Pay Phone · Logic — Issues & Rulings · 07/17/2026 · one page, problem + call together

Every issue and its ruling, side by side.

The logic report and its resolutions, merged so you never have to cross-reference. Each item shows the problem (from the audit) and directly beneath it the ruling (my recommended call). The 10 gating decisions come first — they cascade and resolve most of the numbered findings, whose #-references are clickable. Tags: CONFLICT/GAP/HANDLED = what the audit found · RULING/FIX/DEFER = what I'm proposing. Amend anything by its number; silence = adopted, and I lock it as canonical spec.

The 10 gating decisions

Each shows the problem, then the ruling. These cascade — approving them resolves most of the numbered findings below. Amend any by its D-number; silence = adopted.

D1Scheduling: time-based, not a fixed slot grid
THE PROBLEMSlot math contradicts itself across screens (12/18/24 slots the same night); a 20-min call has no defined place on a 10-min grid; 7:45 PM isn't a valid start time. #20 #21 #32 #82 #83
THE RULINGKill the fixed :00/:10/:20 grid. A session is a continuous block (Tue 7:00–9:00 PM). When a fan picks a service, the booking screen generates real start times for THAT duration from whatever contiguous time is still free, plus a 2-min reset buffer between calls. Capacity is expressed in TIME, shown to the fan as “next openings,” never as a raw slot count. A 2-hour block therefore holds ~10 ten-min calls, ~8 twenty-min, or a mix — computed, never hardcoded. This single ruling dissolves the 12/18/24-slot contradictions and the “7:45 isn’t on the grid” problem.
D2The join window + fair-timer, made symmetric and fair
THE PROBLEMThe 'join window' is referenced in the cancel policy, E4, E6 and defined NOWHERE — no minutes for either side, so no-show and late-join have no trigger. #23 #24 #25 #26
THE RULINGThe rule in one sentence: you’re protected from the OTHER party’s lateness, never rewarded for your own. Celeb joins late → timer doesn’t start until they’re in, fan gets their full paid duration, and the schedule absorbs it via the drift queue (D1 buffers + a “running ~X min behind” banner to later fans). Fan joins late → the call still ends at its scheduled end; the fan eats their own late minutes, after a 60-second grace. No-show thresholds: celeb no-show fires at 5:00 past start (fan auto-refunded); fan no-show fires at the scheduled END of their window (celeb paid in full). Print both numbers in the cancel policy.
D3Off-hours requests: authorize, don’t capture
THE PROBLEMFor a booking OUTSIDE standing hours, no artifact says whether the card is charged at request or at acceptance, or how long the fan's money is held. #2 #3 #56
THE RULINGWhen a fan requests a slot outside standing hours, Stripe AUTHORIZES the card (no charge yet) and the fan lands on a real “Pending — waiting on Dre” screen. The celeb has until 24h before the slot, or 24h from the request, whichever comes first, to accept. Accept → capture + confirm. Expire or decline → authorization released, fan notified, zero charge. This closes the “money held indefinitely” hole and gives the fan a state that currently doesn’t exist.
D4Number privacy vs. the audience list: both are true — say both
THE PROBLEMCheckout says flatly 'Dre never sees your number,' but the celeb also gets an exportable CSV of every fan's name+phone+email. Both can't be absolute. #69
THE RULINGKeep the exportable audience list (it’s the manager pitch). Fix the copy so it stops overclaiming. Canonical checkout line: “Dre never sees your number for calling — every call runs on Pay Phone. You’ll join Dre’s contact list so he can text you when new times open. Unsubscribe anytime.” Two distinct facts: never shared for DIALING (switchboard, absolute) and added to their drop list (disclosed, opt-out). The absolute-privacy line stays on the CALL surfaces; the list disclosure appears at the list-join moment (checkout).
D5Partial call / tech failure: fault-based, GMV-preserving
THE PROBLEMIf the call drops at minute 6 of 10, or the recording is lost, there is NO policy anywhere — the most common real-world dispute is a total blank. #44 #74
THE RULINGThree buckets. (a) Platform fault — server/infra drops the room: fan 100% refunded, celeb paid in full, platform eats it (detected server-side, no dispute). (b) One-party connection fault — if under 50% of paid time was delivered, fan gets a FREE REBOOK (not cash — keeps GMV and the relationship); 50%+ delivered, the call stands. (c) Call was fine but the recording was lost: call stands, fan gets an automatic make-good (a free 5-min Quick Call credit) because the recording was a promised deliverable. This is the single biggest blank in the spec today; it must exist at launch.
D6Recording retention: one clear triangle
THE PROBLEMRetention is claimed three incompatible ways: platform '90 days,' celeb archive 'forever,' fan 'download forever.' #75
THE RULINGFan’s downloaded file: theirs forever, on their device. Streaming/re-download link: 90 days. Celeb archive: persists while the account is active (cheap cold storage — a real talent perk); on account closure, 90-day export grace, then purge. Platform moderation copy: 90 days, then purged unless a Trust & Safety case is open. Write this verbatim into ToS §5 so the three “forever / 90-day / yours” claims stop contradicting each other.
D7Follow is FREE at launch; paid membership is v1.1
THE PROBLEMThe ledger says you revised follow to PAID; the journey draws free watching. The product's second revenue line contradicts itself. #93 #115
THE RULINGResolve the ledger-vs-journey conflict in favor of the journey as drawn. Free watching IS the growth engine — the drop-list is top-of-funnel and you never tax the top of the funnel at launch. Ship free watch now. The paid membership tier becomes a per-celeb opt-in dial (the OnlyFans “free page vs paid page” model already in the ledger), web-checkout, as the first fast-follow. This keeps “no interaction is free” intact — the RING is free, every CALL is still paid — and defers the monetization that would slow acquisition.
D8Extension price = per-minute rate of the booked service
THE PROBLEM'Extension at the celeb's rate' resolves to three different prices across S19/ledger/admin; and the celeb is never asked to consent to staying longer. #34 #77
THE RULINGOne formula, and it already matches the mockup: extension price = (booked service price ÷ its minutes) × extension length. Dre’s 10-min call is $100 → $10/min → +5 min = $50 (exactly what S19 shows). Sol’s $150/10-min → $75 for +5, or a +10 extension = $150 (explains the $125–$150 admin figures once the sample data is swept). Celeb consent: an Hours toggle “Allow extensions when my next opening is free,” default ON, plus an in-call decline. Extensions split 80/5/15 like everything else.
D9Instant payout stays; new payphones carry a 30-day reserve
THE PROBLEMInstant payout on completion leaves ZERO funds to cover a chargeback or a fan report without clawing money back from a celeb — which breaks the 'no clawbacks' promise. #18 #47 #78
THE RULINGKeep instant payout — it’s the supply-side magic and must not change. Protect against chargebacks/reports with a rolling reserve on NEW payphones only: hold 10% for the first 30 days (or first $2,000 earned, whichever clears first), then release and switch to full instant payout. Established celebs with clean history carry no reserve. This is standard Stripe Connect practice and it funds every fan-side remedy (D5, chargebacks, conduct refunds) WITHOUT ever clawing back a celeb. Disclosed in the talent agreement.
D10Adopt one canonical dataset, then sweep every artifact
THE PROBLEMSample data drifts across screens (a $250 payday relic, impossible admin math, one booking ID reused for opposite outcomes) — managers do the math and will catch it. #40-43 #81-88
THE RULINGLock a single consistent example night and propagate it everywhere; managers do the math and will catch any drift. Canonical: Dre Vaughn, Tuesday 7:00–9:00 PM, 10 openings, 8 booked / 2 open; at 7:41 PM, 3 calls done = $240 earned tonight (not $1,340); “Fully booked week” shown as “$2,400 in bookings · $1,920 to you” (gross vs. net, both stated); payday screen = Jordan’s real call (10-min $100 + 5-min ext $50 = $150 · your 80% = $120); admin net revenue = 15% of GMV minus Stripe fees (formula, not a magic number); one booking ID per email outcome. Emoji purge (E2 subject, admin sidebar) and the “line”→“payphone” sweep ride along.

