Concept audit: Nah? ten months in

Concept audit: Nah? ten months in

Where the idea stands, who else is in the room, whether one person can build it, and what the server looks like if any family should be able to run its own.

The short version

  • The idea is sharp, but the product doesn’t exist yet. Ten months after the first prompt there are eight decision records, a design system and a blog, but no app and no server. The last commit was on 19 May.

  • The one-click server wish changes the product, not just the hosting. Path gave every person their own circle on one shared server. “Every family runs its own server” means every group owns a home. That is a different social model, and it is the better one for Nah?.

  • If homes win, Mastodon goes. Mastodon is built for public, federated, one-way following, and it needs five processes and 2–4 GB of memory per instance. A home needs one small binary and one database file.

  • “One click” for a normal family means a hosted home they pay a little for. Self-hosting stays open as the way out. This is the Home Assistant and Nabu Casa pattern, and it answers the funding question the vision never settled.

  • The corner Nah? wants is empty, for a reason. Retro and Yope raised $33M in 2026 on “no algorithm, no ads”, but both are closed. The one open, self-hostable family app, FUTO Circles, was archived in February 2025. The survivors in that corner all have a paid hosted plan, which is what hosted homes would be.

  • It is achievable if the MVP stays the size ADR-0008 set. Build one home for your own circle first. Hosting other families is a second project, and it should start only after six weeks of real use.

Where Nah? stands

Nah? began as a prompt on 19 November 2025. Here is everything that has happened since, oldest first, the way Nah?’s own feed would show it.

  • 19 Nov 2025The prompt. Path again, web-first, on Mastodon’s backend. “Sign up should be easy and effortless, creating private groups too.”

  • 28 Jan 2026The vision. Proposal, technical design and eight capability specs: a Mastodon fork plus a SvelteKit PWA. The build-in-public blog goes live.

  • 3 Mar 2026Tightening. Onboarding, invites, error states, a notification table and a full design system are written into the specs.

  • 25–27 Apr 2026The decision session. No counts anywhere. Invitation is connection. Text, voice and photo. Ritual onboarding. A daily digest. An MVP for five to ten friends. Flutter instead of a PWA. A single MVP spec is drafted in chat and never committed.

  • 19 May 2026The Flutter pivot lands. README, vision and the first capability spec move to Flutter. Eight decision records, PRODUCT.md and DESIGN.md are committed. This is the last commit.

  • 19 Jul 2026The stack ticket closes. The Linear issue “Native vs Flutter vs PWA” is cancelled. No Nah? work is tracked in Linear or Things after this.

  • 11 Sep 2026Today. No app folder, no server folder, no MVP spec.

What’s genuinely strong

  • A point of view in one sentence. “No counts anywhere” is structural, visible and nearly free to build. Most products never find their sentence.

  • Decisions that can be proven wrong. Every ADR names what would falsify it. That is rare discipline, and it made this audit easy.

  • A real design system. Tokens, type, motion rules and anti-references are written down, down to oklch values.

What’s broken

  • The specs still describe January. The decisions moved in April. The MVP spec meant to reconcile them lives only in a chat transcript.

  • Anyone reading the repo gets the old product. That includes a future you and any AI assistant you hand it to.

  • The public Flutter post tells an old story. It describes two AIs disagreeing. Your April notes already corrected that to one session pivoting mid-flow.

Where the specs and the decisions disagree

Topic The specs say The decisions say
Friend limit A “X/150 friends” counter and a constellation ring that fills up No counts or meters. The cap is a sentence: “your circle is full” (ADR-0004)
Notifications Push for requests and comments, a count badge on a bell One daily digest, no badges, opt in to more (ADR-0007)
Onboarding Email and password, profile photo, a three-card explainer, “Welcome home” Four beats: a slow sentence, one real question, a haptic, the quiet space (ADR-0005)
Reactions A heart button on every card, double-tap for Love No reactions in the MVP (ADR-0008)
Connecting Send a request, the other person accepts or declines Invitation is connection, in one motion (ADR-0003)

One factual error to fix

PRODUCT.md, ADR-0001 and ADR-0007 all say EU iPhone users lose push notifications under the Digital Markets Act. Apple announced that in February 2024 for home-screen web apps, then reversed it on 1 March 2024. Native apps were never affected, so the Flutter app gets push in the EU like everywhere else. ADR-0001 still stands on Bluetooth and widgets. The “EU users get a quieter app” caveat can simply go.

