This console shows operational metrics only. User transactions, receipts and backups are encrypted on-device — by design, no admin can read them here.
AI scans today
142
▲ 8% vs yesterday
AI cost today
$4.03
≈ ₦6,650 · ₦47 / scan
Avg latency
2.9s
msSum ÷ attempts
Error rate
2.1%
3 of 145 attempts
AI scan volume · 14 days
peak 153
Proxy health
Success rate97.9%
Avg latency2.9s
Error rate2.1%
Text-only requests: 38% · images discarded after read
Beta access
config/beta
37 / 250
provisioned accounts · 213 slots free
Raises maxUsers — invites still pull from the waitlist
Recent events
Scan-rate anomaly · account #4471 (94 scans/hr)
New contact message · "Can I export to CSV?"
Waitlist · 18 new signups (iOS 11 · Android 7)1h ago
Scan rollup · 142 scans, 3 errors, $4.03today
Statistics
Reading /ops/summary and /ops/accounts…
Accounts
37 / 250
▲ +6 this week
Paid
11 · 30%
9 Plus · 2 Pro
Sync enabled
14
multi-device backup on
Near / over quota
3
upsell candidates
All accounts · 37
Search by uid
O
o••••@gmail.com
Plus · 2 devices · 2m ago
PlusActive
E
e••••@gmail.com
Plus · 3 devices · 30m ago
PlusActive
A
a••••@gmail.com
Plus · 1 device · 1h ago
PlusActive
C
c••••@gmail.com
Plus · sync off · 2d ago
PlusActive
T
t••••@yahoo.com
Plus · 2 devices · 38/40 scans
PlusNear quota
B
b••••@icloud.com
Starter · 20/20 used · 6h ago
StarterUpsell
M
m••••@gmail.com
Plus · scan-rate anomaly · 21m ago
PlusFlagged
K
k••••@outlook.com
Starter · 1 device · 1d ago
StarterActive
Emails are masked and IDs are pseudonymous. Operators never see expense data, receipts or backup contents — those are encrypted on-device.
OTP codes expire in 10 min · rate-limited 5/hr per account. Everything on this pane is live from auth_otp_events — KPIs, funnel, outcomes, deliverability and the 14-day trend. Cards with no events yet say so rather than drawing a shape.
Codes sent · 24h
312
▲ signups + purchases
Verify success
89%
274 of 308 delivered
Median time-to-verify
24s
sent → entered
Deliverability
98.7%
4 bounced of 312
OTP funnel · 24h
auth_otp_events
Sent312 · 100%
Delivered308 · 98.7%
Verified274 · 87.8%
Expired 22 · wrong code 9 · resent 31
Outcomes · 24h
Verified274
Expired22
Wrong code9
Locked · rate-limited3
Lockout after 5 wrong attempts · auto-clears in 1h
Deliverability by domain
gmail.com99.2%
icloud.com98.9%
outlook.com98.4%
yahoo.com97.1%
Yahoo trending low — watch for spam-folder placement
Verify success · 14 days
avg 90%
Share of delivered codes verified within 10-min expiry window
Behaviour-change KPIs — aggregate counts only, no user content. This is the signal that the mission is working.
Have a budget
68%
▲ 6pts this month
Have a savings goal
41%
of active accounts
Median review streak
4 wk
weekly-review habit
Found-money accepted
57%
of nudges shown
Weekly-review streak distribution
{{ s.label }}
Accounts grouped by consecutive weekly reviews
Found-money nudge funnel · 30d
Shown2,140 · 100%
Set aside (logged)1,220 · 57%
Reached a goal milestone410 · 19%
Riffl records the set-aside; money never moves through Riffl.
Free
26
70% of accounts
Plus
11
▲ 3 this month
Free → Plus
9.4%
30-day conversion
Conversion funnel · 30d
Free signups26 · 100%
Hit a Plus gate18 · 69%
Opened paywall12 · 46%
Started Plus3 · 11.5%
Which gate drove the upgrade
{{ g.name }}{{ g.count }}
UpgradeScreen → paywall → start, by originating feature · top-up vs subscription: 8 / 3
Live from sync_metrics — push/pull cycles, ops carried and errors, 14 days. Zero-knowledge by construction: the log stores ciphertext, and this rollup stores counts only — no uid, no content, ever.
