Hepatica — Funnel & Post-Paywall Workbench · Part 3

Part 3 closes the workbench. Companion to design.html (M1–7), flow.html (M8–10) and flow2.html (M11–14). Here: M15 — Onboarding, M16 — Paywall, M17 — restructure consilium, M18 — post-paywall Setup, M19 — the illustration & hero asset system, M20 — the user-action matrix, and M21 — the Coach engine (RAG × DeepSeek). Best practice borrowed from Folik & Calibrum's onboarding consilia and Cysta AI & Salvora's Coach & Setup patterns.

📐 Funnel · post-paywall · assets · matrix · Coach engine · Modules 15–21 🔒 Design system · B · Clinical WOW-then-justify · +6–11pp trial→paid Best practice: Folik · Calibrum · Cysta AI
МОДУЛЬ 15

Onboarding — the pre-auth funnel, worked WOW-then-justify

flow.html §8.1 left Onboarding as a dashed TODO gate. This module designs it. §15.1 sets the framework — the WOW-then-justify formula; §15.2–15.4 run the structure, length & trust consilia; §15.5 works the 8-screen flow for Robert; §15.6 draws the WOW for all 6 cohorts; §15.7 reconciles with the already-built Swift onboarding; §15.9 designs the honest reviews screen. Pre-auth throughout — no email, no Sign in with Apple before the paywall. Status: draft — nothing locked.

15.1 · The WOW-then-justify formula

Hepatica's siblings Folik and Calibrum both locked the same onboarding shape — and both measured +6–11pp trial-to-paid against a plain question funnel. We adopt it as Hepatica's onboarding framework. Seven beats; the WOW is the hinge.

1💔
Pain hook
One emotional sentence the user already believes — "Doctor said reverse it. With what?"
2🚪
Lane select
The 6 cohort doors + "just exploring". The user self-sorts — everything downstream personalises off this.
3✍️
Quiz · anchor
4–5 light taps (labs known, meds, goal). Each answer is an anchor the WOW will pay back.
4🌀
Pre-WOW breath
"Building your plan…" + the method line — AASLD / AGA / EASL grounding. Trust before the reveal.
5
The WOW screen
The catharsis — the user's own projected dashboard: their hero chart, their marker, their lane. Not a demo.
6🌿
Post-WOW breath
"Your plan is ready." A calm beat that names what they just saw and hands off to the offer.
7🔓
Paywall
Copy triggered on what the WOW showed — Robert's paywall headline references his GGT curve.
The WOW is the hinge — every beat before it plants an anchor, every beat after it cashes one in.
Credit & evidence. This is not invented here — it is the locked Folik onboarding consilium and the Calibrum onboarding rework, both of which beat a plain question funnel by +6–11pp trial-to-paid. Cysta AI shipped the lighter cousin: Welcome → persona select → quiz → typed result "You're [type]" + a mini preview. The principle all three share: the WOW is a personalised future-self mock — the user's own projected chart — never a generic feature tour. And it is all pre-auth: no email, no Sign in with Apple before the paywall.
The gap in our build. The already-scaffolded Swift onboarding (§15.5) is a pure question funnel — 9 steps, no WOW. CohortResultView is a text reveal; TrustMethodView is credentials. It collects seven anchors and never cashes one in — the user reaches the paywall having been interrogated, not answered. Module 15 inserts the missing catharsis.

15.2 · Onboarding consilium — does the funnel need a WOW?

Three ways to shape the pre-auth funnel. The 6 cohorts vote with the standard audience weights. The question: keep the built question funnel, restructure it WOW-then-justify, or strip it to the bone.

CandidateShapeRiskVerdict
A · Question funnel, as-builtThe scaffolded 9-step Swift flow as-is: Welcome → Pain → Triage → Labs → Meds → Goals → Diet → CohortResult (text reveal) → TrustMethod → Paywall.Collects 7 anchors and never pays one back. CohortResult is a paragraph, not a moment. The paywall arrives cold — nothing earned the trial. This is Folik's measured losing variant.✗ Rejected
B · WOW-then-justify ⭐Pain → Lane → compressed quiz → pre-WOW breath → personalised WOW (future-self dashboard mock) → post-WOW breath → Paywall. The quiz answers render the WOW.None material — adds one net screen (§15.5). The WOW must stay an honest projection, never a fabricated personal prediction — handled in copy + the disclaimer strip.✓ Ships
C · Ultra-leanPain → Lane select → instant WOW → Paywall. Drop the quiz entirely; the WOW is cohort-generic, not answer-personalised.Fastest, but the WOW is generic — no labs, no meds, no goal — so it can't show the user's numbers. Loses the anchoring that makes B's WOW land.✗ Rejected
Cohortaud %A · as-builtB · WOW ⭐C · ultra-lean
🍷 Nick25353
💉 Greta15253
🍔 Pete20252
💊 Rachel8351
🧬 Patricia15253
🍺 Robert17354
Weighted Σ1002.505.002.81

Why B — WOW-then-justify

B is unanimous (Σ 5.00) — rare, and it says something. Every cohort arrives carrying a fear — and a question funnel never answers a fear, it only interrogates it. The WOW screen is the first time the app says something back.

Pete (20%) kills A and C hardest: his job is "where do I even start with metabolic syndrome" — he needs to see the HbA1c + ALT dual projection, which only B's answer-personalised WOW can draw. Rachel (8%, highest WTP) kills C outright — a generic WOW can't show her FibroScan staircase or the insurance-PDF preview, and that preview is the single thing that justifies the price to her. Robert half-likes C (=4): his pain is simple — "GGT 240→80, is it real?" — and even a generic curve moves him; but B's curve is his curve, so he still scores B=5. A loses everywhere — it is literally the measured-loser funnel.

⭐ B · WOW-then-justify — ships A · question funnel as-built — rejected · no catharsis C · ultra-lean — rejected · WOW too generic to anchor

15.3 · Length consilium — how long should the funnel be?

B won the structure vote — but WOW-then-justify can be run in 6 screens or 12. Every screen costs drop-off; every anchored screen earns conversion. The 6 cohorts vote on the screen count.

CandidateScreensTradeVerdict
A · Lean6 — Pain · Lane · 1-card quiz · WOW · breath+proof merged · PaywallFastest, lowest raw drop-off. But one quiz card can't anchor a rich WOW, and merging the proof into the breath buries it at the commitment moment.✗ Rejected
B · Balanced ⭐8 onboarding screens + paywall — Welcome · Pain · Lane · compressed Quiz · pre-WOW breath · WOW · post-WOW breath · ProofEvery screen does one job: plant an anchor, deliver the WOW, or earn trust. Matches Folik (8) and Calibrum (6 + WOW). No filler.✓ Ships
C · Thorough12 — the 5 built quiz steps kept separate + everything elseMaximal data capture. But four extra quiz screens add drop-off for zero extra anchor value — the WOW only needs labs + goal + lane.✗ Rejected
Cohortaud %A · lean 6B · balanced 8 ⭐C · thorough 12
🍷 Nick25452
💉 Greta15353
🍔 Pete20354
💊 Rachel8255
🧬 Patricia15353
🍺 Robert17442
Weighted Σ1003.344.832.94

Why B — 8 screens + paywall

Lean (A) is tempting — anxious Nick and keep-it-simple Robert both reward it (=4). But cutting the pre-WOW breath removes the trust setup that makes the WOW credible, and merging the proof away wastes the one beat that does the converting. Thorough (C) only Rachel loves (=5, high intent, will answer anything) — every other cohort punishes the four redundant quiz screens. The number is 8: the five built Swift quiz steps must compress to one (§15.7), and nothing else gets cut.

⭐ B · 8 screens + paywall — ships A · lean 6 — rejected · WOW under-anchored C · thorough 12 — rejected · quiz drop-off

15.4 · Trust consilium — how a brand-new app earns belief

Hepatica launches with zero users. It cannot — and must not — claim a userbase it doesn't have. So where does pre-auth trust come from, and where does it sit? The 6 cohorts vote.

CandidateTrust mechanismRiskVerdict
A · Method line onlyTrust = the "grounded in AASLD / AGA / EASL" line tucked inside the pre-WOW breath. Nothing dedicated.Too quiet for the commitment decision. The user hits the price having seen the evidence claim for one second, in passing.✗ Rejected
B · Dedicated proof screen ⭐A full screen right before the paywall — one big, honest number about the evidence base: the research and sources Hepatica is built on.Adds one screen. Must be scrupulously honest — about the research, never a fake userbase (see the copy table below).✓ Ships
C · Persistent source stripA small AASLD/AGA/EASL chip strip on every onboarding screen.Wallpaper. Always present, never noticed — and it competes with each screen's actual job.✗ Rejected
Cohortaud %A · method lineB · proof screen ⭐C · source strip
🍷 Nick25353
💉 Greta15353
🍔 Pete20253
💊 Rachel8253
🧬 Patricia15353
🍺 Robert17353
Weighted Σ1002.725.003.00

Why B — a dedicated proof screen, placed at the commitment moment

Unanimous (Σ 5.00). Every cohort came with a fear, every cohort is one tap from a price — and a brand-new app has no reviews, no "10M downloads", no testimonials to lean on. What it does have is real: the evidence base. The proof screen makes that the trust anchor, full-screen, right where the conversion decision happens. Robert (=5) in particular — his whole question is "is this real?" — a guideline-grade evidence screen answers it. A (method line) is too quiet; C (strip) is ignored wallpaper.

⭐ B · dedicated proof screen — ships A · method line only — rejected · too quiet C · persistent strip — rejected · wallpaper

15.4a · The proof screen — honest "big number", Apple-safe

The founder's instinct is right: a big credibility number near the paywall converts. The trap is what number. Hepatica has no users — so the number is the evidence base, not a userbase. The corpus is a hard fact: DECISIONS.md D12 — 408 source documents → 1,819 research passages (PubMed NAFLD abstracts + AASLD/AGA/ACG/EASL/NICE/WHO guideline PDFs + FDA labels). And those guidelines distil epidemiology of a disease studied across millions of patients. That is the honest, substantiated "wow number".

