Products·Free
The Sovereignty Checklist
The free, channel-free version. Print it, score it by hand, and nothing leaves your desk.
Three ways to run it, none of them gated
The assessment is free. This page is the version that touches no channel at all - you can print it, score it with a pen, and no data about your product ever leaves the room. That is the point.
Prefer a guided run? The same 47 items work as a free Claude skill,
/sovereignty-assess, that walks you through them
conversationally. Prefer a polished, team-ready document? The $49 PDF
adds the scoring rubric, the domain health map, and the action-plan
template. The methodology is identical across all three. Sovereignty
is the free part; polish is the paid part.
How to score
- 2 Yes, fully implemented.
- 1 Partially implemented, or inconsistently applied.
- 0 No, not implemented.
- N/A Not applicable to this product. Subtract 2 from the maximum for each.
Be honest. If you are not sure, lean toward the lower score. It is easy to revise upward later; it is hard to be honest retroactively. Maximum score: 94.
The 6 red flags
These six override everything. A product that fails any one of them has work to do, regardless of its overall score. If you have five minutes, start here.
- 13 Account deletion is straightforward, complete, and timely.
- 24 No confirmshaming. ("Are you sure you want to miss out?" is not a real question.)
- 25 No artificial urgency or scarcity. ("Only 2 left!" when there are 2,000.)
- 27 No trick questions or misdirection in consent flows. The "yes" and "no" are equally clear.
- 30 Vulnerable populations - children, elderly, people in grief or crisis - receive additional protection, not additional targeting.
- 40 User data is not sold, shared for advertising, or monetized without explicit, informed consent.
The 47 items
1 Transparency / 16
"Are we honest about what we’re doing and why?"
- 1Users can see what data is collected about them.
- 2Privacy policy is in plain language - not legal boilerplate.
- 3The business model is visible. Users understand how the product makes money.
- 4Algorithmic recommendations are explained or explainable on request.
- 5Third-party data sharing is disclosed specifically - not bundled into a blanket consent.
- 6Policy changes and updates are communicated proactively, not buried.
- 7Pricing is clear. No hidden fees, surprise charges, or bait-and-switch.
- 8Marketing claims match actual product behavior.
2 Autonomy / 16
"Does the product support user goals - or hijack them?"
- 9Users can complete their primary task without engineered friction barriers.
- 10The product has natural stopping points. No infinite scroll, no compulsive autoplay.
- 11Time-awareness features are available - usage reminders, session limits, or break prompts.
- 12Cancellation is as easy as signup. No retention mazes. No phone-call-required cancellation.
- 13Account deletion is straightforward, complete, and timely.
- 14Data export is available in a portable, standard format.
- 15Default settings serve the user’s interest, not engagement metrics.
- 16Users can customize notification frequency, type, and timing.
3 Invitation / 14
"Do we earn attention through value - or capture it through tricks?"
- 17Onboarding demonstrates value before asking for commitment.
- 18Notifications respect user-set boundaries and schedules.
- 19Permission requests happen in context, when the feature is needed - not on first launch.
- 20Re-engagement messages provide genuine value, not guilt or manufactured urgency.
- 21Upgrade prompts are informational and dismissible - not manipulative or recurring.
- 22Free tiers are genuinely functional. Not crippled to coerce conversion.
- 23The product degrades gracefully - works offline, on slow connections, on older devices when possible.
4 Dignity / 16
"Do we respect the person - or exploit their psychology?"
- 24No confirmshaming. ("Are you sure you want to miss out?" is not a real question.)
- 25No artificial urgency or scarcity. ("Only 2 left!" when there are 2,000.)
- 26No guilt mechanics - no streaks designed to punish absence, no sad mascots, no social pressure to re-engage.
- 27No trick questions or misdirection in consent flows. The "yes" and "no" are equally clear.
- 28Error messages are helpful and human - not blaming, not cryptic.
- 29The product accommodates diverse emotional states. It doesn’t assume everyone is having a good day.
- 30Vulnerable populations - children, elderly, people in grief or crisis - receive additional protection, not additional targeting.
- 31Social features don’t exploit comparison, competition, or fear of missing out.
5 Silence / 12
"Do we know when to be quiet?"
- 32The product knows when not to send a notification.
- 33Quiet modes, focus modes, or reduced-engagement options exist.
- 34Empty states are calm - not anxiety-inducing calls to action.
- 35The product doesn’t punish absence. Coming back after time away feels like a welcome, not a guilt trip.
- 36Background data collection and activity are minimal and fully disclosed.
- 37The product supports completion. It can be "done." It doesn’t engineer endless engagement.
6 Data Sovereignty / 10
"Does the user’s data serve the user - or the business?"
- 38Data collection is minimized to what the feature actually needs. No "collect everything, figure out use later."
- 39Sensitive data is encrypted at rest and in transit.
- 40User data is not sold, shared for advertising, or monetized without explicit, informed consent.
- 41Consent is granular. Separate permissions for separate uses. Users can say yes to some and no to others.
- 42Data retention has clear, documented limits. Users can see and control how long their data is kept.
7 AI and Voice / 10
"If the product uses AI - does the AI honor sovereignty too?"
- 43AI agents are honest about what they don’t know. They say "I’m not sure" instead of fabricating.
- 44The AI’s voice reflects intentional values - not unexamined defaults. Someone chose how it speaks.
- 45AI interactions don’t use sycophancy, emotional manipulation, or false urgency.
- 46AI outputs are presented as suggestions - not commands. The human remains the decision-maker.
- 47AI interactions are reviewable. Users can see what the AI said, correct it, or report problems.
If the product doesn’t use AI, mark items 43-47 N/A and subtract 10 from the maximum.
What your score means
- 80-9485-100%Sovereignty-Honoring
- 60-7964-84%Progressing
- 40-5943-63%Mixed
- 20-3921-42%Extractive
- 0-190-20%Adversarial
Red flags override the total. A product can score well overall and still have a critical failure. If any of items 13, 24, 25, 27, 30, or 40 scored 0, that is your priority regardless of the total.
The three questions
Every one of the 47 items is a specific instance of three deeper questions: What is the person trying to do? What is the product trying to do? Are these aligned? When the answer to the third is yes, sovereignty is honored. When it is no, you have a tension worth naming - not burying in a backlog.
Sovereignty is free. Polish is paid.
Run it on your own product, or on someone else’s. Then run it again in 90 days. If you want the polished, team-ready edition - the scoring rubric, the domain health map, the action-plan template, and a team license - that is the $49 PDF. The assessment above is free and stays free.
Licensed under Creative Commons Attribution 4.0 (CC BY 4.0). Free to use, share, and adapt with attribution to Erin Stanley, Evoked.