RRCC · Race Ready Command Center

It started as race prep.
It became a health command center.

A private, end-to-end-encrypted health & performance platform spanning Mac, iPhone, Apple Watch, and a zero-knowledge sync relay — built by a single athlete in collaboration with AI, on clinical-grade sensor data.

4 apps, one calculation per number
E2E encrypted, zero-knowledge relay
Built with Claude, attributed in every commit
RRCC macOS command center — home dashboard with readiness, weekly volume and coach directive
0Applications
AES-256GCM at rest & in flight
0Hz raw ECG stream
0Automated sync tests
0Verified compression
0Calculation per metric
Chapter 01 · The Origin

One athlete. One start line.
Then the monitoring outgrew the race.

RRCC began as a personal race-readiness tool — and evolved into a full health suite. The same pipeline that tells an athlete whether to train can put an ongoing report of a patient at a physician's fingertips, on desktop or mobile — or a whole roster in front of a coach.

01 — RACE READINESS

Peak for a start line

Chest-strap ECG, beat-by-beat RR intervals, power meters, training load, fueling, and weather windows — everything one athlete needs to arrive at race day ready, with numbers he can defend.

02 — A FULL HEALTH SUITE

The whole picture emerged

Sleep and recovery, blood pressure, HRV, SpO₂, body composition, nutrition, hydration, medications, and clinical-scale self-reports — race prep quietly became continuous, honest health monitoring.

03 — THE CLINICAL PATTERN

Doctors at their fingertips

The same architecture, pointed outward: a physician following patients between visits, or a coach watching a team — live dashboards, physician-ready reports, and notifications on desktop or mobile.

Chapter 02 · The Build

The engineering team
was a subscription.

Every subsystem — the cryptography, the sync protocol, the physiology engines, the watch app — was designed and implemented in collaboration with Anthropic's Claude, guided by a human who set non-negotiable invariants and tested every build on real hardware. The tooling cost is the part nobody believes: an AI-assistant subscription, not a headcount plan.

Concept → Production

Months. Not years. Not a team.

A four-app encrypted platform — macOS, iOS, watchOS, and a Go relay — shipped by one person and an AI collaborator working inside the repository, with the AI's work attributed in the commit history.

The build ran on commercial AI-assistant plans — the entire "engineering department" priced like a phone bill. The plan market captured during the build, at right.

The working agreement did the heavy lifting: "a green build is not a pass," "numbers must not lie," conformance tested, human accepts on hardware.

AI assistant plan pricing captured during the build — Anthropic Claude and OpenAI tiers
Chapter 03 · The System

Every number is computed once.

Sensors feed the phone. The phone syncs ciphertext through a relay that can read nothing. The Mac computes every metric — once — and ships the same figures to every screen. Two surfaces can never disagree about today's readiness, because there is only one calculation.

Polar H10ECG · RR intervals
Verity Senseall-day optical HR
Power meterswatts × time
Smart scale23-field body comp
Apple Healthfull export
▼   BLUETOOTH LE / API   ▼
RRCC Mobile — iPhoneCapture + encrypted vault · write-ahead queue · AI meal logging with human confirm
▼   E2E CIPHERTEXT ONLY   ▼
Zero-Knowledge Relay (Go)stores ciphertext + timestamps · cannot decrypt · either device can revoke
RRCC Watch (Ultra)one-tap logs · glanceable status · holds no keys at all
RRCC Desktop — macOS · The Compute Hubtraining load · calorie bank · readiness · health composite · AI coach · physician report (PDF)
Apple Watch Ultra 3 — RRCC readiness on the wristCapture on the wrist
iPhone 17 Pro Max in cosmic orange — RRCC capture and encrypted vaultVault in the pocket
iPad — RRCC console with Athlete, Doctor and Coach viewsConsole on the table

Device visuals are renders; every screen shows the real software. iPhone screen is a representation of the shipped capture app.

Chapter 04 · The Command Center

Not all wearables are equal citizens.

RRCC ranks its sources. A $90 Polar chest strap exposing raw RR intervals and a 130 Hz single-lead ECG outranks any vendor's opaque score — because raw physiological primitives are what make health data computable, and defensible.

Readiness & Trends

A verdict you can defend.

Fitness, fatigue, and form computed deterministically from months of training history — trended against sleep, HRV, recovery, and heart rate, with a countdown to race day.

Nightly HRV, resting HR, and respiratory rate computed from raw RR intervals — not a vendor score.

Verdicts are withheld until baselines exist: no readiness call without five usable nights, no training-load verdict before 28 days.

