Justin's lead ideas, checked

Residential window replacement · Puyallup/Sumner WA · Researched Fri Oct 9, 2026, ~2:30–3:35 AM PT · Advice, not legal advice · Nothing was bought, signed up for, sent or posted · No past customers or leads contacted. Tap a section to open it.

10-line summary

  1. A · Photo quote: build now, as a "ballpark + confirm". The Flask prototype works. On 5 public house photos it found ~55% of windows (84% of its boxes were right), so the homeowner confirms the count. Cost ≈ $0–0.01 per estimate.
  2. Google Street View, 3D Tiles and Aerial View imagery can't legally be used for window detection (Maps ToS 3.2.3). Zillow photos and data can't be used for marketing. Use the homeowner's own photos, or Hover ($39–139 per job) for hot leads.
  3. Say "ballpark range from photos in about a minute", never "quote in 60 seconds" (FTC substantiation, Google Ads misrepresentation).
  4. B · SMS in 15 s: build now. AI voice call only with the AI/autodialed consent box checked (TCPA: AI voice = artificial voice; WA CEMA $100 per text; WA all-party recording consent). ~$0.012 per text, ~$0.35–0.90 per 3-min AI call.
  5. "80% value drop in 5 minutes" is a misquote. The MIT study measured contact odds (~5× lower at 10 min vs 5 min), not value.
  6. C · Triggers: month 2. Free Pierce permit + assessor data → mail and geo ads only. No calls or texts to these lists, no Customer Match uploads of public or purchased lists. Skip hail (none in Puget Sound 2024–26). "Seals fail at 20–25 yrs" is only partly true (IGUs: 8–20+ yrs).
  7. D · Local SEO: review link to every new finished job (no incentives, no gating, no suggested wording; review keywords don't move rank). Real project pages instead of city clones. Geotagging is a myth (GBP strips EXIF). GBP Q&A API ended Nov 2025, chat ended July 2024.
  8. E: copy Modernize's speed, Podium/Weave's text inbox and review asks, Hover's photo intake. Avoid shared leads, annual lock-in, per-job fees on unbooked leads.
  9. F · Browser agents: later. OAuth/API connectors first (Google, WordPress app passwords, Shopify). Agents with vault + throwaway browser + human 2FA + approval on every action. Never bypass CAPTCHA/2FA. "Emplebitot" doesn't exist.
  10. G · Local Llama/Phi: skip. Hapva's server (3.7 GB RAM) can't run them; a GPU box is ~€184–234/mo vs ~$0.0005 per call on OpenRouter. ⚠ File 12's "revive NWR's 52 old leads" breaks the never-contact-past-leads rule, so strike it.

Researched Fri Oct 9, 2026, ~2:30–3:30 AM PT, for residential window replacement in Puyallup/Sumner, WA (one-URL lead platform, Hapva/Flask stack). Read with 08 (intent signals), 09 (speed to lead), 01 (Google), 10 (AI search). Costs are plain dollars per use where possible. Prices change; each one carries its source. "Unverified" means I could not confirm it from a primary source. Nothing was signed up for, bought, sent or posted. No past customer or lead was contacted, and nothing here should be used to contact them.

Verdicts at a glance
# Idea Verdict $ per use (typical) Main risk
A Photo → window count/size → ballpark Build now, as a ballpark + confirm step. A prototype is working (see A.1). ~$0.00 self-hosted; +$0.001–0.01 per photo for an LLM cross-check; Hover $39–139 per job only when it's needed Undercounting (prototype found about 55% of windows); claims in ads; Google Maps imagery cannot be used for detection
B Instant SMS (15 s) + AI voice call (2 min) Build now: SMS + a callback that sits behind consent. The AI voice call only after the consent box is live. SMS ~$0.012; 3-min AI call ~$0.35–0.90 TCPA artificial-voice consent, WA CEMA ($100+ per text), all-party recording consent
C Trigger pipelines (permits, home age, listings, weather) Later (month 2): permits + home age for mail and geo ads only. Skip Zillow and hail. Permit record ~$0–0.15; postcard $0.26 (EDDM) – $0.91 (Lob) Phone/text to scraped lists is illegal without consent; Zillow ToS; RCW 42.56.070(8)
D Local SEO automation Build now: review asks (new jobs only), real project pages, GBP posts/photos via API. Skip keyword-stuffed review prompts, city-page clones and geotagging. ~$0 (API) + ~$0.001 per page draft Google spam policies; FTC review rule (up to ~$53k per violation)
E Benchmarks (Modernize, Podium/Weave, Hover/Renoworks) Copy speed, photo intake and simple pricing. Avoid shared leads and lock-in. — —
F Browser agent "drop URL + login, AI sets up" Later. Build OAuth/API connectors first; use a browser agent only for leftovers, with approval on every action. ~$0.05–1.00 per task Credential custody, CFAA/ToS, 2FA/CAPTCHA (never bypass)
G Free local stack (Browser-Use + Ollama Llama 3.3 / Phi-4) Skip local models. The current server can't run them. Use OpenRouter pay-per-use. Llama 3.3 70B ≈ $0.0004 per typical call A GPU box costs ~$250+/mo to save pennies

Conflict to fix: file 12-competitor-apps.md, item 6, suggests an "old-estimate revival (NWR's 52 leads)". That breaks Justin's standing rule to never contact past customers/leads. Strike it. Everything below applies to new inbound people only.


