← Back to Quietkeep

Planning for Humans

Why Quietkeep is shaped the way it is.

Every feature below is traced to the finding that motivated it, and every finding carries an epistemic tag, because the strength of the evidence varies enormously and pretending otherwise would be dishonest about a subject where people have been sold a great deal of confident nonsense.

A design decision resting on an emerging or community-construct finding is built so it can be removed. One resting on a negative finding is a prohibition, and prohibitions here are permanent.

Two things this document is not. It is not a claim that Quietkeep is a clinical intervention — it is not, and product law 7 forbids the app from talking that way. And it is not a claim that these findings describe any particular user. They describe patterns the design must not break under. If a pattern doesn't apply to you, the app should still be fine; nothing here is diagnostic.


1 · Why "return" is the whole product

Findings:

What follows. The relief of capture is real and it arrives immediately. That is the trap. Once the thought is written the intrusion quiets, internal rehearsal stops, and the item's survival now depends entirely on the tool. If the tool's resurfacing depends on the user's habit of reviewing, it has handed the job back to the capacity that was failing.

So: the return has to be structural.

→ Product law 1 (no silent nodes), enforced at the write boundary rather than by a sweep (ADR-0011). → Product law 2 (the coverage gauge) — the invariant is not just held, it is shown, because a promise the user cannot verify is one they must take on faith, and this audience has been let down by such promises before. → Cue conversion: wherever possible a time-based obligation becomes an event-based one. This is the whole argument for T1 .ics export — the OS calendar fires the cue whether or not the app is open (ADR-0007).


2 · Why there is no "overdue"

Findings:

What follows. An "overdue" flag adds aversion to a task that is already aversive, and it does so at the exact moment the person is deciding whether to approach it. It is a machine for producing the behavior it labels.

Streaks are the same error with better marketing. A streak converts something you valued into a score, and its real design purpose is the moment it breaks. For someone whose engagement is genuinely variable, that is a manufactured quitting moment.

The two negative findings are load-bearing prohibitions:

Nothing in Quietkeep may assume willpower is a tank — no "you have used your focus for today", no depletion model, no discipline framing. Nothing in Quietkeep may claim to train an underlying capacity. It is a prosthesis, not an exercise regime. It does not make you better at remembering; it remembers.

→ Product law 5, one decay primitive, continuous pressure, "ready again" (ADR-0010). → Product law 3, no past bucket — a passed date becomes a decision, not a mark (ADR-0012). → KC Davis: care tasks are morally neutral. (community-construct — a practitioner framework, widely adopted, not an experimental result.) Undone laundry is not a moral failing. This sets the voice throughout: shame-free, adult, never a rebuke.


3 · Interruption, focus, and getting back

Findings:

What follows. The interruption is not preventable — walk-ins are the job. What is designable is the cue at suspension and the route back.

→ Focus anchor — a manual one-tap "Focus" on any item, which models the state explicitly rather than inferring it. → Capture during focus auto-pairs a resume card, with an optional five-word "I was about to…" prompt. This is Trafton's interruption-lag cue, made cheap enough to actually happen. It is skippable, and skipping is unremarkable — a prompt that nags during an interruption is itself an interruption. → Interrupt gesture (pin + capture) from anywhere, 2-second budget (ADR-0008). Two seconds is not a performance target picked for tidiness — it is roughly the width of the interruption lag. → Resume cards rank above pressure in Next-up. Leroy's residue says the unresolved prior task is already consuming attention; finishing it is cheaper than starting something else on top of it. → Unspent resume cards convert to a day-end review question, never to a reproach. → Because monotropism and hyperfocus are emerging, nothing structural depends on them. They inform ergonomics — the cost of a switch, the value of not fragmenting a session — and if the accounts change, the design bends rather than breaks.

Cirillo's interruption protocol (community-construct — a widely used practitioner technique, not a validated finding): capture the interruption, protect the current block, return. Quietkeep borrows the shape — capture without leaving — and drops the timer, which is a demand.


4 · Clarify, breakdown, and the two-minute rule

Findings:

What follows.

