Skip to content

Hourleaf product roadmap — trust, speed, Shortcuts, and release #3

Description

@kiku-jw

Implement the accepted full Hourleaf product roadmap while preserving the existing local ledger and the minimal, immediately understandable iPhone experience.

Status: Hourleaf 1.0.7 (21) submitted — Waiting for App Review
Next actor: Apple; then Codex release follow-up
Next action: Automatic App Store release is selected. After approval, verify live 1.0.7 in US/LT/UA, then publish the matching GitHub release and update kikuai.dev version claims. Do not call 1.0.7 public before storefront confirmation.

Mac widget follow-up — 2026-08-25

Goal: make the existing iPhone WidgetKit extension useful on Mac through Apple’s iPhone-widgets-on-Mac path, without creating a separate unsynchronized macOS ledger.

Acceptance:

  • Support small and medium widget families with one calm native hierarchy.
  • Show service and credit as hours/minutes; the medium family also shows the current month, Bible-study count, and actual service-year progress toward 600 hours.
  • Preserve opt-in totals, privacy-sensitive rendering, local-first storage, and the existing quick-entry deep link.
  • Evolve the sidecar projection backward-compatibly; the extension never opens the Core Data ledger directly.
  • Add no dependency, native macOS app, CloudKit mode, or new data-writing path.
  • Pass focused state/codec/localization tests, the full relevant test suite, Release build, and visual inspection in both families and long RU/UK copy.

Outcome

Hourleaf becomes a durable private ministry-hours product: entries are recoverable and portable, common actions are one tap or a system Shortcut away, every total is explainable, planning remains calm, and optional platform features do not compromise offline-first use.

Product constraints

  • Native SwiftUI and Apple frameworks; no third-party SDKs, ads, tracking, or product analytics.
  • Local-first and fully usable without network, iCloud, an account, or a paid Apple Developer membership.
  • Preserve all existing user records and Personal Team testing data through an explicit portable-backup migration path.
  • Minimal UI: reveal complexity only where it is needed; explain each control in ordinary RU/UK/EN language with a concrete consequence or example.
  • Credit never contributes to the 600-hour service-year goal; totals may exceed 600; no time carries across August to September.
  • Backup v1 has no password. Warn plainly when notes are included.
  • No external account, direct recipient delivery, CRM, contacts, territories, maps, GPS, streaks, badges, social features, or AI coaching.

Specification decisions

  • Preserve the four-tab app and fast-entry default; advanced planning, report history, data tools and Shortcuts help remain progressively disclosed.
  • Use one actor-isolated asynchronous Core Data repository and one validated command path for SwiftUI, App Intents, widgets, Watch and timer.
  • Every entry mutation appends an immutable revision and returns a persisted Undo-capable mutation receipt.
  • Until Portable Forever is verified, retain and show every soft-deleted entry. Only then may Hourleaf introduce a tested 30-day purge policy.
  • Backup v1 is one canonical JSON .hourleafbackup, SHA-256 checked, plain and password-free; notes receive an explicit warning.
  • Restore v1 validates in a temporary store, previews, makes a verified pre-restore backup and performs whole-database replacement only.
  • Implement iOS 17 App Intents/App Shortcuts immediately after the shared command layer. Control Center controls are iOS 18+ and gated separately.
  • App Intent writes are allowed while locked because they reveal no ledger data; reads remain authenticated. Both work offline and never depend on a live SwiftUI environment.
  • App Group/data widgets, CloudKit, Watch, TestFlight and App Store retain signed-device/account owner gates.
  • Existing com.kikuai.hourleaf.local records migrate to the final bundle through .hourleafbackup.

Executable slices

  • 1. V2 model, actor repository, migration fixtures
  • 2. Shared commands, revisions, soft delete, Recently Deleted, Undo
  • 3. iOS 17 App Intents, App Shortcuts, typed routes, Action Button smoke — code merged at 8d1f70b; signed-device gate pending
  • 4. Canonical backup v1 codec/checksum/export — merged at 10c51b2
  • 5. Backup/CSV UI, previewed restore, rollback
  • 6. One-Tap exploration completed — Repeat Last Entry was removed after field feedback; fast entry remains available through blank Quick Entry, Shortcuts, widget, and timer
  • 7. Explainable report states, review, immutable corrections/templates
  • 8. Calm pace, calendar and versioned service-year archive
  • 9. Reminder actions and opt-in Quiet Gap Check
  • 10. Privacy-safe widget and iOS 18 controls — M4 code merged at cbb24d6; signed App Group/widget/control acceptance remains owner-gated
  • 11. Opt-in crash-safe timer; Live Activity later
  • 12. Opt-in private iCloud — NO-GO until paid CloudKit access and an accepted V3 branch/conflict-preservation model; local-first store plus portable backup remain authoritative
  • 13. Native Apple Watch companion — direct service/credit entry, Watch Connectivity, localized Watch UI, icons, privacy manifest, and embedded packaging are implemented; direct Watch entry and Siri/Shortcuts execution are physically verified on isolated signed bundles, while Store delivery of the Siri repair awaits a new owner-approved build.
  • 14. CSV then fixture-backed competitor imports — strict Hourleaf CSV complete; named adapters remain fixture-gated
  • 15. Local-bundle migration, accessibility/privacy/device QA and owner-gated public release — ungated foundation accepted at cdb303a; signed-device/public-release gates remain

Cross-slice acceptance

  • Existing stores migrate without data loss; destructive actions are reversible.
  • A backup round-trips every supported entity and a failed/corrupt restore cannot replace the live store.
  • Common service/credit additions work through both the app and App Intents via one validated command contract, offline, with undo.
  • Shortcuts are discoverable, parameterized, localized, and do not expose private notes/totals by default.
  • A non-technical older user can understand quick entry, settings, report state, backup/restore, and planning without documentation.
  • Unit, migration, integration, UI, localization, accessibility, offline/restart, and signed-device smoke evidence is recorded per slice.
  • Coherent verified slices are committed and pushed; this Issue remains the sole execution ledger for the roadmap.

