Releases: topeuph-ai/hearth
Release list
Hearth 0.2.4
QR codes. The Invite someone page shows the circle's address as a QR code, and the joining screen can scan one with the camera, so nobody has to type it.
An address you can type. About a hundred characters in six short rows, starting HEARTH, with no L, I or O to confuse, and capitals and spaces do not matter. Each row checks itself, so a typing mistake says which row to look at instead of just failing. The person's name is no longer in the address. Addresses already sent still work.
Known limit: devices restarted without the internet cannot find each other yet. See docs/what-is-proven.md.
Same network as 0.2.0 to 0.2.3 (DNA hash uhC0kdOPBMpnt_E6L_PlYoqr5WWkXt7dYbyMcd52ww123FKSDSIm7): existing circles still work.
Hearth 0.2.3
Opening Hearth again brings its window back. Closing the window keeps Hearth running beside the clock, so it can keep sharing with the circle. Opening it again used to start a second copy that waited forever at "Starting lair keystore". Now only one copy runs, and opening it again shows the one already running. Found on the first two-machine test.
Known limit, written up in docs/what-is-proven.md: Hearth keeps sharing through an internet cut while it is running, but devices restarted without the internet cannot find each other yet.
Nothing else changed from 0.2.2. Same network (DNA hash uhC0kdOPBMpnt_E6L_PlYoqr5WWkXt7dYbyMcd52ww123FKSDSIm7): existing circles still work.
Hearth 0.2.2
Removing somebody from a circle. The holder presses one button. Her app makes a new circle, copies the record into it, and moves everybody else across without anybody typing anything. The person removed is sent nothing. The people moved are told who was removed, by whom, and the reason if one was given. Readings and decided suggestions come across as history, and the second person's agreement is carried across unless they are the one removed.
The second agreement survives the door. Invitations collected from a waiting room now keep which appointment they were given under, so the network checks the second person's signature.
Tidier suggestions. A suggestion that was set aside is shown only to the holder and to whoever offered it.
500 words a section, for the record and for suggestions, with a count in the last hundred words.
The hard questions. A red-team review's fourteen questions, each answered honestly in docs/hard-questions.md.
Same network as 0.2.0 and 0.2.1 (DNA hash uhC0kdOPBMpnt_E6L_PlYoqr5WWkXt7dYbyMcd52ww123FKSDSIm7): existing circles still work.
Hearth 0.2.1
Everything from the interface walkthrough: creating a circle over three pages, writing the record one section at a time with prompts from the PRSB guidance, a summary with a change or suggestion beside each section, tabs, an invite page, a waiting count that flashes and chimes, leaving that asks first and works, the date the record was last updated, and a warning to the holder if a member's chain is forked or has been reported for breaking the rules.
Same network as 0.2.0 (DNA hash uhC0kdOPBMpnt_E6L_PlYoqr5WWkXt7dYbyMcd52ww123FKSDSIm7): circles made with 0.2.0 still work.
Hearth 0.2.0 — the waiting room is the way in
An early demo, not a product. It exists to show that the idea is possible. Expect rough edges, and please do not put anybody's real information into it.
Hearth is a person-centred care record — the things somebody wants professionals to know about how to communicate with them, what matters to them, how to put them at ease. Scoped to the PRSB About Me standard, and deliberately stopping short of anything clinical: no medications, no diagnoses.
There is no server and no operator. Nobody hosts this, nobody can read it, and there is no company that could stop trading and take it with them.
⚠️ Read this first if you used 0.1.1
Circles made with 0.1.0 or 0.1.1 cannot be opened by this version.
A circle in Hearth is the hash of its compiled rules — that is what makes it a real boundary with nobody in charge of it. This release changes those rules, so it is a different set of circles. Nothing is lost from anybody's disk, and nothing is recoverable either: there is no migration, because there is nobody who could perform one.
If you have a circle from 0.1.1 you want to keep, keep 0.1.1 installed and treat this as a separate thing. Otherwise, make your circles again here.
This is the last time that should happen without a much better reason. It was done now, while the number of people affected is approximately nobody.
The one thing I would most like
Install it on two machines and tell me whether they find each other.
I still could not test that. There is one Windows machine here; the other laptop is a Chromebook, and renting a host costs money this project does not have. Everything the design needs is in the build, and three copies find each other on one machine — but nobody has ever watched two computers do it.
If you have two computers, that is half an hour that would tell this project something it cannot find out on its own. Open an issue either way.
What changed, and why it needed new rules
Getting in no longer starts with a long line of characters
In 0.1.1, joining began with "send me the long line of characters from your app". The holder collected an identifier from each person by hand, made an invitation for that one key, and sent it back. Three long strings passing between two people, all looking alike.
That is the step where this stopped being possible for somebody elderly, or somebody being helped. It was also where it went wrong in practice: walking the demo, a finished invitation went into the box marked Their identifier, because that was the first box on the screen that wanted a long string.
Now there is one address. The holder shares it once — by text, by email, read down the phone. It never changes and it works for everybody. Whoever has it can ask to join, and their key arrives with them by the fact of their asking. The holder sees a list of names and lets people in with a press.
