v0.0.5 / 03 August 2026
Changelog
Running version 0.0.5
One entry per release, newest first. This page describes the release you are running; it makes no claim about whether a newer release exists.
Unreleased
- Already using protcul in this browser? The homepage and the entry screen now take you straight to Today instead of showing the public pages again. Signing out brings them back.
- Fixed: what sync brings in now appears on screen as it arrives. Signing in on another device left Today showing an empty pillbox until the page was reloaded, even once the account's records had all arrived — the screens read the local copy exactly once and were never told it had changed underneath them.
- Fixed: signing in on a second device could show an empty pillbox while every Protocol from your first device sat waiting, invisible. The pillbox those Protocols belong to had never been uploaded — accounts created before this fix upload it on their next sync, and the Protocols appear on every device without anything to do by hand.
- Sync no longer reports "all changes saved" while it is holding records it cannot show. Records received but not displayed now read as a sync problem, which is what they always were.
- A device signing in to an account whose records are waiting on a pillbox that has not arrived no longer adds an empty pillbox of its own to that account.
0.0.5 — 2026-08-03
Optional accounts, and the same pillbox on your other devices — with everything encrypted before it leaves this one.
- Create an account with a handle and a passphrase, or keep using protcul exactly as before. Guest mode is still the default and still complete on its own; an account adds one thing, which is sync.
- Everything is encrypted on your device before it is uploaded. What reaches the server is a pseudonymous handle, sign-in material, and opaque encrypted records — never a medication name, a pillbox name, a note, a schedule, or a mark. We cannot read your data, and we cannot recover your passphrase.
- Your devices converge on their own. Each one writes locally first and works fully offline; when they reconnect, edits merge rather than overwrite. Marks made on two devices are both kept, and if two devices edit the same pillbox or Protocol at once, one wins and the device whose edit was overridden is told, with the overridden version kept so nothing you typed disappears silently.
- Sign up while already using protcul as a guest and your existing pillboxes simply become the account's. Sign in on a device that already has guest data and you are shown what is at stake first, then choose to merge it, export it, or discard it — and your guest data is kept until whichever you chose has actually succeeded.
- Delete a pillbox on one device and it goes on the others, along with its Protocols and its history. If two devices delete different pillboxes at once and nothing is left, a fresh empty one is created rather than leaving you with no pillbox at all.
- Change your passphrase from Settings → Account. It re-encrypts everything the server holds and signs your other devices out. It is refused while any record has failed to decrypt, because those could not be re-encrypted and would be lost.
- Sign out returns you to the start without touching that account's local copy. Delete your account and its encrypted records, its handle, and that account's local copy are removed after an export-first prompt; a guest pillbox on the same browser is untouched. There is no recovery path, and registering the same handle later creates an unrelated new account.
- Every backup written by
0.0.1through0.0.4still imports, and still merges rather than overwriting. - The overdue boundary is unchanged at 18:00 device-local.
- Still no notifications, no analytics, and no tracking.
0.0.4 — 2026-08-03
Keep more than one pillbox on the same device, completely separate from each other.
- A quiet "Pillboxes" row in Settings → General is the whole entry point. Use protcul for yourself alone and nothing about pillboxes appears anywhere else.
- Add a pillbox for someone whose medication you manage, give it a name and an optional tag, and rename it whenever you like. Renaming keeps its Protocols and its history.
- Once a second pillbox exists, a switcher appears in the Today header. Today, Protocols, Protocol entry, and every derived Dose and Completion belong to whichever pillbox is active. There is no combined agenda, and nothing bleeds between pillboxes.
- Export one pillbox on its own — same format and same password option as a full export — and the person it belongs to can import it on their own device. That export and import is the entire handoff: it creates no link, no shared access, and no ongoing visibility in either direction.
- Delete a pillbox after an export-first prompt, which says how many Protocols and marks it will erase. It erases only that pillbox; every other one is untouched. If it was the active pillbox, the oldest remaining one becomes active.
- The last pillbox has no delete action. Wiping your data is still the one explicit way to erase everything.
