Skip to content
Back to the path

Unit 5 of 7

Open

Day 5 — Operations, legal and cost limits are set

What you have afterwards: Legal pages, publishing details and cost limits are prepared.

Goal

You clarify what can cost you money, time or trust after publishing.

Understand briefly

A login is not cost control. Anything that triggers a paid feature needs a server-side approval first: request → check → reserve budget → start provider → record usage. Remote config may hide buttons, but it is never the security boundary — the server always makes the final call. And a single “AI on/off” is too coarse: switch individual capabilities separately and keep the free manual route available when you pause the expensive one.

Follow along

Paste this prompt into the AI tool you work with:

My app does: [SHORT DESCRIPTION]. Paid or external calls: [LIST OR “none”]

1. List which legal texts, support routes and data declarations my release goal requires.
2. Propose a separate switch plus daily and monthly limit for every paid feature.
3. Describe a server-side kill switch that also stops an old app version.
4. For each point, tell me how I can tell it actually takes effect.

Explicitly mark anything you are not sure about.

Build it yourself

Write your legal and support pages, create icon, splash and description texts, and set a hard cap for every paid feature.

Verify

Only tick a box once you have really checked it. These criteria are the only way to finish this unit.

0 of 3 confirmed

Still open: 3 criteria

Self-check

Three questions about decisions you made today. There are no points and no grade — only the why. Every answer can be changed.

1. Your app triggers a paid function. What protects you from a surprise bill?
2. What is remote config good for — and what not?
3. You are writing the description for your release. What do you hold to?

0 of 3 answered

Next step

Tomorrow you build the state you would actually ship.

Next: Day 6 — A real release candidate

Privacy setting

With your consent, PostHog EU measures which pages are opened and additionally records your session: mouse movement, clicks, scrolling and the rendered page content are stored as a replayable reconstruction. Typed input is masked before sending. The contents of sign-in, sign-up, password recovery, the founder chat, the newsletter field, your email display, your quiz answers and the checklists are not recorded at all; on the sign-in and sign-up pages recording is paused. Addresses are always stored without query parameters. A random device identifier and technical connection data such as the IP address are processed as well. In addition, strictly defined usage events are measured: how far a post was read, which article element was used, which call to action was clicked, how a newsletter sign-up ended, how far you get in a course or in the feed (recording only whether a task was correct or incorrect, never your answer itself), which video you start, whether you switch the language, and how a sign-in or sign-up attempt ended — without the email address, without the password, and without the error message. Only values from a fixed list and whole numbers from fixed ranges are transmitted — no input and no free text. We also label production, internal, and automated test visits separately and derive whether a visit came from a known interface such as ChatGPT, Claude, or Perplexity from a known referring domain or a strictly allowed campaign value. The full referring address and query parameters are not sent, and this cannot identify a specific AI model. If PostHog's IP-based geo enrichment is enabled in the project, the service can derive an approximate country, continent, and region; we do not request browser or GPS location. Every visit is also assigned to a page area from a fixed list (for example home, blog, tools, account) — the area is sent, not the address. Page loading and stability metrics are measured as well (Core Web Vitals: LCP, CLS, INP, FCP), without network payloads. A click on a link leading away from the site is recorded only as the target domain from a fixed list, without path, query parameters, or link text. For the Idea Wheel, AI Labelling and Limit Reset tools only the kind of action is measured — spin, option changed, copy or export, for instance — never your input and never a result. Learn more about privacy

Without your consent no analytics code is loaded and nothing is recorded. You can withdraw at any time: withdrawal ends collection immediately; data already collected may have been transmitted by then and is deleted after the storage period.