case study
cruush.
The flagship: a map-first queer cruising app with reciprocal discovery and location privacy, live at cruush.app and still in development. This page is what commissioning this studio looks like, shown through the thing it built for itself.
The problem cruush solves
Apps that help people find each other usually make the person the product. Presence is broadcast to strangers, location sits in somebody else's database, and access to your own community is rented back to you month by month. For queer cruising, where being seen by the wrong person carries real cost, that trade is worse than inconvenient.
cruush is built against that arrangement, on two ideas the company treats as its protocol layer: mutual visibility, so two people are shown to each other only when the interest runs both ways, and proximity without disclosure, so someone can be near you on a map without the map giving away where they stand. How you find each other, owned the way a body is owned. Not licensed, not rented, not watched.
How it protects the people on it
Protection is the first requirement of the product, so it is engineered rather than promised. What cruush carries is encrypted, in transit and where it rests: nobody standing between a person and the service reads what passes, and what the service holds is not lying in the open.
Location is treated as the most dangerous thing the app touches. Proximity is computed without disclosure, so the map can say someone is near without ever saying where they stand, and nobody's position is broadcast. Visibility is mutual by construction: a person appears only to someone they have chosen to appear to, and there is no browsing strangers who never opted into being seen.
The service keeps as little as it can, because the safest data is the data never stored, and it runs on infrastructure the company controls, with no third party mining the middle. The exact mechanics stay internal on purpose: publishing the blueprint of a safety system is how it stops being one. What is public is the standard it is built to.
The IP underneath it
The two ideas at the top of this page have names, and the company holds them as intellectual property, both patent candidates: Mutual Visibility Cryptography and Privacy-Preserving Proximity Discovery. They exist because the hardest problems in the product had no acceptable off-the-shelf answer, so the studio invented its own.
Mutual Visibility Cryptography is the visibility side. A person's visibility rules stay encrypted, and the rules are evaluated reciprocally, so two people become discoverable to each other only when each satisfies the other's policy. Consent runs in both directions before anyone appears, and the rule is carried in the cryptography itself rather than in a promise a server is trusted to keep.
Privacy-Preserving Proximity Discovery is the location side, the invention that ships in the app under the name Ghost Mode. Nearby-user discovery is designed to minimize exact-location disclosure, so the app can say someone is close without the map holding a pin on where they stand: each viewer sees rotating display coordinates of their own, a position that is theirs alone and does not sit still.
The claims and the engineering behind them stay internal, like the rest of the safety mechanics. What is public is what they do and what they are worth: they turn the hardest privacy problems into durable capability the company owns outright, and where they hold up they can be licensed as well as shipped. That capability, inventing the missing piece instead of working around it, is part of what a commission hires.
What we made
The whole organism, not a feature list: the map-first interface, the visibility model underneath it, and the product identity, designed and engineered as one thing rather than a design handed to developers or code dressed up afterwards.
The engineering is treated as an asset with a life beyond the first app. cruush's codebase is built to stand up further networks, so the second one costs a fraction of the first. That is what it looks like when software is built as property instead of as output.
The design
The visual language runs on heaven and hell at once, and it runs through the whole app rather than sitting in the logo. The map is a city at night set in a churchly serif, and the people on it are hearts: photographs held in glowing heart frames, gatherings blooming on the street grid like votive candles. The iconography swings between the two worlds on purpose, winged hearts with halos beside horned devils and masks, blackletter out of hymnals crowned in flame.
Queer desire has spent centuries being assigned to one of those worlds or the other. cruush draws it as belonging to both, so the interface reads as somewhere between a cathedral and a back room, and means it.
How it is built
The same way the studio builds for clients, because it is the same people and the same standards. Design and behaviour are decided together, so the result reads as one thing. Architecture is chosen for the next decade rather than the next funding round. The work is built to keep running whether or not the people who wrote it are still in the room, and it is owned whole: repository, design files, accounts, infrastructure.
Commissioned work funds cruush independently, on no one else's terms. It is not a side business subsidising a hobby, and the standards do not drop when the client is the company itself.
The same hands take commissions
Everything above is for sale as a practice. Custom software engineered around you and handed over whole. Custom websites built from the ground up rather than assembled from a theme. Interactive and virtual experiences where art direction and engineering are one decision, and websites for artists treated as part of the work.
If cruush is the kind of thing you want built for your own problem, that is exactly the engagement. Read the questions people ask first, the guides on commissioning, or the honest comparisons with staying on a hosted builder.
use it. commission it. back it.