A. Photo / computer-vision quoting

A.1 Prototype built and tested (Python/Flask + plain HTML/JS)

Location on the box: /workspace/window-estimator/

  • app/detector.py does zero-shot window/door/garage detection with OWLv2 (google/owlv2-base-patch16-ensemble, Apache-2.0, no training). It then runs NMS, drops glass inside doors and garage doors, and drops huge boxes.
  • Scale: the front door's box height is taken as 80 in (a standard 6'8" door), giving pixels per inch.
  • Sizing: each window's W×H becomes united inches (UI), mapped to a price tier.
  • app/app.py (Flask) serves / (a phone-friendly upload page with capture="environment") and POST /api/estimate (1–6 photos → JSON + annotated images).
  • Photos are processed in memory and discarded. EXIF is not kept.
  • Smoke test passed: 2 photos → 5 windows, $4,000–7,000 ballpark, 5.5 s + 4.8 s on CPU.
  • The price book is a placeholder (≤60 UI $450–750; 61–90 $600–1,000; 91–110 $850–1,400; >110 $1,100–2,200). It must be replaced with HOP/NWR's real price sheet before anyone sees a number.
  • A side-by-side test of Grounding DINO tiny (IDEA-Research/grounding-dino-tiny, Apache-2.0) is in gdino_test.py.

Test photos (public Wikimedia Commons; ground truth = my count of window units visible in each photo):

Photo (license) Visible windows OWLv2 correct / false / missed Grounding DINO correct / false Door found → size estimate?
Split-Level Houses in Gang Mills 01 (CC BY-SA 4.0) ~14 8 / 3 (neighbor's house) / 6 5 / 0 OWLv2 no, GDINO yes
Split-Level … 02 (CC BY-SA 4.0) 6 4 / 0 / 2 3 / 0 Yes, 1.38 px/in; upper window 59×40 in (box includes trim)
Split-Level … 03 (CC BY-SA 4.0) ~10 8 / 1 / 2 4 / 0 OWLv2 no
American Foursquare, Danbury CT (CC0) ~13 5 / 1 / 8 (tree-hidden, narrow lites) 5 / 0 No
Puyallup, WA – 315 2nd St NE (CC BY 3.0) 4 1 / 0 / 3 (bay, tree-hidden) 2 / 0 (caught the bay) Yes, 2.05 px/in; gable window 39×37 in
Total ~47 26 / 5 / 21 → precision ~84%, recall ~55% 19 / 0 → precision ~100%, recall ~40% 2 of 5 photos sized

Speed on 8 CPU cores: OWLv2 ~5.4 s per photo, Grounding DINO tiny ~18.5 s per photo. Model cost $0.

What the test shows (plain words):

  • Off-the-shelf models find about half the windows. What they find is mostly right. They miss windows behind trees, porch windows, narrow side lites, and anything on sides that weren't photographed.
  • Sizing only works when a door is visible and roughly in the same plane as the window, and the boxes include trim. Expect ±15–25% on size, which is fine for a tier and not fine for an order.
  • So the product is "ballpark range + you confirm the count", never "a quote".

Make it production-grade (build order):

  1. Capture guide. Ask for 4 photos (front, back, left, right), straight on, with the door in frame. Add an optional "tape measure on one window" photo.
  2. Confirm step (biggest win, $0). Show numbered boxes. The homeowner taps to remove false ones and taps to add missed ones, then picks a type per window (double-hung, slider, picture, casement, bay). This turns 55% recall into close to 100% on count, and makes the homeowner invested in the result.
  3. Ensemble. Union OWLv2 + Grounding DINO (DINO had zero false positives in the test). Optionally add an LLM vision cross-check: "count windows; list ones behind trees".
  4. Fine-tune (month 2–3). Train a detector on public facade sets + ~300–500 labeled local photos from HOP/NWR's own job photos. Labeling is ~1–2 min per photo with Roboflow/CVAT smart polygons, so ~10–15 hours. - For window type, add a classifier on each crop (5 classes, ~100 crops per class).
  5. Keep the in-home measure as the price-setting step. The photo tool books the measure appointment.