Independent opinions (Whoop, Apple) run alongside — ranked, deduplicated, never double-counted.

RRCC Trends — fitness & form, recovery, sleep, HRV and training stress with event countdown
Heart Health

The heart, on the record.

A running 14-day blood-pressure average with reading counts, resting HR, HRV, and a library of deliberate seated ECG spot-checks — voltage samples, RR series, movement and contact quality included.

130 Hz single-lead ECG captured from the chest strap, stored with signal-quality metrics.

Descriptive, never diagnostic — heart-pattern notifications are informational prompts, not diagnoses.

RRCC Heart Health — blood pressure average, resting HR and ECG spot-reading history
Sleep & Recovery

Honest nulls. Real baselines.

Overnight windows segmented from an armband worn all night; recovery scored from the athlete's own beat log, not a black box.

"Not measured" renders as a dash — never zero, never a guess.

A composite score refuses to exist with fewer than two real inputs. The UI says "building baseline" before it ever says a number.

RRCC Sleep & Recovery — HRV, resting heart rate, time in bed, and an explicit Not Measured section
Nutrition & Fueling

A calorie bank, not a vibe.

Intake against measured BMR plus training burn, protein and fiber targets, hydration pacing with a nightly cutoff — and AI-assisted meal logging where the model proposes and the human confirms before anything is written.

Calories out anchored to measured basal rate and real power-meter work — watts × time beats any wrist estimate.

The AI estimates; the vault records only after approval.

The calorie bank card — intake vs. burn with a live deficit verdict
RRCC Nutrition — calorie bank, protein and fiber targets, hydration pacing
Ride Telemetry

Sensor fusion, to the watt.

Power meters, GPS, and 800 Hz IMU road telemetry fused into gauges an exercise physiologist would recognize — energy tank, thermal load, fuel rate, surge power, road buzz.

Multi-source dedup: RRCC's own recordings outrank Garmin, GoPro, and Apple — the best source always wins, the same ride never counts twice.

RRCC Cycling Analysis — gauge cluster with energy, thermal, fueling and power metrics
The Full Record

An entire Apple Health export, ingested.

A 30.3 MB Apple Health archive compresses to 4.3 MB on the wire — 7× — with byte-exact round-trip verification. Steps, vitals, body metrics, sleep, and workouts land in one dashboard with full-history trends.

A corrupt blob fails loudly rather than decoding into plausible garbage that would be imported as health data.

RRCC Apple Health dashboard — activity, heart, sleep and body metric tiles with full-history trends
Chapter 05 · On the Wrist

One tap to log.
Zero keys to lose.

Follow one log through the wrist: open RRCC among the everyday apps, pick a quick log, tap a value on a real clinical scale, and glance at the day's verdict — hydration, intake, wellness, readiness. Two seconds per entry. And by design the watch holds no encryption keys: a lost watch exposes nothing.

STEP 1Watch home screen — RRCC among the everyday appsRRCC lives on the wrist
STEP 2Watch — quick log menuPick a quick log
STEP 3Watch — one-tap water loggingOne-tap hydration
STEP 4Watch — intake targets for water, protein and fiberTargets update live
STEP 5Watch — urine colour on a clinical chartClinical urine-color scale
STEP 6Watch — Bristol stool scale, type 4Bristol scale, honest verdicts…
STEP 7Watch — Bristol stool scale, type 5…even when they're not ideal
STEP 8Watch — wellness and intake loggingWellness, protein, fiber
STEP 9Watch — recovery and form readinessReadiness on the wrist
STEP 10Watch — today's calorie bank at a glanceThe day, at a glance
← scroll the story →

Offline capture cannot lose data: each tap is stamped with wrist time and a wrist-minted UUID, delivered hours later if needed, and upserted idempotently — re-delivery can never double-log, and the record keeps its true timestamp.

Chapter 06 · The Intelligence Layer

AI everywhere.
Except in the math.

AI appears in RRCC in two completely separate roles — and neither is allowed to invent a vital sign.

Bring Your Own Model

Pick your model. Keep your keys.

The coach runs on user-selectable Anthropic or OpenAI models, switchable per task — with every model reading the same computed numbers.

API keys are entered once, masked on screen, stored only in local settings — never in source, never synced, never on a server.

The daily plan unlocks on a schedule the athlete sets; AI narration is a layer on the day, not the source of it.

RRCC Settings — selectable AI coach models and masked local API keys
AI inside the product

Narrates. Coaches. Estimates.

