Closes the remaining store-compliance gaps before App Store / Play
submission:
- Account deletion (App Store guideline 5.1.1): DELETE /me removes the
user row (usage cascades). The app exposes it through one quiet
'Account' caption link under the chat, visible only when signed in,
driving two native dialogs (Sign out / Delete account with a
destructive confirm) — no new views, no menus, minimalism intact.
Deletion signs out and resets the app; copy notes that store
subscriptions are cancelled in App Store / Play settings.
- docs/store/privacy-policy.md: the complete data inventory (matching
the actual schema), transient OpenAI processing with no training, no
profiling or ads, GDPR legal bases and rights, in-app erasure.
- docs/store/terms-of-service.md: not-therapy positioning with crisis
guidance, AI-generated-content caveat, 18+ eligibility,
auto-renewal/cancellation terms, liability, Swedish governing law.
- docs/store/listing.md: App Store and Play copy written to the
honest-claims rule (subtitle 'Think Beyond Thought', keywords,
descriptions), plus App Privacy and Data safety questionnaire
mappings.
- LAUNCH.md updated: host the policy/terms, set store URLs, use the
prepared listing copy.
- Tests: 30 passing (adds DELETE /me coverage).
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0118DaxZR36RpnY524vRqx3z
Reconciles the implementation against the final MVP brief:
- Data model: rename users.provider to auth_provider and
users.subscription_status to subscription, matching the brief's schema
exactly (id, email, auth_provider, subscription, created_at). External
API field names are unchanged.
- Suggestions: replace the starter list with the brief's eight examples.
- Instructions: personality updated to calm, warm, intelligent, curious,
respectful, pedagogical — never judging, manipulative, dramatic,
overly positive, overconfident or preaching. Added per-reply goals:
feel personal, be calm, instill safety, give hope without promising
results, deepen thinking, and always contain at least one genuinely
new thought or question. Added the conversation outcome goal (greater
clarity, greater calm, a new perspective, increased trust in one's own
ability) and 'not a chatbot for general questions' to positioning.
- Paywall transition example updated to the brief's wording ('I'm
starting to see some recurring patterns… Unlock Premium to continue.').
- Knowledge base completed per the brief: communication models
(perceptual positions, observation vs interpretation, chunking,
backtracking, boundaries), reflection exercises (meaning audit,
meta-question, five frames, observer replay, well-formed outcome,
evening question) and a question library organized by purpose.
Appreciation in the Lift step must be anchored in what the user
actually expressed; the Challenge step never preaches.
- README: product principle (one user, one conversation, one analysis,
one recommendation), the removal rule, design words per the brief,
Definition of Done (7 steps), V2 not-now list (journal, saved
insights, community, coaches, courses, voice), and a closed-beta plan
for 20-50 testers with what the minimal data model can already
measure.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0118DaxZR36RpnY524vRqx3z
Replaces the hardcoded message limit with a model-driven paywall and
removes registration before the first question:
- Onboarding: the app opens directly into the chat. Dynamic conversation
starters are served by GET /suggestions (services/api/suggestions.json),
updatable with a deploy — no app release needed. Guests chat via
POST /guest/chat, identified by an app-generated device id; sign-in
moves to the paywall, where a purchase must attach to an account.
- Free experience: the model runs in discovery mode — follow-up
questions, pattern identification, visible understanding — building an
analysis without delivering the full solution.
- Intelligent paywall: the model returns structured output (reply +
analysis_ready). Only when the problem is described, the information is
sufficient and an action plan is ready does it write a calm transition
and pause the conversation. Manufactured urgency, emotional pressure,
fake readiness and mid-answer stops are explicitly forbidden.
- Premium: on unlock the app resends the transcript and the backend
immediately delivers the full analysis, strategies and exercises, then
the dialogue continues without restriction.
- The old FREE_MESSAGE_LIMIT becomes MESSAGE_CAP (default 200/30 days),
kept purely as an abuse backstop — it is not the paywall.
- WelcomeScreen removed; the app is now two views (Chat, Paywall).
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0118DaxZR36RpnY524vRqx3z
Ersätter den tidigare webappen på denna branch med ett fokuserat monorepo:
- apps/mobile: Expo/React Native med tre vyer (Welcome, Chat, Paywall),
Cognito hosted UI-inloggning (Apple/Google/e-post) och In-App
Purchase/Play Billing via en gemensam purchases-modul.
- services/api: en enda Lambda-backend — OpenAI Responses API med
Markdown-kunskapsbas som systeminstruktioner, free tier-gräns i
PostgreSQL (HTTP 402 -> paywall) och kvittoverifiering bakom ett
delat PaymentProvider-interface (Apple/Google, Stripe kan läggas
till för webb senare).
- infra: AWS CDK-stack med API Gateway (JWT-authorizer), Lambda,
Cognito, Aurora Serverless v2 och Secrets Manager.
- db/migrations: minimal datamodell (users + usage), inga
konversationer sparas.
- GitHub Actions: CI (lint, typecheck, test) och deploy från main.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0118DaxZR36RpnY524vRqx3z