Having the address lets somebody ask. It does not let them in, and it shows them nothing.
The invitation still exists — the door still requires the holder's signature over the joiner's key, and every existing member still checks it. You just never see one.
What is said at that door is encrypted
Making the room the only way in has a cost that had to be paid in the same release: a waiting room is readable by anybody who has the address, so every arrival would be announced in the open. "Ronnie Smythe, her cousin", visible to everybody ever given that address.
Who visits somebody is itself sensitive — a psychiatrist, a substance misuse worker, a domestic abuse advocate. So the name and the relationship are boxed to the holder. The key that wrote the knock cannot be hidden and is not; nothing else about it can be read by anybody else standing in that room.
Being asked to agree is now a question, not an instruction
A circle can ask two people to agree before anybody new joins — a safeguard for the day somebody talks the holder into letting a person in.
In 0.1.1 the second person was baked into the circle's identity, which meant naming them was permanent: if they died or lost the device their keys were on, the circle could never admit anybody again. It also meant the holder had to have their key in hand before the circle could be made at all.
Now the circle carries only the rule, and who that person is is written inside it. The holder presses their name in the list of people, and they are asked. They answer — and saying no reaches the holder, so she can ask somebody else. Nobody can be made to agree to an arrival, and nothing pretends otherwise; what is new is that refusing is something that can be said out loud rather than a silence to interpret.
Who was asked, and when, stays visible to the whole circle. That visibility is what the safeguard rests on.
Smaller things found by walking it with three people
- A knock that was put forward stayed in the queue with a button under it, so one arrival could be agreed to twice.
- The third person to arrive could not knock at all: the write was rolled back inside a network lookup on a cell seconds old, in front of a wasm error.
- Being told you had been asked to agree, with nothing on screen to answer with, until a background refresh caught up.
- Two Back buttons that did nothing.
- "Agrees to who joins, along with you" — true for the holder, and shown to everybody, so an ordinary member read that they were one of the two deciding.
What is in the release
uk.topeuph.hearth-0.2.0-setup.exe — the Windows installer, about 115MB. Holochain 0.7.0 and lair-keystore are inside it, so there is nothing else to install: no Rust, no Node, no separate binaries, no server to run.
hearth.webhapp — the application itself, without the desktop wrapper. If you want to run this on Linux or macOS, use this file rather than compiling from source, and build the desktop shell around it — see The desktop app.
That second point matters more than it sounds. Windows and Linux builds of the same source produce different rules and therefore different circles, and no flag on stable Rust fixes it. The released .webhapp is the canonical build. Anybody packaging this for another platform should assemble it from that file rather than compiling the zomes themselves.
What is proven, and what is not
66 tests run against a real conductor on every push, written as attacks rather than as feature checks: an uninvited agent cannot join; an invitation cannot be passed on; a member cannot write somebody else's record; a signal claiming to be from somebody else reaches no screen; only the person an appointment names may answer it; a knock says nothing to the rest of the room.
What they prove is that the rules are enforced. They cannot prove the rules are the right rules — that is a question for a reviewer.
And every fault in the list above passed all of them while it was happening. The tests are about the boundary; a person sitting in front of it is about everything else.
See what-is-proven.md for the honest version, including what is not tested and why.
Built with Claude Code.
Hearth 0.1.1
An early demo, not a product. It exists to show that the idea is possible. Expect rough edges, and please do not put anybody's real information into it.
Hearth is a person-centred care record — the things somebody wants professionals to know about how to communicate with them, what matters to them, how to put them at ease. Scoped to the PRSB About Me standard, and deliberately stopping short of anything clinical: no medications, no diagnoses.
There is no server and no operator. Nobody hosts this, nobody can read it, and there is no company that could stop trading and take it with them.
The one thing I would most like
Install it on two machines and tell me whether they find each other.
I could not test that. There is one Windows machine here; the other laptop is a Chromebook, and renting a host costs money this project does not have. Everything the design needs is in the build, and several copies find each other on one machine — but nobody has ever watched two computers do it.
If you have two computers, that is half an hour that would tell this project something it cannot find out on its own. Open an issue either way.
What is in the release
uk.topeuph.hearth-0.1.1-setup.exe — the Windows installer, about 115MB. Holochain 0.7.0 and lair-keystore are inside it, so there is nothing else to install: no Rust, no Node, no separate binaries, no server to run.
hearth.webhapp — the application itself, without the desktop wrapper. If you want to run this on Linux or macOS, use this file rather than compiling from source, and build the desktop shell around it — see The desktop app.
That second point matters more than it sounds, and it is the reason for this release.
What changed since 0.1.0, and why it needed a new version
0.1.0 was published yesterday and downloaded by nobody, which was lucky.
A circle in Hearth is the hash of its compiled code — that is what makes a circle a real boundary with no operator behind it. It turns out Rust bakes the source path of every dependency into the binary, for its panic messages. Those paths contain the building machine's home directory.
