Mine would be something like this. I’d also like some suggestions, since I’ve forked Stash to build it. If there are users interested in testing, I can provide a link to an instance and an invitation key via DM.
Forks:
Stash Box — Full Specification
A federated mesh of independently operated instances for metadata curation, discovery, ranking, and preservation of adult content.
Tagline: Catalog everything. Curate together. Discover everywhere. Preserve forever.
0. Design Principles
- Metadata is public and federated. Content is local, opt-in, and earned.
- Discovery is the default experience. Not search — recommendations.
- Instances have gravity. Operators and high-trust users tune the taste profile; recommendations bend toward it.
- Preservation is automatic by default. Content lives on multiple instances unless configured otherwise.
- Trust is earned, portable, and verifiable. Reputation follows the user across the mesh via signed attestations.
- The mesh is anonymous by design. Metadata sync runs over onion routing. No instance learns another instance’s IP.
- Local-first, peer-to-peer always available. Every user can run a node, share their own library, or participate in a DHT swarm.
- No single point of failure. Every layer — metadata, snapshots, reviews, rankings, content — is replicated by policy.
1. Federation Architecture
1.1 Instance Roles
- Hub instances — high-uptime, high-storage, host large portions of the archive. Typically operator-funded or community-funded.
- Community instances — themed (e.g., vintage, VR, indie studios, specific performers). Moderate storage.
- Personal instances — individual users running Stash Box locally. Contribute metadata, snapshots, and storage when they choose.
- Read-only mirrors — replicate metadata and snapshots but never accept writes or host content.
- Relay nodes — metadata-only. Handle onion routing, discovery, and sync. No content.
Any node can take on multiple roles.
1.2 Taste Profiles & Instance Gravity
Every instance publishes a taste vector — a high-dimensional embedding computed from:
- Elo votes cast by its users
- Reviews and ratings
- Tags co-occurrence
- Curation priorities
- Opt-in viewing signals (aggregated, never per-user)
- Operator-set gravity sliders
- Vanguard user preferences (weighted heavier)
Every instance also publishes a capability profile:
- Storage capacity, current usage, available bandwidth
- Uptime SLA
- Replication limits (min/max replicas it will host)
- Content policies (what it opts out of)
- Trust thresholds for content access
- Supported federation features
- Federation keys (signed public keys for metadata authentication)
1.3 Peering
- Instances peer automatically based on taste vector similarity (cosine similarity above a threshold), capability compatibility, and mutual trust attestations.
- Operators can override: whitelist, blacklist, or tune peering weights.
- Peer relationships are signed and revocable. Either side can drop a peer at any time.
- Peering tiers:
- Full peer — metadata sync, snapshot sync, content replication, curation quests, ranked discovery.
- Metadata peer — metadata and snapshots only.
- Discovery peer — read-only cross-search and recommendations.
- Relay peer — routing only.
1.4 Trust Attestations Across the Mesh
- Every user has a portable reputation key — a cryptographic keypair signed by their home instance.
- Reputation travels as signed attestations: “Instance A attests that user U has trust level 4, contribution score 12,340, vanguard status active.”
- Other instances can accept, weight, or reject attestations based on their trust in the attesting instance.
- Sybil resistance: attestation weight decays over time, requires regular re-signing, and is penalized by peer disagreement.
2. Trust, Roles, and Content Access
2.1 Trust Levels
- Level 0 — Anonymous: Browse public metadata, directory, rankings, reviews, snapshot collages.
- Level 1 — Registered: Elo voting, edit submissions, reviews, identification board posts, flags.
- Level 2 — Contributor: Auto-approved edits, expanded collages, XP, badges.
- Level 3 — Curator: Duplicate merges, tag management, full snapshot sets, curation quests.
- Level 4 — Archivist: Content upload, replica hosting, expanded curation powers.
- Level 5 — Steward: Governance, API keys, awards voting, gravity tuning, preservation policy input.
2.2 The Vanguard Role
Vanguards are users whose taste fingerprint has high resonance with the instance’s gravity, high trust level, and high contribution score.
- Resonance is computed continuously: cosine similarity between the user’s taste vector and the instance’s taste vector, weighted by how much their curation and reviews were adopted by the community.
- Vanguard status is dynamic — it can be earned, lost, and regained.
- Operators can appoint vanguards manually or let the algorithm do it (default: algorithm, with manual override).