Before you decideWhy you can trust this plan
The research behind your plan
Millions
of liver patients in the studies your plan is built on.
AASLDAGAEASLPubMedFDA
400+
clinical sources
1,800+
research passages
0
generic advice
📚
What this means
Every answer your Coach gives is pulled from this evidence — the same guidelines your hepatologist uses — never generic wellness copy.
Hepatica is a new app — these numbers describe the published research it is built on, not a user count. No claim is made about Hepatica's own results.
See my plan & pricing

The honest "millions" — and where it goes

The founder asked for a big proof badge near the paywall. The answer: yes — but the number describes the evidence, not the userbase. "Built on research covering millions of liver patients" is true, substantiated, and the way guideline medicine actually works. "Millions of users" is false, Apple-rejectable, and unnecessary.
The big word"Millions" sits huge — but the line under it fixes the meaning: "of liver patients in the studies your plan is built on." The claim is about the research, attached to named bodies.
SubstantiationThe three stats are hard facts from DECISIONS.md D12 — 400+ sources, 1,800+ passages, the source chips are the real corpus. Apple 2.3.1 wants claims substantiated; these are.
The honesty lineA quiet sc-disc states plainly: this is the research base, not a user count. It strengthens trust — and removes any rejection surface.
PlacementScreen 8 — between the post-WOW breath and the paywall (§15.5). The user is warm from the WOW; the proof screen is the last credibility beat before the price. A one-line echo of it also bands the paywall itself.
ComplianceNo userbase claim, no "trusted by millions", no testimonials, no outcome promise. Only the evidence base + named guideline bodies. Copy goes to compliance sign-off.
Borrowed — Calibrum (the source-badge wall: Endocrine Society · AUA · AAFP) and Folik ("we packed 300+ pages from AAD, ISHRS, FDA, PubMed"). Hepatica scales it to a full screen at the commitment moment.
Proof-line candidateThe copyApple-safe?
1 · Research-base "millions" ⭐"Millions of liver patients in the studies your plan is built on." + "400+ AASLD · AGA · EASL & PubMed sources."✓ Safe — the number is the research literature, attached to named bodies; substantiated.
2 · Corpus count"400+ clinical sources. 1,800+ research passages. Every answer drawn from guidelines, never generic advice."✓ Safest — hard facts from D12. Less emotionally big, zero risk. Good as the subline.
3 · Guideline-grade sealA seal: "Guideline-grade" + AASLD · AGA · EASL. "Hepatica only says what the liver guidelines say."✓ Safe — authority framing, no number to substantiate.
4 · Userbase claim"Join millions improving their liver" / "Trusted by millions of users".✗ Banned — false (zero users), Apple 2.3.1 rejection, deceptive. Never ship.
Recommended: ship candidate 1 as the hero line + candidate 2 as the substantiating stats (exactly the mockup above), and echo a one-line band — "Built on 400+ AASLD/AGA/EASL & PubMed sources" — on the paywall itself (Module 16). Candidate 4 is documented here only as the anti-pattern. The rule: every big number in this funnel describes the evidence, never Hepatica's own results or userbase — until real outcome data exists, post-launch.

15.5 · The B flow — worked for Robert

The recommended funnel — 8 screens then the paywall — worked for Recovering Robert, the way §8.3 worked Today. Robert's tone rule governs every word: non-judgmental — never "addiction", never "alcoholic", never "relapse".

The 8-screen pre-auth funnel

01Welcome · the promise
02Pain hook
03Lane select · 6 doors
04Quiz · 3-card anchor
05Pre-WOW breath
06The WOW screen
07Post-WOW breath
08Proof · §15.4a
09Paywall → M16
🌿
Hepatica
Reverse fatty liver.
Reclaim your vitality.
An AI companion grounded in AASLD, AGA & EASL guidance — built to help you read your liver and watch it recover.
Get started
I already have an account
No email needed to explore — your data stays on your device.

Screen 1 · Welcome — the promise

Robert found Hepatica from r/stopdrinking. He is hopeful but burned by health apps that judged him. Screen 1 must read calm and clinical, never boot-camp.
One promiseThe tagline, nothing else — no feature list. "Reverse fatty liver" is the aspirational wellness frame (allowed per COMPLIANCE.md).
No login wallPre-auth — the whole funnel is anonymous. No email, no Sign in with Apple before the paywall.
Tone set hereSoft leaf mark, off-white surface — the calm-authority tone Robert needs is established in the first second.
Borrowed — Folik: single-promise welcome, no feature grid.
01 / 08
Sound familiar?
"GGT was 240. Now it's 80. Is my liver actually healing — or am I fooling myself?"
You did the hard part. Hepatica is built to show you the proof.
Yes — show me

Screen 2 · Pain hook

This is Robert's exact sentence, lifted from his cohort pain line. He sees himself in it before he has tapped anything — that recognition is the hook.
Mirror, don't sellOne sentence in the user's own voice. No product claim — it ends on a question, the same question he carries.
ComplianceA question, never a claim — "is my liver healing?" not "your liver is healing". The reassurance ("you did the hard part") is behavioural, not medical.
Per cohortNick sees "Doctor said reverse it. With what?"; Rachel sees the $40K-drug fear. Same beat, the cohort's own words.
Borrowed — Calibrum: pain mirrored verbatim from cohort research.
02 / 08What brings you to Hepatica?
🍷  My doctor just said fatty liver.
💉  I'm on a GLP-1 — Ozempic / Wegovy / Mounjaro.
🍔  Pre-diabetic — metabolic stuff to get ahead of.
💊  I'm on Rezdiffra for MASH.
🧬  PCOS and a fatty liver.
🍺  I've stopped drinking — I want to watch my liver recover.
Just exploring for now

Screen 3 · Lane select — the cohort triage

Robert reads all six doors and lands on his instantly — "stopped drinking… recover" — framed as agency, never as a confession.
Self-sortSix doors + a "just exploring" exit. The tapped door sets the cohort that personalises every screen downstream.
Robert's wordingHis door never says "alcoholic" or "addiction" — it says "stopped drinking… watch my liver recover". The cohort label is internal only.
No dead end"Just exploring" still routes to a generic WOW + soft paywall — never a blank exit.
Borrowed — Cysta AI: persona-door select. Maps 1:1 to the built Swift CohortTriageView.
03 / 08Three quick taps
Do you know your recent liver numbers?
Yes — I have themRoughlyNot yet
GGT80U/L · optional
What are you tracking alongside?
Sober daysWeightSleepNothing yet
Your goal, in one line
See my liver healStay on trackReach normal range
Build my plan

Screen 4 · Quiz — the anchor

Five separate Swift question screens collapse into one calm scroll. Robert enters GGT 80 — that single number is the anchor screen 6 pays back.
Anchors, not interrogationEvery answer renders something in the WOW. Three cards, ~5 taps — not five screens.
Numbers optional"Roughly" / "Not yet" still works — the WOW falls back to a typical-range curve. No one is gated on having labs.
Cohort-conditionalMeds & diet questions fold in only when the cohort needs them — Robert is never asked about Rezdiffra.
Borrowed — Folik: compressed multi-question card. The 5 built Swift quiz steps merge here (§15.7).
🌀
Building your recovery plan…
✓  Reading your numbers against AASLD post-abstinence ranges
✓  Tuning your Coach's tone
○  Drawing your liver-recovery timeline…
Grounded in AASLD, AGA & EASL guidance.

Screen 5 · Pre-WOW breath

A two-second held breath. It does real work — it tells Robert the method (guideline-grounded) right before the reveal, so the WOW lands as credible, not as marketing.
Trust before payoffThe checklist names the method — AASLD ranges, guideline grounding — a beat before the chart appears.
AnticipationThe third line is still "drawing…" — the WOW is one tap away. A designed pause, not a spinner.
Absorbs two Swift stepsThe built CohortResultView + TrustMethodView collapse into this single breath (§15.7).
Borrowed — Calibrum: the "analysing" interstitial that doubles as a credibility statement.
Robert — your recovery planHere's the view you'll build
Liver recovery · GGTWatch
80 U/L↓ 160 since you quit
240 AASLD ref
A projection, not a personal medical prediction — the band is the typical AASLD post-abstinence range. Your real line builds from what you log.
47
Days sober
−160
GGT drop
Day 60
Next milestone
Your plan
Your sober milestones live right inside this chart — the curve and the streak move together.
This is my plan →

Screen 6 · The WOW screen — the catharsis

This is the moment Module 15 exists for. Robert spent five screens being asked questions. Screen 6 finally answers him — and it answers with his own number, 80, on a curve heading into the normal band. His fear gets a visual reply. He has paid nothing; he has seen the artefact he came for.
His future selfThis is his projected Progress tab (§11.2) — the same chart he'll see post-purchase, not a stock demo.
His anchor cashedGGT 80 from screen 4 is the hollow today-dot. Quiz answer → WOW payoff, visibly.
Honest projectionForward segment dashed; band = published AASLD range; the sc-disc strip is non-negotiable. Never "cured/healed" — "into range", "the view you'll build".
Borrowed — Folik & Calibrum: the personalised future-self chart as the onboarding climax. Chart grammar reused from §11.2 exactly.
🌿
Your plan is ready, Robert.
We've set up your GGT recovery timeline, a sober-day tracker, and a Coach that talks about liver recovery — never about willpower.
📉  Recovery chart — GGT into the AASLD range
🔥  Sober-day streak + Day-60 milestone
💬  A Coach that never judges
Start my 7-day trial

Screen 7 · Post-WOW breath

A one-screen exhale between the WOW and the price. It names what he just saw and reassures on tone — then hands off to the offer while the catharsis is still warm.
Name the payoffRecaps the three things "built" — the WOW made concrete and ownable.
Tone reassuranceExplicit: the Coach talks recovery, not willpower. Robert's deciding fear ("will it judge me?") is answered before the price.
Warms the paywall"7-day trial" is named here, so screen 9 is not a cold open. Screen 8 (Proof, §15.4a) sits between this and the price.
Borrowed — Folik: the "your plan is ready" confirmation beat between WOW and paywall.
Screens 8 & 9. Screen 8 — the Proof screen is fully worked in §15.4a: the honest evidence-base "Millions" badge, placed here at the commitment moment. Screen 9 — the Paywall is Module 16 below — its headline must echo Robert's WOW ("Keep watching your liver recover · 7-day free trial"). The funnel ends where M16 begins.

15.6 · The WOW screen — across all 6 cohorts

Screen 6 is the same shell for everyone — a hero chart, three stats, one CTA — but the chart, the projection and the headline swap to the cohort. Same screen, six future selves. Every chart keeps the grammar: actual solid, projection dashed, guidance band, gold reference line.

