Product brief
Vision, audience, offer, tone, pricing, scope, controlled participation, and non-goals.
This documentation package refines the original blueprint into operating documents for a single-creator, AI-generated adult membership platform. The project codename is Nocturne; the public brand name remains undecided.
| Area | Decision | Reason |
|---|---|---|
| Creator model | Single creator/operator only. | No marketplace, no creator onboarding, no creator payouts, and no user-uploaded adult media in MVP. |
| Content model | AI-generated adult images and videos, with a transgender/futanari niche focus. | Specific differentiated demand lane; all content remains synthetic and non-referential. |
| Account model | Pseudonymous accounts with self-custody recovery. | Avoids default email identity while making the recovery tradeoff explicit. |
| Private testing gate | Browser membership creation is owner-invite-only. | One-time invite codes are shown once, stored only as SHA-256 digests, and redeem without email, IP, user-agent, or identity binding. |
| Pricing | Simple $20/month tier; processor-neutral 30-day pass, local checkout sessions with non-authoritative success/cancel returns, stale-session expiry cleanup, local payment proof, webhook replay support, and a source-backed payment-provider decision matrix in foundation. | Keeps the purchase model clear and avoids IP-based regional pricing while leaving final processor/tax packaging open until adult-compatible provider approval is captured. |
| Community | Controlled participation first; local Signals, polls, requests, reactions, and aggregate unlock goals before chat. | Creates retention and agency without opening a high-risk moderation firehose or public activity graph before the core product proves itself. |
| Frontend | Server-rendered HTML/CSS with selective vanilla JavaScript; no NPM dependency chain by default. | Supports premium UI while reducing supply-chain and privacy risk. |
| Media control | No DRM; private media storage and authenticated/signed access. | Protects access without pretending piracy can be solved or weakening the privacy promise. |
| Operational recovery | Backup/restore starts as local doctor visibility plus a non-destructive owner runbook, secret-free artifact manifest, and restore-drill checklist scaffold. | Recovery matters before external testing, but restore execution must stay manual and isolated until it can be made safely operator-confirmed. |
Vision, audience, offer, tone, pricing, scope, controlled participation, and non-goals.
Account recovery, age-gate abstraction, sessions, logs, media access, payments, frontend stack, and VPS/Docker posture.
Production-edge environment, HTTPS reverse-proxy assumptions, HSTS, body limits, owner gate, and privacy-preserving log posture.
Production env template, non-destructive bootstrap bundle, test-VPS compose skeleton with persistent backup/manifest/custody volumes, healthcheck posture, and blocking preflight before public proxy exposure.
Secret-free private test-VPS operator sequence tying bootstrap, smokes, evidence records, backup metadata, restore-drill planning, and readiness into one checklist before official VPS transplant.
Caddy/nginx edge templates, proxy body limits, forwarded-header stance, access-log minimization, and external smoke checks.
Operator-run final-origin checks for health, headers, body caps, public diagnostics, and private media gates after proxy attachment.
Disposable member provisioning plus authenticated checks for login, account, library, media ranges, downloads, checkout returns, owner gate posture, cleanup, and logout through the public edge.
Local operator evidence ledger for preflight, edge smoke, member smoke, cleanup, restore drills, and provider-review artifacts without storing raw logs or secrets.
One operator gate that combines production preflight, selected-origin evidence, backup posture, sealed backup manifests, custody retention, and restore-drill advisory status before widening private testing.
Operational recovery posture, backup target diagnostics, PostgreSQL/media backup guidance, artifact hash manifests, restore-drill plan scaffolding, and retention caveats.
Local store smoke, HTTP smoke, seed, reset-seed, and browser validation runbook for disposable MVP testing before VPS deployment.
Secret-free manual browser checklist for the gated owner dashboard after local-owner-smoke passes.
Synthetic-only policy, Hermes, moderation states, request/poll controls, public intake guardrails, takedown handling, and chat deferral criteria.
Private-VPS operator runbook for report priorities, SLA targets, quarantine-first triage, external escalation triggers, and evidence minimization.
Generation rules, consent layers, trans/futanari tone boundary, anti-predatory retention, and takedown posture.
Known legal, payment, tax, privacy, AI labeling, age assurance, and abuse-response risks to validate before public launch.
Official-source payment processor evidence, avoid/shortlist decisions, vendor questionnaire, and provider-neutral integration guardrails.
Risk-burn-down delivery sequence from planning through private test, paid MVP, controlled participation, and later lounge exploration.
Epics, status legend, acceptance criteria, build package boundaries, and current foundation slice status.
The platform can enforce rules, revoke access, process payments, and respond to abuse without building identity dossiers on lawful users.
This sentence is the privacy architecture guardrail. Future features should be rejected or redesigned when they require unnecessary identity linkage, behavioral profiling, or permanent raw access logs.