What has shipped.

Platform changes, SDK releases and security work, newest first.

Newest first.

  1. 0.1.1

    The API has its own address, api.measura.dev, and the SDK uses it by default.

    • ChangedSDKThe default endpoint is https://api.measura.dev/v1/ingest. Apps on 0.1.0 keep working unchanged.
    • ChangedDocumentationThe API reference uses https://api.measura.dev/v1/{function}.
  2. 0.1.0

    The Android SDK is on Maven Central as dev.measura:measura-sdk.

    • AddedSDKAdd implementation 'dev.measura:measura-sdk:0.1.0' to your app. No more emailed AAR.
    • AddedDocumentationThe install guide explains the Advertising ID permission and how apps for children remove it.
  3. Build milestone

    Campaign ROAS in the dashboard, revenue that nets out refunds, a dashboard that works on a phone, and a contact page.

    • AddedRevenueCampaign ROAS: attributed installs, purchase revenue and spend per campaign, with spend entered in the dashboard or pulled from a connected network.
    • FixedRevenueRefunds, chargebacks and disputes are now subtracted from revenue. They were previously added to it. Revenue reports gross, refunded and net per currency.
    • AddedDashboardThe developer dashboard works on phones: the sidebar opens as a drawer, and page headers and forms fit narrow screens. On desktop the sidebar collapses to icons.
    • AddedWebsiteA contact page with a form, routed to the team, replacing an email link.
    • ChangedDocumentationThe API reference was checked against the code and corrected: status codes, response shapes, plan-gated resources, team and invitation procedures, and the deferred link endpoint.
  4. Build milestone

    The Help assistant answers without an AI model, the Android SDK passed its publish checks on real devices, and the blog was rebuilt.

    • AddedHelpThe in-dashboard assistant answers from the documentation and your own workspace data with no AI model required, and hands a conversation to a person when it cannot resolve it.
    • FixedAndroid SDKNo crash on Android 5.x, an offline queue that drains in batches the server accepts, key resolution that retries, and Wi-Fi-only and low-battery settings honoured on every send. Verified on Android 5.0 and 11 against staging.
    • AddedAndroid SDKhandleDeepLink records a re-engagement when a Measura link opens an app that is already installed, and returns the in-app path.
    • ChangedBlogRedesigned blog with cover images and topics.
    • FixedWebsiteThe methodology page no longer collapses to a narrow column on phones.
  5. Build milestone

    Integrations were rebuilt around a full webhook lifecycle, and attribution and fraud gained detail views.

    • AddedIntegrationsPayment webhooks can be revoked, reactivated and deleted, and every integration is configured from one tabbed page.
    • AddedDashboardAttribution and fraud tables open a detail view with the full decision behind each row.
    • AddedAndroid SDKCollects the Google advertising ID when the user allows it; configurable with collectAdvertisingId.
    • FixedSign-inRefreshed sessions survive redirects, and Google and GitHub always show their account picker.
  6. Build milestone

    All three apps moved to Cloudflare Workers, and a security review was closed out.

    • ChangedHostingThe website and both dashboards now run on Cloudflare Workers.
    • SecurityAPISix findings from a security review closed, including stricter checks in the edge functions and on confirmed email claims.
    • FixedAndroid SDKA blank API key logs an error instead of crashing, and no queued event is dropped on flush.
    • ChangedDashboardDialogs trap keyboard focus, and admin tools are limited by staff tier.
  7. Build milestone

    Plans and billing, account closure, and an in-dashboard Help Center.

    • AddedHelpHelp Center in the dashboard: support conversations with the team, attachments, and feedback.
    • AddedBillingPaid plans with limits enforced on the server, upgrades, scheduled downgrades and usage tracking.
    • AddedAccountAccount closure with a 30 day recovery window, data erasure, and a full account export.
    • AddedSign-inWorking sign-up, and separate sign-in for customers and staff.
  8. Build milestone

    Revenue outside Play billing is attributed, and conversions are sent back to ad networks in their own formats.

    • AddedRevenuePayment webhooks for Paystack, Flutterwave, Stripe and any gateway, with a revenue page showing each payment matched to the install that produced it.
    • AddedPostbacksConversion postbacks in Meta, Google, Snapchat and TikTok formats, or Measura’s own JSON to any URL, with retries.
    • AddedAndroid SDKServer-controlled SDK settings with a remote kill switch, low battery fallback, uninstall detection through push tokens, and opt-in diagnostics.
    • AddedAttributionA later, stronger match now supersedes an earlier attribution instead of being discarded.
    • AddedDocumentationDocumentation search and machine-readable copies of the docs for AI tools.
  9. Build milestone

    The Android SDK gained a size budget that the build enforces, so the figure published in the docs cannot drift from what ships.

    • AddedAndroid SDKSize budget enforced on every build. The release archive is measured and the build fails if it exceeds the figure published in the docs.
    • FixedMarketing siteDuplicate import in the navigation component, and the Gradle version pinned to 8.7 for reproducible builds.
    • AddedDeploymentStaging deploy workflow, dormant until a staging project reference is configured.
  10. Build milestone

    Attribution gained a full decision trace, the Android SDK was hardened, and the dashboards were locked down.

    • AddedAttributionOrdered matching hierarchy: install referrer, then click identifier, then advertising identifier, then fingerprint, then organic. The first match wins.
    • AddedAttributionEvery attribution now stores the signals used, a written reason, and the candidate clicks that were rejected, so a decision can be audited after the fact.
    • AddedAttributionAtomic resolution with a uniqueness constraint per install plus an hourly reconciliation pass for orphaned records.
    • AddedAndroid SDKPlay Install Referrer integration, which gives deterministic attribution through the store install.
    • ChangedAndroid SDKReliability pass covering offline queueing, retry backoff and scheduler resilience.
    • SecurityDashboardsContent Security Policy plus a full security header set on both the admin and developer dashboards.
    • SecurityAPISigned request replay window narrowed to ten minutes, and tenant identity now read only from server controlled token claims.
    • AddedAdminAppend only audit log recording every administrative change with its previous and new values.
    • AddedMigrationImporter acceptance tests end to end, including historical attribution rows.
    • ChangedData retentionPartition drop path verified and unblocked, giving raw events a working ninety day window.
  11. Build milestone

    First hardening pass after an internal production readiness audit, covering ingestion, metering and rate limiting.

    • AddedIngestionBatched event ingestion with per event signature verification and idempotency keys for deduplication.
    • AddedBillingMonthly event metering with per plan caps enforced at ingest time.
    • AddedAPIDurable rate limiting on the deep link redirector and the key resolution endpoint.
    • AddedSecurityAPI keys stored as hashes only, with the plaintext value shown once at creation.
    • AddedAttributionRetrying postback delivery to configured advertising networks.
    • AddedDatabaseComposite indexes on the hot attribution paths, and correct handling of the all zero advertising identifier that signals a user opted out.