  • The Coach — a conversational advisor grounded in every effort, wellness record, and weather window. It reads the computed numbers; it does not produce them.
  • Meal estimation — plain-language or camera logging; the human confirms before the vault records.
  • Daily reads — a deterministic one-liner is always live and free; the AI paragraph below is timestamped, with a staleness note when the numbers have moved.
  • User-selectable models — Anthropic or OpenAI; API keys live on-device, never in source, never on a server.
AI as the builder

Wrote the platform. Under supervision.

  • Every subsystem — cryptography, sync protocol, physiology engines, watch app — designed and implemented with Claude, attributed in the commit history.
  • "A green build is not a pass." Every logic change proven with a harness against real data before it ships.
  • "Numbers must not lie." Magnitudes checked against known references; an all-green scale is treated as a bug.
  • The human owns the devices. Every build is deployed to physical hardware and accepted by its user.

AI never computes a metric

Training load, calorie bank, HRV, readiness, the health composite — all deterministic, testable code. The model layer consumes finished figures.

Baselines before verdicts

No recovery score without five usable nights. No training verdict before 28 days of history. "Building baseline" is a valid answer.

Nulls are honest

"Not measured" is an em dash — never zero, never interpolated. A composite refuses to exist with fewer than two real inputs.

Descriptive, never diagnostic

Notifications are informational spot-check prompts. The physician report prints its own disclaimer on every page.

Stale AI is labeled AI

Every model-written paragraph is timestamped and flagged when the underlying numbers move. Stale narration never poses as current.

Human confirms every AI write

AI-estimated data enters the vault only after explicit approval. The model proposes; the person disposes.

Chapter 07 · Security Architecture

The server knows nothing.
On purpose.

Zero-trust from the first sync byte — and the richest features in the platform run on a relay that cannot read a single record.

🔗

Numeric-comparison pairing

The Mac mints a 20-byte seed shown as QR plus six digits; the phone must confirm the digits match. The digits are the security.

🔑

Keys derive, never travel

HKDF-SHA256 derives account ID, bearer token, and the AES-256-GCM data key from one seed. The key never touches the network.

🕳️

Zero-knowledge relay

Four endpoints: register, push, pull, revoke. It stores ciphertext and timestamps — it cannot decrypt, or even count your devices.

🧨

Either device can kill the link

One revoke call destroys the account and its blobs server-side — the designed response to a lost phone.

The watch holds no keys

Capture-and-relay by design. A lost watch exposes nothing at all.

🔒

Encrypted at rest, everywhere

AES-256-GCM vaults on every computer. Copy the data folder without the key and you hold unreadable ciphertext.

Chapter 08 · The Physician Bridge

A report a doctor can actually use.

On demand, RRCC compiles the vault into a multi-page graphical PDF for the exam room: 14-day blood-pressure average with reading counts, resting HR, HRV, SpO₂, weight deltas, sleep, medication and supplement lists, self-reports on clinical scales, and 30–90 day trend charts — every page footed with a plain disclaimer that it is a self-reported record, not a medical document.

Excerpt of the RRCC physician report — KPI tiles and 30-day resting HR and HRV trends (identifying details removed)
Excerpt from a generated physician report. Identifying details and medication list removed for this case study.
Where this pattern points

Ongoing reporting, at a clinician's fingertips.

RRCC watches one athlete. The architecture doesn't care that it's one. The same pipeline — ranked sensors, deterministic engines, encrypted sync, honest baselines, report generation — is the shape of a system where the monitored person carries the sensors and the professional gets the picture, continuously, instead of at appointments.

For physiciansPatients between visitsA live, physician-readable record — BP trends, HRV, sleep, adherence — on an iPad or web console, with desktop or mobile notifications when a patient's pattern warrants a look, and a printable summary for the appointment itself.
For coachesA whole roster at a glanceReadiness, recovery, and load for every athlete on the team on the sideline iPad — the same one-calculation honesty, multiplied, with alerts when someone's numbers say "rest" louder than the athlete will.
And this console is not a mockup — it runs on iPad today, in demo mode. See the next chapter. ↓
Chapter 09 · The iPad Console — Shipped, In Demo Mode

Athlete. Doctor. Coach.
One iPad.

This is not a concept board — the iPad app runs today in demo mode with a synthetic athlete, no real records shown or written. The same computed record splits three ways: the athlete's day, the physician's clinical read, and the coach's pit wall with live Polar telemetry.

