The three decisions, the machinery, and the guardrails
Five chapters, nine minutes. Three decisions move the migration rate — who moves, when, and on what offer. This act opens with them, then the machinery that makes each one: the cut, the gates, the surfaces that arrive with the billing whether you planned for them or not, and how the real risk is bounded. All of it holds whoever runs it.
Get the one-page summary, written for your role.
The decisioning
Selection is most of the outcome. Timing is most of the rest.
Who moves
The base is cut into cohorts on what predicts acceptance, and the same cut decides who is never approached at all. The cohort that would churn if touched is the cohort that never gets touched — the next chapter is the cut itself.
When
Renewal proximity, engagement windows, and each cohort’s own rhythm decide the send. A subscriber a week from renewal and a subscriber who has not opened the app since March are different conversations on different days.
The offer
Price parity is the posture: the same plan at the same price, on a different rail. Where inertia needs breaking, a one-time sweetener does it — a credit, a bonus month, an annual upgrade — priced as a one-off cost against the margin it recovers and proven on the holdout before it scales. Never a lower recurring price, and never a discount campaign.
Every wave’s results feed the next wave’s decisions — which cohorts responded, which offers paid for themselves, which timing landed. The model running wave six is measurably better than the one that ran wave one, and it is better on your book specifically rather than on an industry average.
Cohorting the base
The base is never one thing, so it is never treated as one.
Six axes in
Tenure
Long-tenure subscribers accept at materially higher rates.
Plan tier
Annual and monthly are different conversations on different calendars.
Engagement
Recent, active use is the strongest single predictor of acceptance.
Renewal proximity
The window where a billing change is expected rather than intrusive.
Risk profile
Cancellation and dispute history — who is held for a later wave.
Reachability
Private-relay and stale addresses bound who can receive wave one.
Approached
The engaged, reachable, renewal-proximate book. This is the population every figure in this playbook is modelled on.
Never approached
Dormant, at-risk and unreachable subscribers. Excluded by design, left on store billing, and excluded from the model rather than assumed into it.
Not every subscriber has to move for the arithmetic to work — chapter 05 priced that in. The excluded tail keeps renewing exactly as it does today.
Most failed migrations fail the same way: the whole book gets the same offer in week one, churn spikes before anyone measures it, and the work is dead by week three. Selection is the defence, and it is structural — it happens before a single email sends.
The wave engine
Fire a measured slice, read the gates, size the next wave.
Gate 01
Migration rate
Below floor, the cohort pauses rather than pushing harder.
Gate 02
Holdout-relative churn
A basis-point delta, set per app — plan mix and tenure move the honest threshold.
Gate 03
Billing health
Authorisation rates, involuntary churn, recovery on failed payments.
Gate 04
Support load
Tickets per thousand migrated, measured per cohort against an agreed ceiling.
Healthy cohorts earn acceleration; struggling ones pause themselves. Subscribers who do not move are re-approached in later quarterly waves, and nothing changes in the meantime for anyone still on store billing.
The surfaces
The stores never just billed. They ran your billing UX and absorbed your billing support.
Surface one · billing account
Plan changes, payment methods, invoices, cancellation — self-serve, in your brand, on your domain.
Load-bearing, because the failure mode is expensive: a subscriber who cannot find cancel does not stay — they dispute, and disputes cost more than the subscription.
Surface two · billing support
Migration, billing and cancellation guidance that never sends a subscriber back to the store.
Migration creates a support spike by design. A help centre is what turns that spike into reading instead of tickets.
Entitlements
Web billing state syncs into RevenueCat, Adapty, Firebase or your own service — the app never learns where the renewal happened.
The one blocker
A purely StoreKit-native entitlement layer with no server-side source of truth. A readiness check catches it before anything is scoped.
Cancellation law
Off-store, it is yours: US click-to-cancel, California’s renewal disclosures, Germany’s cancellation button. Surfaces ship region-aware.
The guardrails
The honest name for the risk is induced attrition — the touchpoint that turns a quiet renewal into a cancellation.
The dormant subscriber
The sharpest version of the fear: paying quietly, not opening the app, gets a billing email and remembers to cancel. So dormant cohorts are excluded from outreach by design. Migration targets the engaged book, where response is high and wake-risk is low.
The holdout
Every wave runs against a matched store-billing holdout. The delta isolates campaign-caused churn from background churn, visible the same day on a live dashboard rather than argued about afterwards.
No coverage gap
The web subscription activates before anyone cancels a store subscription, with double-subscription detection and support follow-up. Apple and Google sign-in are first-class at checkout — no password wall at the auth step.
Involuntary churn becomes managed
The stores’ retry machinery is fixed and invisible. On web it is operations: retries timed to issuer behaviour, card-updater coverage as wallets refresh, pre-dunning before a charge fails, recovery after.
Stopping is a decision, not a project
Nothing in the app changes, so there is no integration to unwind. Stop mid-program and the next wave simply does not send — everyone already migrated keeps billing on a Stripe account you own.
Compliance rides the same rails. The whole path runs outside the app — email and owned channels in, branded web checkout out — which Apple’s guideline 3.1.3(b)7 and Google Play’s payments policy8 permit directly. The binary never changes.
You now have the whole method, and it belongs to nobody in particular. Act IV is the decision it leaves you with — build it or buy it — and then, plainly, our case for being the buy.
7 Apple App Review Guideline 3.1.3(b) — reader and multiplatform services; outside-of-app purchase.
8 Google Play payments policy — external offers and out-of-app transactions.