What it is
Most people with a serious interest in their health end up with the same pile: blood panels in one portal, body scans as PDFs in email, a wearable keeping its own score, glucose exports in a spreadsheet, a consumer genome file nobody has opened since the day it arrived. Each tool is fine at its own job. Nothing reads the whole pile together, and nothing remembers what was decided last month and why.
Jesse Fowler had that pile and a sharper objection: every consumer app optimized for the platform that ran it, not for him. He had already decided to build a small set of personal systems where he owns the data and does the filtering himself. Health was the one he opened every day. On March 22, 2026 he started a Next.js project. By the end of that day it had eleven pages and a login. Six months later it is 391 commits, 58 pages, 32 API route files and the screen he opens when he wakes up.
The project grew out of the Matt Zanis engagement. Zanis, a Duke-trained doctor of physical therapy and fellowship-trained manual therapist (FAAOMPT) and the founder of Rooted in MVMNT, needed a place where some of his clients could track their own data alongside their coaching. His five-pillar framework, Movement, Vitality, Mindset, Nutrition, Training, is encoded in the app as a module two pages draw on. One line from it sets the tone for the whole system: the app is the witness, not the dictator.
What Common Ground did
- Built a full-stack personal health platform from a Next.js starter: 391 commits across 91 days over 196 calendar days, 341 of them co-authored with Claude, 58 page routes, 32 API route files with 53 handlers, 30 database tables declared in SQL, and 78,737 lines of TypeScript.
- Established single sources of truth for every fact that matters: one canon file holds each peptide's vial size and draw volume, and the dose is calculated from it, never hand-typed. A self-check runs at load and throws if the calculated dose disagrees with the expected one. A bad edit, from any session, fails the build instead of shipping a wrong number.
- Built fail-closed security from the start: the app refuses to run without a real signing secret; all writes go through server routes using the service key; the browser holds no write access. Across five distinct hardening rounds: rotated the signing secret and proved the old token rejected in production; moved 23 blood, scan and insurance PDFs behind an authenticated route that checks the session inside the handler (middleware's own rules skip image files); enforced the guest role in middleware across all 13 routes that change data without checking the login themselves; dropped all 24 permissive public-read database policies, confirmed by a control probe where a bad key returned 401 and the anonymous key returned rows before the fix and zero rows after.
- Fixed the most repeated bug class: the same fact in two places. A dose in eight files. A schedule hard-coded in a suggester that disagreed with the day card. A tick on one screen writing to a key the weekly count read from a different one. Each was traced to a root cause and fixed with a single owner per fact.
- Built a serialized client-write queue so rapid taps cannot overwrite each other, a server-side merge by id with newer-wins for the capture list, deletions stored as tombstones, and an eight-deep revision ring so any earlier version can be recovered.
- Added request deadlines across every network call (10 seconds in the service worker, 12 on writes, 20 as a system default) to replace the pattern where a stalled cellular request hangs forever. Switched from CDN-cached static rendering to fully dynamic so the Today page never shows yesterday.
- Hosted a 1.9 GB practice video privately: compressed to 44.3 MB, stored in a private bucket, served only via a session-checked route that mints a signed URL when the play button is tapped. No public URL exists.
- Built two scheduled agents that run outside the app on the owner's machines: a daily voice-journal synthesis that turns recorded notes into a movement recommendation, and a weekly read-only drift check across six measures that emails the owner a numbered list of questions and routes nowhere else.
Results
- Live and in daily use at health.jfowler.io. Private by design: unauthenticated visits redirect to the login page. The robots file says the site is not for indexing.
- The Today page, rebuilt September 27 to run in the order the day is actually done, shows the day's lifts with last weight and a set logger, this week's owed practices with a running count, dose rows that never hide, and a quick weight entry that starts blank. Around it: a stack screen, PR board, trend charts, body measurements, lab and scan viewer, raw genome analysis, glucose view, movement and recovery view, a weekly emailed report and a voice-journal pipeline.
- Every record lives in the owner's own database, behind his own login, on his own domain. No third-party tracking. No anonymous read access since September 15, 2026, confirmed by a control probe.
- 391 commits; the busiest day had 33; the June peak month had 143. One automated test file covers the 78,737 lines. The system was checked by running it and probing production, not by a suite, and adding one is on the open list.
Where we use it
Jesse Fowler is user zero. Health Vault is the screen he opens when he wakes up: the day's lifts, the doses, the labs and scans, in one system he owns. Running his own day on it is how we met the failure a health app cannot afford, a dose shown at four times its true value because one number lived in eight files, and why every fact now has one owner and the build refuses to disagree with itself. That is the rule we bring to any client whose software holds numbers people act on, and we bring it because it happened to us first. The Vault's peptide tracker and dose canon came first and became the seed of Ground Truth.
- Ground Truth Peptides, wiki page
- Ground Truth, Rooted in Health data room
- Health Vault, Rooted in Health data room
External links
- Official website: health.jfowler.io (private app; opens on its sign-in page)
- Public data room: Rooted in Health data room, Health Vault section
At a glance
| Project type | Software product build |
|---|---|
| Industry | Health technology |
| Seat | Builder and founder |
| Ran through | Common Ground |
| Dates | March 2026 to present |
| Duration | Ongoing from March 22, 2026 |
| Official website | health.jfowler.io (private app; opens on its sign-in page) |
| Public data room | Rooted in Health data room, Health Vault section |
| Related pages | Common Ground, Jesse Fowler |
| Credit | Created by Common Ground |