A. Booking lifecycle

#2
DECISIONDefine the join window (#23, 24, 26): recommend — fan may join until 50% of slot elapsed (timer runs to min(full duration, slot end + buffer)); celeb no-show fires at 5:00 past start; both numbers printed in the cancel policy.
RULINGOff-hours = authorize at request, capture on accept (see D3). Never capture an unconfirmed booking.
#3
DECISIONOff-hours request money handling (#2, 3, 56): recommend — Stripe auth (not capture) at request, celeb has 24h or until T-2h (whichever first) to accept, auto-release on expiry, fan sees a pending screen.
RULINGRequest TTL = min(24h from request, 24h before slot). Auto-release the authorization on expiry; fan sees Pending state.
#8
DECISIONExtension formula + celeb consent (#34, 77): recommend — extension price = per-minute rate of the BOOKED service × 5, celeb pre-authorizes extensions via an Hours toggle (default on).
RULINGExtension card declines mid-call: the +time simply isn’t added, a quiet inline “couldn’t add time” shows, call ends on schedule. No retry loop, celeb not interrupted.
#11
GAPBOTH no-show: undefined. Fan forfeits per no-show rule AND celeb gets show-rate hit? Is celeb paid? No source covers it.
RULINGBoth no-show collapses to CELEB no-show: if the celeb isn’t there we can’t prove the fan wouldn’t have shown → fan refunded 100%, celeb not paid. Celeb absence always wins.
#14
GAPreschedule dead-end: "reschedule once to any open slot on that payphone within 30 days" — no open slots in 30 days, or payphone paused/suspended/celeb quits: does the credit convert to a refund? Undefined.
RULINGReschedule dead-end → full refund. If no open slot within 30 days, or the payphone is paused/suspended/closed, the credit auto-converts to a cash refund.
#15
GAPrescheduled-booking lifecycle: can the fan cancel the rescheduled booking ≥24h out for a refund (re-arming the full-refund rule and defeating the <24h penalty)? Can they reschedule again if the CELEB cancels the rescheduled slot? Undefined loop.
RULINGA rescheduled booking is FINAL: no cancel-for-refund, no second reschedule — UNLESS the celeb cancels it, which triggers a full refund. Kills the reschedule-gaming loop.
#18
GAPchargeback/dispute state: a fan disputing the card charge post-call appears nowhere — no state, no admin queue, no policy on whether celeb's already-instant-paid 80% is clawed back (which would break the "no clawbacks" promise, S6 caption).
RULINGChargebacks are funded by the D9 reserve; if the reserve is short, platform eats it. NEVER claw back a celeb — preserves the ‘no clawbacks’ promise. T&S reviews every dispute.
#19
GAPpayment-failed at booking (3DS decline mid-Apple-Pay) and abandoned-checkout slot state: undefined whether a slot is held during checkout at all (see D4).
RULINGSlot is soft-held for 8 min the moment checkout opens; abandoned/failed checkout releases the hold. See D-race (#55).

