Work record / Health and wellness / Health Vault
Health Vault: what I built to own my own data
Consumer health apps serve the platform behind them. So in March 2026 I started building my own, and it is now the screen I open when I wake up.
The seat
I am the builder and the owner of Health Vault. I started it on March 22, 2026, and it is still running. It runs through Common Ground.
| Sector | Health technology |
|---|---|
| Type of work | Software product build |
| Years | March 2026 to present |
| How long | Ongoing from March 22, 2026 |
| Through | Common Ground |
| Credits | Common Ground Jesse Fowler, Builder and owner |
What I was brought in to decide
Anyone serious about their health ends up with the same heap. Blood panels live in one portal, body scans arrive as PDFs in email, a wearable keeps its own score, glucose exports sit in a spreadsheet, and a consumer genome file has gone unopened since it arrived. Each tool does its own job fine. Nothing reads the whole heap together, and nothing remembers what was decided last month or why.
I had that heap, and a firmer objection. Every consumer app optimized for the platform running it, not for me. I had already resolved to build a few personal systems in which I hold the data and do my own filtering. Health was the one I opened every day. On March 22, 2026 I started a Next.js project, and by that evening it had eleven pages and a login. Six months on, it stands at 391 commits, 58 pages and 32 API route files.
It grew out of the Matt Zanis engagement. Zanis is a Duke-trained doctor of physical therapy, a fellowship-trained manual therapist (FAAOMPT) and the owner of Rooted in MVMNT. He needed somewhere some of his clients could follow their own numbers alongside his coaching. His five-pillar framework, Movement, Vitality, Mindset, Nutrition and Training, lives in the app as a module used by two pages. A single line from it captures the attitude of the whole system: the app is the witness, not the dictator.
What we did
- Starting from a Next.js template, I built a complete personal health platform. Over 196 calendar days there were 391 commits on 91 active days, 341 of them co-authored with Claude. The code totals 78,737 lines of TypeScript. It includes 58 page routes, 53 handlers spread over 32 API route files, and 30 database tables declared in SQL.
- Every fact that matters has one source of truth. One canon file records each peptide's vial size and draw volume. The dose is derived from that file and never typed in. A self-check at load throws an error if the computed dose differs from the expected one. A bad edit from any session breaks the build and never ships a wrong number.
- Security fails closed, and has from the start. The app will not run without a real signing secret, every write goes through a server route using the service key, and the browser holds no write access. I then ran five separate hardening rounds. I rotated the signing secret and proved the old token was rejected in production. The 23 blood, scan and insurance PDFs now sit behind an authenticated route that verifies the session inside the handler, since middleware rules skip image files. I enforced the guest role in middleware on all 13 routes that change data without checking the login themselves. And I dropped all 24 permissive public-read database policies. A control probe confirmed it: before the fix a bad key got a 401 while the anonymous key got rows, and after the fix it got zero rows.
- I went after the bug class that kept repeating, which was one fact living in two places. A dose sat in eight files. A schedule was hard-coded in a suggester and disagreed with the day card. A tick on one screen wrote to a key that the weekly count read under a different name. I traced each to its root cause and gave every fact a single owner.
- I built a serialized client-write queue so quick taps cannot overwrite one another. The capture list merges on the server by id, newer wins, and deletions are stored as tombstones. An eight-deep revision ring lets me recover any earlier version.
- Every network call now has a deadline: 10 seconds in the service worker, 12 on writes and 20 as the system default. That ends the habit of a stalled cellular request hanging forever. I also replaced CDN-cached static rendering with fully dynamic rendering, so the Today page never shows yesterday.
- I host a 1.9 GB practice video privately. I compressed it to 44.3 MB and stored it in a private bucket. It is served only through a route that checks the session and mints a signed URL when I tap play. No public URL exists.
- I built two scheduled agents that run outside the app, on my own machines. One synthesizes my daily voice journal into a movement recommendation. The other is a weekly read-only drift check across six measures, which emails me a numbered list of questions and sends nothing anywhere else.
Results
- It is live and I use it daily at health.jfowler.io. It is private by design, so a visit without a login redirects to the login page, and the robots file says not to index it.
- On September 27 I rebuilt the Today page to follow the order the day is actually done. It lists the day's lifts, each with its last weight and a set logger. It shows this week's owed practices with a running count, dose rows that stay visible, and a quick weight entry that begins empty. Around it sit a weekly emailed report and a voice-journal pipeline, along with a movement and recovery view, a glucose view, raw genome analysis, a lab and scan viewer, body measurements, trend charts, a PR board and a stack screen.
- Every record sits in my own database, behind my own login, on my own domain, with no third-party tracking. Since September 15, 2026 there has been no anonymous read access, and a control probe confirmed it.
- There have been 391 commits. The busiest day had 33, and the peak month, June, had 143. One automated test file covers the 78,737 lines. I verified the system by running it and probing production, not with a test suite, and adding a suite is on my open list.
Firm record
Common Ground keeps its own account of this engagement: Health Vault on the Common Ground wiki.