Skip to the page

Invented app · built on Kindling · Why Kindling · The apps · The library · The spec

familiar faces

Under the hood

How the app is built

Familiar Faces hosts no Pools. It reads other people’s, checks each person’s rules, and sends one email a week. Here is every setting, how Theo’s and June’s groups were found, the block lists, the files, and what the v0.1 schema can’t say yet.

Settings, mapped to the spec

SettingValueSpecWhy
Pools hostednone§8.3 §10.2Familiar Faces is a client. The groups belong to the places that keep them. Our discovery file lists no Pools.
How it finds your groupsyour page’s address, and pages under it, in each Pool’s entries§3.4 §3.5Pools and profiles are coupled by URL. Theo gave one address; three of his pages turned up.
How it finds other groupshosts’ well-known files, and any registry§8.3 §8.5 §10.1The same way anyone can. We hold no private directory.
Which Pools it readsthe rule on the About page§3.2Friendship and community, never dating, never a Pool whose keepers ask us not to.
Unlisted Pools you’re inonly if you give us the address§3.2 §8.2They are in no well-known file, on purpose. We don’t go looking.
Order of groups and peoplethe order they said yes§3.4No ranking and no score, so nothing to optimize.
Your mutualspeople listed in two or more of your groups§3.5A keeper counts only where their own page is listed.
Verificationbeside every person, in words and with an icon§4.5 §11.2Always the level from the group they appear through, because a vouch is local to one Pool.
Who can write to whomKindlingDemo.canMessage: accept_from, no_cold_messages, the Pool’s floor, two block lists§7.1 §7.2 §7.3Checked for every group you share, with the reason in words, before anything is sent.
Block listsKindling public · Circular consortium§7.3Every hello is checked against both.
Requestsanswered with the host’s own handshake, here or at the host§5.2One room, many doors: an answer on the Board shows here, and the other way round.
Auto-acceptshown, never set for you§5.5Theo and June have none, so a request waits for them.
Leaving a groupone action, a withdrawal to its keeper§5.3From every screen that names the group, and from the email.
Silent inclusionimpossible here§5.1 §11.2Familiar Faces can’t add anyone to anything. “Ask to be asked in” writes to a keeper; you still say yes.
Transportemail, and one digest a week§6.1No notifications, no badges. Everything works from an inbox.
Portraitsdrawn from each person’s own page, never copied or stored§2.5People without pictures on their page get their initials.
What we read from a pagethe parsed profile, and the pictures§2.3Never age, gender or what anyone is seeking, even where a page says it.
Dormant Poolsshown to members with a notice and the keeper vote§9.1 §9.3Chess After Close is resting; Theo sees why, and the vote.
Moneynothing at the connection layer§1.3Hosts chip in by choice, which buys no placement.
Loading a productindex.html#load-<product key>, from the Kindling registry, embedded when the app is built§3.5 §8.3The Groups screen shows only that product’s groups, by the same rule as above: yours where you’re in them, nearby ones you could join, and ones read only for their members, each saying so. Clear it and everything is as before.

No Pools of its own

A host publishes /.well-known/kindling-pool so crawlers and registries can find its Pools §8.3 §10.2. Familiar Faces’ file names who we are and how to reach us, and lists no Pools, because we keep none. It lives with the company’s site: familiarfaces.example/.well-known/kindling-pool.

The app reads the manifests linked from the compatibility table, each at its own host.

{
  "schema_version": "0.1",
  "pools": [],
  "operator": {
    "name": "Familiar Faces, a friendship app that reads the groups you already belong to",
    "contact": "hello@familiarfaces.example",
    "url": "https://familiarfaces.example"
  }
}

How each viewer’s groups were found

One address each, compared with every manifest’s entries §3.5, with each entry’s own consent proof §3.4.