- Vanguards get:
- Early access to new features
- Weighted influence on gravity tuning
- Priority in curation quests
- Larger storage allocation influence
- Opt-in content access (if enabled)
- Nomination privileges for the annual awards
- A visible badge and leaderboard placement
2.3 Content Access Rules
Content viewing is opt-in, per-instance, and role-gated. Default configuration:
A user can view content if ALL of the following are true:
- Trust level ≥ 4 (Archivist) or they are a Vanguard or explicitly selected by admin
- Opt-in flag is set in their profile
- Contribution score above the instance’s threshold
- They accept the instance’s content terms
- Their viewing behavior is not flagged for abuse
Operators can customize:
- Lower trust requirement for closed/private instances
- Raise it for public instances
- Require admin approval for each user
- Require multi-factor identity binding
- Restrict access to specific tags, studios, or performers
- Restrict access by geographic region, time window, or device class
2.4 What Low-Trust Users See
- Full metadata: performers, studios, tags, dates, resolutions, sources, reviews, ratings, Elo rank
- Snapshot collage (12–24 evenly spaced frames)
- Hover-scrubbable storyboard
- Optional short silent previews
- Scene identification tools
- All curation tools that don’t require watching content
This means a user can fully curate without ever watching the content — the collage is enough to identify, match, merge, and tag.
3. Metadata Curation Engine
3.1 Federated Metadata Curation
- Every instance maintains its own metadata store but syncs changes to peers.
- Metadata changes are signed by the originating user’s reputation key, then by the instance.
- Peers apply changes based on trust rules:
- Changes from high-trust users on trusted peers apply immediately.
- Changes from new users or untrusted peers enter a quorum queue.
- Quorum rules are per-instance: e.g., “3 trusted peers must confirm.”
- Conflicts resolve via:
- Recency + trust weight
- Community vote
- Steward arbitration
- Fork (if two versions of truth are needed, both are kept and shown with divergence markers)
3.2 Completion Scores
Every entity — performer, scene, studio, site, tag, review — has a Completion Score:
- Missing metadata fields
- Snapshot coverage
- Performer/studio links
- Tag coverage
- Source links
- Review coverage
- Duplicate confidence
- Preservation status (how many replicas exist)
Completion feeds directly into curation quests.
3.3 Curation Quests & Bounties
- Local quests — set by the instance operator or vanguard subset.
- Federated quests — set by any peer, opt-in for others.
- Bounties — rare performers, lost studios, obscure scenes, corrupted metadata.
- Preservation quests — “Scene X has only 1 replica. Help it reach 3.”
- Rewards: XP, reputation, badges, gravity influence, storage allocation boosts, vanguard progress.
3.4 Duplicate Detection & Merging
- Perceptual hashing across video frames
- Audio fingerprinting (optional, for verification)
- Metadata similarity scoring
- Community voting with trust-weighted votes
- Multi-user confirmation for merges
- Merge history preserved for audit
3.5 Identification Board — “Which Was That…?”
A dedicated community board for finding half-remembered actors, scenes, studios, sites, or tags.
- Users post queries with descriptions, collages, snapshots, quotes, or context.
- Community suggests matches, votes on candidates, links solved queries to metadata.
- Solved identifications become canonical links and improve search + recommendations.
- Gamification: Detective reputation, solve streaks, badges, bounties for hard cases.
- Federated across instances: a query on one instance can be broadcast to peers with matching taste profiles.
4. Content Preservation & Storage
4.1 Preservation Policy (Default Configuration)
- Default: every scene must have at least 3 replicas on distinct instances.
- Operators configure:
- Minimum replicas (default 3)
- Maximum replicas the instance will host
- Which tags/studios/performers to opt out of
- Preferred peers for replication
- Storage budget (GB/TB)
- Bandwidth budget
- Retention rules (indefinite by default)
- Per-scene overrides always take precedence over instance defaults.
4.2 Auto-Archiving by Cross-Instance Enjoyment
A key rule: instances auto-archive content enjoyed by users across a minimum number of instances.
- “Enjoyed” is measured by:
- Opt-in viewing sessions above a threshold
- High review scores from vanguards and high-trust users
- Elo rankings above a percentile
- Curation activity intensity
- Repeated requests from peer instances
- The default threshold: content that hits enjoyment signals on ≥ 2 instances becomes eligible for auto-archiving by any peer with capacity and matching taste gravity.
- Instances can raise or lower the threshold, or exclude specific tags.
- Auto-archived content is replicated, verified, and manifest-registered — never silently mutated.
4.3 Storage Allocation Algorithm
When an instance has free storage, it fills that storage with content that its users — especially vanguards and high-trust users — would enjoy most.
- Scoring inputs:
- Instance taste vector
- Vanguard taste vectors (weighted higher)
- High-trust user taste vectors (weighted medium)
- General user taste vector (weighted low)
- Peer instance demand signals
- Preservation urgency (rare content, endangered replicas)
- Curation completion score (more complete metadata preferred)
- Content is scored, ranked, and downloaded in order until storage is full.
