Mossforge mikeg@mossforge.app

Work · Android app

Withy

Closed testing as of 28 September 2026

A private health logbook for Android: designed, built, tested and taken through Google Play's closed testing by one developer.

Withy is on Google Play's closed testing track, not in public release. The earliest date it can apply for production access is 8 October 2026. Nothing on this page is described as live until it is.

The problem

People who are asked to keep an eye on their blood pressure, weight or blood glucose, whether by a doctor, for a relative, or for themselves, end up keeping the numbers on paper, in a notes app, or in a phone app that wants an account, shows ads, and tells them what their numbers "mean".

Withy is built for a narrower job, and it does that job well. It is a fast logbook for the numbers you already take. It charts them, and it produces a clean PDF or spreadsheet to hand over at an appointment. It never interprets a reading, and it never sends one anywhere.

That last sentence was the hardest constraint on the project, and most of the decisions below follow from it.

What was built

A native Android app (Kotlin, Jetpack Compose, Material 3), designed, built, tested and published by one developer. The first build was on 27 August 2026 and the closed-track release on 18 September, with the first tester-reported fix shipping on 25 September.

First-run metric picker: the user chooses which of six metrics to track
First run. Pick the metrics you take.
Blood pressure chart with weight overlaid, and the app's note that lines moving together do not mean one affects the other
Overlay (Withy+). Two metrics on one chart.
Blood pressure split into before and after 12:00, with a table of means and counts
Split by time of day (Withy+).

The decisions that shaped it

A logbook, not a health app

The rule every feature is checked against: everything the app displays is either something the user typed, or plain arithmetic over what they typed. Averages and a trend line are allowed. A "normal: 120/80" is not, because that number came from the app rather than the user.

So Withy has no colour-coded risk zones, no "high" or "stage 2" labels, no alerts that fire because of a value, and no example numbers placed in empty fields. The entry form's placeholders are the user's own previous reading. When the app gained target bands on its charts, the band had to be one the user types in. The app never suggests or presets one, and nothing changes colour when a reading falls outside it.

This protects the user, it keeps the app clear of Google Play's health-app policies and of personal liability, and it governs the marketing copy too: the store listing sells capacity and convenience, never an interpretation. The Play category is Health & Fitness rather than Medical, on purpose.

The overlay's caption, "Lines rising or falling together doesn't mean one affects the other," is that boundary showing up on screen: the app puts two metrics on one chart, and it declines to say what that means.

Private because there is no path out

"Withy never transmits your health data" is a claim about the code, and it is true by construction. The published build contains no networking code of its own. Its internet permission is there only because Google Play Billing adds it, for the purchase. An early experiment that read blood-pressure cuff displays through a cloud vision service was kept in debug builds only, so none of its code or keys can reach the published app. The privacy policy says exactly where data can go: Android's own backup to the user's Google account, a file the user chooses to share, and a purchase token sent to Google Play. It makes no broader promise than that.

Play's Data safety form reads no data collected or shared, and the privacy policy explains why that holds for an app holding blood-pressure and glucose readings.

Billing that can't cost the user money by mistake

The free tier is a complete logbook for one person. Every metric, all charting, import, and the backup CSV are free, and stay free after a refund. Withy+ adds capacity and output: more than one profile, unlimited PDFs (three are free), the spreadsheet workbook, and the chart splits and overlays, which free users can try on three days.

Google Play refunds a purchase automatically if the app doesn't acknowledge it within three days. That failure happened on the very first real test purchase. Google's service was briefly unavailable, the purchase went through, and the acknowledgement didn't. The design absorbed it: the feature unlocks whether or not the acknowledgement has gone through, and the acknowledgement is retried both in the moment and on every later launch. The purchase logic sits in plain code with no dependency on Android, so both of Play's traps are covered by ordinary unit tests.

A design system shared across a portfolio of apps

Withy is one of three apps in one codebase, and all three share a design system: one theme, one set of colour tokens, and shared cards and buttons. The palette is moss green, ember and rust, in a light scheme and a dark one. An automated contrast check reads the real colour definitions straight out of the source. On its first run it caught a dark-mode error button at 3.85:1, below the 4.5:1 standard, which four separate on-device reviews had missed.

