Blog

Building in public.

Architecture notes, policy drafts, release stories, and the occasional unvarnished lesson from building a platform where privacy isn't a tagline.

Featured
Engineering April 18, 2026 · 12 min read

Why your PII never touches our servers.

A technical walkthrough of the Secure Vault — the hardware-encrypted on-device store that holds every Clikkin member's identity, keys, wallet, and badges — and the query/response protocol that lets spaces ask narrow questions without ever seeing the underlying data.

AP
Anya Petrova
Platform Architect
EngineeringApr 12 · 8 min

Badges as a single authorization primitive.

How we collapsed roles, subscriptions, promotions, and verifiable credentials into one composable type — and what it bought us in implementation simplicity.

§
PolicyApr 8 · 6 min

Our stance on government data requests.

We can't decrypt what we don't hold keys to. Here's exactly what we can hand over if compelled — and exactly what we can't.

v2.0
ReleaseApr 2 · 4 min

Space Apps (beta) is live on Pro Max.

WASM-based programmable actions, a sandboxed mini-app runtime, and the first six community-built apps — polls, events, bookmarks, shops, AV, and analytics.

StoryMar 28 · 10 min

How Maker Garage grew to 12,000 members in 90 days.

A community-led conversation with the founder of maker.garage — one of the first Branded App tier spaces — on moderation, monetization, and the parts nobody warned her about.

EngineeringMar 22 · 14 min

Anatomy of the coin economy.

A full-reserve, Treasury-backed, permanently-pegged credit system designed to make spam expensive and abuse burn real money. The math, the accounting, and the audit model.

PolicyMar 14 · 7 min

Moderation transparency: every action, attributed.

Why we reject anonymous moderation and what changed the day we started showing moderator identity on every action.

v1.9
ReleaseMar 6 · 3 min

Clikkin Passport rolls out widely.

Document scan, selfie, and liveness via Didit. PII stays on-device; the server holds a boolean flag and a few HMACs. Two-year validity.

StoryFeb 28 · 9 min

What we learned from the first 100 Early Partners.

Retention, coin burn, moderation patterns, monetization paths. The unsexy numbers from the sponsored-app scholarship's first quarterly cohort.

EngineeringFeb 20 · 11 min

Client-side encryption for private spaces.

How space admins hold the only keys that can decrypt their restricted content — and what happens, concretely, when a space is subpoenaed.