Appearance
Analytics
🔵 Research. What is measured, what the creator sees, and the proactive surface it enables.
Why this is a feature and not instrumentation
Today the creator of a biodata is operating completely blind. They send a file and learn nothing: not whether it was opened, not whether it was forwarded, not whether anyone considered it. Every other problem with a PDF is about control; this one is about feedback, and it is the one that makes the product feel alive rather than merely safer.
It is also how the feature passes CLAUDE.md's proactive-value gate, which forbids shipping something whose honest description is "it lets them see X".
What the creator sees
Deliberately small. The audience is a person or a parent, not an analyst.
Your profile this week
👁 128 views 👥 34 unique viewers
🔒 7 access requests ❤️ 3 interestsThe proactive surface
Each of these is derived from stored events, never invented — the standard the proactive principle sets ("Never fabricate insight"):
| Signal | Action it prompts |
|---|---|
| Viewed 14 times this week, 0 access requests | "Your photos are the most-skipped section. Add one where your face is clear." |
| A recipient opened it four times without requesting access | "Someone keeps coming back. Consider opening your family details to them." |
| Nothing shared in 21 days | "Your profile is live but nobody new has seen it. Share it with two more relatives." |
| Unchanged in 90 days | "Details drift. Confirm your role and city are still right." |
| Still active long after a reported match | "Still looking? Pausing stops dead proposals reaching your family." |
⚠ This audience is more sensitive to nagging than a merchant is, because the subject matter is personal and the family is watching. Quiet, in-app, dismissible, and almost never a push. A nudge the creator learns to ignore does not degrade to neutral — it trains them to ignore every nudge.
⚠ Analytics on a PII page is itself a privacy decision
This is the part that differs sharply from vendor-card analytics, and it must be settled before design.
- Do NOT identify viewers. "Someone from Pune viewed your profile" is a surveillance feature and invites harassment of the viewer. Aggregate counts only, unless the viewer has taken a deliberate, identified action such as expressing interest.
- Access requests and interests are identified by consent — the requester chose to be known. Views are not.
- Retention has to be bounded. View logs about a named person are PII and inherit every DPDP obligation on the page itself, including erasure.
- Do not build a re-identification surface by accident. A small enough audience plus a timestamp plus a coarse location is identifying, even without a name.
Existing capability, and what is missing
| Need | State |
|---|---|
| Analytics seam in the app | ✅ @qrsetu/analytics with a pluggable sink |
| A live sink | ⚠ Web only. apps/web installs a GA4 sink; apps/mobile calls setAnalyticsSink nowhere, so every merchant-side track() reaches a no-op console sink |
| A read model for card analytics | ❌ Not established. Card-activity seams in packages/data are stub-only |
| Per-view event capture on a public page | 🔴 Built and ORPHANED. The full client path is wired — setu-card.tsx:104 encodes the QR as ?s=qr, :111 builds the beacon URL, :214 installs it and :216 fires card_viewed with source: qr | organic — but track-card-event is NOT among the 10 live Edge Functions; it exists only under _archive_pre_v2/. The beacon posts to a 404 on every card view. Any consumer analytics design must not assume this pipe works. |
⚠ GA4 must not be the analytics path for a consumer PII page. Sending view events about a named person's marriage profile to a third-party advertising analytics platform is a consent and data-transfer decision that has not been taken, and almost certainly should not be taken. The vendor card's analytics choices do not transfer here.
Classification: the seam is reuse, the read model is new, and the sink choice is a privacy decision rather than an engineering one.
Open questions
- What is a "view"? A recipient opening the same link five times is one interested family, not five. Dedupe rules materially change every number the creator sees.
- Are analytics free or paid? The source analysis puts advanced analytics in the premium tier. Basic feedback is arguably the core value and should be free; depth can be paid.
- Retention period, and whether the creator can clear their own history.
- Does the subject see the analytics, when the subject is not the account holder?