- The instance maintains a storage allocation log so operators can audit and tune.
- Vanguards and high-trust users can submit allocation preferences (“I want more of X”), which enter the scoring.
4.4 Health, Repair, and Verification
- Every replica has a manifest hash and content hash.
- Peers periodically verify each other’s replicas via random challenge.
- Failed verification triggers automatic re-download from a healthy peer.
- If all replicas of a scene disappear, the mesh raises a preservation alert and boosts it to the top of every matching instance’s allocation queue.
- Metadata is always replicated mesh-wide; content replication follows per-instance policy.
4.5 Deanonymized Metadata Sync Over Onion Routing
- Metadata database snapshots sync periodically between peers.
- Sync runs over onion routing (Tor, I2P, or a mesh-specific onion protocol) so peers never learn each other’s IP addresses.
- Instances exchange only:
- Signed metadata records
- Snapshot collage hashes
- Reputation attestations
- Peer capability/taste profiles
- Full content never moves over onion routing — it moves over the P2P layer (Section 5).
- Sync cadence: configurable (default: hourly diffs, daily full reconciliation).
- Instances can be air-gapped and sync via manual export/import bundles.
4.6 Federated Metadata Store
- Every instance keeps a local copy of all metadata it cares about (based on peering and gravity).
- Metadata is signed, versioned, and addressable by content ID.
- Forking is allowed: if two instances disagree on a record, both versions coexist with a divergence marker.
- Users can see which instances hold which versions.
- Resolution happens via trust-weighted voting, steward arbitration, or permanent fork.
5. Peer-to-Peer Content Layer
5.1 Full P2P Protocols Supported
For users who want to share their own library, non-copyrighted content, or participate in swarm distribution:
- BitTorrent / WebTorrent — default for large media
- DHT (Mainline + custom Stash Box DHT for metadata indexing)
- eDonkey2000 / Kad (eMule-style) — for legacy and long-tail content
- IPFS — optional, for content-addressed storage
- Custom Stash Box swarm protocol — optimized for collage/snapshot fragments
Instances can enable any combination; the mesh abstracts them behind a common API.
5.2 Local-First Mode
Users who want to use the site locally can run a personal Stash Box node:
- Full metadata database
- Local content library
- P2P sharing of their own or non-copyrighted content
- Optional federation with public instances
- Full discovery, curation, and ranking features
Personal nodes can contribute storage to the mesh in exchange for reputation.
5.3 Content Sharing Rules (Instance-Level)
- Each instance defines which content it will seed, leech, or ignore.
- Content shared over P2P is tagged with:
- Source instance
- Original uploader (if public)
- Preservation status
- Manifest hash
- Swarm health is tracked by the mesh. Under-seeded content gets boosted.
- Instances can opt out of seeding specific tags, studios, or performers.
- Vanguards and high-trust users can nominate content for swarm boosting.
5.4 Anonymity Options
Users can choose their anonymity level:
- Fully anonymous — onion-routed metadata, DHT-only content, no instance account
- Pseudonymous — instance account with signed reputation key
- Open — public profile, public library sharing
Default for new users: pseudonymous, onion-routed metadata, no content sharing until opt-in.
6. Discovery & Recommendation Engine
6.1 First-Class Discovery
Discovery is the default homepage experience. Search is secondary.
- Home feed: personalized recommendations, mesh trending, instance spotlight, new curation quests, identification board highlights, awards updates.
- Gravity slider: users can shift between “instance theme” and “personal taste” and “mesh-wide.”
- Entity pages: every performer, scene, studio, site, tag, list, and instance has:
- Similar entities
- “Users like you also liked”
- “Appears in”
- “Curated by”
- “Preservation status”
- “Peers hosting this”
- Recommendation API: developers can build custom discovery experiences.
6.2 Cross-Instance Discovery
- Search one instance → optionally broadcast to the mesh.
- Results ranked by: local gravity × peer similarity × personal taste × trust weight.
- Federated trending: what’s rising across peers with similar taste vectors.
- Federated curation quests: join campaigns on peer instances.
6.3 Elo Ranking System
- Glicko-2 or TrueSkill for performers, scenes, studios, sites, tags, lists, instances.
- Pairwise voting UI: two entities side by side, one click, next matchup.
- Weighted by voter trust, vanguard status, and contribution score.
- Time decay for current relevance.
- Personal Elo: each user’s votes create a taste fingerprint.
- Instance Elo: each instance has a taste vector shaped by its community.
- Federated Elo: local, peer-mesh, and global leaderboards.
- Gamified voting: streaks, badges, Taste Maker reputation, daily matchups, weekly tournaments, bracket challenges.
- Annual Stash Box Awards: community votes + Elo + reviews determine the year’s best.