B. Timing edges

#20
GAPMulti-duration menu vs 10-minute slot grid: S12 grid is :00/:10/:20 spacing, but the menu sells 5/10/20-min calls. ADM shows Casey R. booking a "Tue 7:20p slot" for $180 (the 20-min service) — that call runs to 7:40 through the 7:30 grid slot. No artifact defines how a 20-min booking consumes/blocks grid slots, or whether each service gets its own grid.
RULINGResolved by D1: no grid. A 20-min booking consumes a contiguous 20-min window + buffer from the session’s free time.
#21
CONFLICTExtension source-of-time vs back-to-back grid: "+5 min if the next slot is free" (S19) — but slots are contiguous 10-min blocks, so a 5-min extension orphans half the next slot and no artifact says whether the whole slot is consumed, split, or resellable.
RULINGResolved by D1+D8: extensions draw from the next contiguous free minutes, not a ‘slot.’ If under 5 free min follow, the extension isn’t offered.
#22
GAPSold-out session = zero extensions, by definition (next slot never free). The upsell (S19, HIW FAQ) silently disappears on the best nights; "sold out" session Jul 21 shows extensions impossible yet APV2 Jul 25 session shows "2 extensions" with 21 calls in a 2-hour block — capacity math doesn't close either way.
RULINGCorrect and intended: a truly sold-out session offers no extensions. The upsell appearing only when capacity exists is honest, not a bug. Sweep the sample data so ‘sold out’ nights don’t also show extensions.
#23
GAP"Join window" is referenced everywhere (CP twice, E4, E6 "the moment his join window closed") and DEFINED NOWHERE — no number of minutes for fan or celeb anywhere in ledger, journey, policy, or admin.
RULINGJOIN WINDOW DEFINED (D2): celeb no-show at 5:00 past start; fan no-show at scheduled window end; 60-sec grace for a late fan before their clock starts burning. These three numbers go in the cancel policy.
#24
GAPLate-fan cap: fan joins 4 min late to a 5-min call — fair timer says they still get 5:00 (S23/APV2 "fan joined 22 sec late, timer held"), which pushes into the next paid slot. No rule caps a late joiner's entitlement at slot end.
RULINGA late fan is capped at their scheduled end — they never eat into the next fan’s time. The ‘timer held for her’ archive line is the 60-sec grace, not unlimited.
#25
GAPCascade/queue mechanics: celeb joins 3 min late to a sold-out night → every subsequent fixed-time booking collides (fans were told "7:20 PM ET" in E3/SMS). No drift-queue, delay-notification, or "your call is running late" surface exists anywhere; S20's "Next caller starts in 0:12" after a 15-min extended call in a 10-min slot shows the collision drawn but unexplained.
RULINGDrift queue (D1): a late start shifts later calls; each affected fan gets a ‘Dre is running ~X min behind’ push + lobby banner. Buffers absorb small drift; large drift can bump the last opening to a refund.
#26
GAPCeleb wait obligation: how long must the celeb sit in the room for a no-show fan before "complete and paid" fires? Undefined (mirrors #23).
RULINGCeleb’s wait obligation = the 5:00 no-show threshold from the fan’s side too: celeb must stay until 5:00 past start before a fan no-show pays out.
#29
GAPDST: a booking made before a DST shift for a slot after it — "Mon 7:20 PM ET" deadline and slot time can drift an hour against UTC; no artifact mentions DST handling.
RULINGStore all times UTC; display in each viewer’s local tz. A standard tz library handles DST automatically — the 24h deadline is computed on the stored instant, so it can’t drift.
#30
GAPTimezone display: fan sees own timezone at booking (S12, CP) — but nothing says what the CELEB's schedule anchors to when they travel across timezones (their standing "Tue 7–9 PM" is in whose zone?).
RULINGA celeb’s standing hours anchor to their HOME timezone set at onboarding (shown on their public page). Traveling doesn’t move their hours.
#31
GAPLobby/extension timing edge: extension sheet appears at 0:30 (S19); a tap at 0:02 with payment processing past 0:00 — call ends or bridges? Undefined.
RULINGExtension tap must complete before 0:00; a tap after time expires is rejected with ‘call ended.’ No mid-air bridging.
#32
CONFLICTS8 "Next call · in 4 minutes" = 7:45 PM, but the entire slot system is :00/:10/:20 aligned; 7:45 doesn't exist on the grid drawn in S12.
FIX‘7:45’ example is fine once D1 kills the grid — start times are real, not grid-aligned. Sweep any copy implying a fixed grid.