Prototype test images

OWLv2 split1Grounding DINO split1
Split-level 01, CC BY-SA 4.0 · left: OWLv2 (red = window) · right: Grounding DINO (orange)
OWLv2 split2Grounding DINO split2
Split-level 02, CC BY-SA 4.0 · left: OWLv2 (red = window) · right: Grounding DINO (orange)
OWLv2 split3Grounding DINO split3
Split-level 03, CC BY-SA 4.0 · left: OWLv2 (red = window) · right: Grounding DINO (orange)
OWLv2 foursqGrounding DINO foursq
Foursquare, Danbury, CC0 · left: OWLv2 (red = window) · right: Grounding DINO (orange)
OWLv2 puy315Grounding DINO puy315
Puyallup 315 2nd St NE, CC BY 3.0 · left: OWLv2 (red = window) · right: Grounding DINO (orange)

A.2 Model and dataset options

Option What it does License Fit
SAM / SAM 2 (Meta) Segments whatever you point at (point/box prompt). It does not know what a window is: no class labels, no text prompts. SAM 2: Apache-2.0 Only as a mask refiner behind a detector ("Grounded SAM" = Grounding DINO boxes → SAM masks) (Grounded-SAM repo; OpenVINO notebook)
SAM 3 Adds text "concept" prompts. "window" returns every instance with masks (HF docs; Ultralytics) Custom "SAM License" (commercial OK with conditions). Weights are gated behind an access request, so not tested (no signups) Strong candidate for v2. Read the license first
OWLv2 / Grounding DINO Text-prompted detectors Apache-2.0 Used in the prototype
YOLOv8 / YOLO11 (Ultralytics) Fast trained detector AGPL-3.0: a closed SaaS must open-source the app or buy an Ultralytics Enterprise license (quote) Fine for internal tests. For production, prefer an Apache/MIT detector (RT-DETR in HF transformers, torchvision Faster/Mask R-CNN, Detectron2 Apache-2.0)
Mask R-CNN Instance masks per window torchvision BSD / Detectron2 Apache-2.0 Good for facade instance segmentation once trained
win_det_heatmaps Keypoint/heatmap window corners. Handles perspective and gives quadrilaterals, which is better for sizing Code MIT; its dataset mixes ECP + eTRIMS (eTRIMS is research-only) Copy the method, retrain on licensed data

Datasets:

  • CMP Facade: 606 rectified facades with a window class. License is research-oriented and not clearly commercial, so treat it as research/eval only.
  • ECP / eTRIMS: research-only, citation required.
  • Roboflow Universe "window detection" sets (e.g. one with 778 images): each project shows its own license, often CC BY 4.0. Check each project page and keep a license log.
  • Your own job photos are the cleanest commercial training data.

A.3 Imagery and measurement vendors (what's allowed)

Source Cost Can we run window detection on it?
Google Street View Static 10,000 free per month, then $7 per 1,000 ($0.007); metadata free No. Maps Platform ToS 3.2.3(c) bars creating content from Google Maps content, and (vii) bars using it to "train, test, validate or fine-tune" ML. Show it to the homeowner as a "is this your house?" check only
Google Solar API Building Insights 10,000 free, then $0.01 per call Roof/solar data only, no windows. Same ToS limits
Google Photorealistic 3D Tiles (Map Tiles API) 1,000 root requests free, then $6 per 1,000 (a root covers a ~3-hr session) ≈ $0.006 per viewing session No. The Map Tiles policy bans image analysis, object detection and geodata extraction. CesiumJS/deck.gl display with Google attribution is fine; derivatives/overlays that extract data are not
Google Aerial View API 5,000 free, then $16 per 1,000 ($0.016) Display only. Videos can't be downloaded, stored or cached, and URIs are short-lived. So you can't attach the video to a text/email. You can text a link to your own page that plays it live, but only to someone who opted in (CEMA, see B). US addresses only; renderVideo can take hours. Puyallup/Sumner residential coverage was not tested (needs an API key)
EagleView Walls, Windows & Doors report $78 / $72.25 / $67.50 per report (volume tiers); Full House $105 / $98 / $91 Licensed measurement report. The Property Data API v2 is async with modular packs (roof, condition, geometry, imagery). I found no public window/door pack or API price. Free trial of 30 properties per pack, sandbox Omaha only
Hover Per-job $59 / $99 / $139 (Starter); $39 / $79 / $119 on Pro ($999/yr); $79 on Business ($2,999/yr) Phone-photo 3D model. The API (all plans) returns window groups with width, height and united inches. Accuracy depends on a reference measurement; no published accuracy figure. Good "pro" upgrade for hot leads
Renoworks Pro $250/mo, or $200/mo annually ($2,388/yr); auto-renews; 7-day trial needs a card Visualizer (show new windows on the house), not measurement
Zillow photos — No. Zillow API terms forbid scraping, bulk use, and building mail/telemarketing lists; Bridge data bans "direct marketing, telemarketing or other commercial contacts"
LLM vision cross-check Gemini 3.8 Flash $0.75 per 1M in (258 tokens per 768-px tile) ≈ $0.002–0.003 per photo; Claude Haiku 5.5 $0.10 per 1M ≈ $0.0002 per photo; GPT-4o $2.50 per 1M in Fine on homeowner-uploaded photos (they own them; say so in the upload terms)

A.4 The ad claim "Quote in 60 seconds from a photo"

  • FTC: objective claims need a reasonable basis before they run (Advertising Substantiation Policy Statement). The prototype undercounts, so "quote" overstates what it does.
  • Google Ads Misrepresentation: no unreliable claims. Unavailable offers: the promised thing must be available on the landing page.
  • Use: "Get a ballpark price range from photos in about a minute. Exact price after a free in-home measure."
  • Don't use: "Instant quote", "exact price from a photo", or any dollar figure that isn't on the landing page.
  • WA contractor ads must show the L&I registration number (RCW 18.27.100; see 01).

