The public page
Every product you create in Convo has one public page. It is where your users say what they think, watch what you decide, and read what you shipped — without an account, a category picker, or a vote to spend.
This page describes what a visitor sees, in the order they meet it.
One address, three views
A product's public page lives at /{workspace}/{KEY} — for a workspace acme and a product key WEB, that is convo.randomfact.com/acme/WEB. There is no second public URL and no per-product slug to claim.
Three views hang off that one address:
| View | URL | What it is |
|---|---|---|
| Board | /acme/WEB |
The capture box and everything people have said |
| Roadmap | /acme/WEB?tab=roadmap |
Planned, in progress, shipped |
| Changelog | /acme/WEB?tab=changelog |
A dated ledger of what went out |
The board is the bare URL, so the address you print on a help page is the address people land on. The other two are search parameters on that same page, which means each view is linkable, shareable, and survives a reload.
Every piece of feedback also has its own page at /{workspace}/{KEY}/{KEY-n} — convo.randomfact.com/acme/WEB/WEB-42. An item is a conversation, so it gets a URL rather than an accordion, and that URL is what a changelog line, an issue in your own tracker, or a shared link points at. The same three tabs sit in the header there, so a reader who arrives on one piece of feedback can reach the roadmap without going back to the board first.
The same URL shows you something different
/{workspace}/{KEY} is role-determined. A member of the workspace that owns the product gets the maker triage view. Everyone else gets the public page described here. Send a customer the URL you have open yourself, and each of you sees the right thing.
If the product is private, a non-member gets "not found" rather than a locked door — a private product never reveals that it exists.
Seeing it as your users see it
From your product's header, or from the product list on your workspace home, use Public view. It opens the public render in a new tab, with ?view=public on the URL, and the preview follows you across the three tabs and into any item page. Signing out, or opening the URL in a private window, gets you the same thing from the other direction.
The capture box
The capture box is the hero of the board — one field, above the fold, before anything else.
- No account. Nobody signs in to post. Identity is offered afterwards, never demanded.
- No type picker. Ideas, bugs, confusion and praise land in the same box. You sort them out in triage; a stranger should not have to guess your taxonomy.
- No required fields but the note itself. A title input appears once someone starts typing and is entirely optional.
The box is a Markdown composer. Select text to format it, and post with Cmd+Enter or Ctrl+Enter — a bare Enter is a new line. Image uploads are off on every Convo composer.
Titles write themselves
Leave the title blank — most people do — and Convo derives a headline from the note: the text up to the first line break, capped at 100 characters, backing off to the last whole word and ending in an ellipsis when it has to cut. People front-load the point and elaborate below, so the first line is usually the right headline.
A derived title is a real field once written. You can rewrite it in triage, and the derivation never runs again.
Similar feedback, while someone types
After a couple of characters, Convo looks for feedback that already says the same thing and shows it under the box. The status line reads looking…, then either N similar found or looks new.
Matching is semantic, not keyword: the ranking runs on embeddings, so "too bright at night" finds "dark mode" even though they share no words. Every match carries its status, how many people have asked, and a bar showing how close the closest one is.
From a match, one tap adds a +1 — the count moves immediately — and only then does Convo ask the optional follow-up, "What would this help you do?", with a few one-tap phrases to start from. The vote is never held hostage to the sentence.
A post as new button sits below the matches at all times. Convo surfaces candidates and never merges anything on its own: merging two pieces of feedback is a maker's decision, taken in triage or through the API.
Spam defences your users never see
There is no captcha and no sign-in wall. Two quiet defences run instead:
- A honeypot field, invisible to a person, that only an automated form filler will complete. A post that fills it is rejected.
- Rate limits on how much one browser session, and one network address, can write in an hour. Posting, +1-ing and replying all spend from the same budget, so alternating between them does not dodge it. A normal person will never reach either limit.
Choosing how you are known
Convo offers identity after the first post, so it can never gate capture. What the visitor sees is a small dialog with three rungs.
- Continue with Google — the gently preferred rung, and one tap. It leads to a name step: keep the default name, shuffle a generated handle like
curious-comet-94, or type your own. When Google supplied a real name, a chip offers to use it. - Just leave an email — verified by a magic link sent to the address, which returns to the same page and upgrades the session in place. Coming back through the link opens the same name step, on a generated handle: nothing derived from the address is ever offered, let alone published. There is never a password on the public side.
- Stay anonymous — closing the dialog, or pressing Esc, is a complete answer. The post is already saved.
Convo asks once per product per browser session. Decline, and later posts confirm silently instead of re-prompting. Anyone who wants to climb later can use Sign in in the page header; anyone already signed in can click their own name there to change it or sign out.
