# VPNCheap Android TV Customer Feedback Improvement Plan

Date: 2026-07-31  
Mode: planning only  
Plan confidence: **86/100**. Verify the node-loading fixes on real TV hardware and make every refresh state explicit and recoverable. This is an executive judgment score, separate from fingerprint priority.

Governing contract: [Feedback-to-Roadmap Decision Contract v1.0, 2026-07-31](https://vpncheap-feedback-brief-20260731.pages.dev/feedback-to-roadmap-decision-contract.md)

## Evidence and state

- **OBSERVED:** v2.0.25 could not load nodes.
- **MEASURED:** mirror failover, stale-path self-heal, and fresh-login loading fixes exist; tests pass.
- **OBSERVED:** later cross-client no-node recurrence means code evidence alone is not closure.

`△△ ☐☐ | 0/2/2/0`

| State | IDs | Local obligation |
|---|---|---|
| `△` | VPN-10, VPN-12 | Implementation exists; current store-build and device/network proof is missing. |
| `☐` | VPN-17, VPN-13 adoption | Shared freshness and signed client capability are not complete. |

```text
BEFORE  refresh pressed -> silence/spinner -> re-login
AFTER   fetch stage -> safe reason -> retry/cache path -> verified nodes
```

## Execution sequence

Order follows dependency and owner sequence, not numeric rank. Canonical fingerprint scores and program-value judgments are different decision ledgers and are not directly comparable.

Canonical references, not local rescores: item 1 -> VPN-10 and VPN-12, each 81; item 3 -> VPN-17; item 4 -> VPN-13. Item 2 is a separate program-value judgment.

### 1. Node-state release matrix: 81/100, P1

Breakdown: `24 + 15 + 12 + 15 + 5 + 10`.

**PROPOSED:** verify fresh/existing login, cold boot, process reclaim, primary endpoint blocked, mirror failover, stale cached subscription, empty result, manual retry, and account switch on current TV hardware and store build.

### 2. Refresh lifecycle and reason model, program value: 79/100

**PROPOSED:** publish fetching, cached, stale, empty, auth-expired, endpoint-unavailable, and recovered states. Every state has one remote-friendly action and a safe diagnostic code.

### 3. Shared freshness contract, canonical VPN-17 reference: 81/100, P1

Canonical registry breakdown, reference only: `24 + 15 + 12 + 15 + 5 + 10`.

**PROPOSED:** adopt server generation/revision and last-success metadata without forcing re-login; preserve a bounded stale cache when the service is unreachable.

### 4. Signed capability adoption: 54/100, P3 evidence gate

Breakdown: `24 + 3 + 5 + 15 + 0 + 7`.

Proposed-only score is capped at 54. Inventory the current TV identity before adopting Xboard's signed contract; user agent alone is never authorization.

## Phases and acceptance

- **0-30:** freeze the matrix and state/reason contract; test current release on real TV and constrained network.
- **31-60:** fix only failed matrix paths; add lifecycle, failover, cache, and focus tests.
- **61-90:** canary and monitor no-node, refresh-duration, retry-success, and re-login-required events.
- `○` requires nodes displayed and a real tunnel transition plus changed public egress on hardware.

### Phase gates

- **0-30:** evidence coverage reaches 100%.
- **31-60:** every scheduled P1/P2 acceptance is complete or explicitly approved `X`.
- **61-90:** two canary windows close without regression.
- Stop immediately on any listed guardrail.
- P3 acceleration requires the governing-contract exception and never displaces P0-P2.

## Guardrails

- Common actions remain within two D-pad presses; no continuous animation.
- Preserve node list presentation and conceal protocol and ingress details.
- Core/OS state remains authoritative; UI recovery cannot synthesize a connected state.
- Stop on refresh deadlock, auth loop, cache overwrite, or sensitive diagnostic output.