C. Money edges

#34
CONFLICTExtension price formula: ledger says extensions are "at the celeb's rate"; S19 charges $50 for +5 min when Dre's 5-min menu price is $60 ($50 = prorated 10-min rate). ADM shows a $125 extension for @solrivera that maps to no stated formula. Two different implicit rules, neither written down.
RULINGONE extension formula (D8): per-minute rate of the booked service × minutes. Sweep S19/ADM so every extension figure derives from it.
#35
GAPExtension split: ToS §3 "same terms" implies 80/5/15, but never explicit; ADM extension row says "on completion" — completion of the extension or of the whole call?
RULINGExtension splits 80/5/15 and settles on CALL completion (one settlement for base + extension together).
#36
GAPConduct-kill mid-extension: fan buys +5, celeb kills the call for conduct at minute 12 — is the extension ALSO forfeited-and-paid-to-celeb? CP says extensions "follow this same policy," which is ambiguous for a purchase made mid-call that never fully ran.
RULINGConduct-kill mid-extension: the fan forfeits the entire charge including the extension; celeb is paid the full base + extension. Same as any conduct kill.
#37
GAPStripe fee on refunds: ledger PM decision says "platform eats Stripe fee on refunds" but it appears in NO customer-facing or ops artifact (not CP, ToS, ADM, or E6) — an ops rule that exists only in a memo.
RULING‘Platform eats the Stripe fee on refunds’ must appear in ops docs + the talent agreement, not just the ledger. Not fan-facing (fans see a clean full refund).
#38
GAPManager rev-share on drops vs hours: 5 pts stated once (ledger); no artifact distinguishes drops, hours, extensions, or (future) memberships — presumably identical, never stated. Manager cut on conduct-forfeit payouts also undefined.
RULINGManager 5 pts applies identically to hours, drops, and extensions. On a conduct-forfeit (no celeb payout to share), the manager earns nothing — they’re paid on delivered revenue only.
#39
CONFLICT"Paid on completion" vs "on the way" phrasing: S9/APV2 show $1,340 "On the way to Chase" during an IN PROGRESS session — with instant payout ON, completed calls should read "landed"; the screen never distinguishes per-call payout from per-session payout. Needs one sentence of definition (per-call, at completion).
RULINGDefine it: instant payout is PER-CALL at completion. So the label reads ‘landed’ for finished calls and ‘tonight so far’ as a running sum — never ‘on the way’ for money already delivered.
#40
CONFLICTS20 payday screen: "15 min with Jordan M. · $250 · your 80%" → $200. Jordan's call everywhere else is $100 + $50 extension = $150 gross → $120 net (S21 receipt "$150 total"; S23 archive "+$120"). S20 is leftover $250/5-min sample pricing; its "$200" and "today so far: $1,540" (vs $1,340 in S9) both contradict the same night's data.
FIXS20 payday is a $250 relic. Correct to Jordan’s real call: 10-min $100 + 5-min ext $50 = $150 · your 80% = $120. Fix ‘today so far’ to match D10 canonical ($240 tonight, pre-this-call).
#41
CONFLICTE1 "Fully booked week — $2,400 to you" and APV2 "Fully booked week: $2,400 to you": $2,400 is GROSS (24 calls × $100); "to you" at 80% is $1,920. The earnings-estimator hook — the single most important celeb-side number — overstates by 25%. S5 hedges ("Up to $2,400/week") but sits directly under "you keep 80%."
RULINGThe estimator hook must show gross AND net: ‘Up to $2,400/week in bookings · $1,920 to you.’ Never label a gross number ‘to you.’ This is the most-scrutinized celeb number — honesty here builds trust, and $1,920/wk still sells.
#42
CONFLICTADM Today "Net revenue $3,090 after splits + fees" on GMV $18,400: platform's 15% = $2,760 max; $3,090 is impossible without unexplained revenue.
FIXADM net revenue: platform = 15% of GMV minus Stripe fees. On $18,400 GMV: $2,760 − ~$570 fees ≈ $2,190. Replace the impossible $3,090 with the formula-derived figure.
#43
CONFLICTADM @dre drill-in "net to us $2,260" on GMV $18,700: 15% = $2,805; if the $545 delta is Stripe fees, that's never stated, and it doesn't match 2.9%+$0.30 on 187 calls (~$598) either.
FIX@dre net-to-us: 15% of $18,700 = $2,805 − Stripe fees. Show the fee line explicitly so the delta isn’t a mystery.
#44
GAPPartial call / tech failure: the room dies at minute 6 of 10, or recording infra kills the call — no pro-rate, refund, make-good, or fault-attribution policy in ANY artifact. This is the most common real-world dispute and it's a total blank.
RULINGPARTIAL-CALL POLICY (D5) fills this blank: platform fault → full refund + celeb paid; connection fault <50% → free rebook; recording-only loss → make-good credit.
#45
GAPReschedule pricing: fan reschedules (<24h credit) into a slot after the celeb raised the 10-min price from $100 to $150 — honor original price, pay the difference, or refuse? Undefined; also unclear if reschedule must be same service/duration.
RULINGReschedule honors the ORIGINAL price and service. A price change between booking and reschedule doesn’t apply; must be the same duration.
#46
GAPRefund destination edge: refund fires 3+ months later (reschedule chains, disputes) to an expired/cancelled card — no fallback stated.
RULINGRefund to an expired card: Stripe routes to the replacement card on file; if none, we email the fan to add a payout method (ACH/PayPal fallback). Standard Stripe refund fallback.
#47
GAPConduct-forfeit ledger math: ADM says "forfeit to the platform; talent ALWAYS paid in full" — but the four T&S buttons include "Refund fan (not warranted)" with no rule for who funds a refund on a call where talent was already instant-paid (platform eats 80%+? clawback?).
RULINGConduct ‘Refund fan (not warranted)’ button is for operator discretion on borderline cases; funded by the D9 reserve, celeb keeps their pay. Rare, logged, reason-coded.
#50
GAPCeleb cancel after a fan bought a same-night extension chain: refund composition undefined (minor).
RULINGCeleb cancel with a same-night extension chain: refund every captured piece (base + any extensions) for that booking. Simple sum.
#51
GAPTaxes/1099: nothing anywhere on tax docs for celebs earning $10K+/mo (Stripe Connect handles mechanics, but the talent agreement referenced in ToS §7 doesn't exist).
DEFERTaxes/1099: Stripe Connect issues 1099-Ks automatically at threshold. Note it in the talent agreement; no product work for v1.

