People, not votes

Most feedback tools make the feature the unit of record and count votes against it. Convo makes the person the unit of record, because the question that actually moves a product is rarely "how many" — it is "who, and what else have they told me".

A person record is entirely derived. There are no fields to fill in, nothing to maintain, and therefore nothing that can go stale.

The People view

Each product's sidebar has a People entry listing everyone who has said something about that product, most prolific first. A row shows:

  • their generated or Google avatar,
  • their name — a Google name, a name they chose, or "Anonymous" in muted type,
  • their tier — Google, Email, or Anonymous,
  • how much they have said across the workspace,
  • how many of their items are still open — anything not shipped or declined,
  • how many products they have posted to, when it is more than one,
  • a reply owed badge when you are the one who has gone quiet: they spoke last on an open thread and are still waiting.

Search filters the list by name or tier. Selecting anyone opens their record.

The person record

Press P on a feed row, on an item's page, or click a name anywhere, and a panel slides in with everything that person has said — across every product in the workspace, not just the one you were looking at. Someone who filed a bug on your app and an idea on your API is one record, not two.

It holds:

  • Said, Open, and Products counts.
  • Waiting on you, when there is anything — the open threads where this person had the last word, newest first, each a link straight to that conversation. It is derived from the threads themselves, so replying makes it disappear; it is the same rule the who_needs_followup tool reports as replies owed.
  • Last contact — when you last heard from them.
  • Email, when there is one, marked with a lock and labelled as yours to see only.
  • Everything they've said — each item with its key, its current status, an excerpt, and when it arrived, newest first.

That is the whole record. There is no notes field, no score, no segment to assign. It is an index over conversations, rebuilt from those conversations every time you open it, which is why it can never drift out of date.

The three tiers

Identity on a public page is offered, never demanded, and it comes by degrees. Each rung makes the record richer, and nobody is ever blocked from speaking.

Anonymous is the floor and the default. Behind it is an invisible sign-in whose id is the person's identifier, so their posts cohere: three notes from the same browser are one person with a thread and a history, even though you have no idea who they are. There is no contact, so you cannot write back — but you can still read them as a person rather than as three orphan rows.

Email is the fallback rung: an address, verified by a magic link, with no password anywhere on the public side. This is what someone leaves when they want to hear back, and it is what makes the close-the-loop notification possible.

Google is the preferred rung and the richest: one tap yields a name and an avatar, so their posts carry a face on the public board.

Climbing preserves everything. The rungs are built on one session, so signing in with Google or completing a magic link keeps the same identifier — the notes someone left anonymously last month are re-attributed to their now-named self, with no claim step to perform. A verified credential also resolves to the same person across devices, because Google and a verified email each map to one account. Purely anonymous posts cannot follow someone to a new browser; there is no shared key to follow them with.

What stays private

Email is maker-visible only. It appears on the person record, to you and your workspace members, and to that person on their own record. It is never on the public page, never shown to other end users, and never included in the public read path — a public page resolves authorship from a separate profile record that carries only a name and an avatar, so the document holding the email is not even read.

Public authorship is one of three things: a Google name and avatar, a name the person chose for themselves, or "Anonymous". Nothing else.

Anonymous means anonymous. The coherence you get is coherence within one browser, not an identity you can resolve. There is no cross-site tracking, no fingerprinting beyond that session, and no way to turn an anonymous person into a named one from your side.

Unsubscribing is honoured. A close-the-loop message carries a one-click unsubscribe link, and following it sets a flag on the person's record. The notify service skips anyone carrying that flag, every time, with nothing for you to remember or override. It also skips anyone without a verified address, so an unconfirmed email is never written to. The person stays in your People list and can keep leaving feedback — opting out of mail is not opting out of the conversation.

Merging keeps people

Merging two items never costs you a person. Every person attached to either item moves onto the survivor, keeping the stronger of their two roles, and their endorsements come with them. So folding four ways of asking for the same thing into one conversation leaves you with one item and all four people still attached — which is exactly who to tell when it ships.

Asking questions of the record

The People view answers "who is talking to me about this product". The harder questions — who asked for this, who has gone quiet, who should I talk to before I redesign this — are what the API and MCP surface are for: an assistant connected to your workspace can list people, search them, and read one person's full record. Searching people matches on name and email, and also on what they raised, so asking who wanted dark mode resolves through the feedback itself rather than through anybody's name.

Where to go next

Triage the feed is where you meet these people in the first place, and Keyboard shortcuts has the keys. If you have not created a product yet, start with Getting started. Closing the loop, connecting an AI assistant, and the REST API each have their own page.