Two consequences, both now fixed:
- Every machine produced a different circle. Two people running what looked like the same app could not have found each other, with nothing to see and no error anywhere. Builds are now stripped of those paths, so any machine of the same platform produces the same code and the same circle.
- The 0.1.0 installer had my Windows username inside it. It does not any more.
One part of this cannot be fixed, and shapes how the release works. Windows and Linux write those stripped paths with different slashes — \ against / — so the two platforms will never produce byte-identical code, and therefore never the same circle. No option in stable Rust changes that. So there is one canonical build, published here, and every platform is assembled from it. That is what hearth.webhapp is for.
Two things will happen on Windows, and neither means anything is wrong
1. "Windows protected your PC"
The installer is not code-signed, so SmartScreen stops it. Click More info, then Run anyway.
This is what Windows shows for any application whose publisher has not bought a signing certificate. It is not a judgement about the file. If that is not acceptable in your setting — and in some NHS settings it will not be — say so, because signing is a cost rather than a problem.
2. If it never finds anybody, suspect your antivirus
Symptom: it installs, it opens, everything works on your own machine, and it never sees the other person. No error appears anywhere.
Cause, in almost every case: antivirus that scans HTTPS. Norton, Kaspersky, Avast, ESET and most corporate proxies re-sign every secure connection with their own certificate. Windows trusts it, so your browser never notices — but Holochain does not use the Windows certificate store, sees a certificate it cannot trace, and refuses to connect. This cost a day here.
The fix is one exclusion, added to your antivirus's HTTPS scanning exclusions:
dev-test-bootstrap2.holochain.org
Restart the app afterwards. It will not pick up the change on its own.
Before you judge it
Read what is proven and what is not. It says who built this and with what, which parts have 45 adversarial tests behind them, which are built but unwatched, and which are not built at all — the record is not encrypted at rest, and that is stated there first because it is the question worth asking.
I am not a software engineer. My field is music. The code is written with AI assistance and the design decisions are mine; the reasoning is in the commit messages, which are long on purpose.
This is not production software, it is not deployed anywhere, and nobody's real record is in it. It is built far enough to be argued with, which is what it is for.
Hearth 0.1.0 — the first release
⚠️ Superseded — do not use this oneThis installer builds a different circle from the one its own source code
produces, because the build embedded paths from the machine it was made on.
Anybody using it would be on a network of their own, unable to find anybody
else, with no error shown anywhere.It also contains the build machine's Windows username in plain text.
Nobody downloaded it. It is left here rather than deleted so the mistake is
on the record.
The first release. Nobody outside the machine it was built on has ever run this — so if you install it, you already know more about it than I do.
Hearth is a person-centred care record — the things somebody wants professionals to know about how to communicate with them, what matters to them, how to put them at ease. It is scoped to the PRSB About Me standard, and deliberately stops short of anything clinical: no medications, no diagnoses.
There is no server and no operator. Nobody hosts this, nobody can read it, and there is no company that could stop trading and take it with them.
The one thing I would most like
Install it on two machines and tell me whether they find each other.
I could not test that. There is one Windows machine here; the other laptop is a Chromebook, and renting a host costs money this project does not have. Everything the design needs is in the build, and several copies find each other on one machine — but nobody has ever watched two computers do it.
If you have two computers, that is half an hour that would tell this project something it cannot find out on its own. Open an issue either way.
Two things will happen on Windows, and neither means anything is wrong
1. "Windows protected your PC"
The installer is not code-signed, so SmartScreen stops it. Click More info, then Run anyway.
This is what Windows shows for any application whose publisher has not bought a signing certificate. It is not a judgement about the file. If that is not acceptable in your setting — and in some NHS settings it will not be — say so, because signing is a cost rather than a problem.
2. If it never finds anybody, suspect your antivirus
Symptom: it installs, it opens, everything works on your own machine, and it never sees the other person. No error appears anywhere.
Cause, in almost every case: antivirus that scans HTTPS. Norton, Kaspersky, Avast, ESET and most corporate proxies re-sign every secure connection with their own certificate. Windows trusts it, so your browser never notices — but Holochain does not use the Windows certificate store, sees a certificate it cannot trace, and refuses to connect. This cost a day here.
The fix is one exclusion, added to your antivirus's HTTPS scanning exclusions:
dev-test-bootstrap2.holochain.org
Restart the app afterwards. It will not pick up the change on its own.
What is in the file
One installer, about 115MB. Holochain 0.7.0 and lair-keystore are inside it, so there is nothing else to install: no Rust, no Node, no separate binaries, no server to run.
Windows only for now. Linux and macOS build from source with the same command — see the README.
Before you judge it
Read what is proven and what is not. It says who built this and with what, which parts have 45 adversarial tests behind them, which are built but unwatched, and which are not built at all — the record is not encrypted at rest, and that is stated there first because it is the question worth asking.
I am not a software engineer. My field is music. The code is written with AI assistance and the design decisions are mine; the reasoning is in the commit messages, which are long on purpose.
This is not production software, it is not deployed anywhere, and nobody's real record is in it. It is built far enough to be argued with, which is what it is for.