Living blueprint · v1.7 · October 2, 2026

Made by
people.

A complete product and engineering blueprint for a social platform where accounts represent real people, published work is human-made, and advertising is transparent, accountable, and privacy-conscious.

00 / ORIENTATION
“Preserve a trusted place for genuine human expression online—where people can speak, create, debate, entertain, organize, and earn without competing with synthetic identities or generative content.”

WORKING LAUNCH ASSUMPTIONS

  • United States-first closed alpha; international expansion is gated by legal and operational readiness.
  • Public pseudonyms are allowed, but every account is privately verified as a unique human.
  • 18+ at initial launch; minors require a separate safety, age-assurance, and advertising program.
  • Responsive web ships first; iOS and Android follow the stable public API and design system.
  • Chronological Following is the default feed; explainable discovery is opt-in.
  • Direct-sold advertising launches before any programmatic exchange integration.

01 / CONSTITUTION

Product rules before product features.

These principles are architectural constraints, policy commitments, and the test for every roadmap decision.

01

Human presence

One person, one core account. Verification is private; expression may remain pseudonymous.

02

Human authorship

Generative output cannot be published as a user’s work. Assistive-tool boundaries are explicit and appealable.

03

Privacy by design

Collect the minimum, separate identity evidence from social data, and make retention finite.

04

Transparent systems

Explain feed controls, sponsorship, enforcement evidence, reach limits, and appeal outcomes.

05

Creator agency

Creators control audiences, licensing, monetization, portability, and reuse of their work.

06

Safety with due process

Fast intervention for credible harm, human review for consequential decisions, and meaningful appeals.

02 / PRODUCT SYSTEM

One network. Eight working surfaces.

Each surface serves a distinct role while sharing identity, policy, data contracts, and a single design system.

Public web

Profiles, posts, channels, embeds, discovery, legal and transparency centers.

Member app

Home, Following, Explore, search, compose, inbox, notifications, settings, and safety.

Creator Studio

Publishing, scheduling, media library, analytics, rights, memberships, payouts, and brand deals.

Community Console

Membership, roles, rules, queues, events, insights, and moderator operations.

Advertiser Portal

Organization verification, campaigns, creatives, targeting, billing, reports, and compliance.

Trust Console

Reports, investigations, policy actions, appeals, legal requests, and transparency reporting.

Operations Console

Feature flags, incidents, support, fraud, finance, data rights, and audit access.

Developer Platform

Read integrations, embeds, webhooks, OAuth, and export tools; publishing remains restricted.

Members

Authentic identity, expressive freedom, safer interaction, and control over feeds and privacy.

Creators

Human-attention analytics, durable audience relationships, publishing tools, and fair monetization.

Communities

Member governance, roles, events, moderation queues, and healthy participation controls.

Advertisers

Verified human reach, brand-safe placements, transparent delivery, and auditable billing.

Moderators

Context-rich queues, consistent policy guidance, evidence trails, and workload protections.

Developers

Stable contracts, explicit service boundaries, observable workflows, and reversible delivery.

03 / FEATURE CATALOG

The complete capability map.

This is the long-range product envelope—not a promise to ship everything at once. Delivery sequencing appears below.

