We Had 5 Million Users and Could Not Name One of Them: Adding Authentication to a Frictionless Product
Most passwordless stories are about taking a login away. SnapCorn's is about putting one in.
Before August 2024, SnapCorn had no accounts at all. You landed on the site, dropped in a photo, got the background removed in a couple of seconds, downloaded it, and left. No signup, no email, no friction — which is exactly why five million people a month used it, and exactly why we knew nothing about any of them. Not one name. Not one email address. No way to tell a designer who processed fifty images a week from someone who restored a single photo of their grandmother and never came back.
Adding authentication to a product whose entire appeal is that it does not ask you for anything is a genuinely risky move. Ask too early and you have replaced your best feature with a wall. This is how SnapCorn's growth team did it: what our earlier attempt got wrong, why the timing of the prompt turned out to matter more than which login methods we shipped, and what 1.5 million accounts actually bought us.
Key Takeaways
- The trigger moment did more work than the method. SnapCorn prompts for sign-in after a user's third processed image, not on arrival. That progressive placement converted 3x better than the immediate login wall we had tried before, using authentication methods that were not meaningfully different.
- Our earlier signup did not fail because of passwords alone. It failed because it was positioned as a toll gate before any value had been delivered. Removing password friction was necessary; moving the ask was what changed the number.
- Google One Tap outconverted a Google Sign-In button by 40% for a boring reason: fewer clicks. One Tap resolves in under a second with no account chooser and no consent screen for returning users. 75% of SnapCorn's authenticated users ended up on Google or Apple.
- Read the 30% carefully. SnapCorn's 1.5 million registered users are a cumulative total; the 5 million is a monthly visitor count. That ratio is a useful directional figure and is not a cohort conversion rate. The section below spells out all three places our headline numbers change denominators.
- The revenue lift came from what authentication enabled, not from authentication. Free-to-paid conversion rose 40% because we could finally see who was a power user, remember their work, reach them by email, and sync across devices. The login was the prerequisite, not the product.
Five Million Users We Could Not Name
SnapCorn's anonymous-by-default design was a real advantage and a real ceiling at the same time, and the ceiling is easier to describe than the advantage.
The product is a set of AI image tools — single-click background removal, upscaling to 16x, colourisation of black-and-white photos, damage repair, batch processing, and an API. The business model is freemium: core editing free, premium for higher-resolution exports, batch jobs, and the heavier models. Our users are e-commerce sellers shooting product photos, social creators, marketing teams, designers, and a long tail of people restoring family pictures.
Five million of them a month, and this is what we could not do:
- Tell power users from passers-by. Someone processing fifty images a week and someone processing one looked identical in our analytics. We were optimising a funnel we could only see the top of.
- Run a real experiment. Without stable identities, an onboarding A/B test measures sessions, not people. The same user across three devices is three data points pointing in different directions.
- Reach anyone, ever. A user who arrived from a Google search, solved their problem, and left had no relationship with us. No email, no notification, no saved work. Every visit was a first visit.
- Remember anything. No saved preferences, no processing history, no recommendations. A returning power user got the identical generic interface as a first-timer, forever.
- Measure lifetime value. With no way to link sessions, "lifetime" was undefined. We could see revenue and we could see traffic and we could not connect them.
- Know who our customers were. Beyond IP addresses and session cookies we had nothing: no verified emails, no segment signals, nothing to build an ideal customer profile from or to prioritise the roadmap against.
Written out like that, it reads like six problems. It is one problem six times: without a durable identity, every other growth mechanism a freemium business runs on is unavailable. Personalisation, retention, lifecycle email, upgrade targeting, and cohort analysis all take the same input, and we were not producing it.
Our Earlier Signup Failed, and the Password Was Not the Whole Reason
SnapCorn had tried registration before, with email and password, and it went badly enough that "users just do not want accounts" became received wisdom internally. That conclusion was wrong, and getting it wrong cost us time.
