Locked conversations
Some conversations deserve a door that actually locks. In Kool you can lock a thread, and opening it takes Face ID, Touch ID or your device passcode, whichever your phone uses.
Two design decisions in that sentence are worth pulling out, because both were arguments we had with ourselves.
The lock is per device. Locking a conversation on your phone does not lock it on your tablet. That is deliberate, and it comes from asking what the feature is actually for. This is not encryption and it does not defend against us or against anyone with your account credentials. It defends against the specific, extremely common situation of somebody else holding your unlocked phone: a friend looking at a photo, a child playing a game, someone reading over a shoulder. That threat lives in one device at a time, so the setting does too. A lock that synced everywhere would imply a guarantee about the account that the mechanism does not provide.
Devices with no security set up pass straight through. If a phone has no passcode, no Face ID and no Touch ID, there is nothing to check against, and the honest behaviour is to open the conversation rather than to invent a barrier. The alternative would be a prompt that cannot succeed, which locks someone out of their own messages while providing no protection whatsoever. A security control that cannot be satisfied is not stricter. It is broken.
Biometrics with automatic passcode fallback is the same principle. Face ID fails for ordinary reasons, from sunglasses to a dirty camera to a phone lying face down on a table, and each of those would otherwise turn into "you cannot read your messages today".
The lock also travels with the rest of the app's privacy behaviour rather than standing alone. The screen is covered when the app goes into the background, so a locked thread is not sitting in the app switcher for anyone thumbing through it. The same gate is suppressed while a system share sheet is up, because a share sheet technically backgrounds the app and would otherwise trigger a biometric prompt in the middle of the user's own action, which is exactly the sort of thing that trains people to tap past security prompts without reading them.
What we would say to anybody building a feature like this: be precise, in public, about which threat it addresses. "Locked conversations" sounds like it might mean end-to-end encryption, offline-only storage, or protection from the company. Ours means one thing, it means it reliably, and saying so plainly is worth more than the ambiguity would be.