Sync cycles · 14d
—
pushes + pulls
Sync success rate
—
target ≥ 99.5%
Ops carried · 14d
—
in + out
Errors · 14d
—
refused or failed cycles
Cycles per day · 14d
Pulls sit above pushes: a device pulls on every foreground, and pushes only when it has something to send.
What this pane deliberately does not show
Device counts — there is no device census by design; the registry is per-account and never aggregated. Fleet adoption lives on Overview, in flushes.
Blob storage — receipt-image sync isn't built yet (retain → upload → download). Nothing to measure until it ships.
Restore outcomes — a restore is a pull from cursor 0, indistinguishable from any other pull server-side. Instrumenting it would mean labelling traffic the server currently can't tell apart.
COMING SOON · illustrative. Portfolio / Net Worth isn't built. These are the metrics we'll watch — counts only, never values or holdings. Net worth is the most sensitive data; the server never sees amounts.
Plus users w/ ≥1 asset
—
awaiting Portfolio
Median assets / user
—
count only
Track a liability
—
% of Plus
Price-fed opt-in
—
public prices only
Asset-class mix
How many users track each class — counts, not amounts
{{ c.name }}{{ c.count }}
Adoption metrics light up when Portfolio ships
Designed in full, deliberately deferred until the Plus launch product is proven. The server will only ever store counts and class flags — never a single net-worth figure.
Scans · 30 days
3,640
Cost · 30 days
$104
FX — · not live
On-device handled
71%
never left device
Avg latency
2.9s
msSum ÷ attempts
Top accounts by scans
#4471612
#1185410
#2030280
#0907150
#4471 flagged for review · tap to inspect
Allowance usage
Starter (20/mo) — at limit22%
Plus (40/mo) — avg used61%
Accounts at allowance limit3
Entitlements · allowance vs purchased credits
scan_entitlements
Monthly plan allowance refreshes each cycle; granted credits never expire and are spent only after the allowance runs out.
AcctPlanAllowance this cycleCreditsLeftStatus
#2110Plus90/150+400460Healthy
#2098Plus61/150+312401Healthy
#2052Plus12/40+150178Healthy
#2087Plus22/40+4866Healthy
#2071Plus38/4002Low
#2065Starter20/2000Upsell
#4471Plus150/4000Over
Tap a row to comp credits, reset the cycle, or nudge an upsell.2 low · 1 upsell · 1 flagged
Monetization hasn't started. Early access is free, so revenue is genuinely ₦0. Launch is store-billing only — Google Play and Apple collect, and that client isn't built yet. The Paystack rail (checkout, signed webhook, keys) IS built and runs in test mode, but it is dormant and deferred to Riffl Business. Only the account and plan-mix figures below are live; every revenue figure stays zero until store billing ships.
Plan revenue · 30d
₦0
pricing not live
Legacy top-ups
₦0
packs retired — historical only
Collected · 30d
₦0
no payments built yet
Active accounts
—
—
Plan mix · real, from accounts
Not loaded
No paid plans are on sale during early access — any non-free plan above is a comp and earns ₦0. Real MRR begins when pricing launches at public release.
Revenue starts at launch
No subscriptions have been collected — nothing is on sale during early access. This fills with real transactions once store billing ships.
Unsettled grants
Charges marked paid whose entitlement never reached the ledger — money taken without delivery.
—
Not loaded
Recent transactions
no source yet
No transactions — the charge ledger exists and is empty, because nothing has been sold. Once store billing ships, real charges appear here with their reference, channel, and refund/retry controls. Card numbers are tokenised by the store or processor — full PANs never reach Riffl.
Payments readiness
What has to clear before the first charge can move. Launch is store-billing only — Google Play and Apple take the money; Paystack is deferred to Riffl Business.
CAC incorporation — RC 9685707Done
Plan expiry + per-product pricing in the ledgerDone
Grant is atomic with settlement + reconciliation sweepDone
Play Billing client in the appNot built
Proxy: store token verification + refund/renewal streamNot built
Play Console products + store listingNot set up
Apple org enrollment — D-U-N-S applied 16 JulIn process
Apple IAP (after the org clears)Blocked
Corporate bank account — unblocks Paystack (Riffl Business)In process
Pricing goes live at public releasePending
The three built items are the entitlement model itself: a paid plan now carries an expiry, each pass is priced separately, and the grant lands in the same transaction as the charge. The remaining store work is what actually takes money. Dunning and recovery metrics appear here once real charges exist — from live data, never estimates.