01Identity & accounts+
  • Email/phone enrollment
  • Passkeys and recovery
  • Proof of personhood
  • Pseudonymous profile
  • Account portability
  • Delegated business roles
  • Sessions and device center
  • Memorialization and deletion
02Publishing+
  • Text, image, audio, short/long video
  • Drafts and scheduling
  • Threads and series
  • Captions, transcripts, alt text
  • Audience and reply controls
  • Edits with history
  • Content warnings
  • Embeds and link cards
03Social graph+
  • Follows and subscriptions
  • Lists and circles
  • Consented contact discovery
  • Blocks, mutes, keyword filters
  • Communities and roles
  • Events and live rooms
  • Collaborative posts
  • Trusted contacts
04Discovery+
  • Chronological Following
  • Opt-in recommendations
  • Topics and channels
  • Full-text and media search
  • Anti-gaming trends
  • Coarse-location discovery
  • Editorial collections
  • Why-this-result explanations
05Communication+
  • Replies and quote posts
  • Reactions and bookmarks
  • 1:1 and group messages
  • Message requests
  • Voice notes
  • Live chat
  • Notification controls
  • Anti-harassment friction
06Creator economy+
  • Memberships
  • Tips
  • Paid posts and series
  • Ticketed events
  • Digital goods later
  • Revenue dashboard
  • Tax/payout onboarding
  • Refunds and disputes
07Trust & safety+
  • Report and block everywhere
  • Community moderation
  • Safety center
  • Crisis escalation
  • Copyright workflows
  • Policy strikes
  • Appeals
  • Transparency reporting
08Accessibility & localization+
  • WCAG 2.2 AA target
  • Keyboard/screen-reader support
  • Captions and transcripts
  • Reduced motion
  • Dynamic type
  • RTL readiness
  • Locale-aware formats
  • Reviewed policy translations

04 / HUMAN TRUST MODEL

Prove presence. Assess authorship. Preserve dignity.

Personhood and authorship are separate questions. Neither should require publishing a legal identity.

L0

Registered

Confirmed channel, device and abuse screening; read and limited interaction.

L1

Human verified

Liveness/personhood check; publish, message, and join communities.

L2

Identity verified

Optional stronger proof for payouts, advertisers, public-interest roles, or recovery.

L3

Organization verified

Business authority and beneficial-owner checks for advertisers and institutions.

AUTHORSHIP SIGNALS

  • Original in-app capture receipt
  • C2PA Content Credentials when present
  • File and edit-history metadata
  • Generation/manipulation signals
  • Account/device behavior
  • Duplicate/coordinated-upload detection
  • Community reports
  • Expert forensic review

ENFORCEMENT STANDARD

Detectors create review signals, never unquestionable verdicts. Consequential authorship actions require evidence packaging, calibrated thresholds, human review, and appeal.

PERMITTED ASSISTANCE

  • Spell-check and deterministic grammar hints
  • Cropping, exposure, compression, and color correction
  • Accessibility tools including speech-to-text
  • Human-directed translation under policy
  • Noise reduction and restoration within policy
  • Generated examples for news/criticism with clear context

PROHIBITED GENERATION

  • Generated or substantially rewritten posts
  • Synthetic or materially generated images/video
  • Cloned or generated voices and music
  • AI avatars presented as real people
  • Automated engagement or messaging
  • Undisclosed off-platform generation

05 / MEDIA PLATFORM

Every upload begins in quarantine.

Media is validated, assessed, transformed, and governed before a public derivative reaches the CDN.

  1. 01

    Authorize

    Scoped upload session, size/type limits, checksum, quota, and ownership record.

  2. 02

    Quarantine

    Direct upload to private object storage; the application server never proxies large files.

  3. 03

    Inspect

    Validate magic bytes, scan malware, strip active content, extract metadata, and stop decompression bombs.

  4. 04

    Assess

    Read provenance, fingerprint, run safety/authorship signals, and route uncertainty to review.

  5. 05

    Transform

    Normalized image variants, adaptive video ladders, waveforms, captions, thumbnails, and previews.

  6. 06

    Publish

    Atomically attach approved derivatives, update CDN, and emit searchable/feed-ready events.

  7. 07

    Govern

    Rights, retention, regional restrictions, takedowns, legal holds, deletion, and derivative lineage.

06 / TECHNICAL ARCHITECTURE

Modular first. Distributed when earned.

A modular monolith plus asynchronous workers first. Explicit domain boundaries let high-load or high-risk modules separate without rewriting product contracts.