D. Hours / drops / menu

#52
GAPCeleb edits hours with existing bookings inside the removed window: E1/S4 promise "change your menu or hours any time"; no artifact says existing bookings survive (they must — but is the celeb warned? blocked? auto-cancel with pickup-rate hit?).
RULINGExisting bookings are ALWAYS honored. Editing hours only changes FUTURE availability; removing a window that has a booking warns the celeb and leaves the booking intact.
#53
GAPCeleb deletes/re-prices a menu item with future bookings on it: booked price honored (presumably) — never stated; affects reschedule pricing (#45) and the "at your rate" extension formula (#34).
RULINGDeleting/re-pricing a menu item hides it from new bookings; existing bookings keep their booked service + price.
#54
GAPDrop overlapping standing hours: drops are "a separate feature" — but nothing prevents or defines a drop scheduled ON TOP of standing hours (double-sold time).
RULINGDrops and hours draw from ONE calendar, so the system physically can’t double-sell the same minutes. A drop over standing hours just fills the same time — allowed, deduped.
#55
GAPAuto-accept race: two fans complete Apple Pay for the same 7:20 slot within seconds — no slot-hold-at-checkout, lock, or loser-refund flow anywhere (CO has no reservation timer; S12 shows sold slots crossed out but no hold semantics).
RULINGCheckout soft-hold (8 min) prevents the race: first to complete Apple Pay wins; the other sees ‘that time was just taken’ + instant re-pick, authorization released, no charge.
#56
GAPManual-request expiry: see #3 — no TTL, no celeb-side SLA, no fan-side "pending" screen at all (the fan pending state is never drawn).
RULINGOff-hours request TTL + fan Pending screen (D3) — both currently missing, both required.
#57
GAP"Pause payphone" (ADM action; CP "can pause the payphone entirely"): effect on already-paid future bookings undefined — auto-refund all? honor and pause new sales?
RULINGPause = stop NEW sales, honor all paid future bookings. Celeb can’t pause away money a fan already paid.
#58
GAPSuspend (ADM, "requires a reason code"): same question, harsher — plus what the fan is told.
RULINGSuspend (T&S) = stop new sales AND auto-refund every paid future booking with a neutral ‘this payphone is unavailable’ note to fans. Harsher than pause, operator-only, reason-coded.
#60
GAPSlot granularity rule: are slot start times generated from the menu's durations (5-min service on :05s?) or fixed 10-min grid regardless of service? Never specified; drives #20–22.
RULINGSlot granularity resolved by D1: start times generate from the chosen service’s duration against free time, not a fixed grid.
#61
GAPCeleb cancels a whole session (not one booking): E6 handles per-booking refund; bulk-cancel of a night (12+ refunds, list notification, make-good) has no flow.
RULINGWhole-session cancel = one action that bulk-refunds every booking in it, texts the list, and offers each fan first dibs on the next session. Needs a screen (see H).