Cost per estimate: ~$0 on our own server (CPU), plus ~$0.01 if 4 photos get an LLM cross-check. Hover ($39–139) only after a booked appointment, if at all. Risk: an undercount sets a low anchor. Mitigate with the confirm step, a range, and "photographed sides only". Server note: Justin's hapva-1 server has 2 vCPU / 3.7 GB RAM. OWLv2 (~0.6 GB) would fit but run ~15–20 s per photo and compete with Hapva. Run it as a separate small service, or on a $9–16/mo CX33/CX43 (8–16 GB) when there's traffic.


B. Instant SMS + AI voice

B.1 The flow (new inbound only)

  1. The form (with photos) is submitted with the consent box checked.
  2. ≤15 s: a confirmation SMS: "Hi {first}, this is Justin's team at {Company}. Got your photos. Your ballpark is $X–$Y. Want a free measure? Reply with a day or call {number}. Reply STOP to opt out."
  3. ~2 min: the AI voice call, only if they checked the call/AI box. It discloses AI, asks 4 questions (how many windows, timeline, owner?, best time), offers 2 slots, and books into the CRM calendar. If they say "human", it hands off to Justin's cell, or texts "Justin will call you by {time}".
  4. If no answer: one voicemail-free retry at +1 hr. Calls and texts only 8 AM–8 PM local (RCW 80.36.390 for sales calls). Stop on any "stop" or "don't call".
  5. Booking writes to the CRM (Hapva Leads / Jobber / GHL) via webhook. Justin gets a push/SMS.

B.2 Costs (per use)

Piece Price Per lead
Twilio SMS (US) $0.0083 per segment + carrier fees (~$0.003–0.005); 10DLC registration fees one-time/monthly (see 09) ~$0.012 per text; ~$0.04 for 3 texts
Retell $0.07–0.31 per min; example $0.11 = $0.055 infra + $0.04 LLM + $0.015 TTS, + ~$0.015 telephony; KB +$0.005 per min; numbers $2/mo 3-min call ≈ $0.35–0.40
Bland Start $0.14 per min (LLM/STT/TTS included, telephony separate, 100 calls/day); Build $299/mo + $0.12 per min 3 min ≈ $0.42+
Vapi $0.05 per min platform + pass-through STT/LLM/TTS/telephony (a typical stack is $0.13–0.30 per min, per Bland's comparison FAQ, a competitor source) 3 min ≈ $0.40–0.90
Groq LLM (low latency) Llama 3.1 8B $0.05/$0.08 per 1M; Llama 3.3 70B $0.59/$0.79; ~0.35 s latency, 240 tok/s (OpenRouter's Groq row) <$0.01 per call

Latency: aim for under ~1 s voice-to-voice. Groq's time-to-first-token (~0.15–0.95 s in third-party tests) helps. Measure your own round trip before launch; vendor "sub-500 ms" claims are marketing.

B.3 The "80% value drop in 5 minutes" stat: misquoted

  • The MIT/InsideSales study measured the odds of contacting a lead: they drop ~5× (≈80%) between minute 5 and minute 10. It did not measure lead value.
  • HBR (2011) found responding within an hour gave ~7× better odds of qualifying.
  • Use instead: "Leads called within 5 minutes are far more likely to be reached than leads called at 10 minutes." See 09 for sources.

B.4 Legal: what must be in place first

  • TCPA + AI voice: the FCC's Feb 2024 Declaratory Ruling (FCC 24-17) holds that AI-generated voices are an "artificial or prerecorded voice". Calls to a cell phone need prior express consent, and prior express written consent if the call is telemarketing (a sales call is).
  • The FCC's AI-disclosure NPRM (FCC 24-84) is still a proposal as of Oct 2026. Disclose anyway.
  • Statutory damages are $500–1,500 per call.
  • WA CEMA (RCW 19.190): commercial texts to WA residents need clear, affirmative consent. Since the June 11, 2026 amendment, there is a private right of action with $100 per text in damages (see 08/09).
  • Recording: Washington is all-party consent (RCW 9.73.030). The AI says "This call is recorded" at the start, or don't record.
  • One-to-one consent: the FCC's rule requiring one-seller consent was vacated (11th Cir., Jan 2025). That's irrelevant here because Justin's form is first-party. Still, name the specific company.

