theirs to change.

What are the Supabase free plan limits?

On 29 September 2026 Supabase listed 500 MB of database per project, 1 GB of file storage, 5 GB of egress a month plus 5 GB of cached egress, 50,000 monthly active users and two active projects. A project with too little activity over a week is paused, and the free plan takes no automatic backups at all.

What happens when I hit the 500 MB limit?

The project goes into read-only mode. Pages that only read data keep working, and everything that writes fails with the error cannot execute INSERT in a read-only transaction: signups, orders, saved forms. Either upgrade to Pro, or switch read-only off for one session in the SQL Editor, delete what you do not need and run a vacuum so the space is actually given back. Take a copy before you delete anything.

Does the Supabase free plan include backups?

No. Supabase lists automatic backups as not included on the free plan, and its documentation recommends that free projects export their data regularly with the Supabase CLI and keep that copy somewhere else. Daily backups start on Pro, which keeps the last seven.

Is Supabase Pro worth it for a small app?

If real people depend on it, usually yes, and rarely because of the space. Pro stops the weekly pause and turns on daily backups. An app with a few hundred users can sit far below every free limit and still lose a week of work to one bad migration, and on the free plan there is no copy to go back to.

Do backups count against my Supabase egress?

Yes, when the copy is taken from outside Supabase. Egress is every byte your projects send out, and a backup is a download. Supabase's own advice on reducing egress includes backing up fewer tables or less often. A daily copy of a database at the 500 MB limit moves about 15 GB a month, three times the free allowance, and your app's own traffic draws on the same 5 GB.

Written by

Vlad Tkachenko

Founder, Reeve

I spend my time looking at apps built with Lovable, Bolt, v0, Cursor and Replit, and at the short list of mistakes that keep turning up in them.

More about the author

Read next

All articles

Not sure where your own app stands?

Run a free scan and get a plain-language grade from A to F in about 20 seconds. No account, no card.

Scan your app free

Automated external check, not a full audit. Absence of findings is not a guarantee of safety.