E. Identity / account

#62
GAPFan changes phone number: ledger names email as the recovery layer, but no flow exists in any artifact (S31 "You" tab has no change-number row).
RULINGChange-number flow: verify the NEW number by OTP while signed in on the OLD one (or via email recovery). Add the row to the You tab. Required for both sides.
#63
GAPCeleb changes number: THE verified credential (OTP against manager-registered number, S3) — re-verification flow undefined; also what happens if the manager relationship ends (who "owns" the payphone?).
RULINGCeleb change-number = same verified-OTP flow, plus manager re-confirmation. Payphone ownership stays with the celeb; if the manager relationship ends, the celeb keeps the payphone, manager loses the rev-share attribution.
#64
GAPNumber recycling: carriers reassign numbers; new owner OTPs into the old owner's account — saved card, recordings, bookings. No mitigation mentioned (email-confirm on new device, dormancy check). Security hole inherent to number-as-account, unaddressed.
RULINGNumber recycling mitigation: any OTP login from a NEW device also requires the email on file (or a card last-4). Blocks a recycled-number takeover of saved card/recordings. Standard for phone-first apps.
#65
GAPShared/family number: two people, one number = one account by design; never acknowledged.
RULINGOne number = one account, by design. Acknowledge it in help copy; a shared phone shares the account. Fine for launch.
#66
GAPWeb number A → app number B: S26's magic moment only works if numbers match; the mismatch case (booked with work number, signed into app with personal) has no merge/lookup path — fan sees an empty app and panics 10 minutes before a $100 call.
RULINGWeb-number-A / app-number-B: the app offers ‘Booked with a different number? Find my booking’ → verify the other number → merge. Prevents the empty-app panic 10 min before a call.
#67
GAPCeleb-as-fan: S24 caption says celebs download the consumer app too, 7c says role is decided by the signed-in number — those two statements conflict: if role is decided by number, how does a celeb reach fan surfaces to book another celeb? Mechanics undefined.
RULINGRole isn’t global — it’s per-context. A celeb’s account can BOTH run their payphone AND book others as a fan; the app shows the fan surfaces to everyone, the celeb surfaces only to claimed payphones. ‘Role by number’ in 7c means ‘your OWN payphone is recognized,’ not ‘you’re locked out of fan mode.’
#68
GAPManager permissions matrix: E1 "your manager can co-manage," ADM "scoped to their roster," ADM action "Edit menu/hours (with consent)" — nowhere is it defined what a manager can DO (edit prices? cancel bookings? trigger payouts? see fan PII?). The B2B product's core object is unspecified.
RULINGManager permissions matrix (define now): CAN — edit menu/hours/drops, view roster stats, message. CANNOT without per-action celeb consent — cancel bookings, change payout bank, export fan PII. Payouts always land in the CELEB’s Stripe, never the manager’s. This is the B2B product; spec it before build.
#69
CONFLICTNumber privacy vs audience export: S13/CO/S25 say flatly "Dre never sees your number," while S10 gives the celeb an exportable CSV of "12,483 people · every one gave a name, phone, and email." The ledger calls the list a disclosed exception "at signup" — but the checkout and sign-in copy state the absolute with no exception, and no disclosure exists at the list-join moment.
RULINGResolved by D4: keep the export, fix the copy to state both facts. The list-join disclosure appears at checkout, the never-shared-for-calling promise stays on call surfaces.
#70
GAPFan blocked/banned: numbers are cheap to rotate via VoIP; no device/card-fingerprint mention, and the banned fan's paid future bookings' disposition is undefined.
RULINGBan enforcement = card fingerprint + device signal, not just number (numbers are cheap via VoIP). A banned fan’s paid future bookings are refunded and cancelled.
#71
GAPUnder-18 enforcement: ToS §2 requires 18+, App Store listing is 17+ (7c), and the web checkout collects no age attestation at all.
RULINGNOT a contradiction: 17+ is Apple’s maximum age rating (there is no ‘18+’ App Store category), while ToS enforces 18+. Add an 18+ attestation checkbox at checkout. Document the mapping.

F. Call / recording

#72
GAPCeleb recording consent: fan consents at checkout — the celeb claim flow (S2–S7) never once mentions recording; their only consent is buried in ToS §5. For the side whose likeness is the product, there's no explicit consent moment in onboarding.
RULINGAdd an explicit celeb recording-consent moment at go-live (screen 6/7): ‘Every call is recorded for both sides’ with an accept. The side whose likeness IS the product must consent in the flow, not just in ToS.
#73
PARTIALTwo-party-consent law: both parties notified (REC chip, checkout consent, ToS §5) which likely satisfies CA — but no legal note anywhere addresses state-by-state recording law; flag for counsel.
DEFERTwo-party-consent: the mutual REC disclosure likely satisfies CA; flag for counsel with the draft ToS/Privacy. Legal review, not build.
#74
GAPRecording failure: E5 promises the recording and S22 promises a forever-download; no policy for "call happened, recording lost" (partial refund? apology credit?). Also no policy when the recording is the dispute evidence and it's missing.
RULINGRecording-loss make-good (D5c): call stands, fan auto-issued a free 5-min credit. If the lost recording was needed as dispute evidence, the join log + transcript stand in and T&S rules conservatively for the fan.
#75
CONFLICTRetention: platform retains 90 days (S22, E5) vs celeb archive "312 calls · every recording is yours" with no expiry vs fan "download forever." If the archive streams from platform storage past 90 days, retention isn't 90 days; if not, the archive silently rots. Unresolved three ways.
RULINGRetention triangle resolved by D6; write it into ToS §5 verbatim.
#76
GAPModeration bot as third participant: the real-time moderation plan puts a server participant in every call; nothing reconciles this with the 1:1 framing or discloses "monitored" beyond one word in CP/HIW — counsel question.
DEFERModeration participant: the ‘monitored’ disclosure covers it; confirm the exact wording with counsel. The bot is invisible to both parties and doesn’t break 1:1.
#77
GAPCeleb-side extension consent: the +5 offer is fan-tap-only; nothing asks or pre-authorizes the CELEB to stay 5 more minutes. Undefined whether celeb can decline an extension.
RULINGCeleb extension consent = the Hours toggle (D8) + an in-call decline. A celeb with a hard stop turns the toggle off; the +time offer never appears to their fans.
#78
GAPReport-flow outcome for the FAN: report button exists in-call; what a fan-filed report does to payment (hold the split? freeze instant payout?) is undefined — instant payout on completion makes post-hoc fan-side remedies unfundable without clawbacks.
RULINGA fan report FREEZES that call’s instant payout into review (funded stays in the D9 reserve) until T&S rules. This is why the reserve exists — it makes post-call fan remedies fundable without clawbacks.
#80
GAPFan who objects to recording AFTER paying: no cancel-with-refund path defined for this reason (consent was at checkout; presumably standard cancel rules — never stated).
RULINGObjecting to recording after paying = a standard cancel (>24h full refund, <24h reschedule). Recording is non-negotiable and consented at checkout, so there’s no special refund path.