Your plan🍷 Nick
Here's your liver back in range.
ALT projection
ALT 40
85
ALT now
40
Goal
~16w
Projected
This is my plan →
🍷 Newly Diagnosed Nick
His ALT crossing the AASLD-40 line answers "what diet?" without a word of diet copy.
Your plan💉 Greta
Watch your GLP-1 work on your liver.
ALT × weight
−34
ALT
−18
Pounds
dual
One view
Show me the proof →
💉 GLP-1 Greta
Two lines falling locked-step — the drug reached the organ, not just the scale.
Your plan🍔 Pete
Two numbers, one plan — here's the start.
HbA1c × ALT
6.0
HbA1c
70
ALT
↓↓
Together
Build my plan →
🍔 Pre-Diabetic Pete
Two falling lines answer "where do I start" — metabolic syndrome as one fight.
Your plan💊 Rachel
Your Rezdiffra story — documented.
FibroScan · F-stage
F3→F2
Stage
−4.4
kPa
📄 PDF
For insurer
Start documenting →
💊 Rezdiffra Rachel
The insurance-PDF chip is the price justification — shown before the price.
Your plan🧬 Patricia
PCOS and your liver — one screen.
ALT × cycle phase
−14
ALT
4
Cycles
linked
PCOS+liver
This is my plan →
🧬 PCOS-NAFLD Patricia
Cycle-shaded ALT — the two conditions she juggles, finally on one chart.
Your plan🍺 Robert
GGT 240 → 80 → into range.
GGT recoveryWatch
47
Days sober
−160
GGT
Day 60
Next
This is my plan →
🍺 Recovering Robert
His own number, 80, on a curve into the band — the fear gets a visual answer.
Compliance guard — every WOW chart. The forward segment is always dashed and labelled a projection. The shaded band is always published guidance (AASLD / AGA / EASL), never a personal forecast. The "a projection, not a personal medical prediction" disclaimer strip ships on all six. No WOW headline may say cured, healed or guaranteed — allowed verbs are into range, the view you'll build, projected. Robert's chart never shows the word "relapse" — a downward wobble is floored to "stable" per the §8.5 noise-floor rule.

15.7 · Reconciling with the built Swift onboarding

The iOS app already scaffolds a 9-step onboarding (OnboardingContainer.swift, steps 0–8). It is a pure question funnel — no WOW. Here is the exact mapping from the 9 built steps to the recommended B flow: what to keep, compress, merge, replace, and add.

Built Swift step→ B-flow screenActionNotes
0 · WelcomeViewS1 · WelcomeKEEPAlready a single-promise hero — minor copy polish only.
1 · PainHookViewS2 · Pain hookKEEPAlready the emotional hook — verify the per-cohort pain strings (Robert = GGT 240→80).
2 · CohortTriageViewS3 · Lane selectKEEP6 doors + "just exploring" — 1:1 match. Restyle door copy to the user-voice lines in §15.5.
3 · LabsKnownViewS4 · Quiz card 1COMPRESSFirst card of the merged quiz scroll. Add the optional inline value field.
4 · MedicationsQuizViewS4 · Quiz (conditional)MERGEFolded into the scroll, shown only when the cohort needs it — skipped for Robert. Still feeds CohortDetector.
5 · GoalsViewS4 · Quiz card 3COMPRESSBecomes the "goal in one line" card.
6 · DietPrefViewS4 · Quiz (conditional)MERGEFolded in, cohort-conditional — Nick/Pete/Greta see it, Robert can skip.
7 · CohortResultViewS5 · pre-WOW breathREPLACEThe text reveal is demoted — its resolveCohort() / CohortDetector logic is kept and now picks which WOW chart renders. The paragraph becomes the breath.
8 · TrustMethodViewS5 breath + S8 ProofSPLITThe AASLD/AGA/EASL method line moves into the pre-WOW breath; the full evidence content is elevated into the new Proof screen near the paywall (§15.4a).
— (not built)S6 · WOW screenADDThe personalised future-self chart — the one screen the Swift build is missing entirely.
— (not built)S7 · post-WOW breathADD"Your plan is ready" confirmation beat.
— (not built)S8 · Proof screenADDThe honest evidence-base badge (§15.4a) — partly from TrustMethod's content, elevated to a full screen at the commitment moment.
Net count & engineering reuse. Built = 9 question steps → B flow = 8 onboarding screens + paywall. The 4 separate quiz steps (3–6) collapse into 1 quiz scroll; CohortResult + TrustMethod (7–8) collapse into the pre-WOW breath + feed the Proof screen; 3 net-new screens are added (WOW · post-WOW breath · Proof). Net 9 → 8 — one fewer screen, with the catharsis the funnel was missing. Nothing is thrown away: CohortDetector and OnboardingAnswers are untouched — the resolved cohort now selects the WOW chart instead of selecting a paragraph; OnboardingState gains wow / wowConfirm / proof steps and loses the standalone cohortResult / trustMethod cases. The WOW chart is the same SwiftUI chart component as the Progress hero (§11.2) — built once, shown in onboarding as a projection and post-purchase as the live Progress tab.

15.8 · Module 15 — ready for review

Module 15 — ready for founder review. Three consilia run: structure (B · WOW-then-justify, Σ 5.00), length (B · 8 screens + paywall, Σ 4.83), trust (B · dedicated proof screen, Σ 5.00). §15.1 framed the +6–11pp WOW-then-justify formula; §15.5 worked all 8 screens for Robert with non-judgmental copy throughout; §15.6 drew the WOW for all 6 cohorts; §15.4a designed the honest evidence-base proof screen — "Millions" describing the research, never a userbase, with the source counts (400+ / 1,800+) substantiated from DECISIONS.md D12; §15.7 mapped the 9 built Swift steps → 8 B-flow screens. Compliance: pre-auth throughout (no email / Sign in with Apple before the paywall), every WOW chart an honest dashed projection, no diagnosis, no "cured", no fabricated userbase claim. To compliance sign-off: the proof-screen copy, the WOW headlines, the pain-hook lines. Next — Module 16 · Paywall.

15.9 · The reviews screen — designed honest, shipped dark

The founder asked for a Cysta-style "You're in good company" user-reviews screen in onboarding. But Cysta's locked design ships no reviews screen — it deliberately avoids social proof "until 25+ real reviews exist". Hepatica launches with 0 users / 0 reviews — a reviews screen pre-launch is fabricated social proof and a flat Apple 2.3.1 rejection. §15.9 resolves it honestly: the screen is designed now as a real artefact, but ships hidden and switches itself on only once enough real App Store reviews exist. Until then, §15.4a's evidence-base proof screen carries the social-proof beat alone.

Compliance rule — no review until it is real. The reviews screen renders only when the App Store shows ≥ 25 ratings for com.love8ko.hepatica in the user's storefront — Cysta's threshold. Below that it is skipped entirely; the funnel runs §15.4a Proof → Paywall with no gap. Every card is a verbatim, attributed real App Store review pulled from App Store Connect — never written, never composited, never reordered to mislead. First names only, no avatars, no fabricated counts; the rating number is the live App Store aggregate. The screen is feature-flagged off at launch and turned on by config once the threshold is met — no app update needed.
Before you decideYou're in good company
On the App Store
4.8
★★★★★
from 31 App Store ratings
★★★★★
"My ALT dropped from 78 to 49 in three months. Seeing the line move is what kept me logging."
— Daniel R. · App Store review
★★★★★
"The Coach explains my labs in plain English and tells me which guideline it's from. First app that didn't just say 'eat healthy'."
— Megan T. · App Store review
Reviews are unedited and shown exactly as written on the App Store. Hepatica does not select reviews to favour any outcome.
See my plan & pricing

The reviews screen — real, or not at all

The founder's instinct — social proof near the paywall converts — is right; the trap is fake proof. Hepatica's answer: design the screen for real, ship it dark, let real reviews unlock it.
Placeholder copyThe two cards above are illustrative mock copy for the workbench only — production cards are verbatim App Store reviews from App Store Connect, populated at activation.
The gateRenders only at ≥ 25 real ratings. Feature-flagged, config-toggled — no app update to switch on. Below the threshold the screen does not exist.
PlacementWhen active, sits after §15.4a Proof, before the Paywall. Pre-launch the slot is empty and the evidence Proof screen is the last beat before the price.
ComplianceApple 2.3.1 — no fabricated userbase, no composed or curated-to-mislead reviews; the aggregate rating is live, not hand-set.
Borrowed — Cysta AI: the "You're in good company" rating-card pattern and the explicit 25-review honesty rule. Hepatica adopts both — including that the screen does not exist until the reviews do.
МОДУЛЬ 16

Paywall — the funnel's payoff, cohort-routed

The second dashed TODO gate from flow.html §8.1, and the last beat of the WOW-then-justify formula. §16.1 runs the consilium, §16.2 works the paywall for Robert, §16.3 covers all 6 cohorts, §16.4 reconciles with the built Swift PaywallView. The rule Module 15 hands it: the paywall H1 must echo the WOW the user just saw. Modeled on Cysta AI's persona-routed fear-playbook. Status: draft — nothing locked.

16.1 · Paywall consilium — one paywall, or six?

Module 15 hands the paywall one rule — the headline must echo the WOW the user just saw. The consilium tests it: one fixed paywall, a cohort-routed fear-playbook, or a hard high-pressure variant? The 6 cohorts vote.