The mechanics of the failure were ordinary. Consumer users did not want yet another account for an image tool. The password requirements added a decision to a flow that had never had one. Email verification meant leaving our product, opening a mail client, and coming back — a round trip that a meaningful share of people simply never completed. Forgotten-password loops caught the ones who did return later. Every one of those is a real friction cost, and passwordless authentication addresses all of them.
But the deeper problem was where we put the ask. The signup sat at the front. A user arrived wanting a background removed, and the first thing SnapCorn did was present a form. At that moment we had delivered exactly nothing, so the form was not a step in a transaction — it was a toll on an unproven promise.
The reframe that unlocked the project was thinking of a login prompt as a bill. Users pay it in attention and in mild suspicion. Whether they pay depends almost entirely on what you have already given them. Present the bill before the meal and people walk out; present it after and most people pay without noticing. Nothing about the bill itself changed.
That is why "remove the password" was necessary but not sufficient. Passwordless made the bill smaller. Moving it later made people willing to pay it.
The Question Was When to Ask, Not What to Ask For
SnapCorn's central design decision was progressive authentication: prompting for sign-in at behaviourally chosen moments rather than at the door.
Progressive authentication is an approach in which a product defers the sign-in request until a user has taken actions indicating engagement or is about to receive something that authentication genuinely improves, rather than requiring it before the first interaction. The prompt is triggered by user behaviour, not by page load.
For SnapCorn the triggers are:
- After the third processed image. By this point the user has had the product work for them three times. The prompt is framed as saving their history, not as registering.
- Before a high-resolution export. Authentication here is the mechanism for the thing they are already trying to do, so it reads as a step rather than an interruption.
- On reaching a premium feature. The account is a prerequisite for the upgrade path, and the value proposition is already on screen.
Progressive placement converted roughly 3x better than the immediate login wall we had run previously. Same product, comparable methods, different moment.
The generalisation we would defend: for a freemium product, the conversion rate of a sign-in prompt is mostly a function of accumulated delivered value at the instant it fires, and only secondarily a function of how cheap the prompt is to complete. Teams spend their effort on the second variable because it is the one an SDK can change. The first one is free and is worth more.
The corollary is uncomfortable and we think it is true anyway: if your signup converts badly, adding social login will improve it and will not fix it. You are treating the size of the ask when the problem is its position.
The Funnel, Step by Step
SnapCorn's cascade from anonymous traffic to paying users runs through four stages, and each one is measured against a different base — which is why the chart below labels them individually rather than drawing one clean funnel.
The stage that surprised us most was the third. 280,000 monthly active users against 1.5 million registered is an 18.7% monthly return rate, and internally that felt low until we compared it to the thing it replaced. The anonymous baseline was not a lower return rate — it was no measurable return rate at all, because a returning anonymous visitor is indistinguishable from a new one. Authenticated users came back roughly 3x as often as anonymous sessions suggested users were coming back. Some of that gap is genuine retention improvement and some of it is simply that we could finally see it. We do not claim to know the split.
One Tap Beat the Google Button by 40%, for a Boring Reason
SnapCorn deployed three authentication methods — Google One Tap, Google Sign-In, and Apple Sign-In — and One Tap converted about 40% higher than the standard Google Sign-In button. The explanation is not sophisticated.
Google One Tap is a credential prompt that surfaces automatically in context, showing the account the user is already signed into on that browser and completing authentication in a single click, with no typing, no account chooser, and no separate consent screen for a returning user (Google Identity Services documentation). Google Sign-In, as a button, starts a flow: click, then choose an account, then approve. Both are OAuth 2.0 underneath. They differ in how many decisions they place in front of the user.
75% of SnapCorn's authenticated users ended up on Google or Apple. That concentration is worth planning around rather than resisting: those credentials already exist, are already trusted by the user, and carry a verified email address that we would otherwise have had to ask for and then verify ourselves. Sign in with Apple in particular mattered because 60% of SnapCorn's traffic is mobile, and both One Tap and Apple's flow are built for that context in a way that a desktop-shaped form is not.