CLIENTS
Next.js responsive webReact Native iOS/AndroidAdmin web consolesPublic embedsPartner API clients
EDGE
DNS/CDN/WAFRate limiting and bot defenseMedia deliveryRequest authenticationRegional routingFeature gates
PRODUCT DOMAINS
IdentityVerificationProfilesSocial graphContentMediaFeedsSearchMessagingCommunitiesNotificationsTrust & SafetyAdsBillingAnalyticsAudit
PLATFORM
PostgreSQL source of truthRedis ephemeral stateS3-compatible object storageDurable event bus/job queuesSearch indexAnalytics warehouse/lakeSecrets/KMSObservability stack

A MODULE BECOMES A SERVICE ONLY WHEN

01Independent scaling dominates cost02Different availability/data residency03Material security isolation04Stable team ownership/release cadence05Proven queue/event contract

07 / DATA OWNERSHIP

Boundaries developers can enforce.

Every sensitive domain owns its records, access policy, retention, audit trail, and public contract.

DOMAINOWNSNON-NEGOTIABLE
Identity vault

verification references, recovery factors, legal identity where required

Strongest isolation; no feed or ads access.

Accounts & profiles

account state, handles, profile, settings, sessions

Public identity stays distinct from private proof.

Social

follows, lists, blocks, communities, roles

Block semantics override every downstream surface.

Content

posts, revisions, replies, visibility, rights, provenance

Immutable revision history and derivative lineage.

Media

assets, variants, fingerprints, captions, moderation state

Private originals; public sanitized derivatives.

Trust

reports, cases, evidence, actions, appeals

Restricted, audited, purpose-limited access.

Advertising

organizations, campaigns, creatives, targeting, delivery ledger

Organic ranking cannot read advertiser bids.

Finance

ledger, invoices, payouts, taxes, disputes

Double-entry accounting; processors hold payment data.

Analytics

consented events, aggregates, experiments, metrics

Pseudonymized, retention-bound, access-tiered.

Public API

Versioned read access, profiles, public content, discovery, embeds; strict quotas and OAuth scopes.

Publishing API

Restricted approval only; human-initiated workflows, provenance requirements, no bulk engagement.

Internal APIs

Domain-owned commands/reads; service identity, policy checks, idempotency, audit context.

Events

Outbox-produced, schema-versioned, replayable facts such as PostPublished and AdImpressionQualified.

Webhooks

Signed, retryable, deduplicated notifications for creators, advertisers, and approved integrations.

CORE EVENT VOCABULARY

HumanVerificationCompletedPostPublishedMediaDerivativeReadyContentReportedPolicyActionAppliedAppealResolvedFeedCandidateGeneratedNotificationRequestedCampaignApprovedAdImpressionQualifiedInvoiceReconciledDataDeletionCompleted

08 / ADVERTISING PLATFORM

Human attention, sold transparently.

Advertising funds human expression without disguising sponsorship or turning sensitive identity into a targeting product.

ADVERTISER PORTAL

  • Business and payer verification
  • Role-based organization access
  • Objective and buying model
  • Budget, bid, pacing, dates, and caps
  • Audience and placement selection
  • Creative upload and preview
  • Policy declarations and substantiation
  • Review/remediation
  • Billing, invoices, credits, refunds
  • Delivery, attribution, and reports

SUPPORTED FORMATS

  • Labeled feed card
  • Image and carousel
  • Short/long video
  • Search placement
  • Topic/community sponsorship
  • Creator partnership disclosure
  • Event sponsorship
  • House/public-service ads

OPERATING ROLES

  • Advertiser organization
  • Agency/buyer
  • Creative reviewer
  • Campaign operator
  • Finance reviewer
  • Trust & safety reviewer
  • Creator partner
  • Independent auditor

CAMPAIGN LIFECYCLE

01Draft02Submitted03Automated preflight04Human review when required05Approved/rejected with reasons06Scheduled07Delivering08Paused09Completed10Reconciled11Ad-library archive

TARGETING CONSTITUTION

  • Allowed: broad geography, language, device class, contextual topic, community placement, frequency, and consented first-party audiences
  • Restricted: precise location, inferred health, race, religion, sexuality, politics, financial hardship, or other sensitive traits
  • Minors: no profile-based targeted advertising
  • Every impression: sponsor, payer, targeting rationale, and hide/report controls