G. Cross-artifact consistency (mostly the D10 sweep)

#81
CONFLICTS20 payday: $250/$200/$1,540 vs the same call being $150/$120/$1,340 everywhere else (S21, S23, S9, APV2) — see #40.
FIXS20 $250/$200/$1,540 → $150/$120/$240 canonical (D10).
#82
CONFLICTSlot counts: Tuesday = "7:00–9:00 PM · 12 slots" (S5, APV2 Hours) but "4 of 24 slots unsold" TONIGHT (S8/APV2 Today) and "24 slots open" Tuesday (S7d) and "13 of 18 calls done" tonight (S9/APV2 Earnings). Same night is 12, 18, and 24 slots across four screens.
FIXPick 10 openings for the canonical Tue session; propagate to S5/S7d/S8/S9/APV2. One number everywhere.
#83
CONFLICTSession capacity: "23 calls · sold out" and "21 calls · 2 extensions" in 2-hour sessions — 2 hours holds at most 12 ten-min or 24 five-min calls; 23 calls averaging ~$115 gross doesn't fit any menu×time combination.
FIXSession capacity must obey D1 time math (120 min ÷ (service+buffer)). No ‘23 calls in 2 hours.’
#84
CONFLICTTemporal impossibility: Today header 7:41 PM, session started 7:00 PM, yet "13 of 18 calls done" — max 4 calls could have run by 7:41.
FIXAt 7:41 PM (41 min in), at most ~3 calls done — fix ‘13 of 18.’
#85
CONFLICTADM drop event: "@solrivera · 24 slots · 12,483 texts" — 12,483 is DRE's list size; Sol's list is 44,210 in the same admin screen.
FIXAdmin drop event: use Sol’s real list size (44,210), not Dre’s 12,483.
#86
CONFLICTE2 vs ADM: Jordan M. booked Tue 7:20 PM $100 (E2, E3) while ADM shows Casey R. booking "Tue 7:20p slot @dre $180" — same slot, two fans, two prices across sample data.
FIXOne fan per slot in sample data — Jordan XOR Casey at 7:20, not both.
#87
CONFLICTE5 vs E6: both reference booking #PP-88214; E5 says the call ran 10:00 of 10:00, E6 says Dre no-showed the same booking. The four fan emails reuse one booking ID for mutually exclusive outcomes.
FIXOne booking ID per outcome across emails — E5 (completed) and E6 (refunded) can’t share #PP-88214.
#88
CONFLICTE5 "10:00 of 10:00" vs S21/S23 where the same Jordan/Dre call ran 15:00 with an extension.
FIXE5 duration must match the archive (15:00 with extension, or drop the extension from the canonical Jordan call — pick one).
#90
CONFLICTExtension "at the celeb's rate": ledger vs S19 ($50 ≠ $60 five-min menu price) vs ADM ($125 vs Sol's $150 floor) — three artifacts, three implicit formulas.
FIXAll extension figures derive from D8; sweep the three mismatched ones.
#92
GAPConduct-forfeit at checkout: the moderation plan mandates "say so at checkout"; CO fine print covers recording + cancel policy but NOT conduct forfeiture (HIW FAQ and CP have it; the legally load-bearing surface doesn't).
RULINGAdd conduct-forfeiture to the CHECKOUT fine print (it’s legally load-bearing and currently only on CP/HIW).
#93
CONFLICTLedger "follow is PAID" (the founder's revision, overriding free-watchlist) vs journey S28 "Watching is free because it's the ring" and S21/E5 free one-tap list joins. The journey builds the free model the ledger says the founder overrode.
RULINGResolved by D7: free watch at launch; the journey is correct, the ledger’s paid-follow becomes the documented v1.1.
#94
CONFLICT18+ (ToS §2) vs 17+ App Store rating (S7c).
FIX18+/17+ is the correct mapping (see #71); document, don’t ‘fix.’
#95
GAP"Captured at booking, split on completion," "platform eats Stripe fee on refunds," "manager 5 pts" appear ONLY in the ledger — no customer-facing or ops artifact carries them beyond ToS §3's one sentence.
RULINGSurface ‘captured at booking / split on completion’ in ToS §3 (fan-facing) and the manager agreement (celeb/manager-facing), not just the ledger.
#96
CONFLICTDesign law vs artifacts: EMOJI BANNED but E2's subject leads with 💰 and ADM's sidebar uses emoji icons (👥 🛡 ⚙).
FIXPurge emoji: E2 subject (💰) and admin sidebar (👥 🛡 ⚙) violate the design law. Replace with the stroke set.
#97
GAPOld-vocab inventory ("line" where the locked word is "payphone"): site (all pages), ALL SIX EMAILS, ADM (section named "Lines"), app-proto, app-proto-v2, v4 mockups. Journey + design guide are the only swept artifacts.
FIX‘line’→‘payphone’ sweep across site, all 6 emails, admin, both prototypes, v4 mockups. Journey + guide already done.
#98
CONFLICTHIW step 2 hard-codes "(5, 10, or 20 minutes)" as the platform's lengths — that's Dre's menu; the locked decision is celeb-set durations.
FIXHIW step 2 must say ‘the celebrity sets the lengths and prices,’ not hardcode ‘5/10/20.’