Verified delivery

Slice 1 landed on main at 12706b0. Fresh evidence: 32 unit/integration tests; 13 full UI tests plus 3 final report-boundary UI checks; unsigned generic-device Debug and Release builds; exact byte preservation of the V1 model; Sol Max adversarial review GO with no P0/P1/P2 findings. Physical iPhone remains untouched.

Slice 2 landed on main at c0fcb99. Fresh evidence: 58 unit/integration and 16 UI tests; unsigned generic-device Debug and Release builds; strict invalid-date/duration/revision handling; idempotent exact replay; optimistic revision conflicts; soft delete/restore; all four Undo inverses and the exact ten-minute boundary; report calculation/presentation fingerprints; RU/UK/EN validation; unchanged Core Data model/project/entitlements; Sol Max re-review GO with P0 0 and P1 0. Physical iPhone remains untouched.

Slice 3 code landed on main at 8d1f70b. Fresh evidence: 70 unit/integration and 19 UI tests (89/89 total); unsigned Debug and Release builds; Xcode Analyze; exactly three RU/UK/EN promoted commands; one shared repository actor; coalesced active/foreground/startup refresh; typed reminder routing; cold and warm blank-form reset; Sol Max adversarial GO with P0 0 and P1 0. A disposable signed smoke attempt stopped before installation because Xcode has no signed-in Personal Team account, so the physical device and its ledger remained unchanged. The slice stays open only for Shortcuts, Action Button, and reminder lifecycle smoke after the owner signs in to Xcode.

Slice 4 landed on main at 10c51b2. Fresh evidence: exact raw preservation of all 10 V2 entities and 115 attributes; canonical password-free JSON with SHA-256 and bounded validation; atomic no-overwrite protected export; 26 focused backup tests; 115/115 combined tests after Shortcuts integration; unsigned Debug and Release builds; Xcode Analyze; unchanged models/project/entitlements/privacy/dependencies; Sol Max publish GO with P0 0, P1 0, and P2 0. Signed file-protection and File Provider behavior move to the Slice 5 disposable canary. The physical iPhone ledger remains untouched.

Slice 11 is accepted on the feature branch at 962aec5: host-only, default-off crash-safe timer; review-before-save; no note capture; no extension ledger writer. Unit, UI, Release and Analyze gates passed. App Group/control/widget and physical-device canaries remain owner-gated.

Slice 14 is accepted on the feature branch at bc784c0: strict bounded Hourleaf CSV import, deterministic identities, one-save atomic application, conservative duplicate handling, ten-minute batch Undo, aggregate-only preview and human EN/RU/UK UI. Fresh final evidence: 417/417 unit/integration, 43/43 UI, post-cleanup coordinator 4/4, Release build, Xcode Analyze, protected-hash/localization gates and one bounded adversarial review with P0/P1/P2 = 0. A real external-file import journey remains signed-device acceptance; named competitor adapters require an owner-supplied sanitized export fixture.

Live revision-graph validation landed on main at 1dfadb5: backup and live snapshots now share one fail-closed immutable-history validator. App Group, CloudKit and Watch writers remain capability- and signed-device-gated.

Owner-controlled gates

Apple account credentials, 2FA, paid membership, App ID/iCloud container changes, CloudKit production schema, TestFlight/App Store publication, and irreversible provider actions require explicit owner participation when reached.

Activity

  1. kiku-jw commented on Aug 2, 2026

    @kiku-jw
    MemberAuthor

    Roadmap preflight on 2026-08-02:

    • Verified owner/root: /Users/nick/Documents/HoursJW -> https://github.com/KikuAI-Lab/Hourleaf.git.
    • main is clean and synchronized at 4b76a0e.
    • Fresh full simulator baseline passed: 15 unit/integration + 13 UI tests, 28/28 total, on iPhone 17 Pro / iOS 26.5.
    • Current build has no AppIntents.framework dependency or App Shortcuts metadata yet.
    • Native prior-art check supports using Core Data persistent-store replacement plus AppShortcutsProvider without third-party backup/shortcut dependencies.
    • Sol Max specification lane is active; code execution has not started.
  2. kiku-jw commented on Aug 2, 2026

    @kiku-jw
    MemberAuthor

    Slice 1 accepted and published to main at 12706b0.

    Evidence:

    • 32/32 unit and integration tests passed after integration into main.
    • 13/13 full UI tests passed; 3 report-boundary UI checks were rerun on the final code.
    • Unsigned generic-device Debug and Release builds passed.
    • The V1 Core Data model is byte-for-byte unchanged; V2 is additive and current.
    • Migration normalization is strict, idempotent and count/readback verified; malformed required data fails visibly instead of being dropped.
    • Store-load failure, stale report inputs, concurrent settings saves and immutable report receipts have regression coverage.
    • Sol Max adversarial review verdict: GO; no P0/P1/P2 findings.

    The physical iPhone was not installed or mutated. Portable backup plus verified restore remains the gate before any model-changing device install.

    Next active slice: shared mutation commands, replay safety, optimistic revisions, soft delete, Recently Deleted, and ten-minute Undo.

  3. kiku-jw commented on Aug 3, 2026

    @kiku-jw
    MemberAuthor

    Slice 5 execution contract — restore and Data Management

    Accepted base: 10c51b2.

