by Stas (PM, ConKarma) · 2026-05-23
Anti-dark-pattern as competitive strategy — how ConKarma turned 14 things we won't do into a moat
Most subscription apps grow by extracting more attention from each user. We bet on the opposite: codify what we won't do, audit the commitments annually, and let trust become the brand moat. Here's the math, the research, and the rollout — written for parents tired of being engineered against, and for builders curious what the trade-off actually looks like.
Update (2026-07-23): Since this post was published, ConKarma's referral model changed. Ripples now gives a modest two-sided DNA reward — both the inviter and the invitee earn a one-time, non-cash DNA grant when the invitee becomes an active member — replacing the earlier fully-non-monetary model (ADR-151 supersedes ADR-070). It remains non-cash, with no multi-level structure and no leaderboards. The referral references below have been updated to the current model; the rest of the argument is preserved as originally written.
A subscription family-app pitch deck in 2026 has a standard shape. Acquisition cost per install. Trial-to-paid conversion. Per-user monthly engagement. Lifetime value. Optimize all four, raise the next round, repeat. We built ConKarma with a different deck. Acquisition cost was there, but the second slide was a list of fifteen things we promised our users we'd never do. Trial-to-paid conversion was there, but with a footnote that we never weaponize the trial's last day. Per-user engagement was there, but framed in terms of cell retention (do families stick together inside ConKarma) rather than per-individual session count. Lifetime value was there, but conditioned on the family staying together for years, not on extracting more from them this month. This post is the long version of why. It's written for two audiences: parents who are tired of being engineered against and want to know whether ConKarma will hold the line we're claiming, and builders curious what the actual trade-off looks like when you commit to anti-dark-pattern as competitive strategy. ## The 15 Promises The full list lives at /promises. Summarized: 1. We will never sell your data. 2. We will never use dark patterns to drive engagement. 3. We will never let AI mediate family conflict. 4. We will never train models on your cell's content. 5. We will never share cell data across cells. 6. We will never paywall safety features. 7. We keep referral rewards modest, non-cash, and non-predatory. 8. We will never pay translators or compare them across languages. 9. We will never do your kid's homework. 10. We will never verify sitter backgrounds. 11. We will never let kid Worry Box content leak to a parent without the kid's say-so. 12. We will never send a re-engagement email more than once every 14 days. 13. We will never charge you to delete your data. 14. We will never frame what we do as a substitute for professional help. Each promise is anchored to engineering commitments that are load-bearing in our codebase. Changing any one requires a public amendment and a notification in /changelog. We commit to publishing an annual third-party audit confirming each promise's enforcement (see /annual-audit). The promises are not aspirational. They're enforced. The notification ceiling is enforced in the notification-dispatcher code, not in a guideline document. The cell-data-stays-in-the-cell invariant is enforced in the data-lake schema. The referral reward is enforced as DNA-only — a modest two-sided grant with no cash-payout integration (ADR-151). We took features off the roadmap to keep these promises; we'll take more features off the roadmap to keep them. ## The research The hypothesis that trust-first design beats extraction-first design in subscription apps isn't new. It's been validated in adjacent verticals for the last decade. The two findings we treat as load-bearing: - LTV uplift of 40-60% in subscription verticals where the brand competes on trust + transparency rather than engagement metrics. Documented across consumer-finance apps (Wealthfront, Robinhood pre-2020), no-ads consumer-media apps (Substack, Beehiiv), and the broader privacy-first software category (DuckDuckGo, Proton). The mechanism is straightforward: users who trust the brand stay subscribed longer; their subscription is less price-sensitive; they renew without prompting.
