Work Play About Contact

Product Design · Identity · Mobile App

Nox+

A privacy-first identity platform I led end to end with a team of four. The defining call: we cut two of our own AI features, a document scanner and a file-reading assistant, once research showed the real blocker was trust, not convenience.

My Role
Lead Designer & Researcher
Team
1 lead · 1 researcher · 2 designers
Timeline
Sep – Dec 2025
Tools
Figma · FigJam · Qualtrics · Maze
Cover of the Nox+ design handbook
Design Handbook
21-page spec and rationale
Product demo
Guided tour of the final product
At a glance
01
The challenge
College students felt anxious every time they uploaded identity documents to another portal, with no transparency about where their data went.
02
What I did
Leading a 4-person team, I owned research and design end to end, from a survey of 96 and contextual inquiry to the trust model the app hangs on, cutting two of our own AI features once testing showed the real blocker was trust.
03
The outcome
A privacy-first verification flow built around visible trust: redacted previews, revocable sharing, and a cross-platform Face ID handoff, a direction the identity space has moved toward since.

Problem Identification

Meet Pam.

For students, verifying identity had become a privacy risk to brace for, not a routine task.

A graduate student verifying her identity for yet another online portal. Before she uploads her documents, she hesitates, unsure where her data will go or who can access it.

Pam · Graduate Student · University of Washington

"I've uploaded my passport to so many different portals. I never know who actually sees it or how it's stored. Every new system feels like a privacy risk."

For students like Pam, verification is fragmented and opaque: multiple logins, inconsistent requirements, and vague privacy policies. Users feel exposed rather than protected.

User Research

The data confirmed the anxiety.
The interviews revealed why.

The real problem was distrust, not clunky forms.

Students described learned helplessness: burned so many times they'd stopped trusting any system. One told me, "I just assume every portal is going to leak my data eventually." That distrust became the problem Nox+ was designed to solve.

How I researched Survey n=96 Interviews n=16 Contextual inquiry 2 sessions Full method in the handbook →
34%
of respondents were unsure which documents were required during verification
64%
have personally experienced or know someone affected by identity theft related to verification
57%
experienced frequent upload errors when trying to verify their identity online
01
"Why do I have to prove who I am 12 different ways?"
The frustration was fragmentation, not just bad UX. Every platform meant re-uploading the same documents to a different interface. Students cited Duo Security as the benchmark for "simple and reliable." We didn't need a better form; we needed a single source of truth.
02
Security that's invisible feels like no security at all
In contextual inquiries, participants stored passport scans in Google Drive with no encryption because "at least I can see it there." They needed visible proof: lock icons, confirmations, audit trails of who accessed what and when. Trust had to be performed, not just promised.

Design Process

We designed three versions
before we got it right.

The version that worked organized the app around the moment of verification, not document storage.

V1 treated Nox+ as a document vault (upload, store, retrieve), but storage alone didn't solve the trust problem. V2 added transparency panels, which tested better but felt overwhelming. V3 was the reorganization above, and it was the one that held up in testing.

Sketching: exploring feature ideas, screen flows, and layout before moving to digital
Early concept sketches exploring Nox+ app features and layout

Wireframes

I delegated screens across the team and held consistency through regular critiques, translating the research into the app's information architecture: the verification home, documents, history, and household controls.

Wireframes: the app IA and screen structure I owned, from the verification home to documents, history, and household controls
Nox+ wireframes: home, documents, history, and household screens with annotations

Design Decisions

Three decisions that defined
Nox+.

Each call traded a nice-to-have for the one thing Nox+ had to protect: trust.

Each was a moment where two reasonable approaches pointed in opposite directions. The decisions are where the trade-offs actually live.

01

Vault, or moment-of-verification?

A vault made storage the main event, but transparency panels added cognitive load to a moment that should feel automatic. I made the home surface what's being asked for, with security signals visible at the moment of share, and moved storage to a secondary surface.

Lost a clean "manage everything from one screen" hierarchy. Accepted because the research described identity as reactive, not planned.

02

Full document, or redacted preview?

Research kept surfacing the same finding: users felt exposed when their full passport was displayed on-screen, even before sharing. The most accurate preview was also the one that triggered the anxiety we were trying to solve. I made redacted preview the default (only the requested field visible) with "show full" one tap away, controlled by the user.

An extra tap for at-a-glance confirmation. Accepted because the discomfort signal was stronger than the friction signal.

03

What I cut, and why.

An AI document scanner and an assistant with access to your files were strong pitches. Both expanded the trust surface area, exactly the thing Nox+ existed to shrink. I cut both for V1 and held the line at biometric setup, document management, the Nox+ card, transparency panels, and family controls.

