Operator access only.
Browser → Firebase identity and entitlement → Pages. Chat uses the OpenRouter proxy; voice uses the dedicated Mini with Modal overflow; microphone transcription uses Groq. Scripted reactions are static audio. No provider credentials reach this dashboard.
This read-only snapshot does not synthesize audio or warm Modal. Queue counts are instantaneous; instance counters reset on router restart. Readiness is a recent router observation, not an independent health test. Unknown is not zero.
Stripe — web subscriptions and payments ↗
Modal — overflow compute and billing ↗
Cloudflare — Pages, hybrid router and tunnel ↗
Firebase web entitlements authorize access; Stripe is the payment authority. App Store Connect covers Apple purchases only. Usage allowances share cap configuration across web and iOS; consumption ledgers remain separate. The iOS prompt editor does not alter web prompts.
Per-character prompt injection — rendered as <personality_update> in the leading system prompt. Additive: refines the character card, never replaces it. Max 1000 chars each. personality_overlays
Behavior corrections, rendered as <additional_guidelines> after the immutable bundled safety floor — can only tighten, never weaken it. Max 800 chars. safety_additions
Casual one-liners the characters can reference naturally in chat (<current_events>). One per line, max 12 × 160 chars. current_events
Overlays the app's bundled defaults. Blank a field to fall back to the bundled value. Doc: config/live
USD per user per day before the cooldown card gates chat, calls & LLM games. The app picks this up on next launch / foreground (≤5 min). Doc: config/freemium
TRY-ONLY: the proxy tries this override on each chat turn; any failure (unreachable, error status, or an empty reply) silently falls back to the hardcoded deepseek/deepseek-v4-flash-0731 + the audited provider allowlist within the same request — users never see a broken override. 3 consecutive failures trip a 5-minute breaker. Applies to standard chat turns only (vision + the app's own emergency fallback are never touched). Takes effect within ~1 min; no app update.
Use this when a provider is 429ing / 404ing / down. It never leaves an empty allowlist behind (if a kill would empty a pool, that pool falls back to open routing). Takes effect within ~1 min.
Per-pool overrides replace ONLY that rung's allowlist (the app tags each request with its rung). The ultra-wide/open rung and Gemini are never given an allowlist. Model must stay within the disclosed set (V4-Flash family + Gemini) — anything else is ignored by the proxy.
Message reports, bugs, ideas and developer notes from web and iOS, 50 per page. Report bodies are immutable; status and operator notes are editable. Reply email appears only when explicitly shared. Reference numbers match the user's receipt. Doc: message_reports
OpenRouter account spend and proxy / AI Gateway operational estimates from the operator-only telemetry endpoint. These are not web-only unit economics: Mini, Modal, Groq and Stripe have separate source records. Native analytics and App Store Connect do not measure the web funnel.
Provider records and native analytics — check platform, coverage and reporting window before comparing totals.
AI Gateway — chat volume / tokens / cost / latency / errors / providers ↗
App Store Connect — downloads, revenue, subscribers, conversion ↗
Firebase / GA4 — DAU / MAU, retention, sessions, events ↗
Proxy counters are best-effort operational estimates, not conversion, retention or invoice truth. Never add account-wide spend to its own per-request subset.
Every save from this dashboard, newest first. Revert restores the doc exactly as it was before that save (the revert is itself logged — history is immutable). Doc: config_audit