Skip to content

Analytics ​

🔵 Research. What is measured, what the creator sees, and the proactive surface it enables.

Why this is a feature and not instrumentation ​

Today the creator of a biodata is operating completely blind. They send a file and learn nothing: not whether it was opened, not whether it was forwarded, not whether anyone considered it. Every other problem with a PDF is about control; this one is about feedback, and it is the one that makes the product feel alive rather than merely safer.

It is also how the feature passes CLAUDE.md's proactive-value gate, which forbids shipping something whose honest description is "it lets them see X".

What the creator sees ​

Deliberately small. The audience is a person or a parent, not an analyst.

Your profile this week

  👁  128 views          👥  34 unique viewers
  🔒   7 access requests  ❤️   3 interests

The proactive surface ​

Each of these is derived from stored events, never invented — the standard the proactive principle sets ("Never fabricate insight"):

SignalAction it prompts
Viewed 14 times this week, 0 access requests"Your photos are the most-skipped section. Add one where your face is clear."
A recipient opened it four times without requesting access"Someone keeps coming back. Consider opening your family details to them."
Nothing shared in 21 days"Your profile is live but nobody new has seen it. Share it with two more relatives."
Unchanged in 90 days"Details drift. Confirm your role and city are still right."
Still active long after a reported match"Still looking? Pausing stops dead proposals reaching your family."

⚠ This audience is more sensitive to nagging than a merchant is, because the subject matter is personal and the family is watching. Quiet, in-app, dismissible, and almost never a push. A nudge the creator learns to ignore does not degrade to neutral — it trains them to ignore every nudge.

⚠ Analytics on a PII page is itself a privacy decision ​

This is the part that differs sharply from vendor-card analytics, and it must be settled before design.

  • Do NOT identify viewers. "Someone from Pune viewed your profile" is a surveillance feature and invites harassment of the viewer. Aggregate counts only, unless the viewer has taken a deliberate, identified action such as expressing interest.
  • Access requests and interests are identified by consent — the requester chose to be known. Views are not.
  • Retention has to be bounded. View logs about a named person are PII and inherit every DPDP obligation on the page itself, including erasure.
  • Do not build a re-identification surface by accident. A small enough audience plus a timestamp plus a coarse location is identifying, even without a name.

Existing capability, and what is missing ​

NeedState
Analytics seam in the app✅ @qrsetu/analytics with a pluggable sink
A live sink⚠ Web only. apps/web installs a GA4 sink; apps/mobile calls setAnalyticsSink nowhere, so every merchant-side track() reaches a no-op console sink
A read model for card analytics❌ Not established. Card-activity seams in packages/data are stub-only
Per-view event capture on a public page🔴 Built and ORPHANED. The full client path is wired — setu-card.tsx:104 encodes the QR as ?s=qr, :111 builds the beacon URL, :214 installs it and :216 fires card_viewed with source: qr | organic — but track-card-event is NOT among the 10 live Edge Functions; it exists only under _archive_pre_v2/. The beacon posts to a 404 on every card view. Any consumer analytics design must not assume this pipe works.

⚠ GA4 must not be the analytics path for a consumer PII page. Sending view events about a named person's marriage profile to a third-party advertising analytics platform is a consent and data-transfer decision that has not been taken, and almost certainly should not be taken. The vendor card's analytics choices do not transfer here.

Classification: the seam is reuse, the read model is new, and the sink choice is a privacy decision rather than an engineering one.

Open questions ​

  1. What is a "view"? A recipient opening the same link five times is one interested family, not five. Dedupe rules materially change every number the creator sees.
  2. Are analytics free or paid? The source analysis puts advanced analytics in the premium tier. Basic feedback is arguably the core value and should be free; depth can be paid.
  3. Retention period, and whether the creator can clear their own history.
  4. Does the subject see the analytics, when the subject is not the account holder?