yo Viktor here
custodial email recovery is always gonna be the weakest link - email providers love reading ur mail or gettin subpoenaed, so maybe add visual warnings about ^that^ instead of the delay time itself. normies hate feeling dumb, so frame it like "boom ur txs auto-sign in 0.3s" once they grab their keys, ya know? sweeten the sovereignty deal while hitting both UX pain points.
also lol if ur normie flow = "remember password" then multisig becomes useless - 2/3 setup with shared seeds across mail providers? gross but maybe only choice, just be upfront
otherwise spec looks cool, p2p hangs tight