Consent checkbox wording (unchecked by default, not required to submit; put the form's privacy link next to it):

☐ Yes, {Company Name} may text and call me at the number above about my window project, including automated texts and calls that may use an AI-generated or prerecorded voice. Calls may be recorded. Consent isn't required to buy anything. Msg & data rates may apply; message frequency varies. Reply STOP to opt out, HELP for help. [Privacy] [Terms]

If the box is unchecked: show the ballpark on screen, send nothing, and offer a "call me" button or Justin's number.

AI persona script (short):

"Hi {first}, this is Ava, {Company}'s AI assistant. This call is recorded. You sent photos of your windows a couple minutes ago. Is now OK for two quick questions? … About how many windows are you thinking of replacing? … Any timeline: this fall, spring? … Are you the homeowner? … Great. A free in-home measure takes about 45 minutes. I have {Tue 10 AM} or {Wed 4 PM}. Which works? … You're booked; you'll get a text confirmation. Want me to have Justin call you personally too?"

Knowledge-base guardrails:

  • Answer only from the approved FAQ:
  • WA energy code: the current 2021 WSEC-R (effective Mar 15, 2024) needs vertical-fenestration U-0.30 in WA (Marine 4/Zone 5) (SBCC). The 2024 codes take effect May 3, 2027 per SBCC, and the residential U-factor is proposed to tighten (search reports 0.27; verify in the final text).
  • PSE rebates: $50–100 per window, installed by 12/31/2026 (see 08).
  • Never quote a final price, financing terms, or promise rebates.

Verdict: build the SMS now. Add AI voice after the consent box has collected ~2 weeks of opt-ins and Justin has listened to 10 test calls. Risk: high if consent isn't captured and stored (keep the timestamp, IP, page version and checkbox text per lead).


C. Trigger-event pipelines
Trigger Data / cost Verdict
Building permits (roof, siding, remodel, window, heat pump) Pierce County Socrata nhnt-v7ka and Tacoma ArcGIS: free. In the last 12 months: 267 roof, 378 remodel, 342 additions, 303 window (see 08). Shovels: ~2,000 jurisdictions, refreshed twice a month with a 1–2 month lag, no documented webhooks (poll instead); free 500 credits, then $599/$999 per month. Pierce coverage not confirmed (check their coverage map). PermLead: free API tier, paid prices not listed. permitleads.us is Seattle-only ($39 per ZIP per month) Later (month 2): free county data → direct mail
Home age 15–25+ yrs County assessor: free. Pierce: 62% of SFR homes built before 1995 (Puyallup 7,195 of 10,170). HouseCanary $0.30–0.50 per basic call; an effective-age field was not confirmed. RealEstateAPI: pricing not public Use year built (free); skip paid "effective age"
Recent sales County sales records: free (8,683 SFR sales, 4,667 in pre-1995 homes). Not Zillow (ToS bans marketing lists) Mail "new homeowner" cards 30–90 days after a sale
Weather / hail NOAA: no hail events in Puget Sound zones 2024–2026 Skip. Use wind/storm or the heating season instead

Window lifespan check:

  • "Seals fail at 20–25 years" is only partly supported.
  • InterNACHI's life-expectancy chart gives double-pane (IGU) units 8–20 years and vinyl frames 20–40.
  • NAHB (2007) lists aluminum 15–20 and wood 30+, with no vinyl entry.
  • ORNL/IGMA field data: ~1% failure at ~15 years for high-quality certified units; older or cheaper designs fail far more.
  • Fair targeting copy: "Homes built before ~2005 often have original windows near the end of their life." Never say "your seals have failed".

Legal limits:

  • RCW 42.56.070(8): agencies may not hand out lists of individuals for commercial purposes (AGO 2019 No. 3). Permit records by request are OK, but a request "for a mailing list" can be refused. Use the published open-data portals.
  • Channel rules: mail is fine. Do not cold call or text people from permit or assessor data (TCPA, DNC, CEMA). Skip-traced phone numbers are out.
  • Ads:
  • Google Customer Match only accepts first-party data customers gave you directly; purchased or public lists are not allowed (policy). Permit and assessor lists can't be uploaded.
  • Meta customer-list audiences require "all necessary rights and permissions" (terms), so they're also a no for public-record lists.
  • Use geo targeting (ZIP/radius around permit clusters) instead. Never build audiences from past customers' data for outreach (Justin's rule).
  • Meta Special Ad Category:
  • Meta's Housing examples cover sale/rental listings, home insurance, mortgages and appraisal, not home improvement. So window ads normally aren't Housing. This corrects the earlier spec's "always Housing" rule.
  • Exception: any ad that mentions financing (0% APR, monthly payments) falls under the Financial products and services category: no age/gender/ZIP targeting, a 15-mile minimum radius, no lookalikes.
  • When in doubt, declare the category. Under-declaring gets ads and accounts restricted.