RRCC on iPad — home screen with Athlete, Doctor and Coach views and demo mode toggleOne home, three audiences — with the demo-mode switch in plain sight
RRCC iPad — My Day athlete view: nutrition, water, sleep, digestion, intakeAthlete — My Day. Nutrition, hydration, sleep, digestion: the calm daily picture.
RRCC iPad — Clinical Summary doctor view: blood pressure, weight trend, steps, exercise volumeDoctor — Clinical Summary. BP, weight, steps, exercise — labeled a self-reported record, not a medical document.
RRCC iPad — Pit Wall coach view: recovery, form, load, and live team telemetry rosterCoach — Pit Wall. Recovery, form, load — and a whole roster streaming live, tap any rider.

Tap a rider. Watch the zones climb.

Live Polar H10 telemetry, per rider: heart rate, RR interval, skin temperature, sweat rate, G-force — one athlete ramping from Zone 1 into the red.

Live rider telemetry — Zone 1, 104 bpmZ1 · warming up
Live rider telemetry — Zone 3, 146 bpmZ3 · on the gas
Live rider telemetry — Zone 4, 157 bpmZ4 · threshold
Live rider telemetry — Zone 5, 166 bpmZ5 · the red
Chapter 10 · Compliance Posture — The Honest Version

Not certified. Demonstrated.

RRCC is a personal wellness system — not a medical device, not FDA-cleared, not a HIPAA-covered entity. Its value to a regulated audience is architectural: it demonstrates, in working code, the design patterns regulated products need.

Regulated-world requirement
RRCC's working analogue
HIPAA Security Rule — encryption at rest & in transit
AES-256-GCM vault on every device; E2E-encrypted relay traffic; TLS to all APIs
HIPAA — access control & key management
HKDF-derived per-account keys; platform keychain / locked-down key files; keyless wrist device
HIPAA — transmission integrity
Authenticated encryption (GCM); corrupt payloads fail loudly
GDPR — right to erasure
One-call revocation destroys all server-side data; either device can invoke it
GDPR — minimization & portability
Zero-knowledge relay stores ciphertext only; no analytics, no third-party sharing; user's data on the user's devices in documented schemas
21 CFR Part 11-style attribution & audit thinking
Mandatory update stamping; tombstoned deletions; append-only sync log; AI co-authorship attributed in the commit trail
FDA General Wellness positioning
Low-risk wellness framing; "not a medical document" printed on the clinician handout; verdicts descriptive, never diagnostic
AI governance for AI/ML-enabled functions
Deterministic compute / AI narration separation; human confirmation before AI-estimated data is recorded; staleness disclosure on AI output
Software validation culture
Harness-proven changes against real data; cross-platform conformance tests; backward-compatibility tests for every schema evolution

Sync integrity reads like a compliance engineer designed it: every write carries an attribution stamp or is invisible to sync by construction; deletes propagate as tombstones so removal leaves evidence; cursors advance only after durable merge; offline capture cannot silently lose a record.

Objections, Answered

The questions every regulated buyer asks.

"AI hallucinates — we can't have it near health data." +
Correct — so don't let it compute. Deterministic engines own every number; AI narrates on top of computed values and estimates only where a human confirms before commit. The model is structurally incapable of inventing a blood-pressure average.
"AI-written software can't be trusted in a validated environment." +
The counter is process, not promises: real-data harnesses before merge, conformance suites pinning wire formats, backward-compatibility tests for every schema change, human device-testing as the acceptance gate, and a commit history that attributes the AI's work. That is a validation story — and it shipped a four-app encrypted platform at solo-developer cost.
"Privacy makes rich health features impossible." +
RRCC's richest features run on a server that knows nothing. Zero-knowledge sync, on-device compute, and E2E encryption did not reduce functionality — they disciplined it.
"Wearable data isn't clinically useful." +
Raw RR intervals and single-lead ECG from a $90 chest strap, computed honestly and trended over months, plus a physician-ready report the patient brings to an appointment — the credible middle ground between consumer fluff and clinical instrumentation, and where patient-generated health data is actually heading.
"AI adoption means replacing engineering judgment." +
The opposite happened here: the human set non-negotiable invariants — "numbers must not lie," "no silent skips," "deletes are tombstones" — and the AI implemented within them, at a pace no solo human matches.
The One-Sentence Pitch

A single athlete and an AI collaborator built, in months, an end-to-end-encrypted, multi-device, sensor-fused health platform with a validation culture. Imagine that leverage pointed at your pipeline.

Compliance was not a document written after the fact. It is the shape of the architecture.