    • Scope is local-only single-store restore. Cloud-backed or multi-store configurations are rejected before staging; Hourleaf never turns iCloud off automatically.
    • A selected .hourleafbackup is copied into bounded app-owned protected staging, decoded by the frozen v1 codec, imported into a fresh current-model temporary SQLite store, closed/reopened, and accepted only when raw and domain readbacks preserve the incoming digest.
    • Preview is read-only and shows understandable counts/date range before confirmation. Confirm replaces the whole ledger; there is no merge, password, or typed phrase.
    • Every app and App Intent writer is stopped by one repository maintenance lease. Before replacement, Hourleaf creates and rereads an exact portable backup of state A plus coordinator-created old-store evidence.
    • Store transitions use Core Data coordinator copy/replace/destroy APIs only. SQLite, WAL, and SHM files are never copied or deleted manually.
    • A protected journal and armed marker guarantee restart resolves to exact A or exact B, never a mixture. Corrupt or unknown recovery state blocks normal store loading and preserves evidence.
    • All app-owned backup, staging, journal, temporary-store, old-store and CSV files are protected before their first byte; signed-device attribute readback remains a disposable-canary gate.
    • Settings gains one progressively disclosed row for Backup and export. Copy is plain RU/UK/EN, warns that the password-free file and notes are readable, states that restore replaces everything, and explains that CSV is spreadsheet-only.
    • CSV exports active entries only, with notes opt-in and off by default.
    • The physical com.kikuai.hourleaf.local ledger remains untouched until simulator fault tests, Sol review, and a separately signed disposable roundtrip all pass.
  4. kiku-jw commented on Aug 3, 2026

    @kiku-jw
    MemberAuthor

    Slice 5 M1 checkpoint accepted and published on codex/hourleaf-restore-v1 at 6d647753a76d094d4b830679112440a4fee1b133.

    Evidence:

    • independent LedgerMaintenanceTests: 7/7 passed on iPhone 17 Pro Simulator (/tmp/hourleaf-m1-rereview.TC2Lx7/LedgerMaintenance.xcresult);
    • adversarial re-review: GO, P0/P1/P2 = 0;
    • exact-A final digest and store removal now share one Core Data coordinator barrier;
    • writers before the barrier abort close; writers after it cannot land before removal;
    • failed fresh reopen remains retryable;
    • destructive store cleanup accepts only the exact owned typed staging artifact;
    • Core Data model, project, entitlements and privacy manifest unchanged.

    Next: bounded staged import and all-ten-entity temp-store validation, followed by journaled confirm/recovery. CSV and Data Management UI remain in a separate reviewed lane. No physical iPhone app or ledger was touched.

  5. kiku-jw commented on Aug 3, 2026

    @kiku-jw
    MemberAuthor

    Slice 5 Data Management component lane accepted and published on codex/hourleaf-data-management-ui at 8ece9f554c1b16f5be0adfb62dd5a29a62f120bb.

    Evidence:

    • independent focused CSV/UI-state run: 14/14 passed (/tmp/hourleaf-csv-ui-rereview.7ewRma/CSVExporter.xcresult);
    • worker full unit target: 110/110; Debug build and RU/UK/EN localization lint passed;
    • adversarial re-review: GO, P0/P1/P2 = 0;
    • deterministic active-only CSV uses BOM, RFC 4180, CRLF and note opt-in;
    • app-owned share artifacts have idempotent cleanup on completion/cancel/dismiss;
    • restore controls are explicitly unavailable while iCloud sync is active;
    • restore/disappear state cannot discard a candidate concurrently with replacement;
    • plain password-free backup and CSV note privacy warnings are present.

    This branch is deliberately not wired into Settings/AppModel yet; integration waits for the restore backend contract. Physical file-protection proof remains a disposable signed-device gate, and the real iPhone ledger remains untouched.

  6. kiku-jw commented on Aug 3, 2026

    @kiku-jw
    MemberAuthor

    Roadmap completeness audit (research reports 25-28 + PRO recommendation + accepted product contract): no missing P0 feature was found before safe restore. Accepted post-Slice-5 order remains:

    1. One-Tap v1: one derived Repeat last entry action only; latest active record, kind+minutes only, today, no note, .appOneTap, existing Undo. No presets or fourth promoted Shortcut tile.
    2. Report Readiness and immutable corrections/service-year close.
    3. Calm service-only pace to 600, never capped and excluding credit.
    4. Opt-in actionable reminders, then backup-confidence status and privacy-safe quick surfaces.
    5. Timer/Watch/imports/iCloud remain later gated work.

    Deliberate non-features: backup password/recovery key, adaptive suggestions, automatic time creation, zero-time entries, streaks/badges, CRM, PDF without evidence, and Cloud sync as a backup substitute.

    Trust correction required before production signing: local-only must be the truthful default while Settings says sync is planned. Future iCloud sync must be an explicit opt-in with conflict/restore semantics, never silently enabled. This does not alter the current Personal Team local ledger and requires no account action now.

  7. kiku-jw commented on Aug 3, 2026

    @kiku-jw
    MemberAuthor

    Slice 5 M2 accepted and published on codex/hourleaf-restore-v1 at b29fb4e35ea6f292c64b5c8552a540e49f850861.

    Evidence:

    • independent HourleafRestorePreparationTests: 11/11 passed at /tmp/hourleaf-slice5-m2-20260803-051954.xcresult;
    • final combined M2 + M1: 18/18 passed; no SQLite vnode-unlinked warnings after the test-lifetime fix;
    • Sol Max adversarial review: GO, P0/P1/P2 = 0;
    • selected backup is coordinated and bounded, imported across all 10 raw entities, reopened, and accepted only when raw/domain/raw digests remain exact;
    • private-cloud and in-memory stores reject before staging; preview never mutates live data;
    • deterministic typed staging cleanup follows the documented Core Data truncate contract, proves the old store UUID and all model records are gone, survives split cleanup faults and process restart, and never manually deletes SQLite/WAL/SHM;
    • protected model, managed objects, project, entitlements, privacy manifest, and frozen backup v1 codec/exporter are unchanged.

    Next checkpoint: journaled confirm, exact pre-restore A backup/evidence, whole-store replacement, A-or-B crash recovery, and reminder rescheduling. Physical iPhone data remains untouched.

  8. kiku-jw commented on Aug 3, 2026

    @kiku-jw
    MemberAuthor

    UX minimalism slice accepted and published.

    • Branch: codex/hourleaf-ux-minimalism
    • Commit: 7aa67c8
    • Removes the decorative onboarding hero and keeps one concise explanation.
    • Clarifies editable credit-label intent, minute-handling examples, pre-Hourleaf time, and plain-language privacy copy in EN/RU/UK.
    • Removes the misleading storage/sync row until the truthful local-only runtime slice lands.
    • Preserves the safe 0:00 edit confirmation and soft-delete flow.

