For Florida law firms
The EstateDraftFL app for iPhone and Android: sign in, matters, send a document, notifications, remote revocation
both lanes · Deterministic — no model call
Current availability
Owner-gatedWaiting on the platform owner: the owner's Expo project, the sign-in allow-list entry estatedraftfl://auth/callback, Apple (and, for Android notifications, Firebase) credentials through Expo's build service, the store submissions, then MOBILE_APP_PUBLISHED=1 on the deployment (mobile/README.md).
- Where it lives
- The app (built from mobile/ by Expo's build service on the owner's account) · /api/mobile/me · /api/mobile/devices · /api/mobile/matters · /api/mobile/sso-join · /api/documents/register · the account's Security page (/dashboard/security → Phones with the EstateDraftFL app)
- What unlocks it
- anyone with an account: a firm's staff (after the platform's second factor) and the matter's own client
Status is evaluated against this deployment's configuration by the capability-status service at build time; the catalogue's facts were last reviewed on the date shown.
Capabilities
- Owner-gatedSign in with the email link (it opens the app) or the firm's single sign-on, then the platform's second factor for a firm's staff — a session comes back as a one-time code only that installation can exchange; the app never creates an account.
- Owner-gatedThe matters the person can open, read as them: the platform's walls and the firm's second factor apply exactly as on the website.
- Owner-gatedPhotograph a document or choose a file and send it to a matter: it waits in the app's private folder (no signal, a closed app) and goes through the platform's document ingress and quarantine like any upload; refused files keep their reason.
- Owner-gatedLocal encryption: the session and everything the app keeps are encrypted with a key held in the phone's secure storage, readable only while the phone is unlocked and never copied to a backup or a new phone.
- Owner-gatedThe screen is covered whenever the app is not the active one, so the app switcher's picture shows nothing of a matter.
- Owner-gatedRemote revocation: the person (from the website), their firm's administrator or the platform revokes a phone; it is asked each time the app opens, wipes everything and signs out. Another person signing in drops the previous person's queue.
- Owner-gatedNotifications, when the person turns them on: one fixed line — You have an update — never a matter, a party or a figure.
Limits
- The app is not yet in the App Store or Google Play: the owner builds and submits it (mobile/README.md); store review is Apple's and Google's.
- Notifications arrive within about ten minutes of the notice (the outbox drain), and need the owner's push credentials.
- The app sends documents and reads the matters list; drafting, review and approvals stay on the website.
- No hardware identifier is used: a reinstalled app is a new device.
What EstateDraftFL refuses
| Reason code | HTTP | What it means |
|---|---|---|
| auth_required | 401 | The app's request carried no valid session. |
| invalid | 400 | A registration field could not be read. |
| forbidden | 403 | Revoking someone else's phone needs their firm's administrator or the platform. |
| unavailable | 503 | A read could not be answered just now. |
Evidence
- mobile/README.md
- mobile/src/core/queue.ts
- mobile/src/core/session.ts
- mobile/src/secure-storage.ts
- mobile/src/session.tsx
- supabase/migrations/20261003230000_phase21_mobile_devices.sql
- src/lib/mobile/api.ts
- src/lib/mobile/push.ts
- src/lib/supabase/bearer.ts
- src/lib/phase21-mobile-routes.test.ts
- src/components/MobileDevicesPanel.tsx
- .github/workflows/mobile.yml
- docs/security/NATIVE-CLIENT-DESIGN.md
Last reviewed 2026-10-03