.png)
Al-Dalilah
Offline-First Desert Navigation & SaaS Platform — In-App Subscriptions, Hardware Anti-Abuse & Cloud Operations
My Role on This Project
I worked as the Android Engineer on this project. I was brought in to modernize, refactor, and scale an existing Android navigation app. My main responsibilities were migrating the business model from a legacy one-time purchase to a recurring SaaS subscription model, implementing server-backed anti-abuse security, building an offline-first data sync engine, fixing weak-network freezes, and creating a full-stack admin dashboard with an automated analytics pipeline.
Project Overview
Al-Dalilah is a native Android utility built for desert travelers, off-roaders, and field workers operating in harsh, low-connectivity environments. The original application used a simple one-time payment and lacked cloud synchronization or centralized management.
The goal of this project was to transform the app into a reliable SaaS product without compromising its core offline reliability. I upgraded the billing infrastructure to Google Play Billing v6, secured the free trial against abuse using hardware identifiers, enabled offline-first waypoint storage, and built a dedicated web dashboard backed by an automated daily ETL pipeline to monitor revenue, crashes, and active users.
Key Metrics
Zero Freeze
Zero Freeze
Timeout guards prevent ANRs on weak or dead networks
100% Offline
100%
Waypoints saved locally in Room DB before cloud sync
2-Key Security
2-Key
ANDROID_ID + App Set ID hardware validation against trial abuse
24h Automated ETL
24h
Daily pipeline syncing Google Play, GA4, and Crashlytics
Key Features
System Architecture
1. Subscription & Entitlement Guard
Integrated Google Play Billing Library v6 to manage auto-renewing subscriptions. Built an internal EntitlementManager that checks purchase tokens against local encrypted cache and Google Play APIs. Premium features are locked behind reactive state checks, ensuring immediate updates when subscriptions renew, expire, or get canceled.
2. Hardware Anti-Abuse Engine
To offer a 3-day free trial without forcing user registration, I engineered a dual-key fingerprinting mechanism:
- •Combines ANDROID_ID with Google App Set ID.
- •On first launch, queries Firestore to verify whether this hardware pair has ever claimed a trial.
- •If valid, activates a timestamped trial lease. If already used, the app routes straight to the paywall.
3. Legacy VIP Data Migration
To protect goodwill with existing customers who purchased the legacy version:
- •Snapshot listeners query Firestore for legacy purchase records.
- •Validated users receive an encrypted local VIP token stored in EncryptedSharedPreferences.
- •The check runs once, caches securely, and requires zero network access on subsequent launches.
4. Offline-First Persistence & Sync
Built a repository layer backed by Room Database:
- •All point additions, edits, and favorites write to the local SQLite database first.
- •A background sync worker detects connectivity and pushes local changes to Firestore using a timestamp-based conflict resolution strategy.
5. Cloud Admin Dashboard & Daily ETL Pipeline
- •Admin Dashboard: Built with React.js and Node.js, providing the business owner with a live view of active subscribers, trial conversions, and an emergency manual override for VIP access.
- •ETL Pipeline: A scheduled GitHub Action executes a Node.js script every 24 hours to pull data from Google Play Developer API, Google Analytics 4 (GA4), and Firebase Crashlytics, aggregating everything into a clean Firestore analytics collection.
Challenges & Learnings
Challenges
- •Trial abuse prevention without account logins: Solved by pairing ANDROID_ID with App Set ID, striking a balance between user privacy and fraud protection.
- •App freezing on spotty desert connections: Billing queries and Firestore listeners previously blocked app startup on weak connections; resolved by wrapping network calls in defensive coroutine timeouts with fallback to cached states.
- •Offline migration for legacy paid users: Designed a secure, tamper-proof local cache using EncryptedSharedPreferences so paid status persists even without cellular coverage.
- •Fragmented operational data: Solved the need to manually check multiple developer consoles by centralizing Play Console, GA4, and Crashlytics data into one dashboard via automated scripts.
Learnings
- •Production Google Play Billing v6 lifecycle handling, purchase token verification, and subscription state management.
- •Designing robust offline-first mobile architectures with Room, coroutines, and remote Firestore synchronization.
- •Implementing Android security standards using EncryptedSharedPreferences and hardware identifiers.
- •Building automated data collection workflows (ETL) using Node.js and GitHub Actions.
Future Scope
Gallery
.png)