    Verification:

    • independent review: GO, P0/P1/P2 = 0
    • localization plist/key parity and git diff check: pass
    • exact three promoted Shortcuts: pass
    • onboarding UI: pass
    • zero-duration edit/delete UI: pass
    • Settings UI copy: pass

    This branch is intentionally isolated and will be integrated after restore M3.

  9. kiku-jw commented on Aug 3, 2026

    @kiku-jw
    MemberAuthor

    Truthful local-only checkpoint accepted and published on branch codex/hourleaf-local-truth at e2e7e3e.

    Evidence:

    • Runtime storage is local by default in every build; CloudKit remains possible only through a future explicit opt-in and migration gate.
    • Shipping iCloud and Push capabilities, CODE_SIGN_ENTITLEMENTS, and the CloudKit entitlement file are removed; Debug and Release build settings expose no iCloud or Push entitlement.
    • Core Data V1/V2 compiled model bytes and version checksums are identical before and after the IDE CloudKit flag correction, so the existing SQLite path/schema is not split.
    • Fresh unsigned generic-device Debug and Release builds passed.
    • Full simulator suite passed 116/116; after the final Settings cleanup, the affected UI test passed again 1/1. RU/UK/EN plist and key parity checks passed.
    • Sol Max independent review: GO, P0/P1/P2 = 0.
    • Settings no longer exposes the misleading storage/sync row, and privacy copy says plainly that records stay on this iPhone.

    No installer or physical device command was run, and the real iPhone ledger remains untouched. If real CloudKit use were ever discovered despite the canonical history, a separate drain/migration canary remains mandatory before rollout.

  10. kiku-jw commented on Aug 3, 2026

    @kiku-jw
    MemberAuthor

    Restore M3a is frozen, independently accepted, and published.

    • Branch: codex/hourleaf-restore-v1
    • Commit: 17fe55677663b9c67f01fb0d6d7f64dfe72eda44 (Add crash-safe restore journal)
    • Scope: checksummed crash journal and marker, exact A/B terminal decision matrix, protected bounded pre-restore backup evidence, hard-link final/partial crash-window handling, proof-gated cleanup, and idempotent preflight.
    • Focused M2 + M3a verification: 35/35 passed, 0 failures/skips. Result bundle: /tmp/hourleaf-m3a-accept.KWOE9x/Logs/Test/Test-Hourleaf-2026.08.03_07-43-14-+0300.xcresult.
    • Independent worker verification: 35/35 passed. Result bundle: /tmp/hourleaf-restore-m3b-freeze/Logs/Test/Test-Hourleaf-2026.08.03_07-42-27-+0300.xcresult.
    • Generic iOS device builds with signing disabled: Debug succeeded at /tmp/hourleaf-m3a-debug.tZ2MPv; Release succeeded at /tmp/hourleaf-m3a-release.Xtjqw1.
    • Independent Sol review: GO, P0 0 / P1 0 / P2 0.
    • Frozen source hashes: RestoreJournal.swift = 11849b39bcaa5d57ec9693f25e7746c8266ea920a1c0e54df741ae463037ac42; RestoreJournalTests.swift = e9b7a5ed7c355265d7ef5e7b2b8b05592fcc558770396e6be44229ec6ccce995.
    • Remote readback matches local commit exactly; worktree is clean.

    No physical-device install, signing, or real Hourleaf ledger mutation was performed. M3b coordinator integration remains next; it must preserve actor serialization and produce terminal proof only after fresh Core Data readback.

  11. kiku-jw commented on Aug 3, 2026

    @kiku-jw
    MemberAuthor

    Roadmap specification coverage is now frozen and independently accepted.

    • Quick Surfaces + Timer v1: SHA-256 a4973c59fdefbe975c6d06566bfc9fa0851487915296bd2f0e7fa3fd76e51fa2 (1,135 lines / 65,732 bytes).
    • Platform Expansion v1: SHA-256 0fd0085af855e88178d74103ba74adc67a36f60413d0efcd23d72b12566ddd2f (1,852 lines / 98,538 bytes).
    • Independent final research/coverage audit: GO, P0/P1/P2 = 0. The written roadmap is product-complete at specification level; implementation and release remain in progress.

    Frozen dependency order:
    local restore/integration -> One-Tap -> Report + immutable corrections/archive -> Pace/reminders -> Quick Surfaces/Timer -> optional platform trains.

    Key corrections captured before code:

    • exactly three promoted App Shortcuts remain; timer controls are private system actions and never auto-create ledger time;
    • widget/control extension never becomes a second ledger writer and sees only a fail-private redacted sidecar;
    • V3/backup-v2 cannot migrate or ship alone; F1/F1b land only with a selected V3-dependent capability and complete versioned restore;
    • V2 CSV import and local-bundle migration remain independent on the accepted password-free backup-v1/M3 restore contract;
    • every multi-head conflict consumer is defined: reports, service-year archive, pace, reminders, widget, One-Tap, Watch, CSV, backup, imports and ordinary totals fail closed rather than present a provisional branch as truth;
    • sync derives pending uploads from the immutable graph and advances remote tokens only after durable repository commit/readback;
    • backup-confidence evidence is version-aware; unresolved timer state blocks restore.

    No product code, Git branch, Apple account, signing, CloudKit, physical device, or real ledger was changed by these specification lanes. Owner gates remain explicit for App Group/App ID/iCloud, membership if ever chosen, signing/device canaries, Watch, TestFlight/App Store, CloudKit production, and any real-ledger migration.

  12. kiku-jw commented on Aug 3, 2026

    @kiku-jw
    MemberAuthor

    Restore M3a journal correction accepted

    The bounded correction for the exact-A journal contract is now published.

    • Corrected M3b spec SHA-256: d240e1e2fc5a38dbfebde5b1973e7d4b64dd914139db829b38a800ab4a55dd20
    • Commit: 19591ab9c29ccb7ffa670626aa01e06776b0c16a
    • Branch: codex/hourleaf-restore-journal-correction
    • Parent fresh combined restore tests: 52/52 passed
    • Worker focused journal tests: 34/34 passed
    • Worker Debug and generic Release builds: passed
    • Source SHA-256: 52df26d17a244aa8f7ce7ee453f6d2b4b1fb9bb40087c300691485e489716fd5
    • Test SHA-256: 8208375c9114e8643eb4b7968061cfd6bafff41fe66eb295b2a325ea22a917a5
    • Diff scope: exactly RestoreJournal.swift and RestoreJournalTests.swift
    • Device ledger: not touched

    This supersedes the earlier M3b spec revision. The review loop is closed: implementation proceeds against the frozen hash above; non-critical follow-ups go to backlog instead of reopening the specification.

  13. kiku-jw commented on Aug 3, 2026

    @kiku-jw
    MemberAuthor

    Restore M3b accepted and published

    Crash-safe restore confirmation and startup recovery are now committed.

    • Commit: a0ef413d6f3b1f54cd287814d5905902846560f1
    • Branch: codex/hourleaf-restore-v1
    • Frozen spec SHA-256: d240e1e2fc5a38dbfebde5b1973e7d4b64dd914139db829b38a800ab4a55dd20
    • Parent fresh relevant restore suite: 65/65 passed
    • Worker focused suite: 13/13 passed
    • Parent unsigned generic iOS Release build: passed
    • Parent Analyze: passed
    • git diff --check: clean
    • Protected M3a hashes remain exact
    • Physical device and real ledger: not touched

    Accepted behavior includes direct exact-A recovery for all three pre-replacement phases, maintenance writer/readiness gating through reminder reconciliation and the final terminal readback, idle completed-residue cleanup before normal runtime creation, and fail-closed A-or-critical rollback.

    Next executable step is integration with the accepted UX/Data Management/local-only stack. That merge must retain restore APIs while preserving cloudSyncEnabled: false, no iCloud/Push entitlements, and Core Data models with usedWithCloudKit=NO.

  14. kiku-jw commented on Aug 3, 2026

    @kiku-jw
    MemberAuthor

    Restore integration is now published on codex/hourleaf-one-tap-v1 at cd16866ea9e72e8980f74da75d9ef77206f0ab7e.

    Evidence:

    • accepted local-only restore branch merged with the app runtime, Data Management navigation/actions, post-restore refresh, recovery bootstrap, and localized maintenance/recovery copy
    • pre-final-test-addition unit run: 176/176 passed (/tmp/hourleaf-integration-unit.zyhOq0/UnitTests.xcresult)
    • the two final AppModel tests and the Luna-authored Settings → Data Management UI test compile successfully
    • unsigned generic iOS Debug build passed (/tmp/hourleaf-integration-compile.iO9yTG)
    • unsigned generic iOS Release build passed (/tmp/hourleaf-integration-release-final)
    • Xcode Analyze passed (/tmp/hourleaf-integration-analyze-final)
    • localization plists lint and RU/UK/EN key parity passed; git diff --check clean
    • remote branch readback equals the commit above

    Honest limitation: after the earlier 195/195 merged baseline and 176/176 wired unit run, CoreSimulator began hanging before test code execution at waiting for workers to materialize. Repeating on other simulators and restarting CoreSimulator reproduced the same Xcode runner failure, so the final added tests are compile-verified but not execution-verified. No physical iPhone, signing, install, CloudKit, or user ledger was touched.

  15. kiku-jw commented on Aug 3, 2026

    @kiku-jw
    MemberAuthor

    Slice 6 One-Tap v1 published

    Commit 167419f58455fb27e8bd4b573b9a8aa90df838c4 is published on codex/hourleaf-one-tap-v1.

    Evidence:

    • derived Repeat last entry copies only kind and minutes, writes today with no note and .appOneTap, and reuses existing Undo
    • deterministic latest-active selector, stale proposal no-write, double-tap guard, credit preservation, over-600 behavior and exact replay are covered by 16 domain/AppModel tests
    • frozen backup v1 round-trip preserves .appOneTap, nil note, exact minutes and create revision
    • one combined UI flow covers hidden/visible action, repeat, manual draft preservation, Undo and note privacy; accessibility XXXL plus exact Russian/Ukrainian labels also compile
    • final generic Simulator test build succeeded at /tmp/hourleaf-one-tap-final-testbuild
    • unsigned generic iOS Release succeeded at /tmp/hourleaf-one-tap-final-release
    • Xcode Analyze succeeded at /tmp/hourleaf-one-tap-final-analyze
    • EN/RU/UK localization lint and 200-key parity passed
    • V1/V2 model hashes remain dbfcef97... and 69d8472b...; project, schema, backup production format, entitlements and App Intents are unchanged; exactly three App Shortcuts remain

    The Simulator test runner was not retried because the existing Xcode/CoreSimulator failure occurs before test code materializes. No physical device, signing, account, iCloud or user ledger was touched. Next implementation slice: Report Readiness and immutable report/archive corrections.

  16. 106 remaining items

  17. kiku-jw commented on Aug 30, 2026

    @kiku-jw
    MemberAuthor

    App Store campaign preparation — 2026-08-30

    App Store Connect generated and returned the four fixed-cohort links registered for the owned-surface experiment:

    • web-en: https://apps.apple.com/app/apple-store/id6801032003?pt=129302835&ct=web-en&mt=8
    • web-ru: https://apps.apple.com/app/apple-store/id6801032003?pt=129302835&ct=web-ru&mt=8
    • web-uk: https://apps.apple.com/app/apple-store/id6801032003?pt=129302835&ct=web-uk&mt=8
    • github: https://apps.apple.com/app/apple-store/id6801032003?pt=129302835&ct=github&mt=8

    The public Hourleaf README now uses github at e4a78b3; live GitHub readback confirms the exact URL. Draft kikuai.dev PR #91 uses the matching EN/RU/UK tokens at f7dd3b4; Cloudflare passed and fresh preview readback confirmed HTTP 200 plus each expected token. The site remains draft.

