Closes the remaining store-compliance gaps before App Store / Play
submission:
- Account deletion (App Store guideline 5.1.1): DELETE /me removes the
user row (usage cascades). The app exposes it through one quiet
'Account' caption link under the chat, visible only when signed in,
driving two native dialogs (Sign out / Delete account with a
destructive confirm) — no new views, no menus, minimalism intact.
Deletion signs out and resets the app; copy notes that store
subscriptions are cancelled in App Store / Play settings.
- docs/store/privacy-policy.md: the complete data inventory (matching
the actual schema), transient OpenAI processing with no training, no
profiling or ads, GDPR legal bases and rights, in-app erasure.
- docs/store/terms-of-service.md: not-therapy positioning with crisis
guidance, AI-generated-content caveat, 18+ eligibility,
auto-renewal/cancellation terms, liability, Swedish governing law.
- docs/store/listing.md: App Store and Play copy written to the
honest-claims rule (subtitle 'Think Beyond Thought', keywords,
descriptions), plus App Privacy and Data safety questionnaire
mappings.
- LAUNCH.md updated: host the policy/terms, set store URLs, use the
prepared listing copy.
- Tests: 30 passing (adds DELETE /me coverage).
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0118DaxZR36RpnY524vRqx3z
Replaces the hardcoded message limit with a model-driven paywall and
removes registration before the first question:
- Onboarding: the app opens directly into the chat. Dynamic conversation
starters are served by GET /suggestions (services/api/suggestions.json),
updatable with a deploy — no app release needed. Guests chat via
POST /guest/chat, identified by an app-generated device id; sign-in
moves to the paywall, where a purchase must attach to an account.
- Free experience: the model runs in discovery mode — follow-up
questions, pattern identification, visible understanding — building an
analysis without delivering the full solution.
- Intelligent paywall: the model returns structured output (reply +
analysis_ready). Only when the problem is described, the information is
sufficient and an action plan is ready does it write a calm transition
and pause the conversation. Manufactured urgency, emotional pressure,
fake readiness and mid-answer stops are explicitly forbidden.
- Premium: on unlock the app resends the transcript and the backend
immediately delivers the full analysis, strategies and exercises, then
the dialogue continues without restriction.
- The old FREE_MESSAGE_LIMIT becomes MESSAGE_CAP (default 200/30 days),
kept purely as an abuse backstop — it is not the paywall.
- WelcomeScreen removed; the app is now two views (Chat, Paywall).
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0118DaxZR36RpnY524vRqx3z
Ersätter den tidigare webappen på denna branch med ett fokuserat monorepo:
- apps/mobile: Expo/React Native med tre vyer (Welcome, Chat, Paywall),
Cognito hosted UI-inloggning (Apple/Google/e-post) och In-App
Purchase/Play Billing via en gemensam purchases-modul.
- services/api: en enda Lambda-backend — OpenAI Responses API med
Markdown-kunskapsbas som systeminstruktioner, free tier-gräns i
PostgreSQL (HTTP 402 -> paywall) och kvittoverifiering bakom ett
delat PaymentProvider-interface (Apple/Google, Stripe kan läggas
till för webb senare).
- infra: AWS CDK-stack med API Gateway (JWT-authorizer), Lambda,
Cognito, Aurora Serverless v2 och Secrets Manager.
- db/migrations: minimal datamodell (users + usage), inga
konversationer sparas.
- GitHub Actions: CI (lint, typecheck, test) och deploy från main.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0118DaxZR36RpnY524vRqx3z