"The body hikes in one app, mumbles in another, and talks in a third. Context can flip a reading — so Forge needs sibling context without a warehouse to leak it."
Why Cross-App Context at All
The motivating case is a real one: at the end of a return flight, a sudden forefoot ache. In isolation it might lean one way. But with the trip's heavy hiking in view — context that lives in a different app — overuse becomes the more natural question to raise. Context flipped which question was worth asking. The body is inherently cross-app: it hikes in the travel engine, mumbles in the diary, and converses in cwkPippa. Forge is the first consumer that structurally needs to see across those boundaries.
A Survey Engine, Not a Warehouse
The wrong answer is a central "crumb of crumbs" — one store everything syncs into. That would break canonical ownership, open a permanent sync swamp, and pour the most sensitive data in the family into a second database. So the crumb-of-crumbs is a contract, not a DB. Stage one: each engine exposes a digest endpoint over its own data, returning deterministic one-liners for a date window — no model inference at query time. Stage two: the trailing ID on each line is a pointer into the owning engine's API, followed only when judgment decides that line matters. Federated, derived, and rebuildable — never a second source of record.
The Line the Contract Protects
Notice how carefully the foot-pain case is stated. Context did not let the app declare overuse; it let Pippa raise a better-aimed question — and that reasoning happened in Dad-initiated Ask Pippa, not a Forge-generated surface. So even the payoff of cross-app context obeys Track 2: more context yields a sharper question, never a verdict. The digest contract makes the body's cross-app nature usable without a warehouse to secure, without automatic surveillance of every turn, and without health data leaking outward by default. Reuse across the family, with the boundary intact.