Tell the kitchen what keeps you safe, and nothing else

You would show one card and the kitchen would have everything it needs to cook for you safely — the allergen names it is already obliged to act on. Your name, your account and your medical history would stay where they are, because the card never carries them.

A single recurring task, argued from end to end — and two questions at the bottom. Skip to the questions.

Nothing described here has been built. This page does not exist to sell an allergy card; it exists to find out whether one should be made. Every capability below is written as would, because none of it is real yet.

You sit down. The waiter arrives. You say the sentence again — the one you have said in every restaurant for years — and you watch their face to see whether it landed. Sometimes it gets written down. Sometimes it gets repeated back wrong. Sometimes the booking form already asked, and now a company you will never meet again has a health fact about you filed next to your email address, forever.

The information the kitchen actually needs is small, and you already know it. The trouble is the only ways to deliver it are to say it out loud through a stranger, or to hand over far more of yourself than the question deserved.

Nine questions, nine answers

Six words at the table. Nothing else leaves with the waiter.photograph pending

1. What is it? — a card you show, not a file you hand over

A single card you show when you order. It carries the allergen names the kitchen is legally required to act on — and stops there. No surname, no diagnosis, no phone number, no account to create, no app the restaurant must install. The kitchen learns exactly what it needs to cook for you safely, and learns nothing else about you at all.

What is actually on the card?

The allergen names, in the taxonomy the kitchen already works in — in the EU that is the fourteen named allergens every food business must be able to answer for. Beside each one, how far it goes: ingestion only, or trace contact too. That is the whole card.

What is deliberately not on it: who you are, what a doctor wrote, when it was diagnosed, what happened last time. None of that helps the person at the pass, and every line of it is a line that can be copied.

Every clinic’s list is complete for its own visit. None of them is complete for your dinner.photograph pending

2. Why does it matter who holds this? — the complete list can only live with you

Your list is the only one that is actually complete — and that is not a compliment to you, it is arithmetic. The hospital holds the admission. The doctor holds the prescription. The clinic holds the test. Your own memory holds the reaction at a wedding no clinic ever saw. Each record is complete for the visit that produced it and quietly incomplete for the meal in front of you. You are the only holder whose record covers the whole life the meal happens in.

Why can’t an institution just be complete?

In the supply map behind this page, the criterion for ‘nothing is missing’ is a declared negative in nine of the ten record families that could carry an allergy fact. That is not an accusation of sloppiness. It is arithmetic: a record is complete for its own denominator, and no institution’s denominator is your life.

The same map records a second, blunter problem — records get the wrong person attached to them at a measured rate: mixed-up samples, unvalidated joins, readings imported from the wrong device. At a table, with you present, that class of error does not arise.

You would send an answer, not a record. Nothing is copied, so nothing needs deleting.photograph pending

3. How would it work? — the kitchen would get an answer, not your record

You would assemble the list once, from the fragments that are already yours, and keep it on your own device. At the table, the card would show the kitchen a single purpose-bound answer derived from it — valid for this meal, at this table, tonight. Not a login. Not a profile. Not a row in a booking system that outlives the dinner.

What does ‘an answer, not a record’ mean in practice?

A record is a copy. Once a booking platform stores ‘peanut’ against your email address, that copy exists in backups, exports and derived features you will never see. Asking for it back later is the weakest thing you can do, because withdrawal is forward-only: it can stop a holder using something from that moment on, but it does not retract what has already been read, and the supply map records that revocation demonstrably does not reach copies that were derived before it.

An answer is not a copy. It is the smallest true statement that lets the kitchen decide: these flags, this table, tonight. The strongest privacy move is not a better delete button. It is never creating the second copy.

The person who has to decide is not you. It is whoever is at the pass.photograph pending

4. Who else does this touch? — the cook, the host, the friend who booked the table

The decision this card serves is not yours — it belongs to the kitchen: can this dish, as it will actually be cooked tonight, be served to this guest? The waiter has to carry it accurately. The friend who booked should not have to mention it on your behalf. A parent ordering for a child faces the same moment twice.

Who benefits besides the guest?

The obligated side is far larger than the allergic side. Every food business in the EU has to be able to answer the allergen question for fourteen named allergens, at every service, through whichever member of staff happens to be standing there. A card in a taxonomy the kitchen already uses is less work for the kitchen than a spoken sentence it has to interpret and relay.

Stakeholders show up here as content, not as the reader. Each of them has their own version of this task, and each of those deserves its own page.

It would speak the list the kitchen is already obliged to keep.photograph pending

5. What would it need? — the fourteen names the kitchen’s law already uses

No new standard. No hardware at the restaurant. The card would be written in the allergen list the kitchen’s own regulator already imposes, so a line cook can read it in seconds without being trained on anything. On your side: a device you already own, and a few minutes once to assemble the list.