And one pattern to name

Every return to Nah? has produced documents and a re-decision: SvelteKit in January, a PWA matrix in April, Flutter a few messages later, and now the backend is open again. This audit could easily become the next round of that. So it ends in a build order, not in more options.

What we’re actually trying to do

The intent hasn’t wavered across ten months of documents.

A private home for your closest people, to share life without performing for the internet.

PRODUCT.md

The job is narrow: share a real moment with the few people who should see it, and see theirs. Success is years of quiet use, not engagement. Your notes add a layer the specs never picked up. The name means Not Alone Here. The idea seeds in SiYuan are about support: people carrying things together that used to need a big network. And the very first prompt asked for private groups, not only a personal circle.

Put together, Nah? is less “Path again” and more a home for the handful of people who carry each other. That matters for the choice below.

The fork the one-click wish exposes

You asked for something new: any family or clique should be able to run its own server in one click. That sounds like a deployment detail. It isn’t, because it decides who a server belongs to, and that decides who sees what.

</path> Nah? as a network One server. A circle per person. </rect> </ellipse> </ellipse> </line> </line> </line> </line> </circle> Sam </circle> You </circle> Wife </circle> Maya </circle> Jo your circle Wife's circle One Nah? server, run by the project </line> Nah? as homes A small server per group. Your app merges yours. </rect> Family </path> </circle> You </circle> Wife </circle> Mum on Nah? Cloud </rect> Uni friends </path> </circle> You </circle> Sam </circle> Ari on Sam's NAS </rect> Wife's friends </path> </circle> Wife </circle> Maya </circle> Jo on Nah? Cloud you're not in this one </line> </line> member member </rect> Your app one feed from two homes
On the left, Maya sees Wife's moments but not yours, and the server has to work that out for every moment. On the right, a home is the audience. Everyone in it sees everything in it, and your app stitches your homes into one feed.
  Nah? as a network Nah? as homes
Who owns a server The project The group, or Nah? Cloud on its behalf
Who sees a moment Your personal circle, which overlaps other people’s Everyone in the home you posted to
The 150 limit Per person, enforced across one big graph Per home, a simple member cap
Self-hosting Pointless without federation, because circles cross servers Natural: one server per group
Closest to Path The family group chat, done properly
Funding Donations Hosting fees, plus donations
  • Privacy by architecture becomes literal. Your family’s moments sit on your family’s server. “Who can see this?” has a one-word answer: the home.

  • It’s simpler to build. There’s no personal graph, no cross-circle visibility rule and no inner-circle feature. For a smaller audience, start a smaller home.

  • It matches how people already organise. Families and cliques already live in named groups. One motivated person brings the whole group, which softens the cold start. Yope reports that a fifth of its active users invited older relatives.

  • It can pay for itself. Hosting a home is a service people understand paying for.

What homes cost

  • It’s less like Path. Path’s magic was your own circle. The merged feed is your personal view, but every post now goes to a home. People with one home never see that choice.

  • Two decision records need replacing. ADR-0002 (Mastodon) and ADR-0003 (invitation is connection) change. Invitation becomes “join this home”. The other six survive intact.

  • One account per home. The app hides this by reusing your name and photo everywhere.

The competition

The market wants private sharing, and in 2026 money is flowing to it. But the winners are closed, venture-funded apps with a hook and a money lever. Nobody owns the combination Nah? is reaching for: a private space the group owns, open source and self-hostable. The one serious attempt was archived in February 2025.

