The App That Never Asks Your Name

· Praveen Vijayan ·

8 min read Original article ↗

Imagine you saw a physical shop with a strange rule that before you can step inside, before you even know you like the place, you must fill out a form. Your name, your email, and your password—and you will forget it the next day. Only then can you browse the shop.

You would walk away. Most people do, and this is how most everyday apps and websites work today. What if you want to try a writing tool or an AI assistant today? You need to sign up even before the value is delivered. The toll booth comes before the road.

I spent the last few months working on a different idea. It is called Earned Identity, and I recently published a research paper about it.

To be fair, taking people in without a form is not a new idea. Games have offered "play as guest" for years. Firebase and other big platforms let apps create invisible guest accounts. Anonymity at the door is a solved problem.

In every system running today, the moment you want to keep your work safe, the anonymity ends. Enter your email to save your work, or sign up with the form. Earned Identity is the first design where you never pay that price. You get the full safety of a real account: backup, multi-device, phishing proof, and the app still never learns your name.

This article explains the idea in plain language—no computer science degree needed.

Here is the thing most apps get backwards.

When you open a notes app for the first time, the app does not really need to know who you are. It only needs to answer a much smaller question later on: “Is this the same person who wrote these notes yesterday?”

Those are very different questions.

“Who are you?” needs your name, your email, a password — a whole interview at the door.

“Are you the same visitor as before?” needs none of that. A cloakroom solves it with a numbered ticket.

Most apps run a border-control desk when all they need is a cloakroom.

Passwords have many problems. We forget them, we reuse them, we write them in a sticky note, and when any services or any companies get hacked, which happens constantly, millions of passwords are leaked at once. You use that password for a different app, and it's exposed to thieves. Now they have keys to those doors too.

Companies patch this with "forgot password" emails, security questions, and verification codes. Each repair is another moving part that can break.

The research world has known for years that the best fix is to stop using passwords altogether. Your phone already knows how: when you unlock it with your face or fingerprint, no password travels anywhere. Modern passkeys built by Google, Apple, and Microsoft together bring the same trick to a website.

Here is the whole paper in one sentence:

You should not need an identity to start using an app. An identity should grow out of your use of it.

It works in two stages. Let me walk through both with the cloakroom.

You open the app and start working. No form. No pop-up. Nothing.

The moment you first make something—write a note, save a draft—your browser quietly creates a random ticket. Think of it as a cloakroom ticket with a number so long that no one could ever guess it: not a 2-digit number, but a number with 78 digits.

Your browser keeps this ticket. When you come back tomorrow, it shows the ticket, and the app hands you your work. Same visitor, same notes.

You never saw a form. You never typed a name. You may not even know the ticket exists.

Now, a fair worry: “If the app stores my ticket, can’t a hacker who breaks into the app steal it and pretend to be me?”

This is where the design gets careful. The app never stores your ticket. It stores only a fingerprint of it.

A fingerprint identifies you, but nobody can rebuild you from a fingerprint on glass. It works the same here: the app can check “yes, this ticket matches this fingerprint,” but a thief who steals the app’s entire list of fingerprints holds a stack of useless smudges. There is nothing to log in with, nothing to sell, and—because you never gave a name or email—nothing personal in the pile at all.

A burglar breaks into the vault and finds it empty. That is the whole point.

Tickets have a weakness, and the paper is honest about it: lose the ticket, lose the coat.

If you clear your browser data, or your laptop dies, your invisible ticket dies with it — and your work is gone. For your first five minutes of doodling, who cares. But one day the app holds something you would hate to lose. That is the moment—and only that moment—the app speaks up:

“Want to keep this safe, and open it on your other devices? One tap.”

You tap. Your phone asks for your face or fingerprint, the same as unlocking it. Done.

Behind that one tap, your flimsy paper ticket was traded for a passkey—a modern digital key stored by your phone. And passkeys come with superpowers the paper ticket never had:

  • They survive. Your passkey backs up with your phone. New phone? The key comes along, as your photos do.

  • They travel. Want to open your work on a laptop? Scan a QR code with your phone. No typing.

  • They cannot be phished. A fake copy of a website cannot use your passkey. The key itself refuses to work anywhere but the real site. You cannot be tricked into “typing your password” on a scam page, because there is no password to type.

Here is my favorite part—the part I promised at the start.

Remember the bill that every “guest mode” eventually sends: “Enter your email so you don’t lose your progress!” The form you skipped at the door catches up with you at the counter.

Earned Identity never sends that bill. The upgrade to a passkey asks for nothing. No email. No name. No phone number. The app knows you only as ticket number 47—before the upgrade and after it. You have a durable, phishing-proof, multi-device identity, and the app still has no idea who you are.

That, in one line, is what the paper contributes: you keep the safety of a real account without ever telling anyone who you are.

Every honest design names its trade-offs. This one has three.

1. Before you upgrade, your work lives only on one device. Clear your browser before that one tap, and the work is truly gone—there is no “forgot password” email, because the app never got your email. The app must say this clearly and nudge you to upgrade at the right moment.

2. It is not for your bank. Banks, hospitals, and governments genuinely need to know who you are—that is the law, and rightly so. Earned Identity is for the enormous world of apps that never needed your name in the first place: notes, drafts, assistants, and workspaces.

3. Anonymous is not invisible. The ticket number is steady over time, so the app can recognize you across visits—that is its job. The design includes ways to swap your ticket for a fresh one periodically and rules against leaking the number to advertisers. But “they don’t know my name” is not the same as “no one can ever connect the dots.”

One more thing worth saying, because it is the opposite of what you might expect from a research paper.

The paper invents no new cryptography. Zero. Every piece—the random ticket, the fingerprint trick, the passkeys—has existed for years, is built into every modern browser and phone, and has been examined by thousands of security experts.

In security, boring is a compliment. New locks are exciting until someone picks them; old locks that millions have failed to pick are what you actually put on your door. The paper’s contribution is not a new lock. It is noticing that the locks we already own can be arranged in a better order:

First let people in. Let them make something. Offer them the good lock the moment they have something worth locking. And never, at any step, ask their name.

The full paper—with the formal protocol, the security analysis, and the comparisons to how Firebase, PlayFab, and others do guest accounts today—is free to read:

“Earned Identity: Anonymous-First Authentication with Lazy Passkey Elevation for Low-Friction Web Applications” 📄 doi.org/10.5281/zenodo.21862500

I am also building a small app on this pattern, so the next posts will move from “here is the idea” to “here is what happened when real people used it.”

How many of you abandoned an app at the sign-up form? :)

Discussion about this post

Ready for more?