Consumer internet & apps. Every tap is a design decision.
Regulators now read the interface as closely as users do.
Social and creator platforms, subscription and dating apps, marketplaces and super-apps, where growth is won in the interface and regulators now judge the interface itself. We design sign-up, consent, subscription and reporting flows that convert without dark patterns, the trust and safety tools behind them, and AI that labels what it makes.
DPDP Act 2023 — Digital Personal Data Protection Act, 2023GDPR — General Data Protection Regulation (EU) 2016/679WCAG 2.2 AA — Web Content Accessibility GuidelinesOWASP Top 10 for LLM Applications — LLM and generative AI security risksEU AI Act — Artificial Intelligence Act (EU) 2024/1689CERT-In Directions 2022 — Cyber incident reporting directions
Consumer internet & appsThe interface is where the rules are read now.
ClaimsAdvertising & claims: Shapes most of the work
RegulatorSector regulator: Shapes most of the work
PaymentsPayments: Often shapes the work
DataPersonal data: Shapes most of the work
SecuritySecurity & incidents: Often shapes the work
AccessAccessibility: Often shapes the work
AIAI governance: Often shapes the work
What is shifting
The regulator reads the interface, not just the terms of service.
Dark patterns, synthetic media, grievance clocks and children’s data moved from policy pages into the product. Each shift names what it demands, with a fact you can check.
Hundreds of small decisions a day, all made on a screen.
01
Regulators now read the interface, not only the terms.
It demandsSign-up, checkout and renewal screens that pass a dark-pattern audit before they ship.
SignalThe CCPA named 13 dark patterns in 2023; in June 2026 it fined an edtech platform for a pre-ticked donation and a security-software maker for a renewal screen offering ‘Accept risk’.
02
Synthetic media must be labelled at the source.
It demandsCreation tools that label AI output by default, and upload flows that ask before anything is published.
SignalIndia’s IT Rules amendment of 10 February 2026 requires prominent labels and embedded metadata on AI-generated media, in force from 20 February 2026.
03
Platform response clocks are now measured in hours.
It demandsReporting, grievance and takedown tooling with every clock visible to the trust and safety team.
SignalUnder the IT Rules as amended with effect from 20 February 2026, intermediaries must act on government or court orders within three hours and resolve grievances within seven days.
04
Children’s data is regulated by default, not by an age gate.
It demandsAge-aware journeys with verifiable parental consent and no behavioural advertising to minors.
SignalThe DPDP Act bars tracking, behavioural monitoring and targeted advertising directed at children; its parental-consent rules apply from 13 May 2027.
The rulebook
Every screen is evidence, every complaint has a clock.
The intermediary rules, the dark-pattern guidelines, the e-mandate framework and the data law, read for a typical consumer app. Your counsel keeps sign-off.
Frameworks we build to
DPDP Act 2023 — Digital Personal Data Protection Act, 2023
GDPR — General Data Protection Regulation (EU) 2016/679
WCAG 2.2 AA — Web Content Accessibility Guidelines
OWASP Top 10 for LLM Applications — LLM and generative AI security risks
EU AI Act — Artificial Intelligence Act (EU) 2024/1689
Frameworks we design and build to — not a claim of certification.
Advertising & claims
Shapes most of the work
Central Consumer Protection Authority
CCPA dark-patterns guidelines, 2023
Thirteen specified dark patterns, among them false urgency, basket sneaking, confirm shaming, forced action, subscription traps, drip pricing and nagging, are unfair trade practices for platforms offering goods or services in India.
We designEvery journey is checked against the thirteen patterns before release, and the check is kept as evidence.
Intermediaries publish their rules and a grievance officer, acknowledge complaints within 24 hours and resolve them within seven days, and act on government or court orders within three hours; large social platforms carry extra duties.
We designReporting, appeal and takedown flows are designed as product features, with each clock on screen for the team.
Online platforms may not design interfaces that deceive or manipulate users, must explain how their recommender systems rank content, and may not show profiling-based ads to users they know are minors.
We designFor EU users, recommendation settings and ad explanations are built into the product, not a separate help page.
Recurring charges carry a notice at least 24 hours before each debit, with a way to opt out of that debit or the whole mandate; charges of up to ₹15,000 may run without an extra authentication step.
We designRenewal screens show the next charge, its date and the way out, in words that match the bank’s notice.
Verifiable consent of a parent before processing a child’s data, no tracking, behavioural monitoring or targeted advertising directed at children, and consent per purpose with withdrawal as easy as giving it.
We designAge-aware journeys, parental-consent flows and ad systems that switch profiling off for minors.
Social media platforms and e-commerce entities with two crore or more registered users in India erase personal data three years after a user’s last contact, warning the user at least 48 hours before.
We designDormancy notices and deletion jobs are designed and tested, with one easy way to keep the account.
IT Rules amendment, 2026 — synthetically generated information
Tools that create or alter media with AI must label the output prominently and embed permanent metadata where technically feasible; large social platforms must ask users to declare synthetic content and verify the declaration before publishing.
We designCreation and upload flows label AI output by default and keep the user’s declaration with the post.