What if the kitchen is in another country?

Allergen law is jurisdictional: the EU names fourteen allergens, other regimes name different sets. The supply map flags this as a real boundary, not a detail — a card that assumes one list will mislead somewhere. The honest design shows the local set and marks anything outside it as declared-but-unregulated, rather than pretending the categories line up.

The test: would you rather explain it again, or show it once?photograph pending

6. What would it cost and save? — four currencies, one deciding test

Time: a few minutes once to assemble the list, then seconds per meal instead of the same conversation every time. Attention: the ordering moment stops being a negotiation you have to supervise. Energy: the low-grade dread of being the difficult guest goes down. Money: nothing, on either side — there is nothing to buy and nothing for the restaurant to install.

The honest cost side

You do the assembling. Nobody hands you a finished list, because no holder has one — that is the whole argument of card 2, and it cuts both ways. Keeping it current is yours too: an allergy that changes and a card that does not is worse than no card.

And the card only ever says what you do react to. It can never establish that you are not allergic to something: population data cannot prove an individual negative, and no amount of engineering changes that. Anyone promising the reverse is selling you something.

At the table. On one bar of signal. In a language you do not speak.photograph pending

7. Where would it run? — at the table, on a bad connection, abroad

The moment it has to work is the worst possible moment for software: a loud room, a waiter standing there, one bar of signal, sometimes a country whose language you do not read. So it would have to work from your own device without asking the room for anything — no scan, no network round trip, no account lookup.

Why is offline the hard requirement?

Because the fallback for a failure is a spoken sentence through a stranger, which is exactly the failure mode the card exists to remove. In the supply map, resilience under failure is one of the thinnest criteria in the whole universe — it is carried by a handful of probe records and almost nothing else. That thinness is honest, and it is also the reason a person-held card beats a lookup service.

Thirty seconds after you sit down — and then it is over.photograph pending

8. When would it happen? — in the thirty seconds after you sit down

Once, when you make the card. Then in the thirty seconds after you sit down, every time. It is not a subscription, not a thing to maintain weekly, not a feed. It appears at ordering and it is done — and because nothing was copied, there is no afterwards to manage.

What about the meal after this one?

Nothing carries over, deliberately. The next restaurant gets its own single answer, bound to its own service. There is no thread of visits building up somewhere, which means there is also no history of your dining that a later reader could assemble.

If it works here, ‘why do you need my name for that?’ becomes an ordinary question.photograph pending

9. What would change, beyond the meal? — showing becomes normal; handing over becomes strange

The interesting part is not the allergy. It is the shape: a decision that needs one true fact about you, answered with one true fact and nothing else. Pharmacies, doors, hotels, schools, border desks and forms all ask the same badly-shaped question — give us your record — when what they actually need is an answer. If showing becomes normal for a dinner, being asked to hand over a file starts to look like what it is.

Why start with a restaurant?

Because the stakes are real but the transaction is small, the counterparty has a legal duty that already defines the vocabulary, and everyone — allergic or not — has watched this conversation happen at a table. It is the smallest place where the whole argument is visible.

What the kitchen would actually see

Illustrative specimen — invented, not a real person’s card. It is here to show the shape and the size of what travels.

TABLE 12 · TONIGHT ONLY

  • Peanuts — trace contact too
  • Celery — ingestion only

Nothing else is attached. Expires with the meal.

That is the entire payload. Not a profile with two flags on it — two flags, and no profile.

The trade, in one paragraph

The kitchen needs certainty and you want to stay unremarkable, and those two wants only stop fighting if what travels between you is an answer rather than a record. So the card shows the flags the kitchen is already obliged to act on, bound to this table and this night, and leaves nothing behind to be sold, matched or leaked later. That is the whole idea, and the two questions below are how it finds out whether it is worth making.

Two questions about this idea

Whether a kitchen would accept a shown card at all, instead of asking you to say it out loud, is still an open question — answer as if it would.

If this existed: you would make the card once, show it when you order, and the kitchen would get the allergen flags and nothing else. Worth having?
A separate question — optional. A health fact about you can stay with the service that recorded it, or be something you can move and show yourself. Which should it be for your own health facts?

Either question can be answered on its own. Your answer is a count and nothing else — what gets stored is the answer word, which question it answers, whether you changed it, and a timestamp. Nothing in that record identifies you: no cookie, no account, no identifier. This page will not claim perfect anonymity either — the host that serves it sees the ordinary details every website’s host sees when a page loads, including your IP address. It is not stored with your answer and it is not kept, but no web page can honestly promise more than that. On this device the page keeps your answers so it can restore them for you, plus a flag for whether you opened the full argument — that flag is part of the record of how the answer was formed; it is not sent anywhere and nothing on the page reads it back to you. Three commitments behind that: I will never sell this, never use it to target you, and never train anything on it.