Costs per use:

Item Cost
County data $0
EDDM postcard $0.26 postage + ~$0.05–0.10 print
Lob addressed card ~$0.91
Melissa list $0.10 per record
Regrid $0.10–0.15 per record

Pipeline:

  1. Weekly cron pulls new roof/siding/remodel permits.
  2. Join to assessor data (year built ≤ 2005, owner-occupied).
  3. Run the suppression list (past customers/leads, opt-outs, DNC requests).
  4. Send to the mail queue with Justin's approval.
  5. Mail goes 30–60 days after the permit (exterior work is happening; windows are the next project).

D. Local SEO

D.1 Review requests

  • Allowed and recommended: ask every new completed-job customer, with the GBP review link: the g.page/r/…/review link from Business Profile → Read reviews → Get more reviews, or search.google.com/local/writereview?placeid=… (Google help).
  • Send by text only if they gave text consent on the contract or form. Otherwise use email or a printed QR card left at the job.
  • Automate it: job marked complete → wait 2 days → one ask → one reminder at 7 days → stop.
  • Never send to past customers (Justin's rule) or old leads.
  • Not allowed:
  • incentives of any kind (Google calls it fake engagement; FTC 16 CFR 465)
  • asking only happy customers / "review gating" (Google: no "selectively solicit positive reviews"; FTC Endorsement Guides §255.2(d), Ex. 11)
  • suggesting wording. Google's Maps UGC policy says merchants should not "request that specific content be included".
  • So: drafting the review from invoice line items ("mention our Milgard double-hung windows in Puyallup") is out.
  • OK: "If you're up for it, a quick Google review about how the job went helps a small local business a lot." Plain open-ended prompts like "what was the project?" are lower risk, but don't script keywords.
  • Do keywords or location in reviews help ranking? The Sterling Sky (2023) test found no ranking lift from keywords in reviews. Review count, recency and replies matter more (Whitespark factors, see 01). So the keyword-prompt idea risks policy for no gain.
  • Cost: ~$0.012 per SMS ask; $0 email.

D.2 Neighborhood / city pages

  • Google spam policies: scaled content abuse (many pages generated mainly to rank, "no matter how it's created") and doorway abuse ("multiple … pages targeted at specific regions or cities that funnel users to one page").
  • 26 near-clone city pages with GPT-4o-mini filler are the textbook case.
  • Build instead: project pages. One page per real completed job, e.g. "11 vinyl windows, 1978 split-level, Sumner (Lake Tapps area)", with:
  • real before/after photos, window count, product line, U-factor
  • what was hard and how long it took
  • customer quote (with written permission)
  • permit # if public
  • Then a few hub pages (Puyallup, Sumner, South Hill, Bonney Lake) that list the real projects there and local facts: home-age mix from assessor data, PSE/Tacoma Power rebates, permit rules.
  • A cheap model (GPT-4o mini $0.15/$0.60 per 1M ≈ $0.001 per draft) may only draft from the job record. A human approves each page, and no hub page goes up without ≥3 real projects.

D.3 Photo EXIF / geotags

  • Myth. Sterling Sky's Jan 2024 test found geotagging GBP photos had no ranking impact, and that Google strips EXIF/GPS data on GBP uploads. A later 27-location study (Search Engine Land coverage) found no overall effect.
  • Websites: EXIF isn't a known ranking factor, and it leaks customer home locations. Strip EXIF before publishing (the prototype already drops it).
  • What helps instead:
  • real, frequent photos on GBP via the API
  • descriptive filenames and alt text on the site
  • project pages with the neighborhood named in text
  • correct GBP categories and service areas
  • reviews over time
  • local links (chamber, sponsors)

D.4 GBP automation via API (verified status)

Feature Status Use
Posts (localPosts) Available Auto-draft a "project of the week" post from each job. Justin approves
Photos (Media upload) Available Push approved job photos (EXIF stripped)
Reviews: read + reply Available Draft replies; Justin approves
Q&A API discontinued Nov 3, 2025 —
Chat / Business Messages Ended July 31, 2024 Use the call/text button and WhatsApp/text attributes

API access needs a verified profile and a GBP API access request (approval-based). Exact prerequisites not re-verified.

Make.com + Strapi photo-to-project-map pipeline:

  1. Job photo uploaded.
  2. Make webhook fires.
  3. EXIF stripped and a GPS-rounded point (to the neighborhood, not the house) is saved.
  4. A Strapi "Project" entry is created as a draft.
  5. Justin approves.
  6. The site map pin and project page publish; the GBP photo and post go up.

Costs:

  • Make Free: 1,000 credits/mo, 2 active scenarios, 15-min minimum schedule, 5 MB files, no time limit (pricing). Webhook triggers don't use credits while idle. Fine for <~100 jobs/mo.
  • Make Core: ~$9–12/mo for 10,000 credits.
  • Strapi Cloud Essential: ~$18/mo (third-party pricing pages). Strapi self-hosted is $0 on the existing server.
  • Cheaper still: do it inside Hapva (Flask) with no Make at all.