One caution on this comparison: it measures returning users well and new-device users less well. One Tap's advantage depends on an existing browser session with Google. Its measured lead over the button is real for our traffic mix and would narrow for an audience with different browser habits.
Two Weeks, and Where the Time Actually Went
SnapCorn went from kickoff to 100% of traffic in fourteen days in August 2024. The schedule below is the day-range reading of our project record, and it is worth noting that the largest block was not integration.
Backend work on days 3 to 5 was SDK integration into our Node.js and Express services, OAuth callback handlers, JWT validation middleware, webhook endpoints for user event streaming, and the profile merging logic described in the next section. Frontend on days 6 to 8 was the One Tap modal, social buttons styled to match the product, React state management for the authenticated session, and the behavioural triggers.
Days 9 to 11 went to testing, and that allocation was correct. The matrix was devices and browsers, OAuth flows under failure conditions, session continuity, the data merging logic, load behaviour on the authentication endpoints, and consent handling under the EU General Data Protection Regulation alongside cookie consent flows — relevant here because social logins pull profile data, so the lawful basis for processing it has to be established at the moment of sign-in rather than retrofitted. Our authentication touches every user on every visit; a bug there is not a degraded feature, it is a broken front door.
The soft launch on day 12 went to 10% of traffic. Two days of real production data at a survivable blast radius produced a handful of small UX adjustments and, more usefully, the confidence to take the remaining 90% without ceremony.
Stitching Anonymous Sessions Onto Real Accounts
SnapCorn's hardest engineering problem in this project was not authentication. It was making sure a user's history did not begin at the moment they signed in.
Identity stitching is the practice of linking the events a user generated while anonymous to the account they later create, so that analytics, personalisation, and attribution reflect the user's whole journey rather than starting at the sign-in event. Without it, every authenticated user appears in your data to have arrived, converted, and had no prior behaviour.
The consequences of skipping it are worse than they sound. Your conversion paths all look one step long. Your attribution credits the wrong channel, because the anonymous session that came from search gets separated from the account that signed in later. Cohort analysis is impossible before the sign-in date. And your product decisions get made on a dataset that systematically hides everything users did before they trusted you — which, for a value-first product like SnapCorn, is most of what they did.
Concretely, our merge does three things. Prior processing history follows the user into the account, which is both an analytics requirement and the actual promise the sign-in prompt makes. The anonymous identifier and the authenticated identifier are stitched in our analytics layer, so pre-login events attach to the resulting profile. And session continuity holds across the sign-in itself, so the user is not interrupted mid-task.
Sequencing this early is what we would repeat. The merging logic went in on days 3 to 5, alongside the SDK rather than after it, and that was deliberate: retrofitting identity stitching means either backfilling data you may no longer be able to reconstruct or accepting a permanent gap in your history at the exact moment your product changed.
What Authentication Bought Us That Was Not a Login
SnapCorn's free-to-paid conversion rose 40% after launch, and the login itself did none of that work. It was the prerequisite for six mechanisms that did.
A reachable audience. 1.5 million opted-in email addresses, where previously the number was zero. Not a marketing detail — it is the difference between a business that can talk to its users and one that can only wait for them.
Upgrade prompts aimed at someone. We can now identify a user who has hit an export limit three times this week and show them a relevant upgrade path, instead of showing everyone the same banner.
Saved work as a returning reason. Processing history gives users something to come back for that is not a new task. It is also the honest justification for the sign-in prompt, which matters: the ask converts because it is true.
Cross-device continuity. Start on a phone, finish on a desktop. With 60% mobile traffic and desktop as the place heavier edits happen, that hand-off was a real workflow that anonymous sessions could not support.
Cohort analysis that means something. We can segment by authentication method, signup date, and usage pattern, and follow those cohorts over time. Every retention and monetisation question we ask now has a population to ask it about.
A definition of a customer. Verified emails and profile data from social logins gave us the demographic and behavioural signal to build actual customer profiles, which is what prioritises a roadmap.