The argument, in full

This is the long version, for the reading mode that wants it. Everything below traces back to a numbered card above, and the last section says plainly what this would not do.

Open the full argument

On the two decisions hidden in one sentence — back to card 1

“Tell a restaurant my allergies — nothing more” sounds like one job. It is two, and they belong to different people. The kitchen decides whether a dish can be served to this guest; the guest decides how much of themselves to hand over to get that first decision made correctly. The two pull in opposite directions on exactly one axis: how much detail. The kitchen wants more certainty. You want less disclosure. Every existing way of doing this resolves the tension by sacrificing your side of it — the booking form, the loyalty profile, the note in the reservation system.

They only stop pulling against each other if what travels is a derived answer instead of a record. An answer can be maximally useful to the kitchen and minimally revealing about you at the same time, because it is scoped to one decision, one table, one night.

On completeness — back to card 2

The strongest thing that can be said for a person-held list is not that a person is a better database. It is that the person is the only holder whose denominator is the whole life. Behind this page sits a map of ninety-six families of information about a person, crossed with fifty criteria a decision can demand of information — four thousand eight hundred cells, each recording what has actually been released about whether supply of that kind can bear that criterion.

Ten of those families could plausibly carry an allergy fact. Across the criteria that this task demands, the completeness criterion comes back a declared negative in nine of those ten. Read that carefully: it does not say the records are bad. It says no single record family can claim to hold everything, because each one is bounded by the encounter that created it.

On the mechanism — back to card 3

The design rule is: send an answer, never a record. It follows from a measured asymmetry. Asking a holder to stop using something works forward only — it can stop them from that moment on, and it does not retract what has already been read. The same map shows that withdrawal frequently fails to reach copies derived before it: exported lists, cached features, downstream extracts. So the copy you can actually control is the one that was never made.

This is why privacy is not treated here as a price paid for convenience. On this task it is a plain requirement, like the food arriving hot. A version of this that collected your details in exchange for being useful would not be a cheaper version of the idea; it would be a different idea, and a worse one.

On who else this touches — back to card 4

The addressee of this page is the person with the task — the guest. Restaurants, booking platforms and regulators appear as content, because they shape whether the moment goes well. Each one also has a version of the same task from their own side, and that is where the next pages come from, not from turning this page toward them.

On the tools — back to card 5

Nothing new needs standardising. The fourteen-allergen vocabulary already exists as an obligation on the kitchen, which means the card can speak in words the kitchen is already accountable for. Reusing an existing obligation, rather than inventing a format, is what keeps the required effort on the restaurant side at zero.

On what it costs you — back to card 6

Four currencies, honestly. Time and attention move in your favour after a one-off setup cost you pay yourself. Energy moves in your favour because the ordering moment stops requiring supervision. Money does not move at all. The one cost that never goes away is that keeping the list true is your job, and a stale card is worse than none.

On where and when — card 7, card 8

The demanding constraint is the room, not the software: loud, rushed, sometimes foreign, often badly connected. Anything that needs the network at the moment of ordering has already failed, because the fallback is the spoken sentence the card was supposed to replace.

On what would change — back to card 9

If a small, high-stakes, universally recognisable exchange can be done by showing one true fact instead of handing over a file, then the same shape is available everywhere the same badly-formed request is made. The shift is not technical. It is that “why do you need my name for that?” stops sounding difficult and starts sounding reasonable.

What this doesn’t do

  • (card 6) It can never show that you are not allergic to something. Population data does not establish an individual negative; that is a permanent limit, not a missing feature.
  • (card 2) Completeness is never claimed. You assemble the list, and anything you do not know about yourself stays unknown to the card.
  • (cards 1, 3) Nothing described here has been built. Every capability on this page is written as would because none of it exists yet.
  • (card 5) Allergen categories differ by country. A card built on one list will be incomplete against another, and it says so rather than silently mapping across.
  • (card 3) Withdrawal is forward-only. It can stop a holder from that moment on; it does not retract what has already been read, and there is no way to measure from here how far a withdrawal actually travelled.
  • (card 7) How well anything of this kind holds up offline and under failure is one of the least studied questions in the underlying map — carried by a handful of probe records. Treat the offline claim as a requirement, not as a proven result.
  • (card 1) A card does not make a kitchen careful. It removes an interpretation step; it does not remove cross-contact in a busy kitchen.
  • (whole page) The sizing language here (“every ordering interaction”) is context, not evidence. No released measurement in the underlying map supports a market number, so none is given.

The same two questions

If the long version changed your mind, go back up and change your answer — a changed answer is the most useful thing this page could learn. Back to the questions.