E. Benchmarks: what to copy, what to avoid
Company Copy Avoid
Modernize / QuinStreet (pay-per-lead; ~$30–60 shared, $55–110 exclusive; ~$380 per lead reported; 278 BBB complaints) Short multi-step form, instant phone verification, speed Shared leads sold to several contractors, "marketing partners" consent; QuinStreet's own 10-K lists TCPA risk
Podium / Weave (Weave $199/mo base, add-ons $149; Podium quote-only, last public $399/$599) Text-first inbox, review-link texting after jobs, webchat → SMS Annual contracts, bundles; cost/support complaints
Hover / Renoworks Photo intake guidance, measurements returned as JSON, visualizing new windows Pay-per-job costs for leads that never book; vendor lock-in for the core feature

The lesson for Justin's platform: own the fast photo-to-ballpark-to-booking loop, keep leads exclusive, price simply, and never resell leads.


F. Autonomous browser agents ("drop your URL + admin login, AI does setup")

Reality check:

  • Best published scores are still far from reliable on real admin UIs:
  • OpenAI Operator: OSWorld 38.1%, WebArena 58.1%
  • Anthropic's newest models: OSWorld 2.0 ~40–42% strict / ~75–78% partial
  • Failure modes:
  • layout changes; popups/modals
  • 2FA and CAPTCHA (agents must stop)
  • wrong-account edits; hallucinated "done"
  • session timeouts; rate limits; long tasks drifting

Tools and cost per task (10–40 steps):

Tool Pricing ≈ $ per setup task
OpenAI Agents API computer_use (computer-use-preview retired Jul 23, 2026; was $3/$12 per 1M) Model tokens. Built-in per-origin user approval and credential-request events ~$0.10–1.00
Anthropic Computer Use Model tokens + ~4,500 tool tokens per request (computer_toolset_20260801) ~$0.10–1.00
Browser Use (Python, MIT) Open source; cloud $0.02 per browser-hour; V2 from $0.006 per step + $0.01 per task ~$0.05–0.30 + LLM
Browserbase $20 for 100 hrs then $0.12/hr; $99 for 500 hrs then $0.10/hr ~$0.01–0.02 browser time + LLM
Steel.dev Open-source browser API; cloud pricing not verified —
Skyvern ~1 credit per action; Hobby $29 for 30k credits (~1,200 actions); Pro $149 ~$0.50–1.00
Playwright (self-hosted) $0 Scripted flows, no AI. Most reliable for known screens

Benchmarks named by Justin:

  • Autoblogging.ai: $19–999/mo, $0.20–0.48 per article credit. Content generation, the same scaled-content risk as D.2.
  • Expertise AI: enterprise website chat agents, quote-based (~$2,000/mo Business per a third-party review).
  • Kimi browser extension: free. Renamed from WebBridge Sep 22, 2026. Drives your local browser via CDP using your logged-in sessions, so it runs on a desktop, not an iPhone.
  • Fellou: agentic browser, $19 / $39.90 / $199.90 per month, ~4 tasks per 1,000 "Sparks". It gets stuck on complex layouts and CAPTCHAs (third-party review).
  • "Emplebitot": not found. No product by that name turned up. The closest match, "Emebit", is an unrelated Argentine IT firm. Ask Justin where he saw it.

Safe architecture (recommended):

  1. Official APIs/OAuth first. They cover ~80% of setup: - Google OAuth for GBP, Search Console, Analytics and Ads (scoped, revocable) - WordPress Application Passwords: per-app, revocable, used over HTTPS with REST Basic auth; the password is shown once (docs) - Shopify app OAuth with minimal scopes - Meta Business OAuth
  2. No raw admin passwords stored by default. If a login truly can't be avoided (some directory sites): - keep secrets in an encrypted vault (HashiCorp Vault or cloud KMS envelope encryption), never in the DB or prompts - run each task in a disposable browser container that is destroyed afterward - Justin types or approves the 2FA code himself, live - per-action approval for any write: preview the change, then "Approve" - full screenshot audit log; scoped least-privilege sub-accounts where the platform allows (e.g. a WordPress "Editor" user, a GBP "Manager")
  3. Hard rules: never bypass CAPTCHAs or 2FA, never reuse or export session cookies to get past a login, never use a customer's credentials outside the approved task. If a site says no bots in its ToS, do the task by hand or skip it.
  4. Legal: - CFAA: after Van Buren v. US (2021), liability turns on accessing areas you're not authorized to enter ("gates up or down"). Logging in with a client's credentials for the client, within their permission is generally authorized. Exceeding the scope, bypassing access controls, or breaking a platform's ToS still risks contract claims, account bans and state-law claims (hiQ v. LinkedIn ended against hiQ on contract grounds). - Get written client authorization that lists sites and actions. - Liability: an agent's wrong edit on a client's site is your fault. Keep backups and preview diffs.

Build first: a Google OAuth connector (GBP + Search Console) + a WordPress Application Password connector + a "checklist with deep links" for everything else. Add a Browser Use or Agents-API agent later, only for the leftover sites, in approval-per-action mode.