→ Clarify shows one card at a time with forced-choice routing (Do now · Next action · Waiting For · Someday · Reference · Trash). One card removes the comparison. Six fixed routes remove the open field. The routes are the structure D'Zurilla's evidence points at. → Next up offers a small set chosen to be UNALIKE (ADR-0060). The qualification in the finding above is load-bearing: the direction holds where options are similar. Two offers that differ in KIND — a real date, a thing quiet for a month — are chosen between by preference; twenty comparable next-actions are chosen between by weighing, which is the act that fails at activation. At most one per reason, capped at two, and the ranking beneath is unchanged. → A "next action" must be specific enough to start, which is the implementation-intention finding applied. Vagueness is the actual blocker far more often than difficulty. → The timer on Do now is a commitment you make, not a constraint you are held to (ADR-0059). Its value is that the decision to start is cheap — two minutes remains the default for exactly that reason — and the length is yours to choose. It shows only that it is running: no countdown, because a shrinking deadline on an already-aversive task adds aversion at the moment of approach (§2), and no filling shape either, because anything rendered part-way through a chosen span is a fraction, and a fraction is a score. Stopping records nothing. → The breakdown ladder generates all steps but reveals one (ADR-0015). Showing eight steps to someone stuck at activation is choice overload at the worst moment. The granularity dial exists because the right step size is personal and varies by day. → Batch assist at the end of a Dump session keeps capture and decision separate. Deciding while dumping stops the dumping.


5 · Upkeep, habit, and honest timelines

Findings:

What follows.

→ Upkeep uses interval + comfort window, not a habit tracker. No chains, no "day 14 of 66". Given the range Lally found, a progress bar toward automaticity would be fiction for most items and most people. → "Ready again" language frames Upkeep as availability rather than obligation. → Because context cues beat intention, Upkeep chips surface in Work mode where the person already is — pushed to the point of performance rather than parked in a section they must remember to visit (ADR-0013). → The honest framing of Lally is itself a feature: an app that promises a habit in three weeks is lying, and the user will find out.


6 · Rest, lapse, and re-entry

Findings:

What follows.

→ Product law 8: rest is legitimate, and re-entry is the primary designed path — not an error state. Most planners treat a two-week absence as a data problem; for this audience it is the expected usage pattern. → The greeting after a lapse is bounded by schema: Next-up + at most three triage items + the gauge + an amnesty offer. Never the backlog. The bound is in the event shape, not in a UI decision that could regress (event-vocabulary.md §I). → The amnesty offer exists because the alternative — working through what accumulated — is exactly the demand Raymaker's participants describe as unaffordable during recovery. → Rest mode: pressure hidden, Menu forward, gauge quietly present, nothing red. The gauge stays because it is the reassurance — nothing was lost while you were away — and removing it would remove the reason rest is safe. NOT BUILT, and this arrow has been read as shipped (corrected 2026-08-30). NOTES.md struck it as delivered in 0.18.0; that release shipped the re-entry greeting and the amnesty and nothing named rest mode, and no source file contains it. Three entries in nd-collisions.md cite it as an existing protection while arguing to refuse other things — those refusals hold on machinery that IS built, but the citation was wrong. The nearest shipped surface is Just one thing (src/plain.ts), which caps the offer at one and keeps the Menu reachable, and which is invoked and never inferred. Either build the arrow or retire it; leaving it standing is what let three arguments lean on nothing. → Capacity is self-declared (low / steady / sharp / unsure), never inferred. "Unsure" is a first-class option because alexithymia (Bird & Cook) — difficulty identifying one's own internal states, co-occurring at elevated rates in autistic populations (established) — makes forced introspection a barrier. An app that requires you to know how you feel excludes people who don't. → Peak-end shapes the session close screen: a win and a green gauge. The end is disproportionately what gets remembered, and what gets remembered determines whether the app is opened tomorrow.


7 · Load, capacity, and pebbles

Findings:

What follows.

