Under the hood
How Familiar Faces is built
Familiar Faces hosts no Pools. It reads other people’s, checks each person’s rules, and sends one email a week. Here is every setting, every Pool it reads and what it does with each, and what the v0.1 schema can’t say yet.
Settings
What we chose, and why
| Setting | Value | Spec | Why Familiar Faces chose it |
|---|---|---|---|
| Pools hosted | none; the well-known file lists an empty set | §8.3 §10.2 | Familiar Faces is a client. The groups belong to the places that keep them. |
| How it finds Pools | hosts’ well-known files, and any registry | §8.3 §8.4 §8.5 §10.1 | The same way anyone can. We hold no private directory. |
| How it finds your Pools | your page’s address, and pages under it, in each Pool’s entries | §3.4 §3.5 | Pools and profiles are coupled by URL, so your page is the only key we need. |
| Unlisted Pools you’re in | only if you give us the address | §3.2 §8.2 | They are in no well-known file, on purpose. We don’t go looking. |
| Sign-in | a link to your Kindling identity email | §4.1 §4.2 | No new account, no password, no new profile. Only the owner of the page can open Familiar Faces for it. |
| What you see | Pools you’re in, and public Pools | §3.2 | Never an unlisted or invite-only Pool you’re not in. |
| Dating Pools | kept out of the friends view, public or not | §3.2 | Friendship here. A person’s dating life stays where they put it. |
| Order of people | the order they joined each Pool | §3.4 | No ranking, no score. Nothing to optimize. |
| Verification | shown beside every person, in words and with an icon | §4.5 §11.2 | Always the level from the Pool the person appears through, because a vouch is local to one Pool. |
| Who can write to whom | each person’s accept_from and no_cold_messages, the Pool’s minimum, two block lists | §7.1 §7.2 §7.3 | Checked before a hello is sent, with the reason shown. |
| Block lists | Kindling public · Circular consortium | §7.3 | The same two lists the Board and Ferry Room Players subscribe to. |
| Handshakes | shown as the host sent them, answered with the host’s own links | §5.2 | Familiar Faces is a door. The request and the decision stay with the Pool. |
| Auto-accept | shown, never set for you | §5.5 | Theo has none, so a request waits for him. |
| Leaving a Pool | one action, a withdrawal message to its keeper | §5.3 | Within sixty seconds, from the map or from the email. |
| Silent inclusion | impossible here | §5.1 §11.2 | Familiar Faces can’t add anyone to anything. It only reads. |
| Transport | email, one digest a week | §6.1 | No app and no notifications. Everything works from an inbox. |
| Message types | intro for a hello, reply, withdrawal, system for the digest | §6.2 §6.3 | The schema’s six types; see the gaps below. |
| Photos | none shown, none copied | §2.5 | We point at your page. Your page shows what you choose. |
| kindling_noindex | honored: a noindex profile never appears | §2.7 | It means “in no Pool at all”, so it never reaches us. |
| Dormant Pools | shown with a notice and the keeper vote | §9.1 §9.3 | Chess After Close is resting; its members see why, and the vote. |
| Money | nothing at the connection layer | §1.3 | Hosts chip in by choice, which buys no placement. Thanks, if any, come after. |
No Pools of its own
Our well-known file lists nothing
A host publishes /.well-known/kindling-pool so crawlers and registries can find its Pools §8.3 §10.2. Ours says who we are and how to reach us, and lists no Pools, because we keep none. If you want the Tuesday walk, it is on the Board’s file, not ours.