G. "Free stack": Browser-Use + Ollama (Llama 3.3 / Phi-4)

Justin has no computer (iPhone/iPad only), so "local" means a server.

Model (Ollama) Download Memory needed Runs on Justin's hapva-1 (2 vCPU, 3.7 GB RAM)?
Llama 3.3 70B (Q4_K_M) 43 GB ~45 GB at 4k context, ~59 GB at 32k No. Needs a 48–96 GB GPU or 64 GB+ RAM; on CPU it's ~1 token/s at best
Phi-4 14B 9.1 GB ~12.5 GB No. Too little RAM. A 16 GB CPU box runs it at a few tokens per second, too slow for chat or agents
Llama 3.2 3B / small models ~2 GB ~3–4 GB Barely, and it would starve Hapva. Too weak for browser agents

Sources: ollama.com/library/llama3.3, ollama.com/library/phi4, localmodel.run.

Dollar comparison:

  • Hetzner GEX44 GPU (RTX 4000 Ada, 20 GB VRAM): ~€184–234/mo + €79–114 setup (Hetzner). Runs Phi-4 well, but 20 GB can't hold Llama 3.3 70B at Q4.
  • A 96 GB GPU box (GEX131) is ~€1,197+/mo.
  • OpenRouter pay-per-use:
  • Llama 3.3 70B: $0.10 / $0.32 per 1M tokens
  • Phi-4: $0.07 / $0.14 per 1M (OpenRouter)
  • A typical lead-processing call (~3k in / 500 out) ≈ $0.0005 on Llama 3.3 70B. $250/mo of GPU ≈ 500,000 such calls. Justin will make perhaps a few thousand a month.
  • Verdict: keep using OpenRouter (Hapva already does, with a cap). Browser Use is open source and works with any OpenRouter/OpenAI-compatible model. Small open models are poor at multi-step browser control, so use a strong model per step only where F says to.
  • Revisit local hosting only above ~$150/mo of steady LLM spend, or if a privacy rule requires it.

Source index (main)
  • Google Maps Platform ToS §3.2.3 & Map Tiles policies — cloud.google.com/maps-platform/terms; developers.google.com/maps/documentation/tile/policies
  • Google pricing (Street View, Solar, Aerial View, Map Tiles) — developers.google.com/maps/billing-and-pricing/pricing
  • EagleView product price list; EagleView Property Data API v2 docs; Hover pricing page & API docs; Renoworks Pro pricing
  • Zillow API Terms of Use; Bridge Interactive data terms
  • FCC 24-17 Declaratory Ruling (AI voices = artificial voice); FCC 24-84 NPRM
  • RCW 19.190 (CEMA), RCW 9.73.030, RCW 80.36.390, RCW 42.56.070(8), RCW 18.27.100 — app.leg.wa.gov
  • FTC 16 CFR Part 465; 16 CFR 255; FTC Advertising Substantiation statement
  • Google Maps UGC prohibited content & Fake engagement policy; GBP review link help (support.google.com/business/answer/16816815)
  • Google Search spam policies (scaled content abuse, doorway abuse) — developers.google.com/search/docs/essentials/spam-policies
  • Sterling Sky: geotagging test (Jan 2024); review keyword test (2023)
  • GBP API: Q&A deprecation (Nov 3, 2025); Business Messages shutdown (July 31, 2024)
  • Google Ads Misrepresentation & Unavailable offers; Customer Match policy; Meta Custom Audience terms; Meta Special Ad Categories help
  • SBCC (2021 WSEC effective Mar 15, 2024; 2024 codes effective May 3, 2027) — sbcc.wa.gov
  • InterNACHI life-expectancy chart; NAHB/Bank of America "Study of Life Expectancy of Home Components" (2007); ORNL/IGMA IGU field study
  • Bland, Retell, Vapi, Twilio, Groq, OpenRouter pricing pages; Browserbase, Browser Use, Skyvern, Fellou pricing; OpenAI computer-use deprecation notice; Anthropic computer-use docs
  • Ollama library pages; Hetzner GEX44; Make.com pricing; WordPress Application Passwords; Van Buren v. US, 593 U.S. 374 (2021)
  • Prototype photos: Wikimedia Commons "Split-Level Houses in Gang Mills 01/02/03" (CC BY-SA 4.0), "American Foursquare – Danbury, Connecticut" (CC0), "Puyallup, WA – 315 2nd St NE" (CC BY 3.0). The annotated versions are derivatives under the same licenses.
Not verified / gaps
  • Aerial View coverage for Puyallup/Sumner addresses (needs an API key)
  • EagleView window/door API price
  • Shovels Pierce County coverage
  • RealEstateAPI pricing and effective-year fields
  • Steel.dev cloud pricing
  • exact 2024 WSEC-R U-factor in the final rule
  • SAM 3 hands-on test (gated weights)
  • GBP API access prerequisites
  • An LLM-vision accuracy test (no free vision endpoint without signup)