Most campaigns ask you to watch. This one wrote you into the film.
Business
- Turn a broadcast film into something people share
- Brand-safe output with no human in the loop
User
- One photo, one name — no account, no learning curve
- Leave with something worth keeping
Technical
- Per-visitor server-side video rendering
- Moderation API screening both image and text
Brand asset, stranger's content
Every output is an AT&T film carrying a photo and a surname nobody at AT&T approved.
Arbitrary photos, fixed frames
The composite has to look intentional with whatever comes out of a camera roll.
A render inside a visit
Video processing time competing with social-referral attention spans.
One page, one shot
No account and no return visit — the whole thing converts now or never.
I owned the flow end to end — from the film's first frame to the file on someone's phone.
Owned
- Experience Architecture
- Upload-to-Render Flow
- Moderation Integration
- Client Leadership
Collaborated with
- Creative Director
- Developer
- UI/UX Designer
- AT&T & Translation
Give the film away, one family at a time.
Put them in the film, not beside it
The default campaign-UGC pattern parks submissions in a gallery next to the ad, where they do nothing for the person who submitted them.
Composite the visitor's photos into the picture frames inside the film and burn their family name into the edit — the output is the campaign, re-rendered around them.
A gallery asks the audience to give the brand content; this hands them an artifact worth keeping, so the reason to participate is the film itself.
Every completed upload ended in a film the visitor owned and downloaded — not a submission they waited on.




Two sections, no account
Campaign traffic arrives from a social link and leaves in minutes; a signup wall spends that attention on admin.
One page, two sections — the film full-bleed, then scroll to upload, render, and download. No login, no profile, no gallery to maintain.
The whole interaction has to finish in a single visit, so every screen that isn't the film or the upload is a screen that costs completions.
Watch, upload, download — with nothing in between for a visitor to abandon.
Screen the input, not the output
The product hands strangers an AT&T-branded film carrying their photo and their surname, built to be shared.
Licensed a moderation API and put it in front of the render — image and family-name text both screened before a single frame is produced.
Reviewing after the render means the unsafe version already exists and the visitor already waited; a gate costs nothing, a queue costs both.
AT&T could put its own film in strangers' hands without a human reviewing anything.


The film as the reward
Participation returns a personal cut of the campaign, not a slot in a gallery.
Moderation before render
Image and text screened at the gate, so no unsafe output is ever produced.
A wait worth holding
On-page render progress kept people through processing to the download.
The trade-off — I cut the public gallery. That gave up the social proof a visible wall of submissions creates — but it also removed the moderation queue, the account system, and any reason for a visitor to feel exposed.
What I'd improve — the render window. It was fast enough that most people stayed, but I never instrumented where the drop-off actually sat — I designed that wait on instinct.
Next time — when a campaign hands its own asset to the audience, brand safety is a pipeline decision, not a policy one. Gate the input and the output takes care of itself.

