1Brand
Brand permanence (name + bright-vs-darkroom)
✓ Decided · Jul 1 co-founder meeting. Name kept (the current name is confirmed — memorable, contains “pix”, no better alternative found); OnSet dropped. Bright/light adopted as the brand of record with the coral accent (yellow rejected as too Bumble-like, pink as too gendered). A light/dark toggle is a possible future option.
"snupix" sits one letter from "snoop" and fights the safety wedge; the bright/fun beta palette also diverges from the prior editorial-darkroom direction. Both are now live questions and unblock the domain, logo, store reservation, and the landing rebrand.
F1 / §62Trust & Safety
Image hosting — the CSAM trigger
✓ Decided · Jul 1 co-founder meeting. Embed-only for Instagram; the app self-hosts profile photos only, capped ~1MB, with automatic image moderation and a strict no-nudity rule. Moderation/NCMEC: follow the recommended automated pipeline for now, revisit if it becomes a real issue.
The single load-bearing safety call hidden in the beta: the instant Snupix HOSTS or CACHES a user image, the federal CSAM-reporting duty (18 U.S.C. §2258A) attaches — phase or no phase. Embed-only keeps the duty at its narrowest.
Beta §9.1 / E3 / §7.43Beta
Instagram-embed ToS path
✓ Decided · Jul 1 co-founder meeting. Show the 6 most-recent (or pinned) IG posts via a user-authorized pull; the profile photo is set separately and persists even if Instagram changes. Connecting Instagram is optional (~5% of pros keep portfolios private — don't block them).
The clean way to show "4 most recent posts" changed: legacy oEmbed is deprecated and Meta is mid-migration off Basic Display. The handle-hidden / no-link-out rule may also collide with attribution requirements. This is the #1 thing to verify before building.
Beta §2.2 / §9.24Beta
Retention threshold
✓ Decided · Jul 1 co-founder meeting. No hard retention gate for the beta. A 30–40% bar was judged too high/prescriptive this early; read the signal from intuition + user feedback rather than a fixed metric.
The 40–50-participant gate decides whether to build the native app + open the marketplace. But "coming back" has to be defined before you gate on it.
§4 / §9.35Scope
The 5 "Maybe" features
✓ Decided · Jul 1 co-founder meeting. F-106 simplified and deferred (kept out of V1). If built later, model it on Uber's optional in-ride preferences — easy to dismiss, never required.
Five features sit on the borderline in the tracker (F-O-CENSUS, F-106, F-D07, F-D10, F-413). The closest call is the consent / boundary checklist (F-106) — the highest-safety-weight item currently outside V1, right beside the in-person primitives that were pulled in.
C3 + 4 more (5 "Maybe")6Strategy
Calendar vs. liquidity gate (SF → LA)
Barbara's "SF 6 months, then LA" is a calendar; the canon's expansion trigger is a liquidity/retention gate. They usually agree — but if SF hasn't proven retention by month 6, which one wins?
Lean: Keep "6 months" as the aspiration but let the retention gate win — never move to LA on a date if SF hasn't proven repeat participation. Premature geo expansion is the #1 marketplace killer.
Beta §5 / §9.4