Every rung is the same session
Underneath all three rungs is a single invisible anonymous session, and climbing links a credential to it rather than creating a second account. Two consequences matter:
- Earlier posts re-attribute. Post twice anonymously, then sign in with Google, and both of those posts now carry your name — there is no claim step.
- A verified identity follows you. The same Google account or the same magic-link address resolves to one person on a second device. Purely anonymous posts cannot cross devices; there is no shared key to find them by.
What is public, and what is not
An email address is maker-visible only. It never appears on the public page, is never shown to another user, and the public read path never touches the person record that holds it. Nothing is derived from it either: the part before the @ is frequently someone's real name, so it is never used as a public name.
What does show is a display name, at the tier the person opted into:
| Rung | Public name | Avatar |
|---|---|---|
| Anonymous | Anonymous | none |
a generated handle like curious-comet-94, until changed |
a generated bubble | |
| the Google given name, until changed | a generated bubble |
The name is optional and editable at any time from the page header, and a name someone chose is never reset by a later post or a later climb.
The board
Under the capture box is everything people have said — one row each, and nothing more than:
- the title, and its status;
- the item key, who said it, when, and how many replies it has;
- a +1 button, on the row, so agreeing never requires opening anything. Your own feedback shows no +1 button.
The row deliberately does not carry the body of the note. A visitor arrives asking "has someone already said my thing?", and a wall of full notes is the worst possible shape for answering that.
Ordering is recency and status, never vote count. Open feedback — new, planned, in progress — comes first, newest at the top; shipped sits below it; declined sinks to the bottom. The +1 count is shown and never sorts. The page is a conversation, not a leaderboard.
There is no separate search field, because the capture box is the search: type what you were about to post and the matching notes surface.
Everything is live. A status change, a new reply or a fresh post lands on every open tab without a refresh.
An item's page
Clicking a row opens that piece of feedback on its own page: the title and status, the item key, who wrote it, when, the +1, the full note, and the thread.
Anyone can reply, at whatever identity tier they have opted into. Replies from your side of the table are marked Maker so the page reads as a dialogue rather than a suggestion box. A reply filed through the API or an AI assistant is named after the client that sent it and carries its own badge, Maker · via agent — still your side of the table, and visibly not one of your team typing. The same two badges appear in your own feed, so a reply you are reading back is never mistaken for one a colleague wrote.
The roadmap
The roadmap is three stages — Planned, In progress, Shipped — and it is derived entirely from item status. There is no second object to curate and nothing to drag: change an item's status in triage and it moves stages on every open tab.
New and declined feedback never appears here. The roadmap is what is committed and what is done, not the inbox. Within a stage, the most recently moved is first, and a sticky bar at the top carries live counts you can jump by.
The changelog
The changelog is a ledger, not a blog: date, item key, what shipped. An entry is written the moment you mark an item shipped, and the item key on each line links back to the feedback it closes — that page is where the context lives, so the ledger never restates it and never puts words in your mouth.
When an entry is written, Convo also records who asked for the thing: the public names of requesters who chose one, capped, plus a total that includes everyone else. Names appear only with that consent; someone who stayed anonymous is part of the count and nothing more. That acknowledgment is stored on the entry and readable over the API today, while the changelog line itself stays a bare ledger line.
Automatic notification of the people who asked — the email that tells a requester their thing shipped — is still being finished.
Your brand, not ours
The public page wears your product's brand and is deliberately quieter than the maker app: closer to good documentation than to a dashboard.
- Your logo replaces the product name in the header.
- Your accent color drives the page's highlights.
- There is no watermark over the page and no paid tier to remove one. The only Convo mark is a single line in the footer, alongside a privacy link.
- The visitor gets a light and dark toggle, cycling light, dark and system, and their choice sticks.
Custom domains are planned and not built. Every product's page lives at convo.randomfact.com/{workspace}/{KEY} today.
What the page deliberately does not do
Some absences are decisions, not gaps:
- No vote-ranked list. +1s are counted and displayed; they never reorder the board.
- No categories, tags or type pickers on the way in. Everything lands in one box, and triage is where structure gets added.
- No login wall. Reading and posting never require an account, on any surface.
- No analytics dashboards, prioritization matrices, NPS surveys or sentiment scores. If a number is not derivable from the feed, it does not exist.
Where to go next
Post something on your own board and follow it through — the capture box, the identity prompt, the row, the item page. It takes two minutes and it is the fastest way to see what your users see. If you have not created a product yet, start with Getting started.
Then set up the page itself: naming, roles, visibility, branding and the settings pages are covered in Workspaces, members and settings. The same capture box can sit inside your own app — that is Embed the capture box — and your users' own assistants can file feedback without opening the page at all, which is Your users' AI assistants.