# Cartofin launch architecture contract

This document freezes the product domains represented by the commercial website. A capability should not be advertised as available at launch unless it is implemented, tested, and documented consistently with this contract.

## Product boundaries

- Cartofin is a local-first personal and household finance application.
- Household membership never grants blanket access to personal financial records. Access is resource-specific and revocable.
- Cartofin does not provide general household chat. Communication exists only as comments, questions, remarks, and replies attached to a specific task.
- Cartofin does not provide person-to-person expense splitting, debt balances, settlements, or “who owes whom” calculations.
- One expense may still be paid from multiple accounts owned or managed by the user. This is payment allocation, not expense splitting.
- One purchase may contain category splits derived from receipt line items. Category splits must reconcile to the purchase total and do not create balances between people.

## Launch domains

1. Personal finance: cash, bank, card, wallet, loan, investment/asset, and custom accounts; transactions, transfers, category and payment splits, categories/subcategories, tags, attachments, recurring transactions, search/filtering, budgets, bills, subscriptions, goals, debt strategies, assets/liabilities, net worth, and reminders.
2. Household: members, roles, resource permissions, shared financial views, multiple shopping lists, assigned shoppers, recurring shopping items, personal and household tasks, recurring chores, confirmation, task comments, attachments, reassignment, and completion history.
3. Calendar: Cartofin’s offline unified timeline for permitted financial, family, and household records plus opt-in device or supported external calendar synchronization and filters for everyone, the current user, a member, money, tasks, meals, and trips.
4. Spaces: trips, events, and projects with separate ledgers, dates, tasks, and lists.
5. Vehicles: costs, fuel, maintenance, odometer records, documents, and reminders.
6. Reports and export: in-app reports, PDF, and portable data export.
7. Backup and recovery: a client-side encrypted backup package stored in the user’s Google Drive or iCloud storage.
8. Safety and platform: emergency contact cards, optional medical/emergency notes, important numbers, user-controlled SOS countdown and cancellation, call shortcut, permitted SMS/location/household alerts, history, test mode, notifications, and home-screen widgets.
9. Commercial: free, trial, and Premium entitlements; purchase restoration and subscription reconciliation; disclosed advertising and ad-free Premium; crash/product analytics; and privacy-bounded operational administration that cannot expose private household ledger content.
10. Assisted capture and intelligence: typed, spoken, receipt-photo, document, and supported shared-content input that proposes validated Cartofin records for review; plus calculation-backed queries and household briefings over records the user is authorized to access.
11. Meals and pantry: meal planning, recipes, ingredients, servings, dietary preferences, pantry inventory and expiration, low-stock awareness, grocery generation, estimated cost, and confirmed links to shopping, expenses, and food budgets.

## Phase 1–5 launch journeys

- Two or more authorized devices can work offline, reconnect, converge, honor revocation, propagate deletions, and avoid disclosing unauthorized resources.
- Finance views cover planned and actual spending, subscriptions, savings goals, debt payoff, assets/liabilities, and net worth without collapsing unlike currencies or scopes into misleading totals.
- Relevant salary, bill, subscription, loan, savings, renewal, appointment, birthday, school, work, chore, shopping, maintenance, meal, and trip records can appear on the permission-aware unified timeline.
- Tasks and shopping retain recurrence, assignment, prices, history, and linked financial outcomes rather than functioning as isolated checklists.
- The meal journey can move from a planned meal through pantry checking and missing ingredients to a shopping list, estimated cost, confirmed purchase, actual expense, and food-budget update.

## Receipt intelligence

Receipt capture is a launch workflow, not an unrestricted AI database writer. Cartofin may extract merchant, date, currency, totals, tax, discounts, payment hints, and individual line items; normalize the result; propose a category for each item; and group those items into category splits beneath one purchase.

- The receipt total is authoritative. Line items, tax, discounts, rounding, category splits, and payment allocations must reconcile before the purchase can be committed.
- Low-confidence extraction or categorization is highlighted for correction. No receipt-derived financial mutation is silently committed without user review and confirmation.
- A probable match against an existing transaction is offered as an attachment/itemization operation instead of creating a duplicate expense.
- Shopping-list matches may be offered for confirmation. Pantry or other downstream updates, when supported, remain separate, explicit operations.
- Receipt images and extracted data inherit the selected resource scope and must pass the same authorization, validation, journal, encryption, and synchronization path as manually entered records.
- Image preprocessing and OCR should occur on-device where practical. Any cloud processing must be disclosed, minimize the data sent, use secure transport, and have defined retention behavior.

The canonical mutation path is:

`capture -> extraction -> proposed Cartofin objects -> authorization -> user confirmation -> domain validation -> local database -> journal -> encrypted synchronization`

## Task comments

Task communication is part of the task record. Comments may include an author, timestamp, edited state, optional reply relationship, unread state, deletion marker, notification state, and offline/synchronization metadata. Removing a task comment follows the product’s retention, authorization, and synchronization rules.

## Calendar authority

Cartofin’s calendar is the source of truth for Cartofin tasks, bills, reminders, maintenance, household events, and space dates. External calendar synchronization is optional. Deleting an exported event must not silently delete the underlying Cartofin record.

## Backup authority

Backups are created locally, encrypted on the client, and stored as encrypted artifacts in storage controlled by the user. Google Drive and iCloud must not receive readable financial records through the backup feature. Restore establishes a legitimate new device identity rather than cloning the identity of the backed-up installation.

## Acceptance rule

The website, app behavior, store declarations, privacy policy, terms, tutorials, and release testing must describe the same product. Where implementation differs from this document, the capability must be completed or the public claim must be changed before launch.