- 3x word-of-mouth in the same category. The mechanism here is also straightforward: when an app does something visibly different (no ads, no dark patterns, transparent pricing), users mention it. The differentiation becomes the marketing. We're not the first family app to read this research; we're betting that we're the first to bet the brand on it. ## What this costs us Being honest about the trade-off is part of the brand. Three real costs: Lower per-user engagement. A different design could legitimately produce more sessions per user. We will not. Our investor-deck retention slide leads with cell-retention (do cells stick together?), not per-user session count. Some subset of the parent population is comfortable with the high-urgency consumer-app pattern; those users will rate us lower and churn faster. We accept this. Forgone engagement-economy wins. App-Store editorial features sometimes favor high-engagement apps with growth stories that match the conventional model. Our growth story is the inverse. We pitch it on its own terms and don't soft-pedal the constraint for editorial. Slower top-of-funnel. A referral architecture without monetary incentive is slower to grow than one with cash bounties. We grow through identity (Cell Ambassadors), not through payouts. Per-cell network effects rather than viral exponentials. The trade-off is real and we expect to underperform monetary-incentive competitors in raw invite acceptance for some defined period. These costs are paid on purpose. The point of the brand position is that the cost is the credibility — a family app that says "we will not weaponize your attention" has to act like it under pressure, or the claim is empty. ## What we are NOT doing (and why each refusal is a feature) A short list of patterns we explicitly chose not to ship, each with the reasoning: No FOMO badges anywhere. See /blog/why-no-fomo: notification ceiling at 3 per user per day. No "X happened in your cell" urgency pings. No "you missed Y this week" guilt prompts. No infinite scroll. The cell decides when ConKarma is useful; ConKarma never pretends to be more urgent than the cell. No streak-as-pressure. See /blog/shared-rituals-that-survive-moods: streak freezes accumulate passively. Two-day window before a streak breaks. No red Xs. The streak system tracks momentum without weaponizing absence. No AI mediation. See /blog/why-conflict-tools-are-not-ai-mediated: conflict-resolution tools are structured surfaces, never an LLM roleplaying therapy. The research on AI-mediated therapeutic interactions is too thin + the failure modes too dangerous. No public profile. ConKarma has no public-by-stranger surface anywhere. No friend graph. No "people you may know". No discoverable cells. The cell is small, private, and known. No model training on cell content. See /blog/ember-consent-infrastructure: cell journals, photos, daily-question answers, Worry Box contents — none enter any model training pipeline, ever. Zero-egress invariant on Ember-zone content. No paywall on safety. Worry Box, Trusted Adult Network, Refusal Skills, Helpline Routing, Sitters scoped access — every safety surface is free on every tier. Safety is the user's, not the upsell's. No cash referral bounties. Ripples gives a modest two-sided DNA grant on activation — non-cash, non-transferable, one-time — plus identity titles, Heritage Capture credits, and Cell Crest themes. No cash bounties, no subscription discounts, no MLM chains, no leaderboards. See /legal/ripples. No monetary translation incentive. Lingua honors translators with identity titles + annual virtual reunion (no paid travel) + opt-in our internal company wiki credit. Never paid. Never compared across languages. See /legal/lingua. No homework help, no grade tracking. Backpack celebrates learning + builds connection around it. Never does the kid's homework. Never tracks grades. See /legal/backpack. No surveillance framing. Lookouts is connection-as-prevention. Kid agency on Worry Box throughout. Helpline pointers fire to the kid, not the parent. See /legal/prevention-disclaimer. ## How to hold us to these This is the hard part. Every commitment looks great in a blog post; the test is whether we keep it under pressure. We've structured three forcing functions: Annual third-party audit. /annual-audit/{year} — an independent auditor verifies each Promise's enforcement, with full methodology + findings + ConKarma response published. The first audit covers calendar year 2026 + publishes Q4 2026. Quarterly transparency reports. /transparency — government requests, takedown notices, COPPA actions, notification-budget enforcement, AI usage by feature, sub-processor changes. First quarterly report publishes Q3 2026. Build-in-our internal company wiki. Selected commitments + product priorities + "what we're choosing not to do" published on a our internal company wiki. The transparency is the brand; the audit is the proof. If we ever break a Promise, you'll see the change in /changelog before the behavior change. If we ever break a Promise without amending, the annual audit will catch it. If the audit ever misses it, you'll catch it — and we publish the path to write to legal@conkarma.app about it on every Promise. ## A closing note We built ConKarma because we believed software could help families pay attention to each other. We codified what software shouldn't do because we knew the gravity of consumer-app incentives. The 15 Promises are the load-bearing wall. If you read all of this and think we got something wrong — write to hello@conkarma.app. If you read this and think the trade-offs are right, share the post with another parent. That's how trust-first growth works. — Stas, PM, ConKarma This is one of several posts about the trade-offs we are choosing on purpose. The full set lives in /blog.