Repository navigation
Hourleaf product roadmap — trust, speed, Shortcuts, and release #3
Description
Activity
Roadmap preflight on 2026-08-02:
- Verified owner/root: /Users/nick/Documents/HoursJW -> https://github.com/KikuAI-Lab/Hourleaf.git.
- main is clean and synchronized at 4b76a0e.
- Fresh full simulator baseline passed: 15 unit/integration + 13 UI tests, 28/28 total, on iPhone 17 Pro / iOS 26.5.
- Current build has no AppIntents.framework dependency or App Shortcuts metadata yet.
- Native prior-art check supports using Core Data persistent-store replacement plus AppShortcutsProvider without third-party backup/shortcut dependencies.
- Sol Max specification lane is active; code execution has not started.
Slice 1 accepted and published to
mainat12706b0.Evidence:
- 32/32 unit and integration tests passed after integration into
main. - 13/13 full UI tests passed; 3 report-boundary UI checks were rerun on the final code.
- Unsigned generic-device Debug and Release builds passed.
- The V1 Core Data model is byte-for-byte unchanged; V2 is additive and current.
- Migration normalization is strict, idempotent and count/readback verified; malformed required data fails visibly instead of being dropped.
- Store-load failure, stale report inputs, concurrent settings saves and immutable report receipts have regression coverage.
- Sol Max adversarial review verdict: GO; no P0/P1/P2 findings.
The physical iPhone was not installed or mutated. Portable backup plus verified restore remains the gate before any model-changing device install.
Next active slice: shared mutation commands, replay safety, optimistic revisions, soft delete, Recently Deleted, and ten-minute Undo.
- 32/32 unit and integration tests passed after integration into
Slice 5 execution contract — restore and Data Management
Accepted base:
10c51b2.- Scope is local-only single-store restore. Cloud-backed or multi-store configurations are rejected before staging; Hourleaf never turns iCloud off automatically.
- A selected
.hourleafbackupis copied into bounded app-owned protected staging, decoded by the frozen v1 codec, imported into a fresh current-model temporary SQLite store, closed/reopened, and accepted only when raw and domain readbacks preserve the incoming digest. - Preview is read-only and shows understandable counts/date range before confirmation. Confirm replaces the whole ledger; there is no merge, password, or typed phrase.
- Every app and App Intent writer is stopped by one repository maintenance lease. Before replacement, Hourleaf creates and rereads an exact portable backup of state A plus coordinator-created old-store evidence.
- Store transitions use Core Data coordinator copy/replace/destroy APIs only. SQLite, WAL, and SHM files are never copied or deleted manually.
- A protected journal and armed marker guarantee restart resolves to exact A or exact B, never a mixture. Corrupt or unknown recovery state blocks normal store loading and preserves evidence.
- All app-owned backup, staging, journal, temporary-store, old-store and CSV files are protected before their first byte; signed-device attribute readback remains a disposable-canary gate.
- Settings gains one progressively disclosed row for Backup and export. Copy is plain RU/UK/EN, warns that the password-free file and notes are readable, states that restore replaces everything, and explains that CSV is spreadsheet-only.
- CSV exports active entries only, with notes opt-in and off by default.
- The physical
com.kikuai.hourleaf.localledger remains untouched until simulator fault tests, Sol review, and a separately signed disposable roundtrip all pass.
Slice 5 M1 checkpoint accepted and published on
codex/hourleaf-restore-v1at6d647753a76d094d4b830679112440a4fee1b133.Evidence:
- independent
LedgerMaintenanceTests: 7/7 passed on iPhone 17 Pro Simulator (/tmp/hourleaf-m1-rereview.TC2Lx7/LedgerMaintenance.xcresult); - adversarial re-review: GO, P0/P1/P2 = 0;
- exact-A final digest and store removal now share one Core Data coordinator barrier;
- writers before the barrier abort close; writers after it cannot land before removal;
- failed fresh reopen remains retryable;
- destructive store cleanup accepts only the exact owned typed staging artifact;
- Core Data model, project, entitlements and privacy manifest unchanged.
Next: bounded staged import and all-ten-entity temp-store validation, followed by journaled confirm/recovery. CSV and Data Management UI remain in a separate reviewed lane. No physical iPhone app or ledger was touched.
- independent
Slice 5 Data Management component lane accepted and published on
codex/hourleaf-data-management-uiat8ece9f554c1b16f5be0adfb62dd5a29a62f120bb.Evidence:
- independent focused CSV/UI-state run: 14/14 passed (
/tmp/hourleaf-csv-ui-rereview.7ewRma/CSVExporter.xcresult); - worker full unit target: 110/110; Debug build and RU/UK/EN localization lint passed;
- adversarial re-review: GO, P0/P1/P2 = 0;
- deterministic active-only CSV uses BOM, RFC 4180, CRLF and note opt-in;
- app-owned share artifacts have idempotent cleanup on completion/cancel/dismiss;
- restore controls are explicitly unavailable while iCloud sync is active;
- restore/disappear state cannot discard a candidate concurrently with replacement;
- plain password-free backup and CSV note privacy warnings are present.
