Humble & Kind

Money and health are not in the product

·

No setting for them, no way to hide them, no door that opens them. Two subjects removed rather than protected, and why that is the stronger promise.

A dark ground with two small closed shapes set apart from a row of open ones, drawn in grey with no pink mark inside them.

Every product that handles anything sensitive eventually has this conversation. Somebody asks whether the app can hold the delicate thing if it is really well protected, and the answer is usually yes, with a setting, and a note in the terms.

We went the other way on two subjects. Money and health are not in this product. Not hidden, not restricted, not behind a stronger door. Absent.

What absent actually means

It is worth spelling out, because in most software this sentence means a checkbox that defaults to off.

There is no topic for either one when you set up who can ask. Nothing in the interface offers them, so you cannot pick them by accident at eleven at night.

The routes that write to your page refuse them before anything is stored. If something arrives filed under money or health, by hand, from your own assistant, from an import, it does not get written. The request fails and tells you why.

The code that decides who sees what refuses them before it reads a single one of your settings. So even if something had been written in some older version of the world, or planted, it leaves as nothing. There is no rule you could write that opens it, because the refusal happens above the rules.

And the thing that checks your settings when you save them will not let you write a rule that names those subjects as anything other than closed. You cannot build the door, even deliberately.

Four layers, all of them saying no, none of them depending on the others being right.

Why not just protect it

Because protected means guarded, and guarded means there is something there to guard.

A hidden thing survives every mistake in the system. A misconfigured setting can release it. A bug in the wrong place can release it. A future feature written by somebody who did not read this post can release it. The only version of a secret with no failure mode is the one that was never written down, and the only way to guarantee that at scale is to refuse to write it down in the first place.

There is a general rule underneath this that runs through the whole product: whatever collects your information decides what is worth keeping, and only then does anything decide who sees it. Two different jobs. The calendar connector is the clean example. It stores that you are busy from two until four and never stores what the meeting was, so no mistake in any setting anywhere can leak the title of a meeting, because the title was never captured. Money and health are the same idea applied to two whole subjects.

And no advice, on anything

The related decision is about what an answer is allowed to be.

A page answers in your voice, from your words. That makes it a view, not advice, and it says so. It is not allowed to tell the person asking what to do about their money, their body or their legal position, whatever it has been told and however the question is phrased. The check for this sits on the way in, on the words as they enter the page, not on the answer as it leaves. A filter reading answers is a guess about language, and it fails open.

This is also why the wording of an answer is careful about whose view it is. There is a real legal shape to this: a tribunal has already held that what a company's chatbot tells a customer binds the company. A model that can generate a commitment is an unbounded liability. So this one does not generate commitments. It tells you what a person thinks, quotes them, and shows you where each part came from.

One subject left open, on purpose

The calendar is the exception, and it is opt in and blunt. If you turn it on, someone can learn that you are busy on Thursday afternoon. They cannot learn what you are doing, because the words were never stored.

That is roughly the line for everything: a page is for what you know and where you stand, and for enough about your shape to make a conversation possible. It is not a place to keep your private life well defended. Anything that would hurt if it got out should not be typed into any product, including this one, and a product that encourages you to do it anyway because its settings are good is selling you a feeling.

The terms say this too, in fewer words. Make a page if it suits you.