The model, the money, the metrics that would tell us to stop, and the legal obligations that gate launch. emealia is a one-person product with a fixed cost base measured in tens of euros a month — which is a real strategic asset, because it makes the honest positioning affordable.
| Layer | What | When |
|---|---|---|
| Base plan | The full core loop — logging, bands, AI parsing, contributions, multi-meal, history, statistics, weight, all 32 nutrients, daily tips. Everything. | Launch |
| emealia Plus | An add-on layer: recipe suggestions, photo logging, advanced statistics and export, "level up a meal". May only ever add new surfaces; may never gate the core loop or nutrient data. | Only once D7 ≥ 30% |
| Micro-transactions | Not used. Stripe's fixed fee kills the economics at €1; a recurring add-on wins. | Never |
Premium-candidate features are instrumented through UsageMeter from day 1 — invisibly, and free to the user. Contributions should be instrumented this way too, even though they cost nothing to run. If it turns out to be the feature people open the app for, that is worth knowing before the Plus scope is decided.
| Market | Trial | Monthly | Annual | Save |
|---|---|---|---|---|
| Germany | 30 free AI estimates · no card | €5.99 | €39.99 | −44% |
| USA | 30 free AI estimates · no card | $6.99 | $44.99 | −46% |
| Product | Annual | Multiple of emealia |
|---|---|---|
| emealia | €39.99 / $44.99 | 1.0× |
| Cal AI (pre-wind-down) | $29.99 | 0.7× |
| Lose It! | ~$39.99 | 0.9× |
| Lifesum | ~$45 | 1.0× |
| Cronometer Gold | $49.99 | 1.1× |
| MacroFactor | $71.99 | 1.6× |
| MyFitnessPal Premium | $79.99–99.99 | 1.8–2.2× |
| Yazio (DE list) | ~€83.90 | 2.1× |
| Noom | ~$319 annualised | 7.1× |
The trial grants N free AI estimates (default 30, held in runtime admin config and changeable at any time) rather than a 168-hour countdown. Three reasons:
Credits are granted at the first real estimation, not at signup, and no card is taken up front. A multi-meal batch costs one credit, not one per meal.
Six occurrences of "7 Tage" on the German landing page described a trial the product does not offer. The rebuilt landing page states the 30-credit trial everywhere, in both languages. Still outstanding: 3-design.md's copy standard references a "7-day-trial CTA" and needs the same correction.
The July analysis recommended downgrading trial users to a cheaper model to cap variable COGS. That recommendation was rejected, and the reasoning is worth keeping. AI estimation error is roughly 25–35% on mixed dishes on any model — a flagship buys no honest accuracy at this task. So a downgrade would save a fraction of a cent while making the trial worse than the paid product the user is being asked to buy. Same model throughout, at ~$0.004 per estimate.
| Component | Tokens |
|---|---|
| System prompt including the strict JSON schema for macros and micronutrients | ~450–600 in |
| User metadata (age, weight, activity) for relative need | ~80–120 in |
| The meal description itself | ~60–80 in |
| Structured output — the range design roughly triples the numeric fields | ~550–650 out |
| Total per detailed estimate | ~1,150–1,450 |
The output ceiling scales with the multi-meal segment cap (8 × ~1,400 measured per-meal tokens). max_tokens is a ceiling, not a bill — real cost scales with segments actually emitted — but truncation must fail loudly rather than silently retry billed calls, after an incident where a flat ceiling truncated a single-meal response.
| Stage | Topology | Cost |
|---|---|---|
| Beta | Lambda Function URL + SQS worker + private RDS + a NAT instance; frontend on CloudFront/S3, public site on All-Inkl | ~$30–35/mo |
| Production | ECS + ALB — only once traffic justifies the fixed cost | Higher fixed, better at scale |
| Region | eu-central-1 — EU data residency is a product claim, not just a config choice | — |
Total fixed cost including third-party services is ~$56–63/month at 100 users, which is what puts break-even at 13–15 paying subscribers. This is a strategic asset: a product that breaks even at fifteen customers can afford to refuse the revenue mechanics — paywall creep, win-back discounts, data brokerage — that its competitors depend on.
The July analysis proposed an embedding-based semantic cache for 40–60% variable-cost savings. Rejected on privacy grounds — it means a second processor seeing meal text, against the single-DPA posture that is itself a purchase argument in Germany. The savings were real; the trade was not worth it.
| Metric | M3 | M6 | M12 |
|---|---|---|---|
| D7 retention | ≥25% | ≥30% | ≥38% |
| Meals / active user / day | ≥1.5 | ≥1.8 | ≥2.0 |
| Trial → paid | ≥10% | ≥12% | ≥15% |
| AI correction rate | <40% | <30% | <25% |
| Daily tip open rate | ≥15% | ≥20% | ≥25% |
North star: weekly active loggers with ≥4 logging days per week. Not meals, not weight change, not time in app.
