How We Added a Public Leaderboard and SMS to a Live Product

At a glanceHow We Added a Public Leaderboard and SMS to a Live Product
  1. 11. The task
  2. 22. Step-by-step process
  3. 33. Critical decision-making

We already had a free athlete brand audit live at theathletespotlight.com/audit. In one working session we turned it into a growth engine: a shareable score badge, a public leaderboard by sport and level, and SMS follow-up for a generation that doesn’t open email. This is the honest write-up of how — the companion to how we built the audit.

1. The task

Young athletes share everything and live on their phones. So three asks: (1) after the audit, give them a score badge they can post — the more that share, the more athletes show up; (2) a leaderboard they can climb, filterable by sport (basketball vs soccer vs track) and level (high school vs college vs pro); (3) text them their tips, because email is where messages to 18-year-olds go to die. All of it opt-in, and safe for minors.

2. Step-by-step process

  • Wrote the spec first (privacy up front). Before code: opt-in only, a 13+ gate,

public display limited to first name + last initial, and a clean opt-out. Getting the rules down before the routes meant the build couldn’t quietly leak PII.

  • Extended the audit, didn’t fork it. Added a level field at intake and a single

opt-in checkbox at the email step. One new index entry per opted-in athlete.

  • Built three routes. A JSON leaderboard endpoint (filter + rank), a public

leaderboard page (sport/level filters, live), and a per-athlete score page with Open Graph + Twitter cards so it looks like a real badge when shared to Instagram or X.

  • Adversarial privacy pass. A reviewer specifically hunted for any path where an

email, phone, or full last name could reach a public page, and whether opt-out truly removed the entry. It did.

  • Wired SMS. Captured phone + explicit consent (with STOP language) at unlock, and

built the Twilio send so the first personalized text goes out the moment consent is given — dormant until the keys are set, so nothing breaks before it’s turned on.

  • Shipped it live. Deployed, granted the one missing database permission the new

query needed, seeded a real athlete, and screenshotted the badge and the board.

3. Critical decision-making

  • Privacy as a feature, not a footnote. For minors especially, “first name + last

initial” and a hard 13+ gate aren’t friction — they’re what lets us publish at all. We enforce it on the server, so a tampered request can’t opt someone in.

  • Opt-out has to actually delete. A leaderboard that keeps you after you leave is a

liability. Un-checking the box removes both the public entry and its lookup pointer.

  • Don’t block the audit to send a text. The SMS send is best-effort and gated by

keys; if Twilio is down or unconfigured, the athlete still gets their full report.

  • Make the share do the marketing. The score page carries social cards, so every

athlete who posts their badge is a free, on-brand ad that pulls in the next one.

4. Effort and cost comparison

Agent (this session) A human team
Elapsed time ~2 hours on top of the existing audit 1–2 weeks
People 1 (as product manager) backend + frontend + a privacy review
New per-athlete cost ~$0 (a tiny database write) n/a
Privacy review built into the build often an afterthought

5. What the agent can and cannot do

  • Did autonomously: the spec, all three routes, the intake + opt-in changes, the

adversarial privacy pass, the deploy, the database permission fix, and live QA.

  • Needed a human: the Twilio account + carrier (10DLC) registration, and the Meta

pixel ID — real-world accounts only a person can stand up.

  • Wouldn’t do: publish anyone under 13, or expose contact info on a public page.

6. Information ingestion inventory

  • The live audit codebase (endpoints, the single-table data model, the widget).
  • Today’s strategy call, where the leaderboard-and-SMS idea came up.
  • Public guidance on youth-data care (a 13+ gate, minimize what’s shown for minors).

7. Guidelines compliance scorecard

  • Title under 60 chars: yes. Meta description under 160: yes.
  • Hook = a specific, real situation (a live product, a real next step): yes.
  • Figurehead voice, active voice, short paragraphs, H2 structure: yes.
  • No AI fluff: checked.
  • 2–3 internal BlitzMetrics links: the audit article, Dollar a Day, and the Spotlight

Network — to add inline at publish.

8. What’s next

Turn on the SMS keys and the Meta pixel; seed the leaderboard with the real roster; and ship the Friday “MAA” — a weekly re-score that shows each athlete what moved and what to do next. The badge is the flywheel; the leaderboard is the scoreboard; the text is how we actually reach them.

By Dennis Yu · 2026-08-09

Originally published .

Dennis Yu
Dennis Yu
Dennis Yu is the CEO of Local Service Spotlight, a platform that amplifies the reputations of contractors and local service businesses using the Content Factory process. He is a former search engine engineer who has spent a billion dollars on Google and Facebook ads for Nike, Quiznos, Ashley Furniture, Red Bull, State Farm, and other brands. Dennis has achieved 25% of his goal of creating a million digital marketing jobs by partnering with universities, professional organizations, and agencies. Through Local Service Spotlight, he teaches the Dollar a Day strategy and Content Factory training to help local service businesses enhance their existing local reputation and make the phone ring. Dennis coaches young adult agency owners serving plumbers, AC technicians, landscapers, roofers, electricians, and believes there should be a standard in measuring local marketing efforts, much like doctors and plumbers must be certified. He has appeared on 353 podcasts with 619 credited episodes — see the full list of his podcast appearances.