This branch is deliberately not wired into Settings/AppModel yet; integration waits for the restore backend contract. Physical file-protection proof remains a disposable signed-device gate, and the real iPhone ledger remains untouched.
- independent focused CSV/UI-state run: 14/14 passed (
Roadmap completeness audit (research reports 25-28 + PRO recommendation + accepted product contract): no missing P0 feature was found before safe restore. Accepted post-Slice-5 order remains:
- One-Tap v1: one derived
Repeat last entryaction only; latest active record, kind+minutes only, today, no note,.appOneTap, existing Undo. No presets or fourth promoted Shortcut tile. - Report Readiness and immutable corrections/service-year close.
- Calm service-only pace to 600, never capped and excluding credit.
- Opt-in actionable reminders, then backup-confidence status and privacy-safe quick surfaces.
- Timer/Watch/imports/iCloud remain later gated work.
Deliberate non-features: backup password/recovery key, adaptive suggestions, automatic time creation, zero-time entries, streaks/badges, CRM, PDF without evidence, and Cloud sync as a backup substitute.
Trust correction required before production signing: local-only must be the truthful default while Settings says sync is planned. Future iCloud sync must be an explicit opt-in with conflict/restore semantics, never silently enabled. This does not alter the current Personal Team local ledger and requires no account action now.
- One-Tap v1: one derived
Slice 5 M2 accepted and published on
codex/hourleaf-restore-v1atb29fb4e35ea6f292c64b5c8552a540e49f850861.Evidence:
- independent
HourleafRestorePreparationTests: 11/11 passed at/tmp/hourleaf-slice5-m2-20260803-051954.xcresult; - final combined M2 + M1: 18/18 passed; no SQLite vnode-unlinked warnings after the test-lifetime fix;
- Sol Max adversarial review: GO, P0/P1/P2 = 0;
- selected backup is coordinated and bounded, imported across all 10 raw entities, reopened, and accepted only when raw/domain/raw digests remain exact;
- private-cloud and in-memory stores reject before staging; preview never mutates live data;
- deterministic typed staging cleanup follows the documented Core Data truncate contract, proves the old store UUID and all model records are gone, survives split cleanup faults and process restart, and never manually deletes SQLite/WAL/SHM;
- protected model, managed objects, project, entitlements, privacy manifest, and frozen backup v1 codec/exporter are unchanged.
Next checkpoint: journaled confirm, exact pre-restore A backup/evidence, whole-store replacement, A-or-B crash recovery, and reminder rescheduling. Physical iPhone data remains untouched.
- independent
UX minimalism slice accepted and published.
- Branch: codex/hourleaf-ux-minimalism
- Commit: 7aa67c8
- Removes the decorative onboarding hero and keeps one concise explanation.
- Clarifies editable credit-label intent, minute-handling examples, pre-Hourleaf time, and plain-language privacy copy in EN/RU/UK.
- Removes the misleading storage/sync row until the truthful local-only runtime slice lands.
- Preserves the safe 0:00 edit confirmation and soft-delete flow.
Verification:
- independent review: GO, P0/P1/P2 = 0
- localization plist/key parity and git diff check: pass
- exact three promoted Shortcuts: pass
- onboarding UI: pass
- zero-duration edit/delete UI: pass
- Settings UI copy: pass
This branch is intentionally isolated and will be integrated after restore M3.
Truthful local-only checkpoint accepted and published on branch codex/hourleaf-local-truth at e2e7e3e.
Evidence:
- Runtime storage is local by default in every build; CloudKit remains possible only through a future explicit opt-in and migration gate.
- Shipping iCloud and Push capabilities, CODE_SIGN_ENTITLEMENTS, and the CloudKit entitlement file are removed; Debug and Release build settings expose no iCloud or Push entitlement.
- Core Data V1/V2 compiled model bytes and version checksums are identical before and after the IDE CloudKit flag correction, so the existing SQLite path/schema is not split.
- Fresh unsigned generic-device Debug and Release builds passed.
- Full simulator suite passed 116/116; after the final Settings cleanup, the affected UI test passed again 1/1. RU/UK/EN plist and key parity checks passed.
- Sol Max independent review: GO, P0/P1/P2 = 0.
- Settings no longer exposes the misleading storage/sync row, and privacy copy says plainly that records stay on this iPhone.
No installer or physical device command was run, and the real iPhone ledger remains untouched. If real CloudKit use were ever discovered despite the canonical history, a separate drain/migration canary remains mandatory before rollout.
Restore M3a is frozen, independently accepted, and published.
- Branch:
codex/hourleaf-restore-v1 - Commit:
17fe55677663b9c67f01fb0d6d7f64dfe72eda44(Add crash-safe restore journal) - Scope: checksummed crash journal and marker, exact A/B terminal decision matrix, protected bounded pre-restore backup evidence, hard-link final/partial crash-window handling, proof-gated cleanup, and idempotent preflight.
