Skip to content

Roadmap: paid AI tutor, credits, admin, and analytics #6

Description

@pirajoke

Outcome

Evolve MY DICTIONARY into a safe public Telegram language-learning product with deterministic vocabulary practice, optional metered AI/voice, Telegram Stars billing, privacy-safe analytics, protected operations, and recoverable production data.

Product principles

  • Dictionary, cards, quizzes, written practice, pronunciation, and spaced repetition remain usable independently of AI.
  • AI and voice stay grounded in the learner active pack and deterministic progress; usage, credits, budgets, and costs are enforced server-side.
  • Analytics and operating receipts remain aggregate or metadata-only and never store learner prompts, answers, messages, credentials, charge identifiers, or contact details.
  • Public Stars checkout remains fail-closed until the separate Telegram test-environment receipt is complete.

Delivered and verified

  • PostgreSQL storage through migration 0016_mirror_control_plane_v1 with verified backup and restore tooling.
  • Eight starter languages, 100-word packs, language-pair onboarding, topics, cards, review, written/four-choice practice, transcription, audio, XP, streaks, and localized learning flows.
  • Protected admin console, privacy-safe product funnel, notification outbox, audit history, and public D1/D7 cohort metrics.
  • Metered AI tutor, durable credits, bounded companion memory, per-user/project budgets, breaker, and current-runtime provider cost settlement.
  • Voice tutor and translation with consented, bounded transcript handling.
  • Telegram Stars order/payment/subscription/refund/reconciliation code, reviewed catalog, launch gates, operator tooling, and a completed/refunded owner-only 10 XTR production canary.
  • Public Cloudflare route restored and health/login verified.
  • Daily local PostgreSQL backups plus one immutable age-encrypted off-site object and checksum.
  • One isolated recovery-host restore drill completed against the off-site object; restored revision 0016_mirror_control_plane_v1, temporary database removed, receipt private mode 0600.
  • Documentation/license gate merged; stale draft PR Document product operating model and readiness audit #37 closed.
  • Autodeploy intentionally remains absent during the pilot; releases stay reviewed and operator-controlled.

Current verified state — 2026-08-26

  • GitHub main is 174da2fda6df518e4df85d78b60a9c0fcacfef1c; changes after the production release are documentation and repository instructions only. OVH bot/admin both run code release af47038980e1f696204898ad983e838059266632.
  • Bot heartbeat is ready in public pilot mode; bot/admin restart counts are zero; PostgreSQL, backup monitor, loopback health, public health and public admin login are healthy.
  • AI Tutor, Voice Tutor, Voice Translation and bounded Mirror memory are enabled. Public Stars, owner canary, Mirror voice and autodeploy are disabled.
  • Public retention cohort is 1. D1 is 1 retained / 1 eligible / 100%; D7 is 0 retained / 0 eligible / 0%. This is observation only, not product evidence.
  • Aggregate commercial evidence: 1 completed payer, 10 XTR gross, 10 XTR refunded, 0 XTR net; AI provider cost settled at 1,341 micro-USD.
  • Current logs have zero traceback, polling-conflict and token-pattern matches. The production token is file-backed mode 0600 with no inline token.
  • Off-site recovery access is protected, host-key validated, and independently usable from the recovery host. The off-site source and restore both verify revision 0016.

Operating focus

  • NSM: durable words (correct_count >= 3 and interval >= 7).
  • OMTM through 2026-10-03: public D7 retained / eligible / rate.
  • Do not make a product decision from a retention percentage with fewer than 10 D7-eligible learners.

Remaining gates

  • Grow and observe the real public cohort; record D1/D7 and reach at least 10 D7-eligible learners before using the percentage for a product decision.
  • Provision dedicated Telegram test-server bot/user credentials and isolated database/data directory; complete purchase, duplicate delivery, restart recovery, reconciliation, refund, and subscription-cancel scenarios; create and review the private telegram_test receipt. The production 10 XTR canary is operational evidence only and does not satisfy this gate.
  • Rotate the historically exposed Telegram production token through BotFather, verify the replacement heartbeat, and preserve the sanitized evidence copy.
  • Archive or remove the original historical source log when that source becomes available.

Release posture

  • No open delivery PR remains.
  • Public Stars checkout stays disabled until the Telegram test receipt is green.
  • Autodeploy stays disabled for the pilot; deploys follow the reviewed OVH release runbook with backup, exact SHA, restart, schema, heartbeat and health acceptance.
  • Remaining work is external/observational; code, routing, AI runtime, production canary, off-site upload, and isolated restore gates are closed.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions