Without having checked it out properly outside of the landing page, here's a brain-dump of things that competitors get wrong and you can improve by a lot: 1. Support self-custodied 2FA: TOTP/U2F. Do not require phone-number/SMS "for your own protection". 2. Be honest with your customers and users. Don't succumb to dark UX for the sake of control, engagement and growth. Allow setting separate notification settings for…
1. We follow a "trusted devices" model, where you 2FA using your phone number for the first login on a device. Future logins on that device aren't 2FA'd. I agree that using a code gen is a good improvement we can make over time. 2. Marketing opt-out is prominent in account settings. Any email that is very strictly not transactional is considered marketing by our team, and can be opted out of. Developing simple, focus…
> We follow a "trusted devices" model, where you 2FA using your phone number for the first login on a device
It sounds like associating and verifying a phone number is required to sign up and use the service - is this something you're open to changing?
> I assure you there won't be a "refer your friends" badge blinking on the home page of the app
That's great! And TBH I wouldn't mind terribly as long as it can be permanently disabled after a first view.
> We hear from most people that iOS or Android are their preferred platforms, so we have to start there
Understandable. At the very least it would be a huge boon if we can expect to run the Android app without hickups on a fully degoogled Android device (e.g. GrapheneOS).
Will keep an eye on how things develop :)