- Every backup written by
0.0.1,0.0.2, or0.0.3still imports, and still merges rather than overwriting. Every one of them already carried a pillbox, so there is no older shape to convert. - The overdue boundary is unchanged at 18:00 device-local.
- Still no account, no notifications, no analytics, and no tracking. Registered accounts and encrypted sync are not available in this release.
0.0.3 — 2026-08-01
Describe a course in a sentence and watch the form fill itself in.
- A new optional text field at the top of Protocol entry: type something like "Blue pill every evening for four weeks" and the recognized parts fill the form below as you type — medication, day pattern, duration, quantity and unit, and time anchor.
- Recognized parts are highlighted in the sentence and listed beneath it, each naming the form field it fills. Any one of them can be dismissed and brought back.
- Parsing happens entirely on your device. Your sentence is never sent to an LLM, a cloud parser, or anywhere else, and the same sentence always gives the same result.
- Anything not recognized is simply left blank for you to fill in — a partly understood sentence is normal, not an error. Where two readings genuinely disagree, both are marked unresolved and the field stays empty rather than guessing.
- Two ways of describing more than one Intake are understood: two complete anchors joined by "and" ("with breakfast and with dinner"), and "once", "twice", or "three times" a day, which distributes "with meals" across breakfast, lunch, and dinner.
- The note and start date are never filled in from a sentence, and quick entry never removes an Intake row or changes an Intake's identity — so editing a Protocol this way keeps its completion history.
- The form is still the only thing that saves. Nothing is ever created from a sentence you have not reviewed and saved.
- The overdue boundary is unchanged at 18:00 device-local.
- Still no account, no notifications, no analytics, and no tracking. Registered accounts and encrypted sync are not available in this release.
0.0.2 — 2026-08-01
Optional ways to see your schedule, and a way to protect a backup with a password.
- Three presentation preferences in Settings: a week strip above the agenda (off), a month overview (off), and the overdue group (on). They change only what you see — no Protocol, Dose, or Completion is stored, scheduled, or recorded differently, and the daily loop works the same with all three off.
- A seven-day week strip for moving between nearby days, and a read-only month overview showing which days a course covers. Selecting a day in either one opens that day's agenda; neither can mark a Dose.
- Exports can now be protected with a password. The password is processed on your device, is never sent anywhere, and is never stored — if you lose it, the file cannot be opened by anyone, including us.
- Exporting without a password still works and still asks for an explicit confirmation first, because the file it produces is readable by anyone who opens it.
- Import accepts both password-protected and plaintext files, including every backup written by
0.0.1, and shows what the import will add before it changes anything. A wrong password, an altered file, or a file from a newer release stops without touching your data. - The overdue boundary is unchanged at 18:00 device-local.
- Still no account, no notifications, no analytics, and no tracking. Registered accounts and encrypted sync are not available in this release.
0.0.1 — 2026-07-31
The first release: a private, local-only digital pillbox you can use as a guest, on one device, without an account.
- Enter a medication Protocol as a structured form — medication text and optional tag, every-day, every-N-days, and weekday patterns, count-based, calendar, and ongoing durations, one or more Intakes, and every quantity unit and anchor type.
- Today opens on the current device-local day, shows the Doses derived from your Protocols in canonical order, and lets you navigate to other days.
- Mark a Dose taken or deliberately skipped, undo a mark, and backfill a past day. Marks are recorded locally the moment you make them.
- Doses still unmarked after 18:00 device-local are grouped as overdue for that day. This is the initial overdue boundary; any future change to it will be recorded here.
- Pause, resume, stop, and finish Protocols, keep archived courses readable, and start a finished course again as a new Protocol.
- Export your complete dataset as plaintext JSON after an explicit unencrypted-data confirmation, import it back with a preview that merges rather than overwrites, and wipe your local data after an export-first prompt.
- Public homepage, guest entry, privacy policy, terms of use, technology transparency, and this changelog, plus an installable offline-capable app shell.
- No account, no notifications, no analytics, and no tracking of any kind. Registered accounts and encrypted sync are not available in this release.