The rename was mostly a set of decisions about what NOT to touch: 239 domain
references, the Kotlin package, the applicationId and period.db all stay,
because "Period" is the central domain word as well as the old product name.
Records the two things a later reader would otherwise retry: the Command Center
slug cannot be changed (PATCH accepts the field and ignores it, and recreating
the project to change an invisible internal key would throw away its history),
and three names have to agree — repository, git remote, and the site's
forgejoRepo mapping — with the third being the one that fails silently.
Issue #9's body named the old repository path and has been corrected in the
tracker, so the command in it works for whoever picks it up.
"Period" was always a working name — PRODUCT_PLAN.md §55 said so. The real
identity arrived with the brand guide and artwork, and this makes the project
call itself by it.
The repository is renamed in place on Forgejo (null/Period ->
null/Privacy-Period-Tracker), which keeps all 30 commits, all 27 issues, all 8
milestones and the four severity labels — verified by counting them on both
sides rather than assuming a rename is lossless. The git remote follows in the
same breath, so this commit's automatic push is what proves the new URL works.
WHAT DELIBERATELY DID NOT MOVE
"Period" is the product name AND the central domain word, and a mass rename
would have turned the data model into nonsense. PeriodRecord, PeriodWriteResult,
confirmPeriodStart, the period_records table and the button that says "Started
period" all describe a menstrual period rather than a product, and all 239
references to them are untouched.
So are the Kotlin package and applicationId. dev.privacyllc.period already reads
correctly under the new name — privacyllc is the company, period is the app —
and changing it would rewrite 68 files, rename the Room schema directory and
break the hardcoded path in schema-guard.sh for no gain. period.db stays for a
sharper reason: renaming a database file orphans the data on every device that
already has it.
Sixteen files changed, and the diff is small on purpose.
THE NAME HAS A SPACE AND THE ARTWORK DOES NOT
Canonical is "Privacy: Period Tracker". The supplied wordmark sets it without
one, so logo.webp and banner.webp now disagree with every document and with the
app itself. BRAND_GUIDE.md §10 is updated to the space form and says plainly
that the drawn mark has not caught up. Filed separately rather than papered
over, because closing that gap needs an artist and not a rename.
Round 3 adds pass F, which became runnable for the first time. Eight
instrumented tests assert what a lock screen would render; the row says plainly
that nobody has yet looked at an actual locked screen, because the tests check
the notification object and the last mile is what the system chooses to draw.
Three guards have now failed their first proof — schema, boundaries,
permissions. Recorded as a rule rather than a run of bad luck: assume a new
guard is broken until it has been watched failing.
Records the fertility work, the third instance of "the app declines rather than
stretches", and the pre-commit hook that made `git rm` impossible.
Also records my own error rather than tidying it away: `git reset --hard` after
the post-commit hook has pushed does not undo the push, and it discarded an
uncommitted fix mid-proof. Reconciled forward instead of rewriting published
history.
Round 2 covers every screen Batch 03 built, pass by pass, with each partial and
not-run row carrying why. Three new standing gaps, all of them things nobody has
done rather than things that failed: TalkBack has never been run, text has never
been scaled, and nothing has run at minSdk.
The rule this session keeps demonstrating is now stated plainly in both files:
the defects in this project are found by running it, not by reading it.
Three consecutive guards and models were wrong in ways reading them would never
have shown, and each was caught by running it: the Room schema check that Room
itself defeated, the boundary check that examined nothing, and three modelling
faults in the engine. Recorded as a habit rather than three coincidences.
Round 1 was partial and says so, pass by pass, with each not-run row carrying
why. It found two defects that 70 green unit tests could not: the primary
button crashing the app on a second tap, and two API 34 date calls on the
recalculation path that would crash every device below Android 14.
Neither is filed in the tracker. Both were found and fixed inside the batch that
introduced them, before any build left this repository, and an issue closed by
the commit that created the code would be bookkeeping rather than a record.
New standing gap: nothing has been run on a device at this project's own minSdk.
Lint is a good guard for that and is not a substitute for one run on API 26.
doc-claims.sh reported 19 claimed paths that do not exist. Every one was a
deliberate forward reference — the planned modules in the architecture table,
the two documents the trust map records as absent on purpose, and the release
script Period declined.
A backticked path is read as a claim the file is there, so a document saying
"core/database does not exist yet" was asserting the opposite of what it meant.
docs/history/BATCH_LEDGER.md already records the idiom for this case; it is now
applied and stated where it is used, so the next forward reference does not
reintroduce the failure.
Also corrects WORK_CYCLE.md, inherited from the template, which pointed at a
scripts/release.sh this project does not have. A release here is a signed AAB
and a Play submission, so the security checklist carries that procedure.
doc-claims.sh now reports 152 claimed paths, all present, across 20 files.
Period was a bare directory holding one 2,527-line specification, with no git
repository, no tracker and no documentation convention. This is the adoption
from Projects/Template/START-HERE-New-Project.md, plus a project that compiles
so the hooks and future guards have something real to run against.
Documents. scaffold.sh created 19 paths, 0 skipped. The specification moved to
docs/planning/PRODUCT_PLAN.md unchanged in substance, with a status header; the
capitalised Docs/ is gone. Every scaffolded document was filled in for Period.
docs/OPERATIONS.md deleted — an offline app is not a deployed service.
DOC_TRUST_MAP.md written last, describing what is actually here, including what
this project deliberately does not have.
Code. Four Gradle modules. domain/cycle and domain/prediction are kotlin("jvm")
and cannot see the Android SDK, so the engine is testable without an emulator —
17 tests pass, 12 of them the acceptance cases from PRODUCT_PLAN.md §51.
BaselinePredictionEngine is a robust-median prototype and explicitly not the
product; it exists so Batch 02's replacement can be shown to be better rather
than merely different.
Versions verified against their official sources today rather than inherited
from the specification's own numbers, which that document asks for: Kotlin
2.4.10, AGP 9.3.1, Gradle 9.7.0, Compose BOM 2026.08.00, Room 2.8.4, Hilt
2.60.1. AGP 9 ships Kotlin built in, so org.jetbrains.kotlin.android is no
longer applied. compileSdk is 37 because current AndroidX requires it; targetSdk
stays 36, Play's floor from 2026-08-31, and the difference is deliberate.
Six scripts taken into scripts/; the rest declined and named in docs/TOOLS.md.
Three hooks in .githooks/, with pre-commit adapted to Gradle.
closes#1closes#2