- Focused M2 + M3a verification: 35/35 passed, 0 failures/skips. Result bundle:
/tmp/hourleaf-m3a-accept.KWOE9x/Logs/Test/Test-Hourleaf-2026.08.03_07-43-14-+0300.xcresult. - Independent worker verification: 35/35 passed. Result bundle:
/tmp/hourleaf-restore-m3b-freeze/Logs/Test/Test-Hourleaf-2026.08.03_07-42-27-+0300.xcresult. - Generic iOS device builds with signing disabled: Debug succeeded at
/tmp/hourleaf-m3a-debug.tZ2MPv; Release succeeded at/tmp/hourleaf-m3a-release.Xtjqw1. - Independent Sol review: GO, P0 0 / P1 0 / P2 0.
- Frozen source hashes:
RestoreJournal.swift=11849b39bcaa5d57ec9693f25e7746c8266ea920a1c0e54df741ae463037ac42;RestoreJournalTests.swift=e9b7a5ed7c355265d7ef5e7b2b8b05592fcc558770396e6be44229ec6ccce995. - Remote readback matches local commit exactly; worktree is clean.
No physical-device install, signing, or real Hourleaf ledger mutation was performed. M3b coordinator integration remains next; it must preserve actor serialization and produce terminal proof only after fresh Core Data readback.
- Branch:
Roadmap specification coverage is now frozen and independently accepted.
- Quick Surfaces + Timer v1: SHA-256
a4973c59fdefbe975c6d06566bfc9fa0851487915296bd2f0e7fa3fd76e51fa2(1,135 lines / 65,732 bytes). - Platform Expansion v1: SHA-256
0fd0085af855e88178d74103ba74adc67a36f60413d0efcd23d72b12566ddd2f(1,852 lines / 98,538 bytes). - Independent final research/coverage audit: GO, P0/P1/P2 = 0. The written roadmap is product-complete at specification level; implementation and release remain in progress.
Frozen dependency order:
local restore/integration -> One-Tap -> Report + immutable corrections/archive -> Pace/reminders -> Quick Surfaces/Timer -> optional platform trains.Key corrections captured before code:
- exactly three promoted App Shortcuts remain; timer controls are private system actions and never auto-create ledger time;
- widget/control extension never becomes a second ledger writer and sees only a fail-private redacted sidecar;
- V3/backup-v2 cannot migrate or ship alone; F1/F1b land only with a selected V3-dependent capability and complete versioned restore;
- V2 CSV import and local-bundle migration remain independent on the accepted password-free backup-v1/M3 restore contract;
- every multi-head conflict consumer is defined: reports, service-year archive, pace, reminders, widget, One-Tap, Watch, CSV, backup, imports and ordinary totals fail closed rather than present a provisional branch as truth;
- sync derives pending uploads from the immutable graph and advances remote tokens only after durable repository commit/readback;
- backup-confidence evidence is version-aware; unresolved timer state blocks restore.
No product code, Git branch, Apple account, signing, CloudKit, physical device, or real ledger was changed by these specification lanes. Owner gates remain explicit for App Group/App ID/iCloud, membership if ever chosen, signing/device canaries, Watch, TestFlight/App Store, CloudKit production, and any real-ledger migration.
- Quick Surfaces + Timer v1: SHA-256
Restore M3a journal correction accepted
The bounded correction for the exact-A journal contract is now published.
- Corrected M3b spec SHA-256:
d240e1e2fc5a38dbfebde5b1973e7d4b64dd914139db829b38a800ab4a55dd20 - Commit:
19591ab9c29ccb7ffa670626aa01e06776b0c16a - Branch:
codex/hourleaf-restore-journal-correction - Parent fresh combined restore tests: 52/52 passed
- Worker focused journal tests: 34/34 passed
- Worker Debug and generic Release builds: passed
- Source SHA-256:
52df26d17a244aa8f7ce7ee453f6d2b4b1fb9bb40087c300691485e489716fd5 - Test SHA-256:
8208375c9114e8643eb4b7968061cfd6bafff41fe66eb295b2a325ea22a917a5 - Diff scope: exactly
RestoreJournal.swiftandRestoreJournalTests.swift - Device ledger: not touched
This supersedes the earlier M3b spec revision. The review loop is closed: implementation proceeds against the frozen hash above; non-critical follow-ups go to backlog instead of reopening the specification.
- Corrected M3b spec SHA-256:
Restore M3b accepted and published
Crash-safe restore confirmation and startup recovery are now committed.
- Commit:
a0ef413d6f3b1f54cd287814d5905902846560f1 - Branch:
codex/hourleaf-restore-v1 - Frozen spec SHA-256:
d240e1e2fc5a38dbfebde5b1973e7d4b64dd914139db829b38a800ab4a55dd20 - Parent fresh relevant restore suite: 65/65 passed
- Worker focused suite: 13/13 passed
- Parent unsigned generic iOS Release build: passed
- Parent Analyze: passed
git diff --check: clean- Protected M3a hashes remain exact
- Physical device and real ledger: not touched
Accepted behavior includes direct exact-A recovery for all three pre-replacement phases, maintenance writer/readiness gating through reminder reconciliation and the final terminal readback, idle completed-residue cleanup before normal runtime creation, and fail-closed A-or-critical rollback.