For your people For an audience Run by a company Run by the group </rect> Closed, friends-only apps Retro · Yope · Locket · Friendlinq FamilyAlbum · Tinybeans · Marco Polo WhatsApp groups · iCloud Shared Albums Where the money and users are </rect> Owned by the group, for your people Immich, Ente: photo libraries, not homes Nextcloud, HumHub: they feel like an intranet FUTO Circles: this exact idea, archived 2025 </rect> Nah? homes the empty seat </rect> Public, company-run Instagram · BeReal · Noplace Built on reach, counts and ads </rect> Public, on small servers Mastodon · Pixelfed · GoToSocial Small servers, but public by default
Money and users sit top left. The top-right corner, a private space the group owns, has tools but no home. The one app built for exactly that corner was archived when its backer judged it too costly to commercialise.

The closest rivals

Product Where it stands in 2026 What it teaches Nah?
Retro $21M Series A announced in August. About 1M users, and the top app in Germany in December 2025. Premium is about $5 a month The closest live product. A weekly friends-only recap proves “no algorithm, no ads” can win with a subscription
Yope $12.3M in July. About 15M registered, and a fifth of active users invited older relatives Private micro-groups that pull in parents and grandparents. Its turn toward AI features is the part to reject
Locket 80M downloads, about 9M daily users, profitable Presence on the home screen through a widget. It sells its way past its own friend cap
Friendlinq Launched 2 September 2026, no numbers yet Nearly Nah?’s pitch word for word: chronological, invite-only, no ads, “free forever”. No stated way to pay for itself
FamilyAlbum 30M users, used by about 65% of Japanese parents Free unlimited storage. Nah? can’t match that and shouldn’t try
WhatsApp groups Pre-installed, free and end-to-end encrypted. Ads stay out of chats The real competitor. Nah? has to beat the family group chat, not Instagram
FUTO Circles Archived February 2025 Encrypted family social, open and self-hostable: exactly Nah?’s corner. It had a backer and still stopped
Immich and Ente Very active, and both ship Flutter apps Proof that Flutter plus a self-hostable server works for families, and that a paid hosted plan can fund the open work

Signs the market wants this

  • Money is moving. Retro and Yope raised $33M between them in 2026 with “no algorithm, no ads” in the headline.

  • The incumbents admit it. Meta’s own trial evidence puts friends’ content at about 7% of Instagram time. Instagram’s head says personal sharing moved into DMs years ago.

  • The scale is real. FamilyAlbum has 30M users and Locket about 9M a day.

Signs it doesn’t

  • Group chats already absorb the need. They’re free, installed and encrypted.

  • The winners are narrow hooks. A widget, a weekly recap, a camera, music. Nobody is winning as a general private network.

  • Path-shaped apps keep dying. Path in 2018, Cocoon in 2023, Circles in 2025. Cohost, a community-funded network, closed in 2024 with 2,630 paying members and a deficit.

Why Path actually died

Three things killed it. Facebook’s network effect came first, and Path’s own cap made it worse: “most of my friends weren’t on Path”. Then came a 2012 address-book upload scandal that ended in an FTC settlement over children’s data. Finally it was sold to Kakao in 2015, mostly for its Indonesian users. The cap it is remembered for went from 50 to 150 to 500 as growth stalled. Homes answer the first problem better than a personal circle does, because one person brings the whole group.

What everyone does that Nah? refuses

Every commercial player owns the server and runs two things Nah? rejects. One is a hook to bring you back: a daily push, a widget, recaps, AI. The other is a money lever: ads, or paywalls on storage, history or friend count. Refusing both is Nah?’s only durable difference from well-funded rivals, and group ownership makes the refusal believable rather than a promise.

It is also why the principled projects keep dying. In the open-source corner, every survivor has a backer or a paid hosted product. Nah? needs one of those from the start, and that’s the hosted home.

What families lack isn’t another feed. It’s everything group chats get wrong: photos get buried, there’s no archive, notifications are noisy, and nothing works for grandparents. A chronological home with a quiet digest answers the first three. Tinybeans’ email digest for grandparents who never install an app is worth considering later.

Is it achievable?

It’s three questions, and they have different answers.