CandidateShapeRiskVerdict
A · One static paywallA single screen, identical for all 6 cohorts — a generic H1 ("Reverse fatty liver — a plan that fits you"), one fixed bullet set, one default tier. The as-built PaywallView.Breaks the M15 hand-off — the WOW just showed Robert his GGT curve, then the paywall says nothing about it. The funnel's anchor goes uncashed at the commitment moment.✗ Rejected
B · Cohort-routed fear-playbook ⭐One scaffold; the H1 swaps per cohort to echo that cohort's WOW, the 4 value bullets swap to what the cohort cares about, the proof band is constant. Tiers, prices, layout identical for all six.Six H1 strings + six bullet sets to keep compliant — handled in §16.3, all to sign-off. No fabricated claims — the H1 echoes a projection the user already saw.✓ Ships
C · Hard aggressiveCountdown timer, "discount expiring", loss-framed H1 ("Your liver won't wait"), pre-checked priciest tier, dismissal friction ("Are you sure?").Fear-mongering on a health app — Apple 4.5.4 / 3.1.2 scrutiny; corrodes the "Clinical Authority" brand; punishes anxious Nick and burned-by-judgment Robert. Refund-prone.✗ Rejected
Cohortaud %A · staticB · routed ⭐C · aggressive
🍷 Nick25351
💉 Greta15352
🍔 Pete20252
💊 Rachel8351
🧬 Patricia15251
🍺 Robert17251
Weighted Σ1002.485.001.35

Why B — the fear-playbook

B is unanimous (Σ 5.00). The paywall is one screen from a price, and M15 spent eight screens planting a cohort-specific anchor — a static paywall (A) lets that anchor die unspent. Robert kills A hardest: his WOW was his GGT 240→80 curve; a generic H1 makes the eight screens feel like a bait-and-switch. C is rejected with prejudice (Σ 1.35) — a countdown clock on a liver-disease app reads as predatory; Nick (anxious, 25%) and Robert (burned by judgmental apps, 17%) score it 1, and it threatens the whole "Clinical Authority" brand the design system locks. B keeps the proven Loveiko paywall layout and swaps only the words that echo the WOW.

⭐ B · cohort-routed fear-playbook — ships A · one static paywall — rejected · breaks the WOW echo C · hard aggressive — rejected · predatory, off-brand
Founder override — preselect Weekly. The built PaywallView preselects the cohort default tier (Family / Lifetime / Standard). For this design the paywall preselects Weekly $4.99/wk for every cohort — lowest sticker, habit-lock entry — with the other three tiers visible and one tap away. Weekly carries a 7-day free trial (consistent with the built "7-DAY TRIAL" badge and M15's "Start my 7-day trial" hand-off; resolves the CLAUDE.md "weekly no trial" line in favour of the trial). The fear-playbook routes the copy, never the price — every cohort sees the same four tiers at the same prices.

16.2 · The paywall, worked — Robert

The single scrollable paywall, B-variant, worked for Recovering Robert — his WOW was GGT 240→80 into range; the H1 continues that sentence. Non-judgmental throughout — never "addiction", "alcoholic", "relapse".

🌿
Hero image — deferred to a later sprint
Hepatica Pro
Keep watching your liver recover.
Your GGT recovery timeline, your sober-day streak, and a Coach that talks about healing — never willpower. Free for 7 days.
📚 Built on 400+ AASLD · AGA · EASL & PubMed sources
📉Your GGT recovery curve — tracked into the AASLD range
🔥Sober-day streak with Day-30, 60 & 90 milestones
💬AI Coach that explains every lab — and never judges
📄Doctor-ready PDF summaries for your next visit
7-DAY FREE TRIAL
Weekly
Free 7 days, then $4.99/wk · cancel anytime
$4.99/wk
MOST POPULAR
Standard · Annual
≈ $0.77/wk · 7-day free trial
$39.99/yr
2 PROFILES
Family · Annual
Adds a second profile · 7-day free trial
$79.99/yr
BEST VALUE
Lifetime
One-time · all future updates
$99
Start my 7-day free trial
Free for 7 days, then $4.99/week. Auto-renews. Cancel anytime in Settings.
Restore · Terms · Privacy
Hepatica is a Health & Fitness app, not a medical device — it does not diagnose disease or replace your doctor.

Standing in the user's shoes

Robert just saw his GGT curve bend into the AASLD band (§15.6). The paywall's first line — "Keep watching your liver recover" — is the continuation of that sentence, not a new pitch. The eight onboarding screens finally get cashed.
H1 echoes the WOWThe headline references the recovery curve Robert just watched — no new claim, no "cured / healed". Per cohort the H1 swaps (§16.3).
Weekly preselectedFounder override — $4.99/wk sits selected for habit-lock; Standard / Family / Lifetime stay visible and switchable. The CTA + then-line rebind on tap.
Proof bandA one-line echo of §15.4a — the evidence base, not a userbase. The honest trust anchor, right at the price.
Non-judgmentalBullets say "recovery curve", "sober-day streak", "never judges" — never "addiction", "relapse". Robert's deciding fear answered at the price.
Hero deferredThe image is a placeholder — visual assets are a later sprint; the layout reserves the space now.
ComplianceHealth & Fitness disclaimer present; no diagnosis; no fake reviews or userbase; light-mode forced. The 6 H1s + bullet sets go to compliance sign-off.
Borrowed — Cysta AI: the single-scroll fear-playbook scaffold (hero → H1 → value stack → tier grid → trust pill → CTA → restore → disclaimer), and the rule — no fake social proof on the paywall.

16.3 · The paywall × 6 cohorts

One scaffold, six fear-playbooks. The H1 echoes each cohort's WOW; the three lead value bullets swap to what that cohort cares about; the proof band, the four tier cards with Weekly preselected, the prices and the layout are constant.

Hepatica Pro🍷 Nick
Watch your ALT walk back into range.
📚 Built on 400+ AASLD/AGA/EASL sources
🧪 ALT/AST/GGT tracked toward the AASLD-40 line
📷 Photo any meal — a liver-friendliness score
💬 Coach answers "what do I eat?" — cited
Weekly · 7-day trial — selected
Start my 7-day trial →
🍷 Newly Diagnosed Nick
His ALT-into-range chart was the answer to "what diet?" — the H1 keeps it going.
Hepatica Pro💉 Greta
See your GLP-1 working — on your liver.
📚 Built on 400+ AASLD/AGA/EASL sources
📉 ALT and weight on one chart — proof past the scale
💉 Log your GLP-1 dose alongside every lab
👨‍👩‍👧 Family plan — add a second profile
Weekly · 7-day trial — selected
Start my 7-day trial →
💉 GLP-1 Greta
Two falling lines were her WOW; the paywall promises she keeps both.
Hepatica Pro🍔 Pete
Two numbers, one plan — keep them falling.
📚 Built on 400+ AASLD/AGA/EASL sources
🧪 HbA1c and ALT trended together
📷 Meal scanner scores every plate
💬 Coach tells you where to start, and why
Weekly · 7-day trial — selected
Start my 7-day trial →
🍔 Pre-Diabetic Pete
His fear was "where do I start" — the dual-line WOW answered it; the H1 sustains it.
Hepatica Pro💊 Rachel
Keep documenting your Rezdiffra story.
📚 Built on 400+ AASLD/AGA/EASL sources
📄 Insurer-ready PDF — FibroScan stage, kPa, dates
📊 FibroScan F-stage tracked over time
💊 Rezdiffra dose & lab log on one timeline
Weekly · 7-day trial — selected
Start my 7-day trial →
💊 Rezdiffra Rachel
The insurance-PDF chip justified the price before she saw it — the H1 names it.
Hepatica Pro🧬 Patricia
Keep PCOS and your liver on one screen.
📚 Built on 400+ AASLD/AGA/EASL sources
🧬 ALT trended against your cycle phase
🧪 Liver labs + PCOS markers in one dashboard
💬 Coach that understands both conditions
Weekly · 7-day trial — selected
Start my 7-day trial →
🧬 PCOS-NAFLD Patricia
Two conditions on one chart was the WOW; the paywall promises she never splits them.
Hepatica Pro🍺 Robert
Keep watching your liver recover.
📚 Built on 400+ AASLD/AGA/EASL sources
📉 GGT recovery curve toward the AASLD range
🔥 Sober-day streak with milestone markers
💬 A Coach that talks healing — never willpower
Weekly · 7-day trial — selected
Start my 7-day trial →
🍺 Recovering Robert
His own number, 80, headed into the band — the H1 is that sentence, continued.
What swaps, what stays. Swaps per cohort: the H1 (echoes the WOW) and the first three value bullets (the fourth — "Doctor-ready PDF" — is constant). Constant for all six: the proof band, the 4 tier cards with Weekly preselected, the prices, the layout, the CTA, the disclaimer. No cohort sees a different price or a different trial length. Every H1 echoes a projection the user already saw — no new claim is introduced at the paywall.

16.4 · Reconciling with the built Swift PaywallView

PaywallView.swift already renders all four tiers, the shimmer CTA, the badges, the footer links and the fine print in the Clinical palette. Three pure-UI changes bring it to the B design; RevenueCat wiring is the fourth.

ElementBuilt PaywallView doesB design needsAction
Tier preselectdefaultTier → greta/patricia = family, rachel = lifetime, else standard.Weekly preselected for every cohort (founder override).CHANGE
HeadlineOne hardcoded H1 — "Reverse fatty liver — a plan that fits you".Per-cohort H1 echoing the WOW — the 6 strings in §16.3.ADD
Value bullets4 fixed bullet rows, identical for all.First 3 bullets swap per cohort; the 4th ("Doctor PDF") constant.ADD
Proof bandNone.One-line "Built on 400+ AASLD/AGA/EASL & PubMed sources" above the tier stack.ADD
Tiers · badges · shimmer · footer4 tier tiles, gold/teal/deep badges, shimmer CTA, Restore/Terms/Privacy, fine print.Unchanged.KEEP
CTA + then-lineSwitch on selectedTier; weekly already "Start 7-day free trial" / "Free for 7 days, then $4.99/wk".Same — with Weekly preselected the trial CTA shows by default.KEEP
PurchasePlaceholder — purchase() sets isPro = true, no SDK.Real RevenueCat purchase.WIRE
RevenueCat wiring. RC products are already configured — hepatica.weekly / hepatica.yearly / hepatica.family.yearly / hepatica.lifetime, entitlement premium. The build replaces the placeholder purchase() with a Purchases.shared.purchase(package:) call mapping selectedTier → RC package, sets isPro from the premium entitlement on success, and wires Restore to restorePurchases(). Tier prices should read from the RC Offering rather than hardcoded strings, so a price change needs no app update. The three UI changes above (Weekly preselect · per-cohort H1 · proof band) are pure SwiftUI and land independently of the SDK work.

