Identity
There is no email-and-password path. The only way into Slapp is Kenni, the Icelandic electronic ID, so every account is a real person with a verified birthday.
Sign-in
Better Auth runs inside Convex as a local component, with its routes registered on the backend's HTTP router. It has a single generic OAuth provider, Kenni, configured with OIDC discovery and PKCE, an Icelandic UI locale, and forced re-login. A custom user-info step takes the national ID from the token, encrypts it, and derives the birthday. The Convex plugin issues one-hour JWTs, and sessions last 30 days.
Two client-side details: on Android the auth session is redirected to the system browser with a five-minute timeout, because Chrome Custom Tabs drop SIM-based authentication. And a progress marker in MMKV lets the app resume sign-in if an over-the-air update reloads the app mid-flow. The rest of the mobile auth bridge, which caches tokens, uses hysteresis before flipping to signed-out, and can recreate the Convex client after a long background, is described with the data layer on the product page.
On every authenticated call, an identity fast path compares the JWT subject to the users table directly, skipping the auth component, and enforces temporary bans and soft deletion. Admin is a boolean on the user document, checked in 50 backend files. Trusted origins for local development, such as localhost ports and Expo Go, are enabled only when the deployment is not production.
The kennitala
The kennitala is the Icelandic national ID number, and it is encrypted at rest. At sign-up the backend encrypts the full number with AES-256-GCM under an environment key, keeps the first six digits as a birthday key, and assigns a sequential member number. A batched migration exists to re-encrypt every stored kennitala under a new key.
The member number appears in onboarding and is printed on the member tee sold through the shop, so an early member has a low number on their tee. The monetisation chapter covers how the tee is printed with it.
Age gates
Because every birthday comes from the eID, age gates are enforced on the server. The app admits users from 13, which follows from when Icelandic eIDs are issued. Above that:
- Deit, the dating tab, requires 18. The tab is not even rendered for anyone younger.
- Markaðstorg and Leigumarkaður, the consumer marketplace and the rental market inside Svæði, require 18.
- The feed has a variant per age band: 13 to 16, 17 to 20, 21 to 30, 31 to 40, 41 to 50, and over 50.
Every node in the social graph is one real person, so a friend suggestion, a school cohort match or a "people near you" result refers to a single verified account, and the friend suggestion models train on clean labels.
Consent, deletion and child safety
Consent is versioned in code, currently terms 2.7.0 and privacy policy 2.8.0, and users are re-prompted on both mobile and web when a version changes. Account deletion is a soft delete with a 30-day restore window, followed by a scheduled hard purge. A child-safety-standards page is served from the backend, as Google Play policy requires.
Moderation and safety
Blocking hides in both directions and severs friendships, requests and cache entries. Shadow bans and temporary bans are logged and enforced centrally, and a singleton excluded-users cache is consulted by every feed read instead of scanning the users table. Reports cover 16 content types and 12 reasons, including CSAE, fraud and counterfeit goods, at a limit of 20 per hour. Marketplace risk is scored from weighted signals that adjust surfacing without hiding anything automatically, and dHash photo fingerprints block rental listings whose photos match an external index.