FamilyFolds
A calm, colourful operating system for the household, built around one loop: a parent assigns a chore, a child completes it, a parent approves it, points enter an append-only ledger, and the child redeems a reward. Around that sit the things families actually argue about — chat, shared notes, live location and a zero-knowledge password locker.
Architecture, design system and backend contracts are defined and building. The Flutter app is an early vertical slice. This page describes the intended product; what exists today is listed honestly below.
- Platforms4 surfaces
- Features8 documented
- Architecture4 decisions
- Stack10 technologies
[In the box]
What it actually does
- Assign → complete → approve → points → reward, as a single loop
- Append-only point ledger the server owns end to end
- Zero-knowledge password vault with per-item PIN escalation
- Live location sharing that always shows who is looking
- Notes, checklists and a merged family calendar
- Roles for parent, teen, child and extended family
By the numbers
- Status
- Pre-development / early vertical slice
- Flutter app
- ~570 lines
- Backend
- ~350 lines, 5 endpoints
- Ledger
- Append-only, D1 + Durable Object
- Point bounds
- 0 – 1000
- Badge tiers
- 4 (Bronze → Platinum)
- Location history TTL
- 24 hours (default)
- Accessibility target
- WCAG 2.2 AA
- Battery budget
- < 3% / day
- Target MVP
- ~5 months
[Features]
Inside FamilyFolds
Every item below is implemented in the codebase, not planned for a future release.
Chores with a real state machine
draft → assigned → accepted → in_progress → submitted → approved/rejected → done, with photo proof, reason-required rejection, subtasks and overdue escalation.
Schedules, rotation and streaks
Daily, weekday, weekly, interval and rotating schedules with a fairness view, a template library, swaps, vacation pause and streak bonuses.
Server-authoritative points
Points only ever enter through an append-only ledger written by the Durable Object that coordinates the family — never straight from a client.
Reward store with escrow
Points are held while a redemption is pending approval, refunded on failure, and the system can never issue debt.
Transparent location
MapLibre live map with three sharing frequencies, named geofences, check-in requests, trip sessions and a 30-minute teen ghost mode.
Zero-knowledge vault
A 256-bit family vault key wrapped per member with X25519, items sealed with XChaCha20-Poly1305, HaveIBeenPwned breach checks and a printable recovery kit.
Family chat with review
A family room, custom channels and DMs with reactions, voice notes, read receipts, threading, pins, quiet hours and a parent approval queue for kid-uploaded images.
Notes and boards
Family, member and custom boards with LWW-synced checklists, free-form notes, six templates, item-to-task conversion and PDF export.
[Architecture]
How it is built.
The decisions that shaped the codebase, and what each one buys.
One Durable Object per family
FamilyCoordinator serialises submissions and approvals so two parents approving at once cannot race the ledger. It is the single writer by design.
Ledger reconciled by queue
The Durable Object emits events, a queue consumer reconciles them into D1 with INSERT OR IGNORE idempotency, and a cron sweeps every fifteen minutes.
Privacy without a server we operate
The vault is zero-knowledge: keys are wrapped per member and never leave the device. Attachments and proofs go to a private R2 bucket behind signed access.
Design guardrails as testable rules
Never colour as the only state signal. Never white text on yellow. Never coral for destructive actions. Never colour alone. These are written into the design system, not left to taste.
[Who it is for]
Built for
- Organiser parents (30–50) who own the mental load
- Busy parents who want check-ins without arguments
- Teens (13–17) who want autonomy, not surveillance
- Kids (6–12) who want big buttons and instant reward
- Grandparents and extended family who mostly read
[Non-negotiables]
The rules we held
- No penalty points in v1 — the design refuses to be punitive
- Leaderboards are off by default, because competition between siblings backfires for many families
- Location sharing is always transparent: members can see who is viewing them
- Never sell data, never run ads, never charge per child
[Stack]
Built with
Delivered
- Today and Approvals surfaces with a working local chore loop
- Chore model with submitted / approved / rejected states
- Three switchable theme atmospheres
- Backend: health, families list, family create, chore submit, approval
- Queue consumer reconciling ledger events into D1
- Design tokens, HTML prototypes and an adversarial review
Not done yet
Listed rather than hidden.
- The full seven-state task machine and photo proof
- Reward store, escrow and redemption flow
- Live location, geofences and ghost mode
- The zero-knowledge password vault
- Family chat with the parent approval queue
- Notes, checklists and PDF export
[Timeline]
How it got here.
Where this came from, in order.
Phase 0
Decide what it is not
Penalty points were cut from v1 on trust grounds, and the leaderboard was made opt-in because competition between siblings backfires for many families.
Phase 0
Design system and token set
Five theme packs where canvas, ink, primary action, secondary action and focus move together — four atmospheres plus dark.
Phase 0–1
Backend contracts
Five endpoints, one Durable Object per family, an idempotent queue consumer and a D1 ledger that reconciles without double-counting.
Now
Closing the ledger gap
An internal review found two P0 ledger-integrity issues — client-supplied point values and member ids on the approval path. Both are being fixed before any further surface is built.
[FAQ]
Common questions.
The questions we would expect to be asked.
Why is this not finished?
Because the interesting parts are the trust parts. The design docs are done and reviewed, the backend contracts are proven, and the app is an early slice — but we would rather fix the ledger's two P0 findings now than ship a reward store built on an untrustworthy balance.
What does FamilyFolds cost?
The plan is Free for a family of six with chat, chores, points, the store, twenty vault items and 24-hour location history. FamilyFolds+ is proposed at roughly $4–6 per month for unlimited vault storage, attachments, autofill, 30-day location history and weekly review reports. It is a proposal, not a shipped plan — there is no pricing page and no checkout.
Why no ads?
Ads are a trust killer in a product whose entire pitch is that your family's data stays yours. Same reason we never sell data to third parties and never price per child — per-child pricing feels like a tax on family size.
Can I use it now?
No. It is in development and there is nothing to sign up for. The current vertical slice is local-only.
The rest of the catalogue
[Get in touch]
Questions about FamilyFolds?
Want to know more about FamilyFolds — timelines, availability or how it works under the hood? Send us a note.
Taking on select projects for 2026