Consumer Messaging Platform — WhatsApp-Class System  ·  View 15 of 23

Status and Stories Pipeline

Ephemeral posts with an audience resolved at publish time, encrypted per post, and hard-deleted at 24 hours.

Editable source SVG draw.io All views
Create
Create
Text, Photo or Video Composer
Text, Photo or Video Composer
Audience rule
Contacts except, only share
Audience rule...
Protect
Protect
Random Status Key
AES-256 per post
Random Status Key...
Encrypted Status Blob
Encrypted Status Blob
Publish
Publish
Status Service
Status Service
Status Blob Store
Hard TTL 24 h
Status Blob Store...
Audience Roster
Resolved at publish
Audience Roster...
Distribute
Distribute
Fanout to Allowed Viewers
Key copy per device
Fanout to Allowed Viewers...
CDN Edge
Pre-warmed on publish
CDN Edge...
Consume
Consume
Viewer Device
Decrypt and render
Viewer Device...
View Receipt
If read receipts on
View Receipt...
Expire
Expire
TTL Reaper
Hard delete at 24 h
TTL Reaper...
Viewer List
Purged with the post
Viewer List...
audience snapshot
audience snapshot
Status and Stories Pipeline
Status and Stories Pipeline
Application we own
Application we own
Decision point
Decision point
Security / platform
Security / platform
Data store
Data store
Interface / broker
Interface / broker
synchronous
synchronous
Expiry is enforced server side and on device; a viewer who never opened it loses access at 24 h.
Expiry is enforced server side and on device; a viewer who never opened it loses access at 24 h.
v 1.0 · owner Platform Architecture · date 2026-08
v 1.0 · owner Platform Architecture · date 2026-08
Text is not SVG - cannot display

Audience

  • The audience rule is evaluated once at publish and frozen as a roster
  • A contact added later does not retroactively gain access to an existing post
  • Key copies are distributed per viewer device, using the same session machinery as chat

Expiry

  • A hard 24-hour TTL enforced by a reaper server side and by the client independently
  • Viewer lists are purged with the post rather than retained as analytics
  • An unopened status expires exactly like an opened one

Cost control

  • Blobs are pre-warmed to the CDN at publish so a popular post is served from the edge
  • One blob per post regardless of audience size — only key copies scale with viewers
  • View receipts are optional and follow the same reciprocity rule as read receipts