6.4 Directory & Reviews
- Site & Network Profiles: URL, description, categories, pricing, payment methods, features, pros/cons, alternatives.
- Studio Profiles: History, owned sites, performer roster, notable scenes, completion score.
- Performer Profiles: Bio, aliases, scene credits, official links, Elo rank, reviews.
- User Reviews & Ratings: structured, with verified usage flags.
- Verified Badges: studios and performers can claim and confirm profiles.
- Search & Filters: niche, price, rating, features, payment methods.
- User Lists: “Best VR Sites 2026,” “Top 10 Indie Studios,” “Most Underrated Performers.”
- SEO Engine: public pages for every site, performer, studio, scene, and tag.
7. Ecosystem & Integrations
7.1 Stash App Integration
- Two-way sync: pull metadata, push edits, see rankings, launch playback.
- Direct contribution to preservation from within Stash.
- Collage generation triggered from Stash library scans.
7.2 Public API
- GraphQL and REST
- SDKs: Python, JavaScript/TypeScript, Go, Rust
- Webhooks for real-time metadata, preservation, and ranking events
- Federation API for instance-to-instance sync
7.3 Browser Extension
- Overlay Stash Box scores, reviews, and preservation status on any adult site
- One-click “Add to Stash Box”
- Vote on Elo matchups without leaving the page
- Contribute snapshots from any video player
7.4 Mobile App
- Elo voting
- Curation quests
- Review writing
- Identification board
- Notifications (preservation alerts, awards, peer requests)
- Local node management (for advanced users)
7.5 Developer Sandbox
- Public test instance with sample data
- Federation simulator for testing peer interactions
- API playground with real queries
- Reputation and trust emulation tools
8. Gamification & Community
- XP, levels, badges, streaks for every contribution.
- Leaderboards: top curators, voters, reviewers, identifiers, preservationists — local, mesh, global.
- Guilds: niche or studio-specific teams with shared goals.
- Adopt a Site/Performer: dedicated users become primary curators.
- Mentorship: experienced editors guide new contributors.
- Public roadmap: community votes on features.
- Annual awards: a major event celebrating the community.
- Preservation badges: for hosting replicas, seeding rare content, keeping the mesh alive.
- Vanguard recognition: a distinct tier with visible influence.
9. Governance & Operator Controls
Each instance operator controls:
- Instance theme and gravity
- Trust thresholds for content access
- Vanguard thresholds (or manual appointment)
- Replication policy (min replicas, opt-outs, preferred peers, budgets)
- Federation agreements (which peers, which taste profiles)
- Content access rules and opt-in requirements
- Local moderation and curation priorities
- Metadata fork resolution policy
- P2P protocol enablement
- Anonymity requirements
- Storage allocation tuning
High-trust subsets can be delegated gravity tuning and policy input.
Users can:
- Join multiple instances
- Carry portable reputation and taste fingerprints
- Export their contribution history
- Run their own node and federate optionally
10. The Flywheel
More discovery → more users → more curation → better metadata → better recommendations → more trust → more content access → more preservation → more availability → more discovery.
The federated mesh makes the archive resilient, personalized, and alive. Every instance contributes to the whole. Every user helps complete the archive. Every vote, edit, review, identification, replica, and seeded swarm strengthens the mesh.
11. MVP Roadmap
- Phase 1: Single-instance portal + snapshot collages + Elo voting + identification board + trust levels.
- Phase 2: Opt-in content access + vanguard role + curation quests + completion scores + gamification.
- Phase 3: Directory + reviews + Stash app integration + public API + browser extension.
- Phase 4: Federation protocol + onion-routed metadata sync + taste-based peering + preservation replication.
- Phase 5: P2P content layer (DHT, BitTorrent, eDonkey, IPFS) + local-first mode + storage allocation engine.
- Phase 6: Mobile app + annual awards + advanced recommendation engine + mesh-wide curation campaigns.
12. Summary
Stash Box is a federated mesh of instances where:
- Metadata is curated by the community and synced anonymously over onion routing.
- Content is opt-in, role-gated, and preserved automatically by policy.
- Discovery is first-class: recommendations for everything, gravity-tuned per instance.
- Vanguards and high-trust users shape instance taste and content access.
- Storage fills itself with what users would enjoy most.
- Full P2P (DHT, BitTorrent, eDonkey, IPFS) powers content sharing and swarm health.
- Local-first users can run their own nodes and federate optionally.
- Gamification maximizes content completion and curation completion.
- Elo, directory, reviews, identification board, Stash integration, API, browser extension, mobile app, and annual awards round out the ecosystem.
The result is an open, resilient, community-owned archive and discovery engine — built by the community, preserved by the mesh, and personalized for every taste.