AI in the authoring loop — not the send loop

Your push strategy needs a standing owner. Almost no app has one.

PushNotifAI reads your behavioral data every week and proposes notification flows with the diagnosis attached. You approve. A deterministic engine executes every send over our own APNs pipe — and a permanent holdout tells you whether it's actually working.

Every individual send traces to a rule you can read.
Built for consumer iOS · 10k–1M MAU
Own APNs pipe, HTTP/2 & ES256 NSE true delivery telemetry Postgres only — deliberately boring <1 hr to first event
The problem

Push is the highest-leverage retention channel on iOS. Almost every app abuses it.

Three failures compound — and no existing tool is built to fix any of them.

The rules go stale by construction

An engineer set up push during onboarding week and never looked again. The users changed, the product changed, the cadence rules didn't. Braze and OneSignal execute a strategy brilliantly — they have no opinion on whether it's still the right one.

Everyone measures the wrong thing

Tools report CTR and opens on sends — an unfalsifiable number. A push that interrupts someone about to open the app anyway scores a "conversion." Most reported lift is cannibalized organic engagement, and virtually nobody runs the holdout that would reveal it.

Permission is non-renewable, treated as free

On iOS a revoked notification permission is an absorbing state — no in-app recovery, the user won't dig into Settings. Every send carries a small chance of permanently destroying the channel. Tools hand you one frequency cap, set by guess, never revisited.

How it works

The AI authors the strategy. A human approves it. The engine never improvises.

The intelligence sits where it belongs — in the weekly analysis, not in the per-send decision. Everything downstream of approval is deterministic and auditable.

01
Observe
The SDK streams events. The system watches — no flows exist yet, so nothing sends.
02
Propose
A weekly job reads cohort data and drafts flows as diffs, each with its diagnosis and evidence.
03
Approve
You review a handful of proposals. Approve, edit, or reject. Nothing ships unseen.
Human in the loop
04
Execute
Match → filter → select → schedule, re-validated at fire time. Every decision is logged.
05
Measure
Each flow runs against a holdout. Underperformers get flagged for retirement automatically.
The core interaction

A proposal you can actually argue with.

The AI's output isn't an invisible per-user decision — it's a reviewable artifact. Every proposal carries the diagnosis that motivated it, so the whole trust problem collapses into a yes/no you can defend.

  • The diagnosis is a first-class field, not documentation. In six months it's the only thing that explains why a rule exists.
  • Retirement proposals matter as much as creation. The failure mode of every rules engine is accumulating rules nobody deletes — so the AI actively proposes removals.
  • It won't overclaim. When the data is thin, it says "insufficient evidence" instead of manufacturing a narrative from noise.
  • You author the copy. The AI composes the targeting, timing, and cadence around your own templates — never the words.
Proposed · retire Flow #7

The re_engage_day_14 flow has run for 9 weeks. Treatment opens are flat against its holdout, and organic sessions are down 3% in treatment — the flow is quietly suppressing the behavior it was meant to lift.

recommendation retire
evidence holdout Δ opens +0.1% (n.s.)
  organic session rate −3.0% vs holdout
confidence high
Retire flow Keep Inspect

A loss disguised as a win — caught because the holdout watches organic behavior, not just sends.

Full funnel · per send
Sent
100%
Accepted
97%
Delivered
82%
Opened
41%

Delivered is real, not inferred. APNs only ever confirms it accepted a push — the Notification Service Extension that ships with our SDK fires a beacon when the payload is processed on-device. No API-only integration can measure this.

The permanent holdout

A stable, hash-assigned slice of users receives nothing, ever. It's how you tell a program that's working from one that's quietly harmful — and it's non-negotiable, because notification-attributed opens are largely cannibalized organic opens.

Measurement

We report incrementality, not attribution.

The dashboard will never show you "notifications drove 40k opens." It shows lift against a control — with honest confidence intervals, and the word "not yet significant" when that's the truth.

  • Guardrails that catch slow poisoning: opt-out rate, token-invalidation rate as an uninstall proxy, and organic session rate in treatment vs. holdout.
  • A decision inspector for any user: which flows matched, which won, what was suppressed and why. The trust surface — and the debugging surface.
  • Quiet hours defer; caps and cooldowns suppress. We never cancel a wanted notification just because it's 3am — we hold it until morning.
Who it's for

Built for the founding engineer who owns push and has no growth team.

A fit if you're

  • A consumer iOS app between 10k and 1M MAU, seed to Series A — enough event volume to analyze, no lifecycle marketer.
  • Shipping real behavioral events already, and tired of push rules nobody has revisited in a year.
  • Willing to spend five minutes a week approving proposals — and nothing else.
  • Done being told a number you can't falsify. You want to know if push is actually working.

Not the fit

  • An enterprise with an existing Braze contract and a feature checklist.
  • Looking for Android, email, SMS, or a visual journey-builder canvas today.
  • Wanting AI to write your copy — that's the customer's job here.
Early access

Give your push strategy the owner it never had.

We're onboarding a small set of consumer iOS apps. Leave your email and we'll reach out with an integration key and a walk-through.

Single-tenant, invite-only for v1. No credit card, no sales call unless you want one.

Thanks — request noted. Your mail client should open so you can send it our way. If it didn't, email us at vik.devmail@gmail.com.