On the two decisions hidden in one sentence — back to card 1
“Tell a restaurant my allergies — nothing more” sounds like one job. It is two,
and they belong to different people. The kitchen decides whether a dish can be served to this guest;
the guest decides how much of themselves to hand over to get that first decision made correctly. The
two pull in opposite directions on exactly one axis: how much detail. The kitchen wants more certainty.
You want less disclosure. Every existing way of doing this resolves the tension by sacrificing your
side of it — the booking form, the loyalty profile, the note in the reservation system.
They only stop pulling against each other if what travels is a derived answer instead of a record.
An answer can be maximally useful to the kitchen and minimally revealing about you at the same time,
because it is scoped to one decision, one table, one night.
On completeness — back to card 2
The strongest thing that can be said for a person-held list is not that a person is a better
database, and not that it would be complete — no list is. It is that the person is the only
holder whose denominator is the whole life, so the person is the only one who can even attempt the
combination. Behind this
page sits a map of ninety-six families of information about a person, crossed with fifty criteria a
decision can demand of information — four thousand eight hundred cells, each recording what has
actually been released about whether supply of that kind can bear that criterion.
Ten of those families could plausibly carry an allergy fact. Across the criteria that this task
demands, the completeness criterion comes back a declared negative in nine of those ten. Read that
carefully: it does not say the records are bad. It says no single record family can claim to hold
everything, because each one is bounded by the encounter that created it.
On the mechanism — back to card 3
The design rule is: send an answer, never a record. It follows from a measured asymmetry. Asking a
holder to stop using something works forward only — it can stop them from that moment on, and it
does not retract what has already been read. The same map shows that withdrawal frequently fails to
reach copies derived before it: exported lists, cached features, downstream extracts. So the copy you
can actually control is the one that was never made.
This is why privacy is not treated here as a price paid for convenience. On this task it is a
plain requirement, like the food arriving hot. A version of this that collected your details in
exchange for being useful would not be a cheaper version of the idea; it would be a different idea,
and a worse one.
On who else this touches — back to card 4
The addressee of this page is the person with the task — the guest. Restaurants, booking
platforms and regulators appear as content, because they shape whether the moment goes well. Each one
also has a version of the same task from their own side, and that is where the next pages come from,
not from turning this page toward them.
On the tools — back to card 5
Nothing new needs standardising. The fourteen-allergen vocabulary already exists as an obligation
on the kitchen, which means the card can speak in words the kitchen is already accountable for.
Reusing an existing obligation, rather than inventing a format, is what keeps the required effort on
the restaurant side at zero.
On what it costs you — back to card 6
Four currencies, honestly. Time and attention move in your favour after a one-off setup cost you
pay yourself. Energy moves in your favour because the ordering moment stops requiring supervision.
Money does not move at all. The one cost that never goes away is that keeping the list true is your
job, and a stale card is worse than none.
The demanding constraint is the room, not the software: loud, rushed, sometimes foreign, often
badly connected. Anything that needs the network at the moment of ordering has already failed, because
the fallback is the spoken sentence the card was supposed to replace.
On what would change — back to card 9
If a small, high-stakes, universally recognisable exchange can be done by showing one true fact
instead of handing over a file, then the same shape is available everywhere the same badly-formed
request is made. The shift is not technical. It is that “why do you need my name for that?”
stops sounding difficult and starts sounding reasonable.
What this doesn’t do
- (card 6) It can never show that you are not allergic to something.
Population data does not establish an individual negative; that is a permanent limit, not a missing
feature.
- (card 2) Completeness is never claimed. You assemble the list, and anything you
do not know about yourself stays unknown to the card.
- (cards 1, 3) Nothing described here has been built. Every capability on this
page is written as would because none of it exists yet.
- (card 5) Allergen categories differ by country. A card built on one list will
be incomplete against another, and it says so rather than silently mapping across.
- (card 3) Withdrawal is forward-only. It can stop a holder from that moment on;
it does not retract what has already been read, and there is no way to measure from here how far a
withdrawal actually travelled.
- (whole page) The photographs are illustrations of the moments described, made
for this page. They are not documentary evidence and no one in them is a real customer.
- (card 7) How well anything of this kind holds up offline and under failure is
one of the least studied questions in the underlying map — carried by a handful of probe
records. Treat the offline claim as a requirement, not as a proven result.
- (card 1) A card does not make a kitchen careful. It removes an interpretation
step; it does not remove cross-contact in a busy kitchen.
- (whole page) The sizing language here (“every ordering interaction”)
is context, not evidence. No released measurement in the underlying map supports a market number, so
none is given.
The same two questions
If the long version changed your mind, go back up and change your answer — a changed answer is
the most useful thing this page could learn. Back to the questions.