Compiled 3 October 2026. Our reading of typical programmes, not legal advice. Rules change; your counsel confirms how each one applies to you.
Challenges
Where consumer internet & apps loses customers and time.
What comes up first in most consumer internet & apps conversations — outside, at the screen, and inside, in the operation.
AYour customers
A1
Cancelling as easily as subscribing
Renewal reminders that arrive in time, a visible way out and no shaming copy on the way.
A2
Knowing what is real
Labels on AI-generated images, voices and posts, and on paid creator content.
A3
A report that gets a reply
Complaints acknowledged, tracked and resolved within the stated time, with a route to appeal.
Every tap is a consent, a purchase or a report.
BYour operation
B1
Growth against friction
Every consent step and disclosure tested against conversion, not argued about.
B2
Trust and safety at scale
Moderation queues, appeals and government orders running against clocks of hours, not days.
B3
One product, many rulebooks
Indian, EU and app-store rules applied to the same screens without forking the product.
What we build
The disciplines behind a typical consumer internet & apps programme.
A typical programme here draws on each discipline in this mix. Every line names what it builds for the industry and links to the capability that does the work.
Audit the flows first, then rebuild what users feel.
The way in walks every journey from sign-up to cancellation against the rules and ranks the fixes by risk and by revenue. Lengths are typical, never promised.
The way in
Dark-pattern and consent audit
We walk every sign-up, checkout, renewal and cancellation flow against the thirteen patterns, the e-mandate rules and DPDP consent, and rank the fixes by risk and by revenue.
Package
Sprint · Fixed fee
Typical length
2–3 weeks
It sets
Trial-to-paid conversion, as a baseline
Product experience audit
Martech stack audit & roadmap
What it hands over
A dark-pattern register with a fix for each finding
Cancellations completed without contacting support
Grievances resolved within the seven-day clock
AI, under the rules
AI labels what it makes, people decide what stays up.
Each use case has an owner, an evaluation set and a log; no model removes content or closes a complaint on its own.
Use case 01
Content-label checker
Measured byShare of AI-generated uploads labelled at the source
Tested forOWASP LLM01 · Prompt injection
agent / content-label-checkerGuarded
TaskChecks uploads for signs of AI generation and prompts the creator to declare and label them before they are published.
GuardrailTreats uploaded files and captions as untrusted input; never deletes or publishes on its own, and sends unclear cases to a reviewer.
HumanTrust and safety reviewers decide every disputed label.
LogDeclarations, checks run and reviewer decisions, per post.
✓Ships only with its evaluation set, its guardrail and an owner
Use case 02
Grievance triage assistant
Measured byGrievances resolved within the seven-day clock
Tested forOWASP LLM02 · Sensitive information disclosure
agent / grievance-triage-assistantGuarded
TaskSorts incoming complaints by type and by clock, and drafts the acknowledgement.
GuardrailDrafts only; no complaint is closed, rejected or answered by the model alone, and personal details are masked in its prompts.
HumanA grievance officer approves every resolution.
LogCategory, clock, draft and final reply.
✓Ships only with its evaluation set, its guardrail and an owner
Use case 03
Dark-pattern linter
Measured byFindings caught before release
Tested forOWASP LLM09 · Misinformation
agent / dark-pattern-linterGuarded
TaskReviews new screens and copy against the thirteen patterns before release and flags likely matches.
GuardrailAdvisory only: it cannot block or ship a release, and a clean result is never treated as approval.
HumanThe product owner signs off each flagged screen.
LogScreens checked, flags raised and the decision taken.
✓Ships only with its evaluation set, its guardrail and an owner
Work and insights
Case studies stay private until a client approves them.
No consumer internet & apps client is named or described without written approval. Here is what we have written that bears on the industry.
A typical programme · composite
A subscription app rebuilt its sign-up, renewal and cancellation flows around a dark-pattern checklist and the bank’s pre-debit notice, and ran the new flows against the old ones so retention, refunds and complaints were measured side by side.
Anonymised and illustrative: the shape a programme takes, never a named client.
Related reading
Nothing published on consumer internet & apps yet. Ask us what we are seeing in the industry.
Q.01Do the dark-pattern guidelines apply to apps as well as websites?
They apply to platforms offering goods or services in India, to advertisers and to sellers, whatever the interface, and the CCPA has penalised digital platforms under them. We audit the app and web journeys together; your counsel confirms how they apply to you.
Q.02What does the 2026 IT Rules amendment mean for our AI features?
If your product lets people create or alter images, audio or video with AI, the output must carry a prominent label and, where technically feasible, embedded metadata that cannot be stripped. Large social platforms must also ask users to declare synthetic content before it is published. We design both into the product; your counsel confirms the position.
Q.03Can cancellation be easy without hurting revenue?
We measure it rather than assume it: the new flow runs against the old one, with retention, refunds and complaints tracked side by side, and the numbers decide what ships.
Q.04Do you build trust and safety tooling?
Yes: reporting, appeals, moderation queues and grievance tracking, with each regulatory clock visible and an audit trail for every decision. AI can sort and draft; people decide.