Blood pressure chart in dark mode with trend lines and a 7-day average
Trend line and 7-day average, dark theme.
Log tab in dark mode with the new-reading form and history
Log, dark theme.

Migrations that protect data

A health log is only worth keeping if an update never loses it. The database has gone through eight schema migrations (version 2 to version 10), and each one is proven against real rows by a test that seeds data in the old schema, migrates it, and checks what comes out. No migration is signed off on reasoning alone. A second test builds a fresh install and a migrated install side by side and fails if they differ.

Backup was verified the same way. Android's cloud backup was run end to end on two real phones (Android 13 and Android 17), each restoring 150 readings identical to the originals. That testing turned up something no code review would have caught: the database file on disk is an empty header, and every reading lives in a second file beside it. A backup rule naming only the database file, which is the obvious tidy-up, would restore an empty log without a single error.

A rename before launch

A trademark search, run before any public release, found the app's original name already registered in the same class, for another app in the same store. The app was renamed Withy on 15 September, three days before the first closed release, while a rename still cost a day's work and a new Play entry. After a public launch it would have cost the listing.

The release path

Date (2026) Step
10 Sep First build published to Play's internal track; the one-time product created
11 Sep First real test purchase, and the missed acknowledgement it was designed to survive
14 Sep Trademark conflict found
15 Sep Renamed to Withy; new Play entry, store listing written and entered
16 Sep Every App content declaration completed; content rating Everyone / PEGI 3
18 Sep Closed track opened. The first review was rejected on a health-declaration answer rather than the build, and the same build was resubmitted with the answer corrected
24 Sep Twelve testers opted in, the number Google requires
25 Sep Version 1.0.2 on the closed track, fixing three bugs traced from one tester's report
8 Oct, earliest Application for production access, if all twelve testers stay opted in for fourteen continuous days

New personal developer accounts must run a closed test with at least twelve testers, who stay opted in for fourteen continuous days, before Google will consider an application for public release. One dropout restarts the fourteen days for everyone, so the opted-in count is checked daily until the application goes in.

One report, three fixes. A tester said Withy "isn't saving". The reading had in fact saved; the history list was keeping it just out of view. Tracing that turned up two further real bugs: the entry form could keep a stale time after the phone had been set aside, and the date picker could shift a reading by a day in US evening hours. All three were fixed, verified on a phone running the release build, and shipped to testers as 1.0.2 the next day.

The PDF report

The first page of the report a user hands over at an appointment, exported from synthetic sample data:

First page of the Withy PDF report: blood pressure averages, a chart with trend lines, and a table of readings

Numbers

Measure Value Source
Unit tests at 1.0.2 787, all passing; lint report empty pre-release run, 25 Sep 2026
Instrumented (on-device) tests 50 of 50 passing on a Pixel 6 23 Sep 2026
Schema migrations, each tested against seeded rows 8 (v2 to v10) migration test suite
Cloud backup round trips on real hardware 2 phones, 150 readings each, identical after restore backup verification record
Supported Android versions 7.0 (API 24) to 17 (API 37) build configuration
Permissions in the published build Internet, network state and billing, the ones Play Billing needs; no camera merged release manifest
Data safety declaration No data collected or shared Play Console
Content rating Everyone / PEGI 3 Play Console, 16 Sep 2026
Closed-test testers opted in 12 of 12 required, from 24 Sep 2026 Play Console
Price Free; Withy+ is a one-time $4.99 Play Console
First build to closed track 22 days (27 August to 18 September) git history

About these screens

Captured on 28 September 2026 from the debug build of 1.0.2 on a Pixel 10 Pro emulator (Android 17), using the app's built-in synthetic sample data, so no real readings appear. The status bar is frozen in demo mode. The paid chart views were unlocked with the debug build's test switch rather than a purchase.

What is not claimed