Building an Alarm You Can't Swipe Away: Inside Blessy's Design
Why Blessy uses real iOS alarms, detects prayer with the camera without ever recording, ships no accounts, and hides the snooze button — the design decisions, explained.
Every product is a pile of decisions. Most apps hide them; we would rather explain ours, because for an app that wakes you for prayer, how it works is inseparable from whether you can trust it. Here are the five decisions that define Blessy.
1. Real alarms, or nothing
Most "alarm" apps on the App Store are notification apps in costume. A notification can be silenced by Silent mode, swallowed by a Focus, or simply missed — and your one shot at dawn evaporates.
Blessy is built on AlarmKit, the framework Apple introduced in iOS 26 that lets third-party apps schedule actual system alarms — the same machinery as the built-in Clock. They ring through Silent, through Focus, at full presence. This is also why Blessy requires iOS 26: we were unwilling to ship the costume version first and fix it later. An alarm you can't rely on isn't an alarm; it's a suggestion.
2. The dismissal must cost a posture
The snooze spiral is not a willpower failure — it's what happens when the sleepiest version of you is offered a one-tap exit. So Blessy's alarm has no one-tap exit. It ends when the front camera recognizes your joined hands, held in prayer while dawn light climbs the border of the camera card — ten calm seconds by default, and you choose the length per alarm.
Why a posture? Because movement, posture and attention are the three signals that genuinely dissipate sleep grogginess — and because joining your hands is not a neutral gesture. It is the body's oldest way of saying I am here, and I am asking. By the time the light completes, you are upright and you have already prayed your first prayer. The alarm didn't just wake you; it delivered you somewhere.
A one-time calibration learns how you pray — kneeling, sitting, bowed — and mornings when the camera can't work, you can finish the ritual without it. Strictness about waking; flexibility about being human.
3. The camera must be architecturally incapable of betrayal
An alarm that watches you pray had better answer the obvious question beyond doubt. Our answer is architecture, not promises: posture detection runs entirely on-device using Apple's vision frameworks. Frames are analyzed in memory and discarded; nothing is ever recorded, stored or transmitted. Blessy has no servers — there is nowhere an image could go, even by bug or by subpoena.
The same architecture decision covers everything else: no accounts, no passwords, no analytics, no trackers. Your streak backs up, optionally, to your iCloud, unreadable by us. The privacy policy fits on a page because the data doesn't exist.
4. The Word before the world
The most dangerous object in your morning is the phone in your hand the moment the alarm dies — one reflexive swipe and you are in someone else's agenda. So Blessy fills that exact second: the alarm dissolves directly into a verse chosen for the day, one of 365, leaning toward the theme you carry this season — faith, hope, anxiety, gratitude, forgiveness.
You read, you say amen, the streak ticks, and then the phone is a phone again. We can't stop you opening the feed afterward. We can make sure Scripture got there first.
5. Even the sound should believe in the morning
No sirens. The 21 alarm scores are original compositions on warm timbres — felt mallets, low bells, strings, birdsong — tuned deliberately mellow and played to rise gently but insistently. An alarm's job is to be impossible to ignore, not painful to hear. The seam between the alarm and the verse is a single slow crossfade, because the transition from night to prayer deserves better than a hard cut.
Every one of these decisions cost us something — an iOS version floor, a harder onboarding, features we refused to bolt on. We think the trade is right because the product's real job is small and enormous at once: four minutes, at first light, that belong to God before they belong to anyone else. Software should spend itself on that, and then get out of the way.