Skip to content
Back to the path

Unit 5 of 7

Open

Day 5 — Operations, legal and cost limits are set

What you have afterwards: Legal pages, publishing details and cost limits are prepared.

Goal

You clarify what can cost you money, time or trust after publishing.

Understand briefly

A login is not cost control. Anything that triggers a paid feature needs a server-side approval first: request → check → reserve budget → start provider → record usage. Remote config may hide buttons, but it is never the security boundary — the server always makes the final call. And a single “AI on/off” is too coarse: switch individual capabilities separately and keep the free manual route available when you pause the expensive one.

Follow along

Paste this prompt into the AI tool you work with:

My app does: [SHORT DESCRIPTION]. Paid or external calls: [LIST OR “none”]

1. List which legal texts, support routes and data declarations my release goal requires.
2. Propose a separate switch plus daily and monthly limit for every paid feature.
3. Describe a server-side kill switch that also stops an old app version.
4. For each point, tell me how I can tell it actually takes effect.

Explicitly mark anything you are not sure about.

Build it yourself

Write your legal and support pages, create icon, splash and description texts, and set a hard cap for every paid feature.

Verify

Only tick a box once you have really checked it. These criteria are the only way to finish this unit.

0 of 3 confirmed

Still open: 3 criteria

Self-check

Three questions about decisions you made today. There are no points and no grade — only the why. Every answer can be changed.

1. Your app triggers a paid function. What protects you from a surprise bill?
2. What is remote config good for — and what not?
3. You are writing the description for your release. What do you hold to?

0 of 3 answered

Next step

Tomorrow you build the state you would actually ship.

Next: Day 6 — A real release candidate

隐私设置

在你同意后,PostHog EU 会统计哪些页面被打开,并额外录制你的会话:鼠标移动、点击、滚动以及页面呈现的内容会被保存为可回放的重建记录。你输入的文字在发送前会被遮蔽。登录、注册、密码找回、创始人聊天、订阅邮件输入框、你的邮箱显示、你的测验答案以及检查清单的内容完全不会被录制;在登录和注册页面,录制处于暂停状态。网址始终不带查询参数保存。此外还会处理一个随机设备标识以及 IP 地址等技术连接数据。除此之外,还会统计少数严格定义的使用事件:文章被读到什么程度、使用了哪个文章模块、点击了哪个行动号召,以及订阅邮件的结果如何。仅传输固定清单中的取值——不含输入内容,也不含自由文本。 了解更多隐私信息

未经你同意,不会加载任何分析代码,也不会进行录制。你可以随时撤回:撤回会立即停止采集;此前已采集的数据可能已经传出,并会在存储期限后删除。