{
"schema_version": "0.1",
"pools": [],
"operator": {
"name": "Familiar Faces, a friendship app that reads the groups you already belong to",
"contact": "hello@familiarfaces.example",
"url": "https://familiarfaces.example"
}
}
§3.5 coupling
How Theo’s groups were found
A profile may appear in many Pools, and Pools and profiles are loosely coupled by URL §3.5. Theo gave us one address, theo-lindqvist.carrd.example. It appears as an entry in these ten manifests, two of them through a page he keeps under that address, each with its own consent proof §3.4:
- Chess After Close · entry added 8 January 2026 · consent
email-link· hs-board-chess-after-close-theo - Ada Quillon’s Listeners · entry added 20 June 2026 · consent
email-link· hs-ada-quillon-ada-listeners-theo - New in Town · entry added 20 August 2026 · consent
email-link· hs-board-new-in-town-theo - Start a Band: Port Ellery · entry added 25 August 2026 · consent
email-link· hs-ferry-room-start-a-band-theo - Friday Subs · entry added 2 September 2026 · consent
email-link· hs-ferry-room-friday-subs-theo - Rain Check: Everyone · entry added 3 September 2026 · consent
email-link· hs-rain-check-rain-check-everyone-theo - Port Ellery Thursdays · entry added 3 September 2026 · consent
email-link· hs-rain-check-rain-check-port-ellery-theo - Rides to Appointments · entry added 5 September 2026 · consent
curator-vouching· hs-foul-weather-friends-rides-to-appointments-theo · through theo-lindqvist.carrd.example/rides - Meals When It’s Hard · entry added 6 September 2026 · consent
email-link· hs-foul-weather-friends-meals-when-its-hard-theo · through theo-lindqvist.carrd.example/meals - Release Night: Kitchen Light at the Ferry Room, Friday 16 October · entry added 21 September 2026 · consent
email-link· hs-ada-quillon-release-night-port-ellery-theo
Everyone else on Theo’s map was found the same way, from the same files. We never follow a person into Pools Theo isn’t in. The app shows all ten.
The Pools it reads
Every Pool in Port Ellery’s world, and what we do with it
The library’s board, a musicians’ list, a letter co-op, the friendship side of a non-monogamy community, a supper club, and more. Each row is one manifest, linked to its host’s own copy. The app’s compatibility table says which of these it reads, and why.
| Pool | Host | Visibility | Intent tags | How we find it | In Theo’s friends view |
|---|---|---|---|---|---|
| Kindling | public | curating, founding-cohort | Its host’s well-known file | Readable: public | |
| Kindling | public | building, open-source | Its host’s well-known file | Readable: public | |
| Kindling | public | spec-review, indieweb | Its host’s well-known file | Readable: public | |
| Kindling | public | governance | Its host’s well-known file | Readable: public | |
| Kindling | public | research, writing, journalism | Its host’s well-known file | Readable: public | |
| The Board | public | walking, friendship | Its host’s well-known file | Readable: public | |
| The Board | public | gardening, friendship | Its host’s well-known file | Readable: public | |
| The Board | public | conversation, language-exchange, friendship | Its host’s well-known file | Readable: public | |
| The Board | public | carpool | Its host’s well-known file | Readable: public | |
| The Board | public | chess, friendship | Its host’s well-known file | Shown: Theo is in it | |
| The Board | public | new-in-town, friendship | Its host’s well-known file | Shown: Theo is in it | |
| The Board | public | repair, volunteering | Its host’s well-known file | Readable: public | |
| Ferry Room Players | public | sub, drums, bass, keys, guitar, music | Its host’s well-known file | Shown: Theo is in it | |
| Ferry Room Players | public | band, music, friendship | Its host’s well-known file | Shown: Theo is in it | |
| Ferry Room Players | public | horns, strings, session, music | Its host’s well-known file | Readable: public | |
| Ferry Room Players | public | songwriting, demos, music | Its host’s well-known file | Readable: public | |
| Ferry Room Players | public | crew, sound, volunteering, music | Its host’s well-known file | Readable: public | |
| The Circular | public | writing, editing, volunteering | Its host’s well-known file | Readable: public | |
| Scattered Light | public | peer-support, stewarding | Its host’s well-known file | Readable: public | |
| Scattered Light | invite-only | peer-support | Listed nowhere. Only if a member gives us the address. | Never shown: invite-only | |
| Correo Lento | public | language-exchange, spanish, english, letters | Its host’s well-known file | Readable: public | |
| Correo Lento | public | language-exchange, portuguese, english, letters | Its host’s well-known file | Readable: public | |
| Correo Lento | public | language-exchange, french, english, letters | Its host’s well-known file | Readable: public | |
| Correo Lento | public | language-exchange, tagalog, english, letters | Its host’s well-known file | Readable: public | |
| Late Supper | public | matchmaking, dating | Its host’s well-known file | Kept out: tagged dating | |
| Late Supper | unlisted | dating | Listed nowhere. Only if a member gives us the address. | Never shown: unlisted, and tagged dating | |
| Late Supper | unlisted | dating, second-chapters | Listed nowhere. Only if a member gives us the address. | Never shown: unlisted, and tagged dating | |
| Many Moons | public | non-monogamy, community, friendship, dating | Its host’s well-known file | Kept out: tagged dating | |
| Many Moons | public | non-monogamy, solo-poly, friendship | Its host’s well-known file | Readable: public | |
| Many Moons | unlisted | household, non-monogamy | Listed nowhere. Only if a member gives us the address. | Never shown: unlisted | |
| Hearthhold | public | platonic-partnership, chosen-family | Its host’s well-known file | Readable: public | |
| Hearthhold | unlisted | co-parenting, chosen-family | Listed nowhere. Only if a member gives us the address. | Never shown: unlisted | |
| Hearthhold | public | housemates, later-life, friendship | Its host’s well-known file | Readable: public | |
| Wren’s List | public | dating, date-me-doc | Its host’s well-known file | Kept out: tagged dating | |
| Second Tide Books | public | dating, books | Its host’s well-known file | Kept out: tagged dating | |
| Queer Harbor | unlisted | dating, queer | Listed nowhere. Only if a member gives us the address. | Never shown: unlisted, and tagged dating | |
| Face Up | public | dating | Its host’s well-known file | Kept out: tagged dating | |
| Heartwood | public | dating | Its host’s well-known file | Kept out: tagged dating | |
| Heartwood | public | friendship | Its host’s well-known file | Readable: public | |
| Sundial | public | dating | Its host’s well-known file | Kept out: tagged dating | |
| Card Catalog | public | dating | Its host’s well-known file | Kept out: tagged dating | |
| Drip Line | public | climbing, belay, partners | Its host’s well-known file | Readable: public | |
| Drip Line | public | bouldering, climbing, friendship, regulars | Its host’s well-known file | Readable: public | |
| Drip Line | public | running, friendship, regulars | Its host’s well-known file | Readable: public | |
| Drip Line | public | climbing, new-to-climbing, friendship | Its host’s well-known file | Readable: public | |
| Drip Line | unlisted | climbing, bouldering, women-and-nonbinary, friendship | Listed nowhere. Only if a member gives us the address. | Never shown: unlisted | |
| Foul Weather Friends | public | mutual-aid, lending, tools | Its host’s well-known file | Readable: public | |
| Foul Weather Friends | public | mutual-aid, rides, carpool | Its host’s well-known file | Shown: Theo is in it | |
| Foul Weather Friends | unlisted | mutual-aid, check-ins, neighbors | Listed nowhere. Only if a member gives us the address. | Never shown: unlisted | |
| Foul Weather Friends | public | mutual-aid, meals, cooking | Its host’s well-known file | Shown: Theo is in it | |
| Ada Quillon | public | music, listening, friendship, songwriting | Its host’s well-known file | Shown: Theo is in it | |
Release Night: Kitchen Light at the Ferry Room, Friday 16 October | Ada Quillon | public | music, show, kitchen-light | Its host’s well-known file | Shown: Theo is in it |
| Ada Quillon | public | music, show, house-show, kitchen-light | Its host’s well-known file | Readable: public | |
| Ada Quillon | public | music, show, kitchen-light | Its host’s well-known file | Readable: public | |
| Cape Tarrow Alumni | public | mentorship, first-generation, alumni, careers | Its host’s well-known file | Readable: public | |
| Midspan | public | mentorship, first-generation | Its host’s well-known file | Readable: public | |
| Midspan | invite-only | mentorship, first-generation, students | Listed nowhere. Only if a member gives us the address. | Never shown: invite-only | |
| Rain Check | public | board-games, game-night, tabletop, rain-check, friendship | Its host’s well-known file | Shown: Theo is in it | |
| Rain Check | public | board-games, game-night, rain-check, port-ellery | Its host’s well-known file | Shown: Theo is in it | |
| Rain Check | public | board-games, game-night, rain-check, olympia | Its host’s well-known file | Readable: public | |
| Rain Check | public | board-games, game-night, rain-check, tacoma | Its host’s well-known file | Readable: public | |
| Rain Check | public | board-games, game-night, rain-check, portland, role-playing | Its host’s well-known file | Readable: public | |
| Rain Check | public | board-games, game-day, rain-check, rides, lending | Its host’s well-known file | Readable: public | |
| Seen Work | unlisted | trades, referrals, work | Listed nowhere. Only if a member gives us the address. | Never shown: unlisted | |
| Seen Work | public | trades, referrals, curating | Its host’s well-known file | Readable: public | |
| Slack Water | public | festival, slack-water, folk, maritime-music, friendship | Its host’s well-known file | Readable: public | |
| Slack Water | public | festival, slack-water, folk, maritime-music, friendship | Its host’s well-known file | Readable: public | |
| Slack Water | public | session, folk, fiddle, shanties, music | Its host’s well-known file | Readable: public | |
| Slack Water | public | volunteering, crew, sound, festival-crew | Its host’s well-known file | Readable: public | |
| Slack Water | public | carpool, rides | Its host’s well-known file | Readable: public |
Visibility rules
What Theo can see, and what he never will
- Pools Theo is in.
Shown in full, with everyone who said yes to them.
- Public Pools.
Readable. Shown when they are next door to his, or when he looks one up. Never pushed at him.
- Unlisted and invite-only Pools he isn’t in.
Never shown, and never looked for §3.2.
- Anyone’s dating Pools.
Never in a friends view, public or not, and nothing hints they exist.
Plainly, with names
Mae Castellano is in Friday Subs and Start a Band with Theo, so she is on his map. She is also on Queer Harbor’s dating list, which is unlisted, and in Many Moons: Harbor Counties, which is public but tagged dating. Neither appears.
Ada Quillon has a shelf-talker on Second Tide Books’ Singles Shelf. It is public and it is for dating, so it doesn’t appear either.
If Theo joins the Tuesday walk, Carl Jansen appears as a walker. His place in Late Supper’s Second Chapters, unlisted and for dating, never does.
Client conformance
A compliant Pool UI, point by point
§11.2 asks four things of a UI; §11.4 asks three of a messaging client. Here is how Familiar Faces does each.
- Renders verification levels beside every profile (§4.5).
Every person on every page carries
KindlingDemo.levelBadge: the level in words, with an icon. Unverified is gray and dashed. - Honors the spam-filtering layers (§7).
A hello is checked with
canMessageagainst the sender’s level, the Pool’s own minimum, the person’saccept_fromandno_cold_messages, and two block lists, before anything is sent. - Supports withdrawal (§5.3).
Every group on the map has one “Leave” button, and every digest has one link per group. Each sends a
withdrawalmessage to the keeper. - Never performs silent inclusion (§5.1).
Familiar Faces can’t add anyone to any Pool. Requests come from keepers, and are answered with the host’s own accept and decline links.
- As a messaging client (§11.4).
Every message we write validates against
kindling_message.schema.json, shows the sender’s level, and passes the identity gate first (§7.1).
Block lists
The two lists we check every hello against
Messages from anything on these lists are refused before they reach anyone §7.3.
Kindling public block list
Copy: blocklist.json · published at https://protocol.kindling.foundation/blocklist.json · version 3, 20 September 2026
The block list the Kindling project will publish under SPEC.md §7.3, for identities and implementations with confirmed abuse. The entries here are illustrative until the registry opens. No personal details are ever published.
| Type | Target | Reason | Added |
|---|---|---|---|
implementation | scrapekit/0.3 | scraping | 2 July 2026 |
identity | promo-blast@mail.example | spam | 14 August 2026 |
The Circular consortium block list
Copy: circular/blocklist.json · published at https://thecircular.example/blocklist.json · version 8, 27 September 2026
Shared by every member of the Circular consortium. Each member subscribes; any member may propose an entry, and two others must second it.
| Type | Target | Reason | Added |
|---|---|---|---|
curator_identity | listed-them-anyway@mail.example | consent_violation | 27 September 2026 |
pool_url | https://free-friends-now.example/pools/everyone.json | consent_violation | 26 September 2026 |
identity | bulk-intros@relay.example | spam | 3 September 2026 |
implementation | scrapekit/0.3 | scraping | 3 July 2026 |
The files
Every document we publish, validated
Each validates against the repository’s JSON Schemas. There is no pools/ folder, because there are no Pools.
- .well-known/kindling-pool
Our discovery file: an operator, a contact, and no Pools - handshake/demo-request.json
Maggie’s request to Theo (handshake request, hosted by the Board) - messages/hello-theo-to-ada.json
Theo’s hello to Ada (intro) - messages/reply-ada-to-theo.json
Ada’s reply (reply) - messages/withdrawal-theo-new-in-town.json
Leaving New in Town (withdrawal) - messages/digest-theo-2026-09-28.json
The Monday email (system)
Honest limits
What the v0.1 schema can’t say yet
Where the specification text and a schema disagree, our JSON follows the schema. These are the gaps that touch a client like Familiar Faces.
- A client has no place in the protocol.
v0.1 defines Pool hosts, UIs, parsers and messaging clients §11, but nothing for an app that only reads other hosts’ Pools. We publish a well-known file with an empty
poolslist so crawlers find an operator and a contact, and nothing else. A Pool can’t tell which clients read it. - Nothing says “this Pool is for dating”.
Intent tags are free text §3.2. We keep out any Pool tagged
dating, which works for every Pool in this world. A Pool that wroteromanceinstead would slip through, and a Pool like Many Moons: Harbor Counties, tagged bothfriendshipanddating, is kept out entirely because we can’t tell who meant which. - Unlisted is not private.
The protocol has no access control on a manifest §3.1. Anyone holding the address of an unlisted Pool can read who is in it, and a public Pool lists all its members to anyone. Keeping Mae’s other Pools out of Theo’s view is our choice, not something the protocol enforces.
- There is no way to ask to join.
The handshake starts with a curator §5.2. “Ask to join” is an ordinary email to the Pool’s
curator_contact, asking them to send a request. - A digest has no message type, and no single Pool.
§6.3 lists four types and the schema six. Neither has a digest, so we send a
systemmessage. It spans several Pools, andvia_poolholds one, so the digest has none. - Nothing links one person’s pages.
Theo keeps a page for Meals When It’s Hard under his own address. v0.1 has nothing that says two pages belong to one person §3.5, so we count a page under your address as yours, and say so. A page on another host would not be found.
- Owning a page, for a client.
§4.2 defines email verification when a Profile first enters a Pool. Nothing says how a reading client confirms that you own a page. We email a link to the Kindling identity already in your entries’
contact_methods. - Verification is per entry.
A vouch is local to one Pool §4.4. Yusra is curator-vouched in New in Town; in another Pool she could be email verified. We show the level from the Pool someone appears through, so one person can show two levels on one screen.
- Level names differ between the text and the schema.
§4.5 names
email-verified,oauth-verified,curator-vouchedandunverified. The schemas sayemail,oauth,curator-vouched,unverifiedandcryptographic. Our JSON follows the schemas; our pages use the words. - A Pool’s sender floor can’t name vouching.
Friday Subs asks senders to be at least
oauth. §7.1 says a vouched sender passes inside the Pool that vouched for them, butminimum_sender_verificationallows onlyunverified,emailoroauth. Theo, email verified, can’t write through Friday Subs; he can write to the same people through Start a Band, which sets no floor. - Mutual interest has no field.
no_cold_messagesneeds “confirmed mutual interest” §7.2, and nothing records it. Carl Jansen has it on, so Theo can’t write first, and no message type lets the two of them say they’d like to hear from each other. - Dormant is not archived.
§9.4 says archived Pools process no messages. It says nothing about dormant ones. We let hellos through Chess After Close while it rests, and say that it is resting.
- The window is configurable in text, not in the manifest.
§5.2 says the 14-day window is “configurable per Pool”. There is no field for it. Friday Subs carries its 48 hours in each request’s
expires_atand says so ingovernance_rules; we read the date, not a setting. - No provenance on parsed profiles.
§2.3 names
extraction_source, but the parsed-profile schema has no such field and forbids extra ones. We can’t show which lines of Ada’s page were marked up and which were inferred. - Thanks have no place in v0.1.
A chargeable surface at the connection layer is a non-goal §1.3. Thanks after an introduction worked is in the v0.2 draft, which says it can never become a paywall. We follow it already, off the protocol.