H. Missing screens — build order

#100
GAPFan refund/report screens — admitted undrawn, twice.
RULINGFan refund/report UI — PRIORITY 1 (paired with D5/D9). Draw next.
#111
GAPWeb account surface for fans: cancel/reschedule links exist in E3, but no logged-in web "my bookings" page — the no-app promise breaks at the first cancel.
RULINGFan web ‘my bookings’ page (magic-link auth) — PRIORITY 1. The no-app promise breaks at the first cancel without it.
#102
GAPCeleb cancels-a-booking flow — E2 says "do it in the app"; no screen exists.
RULINGCeleb cancel-a-booking flow — PRIORITY 2 (E2 already tells them ‘do it in the app’).
#103
GAPReschedule picker — S30 has the button; E3 has the link; no screen.
RULINGReschedule picker — PRIORITY 2 (button + email link already point at it).
#104
GAPFan pending-request state for off-hours asks (celeb side drawn; fan side absent).
RULINGFan Pending-request screen — PRIORITY 2 (required by D3).
#106
GAPCeleb consent-to-recording moment in onboarding.
RULINGCeleb recording-consent moment — PRIORITY 2 (D-72), one screen in onboarding.
#61
GAPCeleb cancels a whole session (not one booking): E6 handles per-booking refund; bulk-cancel of a night (12+ refunds, list notification, make-good) has no flow.
RULINGWhole-session cancel — PRIORITY 2 (bulk refund + list notify).
#105
GAPManager dashboard — the "real B2B product" per ledger; exists only as ADM's one-line note.
RULINGManager dashboard — PRIORITY 2 (the B2B product; permissions per #68). Bigger effort, plan after the two P1s.
#108
GAPWaitlist for sold-out sessions — a sell-out dead-ends with no capture ("text me if a slot frees").
RULINGSold-out waitlist (‘text me if a slot frees’) — PRIORITY 3, captures demand scarcity throws away.
#107
GAPBanned-fan experience (what they see, outstanding bookings, appeal path).
RULINGBanned-fan experience — PRIORITY 3 (neutral copy, outstanding bookings refunded, no appeal at launch).
#110
GAPCeleb rates/blocks a fan: S8 shows the fan's "★ 5.0 THEIR RATING," but no screen captures a celeb rating a fan, and celeb-blocks-fan doesn't exist.
RULINGCeleb rates/blocks a fan — PRIORITY 3 (the fan already has a ★ rating shown; add the celeb-side capture).
#109
GAPAccount deletion / data rights (CCPA/GDPR delete vs recordings that are the OTHER party's evidence/keepsake).
DEFERAccount deletion / data rights — with counsel + Privacy v1; recordings are the OTHER party’s evidence, so deletion anonymizes rather than erases.
#112
GAPSupport surface: "a human answers" — no SLA, no in-product help beyond one row.
DEFERSupport SLA + in-product help — email + a help row at launch; formal SLA later.
#113
GAPAndroid app — 7b says "Google Play, same link"; no Android artifact or plan.
RULINGAndroid — same React Native/Expo build as iOS, same screens; confirm it’s in the build plan (it is, per push architecture).
#114
GAPPayment-failure and 3DS states in checkout; slot-hold timer during checkout.
RULINGPayment-failure / 3DS / slot-hold states — part of the checkout build (D3/#55).
#115
GAPMembership/paid-follow product: no checkout, no pricing, no take-rate, no screens — despite being a locked the founder revision and the "owned audience" monetization.
DEFERMembership/paid-follow product — v1.1 per D7; no v1 screens.
#116
GAPTalent agreement (ToS §7 references it) — document doesn't exist.
RULINGTalent agreement — the doc that carries reserve (D9), rev-share, taxes, extension terms. Draft with counsel before onboarding real talent.
#117
GAPCeleb archive export at scale + what happens to the archive if the celeb leaves the platform.
DEFERCeleb archive export at scale + on-departure — covered by D6 retention; bulk export is a v1.1 nicety.
#118
GAP"Open a payphone manually" (ADM Today button) — operation undefined.
RULING‘Open a payphone manually’ (admin) = ops force-opens a session for a celeb (e.g. a special event the manager arranged). Define as an admin action.
#119
GAPMulti-celeb/manager bulk tooling (invite 50 clients, batch hours) — the 10-managers GTM has no artifact.
DEFERManager bulk tooling (invite 50, batch hours) — v1.1; the 10 launch managers can be onboarded hands-on.
On approval: these become the ledger's canonical spec, I run the FIX sweep across every artifact (sample data, emoji, line→payphone), then draw the Priority-1 missing screens (fan refund/report + fan web "my bookings"). After that, no flow a fan or celeb can reach has undefined behavior — the bar for dev mode.