Next executable step is integration with the accepted UX/Data Management/local-only stack. That merge must retain restore APIs while preserving
cloudSyncEnabled: false, no iCloud/Push entitlements, and Core Data models withusedWithCloudKit=NO.- Commit:
Restore integration is now published on
codex/hourleaf-one-tap-v1atcd16866ea9e72e8980f74da75d9ef77206f0ab7e.Evidence:
- accepted local-only restore branch merged with the app runtime, Data Management navigation/actions, post-restore refresh, recovery bootstrap, and localized maintenance/recovery copy
- pre-final-test-addition unit run: 176/176 passed (
/tmp/hourleaf-integration-unit.zyhOq0/UnitTests.xcresult) - the two final AppModel tests and the Luna-authored Settings → Data Management UI test compile successfully
- unsigned generic iOS Debug build passed (
/tmp/hourleaf-integration-compile.iO9yTG) - unsigned generic iOS Release build passed (
/tmp/hourleaf-integration-release-final) - Xcode Analyze passed (
/tmp/hourleaf-integration-analyze-final) - localization plists lint and RU/UK/EN key parity passed;
git diff --checkclean - remote branch readback equals the commit above
Honest limitation: after the earlier 195/195 merged baseline and 176/176 wired unit run, CoreSimulator began hanging before test code execution at
waiting for workers to materialize. Repeating on other simulators and restarting CoreSimulator reproduced the same Xcode runner failure, so the final added tests are compile-verified but not execution-verified. No physical iPhone, signing, install, CloudKit, or user ledger was touched.Slice 6 One-Tap v1 published
Commit
167419f58455fb27e8bd4b573b9a8aa90df838c4is published oncodex/hourleaf-one-tap-v1.Evidence:
- derived Repeat last entry copies only kind and minutes, writes today with no note and
.appOneTap, and reuses existing Undo - deterministic latest-active selector, stale proposal no-write, double-tap guard, credit preservation, over-600 behavior and exact replay are covered by 16 domain/AppModel tests
- frozen backup v1 round-trip preserves
.appOneTap, nil note, exact minutes and create revision - one combined UI flow covers hidden/visible action, repeat, manual draft preservation, Undo and note privacy; accessibility XXXL plus exact Russian/Ukrainian labels also compile
- final generic Simulator test build succeeded at
/tmp/hourleaf-one-tap-final-testbuild - unsigned generic iOS Release succeeded at
/tmp/hourleaf-one-tap-final-release - Xcode Analyze succeeded at
/tmp/hourleaf-one-tap-final-analyze - EN/RU/UK localization lint and 200-key parity passed
- V1/V2 model hashes remain
dbfcef97...and69d8472b...; project, schema, backup production format, entitlements and App Intents are unchanged; exactly three App Shortcuts remain
The Simulator test runner was not retried because the existing Xcode/CoreSimulator failure occurs before test code materializes. No physical device, signing, account, iCloud or user ledger was touched. Next implementation slice: Report Readiness and immutable report/archive corrections.
- derived Repeat last entry copies only kind and minutes, writes today with no note and
106 remaining items
App Store campaign preparation — 2026-08-30
App Store Connect generated and returned the four fixed-cohort links registered for the owned-surface experiment:
web-en:https://apps.apple.com/app/apple-store/id6801032003?pt=129302835&ct=web-en&mt=8web-ru:https://apps.apple.com/app/apple-store/id6801032003?pt=129302835&ct=web-ru&mt=8web-uk:https://apps.apple.com/app/apple-store/id6801032003?pt=129302835&ct=web-uk&mt=8github:https://apps.apple.com/app/apple-store/id6801032003?pt=129302835&ct=github&mt=8
The public Hourleaf README now uses
githubate4a78b3; live GitHub readback confirms the exact URL. Draft kikuai.dev PR #91 uses the matching EN/RU/UK tokens atf7dd3b4; Cloudflare passed and fresh preview readback confirmed HTTP 200 plus each expected token. The site remains draft.The experiment is prepared, not active. Its 30-day clock starts only after Hourleaf 1.0.5 (18) is publicly available and PR #91 is merged/live. Any earlier
githubcampaign activity must be excluded by date from the observation window.Authenticated App Store Connect baseline readback for the registered experiment: Campaigns, all app download dates, 23–29 Aug 2026 (UTC-day reporting), reports “Insufficient data to show campaigns.” This is a measured unreportable baseline, not a measured zero. The post-activation observation must use its own date window after all four links and Hourleaf 1.0.5 are public.
1.0.5 source CI and isolated device install — 2026-08-30
- Exact
maincommite4a78b3passed CI run33330045776. - Release guard and guard self-test passed.
- Unit/integration: 531/531; app-owned UI: 53/53; zero failures.