16.5 · Module 16 — ready for review

Module 16 — ready for founder review. One consilium run: B · cohort-routed fear-playbook (Σ 5.00, unanimous) over A · static (2.48) and C · aggressive (1.35). §16.2 worked the full single-scroll paywall for Robert — hero placeholder, WOW-echoing H1, proof band, 4-bullet value stack, 4 tier cards with Weekly preselected per the founder override, CTA, restore/terms, disclaimer. §16.3 gave the H1 + 3 bullets for all 6 cohorts. §16.4 mapped the built PaywallView.swift → the B design: three pure-UI changes (preselect Weekly · per-cohort H1 · proof band) plus the RevenueCat wiring of the placeholder purchase. Compliance: Health & Fitness disclaimer on the paywall, no diagnosis, no fake reviews or userbase, light-mode forced, hero image deferred. To compliance sign-off: the 6 paywall H1s, the 6 bullet sets, the §15.9 reviews-screen activation rule. The pre-auth funnel — Modules 15 + 16 — is complete. Continues below — M17 is a fresh-eyes restructure pass over the whole flow, M18 designs the post-paywall Setup walkthrough, and M19 settles the illustration style; the workbench now covers Modules 1–19.
МОДУЛЬ 17

Fresh-eyes flow restructure — a consilium pass over M1–18

The workbench was built incrementally across many sessions — design system, then the worked tabs, then the funnel. This module is the step-back pass: a fresh read of the whole flow, catching where the documents drifted from each other or from the built Swift app, fixing what could be fixed in place, and recording what is carried forward. §17.1 is the findings table; §17.2 re-confirms the contested tab order by vote; §17.3 records what was applied and what is carried.

17.1 · The fresh-eyes pass — what drifted

Seven findings from reading M1–18 end to end. Most are drift — a later module made an earlier one stale — and were fixed in place this pass. Two are workbench↔code gaps where the built Swift app and the workbench disagree; those become Swift V1 rework items. One is a real gap — a sequence the workbench never drew — filled by M18.

AreaWhat the fresh-eyes pass foundTypeResolution
flow.html §8.1 · flow2.html §14.1 — flow mapsOnboarding & Paywall still drawn as dashed "TODO · own consilium" gates, lede "deliberately not designed yet" — but M15 & M16 designed them.driftBoth flow maps rebuilt — Onboarding→M15, Paywall→M16, a Setup→M18 stage added, Disclaimer marked post-paywall. Fixed.
flow.html §8.2 — Disclaimer vs built DisclaimerView.swiftThe workbench mockup shows four info points + one "Continue" button. The built screen has "what Hepatica DOES / DOES NOT" blocks and two mandatory consent checkboxes — educational-use + AI-processing consent.wb ↔ code§18.2 redraws the Disclaimer reconciled — the AI-consent checkbox is compliance-required (Coach sends labs & messages to DeepSeek). §8.2 stands as the calm-framing reference.
RootTabView.swift — tab orderThe built bar is Today · Labs · +Log · Coach · Progress — the pre-re-evaluation order. The workbench locked Today · Coach · +Log · Progress · Labs at §4.3 (Coach promoted, Labs to the calm edge).wb ↔ code§17.2 re-confirms the workbench order by a 6-cohort vote; RootTabView is a Swift V1 rework item.
flow2.html §14.4 — open questionsListed "Onboarding & Paywall — still dashed TODO gates" as the next workbench set — stale once M15/M16 shipped.driftReplaced with the live open item — Swift reconciliation (tab order, the no-WOW onboarding, the paywall preselect). Fixed.
flow3.html — Module 15 bannerSection cross-references off by two — "§15.3 works the flow… §15.5 reconciles" where the real sections are §15.5 / §15.6 / §15.7.driftBanner cross-refs corrected. Fixed.
flow2.html §14.2 — cross-tab gapsCoach & Progress empty states, the Log alcohol safety strip, and the Coach verdict-pill decision — flagged honestly, still not drawn.carriedNot closed in this pass — they are real screens, not drift. Carried to the Swift V1 build as tracked TODOs; recommend a small follow-up workbench pass.
Post-paywall sequenceRootRouter gates Paywall → Disclaimer → Setup (5 cards) → Tabs. The 5-card Setup walkthrough existed only in Swift — the workbench never designed it.gapM18 designs the post-paywall Setup walkthrough — consilium, the Disclaimer reconciled, the 5 cards worked, all 6 cohorts. Fixed.
What the pass did not find. Tab order is consistent across all four HTML files — the drift is only against the built Swift. Cohort weights (Nick 25 / Greta 15 / Pete 20 / Rachel 8 / Patricia 15 / Robert 17) and pricing (Weekly $4.99 · Standard $39.99 · Family $79.99 · Lifetime $99) are stated identically everywhere. The 6-cohort model, the design-system tokens and the JTBD map hold across M1–16. The workbench is sound — this pass tightened the seams, it did not rebuild.

17.2 · The tab-order reconciliation — workbench vs the built app

The one place the workbench and the built Swift app openly disagree. RootTabView.swift was written before §4.3 re-evaluated the bar by interaction frequency. Two orders, the 6 cohorts vote — the winner is the canonical order both the workbench and the Swift V1 rework adopt.

CandidateOrder (left → right · centre FAB)Rationale
A · built-SwiftToday · Labs · +Log · Coach · ProgressThe order RootTabView.swift ships today — Labs second. Pre-dates the §4.3 frequency re-evaluation.
B · workbench ⭐Today · Coach · +Log · Progress · Labs§4.3's re-evaluated order — Coach is a near-daily surface (incl. the 2 a.m. anxiety check) so it sits at slot 2; Labs is consulted ~quarterly so it moves to the calm outer edge.
Cohortaud %A · builtB · workbench ⭐
🍷 Nick2535
💉 Greta1535
🍔 Pete2035
💊 Rachel845
🧬 Patricia1535
🍺 Robert1725
Weighted Σ1002.915.00

Why B — and why the Swift app changes, not the workbench

B is unanimous (Σ 5.00). Every cohort opens Coach far more often than Labs — Coach is the daily question surface, Labs is where a new panel lands once a quarter. Robert scores A=2: putting Labs at slot 2 buries the two surfaces he lives in — his Coach ("is it healing?") and his Progress recovery curve. Rachel is softest on A (=4) — she is the most Labs-heavy cohort, so Labs near the front costs her least — but even she prefers B. The vote settles it: the canonical order is Today · Coach · +Log · Progress · Labs; RootTabView.swift is re-ordered to match in the Swift V1 rework.

⭐ B · Today · Coach · +Log · Progress · Labs — canonical A · built-Swift order — superseded · RootTabView rework

17.3 · Restructure — applied & carried

Module 17 — the restructure pass. Applied this pass: both flow maps (flow.html §8.1, flow2.html §14.1) rebuilt to show M15/M16/M18 worked and the Disclaimer post-paywall; flow2.html §14.4–14.5 refreshed; the flow3.html M15 banner cross-refs corrected; all four files' nav + footers refreshed. Resolved by vote: the canonical tab order — B · Today · Coach · +Log · Progress · Labs (Σ 5.00). Carried to the Swift V1 rework: the RootTabView re-order, the Disclaimer's two consent checkboxes (§18.2), the no-WOW onboarding (§15.7), the paywall tier preselect (§16.4). Carried as a follow-up workbench pass: the §14.2 cross-tab gaps — Coach & Progress empty states, the Log safety strip, the Coach verdict-pill decision. Logged in DECISIONS.md D20.
МОДУЛЬ 18

Post-paywall onboarding — the Disclaimer & the Setup walkthrough

The funnel does not end at the paywall. RootRouter gates Paywall → Disclaimer → Setup (5 cards) → Tabs — and the Setup walkthrough existed only in Swift. This module designs it: §18.1 runs the card-set consilium; §18.2 reconciles the Disclaimer gate; §18.3 works the 5 cards for Nick; §18.4 covers all 6 cohorts; §18.5 reconciles with the built Swift Setup. Modeled on Cysta AI's post-paywall Setup pattern. Status: draft — nothing locked.

18.1 · Setup-flow consilium — which five cards?

The post-paywall Setup is the bridge between "I paid" and "I have a habit". Cysta AI runs five cards; the built Swift app runs a different five. Three card-sets, the 6 cohorts vote with the standard audience weights.

CandidateThe five cardsRiskVerdict
A · built-Swift, as-isWelcome → Tabs tour → Log first labs → Personalize → Ready."Tabs tour" is a generic feature tour with no cohort anchor. "Personalize" re-asks what the M15 lane-select already established. "Log first labs" as its own card pressures a day-1 action many users can't do yet — and a fail there sours the whole setup.✗ Rejected
B · Cysta semantics, literalWelcome → Focus → Baseline → Daily 90s plan → Ready.Faithful to Cysta's proven funnel and every card carries a cohort anchor — but Baseline is display-only, dropping the built app's genuinely useful "scan your first lab now" capture.✗ Rejected
C · Merge ⭐Welcome → Focus → Baseline (+ optional on-the-spot lab scan) → Daily 90s plan → Ready.None material. Keeps Cysta's anchored funnel, folds the built "log first labs" into Baseline as an optional scan, and drops "Personalize" as redundant — the cohort is already set in onboarding (M15).✓ Ships
Cohortaud %A · as-builtB · CystaC · merge ⭐
🍷 Nick25345
💉 Greta15245
🍔 Pete20345
💊 Rachel8345
🧬 Patricia15245
🍺 Robert17345
Weighted Σ1002.704.005.00

Why C — the merge

C is unanimous (Σ 5.00). The cohorts reject A because two of its five cards waste the user's attention: a generic tab tour teaches nothing the cohort cares about, and "Personalize" asks a question already answered three screens earlier. Greta & Patricia score A=2 hardest — their setup needs to feel like the app already knows them (GLP-1, PCOS), and a generic tour signals it doesn't. B fixes the anchoring but leaves the lab-capture on the table; C keeps it as an optional Baseline action — there if the user has a report to hand, never a blocker if not.

⭐ C · Welcome · Focus · Baseline · Daily 90s plan · Ready — ships B · Cysta literal — rejected · drops the lab capture A · as-built — rejected · two wasted cards
The locked Setup spine — 5 cards. 1 · Welcome — "you're in", set the 2-minute expectation. 2 · Focus — the cohort's top-3 surfaces, so Today doesn't open cold. 3 · Baseline — three day-1 entries (skippable), with an optional "scan a lab report" shortcut. 4 · Daily 90s plan — the Today→+Log→Coach loop, framed as 90 seconds. 5 · Ready — a per-cohort send-off into the right tab. Every card is skippable; the bar shows a 5-pill progress capsule + Back + Skip. Asset slugs: setup-welcome · setup-focus · setup-baseline · setup-plan · setup-ready (§ASSET_PROMPTS).