→ Pebbles are load, not work (ADR-0014). The unresolved thing you are carrying has weight even when it is not a task, and a system that only models tasks will consistently over-ask on the days you can least afford it. An active pebble may depress capacity/WIP — which is the app asking for less, automatically, without requiring you to explain yourself. REVERSED IN 1.34.0, and this sentence outlived it (corrected 2026-08-30). offerCapFor is now a constant — it returns the cap unchanged — and the argument against the old behavior is kept at that call site rather than the behavior: narrowing the offer on a low day is a pacing mechanism, and two of the populations this app serves need opposite things from it, so what bends is which things are offered (weightOrderFor) and never how many. The app's copy was fixed in the same release, with its own note that copy outliving the behavior it describes is the plainest kind of lie a surface can tell; this research document was not, and what-it-should-be.md has stated the corrected behavior correctly the whole time. Two research files in one repo disagreed, and the stale one was the one being cited. → Pebbles annotate the timeline so low-capacity stretches have a visible reason. Strictly co-occurrence: the app shows the pebble and the capacity in the same period. It never says one caused the other (product law 7). → Dependency dates use buffer language: declare feeds → (project, suspense) plus a lead estimate, compute latest-start, show buffer burn. Goldratt's insight is that the burn rate is the signal — which is why a passed date raises a replan card with days-left context rather than a late flag. → The planning fallacy is why estimates are logged from v1 even though learning from them is v2. The correction is empirical — your own history — and it cannot be backfilled. It is also why estimates are never used to judge: the fallacy is universal, not a personal failing.


8 · Bother, worry, and things that are not tasks

Findings:

What follows.

→ The bother flow takes free text and asks the one question that matters: whose is it — mine to solve · mine to track · not mine to carry. → It must terminate in a route or a Park-with-return-clock. No exit that leaves the bother where it was. This is Borkovec applied literally: the return clock is the designated later time, and it is a guarantee, which is what makes letting go possible now. → "Not mine to carry" still produces a record — the Not Now ledger. Declining is a decision worth keeping, not a deletion. It is also the thing to point at when the same request comes back. → Request slots are stimulus control for incoming demand: a scheduled place for requests to land, so they are not evaluated at arrival. → The comms-sweep chip is the same idea for messages. The app owns the schedule of looking and never the messages themselves — there is no integration and no event that could carry message content (event-vocabulary.md §E). Sweeps ride focus-exit ramps, because the cost of checking is the switch, and a switch already happening is free.


9 · Where the interest actually comes from

Findings:

What follows. Both are tagged community-construct and nothing structural rests on either. Their influence is confined to things that are true regardless of whether the model is:

→ "Not this" cycles freely on the Next-up card, with no penalty and no record of refusal. Whatever the underlying account, a planner that makes declining today's suggestion feel like a failure will be abandoned. Nothing is logged as a rejection, because a rejection log would eventually be shown to someone. → The Menu exists so that interest has a legitimate home that owes nothing (law 6) — and since 1.11.0 one thing from it rides in the offer on the main surface (ADR-0060), carrying no date and no Done, so interest is present rather than merely permitted. → The voice rules — no rebukes, no disappointed copy, no red walls, no implied judgment in an empty state — are the app's answer here, and they cost nothing if any particular account of the sensitivity is wrong.

Corrected 2026-08-09. This paragraph used to say the RSD tag drove the voice. It no longer does, and RSD is now a named refusal: it has no separate diagnostic standing and no measure of its own, so nothing in the app may be designed around it as an entity. What is well evidenced is emotional dysregulation in adult ADHD, and it carries every one of these rules on its own.

The rules are unchanged, which is the whole point. Designing them on a construct that later failed would have been the same design; the difference is whether the record can tell you why, and whether a feature built later inherits a warrant that does not hold. The app must never form an opinion about why somebody feels what they feel — that is law 7, and it is the reason a named feature for this was never the right shape regardless of the evidence.


10 · The negative findings, stated as prohibitions

These earn their own section because they are the easiest to violate by accident — each corresponds to a feature that would look perfectly reasonable in a spec.

Why they are here rather than quietly obeyed: each of these is a feature somebody will eventually propose in good faith, because they all appear in successful competing products. This table is the answer, with the reason attached.


10b · The field this app is in, and had never cited

Added 2026-08-30. Everything above is cognitive psychology — memory, attention, capacity. None of it describes the artefact, and there are two literatures about that which this document had never reached for. Both are directly about what this app is, and the second one states its premise better than the repo ever has.