- Apple Developer now has a dedicated
group.com.kikuai.hourleaf.localApp Group assigned only tocom.kikuai.hourleaf.localand its quick-surfaces extension. - Xcode regenerated development profiles for both local targets; entitlement readback contains exactly
group.com.kikuai.hourleaf.local. - The isolated iPhone build installed successfully and device readback reports
com.kikuai.hourleaf.localas 1.0.5 (18). - No previous local test bundle existed, and the production
com.kikuai.hourleafledger was not read, replaced, or removed.
Physical UI acceptance, Watch installation/direct entry, signed production archive, upload, and submission remain open gates.
- Exact
Hourleaf 1.0.5 (19) App Review submission — 2026-08-30
- Shipping source is
2184275;568526dchanges only UI-test interaction. Release receipt is committed onmainat3617106. - The retained signed archive is
Hourleaf 1.0.5 (19).xcarchiveand contains the iPhone app, WidgetKit extension, and embedded Apple Watch app, all at 1.0.5 (19). - App Store Connect processed build 19, attached it to iOS 1.0.5, saved EN/RU/UK release notes and current review information, and accepted submission
c3e3fbfd-a784-4e49-90f7-172d7b9b4b0dat 23:59 EEST. - Fresh App Store Connect readback shows
Waiting for Review, one submitted object, and zero drafts. - Automatic release after approval remains enabled; distribution is immediate to all users and the current rating is preserved.
- The owner accepted current app behavior and explicitly ended additional optional phone and CI canaries. No further test cycle is a release gate.
Next actor is Apple. Public availability remains separate from review status. After 1.0.5 is publicly returned by Apple, merge kikuai.dev PR #91, verify the EN/RU/UK campaign links live, publish the GitHub 1.0.5 release, and start the registered 30-day attribution window.
- Shipping source is
Hourleaf 1.0.5 public activation — 2026-08-31
- Apple public lookup now returns
1.0.5with release timestamp2026-08-31T13:23:12Zin the US, Lithuania, and Ukraine. This closes public availability separately from App Review submission. - kikuai.dev PR #91 merged at
2026-08-31T17:18:35Zas63006ac. Cloudflare production deployment1bd00c3f-3216-465c-a5b2-c864e0386e2fbecame active. - Fresh live readback returned HTTP 200 for English, Russian, Ukrainian, and
/hourleaf.md. Each localized page contains its exactweb-en,web-ru, orweb-ukcampaign token; the Markdown facts page returnstext/markdownand identifies public version 1.0.5. - GitHub release v1.0.5 was published at
2026-08-31T17:27:43Z. Its tag points to exact shipping source2184275, and its App Store link uses campaign tokengithub.
The registered zero-cost attribution window activated at
2026-08-31T17:28:13Z, after all four owned links were live. It ends at2026-09-30T17:28:13Z; the first readback is scheduled for2026-09-07T17:28:13Z. Anygithubactivity before activation must be excluded. The pre-activation App Store Connect baseline remains measured but unreportable (Insufficient data), not zero.- Apple public lookup now returns
Implemented the previous-month report direct-send flow in
a2b302f, with final button copy refined incff823f.- The Add-screen report prompt now offers Send alongside optional review.
- The Progress report card offers the same direct action for ready or changed reports.
- Choosing Send creates the immutable snapshot, marks it sent immediately, and then opens the system share sheet. The UI states this consequence explicitly, so cancelling the share sheet does not silently change the contract.
- Updated EN/RU/UK copy, reminder wording, screenshot source copy, and regression coverage.
Verification:
xcodebuild -project Hourleaf.xcodeproj -scheme Hourleaf -destination "generic/platform=iOS Simulator" -derivedDataPath <temporary> CODE_SIGNING_ALLOWED=NO build-for-testing— TEST BUILD SUCCEEDED. Localization plists, screenshot JSON, andgit diff --checkalso passed. No physical device or simulator UI run was used.Pushed to
origin/main. App Store release was not started by this change.Hourleaf 1.0.6 (20) is submitted to App Review.
- Shipping source:
1809aa83f0264b2a9f70bb79c976ca840aaf4cce; durable submission receipt:f962021. - Retained signed archive:
~/Library/Developer/Xcode/Archives/2026-09-01/Hourleaf 1.0.6 (20).xcarchive. - Xcode upload succeeded; App Store Connect processed build 20 and assigned it to Hourleaf Internal.
- EN/RU/UK release notes and build-20 review notes are saved; build 20 is attached to version 1.0.6.
- Submission
5fa95a97-2118-4eef-b015-0c9f3b123812contains exactly one object,iOS 1.0.6 (20), and displaysWaiting for Review; draft count is zero. - Automatic release after approval, immediate availability to all users, and preservation of the current rating are selected.
- Focused report-model verification passed 7/7. The known aggregate CI boundary is documented in
AppStore/release-checklist.md; no additional broad test loop was run per owner direction.
Next actor: Apple App Review. Public 1.0.6 availability and matching site/GitHub release remain separate gates.