Less differentiation in a pitch deck. But every cut feature would have diluted the core promise.

Solution

Introducing Nox+.

Prove who you are without ever putting your documents on screen.

Nox+ is built on a simple premise: people don't want to manage their identity; they want to forget about it until they need it. The app pairs a physical proof card with a mobile platform for verification across digital and in-person contexts, and every feature answers the question participants kept asking: "Who has my data, and can I trust them?"

The Nox+ mark: a shield built around a verification star, in light and dark
Nox+ app icon, light and dark variants
The final designs: the identity home with a branded proof-of-identity card, the document vault, a privacy-preserving share (FAFSA keeps no copy of your documents), and family access
Final Nox+ screens: IDs home, document vault, FAFSA data-shared, and family access
The payoff, end to end: Pam uploads to FAFSA, approves the share with Face ID in Nox+, and the site confirms, without her documents ever being exposed on screen
Cross-platform verification: from the FAFSA website to Face ID approval in Nox+ to a verified confirmation
The cross-platform verification, step by step
1
On the FAFSA site
A portal asks Pam to verify her identity.
2
Approve in Nox+
She confirms with Face ID. No documents leave the app.
3
Encrypted token
Only the essential fields are shared, through an encrypted token exchange.
4
Verified
FAFSA confirms her identity and keeps no copy of her documents.

Validation

Testing that changed
the design.

Testing didn't just confirm the design. It changed it, every round.

Every round of usability testing existed to answer one question: do people trust this? Each round sent me back to change something specific.

63→94%
task success on the core verification flow, from the first prototype to the final usability round
Moderated usability test · 8 participants · 5 core tasks · measured first vs. final prototype
SUS 86
System Usability Scale score on the final prototype, in the “excellent” range
System Usability Scale · same 8 participants · post-test survey
96
students surveyed, plus interviews and contextual inquiries with people affected by a breach
Discovery phase · 21-question survey (n=96) + 16 interviews + 2 contextual inquiries
01
The AI we took out
An early prototype answered questions with a conversational assistant that could read your documents. Testing killed it: participants said plainly they didn't trust an AI with that level of access to their identity. I cut it and kept the intelligence quieter, a familiar search bar with AI-assisted recommendations underneath. Trust beat novelty.
02
A fingerprint pad sized by hand
For the proof card, I tested a single fingerprint point against the whole bottom edge. Watching where people naturally rested a thumb settled it: the bottom 30 to 40 percent felt right to nearly everyone. Testing also set the rule that details stay visible for 30 seconds after unlock, then hide, so a glance never becomes an exposure.
Three spreads from the Nox+ design handbook: the branded cover, the household and family-access app screens, and the dimensioned spec for the physical Universal Proof Card 21-page handbook · open PDF →
Every decision above is documented for the engineers who would build it: personas, storyboards, component specs, and the dimensioned Universal Proof Card. A sample of the 21-page handbook.

Systems Thinking

A trust product is judged by
its in-between states.

Confidence is won or lost in the states that aren't the happy path.

Before you're set up, when a document is about to lapse, when you want your data back: I designed those states as deliberately as the main flow, because that's where trust is tested.

🧭
Light Mode, before full verification
New users explore freely and activate their full digital ID later. The first run never hides behind a wall; it invites you in, then earns the deeper access.
💳
The card that goes dark
The physical proof card shows nothing until a biometric unlock, reveals your details for 30 seconds, then deactivates. A dropped card is just a blank card.
Documents that warn before they lapse
Expiration alerts surface ahead of time ("your passport expires in 6 months"), so a verification never fails at the worst possible moment. Any share can also be revoked from the transparency panel.
👪
Family access that expires
Guardian access is time-boxed to 14 days and managed from one screen, so a permission granted in a hurry cannot quietly live forever.

Live Prototype

See Nox+ in action.

A walkthrough of the Figma prototype demonstrating the complete user flow: from onboarding and biometric setup through document management and identity verification.

Prototype Walkthrough · silent screen recording

Reflection

What leading taught me
& what I'd do differently.

The hardest part of leading this wasn't the design itself. It was prioritization. With four people and 10 weeks, every yes to a feature was a no to two others. Saying no to good ideas, especially my own, was the work.

Apple's Digital ID launched in November 2025 while we were still building Nox+: the same trust problem, now surfacing in the world's largest consumer ecosystem. It didn't validate our specific design, but it was a good sign we'd read the problem right.

With more time, I'd push beyond students. The same verification anxiety hits immigrants, elderly people managing healthcare documents, and gig workers. Testing with those groups would show whether our trust-first framework holds across audiences.

Next Project
Saksham: Inclusive Learning for All
View case study →