# VPNCheap Apple TV Customer Feedback Improvement Plan

Date: 2026-07-31  
Mode: planning only  
Plan confidence: **86/100**. Prove the refresh-performance fix on TV hardware and unify node freshness without exceeding the extension or remote-control budget. This is an executive judgment score, separate from fingerprint priority.

Governing contract: [Feedback-to-Roadmap Decision Contract v1.0, 2026-07-31](https://vpncheap-feedback-brief-20260731.pages.dev/feedback-to-roadmap-decision-contract.md)

## Evidence and state

- **OBSERVED:** refresh appeared unresponsive or hung.
- **MEASURED:** regex caching reduced the benchmark from 7.28s to 0.081s and unit tests pass.
- **OBSERVED:** no post-fix hardware/store-build receipt exists; cross-client no-node recurrence remains.

`△△ ☐☐ | 0/2/2/0`

| State | IDs | Local obligation |
|---|---|---|
| `△` | VPN-04, VPN-12 | Refresh and self-heal implementation exists; real-device proof is missing. |
| `☐` | VPN-17, VPN-13 adoption | Shared freshness and signed capability are not end-to-end. |

```text
BEFORE  remote click -> frozen frame -> uncertain result
AFTER   immediate state -> bounded work -> nodes or reason -> retry
```

## Execution sequence

Order follows dependency and owner sequence, not numeric rank. Canonical fingerprint scores and program-value judgments are different decision ledgers and are not directly comparable.

Canonical references, not local rescores: item 1 -> VPN-04; item 2 -> VPN-12; item 4 -> VPN-13. Item 3 is a separate program-value judgment.

### 1. Hardware refresh acceptance: 65/100, P2

Breakdown: `16 + 7 + 12 + 10 + 10 + 10`.

**PROPOSED:** verify current store build on representative Apple TV hardware for cold launch, refresh, large node list, endpoint failure, cached recovery, memory pressure, focus continuity, and repeated connect/disconnect.

### 2. Cross-client node-state matrix: 81/100, P1

Breakdown: `24 + 15 + 12 + 15 + 5 + 10`.

**PROPOSED:** join the shared fresh/existing login, stale path, empty-list, retry, and account-switch matrix while keeping tvOS-specific focus and memory acceptance.

### 3. Visible freshness contract, program value: 78/100

**PROPOSED:** show fetching, cached, stale, empty, and recovered states with one D-pad action; consume Xboard generation/revision without forcing re-login.

### 4. Signed capability adoption: 54/100, P3 evidence gate

Breakdown: `24 + 3 + 5 + 15 + 0 + 7`.

Adopt only after Xboard freezes the contract and the tvOS identifier is inventoried. UA-only authorization scores **18/100**.

## Phases and acceptance

- **0-30:** hardware/store-build verification and state-contract design.
- **31-60:** fix failed cases; add focus, memory, cache, and failover tests.
- **61-90:** canary and track refresh duration, hang, no-node, retry success, and extension termination.
- `○` requires real hardware, stable focus, extension memory within the verified budget, and changed public egress after connection.

### Phase gates

- **0-30:** evidence coverage reaches 100%.
- **31-60:** every scheduled P1/P2 acceptance is complete or explicitly approved `X`.
- **61-90:** two canary windows close without regression.
- Stop immediately on any listed guardrail.
- P3 acceleration requires the governing-contract exception and never displaces P0-P2.

## Guardrails

- Common actions remain within two D-pad presses; no continuous animation.
- Keep the PacketTunnel extension within the proven memory budget.
- Never expose ingress detail or protocol; nodes remain lists.
- Core/NetworkExtension owns connection truth; no supervisory auto-teardown.