18.2 · The Disclaimer gate — reconciled with the built screen

The first post-paywall screen. flow.html §8.2 drew it as a calm four-point info screen with one Continue button — but the built DisclaimerView.swift carries two mandatory consent checkboxes: educational-use and AI-processing. The AI checkbox is not optional polish — the Coach sends labs and messages to DeepSeek, so explicit consent is a compliance requirement. §18.2 reconciles the two: §8.2's calm framing, the built screen's consent gate.

Hepatica 🌿
Before you start
Hepatica is your educational companion for fatty-liver health — here's what that means, and what it doesn't.
What Hepatica does
✓ Tracks your liver markers over time   ✓ Explains labs in plain language, with sources   ✓ Builds doctor-ready summaries
What it does not
✕ Diagnose NAFLD or MASH   ✕ Stage fibrosis   ✕ Replace your doctor or hepatologist
☑️Hepatica is for tracking and education — not a medical device, not a diagnosis, not a replacement for my doctor.
☑️I consent to Hepatica sending Coach messages and lab scans to our AI partner for processing, as described in the Privacy Policy.
I agree — Continue
Both boxes are required. By continuing you acknowledge Hepatica is a Health & Fitness app, not a medical device.

Standing in the user's shoes

The user just paid and wants in. This gate has to hold the line on compliance without feeling like a legal wall — calm header, plain DOES / DOES NOT, two checkboxes, one button that stays disabled until both are ticked.
Two consent checksEducational-use and AI-processing — both mandatory. The Continue button is disabled until both are ticked; this matches the built DisclaimerView.swift.
Why the AI boxThe Coach sends labs and messages to DeepSeek via the Worker proxy — explicit, separable consent is required, not bundled into a single "I agree".
DOES / DOES NOTThe warm verdict palette, never clinical red — the "does not" block uses the gold --cta-deep, not an alert tone. Diagnosis, staging and doctor-replacement are explicitly disclaimed.
PlacementFires once, post-paywall, immediately before the Setup walkthrough. Acceptance + timestamp persist to disclaimerAcceptedAt / aiConsent.
ComplianceEvery line drafted from COMPLIANCE.md. Supersedes the §8.2 single-button mockup; §8.2 stays the reference for the calm-framing tone. Copy to founder + compliance sign-off.
Borrowed — Cysta AI & JabWell: the post-paywall consent gate with separable AI-processing consent. The §8.2 calm "Before you start" framing is kept; the two-checkbox gate is added to match the built screen.

18.3 · The Setup walkthrough — worked for Nick

The 5-card C-variant walkthrough, worked for Newly Diagnosed Nick (25% — the mass cohort). Each card is a single job: a 5-pill progress capsule, a 1:1 illustration zone (asset deferred), one idea, one button. Skippable throughout.

Skip
🎨
setup-welcome · 1:1
Welcome to Hepatica Pro.
You're in. Two minutes to set up — then your liver dashboard is yours.
Let's go →
1 · Welcome
Lands the purchase — sets a 2-minute expectation, no task yet.
Skip
Here's where your focus goes.
① Labs — your ALT & AST, tracked to the AASLD-40 line
② +Log — photograph any meal for a liver score
③ Coach — ask "what do I eat?" — answered, cited
Next →
2 · Focus
The cohort's top-3 surfaces — so Today never opens cold.
Skip
Your day-1 numbers.
Three quick entries — skip any you don't have yet.
🧪 Latest ALT / AST — tap to add
⚖️ Weight or waist — tap to add
🩺 Main symptom — fatigue, none…
📷 Or scan a lab report instead
Got it →
3 · Baseline
3 day-1 entries — skippable — + the optional lab scan folded in.
Skip
90 seconds a day.
30s  Today — check your ALT trend
30s  +Log — a meal photo
30s  Coach — ask one question
Small, daily — and the line moves. That's the whole method.
I can do that →
4 · Daily 90s plan
The Today→+Log→Coach loop, framed as a 90-second habit.
🎨
setup-ready · 1:1
You're all set, Nick.
Your Today tab is built around your ALT. Start there — your first scan starts the streak.
Enter Hepatica →
5 · Ready
Per-cohort send-off into the right tab — Nick lands on Today.

18.4 · The Setup walkthrough × 6 cohorts

One 5-card spine, six fittings. The Baseline card is the most cohort-distinct — shown here for all six. Its three day-1 entries swap to what that cohort tracks; the Focus surfaces and the Ready send-off swap with it.

Setup · 3 of 5🍷 Nick — your day-1 numbers
🧪 Latest ALT / AST
⚖️ Weight or waist
🩺 Main symptom
Got it →
🍷 Newly Diagnosed Nick
Focus: Labs · +Log · Coach. Ready → Today.
Setup · 3 of 5💉 Greta — your day-1 numbers
💉 GLP-1 med & dose
⚖️ Starting weight
🧪 Latest ALT
Got it →
💉 GLP-1 Greta
Focus: Progress · +Log dose · Coach. Ready → Progress.
Setup · 3 of 5🍔 Pete — your day-1 numbers
🩸 Latest HbA1c / glucose
⚖️ Weight
🧪 Latest ALT
Got it →
🍔 Pre-Diabetic Pete
Focus: Labs · +Log meal · Today. Ready → Today.
Setup · 3 of 5💊 Rachel — your day-1 numbers
💊 Rezdiffra start date
📊 Baseline FibroScan kPa / stage
🧪 Latest labs
Got it →
💊 Rezdiffra Rachel
Focus: Labs · Progress PDF · +Log dose. Ready → Labs.
Setup · 3 of 5🧬 Patricia — your day-1 numbers
🧬 PCOS diagnosis date
🗓 Cycle day today
🧪 Latest ALT
Got it →
🧬 PCOS-NAFLD Patricia
Focus: Labs · Today PCOS+liver · Coach. Ready → Today.
Setup · 3 of 5🍺 Robert — your day-1 numbers
🗓 Sober-since date
🧪 Latest GGT
🎯 Your main goal
Got it →
🍺 Recovering Robert
Focus: Progress GGT · Today streak · Coach. Ready → Progress.
What swaps, what stays. Swaps per cohort: the Focus three surfaces, the Baseline three entries, and the Ready send-off tab. Constant for all six: the 5-card spine, the progress capsule, Back / Skip on every card, the Welcome and Daily-90s-plan copy, the skippability rule. The cohort itself is not re-asked — it was set at M15 lane-select and simply read here. No card is ever a hard gate: a user with no labs to hand skips Baseline and still reaches Today.

18.5 · Reconciling with the built Swift Setup

The Swift app already has a SetupContainer + SetupState and five screen files — but candidate A's five, not C's. Bringing it to the C design is two renames, one merge, one drop, two new screens.

ElementBuilt Swift Setup doesC design needsAction
SetupContainer / SetupState5-step container, 5-pill progress, Back + Skip, slide transitions, finish()setupComplete.Same container — the step list changes to Welcome / Focus / Baseline / Daily-plan / Ready.KEEP
SetupWelcomeView · SetupReadyViewWelcome card + "you're all set" card.Kept — polish copy; Ready gets a per-cohort send-off line + entry tab.KEEP
SetupTabsTourViewGeneric 4-tab feature tour.Becomes SetupFocusView — the cohort's top-3 surfaces.CHANGE
SetupLabEntryOfferViewStandalone "log your first labs" card.Folded into Baseline as an optional "scan a lab report" row — no longer its own step.MERGE
SetupCohortSetupView"Personalize to your situation."Dropped — the cohort is already set at M15 lane-select; re-asking is the rejected candidate A.REMOVE
SetupBaselineView (new)3 cohort-specific day-1 entries, all skippable, + the optional lab-scan shortcut.ADD
SetupDailyPlanView (new)The Today→+Log→Coach loop card, "90 seconds a day".ADD
Baseline dataEntries persist to onboardingAnswersJSON + the lab store, so Today opens populated.WIRE
Disclaimer + Setup, in the gate chain. RootRouter already gates Paywall → DisclaimerViewSetupContainerRootTabView behind disclaimerAcceptedAt / setupComplete — the chain is correct and stays. The §18.2 reconcile is copy-only on DisclaimerView (the two consent checkboxes already exist there). The Setup work is the five screens above; the cohort is read from cohortRaw, never re-asked. All Setup screens force light mode and reuse the shared ContinueButton / HeroImage components.

18.6 · Module 18 — ready for review

Module 18 — ready for founder review. One consilium run: C · the merge (Σ 5.00, unanimous) over B · Cysta-literal (4.00) and A · as-built (2.70) — the locked 5-card spine is Welcome · Focus · Baseline · Daily-90s-plan · Ready. §18.2 reconciled the Disclaimer gate with the built two-checkbox DisclaimerView (educational-use + AI-processing consent). §18.3 worked all 5 cards for Nick; §18.4 fitted Baseline + Focus + Ready to all 6 cohorts. §18.5 mapped the built Swift Setup → the C design: keep the container, rename TabsTour→Focus, merge LabEntryOffer into Baseline, drop CohortSetup, add Baseline + DailyPlan. Compliance: Health & Fitness throughout, two explicit consent checks, no diagnosis, light-mode forced, hero images deferred to the asset sprint. To compliance sign-off: the Disclaimer copy, the Setup card copy. With M17 + M18 the workbench covers Modules 1–18 — the whole flow, pre-launch through the first daily loop. M19 below settles the in-app illustration style.
МОДУЛЬ 19

In-app illustration & hero system — the asset-style consilium

The asset prompts were first drafted in the editorial-photography style of the sibling Cysta AI (logged D22). The founder challenged it — Hepatica has a different design system and a different audience. This module runs the consilium properly: §19.1 votes the visual direction; §19.2 specs the winning illustration system. The detailed per-asset prompt file is private/ASSET_PROMPTS.md. Status: draft — nothing locked.

19.1 · The asset-style consilium — photography, or illustration?