If we were arguing this project internally again, we would not lead with the conversion number. We would lead with the observation that a freemium business without identity has no growth loop available to it — every retention, lifecycle, and monetisation tactic in the standard playbook takes a known user as its input. We were not underperforming on those tactics. We could not run them.
Reading a 30% Activation Rate Honestly
SnapCorn's headline figures change their denominator three times, and anyone benchmarking their own product against them should know exactly where.
The 30% divides a cumulative total by a monthly count. 1.5 million registered users accumulated from the August 2024 launch onward. 5 million is monthly anonymous visitors. Dividing one into the other gives a directionally useful sense of scale and is not a cohort activation rate. A real one would follow a defined group of first-time visitors over a defined window and report what share of that group registered. We are reporting the ratio because it is the figure we have, labelled as what it is.
The 40% free-to-paid lift is relative, on a base we are not publishing. A move from 1.0% to 1.4% and a move from 5.0% to 7.0% are both "+40%". They are extremely different businesses. Treat this as evidence of direction and magnitude of change, not as something you can compute revenue from.
The two 40% figures are unrelated. One is the free-to-paid conversion lift after launch. The other is One Tap's conversion advantage over the Google Sign-In button. Different experiments, different populations, coincidentally the same number, and we have seen them merged in summaries of this work.
The two 3x figures are also unrelated. One is progressive authentication converting about 3x better than an immediate login wall. The other is authenticated users returning about 3x more often than anonymous sessions indicated. Again: same multiplier, separate measurements.
18.7% is the number we actually watch. Monthly active users against registered users is the only one of these with a stable, honest denominator, and it is the one that gets harder over time, because the denominator only grows. A registered-user count is a vanity number that cannot go down. The ratio can.
All figures in this post are SnapCorn first-party data: product analytics, Mixpanel behavioural tracking, Segment profile unification, and our own authentication analytics, from the August 2024 launch onward. Where a figure is a relative change, it is labelled as one. Where a ratio spans two different bases, the bases are named.
The Roadmap Is a List of Things Authentication Made Possible
SnapCorn's forward plan reads oddly for an authentication write-up, because most of it is not authentication. These were the priorities set coming out of the launch, stated as intent at that time rather than as shipped features.
Two items are genuinely about coverage. Facebook login addresses users who default to Meta credentials, and WhatsApp login targets India, Southeast Asia, and Latin America, where WhatsApp is the messaging default rather than one app among several. Both extend reach into audiences that Google and Apple do not cover evenly. Face ID and Touch ID for returning iOS users belong in the same category: fewer interactions, again.
Everything else on the list is a capability that requires knowing who someone is. Machine-learning conversion scoring that predicts upgrade likelihood from authentication method, usage pattern, and profile data. A processing history dashboard showing users the cumulative value they have received. Cross-platform sync as a first-class feature. Personalised model recommendations based on the kinds of images a user actually works with. A referral programme built on the social graph the login already gives us. Further out, team workspaces, developer API keys, and a marketplace for specialised AI models — none of which can exist without accounts, payment identity, and licence management.
That is the shape of the argument for doing this at all. Authentication is rarely worth building for its own sake. It is worth building because roughly half a product roadmap turns out to be blocked behind it, and that half stays invisible until you look.
Frequently Asked Questions
When should a freemium product ask users to sign in?
SnapCorn's answer is: after the product has demonstrably worked for the user at least once, and ideally at a moment where authentication is the mechanism for something they are already trying to do. Our triggers are the third processed image, the point of a high-resolution export, and arrival at a premium feature. Placing the prompt this way converted roughly 3x better than the immediate login wall SnapCorn had tried previously, using comparable methods. The prompt's conversion rate is mostly a function of value already delivered when it fires.
What is progressive authentication?
