Skip to content
In development

FamilyFolds

A calm, colourful operating system for the household, built around one loop: a parent assigns a chore, a child completes it, a parent approves it, points enter an append-only ledger, and the child redeems a reward. Around that sit the things families actually argue about — chat, shared notes, live location and a zero-knowledge password locker.

Architecture, design system and backend contracts are defined and building. The Flutter app is an early vertical slice. This page describes the intended product; what exists today is listed honestly below.

FamilyFolds
iOSAndroidWebDesktop

[In the box]

What it actually does

  • Assign → complete → approve → points → reward, as a single loop
  • Append-only point ledger the server owns end to end
  • Zero-knowledge password vault with per-item PIN escalation
  • Live location sharing that always shows who is looking
  • Notes, checklists and a merged family calendar
  • Roles for parent, teen, child and extended family
iOSAndroidWebDesktop

By the numbers

Status
Pre-development / early vertical slice
Flutter app
~570 lines
Backend
~350 lines, 5 endpoints
Ledger
Append-only, D1 + Durable Object
Point bounds
0 – 1000
Badge tiers
4 (Bronze → Platinum)
Location history TTL
24 hours (default)
Accessibility target
WCAG 2.2 AA
Battery budget
< 3% / day
Target MVP
~5 months

[Features]

Inside FamilyFolds

Every item below is implemented in the codebase, not planned for a future release.

Chores with a real state machine

draft → assigned → accepted → in_progress → submitted → approved/rejected → done, with photo proof, reason-required rejection, subtasks and overdue escalation.

Schedules, rotation and streaks

Daily, weekday, weekly, interval and rotating schedules with a fairness view, a template library, swaps, vacation pause and streak bonuses.

Server-authoritative points

Points only ever enter through an append-only ledger written by the Durable Object that coordinates the family — never straight from a client.

Reward store with escrow

Points are held while a redemption is pending approval, refunded on failure, and the system can never issue debt.

Transparent location

MapLibre live map with three sharing frequencies, named geofences, check-in requests, trip sessions and a 30-minute teen ghost mode.

Zero-knowledge vault

A 256-bit family vault key wrapped per member with X25519, items sealed with XChaCha20-Poly1305, HaveIBeenPwned breach checks and a printable recovery kit.

Family chat with review

A family room, custom channels and DMs with reactions, voice notes, read receipts, threading, pins, quiet hours and a parent approval queue for kid-uploaded images.

Notes and boards

Family, member and custom boards with LWW-synced checklists, free-form notes, six templates, item-to-task conversion and PDF export.

[Architecture]

How it is built.

The decisions that shaped the codebase, and what each one buys.

01

One Durable Object per family

FamilyCoordinator serialises submissions and approvals so two parents approving at once cannot race the ledger. It is the single writer by design.

02

Ledger reconciled by queue

The Durable Object emits events, a queue consumer reconciles them into D1 with INSERT OR IGNORE idempotency, and a cron sweeps every fifteen minutes.

03

Privacy without a server we operate

The vault is zero-knowledge: keys are wrapped per member and never leave the device. Attachments and proofs go to a private R2 bucket behind signed access.

04

Design guardrails as testable rules

Never colour as the only state signal. Never white text on yellow. Never coral for destructive actions. Never colour alone. These are written into the design system, not left to taste.

[Who it is for]

Built for

  • Organiser parents (30–50) who own the mental load
  • Busy parents who want check-ins without arguments
  • Teens (13–17) who want autonomy, not surveillance
  • Kids (6–12) who want big buttons and instant reward
  • Grandparents and extended family who mostly read

[Non-negotiables]

The rules we held

  • No penalty points in v1 — the design refuses to be punitive
  • Leaderboards are off by default, because competition between siblings backfires for many families
  • Location sharing is always transparent: members can see who is viewing them
  • Never sell data, never run ads, never charge per child

[Stack]

Built with

FlutterDartMaterial 3 (customised)Cloudflare WorkersD1Durable ObjectsQueuesR2OIDC / JWKSdesign tokens (JSON + CSS)

Delivered

  • Today and Approvals surfaces with a working local chore loop
  • Chore model with submitted / approved / rejected states
  • Three switchable theme atmospheres
  • Backend: health, families list, family create, chore submit, approval
  • Queue consumer reconciling ledger events into D1
  • Design tokens, HTML prototypes and an adversarial review

Not done yet

Listed rather than hidden.

  • The full seven-state task machine and photo proof
  • Reward store, escrow and redemption flow
  • Live location, geofences and ghost mode
  • The zero-knowledge password vault
  • Family chat with the parent approval queue
  • Notes, checklists and PDF export

[Timeline]

How it got here.

Where this came from, in order.

    1

    Phase 0

    Decide what it is not

    Penalty points were cut from v1 on trust grounds, and the leaderboard was made opt-in because competition between siblings backfires for many families.

    2

    Phase 0

    Design system and token set

    Five theme packs where canvas, ink, primary action, secondary action and focus move together — four atmospheres plus dark.

    3

    Phase 0–1

    Backend contracts

    Five endpoints, one Durable Object per family, an idempotent queue consumer and a D1 ledger that reconciles without double-counting.

    4

    Now

    Closing the ledger gap

    An internal review found two P0 ledger-integrity issues — client-supplied point values and member ids on the approval path. Both are being fixed before any further surface is built.

[FAQ]

Common questions.

The questions we would expect to be asked.

Why is this not finished?

Because the interesting parts are the trust parts. The design docs are done and reviewed, the backend contracts are proven, and the app is an early slice — but we would rather fix the ledger's two P0 findings now than ship a reward store built on an untrustworthy balance.

What does FamilyFolds cost?

The plan is Free for a family of six with chat, chores, points, the store, twenty vault items and 24-hour location history. FamilyFolds+ is proposed at roughly $4–6 per month for unlimited vault storage, attachments, autofill, 30-day location history and weekly review reports. It is a proposal, not a shipped plan — there is no pricing page and no checkout.

Why no ads?

Ads are a trust killer in a product whose entire pitch is that your family's data stays yours. Same reason we never sell data to third parties and never price per child — per-child pricing feels like a tax on family size.

Can I use it now?

No. It is in development and there is nothing to sign up for. The current vertical slice is local-only.

The rest of the catalogue

[Get in touch]

Questions about FamilyFolds?

Want to know more about FamilyFolds — timelines, availability or how it works under the hood? Send us a note.

Taking on select projects for 2026