Question Answer Why
Nah? for your own circle Yes The MVP is small: accounts, invites, three moment types, a chronological feed and a digest. On a simple backend it’s about three months of focused work, or around six months of evenings next to client work. TestFlight covers five to ten friends with only a light beta review.
Any family, one click In stages It’s a second product: provisioning, payment, backups, support and terms. Start it only once your circle has used Nah? for six weeks and still wants it.
A lasting project Unproven Money is flowing to private sharing in 2026, but to closed apps with hooks, while open projects keep hitting funding cliffs. Families already have free defaults in WhatsApp and iCloud Shared Albums, so Nah? has to be clearly nicer, not just more principled.

Rough effort for the MVP

The server figures come from the research pass. The app figure is my own estimate. All are focused weeks, not calendar weeks.

Piece Weeks
Home server: homes, invites, three moment types, feed, digest job, export 3–4
Push relay for Apple and Google about 1
Invite domain, home directory, demo home about 1
Flutter app: ritual onboarding, feed, three composers, invites, offline queue 6–8
Total 11–14

Hosting other families adds about two weeks for hosted homes and one to two for app-store packaging. A Nah? relay for home boxes adds two to three more.

The risks, biggest first

  • Re-deciding instead of building. The history above is the evidence.

  • Solo capacity. Nah? competes with paid client work for the same evenings. Voice is the costliest composer, so build it last inside the MVP.

  • The quiet-app trap. No counts, a daily digest and no reactions make a calm app, and calm apps can die quietly. ADR-0004 and ADR-0007 already name this, and the six-week test is where you’ll find out.

  • Store rules. Apple’s guideline 1.2 requires filtering, reporting, blocking and a published contact for any app with user content, private groups included. Apple holds the app’s publisher responsible even when the content sits on someone else’s server. The MVP list has none of this. “Remove from home”, “report to the home’s admin”, a project abuse contact and the directory’s cut-off switch would cover it. In-app account deletion is required too.

  • Children. Family homes will hold photos of children, and some members will be teenagers. Path’s FTC settlement was about children’s data. Set a minimum member age before the first family joins. In Germany, under-16s need parental consent under GDPR.

  • Hosting other people’s family photos. Nah? Cloud would make CDIT a hosting provider for EU users. Closed homes likely fall outside the Digital Services Act’s “online platform” duties, but notice-and-action, a privacy policy and GDPR terms still apply. Run a compliance pass before the first paying family.

Server architecture, in depth

Start from what a home server has to do, because it’s far less than Mastodon does.

The whole job

  • Create accounts and sign people in.

  • Turn an invite link into membership of a home.

  • Store moments: a line of text, one photo, or up to 60 seconds of voice.

  • Serve the feed.

  • Wake phones once a day when the home had new moments.

  • Export everything.

`-- The entire feed algorithm for a home SELECT * FROM moments WHERE home_id = ? ORDER BY created_at DESC LIMIT 30;`

A home has at most 150 members, so there’s no fan-out, no timeline cache and no ranking. There’s also no search, no counts and no discovery, so the server never has to understand what a moment says. That pays off later, in the encryption section.

Backends compared

Five realistic options, judged on one question: could a family run one without ever calling you?

Backend What runs Memory Fits Nah?’s model One click per family
Mastodon 4.6 Web, streaming, Sidekiq, PostgreSQL and Redis: five containers, plus TLS and email 2–4 GB No. One-way follows, counts in every API response, and a permanent fork to maintain No. Managed hosts exist because it needs an operator
GoToSocial 0.22 One Go binary with SQLite 250–350 MB Partly. Still follow-based, still beta, and its allowlist mode is “experimental” Nearly, but the product fights the model
PocketBase 0.39, as a Go framework One Go binary with SQLite, files on disk or S3 under 100 MB Yes. You write a small social layer, and there’s an official Dart SDK Yes
Serverpod 3 A Dart server plus PostgreSQL Postgres-sized Yes, and it shares Dart models with the app No. PostgreSQL is required
Supabase, self-hosted Ten or more containers 1.5–4 GB idle Yes No

The recommendation

Build “Nah? Home” as one Go binary on PocketBase, used as a framework rather than as an app. PocketBase brings sign-in, file storage, live updates, scheduled jobs, backups to S3 and an admin screen in one file, with an official Dart SDK for the Flutter side. You add the social layer, which for this MVP is small: homes, invites, moments, the digest job and export. Voice and photos are encoded on the phone, so the server never runs FFmpeg.

Two honest caveats. PocketBase is still 0.x, with one maintainer and breaking changes between releases, so pin the version and vendor it. If it ever stalls, what’s underneath is plain Go and SQLite, which you can keep running without it. GoToSocial is the runner-up if keeping the Mastodon API matters. It saves writing a server, but every Nah?-specific rule would fight a federation server, which is how Hometown ended up a year behind.

One lesson to take from Mastodon: an instance’s domain can never change, so its identity is welded to a hostname. Give every home an ID backed by its own key from day one, so it can prove it’s the same home after it moves.

How the pieces fit

</path> </rect> The group's homes </rect> Run by the Nah? project </rect> Apple / Google push APNs and FCM </rect> Nah? app one session per home offline cache and queue </rect> Home A, on Nah? Cloud one binary, one SQLite file media on disk or S3 </rect> Home B, on a cousin's NAS the same binary reached through a tunnel </rect> Push relay forwards sealed wake-ups </rect> nah.app/i invites and home directory </line> </line> moments & media </line> wake-up </polyline> </polyline> push, signed with the publisher's key </line> notification </polyline> the invite link opens the app, and the directory says where the home lives
Moments and media only ever travel between phones and their home. The project runs two small things every home needs: a push relay, and the invite domain with its directory. Neither one ever sees a moment.

What the project must run, whatever else happens

  • A push relay. Apple and Google only accept pushes signed with the app publisher’s keys, and a self-hosted home can’t hold those. Homes send a sealed wake-up to a small relay that forwards it. Mastodon’s apps, Ice Cubes, and Bitwarden’s apps talking to self-hosted Vaultwarden all work this way. With the payload encrypted to the phone under the Web Push standard, the relay only learns that some home woke some phone.

  • The link domain. iOS only opens an app from links on domains listed in the app’s entitlements, so the invite domain has to be yours. Put the home’s ID in the link and the invite token after the #, which browsers never send to a server.

  • A home directory. A small table mapping each home’s ID to its current address. It lets a home move hosts without anyone needing a new invite. It also gives you a switch to cut off a home that breaks the rules, which Apple expects from the app’s publisher. It knows which homes exist, not who is in them.

  • A demo home for App Review. Reviewers need a working account on a working home.

Nothing else has to be central: no global accounts, no analytics, no copy of anyone’s moments.

The one-click ladder

Only the top rung is one click for an ordinary family. The rungs below it exist so nobody is locked in, and that is what makes the top rung trustworthy.

Rung Who it’s for What they do What it costs them
Nah? Cloud Any family Tap “Start a home” in the app, pay, share the invite link A few euros a month, set by you
PikaPods The relative who has heard of self-hosting Pick Nah? Home from the catalogue. TLS, updates and backups are handled About $1–2 a month. PikaPods shares 20% of revenue with you
Home-server app stores Owners of an Umbrel, CasaOS, YunoHost or TrueNAS box Install from the store, then scan a QR code in the app Hardware they already own
Container or binary Tinkerers Run one container or one binary on a NAS or VPS Their own time

Getting listed is mostly pull requests: Umbrel, CasaOS, YunoHost and TrueNAS each take a manifest in their app repositories. Coolify wants 1,000 GitHub stars first, and Hetzner’s app catalogue isn’t taking new apps.

Ente, the open-source encrypted photo service with a Flutter app, is the useful warning. Its self-hosting is well built, yet the app hides the “use my own server” switch behind tapping the logo seven times. Hosted is the product and self-hosting is the guarantee. Plan for the same split.

Payment is part of the click. Selling hosting inside the iOS app means Apple’s in-app purchase, with a 15% cut under the Small Business Program. It is also the most one-click payment there is.

Home boxes behind a router

A box in someone’s living room has no fixed address, no domain and no certificate. The options, from least to most work for you:

  • Tailscale Funnel, built into the binary. Tailscale’s Go library can publish the home on a public ts.net address with a certificate. The family still needs a free Tailscale account, and Funnel’s bandwidth cap isn’t published.

