Skip to content

Prototype: fictional data, not a real service

Demo with made-up data. Do not enter real details: anyone can use this demo.

Concept — for decision

Choices: mainstream UX or current design

The owner's principle: mainstream best-practice UX is the default. The mission is protected by technical, legal and organisational measures, not by a worse experience. Per choice: A = mainstream, with the measure; B = the current protective design; C = something else.

Look at the two screens in each row and pick A, B or C in the register. This page stores nothing. All names, amounts and rooms are invented. S = under a day · M = days · L = weeks

  1. UX-1 · Names and profile photo

    EffortM

    What it protects: Organisers stay unrecognisable; membership cannot be inferred from metadata.

    Measure with A: Per room you pick name or pseudonym; a one-time explainer; room names never name a union (UX-11).

    A · MainstreamName and photo, your choice
    B · Current designPseudonym only
  2. UX-2 · Public rooms

    EffortM

    What it protects: No infiltration of sensitive rooms; no linking through the moment someone joins.

    Measure with A: Private and sensitive rooms by invitation only, with batched admission.

    A · MainstreamBrowse and search rooms
    B · Current designRooms per city and language
  3. UX-3 · Joining is instant

    EffortS

    What it protects: The platform cannot link signing up and joining through timing.

    Measure with A: Instant in open rooms; private rooms: ‘in within minutes’ with progress, shorter windows.

    A · MainstreamTap and you are in
    B · Current designBatched admission at a set time
  4. UX-4 · Read receipts and typing

    EffortS

    What it protects: Metadata: the server stores receipts and typing in the clear.

    Measure with A: On in 1:1 and small private groups, off in large rooms; you can switch it off; listed in ‘what we can see’.

    A · MainstreamTicks and ‘typing…’ in 1:1
    B · Current designOff everywhere
  5. UX-5 · Notification previews

    EffortM

    What it protects: The Apple or Google push service sees no sender and no text.

    Measure with A: The push stays content-free; your phone decrypts and only then shows sender and text.

    A · MainstreamSender and text in the notification
    B · Current designContent-free notification
  6. UX-6 · History on a new phone

    EffortM

    What it protects: A lost or seized phone gives away no old conversations.

    Measure with A: Encrypted backup, opened only with your key or passphrase; off by default in sensitive rooms.

    A · MainstreamRestore with a recovery key
    B · Current designFrom joining only
  7. UX-7 · Logging in again

    EffortL

    What it protects: No account takeover; no link to a phone number or e-mail.

    Measure with A: The platform code stays the proof that you work there; a passkey per device; recovery e-mail optional, encrypted and not linked to the platform (to decide).

    A · MainstreamLog in with a passkey
    B · Current designPlatform code only
  8. UX-8 · Finding colleagues

    EffortS

    What it protects: Your address book and who you know (your social graph) never reach our server.

    Measure with A: No address-book upload; colleagues share a link or QR code themselves and get in with their own platform code.

    A · MainstreamInvite by link or QR code
    B · Current designNo way to find or invite
  9. UX-9 · Income overview

    EffortM → L

    What it protects: Data Governance Act, no PSD2 licence needed, no price signalling through comparisons (competition law).

    Measure with A: Charts, categories and statement import now; regional averages only after the ACM/DGA route (D-024), via secure aggregation.

    A · MainstreamLike a banking app, regional average later
    B · Current designYour own figures only
  10. UX-10 · Work preferences

    EffortS

    What it protects: No matching with platforms (DGA); polder.tech stays neutral.

    Measure with A: One tap with your consent, only with the body you choose; you can withdraw any time. No matching.

    A · MainstreamShare with your representative
    B · Current designFor yourself only
  11. UX-11 · Room names and search

    EffortM

    What it protects: A room name never sits readable on the server or in a search index.

    Measure with A: Room names encrypted; search runs on your phone. Same ease, nothing readable on the server.

    A · MainstreamReal names, search works
    B · Current designNeutral names, search off
  12. UX-12 · Getting help

    EffortS

    What it protects: Neutrality between bodies; polder.tech gives no legal advice.

    Measure with A: A short ‘what happened?’ choice → best route; representatives and moderation first, help organisations as links.

    A · MainstreamOne ‘Get help’ button
    B · Current designChoose from three routes
  13. UX-13 · Onboarding length

    EffortS

    What it protects: Explicit consent for sensitive data (GDPR Art 9) stays in place.

    Measure with A: Only what is needed to start; consent for representatives is asked at first contact.

    A · MainstreamShort and progressive
    B · Current designCode, pseudonym, all consent upfront
  14. UX-14 · Metrics to improve the app

    EffortM

    What it protects: Trust: no tracking, no profile of who does what.

    Measure with A: Off by default; counters on your phone only, aggregated, no identifiers; documented publicly.

    A · MainstreamOpt-in counters, private
    B · Current designNo metrics at all