Personal Information Management (PIM) — Jones; Bergman; Bergman, Beyth-Marom & Nachmias. Its central named problem is project fragmentation: the materials belonging to one project scattered across the very tools built to manage them, so that assembling the state of anything is a manual act performed from memory. That is the problem an owner of many separate systems is describing when they say the integration lives in their head. The field's named remedy is unification, and it is the field this product sits in.

→ The integration is the feature, not a convenience over it. Anything that splits one thing's facts across two surfaces re-creates the problem the tool is for. This is the research reason the log is one log and the fold is one fold, and the reason a second definition of "what matters today" was refused in src/today.ts on the app's own instincts before this citation existed.

Bellotti et al., CHI 2004 — "What a to-do." Studied how knowledge workers actually manage tasks, and found the opposite of what task software assumes: people are not bad at prioritizing. Participants were "remarkably proficient at keeping track of tasks, with everything that mattered getting done in time through painstaking use of a variety of resources." The finding that matters is what follows from that — since people still complain, the problem being reported is the effort that must go into being that proficient.

→ The target is not rescue. It is cost. A person running an elaborate manual system is succeeding, expensively, and a tool that frames itself as fixing their failure has misread them and will read as condescension. Everything this app refuses — scores, streaks, completion rates, "you are behind" — is refused partly for this reason, and now has a citation for it rather than only a value. This is also the cleanest statement of the product's premise available anywhere in the corpus, and it is twenty-two years old.

Neither field appears anywhere else in this repo. Recorded here so the next survey starts from them rather than rediscovering them.

What this app is aimed at, and the rule that comes with saying so

Added 2026-09-01. Everything in this document is here because it describes neurodivergent readers, who are who this is built for. What the document had never said is what it is aimed at, which is a condition rather than a diagnosis: low capacity, high demand, interruption, and engagement that varies.

Saying that is not a widening of the audience. It is a statement of the mechanism, and it earns its place because it makes whole literatures legitimately applicable — cognitive aids and structured protocols below, structured handover, high-reliability organizations, distributed cognition, situation awareness. Every one of those studies competent people in degraded conditions, none of them is reachable from a diagnosis alone, and all of them bear directly on what this app is trying to do.

Military planning doctrine belongs on that list too, and it is worth saying why. Doctrine assumes people who are capable, under load, and out of contact when it matters — so it externalises exactly what is expensive to hold: the conditions being watched for, what must be reported at once, and intent written so somebody can act correctly without asking. That is the same conclusion this document reaches from cognitive psychology, arrived at institutionally and decades earlier. It is an acknowledged influence on how the problem is framed. It stays out of the product's own vocabulary entirely — the voice is adult, calm and civilian, and no military term appears in any name or line of copy in this app. Influence on the thinking is not license over the words.

THE RULE THAT COMES WITH THE FRAMING, and it exists because it will not announce itself. The moment this reads as for people under load, ordinary productivity research becomes reachable — a literature built on streaks, ranking by importance, nudges and completion metrics, every one of which is refused here on the evidence above. Somebody will eventually arrive holding a real finding for a thing this app structurally may not do, and it will look like diligence.

A general-population finding may inform a design. It may never override a refusal. Where the two conflict, the narrower finding governs — and the reason is arithmetic rather than loyalty. A general-population result is averaged over people for whom the failure is cheap. Every refusal in this document exists because this is where that failure is most expensive and least recoverable, and an intervention that is positive on average can be negative exactly there while the average never shows it.

A third literature, and it is the one with the outcome numbers

Added 2026-09-01. This whole document argues that moving something out of a head and into a structure changes what happens. The strongest outcome evidence for that claim anywhere is in patient safety, and none of it was cited here.

The pair is the finding, and it is a prohibition. The structure did not stop working between 2009 and 2014. What differed is that the first was an intervention people were trained into and the second was a form they were required to file. A structure does not do the work by existing.

Nothing in Quietkeep may assume that offering a shape produces the outcome the shape was measured with. Not a template, not a field, not a prompt, not a checklist of its own. The measured effect belongs to the implementation, and this app cannot implement anything into somebody's life — it can only be cheap enough to use and honest about what it does.

That reads as a limitation and is closer to a license: it is the argument for why capture is one box, why nothing here has a setup flow, and why every surface has to earn its place at the moment of use rather than at configuration time.

