The family app · plan for review · 8 August 2026

Turning the family app into a real app on your phone.

Read this, and either approve it or tell me what to change. Nothing has been built. Nothing is deployed. This is the plan only.

Right now the family app is a website you open in a browser. At the end of this it is an app with its own icon on the home screen — tap it, no address bar, Skippy inside it. And your phone can buzz, which nothing in this whole system can do today.

That last part is the real prize. Today the app's own updates list is the only place anything arrives, which means you have to go and look. That changes the day this ships.

The order matters, and it is your order

You said the new design goes on before it gets converted. That is how this is written. Converting first would mean wrapping up a half-finished look and shipping it to a phone, then changing it underneath everyone.

What changes for you and Chantelle

The app looks like the design Chantelle picked — one big number on a block of colour at the top of each screen, thin lines instead of boxes, nothing rounded, nothing animated. Every button stays exactly where it is. Nothing you tap moves.

It then stops being a website. Own icon, one tap, no address bar. Skippy comes with it, and so does the kids' screen.

Both phones buzz, each with their own things. Yours never reach her lock screen and hers never reach yours. Her phone asks her first, on her own device — you authorised the capability, she still gets to say no, and a no from her is final.

No new passwords, and neither of yours changes. One small thing does: the app still accepts an old shared sign-in from before you each had your own. That gets switched off. Anyone whose phone is still holding it is asked once for the password they already have.

One honest limit, said here rather than buried

The buzzing runs through the Mac at home. With that Mac off, no buzz arrives — every screen still works, but the phone stays quiet. Moving that off the Mac is a separate project, and the plan says how we decide whether it is worth doing: measure how often the Mac is actually off when something needs you, over a fortnight, then decide from the number instead of from a guess.

The four steps

  1. Fix what would otherwise get baked in

    Invisible to everyone. The automatic checks that are supposed to catch breakage were partly pointing at the wrong files — one entire rebuild passed every check while being invisible to all of them. This repairs the checking, writes down every hidden connection the app depends on, and pulls out the colours that are typed directly into the page in hundreds of places a design change can't reach.

    This is what makes step two provable instead of hopeful. Skipping it is how the last two attempts failed.

    What's holding it up: nothing. It can start today. One moment needs you and Chantelle both reachable at the same time, for the sign-in change.
  2. The rebrand and the redesign

    One screen at a time, in a fixed order, each rebuilt in its own sealed compartment rather than painted over the old one. Chantelle sees three pictures of each screen and says yes or no. Then it goes live, one screen at a time, and can be put back with one line if anything's wrong.

    The words on screen and what every number means are frozen — a machine compares them before and after and rejects the work if anything moved. An earlier attempt silently reworded nearly four thousand pieces of text.

    What's holding it up: step one. Then Chantelle, per screen — and if she's unreachable for three days a screen goes live on measurement alone, so nothing stalls.
  3. Check everything again

    Across all four people's screens, not just yours. Yours is the only fully filled-in one, so every check ever run has looked at the one screen where the empty-data problem doesn't show up — four hundred blank boxes sat on the other three for months for exactly that reason. Plus every screen you can only reach by tapping, which no tool could reach until recently.

    What's holding it up: step two.
  4. Convert it to the app

    A thin native shell around the live site. It does not carry its own copy of the app — it opens the real thing inside itself. That's not cosmetic: a local copy would never pass through the front door where private material gets cut out, which would hand Chantelle a version with your private material still in it.

    Then the notifications get built and proven, and after that the desktop version — a separate shell around the same site that doesn't touch the phone build.

    What's holding it up: step three, and one sitting at your Mac with Xcode. That's the only moment in the whole plan that genuinely needs you.

How long it takes

There are no hours, days or weeks anywhere in this plan, on purpose — you've corrected that twice. Instead every step says what is holding it up, and that's only ever one of four things: a decision only you can make, a credential or terms nobody has read, a sitting at your Mac nobody can do for you, or another step finishing first.

Steps one and two are held up by nothing at all. They are unblocked, and they are just work.

What we are deliberately not doing yet

This is the most valuable part of the plan, and it's the part that usually gets skipped: naming the work that a later step would throw away.

What already exists, so nobody rebuilds it

Already builtWhat that means
The native shellBuilt on 31 July for this exact app. Named, configured, icons drawn. It has never been opened in Xcode — that's your one sitting.
Skippy inside the appAlready there, already answering, already wired to the grounded engine. Not being rebuilt.
The privacy boundaryAlready enforced at the front door, per person, on every request. The conversion is designed specifically so this keeps working untouched.
The designChantelle chose it on 5 August, you confirmed it on the 6th. It is the family app's own look, not the business branding — so the business rebrand doesn't hold this up.

The three things you already answered

The app's permanent name

Live Free Love Free. One note, not a question: the name and its hidden identifier lock permanently at the first upload to Apple, so whoever does that upload confirms them first.

Whose phone is allowed to buzz

Both, with separate lists. I read "both buzz" as separate lists rather than asking again — the alternative puts a card about your private material on her lock screen, which was never on the table.

Android

After iPhone, and not scoped yet. It sits in the plan the way desktop does: named, waiting, costing nothing now.

For the creative director

The design itself is settled and is not reopened by this plan. What the creative director is walking into is step two, and there are four questions sitting with Chantelle that belong to design rather than to engineering:

None of these hold the build up. A screen whose question is still open gets built to how it behaves today and goes live with everything else; only the disputed piece gets revisited when she answers.

The one rule the creative director needs to know before starting

The drawings contain invented numbers — a weight of 84.2 against a real 209.8, a readiness of 81 against a real 77. The drawing supplies the structure, the order and the proportion. The live data supplies every single value. A builder matching the drawing copies the number, and that has happened here before.

What we honestly don't know yet

Nine open items are written into the plan itself rather than hidden. None is a contradiction — each is a call for whoever builds that part. The two worth knowing about:

How this plan was checked

The full specification was handed, eight separate times, to a reader who knew nothing except where the file was — no conversation, no context, no previous findings — and asked one question: what would you build from this? Seven rounds of fixes went back in.

That's what caught, before a single line of code existed: