VPN customer intelligence · working brief
Build the whole customer story.
MN can see payments, product use, support and retention in separate places. The missing proof is whether those facts can become one trustworthy VPN journey—from the need before purchase to value, true cost and renewal.
Start with one real customer. Prove every link. Mark every gap. Then repeat the proven joins across equal-window cohorts and use prospective evidence to find the real ICP.
One chain.Observed · inferred
conflicting · unknown
01 · The gap
Six rooms can describe six different customers.
A payment row, a connection event and a support conversation can all be correct—and still fail to tell us what happened to the same person.
The actual questionCan MN follow one VPN customer from the promise that attracted them to the job they tried, the result they got, the money MN kept and the reason they stayed or left?
02 · First vertical proof
Reconstruct one customer from start to finish.
Choose the case by a frozen rule. Keep identity private. Build a chronological evidence map. Treat every unsupported bridge as a broken link.
How to use thisSelect a stage. The right side shows the question, minimum evidence and the failure that the trace must expose.
What brought this person here?
Which problem, trigger, channel, message, offer and promise preceded the first purchase?
Campaign or referral exposure, landing page, offer shown and any consented problem-intent signal. If MN did not retain this, record unknown.
Whether the eventual customer can be recognised before purchase—and whether acquisition claims survive contact with the actual source record.
Illustrative structure. This panel contains no real customer record. The production case stays inside MN’s approved source boundary and uses a stable opaque key outside it.
03 · What the trace earns
One case tests the system. It does not describe the market.
Primary outputThe valuable artifact is the broken-link register: what exists elsewhere, was never joined, was never generated, conflicts, or is legitimately restricted.
Whether the chain works.
- A payment can link to its refund and entitlement.
- A product failure was visible before support contact.
- Several conversations belong to one support episode.
- Support closure matches—or conflicts with—product recovery.
- Hidden labour and financial consequences can be attributed.
- The smallest trustworthy customer record can be defined.
How common or valuable the pattern is.
- The incidence of a problem across VPN customers.
- The average retained contribution of a segment.
- That a channel, offer or product change caused an outcome.
- That a memorable case is representative.
- That a realised good customer can be recognised prospectively.
- The real ICP. That requires cohorts and later validation.
04 · Evidence frontier
Enough exists to start. Some history can never be recovered.
Run the retrospective pass now. Keep irrecoverable fields unknown. Begin prospective collection at the same time.
Fastest safe pathUse existing account, payment, refund, churn, support and activity evidence first. Commission device semantics, customer-job evidence, labour and cost without waiting to learn from the first pass.
Historical fields that MN never collected cannot be reconstructed honestly. A plausible guess remains unknown. The fix is a new instrumented cohort, not a smoother story.
05 · Two independent verdicts
The VPN can work while the customer still fails.
Every eligible attempt needs two answers. Neither may silently stand in for the other.
Concrete exampleThe tunnel connects successfully, but the streaming service still blocks the customer. Technical success. Customer-job failure.
Technical service
Did MN establish and maintain the promised VPN service under an accepted definition?
Customer’s actual job
Did the real-world thing the customer needed to accomplish actually work?
A customer can keep paying even while the VPN repeatedly fails. A customer can receive a refund, later get the VPN working, and continue using MN. A customer can experience VPN failures without ever contacting support.
06 · Scale without self-deception
After the trace, compare every eligible first payer fairly.
Same entry period. Same follow-up window. Everyone stays in the denominator—including unknowns.
The cohort ruleDay 0 is the first source-owned settled payment that creates VPN entitlement. Follow every admitted account for day 0–7, day 0–90 and day 0–180.
inside a 1,970-account cut
Why this is not the ICP—or a proper Apple test.
The 150 were selected only because they formed the largest latest-country × latest-gateway × latest-plan cell. The other 1,820 accounts are a mixed remainder, not a matched non-Apple control. Apple gateway does not prove Apple device or iOS use. Keep the old cohort as a benchmark and falsification set; build the primary study from every eligible first payer in the same closed period.
07 · Real customer value
Revenue is only the first line.
A customer becomes commercially valuable only after the direct cost of winning and serving them is counted inside the same window.
Plain definitionA payment is what the customer paid. A fee is money a processor or store keeps for moving that payment. They are different sides of the same transaction.
Retained contribution
Count the work, the result and what happened next.
One conversation is a message container. One support episode is the whole problem from first signal through work, recovery, customer outcome and financial consequence.
08 · Commercial destination
Turn trustworthy outcomes into the real VPN ICP.
The goal is to recognise the right prospect before purchase, reach them profitably, promise the right job and keep delivering it.
Forward-ICP gateA later good outcome can reveal a candidate pattern. It cannot be used as the targeting signal. The final recognition rule must use lawful information available before purchase.
09 · Red-team the story
A complete-looking map can still be fiction.
Strongest attackEvery row can look plausible while referring to a different identity, time window, definition or event grain.
“The customer paid, support solved it, and they stayed.”
That sentence can be assembled from three true rows and still be false about one customer.
10 · Technical details, links and footnotes
The evidence underneath the page.
Proof stateThis page explains the current proposed method. It does not claim that MN has completed the one-customer trace, accepted the source semantics, built the cohort, found the ICP or authorised production action.
Minimum join contract
For every source bridge record: source system, source owner, source key inside the approved boundary, target grain, direction, cardinality, null and duplicate rates, time coverage, extraction time, definition version, consent or privacy boundary, and status: observed, inferred, conflicting or unknown.
Privacy rule
The case is worked inside MN’s governed boundary. Kairos outputs use aggregates or opaque keys. Names, emails, raw account IDs, browsing content and unnecessary support text do not leave the authorised source environment.
Working glossary
- ICP
- Ideal customer profile: the prospect MN can recognise before purchase and serve profitably.
- Customer job
- The real-world result the customer hired the VPN to achieve.
- CAC
- Customer acquisition cost: attributable spend required to win the customer.
- Event grain
- The unit one row describes: account, payment, attempt, conversation, episode or transition.
- Retained contribution
- Payments left after direct acquisition, payment, service, support, refund and risk costs.
- Unknown
- A required fact not supported by the current evidence. It is an outcome state, not a failure to fill a box.
Canonical working sources
The full evidence trail lives in the vault. These links open the current synthesis rather than copying it into a second drifting record.
Footnotes
- The 1,970-account cohort is survivorship-selected and remains a benchmark or falsification set, not the primary study population.
- The 150-account subgroup was the largest latest-country × latest-gateway × latest-plan-family cell. Apple gateway is not Apple device or iOS evidence.
- Current source visibility supports a useful retrospective 90/180-day study, but customer-job success, full event-time device semantics, labour and customer-window cost require commissioning or prospective collection.
- One case can test join integrity and falsify system assumptions. It cannot estimate incidence, average economics, causality or ICP.
- The independent blind portfolio reconstruction has no verdict in the current dossier; this page is therefore an internal explanatory artifact, not independent certification.
- Active scope is consumer VPN only. GoProxies and proxy customers remain parked until the VPN programme reaches its diminishing-returns gate.