Progressive authentication defers the sign-in request until a user has taken actions that indicate engagement, or until they are about to receive something authentication genuinely improves, instead of requiring an account before the first interaction. The trigger is user behaviour rather than page load. SnapCorn uses three triggers: after the third processed image, before a high-resolution export, and on reaching a premium feature. The approach lets a no-signup-required product stay no-signup-required for anyone who only wants one thing from it.
Does adding a login reduce usage of a no-signup product?
Not in SnapCorn's case, because we did not make authentication a condition of use. Anonymous users can still process images without an account; the prompt appears at behavioural triggers and is dismissible. 1.5 million users registered while the free anonymous path stayed open. The risk of adding a login is real, but it comes from gating access, not from offering an account — and those are separable decisions that get conflated routinely.
Why does Google One Tap convert better than a Google Sign-In button?
Google One Tap converted about 40% higher than the Google Sign-In button at SnapCorn because it requires one interaction rather than three. One Tap surfaces contextually, shows the account the user is already signed into in that browser, and completes in under a second with no account chooser and no separate consent step for returning users. The Sign-In button starts a flow: press, choose an account, approve. Both are OAuth 2.0 underneath; the difference is entirely in how many decisions sit in front of the user. The advantage depends on an existing browser session with Google and would narrow for audiences without one.
How do you keep analytics intact when anonymous users sign in?
SnapCorn merges anonymous session data onto the authenticated profile at the moment of sign-in, a practice usually called identity stitching. Prior processing history follows the user into the account, the anonymous and authenticated identifiers are linked in the analytics layer so pre-login events attach to the resulting profile, and the session continues uninterrupted through the sign-in. Without this, every authenticated user appears to have arrived and converted with no prior behaviour, which breaks attribution and makes cohort analysis impossible before the signup date. SnapCorn built the merging logic alongside the SDK on days 3 to 5 rather than afterwards, because retrofitting it means either backfilling data you may not be able to reconstruct or accepting a permanent gap.
What does a 30% anonymous-to-authenticated conversion rate actually mean?
SnapCorn's 30% divides 1.5 million cumulative registered users by 5 million monthly anonymous visitors, so it is a directional ratio rather than a cohort activation rate. A cohort rate would follow a defined set of first-time visitors over a defined window and report what share registered. The figure with a stable denominator is 18.7% — 280,000 monthly active users against 1.5 million registered — and that is the one SnapCorn watches, because the registered-user count only grows and therefore the ratio can fall even when the business is healthy.
Conclusion
SnapCorn spent longer than we should have believing that our users did not want accounts. What they did not want was a form standing between them and a background removal, which is a different and much more solvable problem.
The two changes that produced the outcome were both about position rather than substance. We moved the ask from the front door to the third image, and we cut the interactions inside the ask from three to one. The authentication methods were table stakes; every serious provider offers them. The placement decisions were ours, cost nothing to implement, and are where the conversion came from.
If you are running a freemium product with a large anonymous top of funnel, the diagnostic we would suggest is not "how do we make signup easier." It is: at the moment your prompt fires, what has the user already received from you? If the answer is nothing, no amount of reducing friction will fix it, because friction is not what is stopping them. And if you are choosing not to have accounts at all, the honest question is which parts of your roadmap you have quietly ruled out — for us the answer was most of them, and we did not notice until we had identities and saw what became available.
About this post: written by the SnapCorn Growth Team. SnapCorn is an AI image editing platform offering background removal, upscaling to 16x, colourisation, photo restoration, batch processing, and an API, on a freemium model, serving a global user base across web and mobile. Every figure here is SnapCorn first-party data — product analytics, Mixpanel behavioural tracking, Segment profile unification, and authentication analytics — from the August 2024 authentication launch onward. Relative changes are labelled as relative; ratios that span two different measurement bases have those bases named in the text. The fourteen-day schedule is our day-range reading of a project record that labels its first block by week and its remaining blocks by day. Roadmap items describe priorities set coming out of the launch, not shipped features. MojoAuth, the authentication provider we integrated, has published its own account of this engagement using the same figures: see the SnapCorn case study.