- Shipping source:
Hourleaf 1.0.6 public completion — 2026-09-03
- Apple official lookup returns
1.0.6, bundlecom.kikuai.hourleaf, and release timestamp2026-09-02T13:41:04Zin the US, Lithuania, and Ukraine; all three product pages return HTTP 200. - GitHub release v1.0.6 is public and points exactly to shipping source
1809aa83f0264b2a9f70bb79c976ca840aaf4cce. - kikuai.dev PR #95 merged as
f958c1c1e4fe9274f3f4f3d6e9d275c3d91acb3b; Cloudflare production deployment4aef03b5-1fbb-4330-8ce0-6a9d244547d9completed successfully at2026-09-03T21:04:44Z. - Fresh production readback passed for EN, RU, UK, and agent-readable facts. Every route returns HTTP 200, identifies 1.0.6, describes direct Send without claiming delivery proof, and preserves its exact owned campaign token.
- Setup guides in all three languages plus privacy and support pages also return HTTP 200.
- Durable release receipt is on Hourleaf
mainatcf03c01. No additional app test or physical-device cycle was run during public reconciliation, per owner direction.
Release work is complete. The existing zero-cost campaign measurement remains active through 2026-09-30, with the first scheduled readback due 2026-09-07.
- Apple official lookup returns
Campaign pre-readback verification — 2026-09-07T00:07:26+03:00
- The published web-en, web-ru, web-uk, and github App Store campaign URLs were checked individually. Each returned HTTP 200 and preserved its exact ct token in the final App Store URL.
- A web-uk request returned HTTP 429 only during the initial four-link burst; an isolated retry returned HTTP 200 with ct=web-uk. This is Apple request throttling, not evidence of a broken owned link, so no link correction was made.
- Live EN/RU/UK KikuAI pages still embed their matching campaign token; the GitHub README and v1.0.6 release still use ct=github.
- The stale portfolio-map version was corrected from 1.0.5 to the already-proven public 1.0.6 at kiku-jw/kikuai-project-map@9806747. The map continues to state that installs, repeat use, external demand, and revenue are unverified.
The registered first attribution readback remains due at 2026-09-07T17:28:13Z (20:28:13 EEST). No App Store Connect metrics were read early, no unavailable value was recorded as zero, and no campaign, monitor, Store setting, outreach, spend, device, or product behavior changed.
First campaign attribution readback — 2026-09-08T10:37:36Z
Source: App Store Connect → Hourleaf → Analytics → Acquisition → Campaigns.
- Report range:
31 Aug–6 Sep 2026, the latest complete seven-day range available in Apple reporting. - App download date filter:
All. - Apple displays the exact state: “Недостаточно данных, чтобы показать кампании.” (
Insufficient data to show campaigns.) - No campaign rows or attributable product-page views, first-time downloads, or conversion rates are exposed for
web-en,web-ru,web-uk, orgithub. - These values are unknown/unreportable, not zero. The UTC-day bucket for 31 August overlaps the activation timestamp, but because Apple exposes no attributed values, no pre-activation
githubactivity was counted or inferred. - No campaign link, Store setting, site, outreach, spend, device, or app behavior changed.
Experiment state:
WAIT. The fixed observation window remains2026-08-31T17:28:13Zthrough2026-09-30T17:28:13Z. Next unchanged readback: 2026-09-14; final decision only after the 30-day window matures.- Report range:
Campaign closeout and product decision — 2026-09-29
The owner asked to end the zero-cost owned-link experiment now. The latest complete App Store Connect range available was 31 Aug–28 Sep 2026, App Download Date = All.
Evidence
- Overall Hourleaf acquisition for that range: 51 product-page views and 9 first-time downloads.
- Campaigns still displays “Недостаточно данных, чтобы показать кампании.”
- Apple documents that a campaign appears only after at least 5 first-time downloads from individual users. Therefore none of
web-en,web-ru,web-uk, orgithubcrossed the reporting threshold. Per-channel values below that threshold remain unknown, not zero. - The 31 Aug UTC bucket partly predates the 2026-08-31T17:28:13Z activation, and Apple exposes no campaign rows, so the nine overall downloads cannot honestly be attributed to the experiment.
- This is an owner-authorized early close one day before the planned 30-day endpoint; 28 Sep is the latest complete reporting day.
Verdict: UNPROVEN / INSUFFICIENT REACH. The experiment does not demonstrate a bad product page or zero interest. It demonstrates that the four passive owned surfaces did not generate enough attributable volume for Apple to expose channel metrics.
Apple reference: https://developer.apple.com/help/app-store-connect-analytics/acquisition/campaign-links
Product and monetization decision
Current category evidence shows that monetization is possible mainly for broader ministry suites with CRM-like planning, maps, contacts, timers, and other high-maintenance features. Hourleaf's differentiated value is the opposite: a calm, private, Apple-native hours/reporting utility.
Decision:
- Keep the Hourleaf core free, ad-free, tracking-free, and without subscription or donation prompts.
- Do not run paid acquisition or congregation-style outreach. Continue only honest App Store metadata/localization, the existing kikuai.dev guides, GitHub, and context-appropriate word of mouth.
- Treat Hourleaf as a useful public engineering/portfolio case study: SwiftUI, Watch, Siri/App Intents, offline-first persistence, accessibility, localization, backups, and App Store delivery.
- If commercial value is desired later, validate a separately branded, nonreligious time/goal tracker built from generic components. Do not turn Hourleaf users or ministry data into a lead funnel.
- Revisit monetization only if organic usage produces materially stronger evidence or the separate general-purpose product is validated independently.
This choice also avoids unnecessary EU trader overhead. Apple's current DSA guidance says a hobby app with no commercialization intent may be a non-trader, while revenue, paid/IAP/ad-supported distribution, or commercial promotion are factors that can indicate trader status:
https://developer.apple.com/help/app-store-connect/manage-compliance-information/manage-european-union-digital-services-act-trader-requirements50-hour celebration
Published to
mainat193827d:- combines current-month service and credit minutes;
- triggers when the total crosses 50 hours;
- celebrates once per month, including after delete/re-add cycles;
- does not replay old milestones after an update, startup, or backup restore;
- shows short native confetti plus localized EN/RU/UK congratulations;
- respects Reduce Motion and posts a VoiceOver announcement;
- stores only presentation state in UserDefaults, outside the ledger and backups.
Verification:
xcodebuild -project Hourleaf.xcodeproj -scheme Hourleaf -destination 'generic/platform=iOS' -derivedDataPath <temporary> CODE_SIGNING_ALLOWED=NO build-for-testing -quiet— passed; app, Watch, extensions, and tests compiled.- EN/RU/UK localization lint — passed.
git diff --check— passed.- No simulator runtime is installed, so the new tests compiled but were not executed. No iPhone, Watch, signing state, or App Store version was touched.
Hourleaf 1.0.7 (21) submitted to Apple on 2026-09-30. Exact shipping source:
989c1a9; release receipt:4a546fd. Xcode archive/export/upload succeeded; App Store Connect processed build 21, assigned it to Hourleaf Internal, accepted EN/RU/UK release notes and reviewer notes, and displayedWaiting for ReviewafterSubmitted items: 1. Automatic release after approval and immediate rollout are selected. Four new milestone tests passed; the full hosted suite retains the same date-sensitive baseline failures as 1.0.6 (24 unit and one UI), so it is not green. Public 1.0.7 availability, website update, and GitHub release remain pending storefront confirmation.Release follow-up, 2026-09-30 05:17 UTC window: official Apple lookup still returns Hourleaf 1.0.6 (com.kikuai.hourleaf) in US, LT and UA. App Store Connect redirected the authenticated review check to sign-in with an expired/failed session, so the current review state of 1.0.7/build 21 is unverified; this is not evidence of rejection. The browser sign-in page is left for owner reauthentication. No GitHub release, site version claim, Store setting, app data or physical device was changed. Next action: owner signs in to App Store Connect, then resume review/public-store verification. Shipping source remains 989c1a9.
Owner reauthentication confirmed on 2026-09-30. Fresh App Store Connect readback shows iOS 1.0.7 Waiting for Review with build 21 selected, automatic release after approval and immediate rollout enabled. No resubmission is needed. Official Apple lookup still returns public 1.0.6 in US, LT and UA. The authentication blocker is resolved; next actor is Apple App Review. GitHub v1.0.7 and EN/RU/UK site updates remain conditional on approval plus public storefront confirmation. No Store setting, app data or physical device was changed.
Hourleaf 1.0.7 (21) — public release verified
Apple has approved this release. Fresh authenticated App Store Connect readback shows iOS 1.0.7 Ready for Distribution with build 21 and automatic release selected.
Public evidence
- The US, Lithuanian, and Ukrainian product pages return HTTP 200 and show current version 1.0.7, released 2026-09-30T16:44:32Z. The Apple lookup API initially lagged at 1.0.6 for US/LT while UA returned 1.0.7; the later product-page readback confirms all three.
- GitHub release v1.0.7 is published, not draft or prerelease. The tag resolves exactly to shipping source 989c1a9, not a later documentation commit.
- kikuai.dev main commit 229f10f28e0fc52fa89d54ccb912a63a947dafe0 deployed successfully through the existing Cloudflare Pages workflow at 2026-09-30T17:30:40Z.
- Live English, Russian, Ukrainian, and Markdown facts routes all return HTTP 200 and identify 1.0.7. The localized copy describes the 50-hour service-plus-credit celebration; the exact web-en/web-ru/web-uk campaign links remain intact. The facts still distinguish this monthly celebration from the service-only 600-hour goal.
Verification and durable state
- Website: all 6 focused Hourleaf public-page tests pass; production build succeeds with 366 prerendered routes.
- Release checklist updated and pushed on main in a5419e2. Earlier full-suite limitations remain recorded; this reconciliation does not claim a new full app-test pass.
- Portfolio map updated and pushed on main in ede84aa, preserving the free/ad-free/tracking-free maintenance positioning and the unproven distribution-experiment outcome.
- Diff and publication checks passed. All three task checkouts were clean after their pushes; no credentials or private records were added.
- No app source, app data, schema, signing configuration, or physical device was touched. No additional device-test cycle was started.
The requested 1.0.7 public-release reconciliation is complete. No remaining release action is required from Nick. The broader roadmap issue stays open; the dedicated 1.0.7 follow-up can stop.
Implement the accepted full Hourleaf product roadmap while preserving the existing local ledger and the minimal, immediately understandable iPhone experience.
Status: Hourleaf 1.0.7 (21) submitted — Waiting for App Review
Next actor: Apple; then Codex release follow-up
Next action: Automatic App Store release is selected. After approval, verify live 1.0.7 in US/LT/UA, then publish the matching GitHub release and update kikuai.dev version claims. Do not call 1.0.7 public before storefront confirmation.
Mac widget follow-up — 2026-08-25
Goal: make the existing iPhone WidgetKit extension useful on Mac through Apple’s iPhone-widgets-on-Mac path, without creating a separate unsynchronized macOS ledger.
Acceptance:
Outcome
Hourleaf becomes a durable private ministry-hours product: entries are recoverable and portable, common actions are one tap or a system Shortcut away, every total is explainable, planning remains calm, and optional platform features do not compromise offline-first use.
Product constraints
Specification decisions
Executable slices
8d1f70b; signed-device gate pending10c51b2cbb24d6; signed App Group/widget/control acceptance remains owner-gatedcdb303a; signed-device/public-release gates remainCross-slice acceptance
Verified delivery
Slice 1 landed on main at 12706b0. Fresh evidence: 32 unit/integration tests; 13 full UI tests plus 3 final report-boundary UI checks; unsigned generic-device Debug and Release builds; exact byte preservation of the V1 model; Sol Max adversarial review GO with no P0/P1/P2 findings. Physical iPhone remains untouched.
Slice 2 landed on main at c0fcb99. Fresh evidence: 58 unit/integration and 16 UI tests; unsigned generic-device Debug and Release builds; strict invalid-date/duration/revision handling; idempotent exact replay; optimistic revision conflicts; soft delete/restore; all four Undo inverses and the exact ten-minute boundary; report calculation/presentation fingerprints; RU/UK/EN validation; unchanged Core Data model/project/entitlements; Sol Max re-review GO with P0 0 and P1 0. Physical iPhone remains untouched.
Slice 3 code landed on main at
8d1f70b. Fresh evidence: 70 unit/integration and 19 UI tests (89/89 total); unsigned Debug and Release builds; Xcode Analyze; exactly three RU/UK/EN promoted commands; one shared repository actor; coalesced active/foreground/startup refresh; typed reminder routing; cold and warm blank-form reset; Sol Max adversarial GO with P0 0 and P1 0. A disposable signed smoke attempt stopped before installation because Xcode has no signed-in Personal Team account, so the physical device and its ledger remained unchanged. The slice stays open only for Shortcuts, Action Button, and reminder lifecycle smoke after the owner signs in to Xcode.Slice 4 landed on main at
10c51b2. Fresh evidence: exact raw preservation of all 10 V2 entities and 115 attributes; canonical password-free JSON with SHA-256 and bounded validation; atomic no-overwrite protected export; 26 focused backup tests; 115/115 combined tests after Shortcuts integration; unsigned Debug and Release builds; Xcode Analyze; unchanged models/project/entitlements/privacy/dependencies; Sol Max publish GO with P0 0, P1 0, and P2 0. Signed file-protection and File Provider behavior move to the Slice 5 disposable canary. The physical iPhone ledger remains untouched.Slice 11 is accepted on the feature branch at
962aec5: host-only, default-off crash-safe timer; review-before-save; no note capture; no extension ledger writer. Unit, UI, Release and Analyze gates passed. App Group/control/widget and physical-device canaries remain owner-gated.Slice 14 is accepted on the feature branch at
bc784c0: strict bounded Hourleaf CSV import, deterministic identities, one-save atomic application, conservative duplicate handling, ten-minute batch Undo, aggregate-only preview and human EN/RU/UK UI. Fresh final evidence: 417/417 unit/integration, 43/43 UI, post-cleanup coordinator 4/4, Release build, Xcode Analyze, protected-hash/localization gates and one bounded adversarial review with P0/P1/P2 = 0. A real external-file import journey remains signed-device acceptance; named competitor adapters require an owner-supplied sanitized export fixture.Live revision-graph validation landed on
mainat1dfadb5: backup and live snapshots now share one fail-closed immutable-history validator. App Group, CloudKit and Watch writers remain capability- and signed-device-gated.Owner-controlled gates
Apple account credentials, 2FA, paid membership, App ID/iCloud container changes, CloudKit production schema, TestFlight/App Store publication, and irreversible provider actions require explicit owner participation when reached.