  • Cloudflare Tunnel. Solid, but it needs a domain on a Cloudflare account. The free quick tunnels are for testing only and drop the live-update connection PocketBase uses.

  • A Nah? relay, later. Copy Home Assistant’s remote access. The home dials out to a relay the project runs, and the relay routes traffic by hostname without decrypting it, so the certificate’s key stays at home. A thousand homes would cost tens of euros a month in servers. Plan for Let’s Encrypt’s limit of 50 certificates per domain per week before you issue one per home.

Why not peer-to-peer

Every serverless stack hits the same wall. iOS suspends background connections, so a photo posted at 9pm reaches nobody until its poster reopens the app. You end up needing an always-on peer, which is a home server by another name. None of the candidates has a Flutter-ready, stable SDK a solo developer could ship on in months. Iroh reached 1.0 in June 2026 and is worth a second look later as a way to reach home boxes without a relay, but it has no Dart bindings yet.

What a home costs to run

These are estimates. They assume photos are re-encoded on the phone to about 550 KB including a thumbnail, voice clips are 32 kbps Opus at about 150 KB each, originals aren’t kept, and storage costs Backblaze’s $6.95 per terabyte per month.

Home Moments a day Media a year Storage a month Traffic a month
Busy clique, 150 people 20, half photos about 2.5 GB about $0.02 16–20 GB
Typical family, 12–20 people 3 about 0.35 GB under $0.01 1–2 GB

The smallest Hetzner server costs €5.49 a month, includes 20 TB of traffic, and can hold dozens of hosted homes. A Raspberry Pi at home uses about €1 of electricity a month. Storage and compute round to zero per home. What costs money is your time: support, backups and upgrades. Price for that, not for the disk.

What it could earn

Nabu Casa sells Home Assistant Cloud for $6.50 a month. It is profitable without outside investors and funds the Open Home Foundation. It also sits on more than two million active Home Assistant installs, and its subscriber numbers aren’t public. The model works, but it monetises a huge free base, and Nah? starts from zero.

Paying homes at €3 a month Before Apple’s cut After 15%
100 €300 a month €255 a month
1,000 €3,000 a month €2,550 a month

A hundred homes covers the infrastructure many times over and pays for none of your time. A thousand is a small but real income. Treat hosting as what keeps Nah? alive, not as a business case, until the circle test says people want it.

Backup and moving out

A home is one SQLite file plus a folder of media. Litestream streams the database to object storage continuously, and the media folder syncs alongside it. “Move my home” is a zip of both, downloaded from the app and restored anywhere the home binary runs. Leaving in one tap is the promise that makes paying for Nah? Cloud feel safe.

Encryption: later, but cheap

With Nah? Cloud you could read the families’ moments, exactly as the Mastodon plan admitted for its single server. Homes give a clean way out later. Because the server never searches, ranks or counts, it never needs to read a moment. Moments and media can become encrypted blobs without changing the server: the home’s key travels after the # in the invite link, and phones make their own thumbnails. The hard part is removing someone, which means handing a new key to everyone who stays. That isn’t MVP work. Just don’t add server features that need to read moments, and the door stays open.

What to decide, in order

  1. Pick the model: network or homes. Everything below assumes homes. If you choose network, keep Mastodon and drop the one-click goal.

  2. Write two decision records. One replaces ADR-0002 with the home server. One replaces ADR-0003 with “invitation is joining a home”.

  3. Clean the specs in one pass. Commit the MVP spec against homes, mark the January capability scaffolds as superseded, and remove the EU push claim.

  4. Build the walking skeleton. Run one home server on your existing Komodo fleet behind a Cloudflare tunnel. Build a Flutter app that joins a home by invite link, posts text and shows the feed. Then add photo, then voice, then the digest.

  5. Spend six weeks with your circle. Judge it by the “what would prove this wrong” lines already written in the ADRs.

  6. Only then build for other families. Harden the push relay, then Nah? Cloud, then the one-click listings.

Sources

Audit and policy

Servers

Push, hosting and connectivity

Competition

Prepared from the Nah? repository, the April decision notes in SiYuan, Linear, and two research passes on 11 September 2026. Estimates are marked as estimates.