TRUST SAFEGUARDS

  • Public searchable ad library
  • Political/issue ads off until a dedicated compliance program
  • Prohibited-category and claim-substantiation policy
  • Creative and destination scanning
  • Spend and anomaly controls
  • No undisclosed native ads
  • Material-connection disclosures
  • Organic ranking isolated from bids

SERVING DECISION

1Eligibility/policy2Privacy/consent3Campaign/creative status4Context/placement match5Budget/pacing6Frequency cap7Brand safety8Auction/priority9Renderable response10Event ledger11Fraud adjustment

MEASUREMENT

  • Viewable impressions and video quartiles
  • Clicks and destination quality
  • Reach/frequency
  • Consented conversions
  • Creator sponsorship outcomes
  • Invalid traffic/refunds
  • Aggregate privacy thresholds
  • Billable-event reconciliation

A — house ads and manually sold sponsorships

B — self-serve verified advertisers and card-on-file billing

C — agencies, first-party audiences, conversion API, creator partnerships

D — governed programmatic demand only where strategically justified

09 / SECURITY, PRIVACY & POLICY

Trust must survive contact with operations.

Controls are part of the product definition, not a pre-launch checklist.

Account security

Passkeys/WebAuthn, risk-based sessions, verified recovery, step-up auth, device/session visibility.

Application security

Threat modeling, secure defaults, dependency controls, SAST/DAST, review, ASVS alignment, disclosure program.

Infrastructure

Least privilege, short-lived credentials, segmentation, hardened images, KMS encryption, immutable logs.

Abuse resistance

Rate limits, graph/behavior detection, device risk, spam friction, influence investigations, red teams.

Privacy

Data inventory, purpose binding, consent receipts, minimization, retention, DPIAs, export/delete/correct.

Operations

On-call, incident command, severity matrix, runbooks, backups, restore drills, vendor risk, reviews.

LAUNCH READINESS PACK

  • Terms, Community Standards, AI/Authorship Policy, Privacy and Cookie Notices
  • Copyright/DMCA intake and counter-notice
  • Law-enforcement and emergency request process
  • Data access, correction, portability, and deletion
  • Ad terms, prohibited categories, library, and sponsorship disclosures
  • Billing, renewals, refunds, tax, and creator payouts
  • App-store UGC, payment, deletion, and privacy requirements
  • Regional launch checklist with qualified counsel
This blueprint is product planning, not legal advice. Qualified counsel must approve launch-market policies.

10 / RELIABILITY & DELIVERY QUALITY

Ship small. Observe everything. Reverse safely.

Targets mature with traffic, but operational ownership begins in the first vertical slice.

INITIAL SERVICE OBJECTIVES

  • Core reads: 99.95% availability target
  • Core writes: 99.9%
  • Feed API p95 under 500 ms excluding media
  • Publish acknowledgement p95 under 800 ms
  • Critical notification enqueue p95 under 60 seconds
  • Priority safety acknowledgement under 15 minutes
  • Restore objectives exercised quarterly

DEFINITION OF DONE

  • Unit/contract tests
  • Migration rehearsal
  • Accessibility checks
  • Performance budgets
  • Security/privacy review
  • Abuse-case tests
  • Observability/rollback
  • Analytics plan
  • Support/moderation readiness
  • Flagged rollout

11 / DELIVERY ROADMAP

Nine gates from charter to scale.

Dates follow evidence. Each phase exits only when product, policy, safety, and operations are ready together.

0

Foundation

Charter, assumptions, policies, threat model, architecture decisions, metrics approved.

1

Trust prototype

Registration, passkey, personhood, recovery, minimization, and appeals tested.

2

Core vertical slice

Verify → publish → process → feed → report → moderate → appeal works end to end.