And one claim this document should not lean on

The curb-cut effect — that designing for people at the margin ends up benefiting everybody — is an appealing frame for what this app is doing, and it splits cleanly in two when the evidence is actually looked for.

So the instance may be said and the rule may not. This app can honestly note that what makes it work under load is not exotic — plenty of people meet those conditions sometimes. It may not claim that designing for the margin therefore benefits everyone, because that is the half with no denominator, and asserting it would be exactly the confident nonsense the epistemic tags exist to keep out.

11 · The five things Quietkeep claims are different

Stated as claims, not conclusions. The competitive pass that would test them is V-08 in verifications.md, and it has not been run — it is owed before any public release copy is written. Publishing these as established differentiators before that check would be exactly the false-confidence failure Doctrine §5 names.

  1. A decay-based Upkeep lane — recurring things modeled by comfort window and rising pressure rather than by due dates or streaks.
  2. Unified suspend–capture–resume bound to a modeled focus state — the focus anchor, the paired resume card, and the interrupt gesture as one mechanism rather than three features.
  3. Bother triage that terminates in clock-guaranteed routes — worry handling with no exit that leaves the worry unheld.
  4. A horizon-integrity engine — the no-silent-nodes invariant enforced at the write boundary and proved by a visible gauge.
  5. A pebble load ledger — non-task load modeled explicitly and allowed to reduce what the app asks of you.

Canon index

Everything cited above, with its tag.

Established Barkley (temporal myopia; point of performance) · Brown (executive function clusters) · prospective memory, incl. time-based vs event-based and cue conversion · Altmann & Trafton (memory-for-goals) · Trafton et al. (resumption cues, interruption lag) · Mark (interruption costs) · Leroy (attention residue) · Radvansky (event boundaries) · Masicampo & Baumeister (plans quiet intrusive thoughts) · Gilbert (intention offloading) · Sirois & Pychyl (procrastination as mood repair) · Gollwitzer (implementation intentions) · D'Zurilla (problem-solving structure) · Borkovec (worry postponement / stimulus control) · Lally (habit timelines) · Wood & Neal (context cues) · Kahneman (planning fallacy; peak-end rule) · Goldratt (buffers, in operations research) · Bird & Cook (alexithymia) · Raymaker (autistic burnout — qualitative)

Emerging Monotropism (Murray, Lesser, Lawson) · hyperfocus (Ashinoff & Abu-Akel)

Corrected 2026-08-09. Choice overload used to sit in the Established list above, marked "direction established, magnitude contested". That was too kind to it: the classic demonstration replicates poorly and meta-analysis puts the average effect near zero, so the direction is not established either. It has moved here.

This changes nothing about the app, and that is the point of saying so. The offer is still capped, and still at two unalike things. What holds it up is not choice overload as a general law but the cost of COMPARING at the moment you are stuck — a narrower and much better evidenced claim, and the one ADR-0060 argues from in its own words. A decision can be right while the reason written beside it is wrong, and the only way anyone finds that out is if the reason is written down where it can be checked.

Contested choice overload (classic result replicates poorly; meta-analytic average near zero — the app's cap rests on comparison cost at activation instead) · demand avoidance as a distinct profile · rejection-sensitive dysphoria as a diagnostic entity (now a named refusal — see NOTES.md; the emotional dysregulation underneath it is well evidenced and carries the voice rules on its own)

Community-construct Dodson (interest-based nervous system) · RSD · spoon theory (Miserandino) · KC Davis (moral neutrality of care tasks) · Personal Kanban WIP limits (Benson & Barry) · Cirillo (interruption protocol)

Negative findings — prohibitions Ego depletion (failed replication) · working-memory training transfer (does not transfer) · "21 days to a habit" (no basis)


A note on citation. This document names findings and the people associated with them; it does not reproduce their text, and it is not a literature review. Where a construct is contested it is tagged as contested. Where the app borrows a shape from a practitioner method rather than a research result, it says so. Prior art in personal productivity methodology is acknowledged as prior art — Quietkeep claims no affiliation with, endorsement by, or compatibility with any methodology or its trademark holders (ADR-0016).