Should an App Be Allowed to Embarrass You Awake? A Conversation

Short answer: engineered consequence apps sit ethically closer to a $20 gym cancellation fee than to public shaming, as long as the exposure is small, private, and time-limited. Two people disagree about whether that's good enough.

The conversation below is constructed — a composite of arguments I’ve had, half-remembered, with three different friends who work in product and psychology — but every position in it is one somebody has actually made to my face.

Two people, one coffee, one open laptop showing an app’s onboarding screen.

A: So if you don’t get up, it posts a photo. From your camera roll. To your friends.

B: For 48 hours, then it’s gone. And you picked the friends.

A: That’s still an app choosing to embarrass you on purpose. That’s the product — isn’t that just shame with better UX?

B: It’s the same shape as a $20 late fee at a boutique gym. You agreed to the stakes before they applied. The stakes just happen to be social instead of financial.

A: Money doesn’t have a face. A photo does.

B: Right — and that’s not an accident, it’s the point. B.J. Fogg’s behavior research at Stanford has argued for years that consequences work in proportion to how much they matter to the specific person, not in the abstract. Twenty dollars means nothing to some people and a lot to others. A photo your sister sees means something to almost everyone, almost every time. That’s not a flaw in how it’s built. That’s why it’s more reliable than a fine.

A: That’s the same argument casinos make about variable rewards. “It works” isn’t the same as “it’s fine.”

B: Sure — and that’s the actual line to draw, not “does it work.” Natasha Dow Schüll’s research on slot machines describes systems built to extract value from you without your ongoing consent, hidden inside a loop you can’t see the edges of. This is the opposite: you see the whole thing before you opt in, the group is people you chose, and the exposure has a 48-hour expiration built in, not an open-ended one.

A: So consent is doing all the ethical work here.

B: Consent, scope, and an end date. Silence from the group can carry the same weight without anyone saying a word — take any one of those three away, though, and I’d agree with you. A stranger audience, no disclosure, or a photo that stays up forever — that’s shame as a product feature. Small chosen group, disclosed upfront, gone in two days — that’s a stake, the same category as a bet you made with a friend, just automated.

A: I still think there’s a version of this that goes wrong for the wrong person — someone already anxious about how they look, someone whose “friend group” isn’t actually safe.

B: I don’t think that’s wrong. I think that’s the actual limitation, not a debate-ending one — which is exactly why the group is supposed to be small and chosen, not open by default. The safeguard is real, but it only works if people actually pick carefully who’s in the room. Plenty won’t.

A: Peloton’s streak counter skips the consent question almost entirely — nobody signs a scope or an end date before the app starts making them feel bad about a broken number.

B: Right, and that’s the actual difference worth naming. A leaderboard applies to everyone by default. What we’re describing only works because somebody opted in on purpose.

Neither of them changed the other’s mind. That’s usually how it goes with systems like this one — DontSnooze’s version included — that trade privacy for leverage on purpose.

Keep reading