3

Closed alpha

Invited creators, responsive web, moderation operations, security review, trust baselines.

4

Community beta

Search, notifications, communities, Creator Studio, discovery, and scalable media.

5

Mobile launch

iOS/Android parity, store compliance, capture provenance, push, and deep links.

6

Creator economy

Memberships, tips, payouts, tax onboarding, disputes, and reconciliation.

7

Ads pilot

Verified direct advertisers, reviewed creatives, transparent delivery, invoices, reports, ad library.

8

Scale & expansion

Regional readiness, mature SRE, advanced media, partner APIs, governed ad expansion.

12 / OWNERSHIP & MEASUREMENT

Teams own outcomes, not just components.

Cross-functional ownership prevents trust, safety, finance, and accessibility from becoming handoffs.

Product & Design

research, roadmap, design system, accessibility, product analytics

Identity & Trust

personhood, authentication, recovery, fraud, privacy-preserving proof

Core Social

profiles, graph, content, feeds, discovery, communities

Media

uploads, transcoding, delivery, captions, provenance, live media

Trust & Safety

policy, tooling, moderation, appeals, crisis and legal operations

Monetization

creator economy, ads, billing, payouts, measurement

Platform & SRE

cloud, data platform, developer experience, security, reliability

Legal, Policy & Ops

regional readiness, support, finance, vendor risk, transparency

Trust

verified-human rateduplicate-account prevalencesynthetic-content prevalencefalse-positive action rateappeal reversal

Community

meaningful reply ratehealthy conversation rateretentionblock/report ratesmoderator health

Product

activationweekly retained humanspublish successfeed satisfactionsearch successa11y defects

Business

creator earningssubscription retentionverified-human ad reachadvertiser retentioninvalid trafficmargin

Operations

availabilitylatencyincident recoverymoderation responsesupport resolutionrights completion

13 / RISK REGISTER

Design the response before the incident.

These risks should remain visible in architecture reviews, roadmap decisions, and launch gates.

01

Personhood friction or exclusion

Multiple paths, accessibility tests, regional alternatives, recovery, and human escalation.

02

AI detection false positives

Signals not verdicts, provenance weighting, evidence, expert review, and calibrated appeals.

03

Harassment and coordinated abuse

Safety defaults, graph controls, limits, tooling, crisis playbooks, and victim support.

04

Media and infrastructure cost

Quotas, adaptive processing, tiered storage, CDN strategy, attribution, progressive rollout.

05

Advertising erodes trust

Direct-sold first, restricted targeting, ad library, labels, independent ranking, user controls.

06

Premature complexity

Modular monolith, managed services, contract tests, split triggers, staged capabilities.

07

Regulatory expansion

Country gates, data inventory, policy ownership, legal review, regional controls.

08

Insider or vendor access

Least privilege, audit trails, dual control, vendor minimization, regular review.

14 / REFERENCE BASELINE

Build against living standards.

The team must re-check these sources before each relevant release; regulations and platform rules change.

NEXT GOVERNANCE MEETING

Eight decisions unlock the build.

  1. Select the first proof-of-personhood provider and fallback path.
  2. Ratify the assistive-tool boundary, including translation, restoration, and autocomplete.
  3. Confirm 18+ United States-first launch and path to later age groups/regions.
  4. Choose infrastructure vendors and document portability/exit plans.
  5. Set moderation taxonomy, severity, response targets, and appeals authority.
  6. Choose the first creator business model and platform fee philosophy.
  7. Approve direct-sold ad principles, prohibited categories, and political-ad posture.
  8. Define closed-alpha success and safe public-launch metrics.

Decision records should name the owner, context, alternatives, decision, consequences, review date, and implementation status.

HOW TO USE THIS RESOURCE

Read. Decide.
Build. Measure.

The project content file is the source of truth for this page. Update it alongside architecture decisions and roadmap changes, review the diff, then publish a new version to the same link.

01Start from a roadmap gate02Write a decision record03Ship behind a flag04Measure trust and harm