    The experiment is prepared, not active. Its 30-day clock starts only after Hourleaf 1.0.5 (18) is publicly available and PR #91 is merged/live. Any earlier github campaign activity must be excluded by date from the observation window.

  18. kiku-jw commented on Aug 30, 2026

    @kiku-jw
    MemberAuthor

    Authenticated App Store Connect baseline readback for the registered experiment: Campaigns, all app download dates, 23–29 Aug 2026 (UTC-day reporting), reports “Insufficient data to show campaigns.” This is a measured unreportable baseline, not a measured zero. The post-activation observation must use its own date window after all four links and Hourleaf 1.0.5 are public.

  19. kiku-jw commented on Aug 30, 2026

    @kiku-jw
    MemberAuthor

    1.0.5 source CI and isolated device install — 2026-08-30

    • Exact main commit e4a78b3 passed CI run 33330045776.
    • Release guard and guard self-test passed.
    • Unit/integration: 531/531; app-owned UI: 53/53; zero failures.
    • Apple Developer now has a dedicated group.com.kikuai.hourleaf.local App Group assigned only to com.kikuai.hourleaf.local and its quick-surfaces extension.
    • Xcode regenerated development profiles for both local targets; entitlement readback contains exactly group.com.kikuai.hourleaf.local.
    • The isolated iPhone build installed successfully and device readback reports com.kikuai.hourleaf.local as 1.0.5 (18).
    • No previous local test bundle existed, and the production com.kikuai.hourleaf ledger was not read, replaced, or removed.

    Physical UI acceptance, Watch installation/direct entry, signed production archive, upload, and submission remain open gates.

  20. kiku-jw commented on Aug 30, 2026

    @kiku-jw
    MemberAuthor

    Hourleaf 1.0.5 (19) App Review submission — 2026-08-30

    • Shipping source is 2184275; 568526d changes only UI-test interaction. Release receipt is committed on main at 3617106.
    • The retained signed archive is Hourleaf 1.0.5 (19).xcarchive and contains the iPhone app, WidgetKit extension, and embedded Apple Watch app, all at 1.0.5 (19).
    • App Store Connect processed build 19, attached it to iOS 1.0.5, saved EN/RU/UK release notes and current review information, and accepted submission c3e3fbfd-a784-4e49-90f7-172d7b9b4b0d at 23:59 EEST.
    • Fresh App Store Connect readback shows Waiting for Review, one submitted object, and zero drafts.
    • Automatic release after approval remains enabled; distribution is immediate to all users and the current rating is preserved.
    • The owner accepted current app behavior and explicitly ended additional optional phone and CI canaries. No further test cycle is a release gate.

    Next actor is Apple. Public availability remains separate from review status. After 1.0.5 is publicly returned by Apple, merge kikuai.dev PR #91, verify the EN/RU/UK campaign links live, publish the GitHub 1.0.5 release, and start the registered 30-day attribution window.

  21. kiku-jw commented on Aug 31, 2026

    @kiku-jw
    MemberAuthor

    Hourleaf 1.0.5 public activation — 2026-08-31

    • Apple public lookup now returns 1.0.5 with release timestamp 2026-08-31T13:23:12Z in the US, Lithuania, and Ukraine. This closes public availability separately from App Review submission.
    • kikuai.dev PR #91 merged at 2026-08-31T17:18:35Z as 63006ac. Cloudflare production deployment 1bd00c3f-3216-465c-a5b2-c864e0386e2f became active.
    • Fresh live readback returned HTTP 200 for English, Russian, Ukrainian, and /hourleaf.md. Each localized page contains its exact web-en, web-ru, or web-uk campaign token; the Markdown facts page returns text/markdown and identifies public version 1.0.5.
    • GitHub release v1.0.5 was published at 2026-08-31T17:27:43Z. Its tag points to exact shipping source 2184275, and its App Store link uses campaign token github.

    The registered zero-cost attribution window activated at 2026-08-31T17:28:13Z, after all four owned links were live. It ends at 2026-09-30T17:28:13Z; the first readback is scheduled for 2026-09-07T17:28:13Z. Any github activity before activation must be excluded. The pre-activation App Store Connect baseline remains measured but unreportable (Insufficient data), not zero.

  22. kiku-jw commented on Sep 1, 2026

    @kiku-jw
    MemberAuthor

    Implemented the previous-month report direct-send flow in a2b302f, with final button copy refined in cff823f.

    • The Add-screen report prompt now offers Send alongside optional review.
    • The Progress report card offers the same direct action for ready or changed reports.
    • Choosing Send creates the immutable snapshot, marks it sent immediately, and then opens the system share sheet. The UI states this consequence explicitly, so cancelling the share sheet does not silently change the contract.
    • Updated EN/RU/UK copy, reminder wording, screenshot source copy, and regression coverage.

    Verification: xcodebuild -project Hourleaf.xcodeproj -scheme Hourleaf -destination "generic/platform=iOS Simulator" -derivedDataPath <temporary> CODE_SIGNING_ALLOWED=NO build-for-testing — TEST BUILD SUCCEEDED. Localization plists, screenshot JSON, and git diff --check also passed. No physical device or simulator UI run was used.

    Pushed to origin/main. App Store release was not started by this change.

  23. kiku-jw commented on Sep 1, 2026

    @kiku-jw
    MemberAuthor

    Hourleaf 1.0.6 (20) is submitted to App Review.

    • Shipping source: 1809aa83f0264b2a9f70bb79c976ca840aaf4cce; durable submission receipt: f962021.
    • Retained signed archive: ~/Library/Developer/Xcode/Archives/2026-09-01/Hourleaf 1.0.6 (20).xcarchive.
    • Xcode upload succeeded; App Store Connect processed build 20 and assigned it to Hourleaf Internal.
    • EN/RU/UK release notes and build-20 review notes are saved; build 20 is attached to version 1.0.6.
    • Submission 5fa95a97-2118-4eef-b015-0c9f3b123812 contains exactly one object, iOS 1.0.6 (20), and displays Waiting for Review; draft count is zero.
    • Automatic release after approval, immediate availability to all users, and preservation of the current rating are selected.
    • Focused report-model verification passed 7/7. The known aggregate CI boundary is documented in AppStore/release-checklist.md; no additional broad test loop was run per owner direction.

    Next actor: Apple App Review. Public 1.0.6 availability and matching site/GitHub release remain separate gates.

  24. kiku-jw commented on Sep 3, 2026

    @kiku-jw
    MemberAuthor

    Hourleaf 1.0.6 public completion — 2026-09-03

    • Apple official lookup returns 1.0.6, bundle com.kikuai.hourleaf, and release timestamp 2026-09-02T13:41:04Z in the US, Lithuania, and Ukraine; all three product pages return HTTP 200.
    • GitHub release v1.0.6 is public and points exactly to shipping source 1809aa83f0264b2a9f70bb79c976ca840aaf4cce.
    • kikuai.dev PR #95 merged as f958c1c1e4fe9274f3f4f3d6e9d275c3d91acb3b; Cloudflare production deployment 4aef03b5-1fbb-4330-8ce0-6a9d244547d9 completed successfully at 2026-09-03T21:04:44Z.
    • Fresh production readback passed for EN, RU, UK, and agent-readable facts. Every route returns HTTP 200, identifies 1.0.6, describes direct Send without claiming delivery proof, and preserves its exact owned campaign token.
    • Setup guides in all three languages plus privacy and support pages also return HTTP 200.
    • Durable release receipt is on Hourleaf main at cf03c01. No additional app test or physical-device cycle was run during public reconciliation, per owner direction.

    Release work is complete. The existing zero-cost campaign measurement remains active through 2026-09-30, with the first scheduled readback due 2026-09-07.

  25. kiku-jw commented on Sep 6, 2026

    @kiku-jw
    MemberAuthor

    Campaign pre-readback verification — 2026-09-07T00:07:26+03:00

    • The published web-en, web-ru, web-uk, and github App Store campaign URLs were checked individually. Each returned HTTP 200 and preserved its exact ct token in the final App Store URL.
    • A web-uk request returned HTTP 429 only during the initial four-link burst; an isolated retry returned HTTP 200 with ct=web-uk. This is Apple request throttling, not evidence of a broken owned link, so no link correction was made.
    • Live EN/RU/UK KikuAI pages still embed their matching campaign token; the GitHub README and v1.0.6 release still use ct=github.
    • The stale portfolio-map version was corrected from 1.0.5 to the already-proven public 1.0.6 at kiku-jw/kikuai-project-map@9806747. The map continues to state that installs, repeat use, external demand, and revenue are unverified.

    The registered first attribution readback remains due at 2026-09-07T17:28:13Z (20:28:13 EEST). No App Store Connect metrics were read early, no unavailable value was recorded as zero, and no campaign, monitor, Store setting, outreach, spend, device, or product behavior changed.

  26. kiku-jw commented on Sep 8, 2026

    @kiku-jw
    MemberAuthor

    First campaign attribution readback — 2026-09-08T10:37:36Z

    Source: App Store Connect → Hourleaf → Analytics → Acquisition → Campaigns.

    • Report range: 31 Aug–6 Sep 2026, the latest complete seven-day range available in Apple reporting.
    • App download date filter: All.
    • Apple displays the exact state: “Недостаточно данных, чтобы показать кампании.” (Insufficient data to show campaigns.)
    • No campaign rows or attributable product-page views, first-time downloads, or conversion rates are exposed for web-en, web-ru, web-uk, or github.
    • These values are unknown/unreportable, not zero. The UTC-day bucket for 31 August overlaps the activation timestamp, but because Apple exposes no attributed values, no pre-activation github activity was counted or inferred.
    • No campaign link, Store setting, site, outreach, spend, device, or app behavior changed.

    Experiment state: WAIT. The fixed observation window remains 2026-08-31T17:28:13Z through 2026-09-30T17:28:13Z. Next unchanged readback: 2026-09-14; final decision only after the 30-day window matures.

  27. kiku-jw commented on Sep 29, 2026

    @kiku-jw
    MemberAuthor

    Campaign closeout and product decision — 2026-09-29

    The owner asked to end the zero-cost owned-link experiment now. The latest complete App Store Connect range available was 31 Aug–28 Sep 2026, App Download Date = All.

    Evidence

    • Overall Hourleaf acquisition for that range: 51 product-page views and 9 first-time downloads.
    • Campaigns still displays “Недостаточно данных, чтобы показать кампании.”
    • Apple documents that a campaign appears only after at least 5 first-time downloads from individual users. Therefore none of web-en, web-ru, web-uk, or github crossed the reporting threshold. Per-channel values below that threshold remain unknown, not zero.
    • The 31 Aug UTC bucket partly predates the 2026-08-31T17:28:13Z activation, and Apple exposes no campaign rows, so the nine overall downloads cannot honestly be attributed to the experiment.
    • This is an owner-authorized early close one day before the planned 30-day endpoint; 28 Sep is the latest complete reporting day.

    Verdict: UNPROVEN / INSUFFICIENT REACH. The experiment does not demonstrate a bad product page or zero interest. It demonstrates that the four passive owned surfaces did not generate enough attributable volume for Apple to expose channel metrics.

    Apple reference: https://developer.apple.com/help/app-store-connect-analytics/acquisition/campaign-links

    Product and monetization decision

    Current category evidence shows that monetization is possible mainly for broader ministry suites with CRM-like planning, maps, contacts, timers, and other high-maintenance features. Hourleaf's differentiated value is the opposite: a calm, private, Apple-native hours/reporting utility.

