Privacy-Period-Tracker/docs/data
null ad085fb4ce docs: correct 57 claims the code and tracker disagreed with
Every document in the tree audited against the source, the tracker and git
history, each finding then given to a second reader tasked with refuting it.
74 raised, 12 refuted, 57 applied. No code changed.

THE README DESCRIBED A SKELETON

Its Status table — the one place a claim about what is built is allowed to live
— still read "there is no usable app yet", with Not built against Room, the four
core screens, fertility and notifications, and No round run against QA. Five
batches had shipped and three QA rounds had run.

TWO DOCUMENTS WERE SILENTLY NEVER FIRING

architecture/README.md and design/README.md wrote Governs: as prose ("the Gradle
module graph", "the design tokens in core/designsystem"). Neither contains a
path token, so doc-triggers.py reduced them to globs matching nothing, and one
real glob apiece made them look path-governing rather than subject-governing —
the state the script's own header calls invisible. Editing a Room entity never
fired the document owning the migration table. Both now fire, proved by running
the script.

SECURITY.md CLAIMED FOUR UNBUILT PROTECTIONS

App lock listed among what works offline; biometric/PIN gating described as
protecting app launch; the incognito launcher as existing; Play Billing in the
third parties table without the "not yet integrated" marker its neighbours
carry. All are Batch 06/07 work.

The advertising boundary was overstated in SECURITY.md and the README alike:
both said the ads module declares no dependency and a guard proves it. There is
no ads module. The pre-declared ":core:ads" to emptySet() rule is stricter than
the sentence it replaced and matches nothing until Batch 07, which is why the
guard is proved by injection rather than trusted.

SMALLER, EACH A REAL TRAP

WORK_CYCLE.md pointed at docs/architecture/scripts/forgejo-issue.py, a template
path absent here — missed by doc-claims.sh, which reads backticked prose and not
fenced blocks. ClaudeReport.md's Round notes said "No rounds yet" after three
rounds because ClaudeQAPlan.md's after-a-round list never named that section;
the playbook is fixed first. The instrumented-test count was eight in three
places and is four. HISTORY.md said the repository had no code and that nothing
had been tried and dropped, when three approaches had.

DELIBERATELY UNCHANGED

ClaudeReport.md's last verified build SHA stays at 0451fbe — no round has run
since, and moving it would claim a verification nobody performed. Every
DEVELOPMENT_LOG entry stays as written.

Guards: ./gradlew check, schema-guard.sh, doc-claims.sh (235 claimed paths, all
present), doc-triggers.py, and a link sweep over 21 markdown files.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-18 16:33:14 -05:00
..
img docs: correct 57 claims the code and tracker disagreed with 2026-08-18 16:33:14 -05:00
README.md docs: correct 57 claims the code and tracker disagreed with 2026-08-18 16:33:14 -05:00

README.md

Data — Privacy: Period Tracker

Status: Current
Owner: _null
Last reviewed: 2026-08-18
Governs: docs/data/** — the assets privacyllc.dev renders for this project
Review trigger: A rebrand, or any change to the icon, logo or banner

What goes here

Three files, in img/, at exactly these names:

docs/data/img/icon.webp     the square mark, used wherever the project is listed
docs/data/img/logo.webp     the full lockup, used on the project page
docs/data/img/banner.webp   the wide image, used across the project header

All webp. All required. Only img/ is checked — an asset left in docs/data/ instead of docs/data/img/ is not found.

Dimensions, weights and how to generate them are in img/README.md, beside the files they describe. This document owns the rule; that one owns the spec. Stating both in both places is how two copies of one convention start disagreeing.

No placeholders ship here, deliberately. The template this repository adopted carried a 0-byte logo.webp once, and an empty file is the worst of the three states: a check that asks "does the path exist" calls it present, and anything that reads the bytes rejects it — a consumer verifying the webp signature answers 415, which reads as a corrupt asset rather than a missing one. Absent is honest and the conformance check reports it as absent, which is what gets it filled in.

Extra sizes and variants are welcome beside them — icon-512.webp, logo-dark.webp — and are not treated as clutter. Only the three exact names are checked for.

If an asset is missing, open an issue — do not invent one

An agent cannot draw a logo, and this is the one gap in the whole convention that cannot be closed by writing a file.

So when an asset is absent, file an issue rather than producing something: title it for the asset, label it P2, and end the body with its Verify: line — Verify: docs/data/img/logo.webp exists and the project card renders it.

Do not generate a placeholder. A placeholder that looks deliberate outlives the issue that would have replaced it: nobody files a ticket against an image that appears to be finished. An obviously absent asset keeps asking.

Why this folder is different from every other one here

The Command Center consumes these. Every other document in this tree is written for a person to read; these are fetched and rendered on privacyllc.dev's project page.

That has one consequence worth stating plainly: this folder cannot be declared exempt. A repository may tell the conformance check that a required document is deliberately absent — kept out of git on purpose, say — and the check will believe it. It will not accept that declaration for docs/data/, because the result would be a project card with nothing to show and nothing explaining why, which is the exact failure the check exists to prevent.

Why webp and not PNG

One format, checked by its magic bytes rather than its file extension, so the site can serve it inline with confidence. A file whose first bytes are RIFF/WEBP cannot be an HTML document or an SVG carrying script, which is what makes it safe to render directly rather than forcing a download.

Renaming a PNG to .webp will not work, and is meant not to.

This is not an asset library

Screenshots, mockups, reference art and exported source files do not belong here. They belong wherever the project already keeps them. This folder holds the three marks that identify the project elsewhere, and stays small enough that its contents are obvious at a glance.