Two locked documents already point the way. DESIGN_SYSTEM.md names the aesthetic «Mayo Clinic × Headspace» and its onboarding rule says «Illustrations only до disclaimer-accept» — the visuals were always conceived as illustration. And design.html §7.3 locks an anti-pattern: «no glowing livers, no detox juices — the category is clinical authority, not wellness». Editorial apothecary still-life (dried botanicals, herbal tea, linen) is exactly the wellness register that anti-pattern rejects. Three directions, the 6 cohorts vote.

apothecary still-life · linen · dried botanicals
A · Editorial photography
Cysta DNA — premium, but a wellness-boutique register.
B · Calm clinical illustration ⭐
Mayo × Headspace — the locked design system itself.
C · Hybrid
Illustration base + photo heroes — two vocabularies.
CandidateShapeRiskVerdict
A · Editorial photographyThe first-draft style — editorial product photography, apothecary still-life, dried liver botanicals, linen, no faces. Sibling Cysta / Folik / Salvora DNA, re-palettised teal/gold.It is the wellness register §7.3 explicitly rejects; reads precious / lifestyle-boutique to the older, male-skewing NAFLD cohorts; mismatched to the «Headspace» half of the locked design system.✗ Rejected
B · Calm clinical illustration ⭐Soft semi-flat vector illustration — gentle gradients + paper grain, warm rounded forms, generous negative space, abstract metaphors (a line easing into a band, a path, a calm horizon); the liver only as the brand's abstract teal→gold lobe.None material. Must be rich craft-illustration (Headspace-grade depth & texture), never cheap flat clip-art — handled in §19.2's style DNA.✓ Ships
C · HybridIllustration as the base system, plus a few photographic heroes on the highest-stakes screens (paywall, proof).Re-imports the wellness/photography problem exactly on the paywall, where it costs most; two vocabularies for a solo founder to keep coherent.✗ Rejected
Cohortaud %A · photoB · illustration ⭐C · hybrid
🍷 Nick25354
💉 Greta15445
🍔 Pete20254
💊 Rachel8245
🧬 Patricia15454
🍺 Robert17254
Weighted Σ1002.854.774.23

Why B — calm clinical illustration

B wins clearly (Σ 4.77). It is not a new idea — it is what DESIGN_SYSTEM.md already specifies («Mayo Clinic × Headspace», «illustrations only до disclaimer-accept»). Pete (20%) and Rachel (8%) kill A hardest (=2): a practical pre-diabetic man and a $40K-drug MASH patient read apothecary still-life as lifestyle fluff, not clinical authority. Robert (17%) scores B=5 — Headspace's calm illustration is the visual language of recovery apps; it lowers health anxiety where a precious photograph cannot. Greta & Patricia (the wellness-leaning cohorts) are the only ones who warm to A — and even they prefer B or C. C is rejected not on taste but on incoherence: a photographic paywall hero drops the user back into the wellness register at the exact moment authority matters most, and two vocabularies are a consistency tax a solo founder shouldn't pay. Runoff note: B only wins if it is executed as rich illustration — Headspace-grade craft, depth, gradient, texture — never flat clip-art. The earlier photography pick (D22) is superseded; logged D23.

⭐ B · calm clinical illustration — ships A · editorial photography — rejected · wellness register, off-system C · hybrid — rejected · incoherent at the paywall

19.2 · The illustration system — what B is

One coherent illustration language across every generated asset — onboarding heroes, paywall heroes, the Setup cards, empty states and icons. The detailed per-asset prompts live in private/ASSET_PROMPTS.md; this is the system it is built on.

DimensionThe B system
RegisterCalm clinical illustration — «Mayo Clinic × Headspace»: clinical clarity meets Headspace calm. Reassuring, never anxious; authoritative, never cold.
RenderSoft semi-flat vector — gentle gradients, subtle paper-grain texture, soft diffused light, warm rounded organic forms, generous negative space, no harsh outlines. Rich craft-illustration, not flat clip-art, not 3D, not photoreal.
PaletteThe locked tokens only — teal #2D7B7E + warm gold #D4A574 + off-white #EEF3F2; warm severity (amber → clay) used sparingly. No clinical red, no neon.
SubjectsAbstract calm metaphors — a line easing into a guidance band, a path of stepping stones, a low calm horizon at sunrise, concentric rings, a single unfurling leaf, a tide going out. The liver appears only as the brand's abstract teal→gold lobe glyph — never anatomical, never a literal organ.
Carry-over rulesNo faces / no people; no liver-anatomy close-ups (locked anti-pattern); no clinical red; zero alcohol imagery anywhere (Robert hard rule + veto); no cute mascots or organs-with-eyes.
Inventory23 imagesets — Sprint B (7 onboarding heroes, 3:4) · Sprint C (6 paywall heroes 3:4 + 5 Setup cards 1:1) · Sprint E (5 empty-state / icon, 1:1). Slugs, screens and aspect ratios unchanged from the first draft.
Aspect matrix3:4 — full-screen heroes (onboarding + paywall, contained) & pdf-cover. 1:1 — Setup cards, empty states, icons. 9:16 not used in V1.
The prompt spec. private/ASSET_PROMPTS.md (gitignored, founder-only) is rewritten to this system: a calm-illustration master skeleton, all 23 per-asset concepts re-imagined as illustration metaphors, the 7-point WOW QA gate, and a 6-cohort weighted Σ≥7.5 lock per asset. Hero images are generated in a later visual-assets sprint; the workbench mockups (M15/M16/M18) keep the dashed placeholder zones until then. The shared Swift HeroImage component renders each asset with a Color.hepBrandSoft fallback until its PNG lands.

19.3 · Module 19 — ready for review

Module 19 — ready for founder review. One consilium run: B · calm clinical illustration (Σ 4.77) over C · hybrid (4.23) and A · editorial photography (2.85). The decision realigns the asset style with the locked design system («Mayo Clinic × Headspace») and the §7.3 «clinical authority, not wellness» anti-pattern, and fits the older, male-skewing NAFLD audience. §19.2 specs the system; private/ASSET_PROMPTS.md is rewritten to match (23 assets, illustration prompts). Supersedes D22 — logged DECISIONS.md D23. The workbench now covers Modules 1–19; the whole product is designed end to end — flow, funnel, post-paywall, and the visual system.
МОДУЛЬ 20

User-action matrix — the coverage audit before Swift

Modules 8–19 designed the screens. This module checks the coverage: every user action × every state it can be in — happy, empty, error, offline, edge, and light/dark — so the Swift build inherits no undesigned path. §20.1 is the matrix; §20.2 closes the gaps it surfaces (incl. paywall back-navigation and the light/dark contrast audit); §20.3 specs the debug menu as the tool that makes every path reachable for testers.

20.1 · The matrix

Every user action down the side; every state across the top. designed · gap to close in §20.2 · not applicable. The Light/Dark column tracks whether the surface has been contrast-audited in both appearances — dark mode was deferred to the Swift build, so the core tabs read ⚠ until audited.

User action HappyEmptyErrorOfflineEdgeLight/Dark
PRE-AUTH FUNNEL
Cold launch / resume
Onboarding triage / WOW
Paywall — view & purchase
Paywall — back / skip
Disclaimer · Setup walkthrough
TODAY
Open Today / cohort dashboard
Toggle light/dark theme
+LOG (5 MINI-FLOWS)
Log meal photo
Log drink / sober day
Log lab / medication / symptom
COACH
Ask the Coach
Follow-up · switch view · export PDF
LABS · PROGRESS · SETTINGS
Scan lab → OCR confirm
View analyte grid / trends
Milestone · doctor PDF export
Switch cohort · customise Today
Restore / manage subscription
What the matrix surfaces — 9 gaps. Empty: Coach first-open and Progress pre-data have no designed skeleton (the M14 §14.2 gaps). Error: paywall purchase-failure, failed meal/lab capture, failed lab-OCR, subscription-restore failure. Offline: Coach has no offline fallback; paywall & restore need an offline notice. Edge: the paywall is a locked gate (no back-navigation), there is no "undo a log", and the drink log has no safety strip (M14 §14.2). Light/Dark: the core tabs (Today, Labs, +Log, Settings) are designed light-only — dark mode is unaudited, the recurring white-on-white risk. §20.2 closes all nine.

20.2 · Closing the gaps

The nine gaps, resolved. The two empty states are drawn (the §8.6 ghost-skeleton pattern); the rest are decisions + rules the Swift build inherits.

💬
Your Coach is ready
Ask anything about your liver, your labs or your plan — answers are cited to AASLD · AGA · EASL.
"Is my ALT of 84 dangerous?"
"What should I eat tonight?"
Coach — empty state
Ghost avatar + 2 cohort starter prompts — never a blank thread.
your trend line builds here
One point logged. Two more and the line begins.
Progress needs a few data points before a trend is honest. Keep logging — the curve appears at point 3.
Log today's number →
Progress — pre-data state
Dashed ghost chart + honest "needs 3 points" — no fabricated trend.
Paywall navigation (amends M16.2). The paywall is no longer a locked gate. A back affordance returns the user to the onboarding/WOW screens so they can re-read what they're buying before committing — the funnel is reviewable, not a trap. For TestFlight a tester-only Skip (Folik pattern) passes the paywall without a purchase — gated by the same two-arm #if DEBUG + TestFlight check as §20.3, stripped from App Store builds. The four tiers, prices and Weekly-preselect (M16) are unchanged.
Light/dark theme — contrast audit + the Today toggle. The recurring sibling bug is white text on a white surface when a screen built light-only is forced dark. Rule for the Swift build: every text colour is a semantic token that flips with appearance — never a hardcoded white/near-white; the verdict triad and the --night-* tokens (already in DESIGN_SYSTEM.md) define both modes; every screen is checked in both before merge. A light/dark toggle sits on the Today tab, writing a theme @AppStorage override (System / Light / Dark). Coach keeps its 22:00–06:00 night-auto. The workbench's own M9 Coach chat mockups were re-checked — bubbles use var(--ink) on tinted backgrounds, no white-on-white.
Error · offline · undo. Coach offline — no network → the canned fallback "Coach is offline — here's your tracked data and trend summary" (per API_REGISTRY.md), never a spinner that hangs. Failed capture / OCR — meal, lab and OCR failures show a retry + a manual-entry path, never a dead end. Purchase / restore failure — a plain inline error + retry, the paywall stays usable. Undo a log — every +Log capture shows an undo on its confirmation toast (a mis-logged drink or meal is reversible). Log safety strip — the drink log carries the COMPLIANCE.md alcohol-support line ("for alcohol-use-disorder support, talk to a professional"). Coach verdict stays prose, not a triad pill — confirmed deliberate (a chat answer is not a lab row).

20.3 · Testing surfaces — the debug menu

A coverage matrix is only honest if a tester can actually reach every cell. The standard tool — already scaffolded in the Swift app — is an in-app floating debug overlay with a jump-to teleporter.

The pattern (industry-standard, Loveiko reusable). A draggable floating activator (a gold wrench) opens a debug panel with: (a) jump-to teleporter — teleport straight to any phase (Onboarding 0–8 · Paywall · Disclaimer · Setup 0–4 · any Core tab) via transient @AppStorage keys; (b) presets — Day-0 (wipe) and Day-30 (seed a power-user with mock labs/streaks); (c) manual flag toggles. Buttons grouped by phase. The built DebugFloatingButton + DebugPanelView + DemoSeed already implement this.
The TestFlight wrapper — make it appear on the phone, never in the App Store build. The leak-proofing is a two-arm gate: the debug overlay renders when #if DEBUG OR the app is a TestFlight build — detected by the sandbox App Store receipt (appStoreReceiptURL path ends sandboxReceipt), the check already in Utils/BundleDebugFlags.swift. Result: the panel is live for the founder in Xcode and for TestFlight testers on-device, and is compiled out of the public App Store release. Locked as the Loveiko standard — any new project wires it from this section in ~30 minutes.

20.4 · Module 20 — ready for review

Module 20 — ready for founder review. The user-action matrix audited every action × six states and surfaced 9 gaps, all now closed: the Coach & Progress empty states are drawn (ghost-skeleton, §8.6 pattern); paywall back-navigation + a TestFlight Skip are specced (amends M16.2); the light/dark contrast rule + the Today theme toggle are locked; error / offline / undo / the Log safety strip are decided; the Coach verdict stays prose. §20.3 locks the floating debug menu + jump-to teleporter with a two-arm TestFlight wrapper. To the Swift build: the matrix is the QA checklist — no path ships undesigned.
МОДУЛЬ 21

The Coach engine — RAG × DeepSeek, modeled on Cysta AI & Salvora

M9 designed the Coach screen — the specialist-view panel, verdict-first, per-cohort tone. This module designs the engine behind it, so the RAG knows how everything is loaded and works. The siblings Cysta AI and Salvora already ship this exact stack — M21 maps it onto Hepatica's built networking layer and the already-built liver_knowledge.sqlite corpus. §21.1 architecture · §21.2 the RAG · §21.3 the request pipeline · §21.4 the prompt library · §21.5 the Coach UI & Swift reconcile.

21.1 · Architecture — five components, all copied from siblings

The Coach is not invented here. Cysta AI and Salvora shipped a cited, RAG-grounded chat; Hepatica copies the five components and re-points them at the liver corpus and the 6 cohorts.

ComponentCopied fromWhat changes for Hepatica
RAGServiceCysta Services/RAGService.swiftLoads liver_knowledge.sqlite instead of pcos_knowledge.sqlite; identical in-memory cosine retrieval.
CoachServiceCysta Services/CoachService.swiftLiver intent-classifier triggers (jaundice, withdrawal, Rezdiffra dosing); same retrieve → prompt → DeepSeek path.
PromptLibraryCysta + Salvora Services/PromptLibrary.swiftLiver-coach base prompt; 6 Hepatica cohorts; the 3 specialist views (M9); liver compliance rules.
CoachThreadStoreSalvora Core/Stores/ChatThreadStore.swiftPer-thread cohort snapshot (Salvora snapshots persona); UserDefaults-JSON threads.
Coach UICysta Features/Coach/*ChatThreadDetailView · MessageBubble · SourceBlock · CoachFollowupParser — re-themed Clinical; the M9 specialist-view panel.
Already in place. Services/API.swift + APIClient.swift route to the deployed Worker hepatica-api.veribag.workers.dev (/deepseek, /openai). liver_knowledge.sqlite is built and sits in Hepatica/Hepatica/Resources/. The build only adds the five Swift components above — no new infrastructure.

21.2 · How the RAG is loaded & works

The on-device knowledge base — how it ships, how it loads, how a query finds its sources. No sqlite-vec extension: retrieval is pure-Swift cosine over an in-memory cache.

StageWhat happens
Shipliver_knowledge.sqlite (~7.6 MB — meta / sources / chunks; each chunk a 512-float embedding as a BLOB) is bundled in Resources/add it to the bundle target in project.yml. Built by the scripts/rag/ pipeline from AASLD · AGA · EASL · FDA · PubMed (per RAG.md).
LoadAt app launch RAGService.shared opens the DB, reads every chunk + source into memory (~3–8 MB resident), then closes the file. All later queries hit the in-memory cache. DB missing/corrupt → silent graceful degrade (RAG returns empty).
Embed the queryThe user's question is embedded via the Worker /openai route — text-embedding-3-small @ 512 dimensions (same model + dims the corpus was built with). An LRU cache (≤100 entries) avoids re-embedding repeats.
RetrieveBrute-force cosine similarity of the query vector against every cached chunk; sort; take top-K (K≈5). Dimension mismatch (≠512) → return empty, never crash.
Hand offThe top-K chunks + their source citations are passed to PromptLibrary for the system-prompt RAG block. Zero hits → the no-RAG-hit honest hedge (§21.4).

21.3 · The CoachService pipeline

What happens between the user tapping send and the answer appearing. Seven steps; the intent classifier and the no-hit hedge are the compliance guards.

1✍️
User message
Sent with the thread history + the thread's cohort snapshot.
2🛡
Intent classifier
Client-side. Crisis (jaundice, vomiting blood, withdrawal, suicidal) · diagnosis-ask · dosing-ask → a canned refusal pivot, no LLM call.
3🔍
RAG retrieve
§21.2 — embed the query, cosine top-K liver-corpus chunks + citations.
4🧩
Context resolution
Inject the user's own loaded data — recent labs ≤90d, meals, streak, cohort — so the Coach answers about their numbers.
5📝
Assemble prompt
PromptLibrary builds the system prompt — base + compliance + cohort tone + specialist view + RAG block (§21.4).
6🤖
DeepSeek
Worker /deepseekdeepseek-chat, temp 0.4, max 1200, non-streaming, 30s timeout.
7
Parse → answer
Extract text, [cN] citations and the [follow_ups] block → CoachAnswer → render.
Steps 2 and the no-hit hedge are the guards — the Coach never diagnoses, never invents a citation, never hangs offline (canned data-summary fallback).

21.4 · The prompt library — views, cohorts, compliance

The system prompt is assembled from blocks. The base role + compliance rules are constant; the specialist view and the cohort tone swap per thread; the RAG block swaps per query.

BlockContent
Base role"An educational liver-health coach grounded in AASLD / AGA / EASL / Mayo / PubMed. Not a physician — does not diagnose, prescribe or stage."
Compliance rulesFrom COMPLIANCE.md — no diagnosis ("consistent with", never "you have NAFLD"); no "cure / reverse" as a cure claim; no FibroScan/FIB-4 staging; no medication dosing; Rezdiffra disclaimer; alcohol framed as recovery, never judgment; every answer cites or pivots.
3 specialist views🫀 Hepatology (AASLD · EASL · Mayo — enzymes, fibrosis, diet) · 🍺 Recovery (NIAAA · AGA — alcohol, recovery timelines, non-judgmental) · ⚖️ Metabolic (ADA · Endocrine Society — glucose, weight, GLP-1, PCOS). A view is a guideline perspective, never a named person.
Cohort → default view🍷 Nick → Hepatology · 💉 Greta → Metabolic · 🍔 Pete → Metabolic · 💊 Rachel → Hepatology · 🧬 Patricia → Metabolic · 🍺 Robert → Recovery. The answer leads with that view; the other two collapse into "+ 2 more views" (M9 v2).
Cohort tone6 tones (M9 v3) — Nick empathetic-educator · Greta progress-focused · Pete triage-guide · Rachel clinical-partner · Patricia hormonal-systems · Robert non-judgmental-recovery.
Escalation triggersJaundice · vomiting blood · severe abdominal pain · alcohol-withdrawal symptoms · suicidal ideation → an immediate "seek urgent care / 988" pivot, ahead of any RAG answer.
Response shapeVerdict-first (M9 v2) — a plain bold answer, then the cited reasoning, then a calm disclaimer. Inline [cN] citation markers; a closing [follow_ups] block of ≤2 next questions.
No-RAG-hit hedgeZero chunks retrieved → the prompt instructs an explicit hedge ("I don't have a specific reference for this — here's general guidance, confirm with your doctor"). Never fabricate a citation.

21.5 · The Coach UI & reconciling with the built Swift

M9 designed the screen; the built app has a CoachView stub. The UI is copied from Cysta's Coach feature and re-themed Clinical.

ElementBuilt todayThe buildAction
CoachViewTabs/CoachView.swift — a StubScreen.Thread list → ChatThreadDetailView (scroll + composer), the M9 specialist-view panel.BUILD
MessageBubbleUser right / assistant left + safety strip + SourceBlock + follow-up chips. Renders **bold** / *italic* via AttributedString(markdown:) and strips inline [cN] markers — so asterisks become bold, never literal text.BUILD
SourceBlockCollapsible "N sources" chip → numbered citation cards, tap → in-app browser.BUILD
API routesAPI.swift/deepseek + /openai defined & reachable.Unchanged — CoachService / RAGService call them.KEEP
Corpusliver_knowledge.sqlite in Resources/.Add to the project.yml bundle target so it ships in the app.WIRE
The «asterisks» fix. Raw DeepSeek output contains Markdown (**bold**) and inline [c1] citation markers. Rendered verbatim, the asterisks show as literal characters — the "system error" the founder flagged. The fix is the Cysta MessageBubble pattern, copied as-is: convert the text with AttributedString(markdown: .inlineOnlyPreservingWhitespace) so **…** renders bold and *…* italic, and regex-strip the [cN] markers from the body (the citations render in SourceBlock instead). Locked into the M21 build spec.

21.6 · Module 21 — ready for review

Module 21 — ready for founder review. The Coach engine is specced as five components copied from Cysta AI & Salvora — RAGService, CoachService, PromptLibrary, CoachThreadStore, the Coach UI — re-pointed at liver_knowledge.sqlite and the 6 cohorts. §21.2 documents how the RAG ships, loads and retrieves (in-memory cosine, 512-d, top-K); §21.3 the 7-step pipeline with the client-side intent classifier; §21.4 the prompt library — 3 specialist views, 6 cohort tones, the compliance rules, the no-hit hedge; §21.5 the Coach UI + the Markdown-rendering fix for the asterisks bug. With M20 + M21 the workbench covers Modules 1–21 — the product is designed end to end. The Swift V1 build is the next track, starting with the D20 funnel reconcile.