Theo Lindqvist

Gave us theo-lindqvist.carrd.example. Found in:

June Okafor

Gave us june-okafor.notion.example. Found in:

The block lists every hello is checked against

Anything on these lists is refused before it reaches anyone §7.3.

Kindling public block list

Copy: blocklist.json · version 3, 20 September 2026

The block list the Kindling project will publish under SPEC.md §7.3, for identities and implementations with confirmed abuse. The entries here are illustrative until the registry opens. No personal details are ever published.

TypeTargetReason
implementationscrapekit/0.3scraping
identitypromo-blast@mail.examplespam

The Circular consortium block list

Copy: examples/circular/blocklist.json · version 8, 27 September 2026

Shared by every member of the Circular consortium. Each member subscribes; any member may propose an entry, and two others must second it.

TypeTargetReason
curator_identitylisted-them-anyway@mail.exampleconsent_violation
pool_urlhttps://free-friends-now.example/pools/everyone.jsonconsent_violation
identitybulk-intros@relay.examplespam
implementationscrapekit/0.3scraping

Messages, as the app writes them

Samples, each validated against kindling_message.schema.json. The app writes the same shapes when you say hello or leave a group; open the message under any of them.

What the v0.1 schema can’t say yet

Where the specification text and a schema disagree, our JSON follows the schema. These are the gaps that touch an app like Familiar Faces.

  1. A client has no place in the protocol.

    v0.1 defines hosts, UIs, parsers and messaging clients §11, but nothing for an app that only reads other people’s Pools. Familiar Faces publishes a well-known file with no Pools, so crawlers find an operator and a contact. A Pool can’t tell which apps read it.

  2. Nothing links one person’s pages.

    Theo keeps a page for Meals When It’s Hard at …carrd.example/meals. Nothing in v0.1 says it is his §3.5. We count a page under your own address as yours, and say so. A page on another host would not be found.

  3. Hosts can’t say which apps should read them.

    Foul Weather Friends asks that no app read the Check-In Circle; Slack Water and Rain Check name the apps that should read theirs. There is no field for this, so the notes travel outside the manifests, and we follow them by hand.

  4. Nothing says “this Pool is for dating”.

    Intent tags are free text §3.2. We keep out any Pool tagged dating. A Pool tagged romance would slip through, and one tagged both friendship and dating is kept out whole.

  5. No field for an event, a weekly night or a rhythm.

    Tuesdays at eight, the first Friday, release night on 16 October: all of it lives in charters and governance rules §3.2, and in hosts’ notes. This week is built from sentences we quote, and a charter that changes its wording drops out of the week until we read it again.

  6. A keeper is not a member.

    Curators are listed apart from entries §3.2. Ada keeps her listeners’ list without being on it, so she is Theo’s mutual only through Start a Band.

  7. A digest has no message type, and no single Pool.

    §6.3 lists four types and the schema six. Neither has a digest, so the Monday email is a system message spanning several Pools, and via_pool holds one, so it has none.

  8. There is no way to ask to join.

    The handshake starts with a curator §5.2. “Ask to be asked in” is an ordinary email to the keeper.

  9. Verification is per entry.

    A vouch is local to one Pool §4.4. Theo is vouched in Rides to Appointments and email verified everywhere else, so the same person shows two levels on one screen.

  10. A Pool’s sender floor can’t name vouching.

    Friday Subs asks senders to be at least oauth §7.1. Theo, email verified, can’t write through it; he can write to the same people through Start a Band.

  11. Mutual interest has no field.

    no_cold_messages needs “confirmed mutual interest” §7.2, and nothing records it.

  12. Level names differ between the text and the schema.

    §4.5 says email-verified and oauth-verified; the schemas say email and oauth. Our JSON follows the schemas; our screens use words.

  13. Leaving, for a keeper.

    June keeps the seed swap and is listed in it. A withdrawal §5.3 takes her page off the list; nothing in v0.1 says what happens to her keeping it. We say so on the screen and leave the keeping alone.