    Decision:

    • Keep the Hourleaf core free, ad-free, tracking-free, and without subscription or donation prompts.
    • Do not run paid acquisition or congregation-style outreach. Continue only honest App Store metadata/localization, the existing kikuai.dev guides, GitHub, and context-appropriate word of mouth.
    • Treat Hourleaf as a useful public engineering/portfolio case study: SwiftUI, Watch, Siri/App Intents, offline-first persistence, accessibility, localization, backups, and App Store delivery.
    • If commercial value is desired later, validate a separately branded, nonreligious time/goal tracker built from generic components. Do not turn Hourleaf users or ministry data into a lead funnel.
    • Revisit monetization only if organic usage produces materially stronger evidence or the separate general-purpose product is validated independently.

    This choice also avoids unnecessary EU trader overhead. Apple's current DSA guidance says a hobby app with no commercialization intent may be a non-trader, while revenue, paid/IAP/ad-supported distribution, or commercial promotion are factors that can indicate trader status:
    https://developer.apple.com/help/app-store-connect/manage-compliance-information/manage-european-union-digital-services-act-trader-requirements

    50-hour celebration

    Published to main at 193827d:

    • combines current-month service and credit minutes;
    • triggers when the total crosses 50 hours;
    • celebrates once per month, including after delete/re-add cycles;
    • does not replay old milestones after an update, startup, or backup restore;
    • shows short native confetti plus localized EN/RU/UK congratulations;
    • respects Reduce Motion and posts a VoiceOver announcement;
    • stores only presentation state in UserDefaults, outside the ledger and backups.

    Verification:

    • xcodebuild -project Hourleaf.xcodeproj -scheme Hourleaf -destination 'generic/platform=iOS' -derivedDataPath <temporary> CODE_SIGNING_ALLOWED=NO build-for-testing -quiet — passed; app, Watch, extensions, and tests compiled.
    • EN/RU/UK localization lint — passed.
    • git diff --check — passed.
    • No simulator runtime is installed, so the new tests compiled but were not executed. No iPhone, Watch, signing state, or App Store version was touched.
  28. kiku-jw commented on Sep 29, 2026

    @kiku-jw
    MemberAuthor

    Hourleaf 1.0.7 (21) submitted to Apple on 2026-09-30. Exact shipping source: 989c1a9; release receipt: 4a546fd. Xcode archive/export/upload succeeded; App Store Connect processed build 21, assigned it to Hourleaf Internal, accepted EN/RU/UK release notes and reviewer notes, and displayed Waiting for Review after Submitted items: 1. Automatic release after approval and immediate rollout are selected. Four new milestone tests passed; the full hosted suite retains the same date-sensitive baseline failures as 1.0.6 (24 unit and one UI), so it is not green. Public 1.0.7 availability, website update, and GitHub release remain pending storefront confirmation.

  29. kiku-jw commented on Sep 30, 2026

    @kiku-jw
    MemberAuthor

    Release follow-up, 2026-09-30 05:17 UTC window: official Apple lookup still returns Hourleaf 1.0.6 (com.kikuai.hourleaf) in US, LT and UA. App Store Connect redirected the authenticated review check to sign-in with an expired/failed session, so the current review state of 1.0.7/build 21 is unverified; this is not evidence of rejection. The browser sign-in page is left for owner reauthentication. No GitHub release, site version claim, Store setting, app data or physical device was changed. Next action: owner signs in to App Store Connect, then resume review/public-store verification. Shipping source remains 989c1a9.

  30. kiku-jw commented on Sep 30, 2026

    @kiku-jw
    MemberAuthor

    Owner reauthentication confirmed on 2026-09-30. Fresh App Store Connect readback shows iOS 1.0.7 Waiting for Review with build 21 selected, automatic release after approval and immediate rollout enabled. No resubmission is needed. Official Apple lookup still returns public 1.0.6 in US, LT and UA. The authentication blocker is resolved; next actor is Apple App Review. GitHub v1.0.7 and EN/RU/UK site updates remain conditional on approval plus public storefront confirmation. No Store setting, app data or physical device was changed.

  31. kiku-jw commented on Sep 30, 2026

    @kiku-jw
    MemberAuthor

    Hourleaf 1.0.7 (21) — public release verified

    Apple has approved this release. Fresh authenticated App Store Connect readback shows iOS 1.0.7 Ready for Distribution with build 21 and automatic release selected.

    Public evidence

    • The US, Lithuanian, and Ukrainian product pages return HTTP 200 and show current version 1.0.7, released 2026-09-30T16:44:32Z. The Apple lookup API initially lagged at 1.0.6 for US/LT while UA returned 1.0.7; the later product-page readback confirms all three.
    • GitHub release v1.0.7 is published, not draft or prerelease. The tag resolves exactly to shipping source 989c1a9, not a later documentation commit.
    • kikuai.dev main commit 229f10f28e0fc52fa89d54ccb912a63a947dafe0 deployed successfully through the existing Cloudflare Pages workflow at 2026-09-30T17:30:40Z.
    • Live English, Russian, Ukrainian, and Markdown facts routes all return HTTP 200 and identify 1.0.7. The localized copy describes the 50-hour service-plus-credit celebration; the exact web-en/web-ru/web-uk campaign links remain intact. The facts still distinguish this monthly celebration from the service-only 600-hour goal.

    Verification and durable state

    • Website: all 6 focused Hourleaf public-page tests pass; production build succeeds with 366 prerendered routes.
    • Release checklist updated and pushed on main in a5419e2. Earlier full-suite limitations remain recorded; this reconciliation does not claim a new full app-test pass.
    • Portfolio map updated and pushed on main in ede84aa, preserving the free/ad-free/tracking-free maintenance positioning and the unproven distribution-experiment outcome.
    • Diff and publication checks passed. All three task checkouts were clean after their pushes; no credentials or private records were added.
    • No app source, app data, schema, signing configuration, or physical device was touched. No additional device-test cycle was started.

    The requested 1.0.7 public-release reconciliation is complete. No remaining release action is required from Nick. The broader roadmap issue stays open; the dedicated 1.0.7 follow-up can stop.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions