Platform services
exo-analyze
Exo-owned product analytics — one funnel from visit to margin, with PostHog as a swappable adapter.
Source: ADR 0006, accepted (owner-approved) on 2026-09-27. It is on main and not yet on
staging: read it on main.
Roadmap: product-analytics.
Why
RevenueCat and Stripe only report payments. Without visits, sign-up conversion, and cost to serve, Exo cannot compute per-App unit economics or margin. Letting each App wire its own analytics platform would repeat the integration per App and scatter the data.
Decision
-
Ingestion and schema live in Exo's Convex backend, partitioned per App and per environment. Apps send events to one Exo endpoint through a thin SDK (web and Expo).
-
Exo stores the funnel end to end:
visits → sign-ups (Exo Key) → paid (RevenueCat / Stripe webhooks) → cost to serve (exoAiBrokerJobs + exo-verify + infra)That join gives per-App acquisition, conversion, revenue per user, and margin.
-
PostHog sits behind Exo as a swappable adapter for dashboards and session replay. Plausible and GA4 remain possible adapters.
-
Apps never integrate an analytics platform directly.
Unit economics
- Today's event volume fits PostHog's free tier (~1M events/month). The incremental cost is Convex storage and function usage for the event table, expected to be a few dollars per month.
- Each App's dashboard reports cost per active user and gross margin per paying user.
- Beyond the free tier, Exo can sample or aggregate before forwarding to the adapter, while keeping full-fidelity funnel counts in Convex.
Alternatives considered
| Option | Why not |
|---|---|
| Per-App PostHog, Plausible, or GA4 | No cross-App funnel, no join to Exo Key or exo-router cost, and vendor lock-in in every codebase |
| PostHog as system of record | Ties the revenue and cost-to-serve joins to a vendor schema |
| RevenueCat and Stripe only | The status quo: payments without the top of the funnel or cost |
Consequences
- Exo ships and versions the analytics SDK, and exo-deploy bakes it into the mobile template.
- Event schema changes are platform decisions, reviewed like any other Exo contract.
- Privacy and consent handling (cookie banners, data deletion) is centralized in Exo.
Status
Accepted; planned. Event schema, SDK, and endpoint: TBD.
Source: content/docs/platform/exo-analyze.mdx
exo-verify
Code verification as a platform service — a verify contract, sandboxed runs, live staging checks, and an AI review pass.
exo-router
Exo's smart model routing — one metered AI egress where an assessor scores each task, the utility function weighs capability against cost, and the Convex AI Gateway executes. Apps never hold provider keys.