Window
loading…
Visits (30d)
—
Signups (measured)
—
Conversion
—
Visits today
—
By channel
Which posts actually convert. Low visits = the post isn't landing. High visits + low conversion = the landing page is.
Channel
Visits
Signups
Conversion
—
By device
How people browse riffl.app.
By OS
iOS share is how urgent TestFlight is — we ship Android first.
Daily visits
Top pages
Which pages people actually land on. /pricing traffic with no signups means the price is the objection, not the pitch.
Total signups
—
This week
—
This month
—
Told us interests
—
By device
Loading…
Most wanted
Loading…
Early access cohort
config/waitlist
The capped list. Once it fills, new signups are still collected — they go to waitlist_next and are told early access is full.
—/ —
Nobody already in the cohort is ever moved out — the list is decided at signup.
Send invites
POST /ops/invite
Oldest signup first. Anyone already invited is skipped, and a failed send is never marked — it retries next run.
Send getting-started tips
POST /ops/tips
Post-install guidance. Only people who were actually invited and can install — iOS-only founders are excluded. Anyone already sent is skipped, and a failed send is never marked, so it retries next run.
Everyone here is on Android — "Both" and unstated were all sent the Android build. The narrower options slice what people said at signup, not what they run.
Recent signups
Loading…
Next in line
Signed up after the cohort filled. Still real demand — invite them when you open the next wave.
This list is token-gated — only an operator holding the ops token can load it. Export CSV downloads every signup (email · source · device · interests · date) so you can import them into your invite/email tool.
Distinct layouts
—
Captures blocked
—
With a sample
—
Redaction rejects
—
Should stay 0
Receipt layouts Riffl could not read
ranked by captures blocked
Grouped by layout, not by capture — one unhandled bank met by forty testers is one row worth forty.
Layout samples are disabled pending a redactor rewrite (audit 2026-07-22); rows below are structural fingerprints only.
Loading…
COMING SOON
No hosted-backup service yet
Today backup is an on-device encrypted file the user exports themselves — there's no server-side hosted backup to report storage, restores or integrity checks on. This panel activates if and when hosted backup ships.
Zero-knowledge by design. Whenever hosted backup ships, files are encrypted on-device before upload — this console would only ever see size, count and integrity status, never the contents.
Unread
5
This week
12
Resolved
18
Top topic
Bug
5 of 12
Inbox
contact_messages
Tunde A. Feature
Can I export to CSV? I'd love to pull my spending…
2h
Ngozi E. Bug
The AI read got the date wrong on a GTBank screenshot…
5h
Bisi O. General
Just wanted to say the audit view is brilliant…
1d
Chidi N. Press
I write for a Lagos tech newsletter and would love…
2d
Amara K. Billing
When paid plans launch, will my early-access scans…
3d
Inbound from the website contact form. Replies go out via your own email client — no bulk-send integration needed.
Compose a broadcast
Audience comes from the server's own accounts record (signup order), never the Resend contact list. Every send honours unsubscribes; {{unsubscribe_url}} in your HTML becomes each recipient's own link. Dry-run first — the Send button only unlocks for the exact composition you dry-ran.
OA
Olamide AgboolaOwner
olamide@riffl.app · Lagos, Nigeria
Sign out
Profile
Full name
Email
Timezone
Security
Password
Changed 3 weeks ago
Two-factor authentication On
Authenticator app
Passkey
Sign in without a password
Active sessions
MacBook · Chrome · this device
Lagos, NG · active now
iPhone · Riffl Ops
Lagos, NG · 2h ago
Windows · Edge
Abuja, NG · 5 days ago
Recent sign-ins
MacBook · Chromenow · Lagos
iPhone · Ops app2h · Lagos
Windows · Edge5d · Abuja
Your recent actions
Suspended scans · #4471
21m ago
Sent 142 early-access invites
Today, 09:12
Retried charge · #3390
Yesterday
Signed in from a new device
5 days ago
Riffl
OPS CONSOLE
Owner sign-in
Restricted to the account owner
Email
Password
Enter your email and password.
or
Two-factor code
Enter the 6-digit code from your authenticator app
Enter the 6-digit code.
Operational data only · encrypted user data is never accessible here