The brief
An established mobile-security company came to us with what looked like an engagement problem.
Its paid customers were renewing their subscriptions, but many rarely opened the app. Product analytics showed a familiar pattern: people completed setup, checked the app for a short period, then stopped returning. The company could see retained subscriptions alongside low active use, but it could not tell what that combination meant.
One interpretation was that customers had lost interest and might cancel later. Another was that the app was doing its job quietly. A security product is not a fitness tracker or a social network. Frequent visits may indicate value, but they may also indicate worry, confusion or repeated problems. Low activity may signal neglect, or it may mean the customer feels protected.
The product team had responded by increasing reminders and reassurance messages. Customers were told that checks were running, threats had been assessed and their protection remained active. Open rates were monitored closely. More messaging generated more app visits, which appeared positive on the dashboard.
The team was less certain that it was good for the customer.
Usability.ie was asked to help answer a more useful question than “How do we increase engagement?” We reframed it as: “What does healthy use look like for a product people buy so they can think less about security?”
Why the analytics could not settle it
The existing data was useful, but it was being asked to explain motivation. It could not.
An inactive subscriber might be satisfied, forgetful, confused, technically protected, incorrectly configured or preparing to cancel. Those customers can produce very similar event histories. A visit prompted by a notification might show successful re-engagement, or it might show that the notification caused concern.
We reviewed the main behavioural measures with the product and analytics teams. These included setup completion, protection status, frequency of app opens, notification opens, changes to settings, support contact and subscription renewal. We also mapped the assumptions attached to each measure.
That exercise exposed a basic problem. App opens had quietly become a proxy for customer value because they were easy to count. Nobody had established that a customer needed to open the app regularly to receive the service or feel confident in it.
We did not discard engagement data. We treated it as evidence of behaviour, not evidence of satisfaction.
The research approach
We recruited customers across several behavioural patterns: frequent users, occasional users, subscribers who had stopped opening the app, people who had contacted support and customers approaching renewal. We wanted to compare the explanations people gave for apparently similar patterns in the analytics.
Before each interview, the research team reviewed a limited behavioural summary with personal details removed. That allowed us to ask about actual use without presenting participants with an exhaustive activity log. Research about a security product can become unsettling if participants feel watched by the company meant to protect them.
The interviews covered:
- what customers thought they had bought;
- what they expected the app to do without their involvement;
- how they decided whether protection was working;
- which events made them open the app;
- how they interpreted alerts, warnings and reassurance messages;
- what they expected to see before renewal;
- whether low use felt deliberate or accidental.
We then reviewed the notification programme as part of the product experience, rather than as a separate marketing channel. Every recurring message was classified by purpose: action required, incident report, service status, education, renewal, cross-sell or reassurance. We checked whether the wording made the required action clear and whether the message introduced anxiety without giving the customer anything useful to do.
Finally, we tested alternative message concepts. Participants compared quieter status language with more urgent prompts, and event-based communication with routine reassurance. We asked them to explain what they believed had happened, whether they needed to act and how the message changed their confidence in the service.
What we learned
The low-use group was not one audience.
Some customers had forgotten what the subscription covered and were at genuine risk of cancelling. Others assumed protection was active but had incomplete setup. Those were service and onboarding problems. Their inactivity concealed uncertainty.
A distinct group, however, described low use as the intended outcome. They had bought relief from having to monitor threats themselves. Payment acted as a mental shortcut: the subscription was active, therefore somebody competent was taking care of the problem. These customers did not want a relationship with the app. They wanted evidence that it would intervene when necessary.
This was not blind trust. Customers still wanted a clear way to confirm status and understand what had happened over time. They simply did not want routine prompts to manufacture a reason to look.
The notification review explained why some apparently successful campaigns were counterproductive. Repeated messages such as “You are protected” drew attention back to the risk. Vague references to scans or threats made people wonder whether there was a problem being softened by reassuring language. When several of these messages arrived close together, some customers inferred that the app needed attention even when no action was required.
In interview language, the service was interrupting people to tell them they could relax.
The more urgent variants performed well on opens because they created doubt. That did not make them better messages. Customers entered the app to check whether something was wrong, then found a normal status screen. The visit counted as engagement, but it spent a small amount of trust.
This distinction changed the product discussion. Passive retention was not automatically healthy, but neither was it automatically a warning sign. The team needed indicators that separated confident non-use from confused non-use.
What the client changed
We helped the team define a healthier measurement model around protection, comprehension and confidence.
Routine app opens were downgraded from a primary success measure. The team gave more weight to successful setup, valid protection status, comprehension of important alerts, resolution of required actions, support reasons and renewal confidence. Low activity became a segment to understand, not a defect to eliminate.
The notification programme was reduced and reorganised. Messages with no decision or action attached were challenged. Routine reassurance was consolidated into a quieter service summary. Action-required alerts stated what had happened, what the product had done and what the customer needed to do next. Educational messages were separated from security incidents so that advice did not resemble an alarm.
We also recommended a clearer home screen for customers who opened the app after a long absence. Instead of rewarding frequency, it answered the questions that brought a passive customer back: Is protection active? Has anything important happened? Do I need to do anything? When was the last meaningful check?
For renewal, the product summarised service activity without inflating routine events into dramatic threat counts. This gave customers evidence of value while preserving the quiet, background role they had purchased.
The final recommendation was deliberately modest. A mobile-security app should earn attention when attention is useful. It should not create concern to improve an engagement chart.
Illustrative results: sample reporting only
In an illustrative post-change period, routine notification volume fell by 38%, while the rate at which customers completed genuinely required security actions rose by 17%. Support contacts asking whether protection was active fell by 22%.
The revised status message produced 14% fewer app opens than the previous urgency-led version, but customer testing showed a 26 percentage-point improvement in correct understanding of whether action was required. That lower open rate was treated as a positive result because the message no longer created unnecessary concern.
Among the illustrative passive-user segment, stated confidence before renewal increased by 12 percentage points, and cancellation intent fell by 9 percentage points. Subscription renewal improved by a sample 4.6% relative lift during the comparison period.
These sample figures require agreed definitions, an appropriate comparison period, sufficient sample sizes and checks for campaign, pricing and seasonal effects before any causal claim can be made.
What this work demonstrates
Product teams often know what customers did but not what the behaviour meant. That gap matters when the product is designed to operate in the background.
Usability research can connect behavioural segments with customers’ expectations, language and decision-making. In this case, the useful finding was not that engagement needed to rise. It was that the team needed to distinguish reassurance from interruption, and confident non-use from unresolved uncertainty.
That led to a clearer product, fewer unnecessary messages and measures better suited to the service customers believed they were buying.
Have a similar usability question?
Tell us which journey matters, what evidence you already have and what decision the research needs to support. We will recommend a proportionate audit or research approach.