Pre-committed responses, written down before the data arrives so they cannot be rationalised away afterwards.
| Condition | Action | Currently observable? |
|---|---|---|
| D7 < 20% after 200 users | Stop acquisition, redesign the core loop | Yes |
| AI correction rate > 50% | Fix parsing and portion defaults before scaling | Needs G2 |
| Daily tip opens < 15% | Coaching cadence or copy not landing → rework | No — nothing delivered |
| AI cost > €0.08/user/month | Audit every AI call — something is leaking | Partial — observability 2/4 |
| Trial → paid < 5% | Rework onboarding and value proposition before scaling marketing | Yes |
| Recurring reviews mentioning obsession or anxiety | Reduce number visibility further; re-audit contribution copy first | Yes |
eu-central-1), one AI processor, a signed DPA. No fan-out to a second model provider — deliberately, and it is the reason semantic caching was rejected.People must be clearly informed when they interact directly with an AI system, at the appropriate point in the user journey, and disclosures must be accessible rather than buried.
emealia already complies in substance — every estimate is labelled an estimate and shown as a range rather than false precision, which is more than the notice requires. What is missing is the notice itself: an AI-interaction disclosure at onboarding and at the meal-input surface. This needs a line item next to the GDPR epic. It is also a marketing asset: "the estimate is honestly labelled because that is what the law and the science both require" sits well beside DSGVO in Germany.
A secondary benefit of the deterministic tip library: you can prove which rule fired, which is exactly the auditability Art. 50 rewards.
Blocked on legal counsel (H10)
emealia is positioned as a general-wellness / informational product — not a medical device and not medical advice, resting on the EU MDR general-wellness exemption and the FDA General Wellness policy, and staying clear of the German HWG by making no disease-treatment or prevention claim anywhere.
Terms pending sign-off: informational and educational purposes only · general wellness · not a medical device · not intended to diagnose, treat, cure, mitigate or prevent any disease · no doctor–patient relationship · no reliance.
Counsel decides three things: whether an explicit acknowledgment checkbox is needed at registration, the exact lawful basis for any Art. 9 health data that lands in the free-text context field (a disclaimer does not switch off Art. 9), and the final wording. Draft copy and placements are in Design.
The FTC reopened click-to-cancel rulemaking in March 2026 and roughly 30 US states have their own auto-renewal laws. emealia's no-win-back-discount policy already exists; the remaining work is to make one-tap cancellation visible and say so publicly. Against Noom's >1,200 BBB cancellation complaints and MyFitnessPal's class action, cancellation is a marketing feature rather than a compliance chore.
| Mechanism | Status |
|---|---|
| Social-only authentication (Google + Apple) — outsources bot and fake-account detection to the platforms at no cost | Documents disagree — see the gap list |
| Hard credit cap (30 estimates) instead of a time window | Shipped |
| Per-user daily caps and a max-meals-per-batch limit | Shipped |
| Disposable email-domain blocklists | Available if an email path ever exists |
| Device fingerprinting | Rejected — GDPR and consent conflict |
These cannot be delegated. Everything else in the plan is unblocked around them, per the "0.0 is a paradigm, not a blocker" rule — build against fakes and placeholders until a real setup is genuinely needed.
| Action | Why it blocks |
|---|---|
| Set the Anthropic monthly spend cap in Console | Before any key is used in production. The only hard stop on runaway AI cost. |
| Sign the Anthropic DPA | Before the first EU user's data reaches the API |
| Add Impressum §5 DDG | Legal entity details, required for the German market |
AWS account in eu-central-1 with Budget Alarm + Cost Anomaly Detection | Cost containment for a one-person operation |
| Auth0 EU tenant — Google + Apple Sign-In | Blocks the auth epic; also settles the email/password contradiction |
ANTHROPIC_API_KEY in GitHub repo secrets | CI |
| Run G1 — band comprehension, 5 testers, ≥3/5 unaided and now including the contribution list | Was required before the Today UI was finalised. The UI is finalised. |
| Run G2 — AI calibration, 30 real meals (15 DE / 15 US), correction rate <40% | Gates acquisition spend |
| iubenda privacy policy + ToS (GDPR + CCPA) | Launch blocker |
| Medical / general-wellness disclaimer sign-off (H10) | Launch blocker — the whole positioning rests on wording nobody has approved |
| Fix the trial mismatch on the public site | Legal exposure; gates all acquisition spend |