Trust Updated 2026-08-22 View as Markdown

Changelog

Platform changes that affect what you can do. Internal refactors, performance work and dependency updates are not listed.

August 2026 — anyone can create an account

Signup is open. There is no waitlist, no approval step and no card.

  • Register and start. A username and a password at nlight.fit/app creates the account and signs you in. New accounts are on the free plan.
  • Free is a real tier, not a trial. The whole tracking product — ledger, WHOOP, labs, genetics, CSV, charts, the nightly correlation engine — stays free and unmetered. The coach runs on the same grok-4.6 as Member, thinking over your last 60 days at high reasoning. Member raises that to your full record at maximum depth. See membership.
  • Over the monthly coach allowance, answers get cheaper rather than refused. Reasoning drops to the floor and the context narrows. Nothing tells you to come back next month.
  • Voice now has a monthly budget — about 10 minutes free, 60 for Members — enforced when the session starts rather than partway through a sentence.
  • Everyone who already had an account has a free year of Member, starting the day open signup shipped.
  • No password reset yet. There is no email on file to send one to, so keep your password somewhere durable.

August 2026 — security and privacy hardening

  • Delete your account from Settings. Username + password confirmation erases the profile, ledger, labs, genetics, photos, chats, tokens and related collections. Stripe payment records are kept as a legal/tax record.
  • Honest coverage. The security and privacy pages, the landing Trust section, and the login privacy note now say exactly which fields are encrypted at rest — and that labs, genetics, photos and chat transcripts are not.
  • Safer failures. Unreadable encrypted values are withheld instead of being shown or sent to models as ciphertext. Revoking an MCP token also kills the matching OAuth refresh token.
  • Sessions can be killed. Change your password or use Sign out other devices in Settings and every other session ends on the next request. The MCP server accepts only an API token, not a browser session.

August 2026 — docs assistant

A public, docs-only assistant now sits in the bottom-right corner of the documentation site and the marketing pages.

  • Find, curate, navigate. Ask a general question and it narrows to the best published pages, with heading-level links. It will not talk about anything except nLight.fit documentation. Following a link keeps the chat in that tab so you can keep opening the other pages it suggested.
  • Readable answers. Replies render GitHub-flavored Markdown — tables, headings, lists — instead of raw pipes. Free vs Member comparisons use a compact three-column table.
  • Membership, explained. It can walk through why the Member plan is $50/year — higher reasoning over full history — with the same concrete examples as the membership page.
  • Locked down and rate limited. Off-topic questions, jailbreaks and secret-fishing are refused without a model call. Public IP limits cover a burst window, an hour and a day. See docs assistant.

August 2026 — Member is $50/year

List price moved from $30 to $50 per year. See membership for what the upgrade buys.

August 2026 — Member, $30/year

The paid intelligence tier is now a path you can take, not only a billing rail. Price later moved to $50/year (see the entry above).

  • Pricing on the landing page. Free (early access) and Member sit next to each other. Become a Member goes to /app?upgrade=1 so checkout is attached to your signed-in account. A public Stripe Payment Link is never shown.
  • Upgrade in the app. Settings opens on a Membership panel. The same panel is in your Profile. Free accounts also see an Upgrade chip in the top-right account bar.
  • What membership buys. Frontier-model intelligence on your full history, highest reasoning, mission analysis, and expanded voice. See membership.
  • Mission analysis upgrade path. A free account that asks for Mission Analysis sees a Member CTA that opens Settings rather than a generic retry error.

August 2026 — an API you can find and try

Everything here is for the client integrating against nLight.fit rather than for the person using it.

  • A sandbox that needs no account. POST /api/sandbox speaks the same MCP protocol with the same eighteen tool schemas as the production server, answered from a synthetic member record — a complete, credential-free environment with a populated history to develop against. Every response is marked as synthetic. See sandbox.
  • An OpenAPI specification at /openapi.json, describing the REST and MCP surface including the auth, rate-limit and versioning conventions.
  • Discovery documents at their conventional paths — an RFC 9727 API catalog and an MCP server manifest — so a client can find the API without being told where to look.
  • A developer hub at /developers listing every resource with its URL.
  • Rate limits reported, not just enforced. Every response now carries RateLimit and RateLimit-Policy, so a client can pace itself instead of discovering the limit by hitting it. A 429 adds Retry-After. See errors and limits.
  • A versioning and deprecation policy with the headers behind it: Api-Version on every response, and Deprecation and Sunset when something is on its way out, with stated notice periods. Nothing is deprecated today. See versioning and deprecation.

August 2026 — MCP server

External AI clients can now read your record.

  • One-click connection for Claude. Paste https://nlight.fit/api/mcp into Settings → Connectors → Add custom connector, sign in, approve a screen that says exactly what will be readable. No token to mint, no config file to edit, and it works the same on Desktop, on the web and on mobile. The connection is read-only and cannot be made otherwise — the server will not issue a write scope to a connector at all. See client setup.
  • MCP server at POST /api/mcp, stateless JSON-RPC over HTTP, with eighteen read-only tools. Claude Code, Claude Desktop and Cursor all connect directly. See MCP server.
  • Your goals and constraints over MCP. get_profile gives an external client your Mission Statement and the injuries, allergies and exclusions any recommendation has to respect. Until now a connected client could read your genetics, your bloodwork and your recovery — and compose a training or supplement plan without any way to see an injury on file. Your name and your free-form notes are deliberately never exposed; see what is not exposed.
  • Supplements over MCP. get_supplements is now published to external clients, and the genetics tool carries a cross-check against it: get_methylation_data states which of its recommended compounds you already take, which are genuinely still open, and which item in your current stack your own variants argue against. Until now the half that recommends was reachable over MCP and the half that checks was not, so a client could suggest adding something you already take.
  • Warehouse tools — six tools available only over MCP that return raw analytical evidence rather than a precomputed verdict: the daily feature matrix, the correlation graph as structured edges, all-time facts, statistical models and narrative summaries. These let a client test a hypothesis the nightly engine never considered.
  • API tokens — revocable machine credentials with explicit read and write scopes, stored as hashes, managed from Settings → MCP / CLI Access. See token management.
  • This documentation site, with the tool and metric references generated directly from source so they cannot drift.

August 2026 — statistical honesty

Changes to what the platform is willing to state, and how plainly it admits what it does not know.

  • Every tool result says how current it is. A tool answering over MCP now stamps a dataThrough date — the day your record actually runs through, not the day the answer was computed. Live ledger figures and nightly-computed ones used to be quotable side by side as though they described the same moment, which is how a client ends up presenting a stale number as today's. See how current is this result.
  • Sparsely-logged habits no longer masquerade as recovery drivers. A behaviour has to be recorded on at least 30% of the days being modelled before it earns a slot in your personal recovery formula. Below that, treating every unlogged day as "didn't do it" produced a coefficient measuring whether you filled in the row rather than whether the habit worked — which is how "prior-day vitamins: −9.9 recovery points" reached the coach from a habit logged one day in seven.
  • Confounded terms are labelled where they appear. A recovery-formula term the correlation engine judged confounded now reads as such wherever it is stated, so a real association is not presented as a lever you can pull. See your recovery formula.
  • Beliefs are scored against what could actually be tested. When your stated beliefs are cross-examined against your statistics, only measurable claims — observed patterns and behavioural assertions — count toward the result. A preference or a plan asserts nothing a correlation can check, and counting it as "untested" made the check read as far weaker than it is.
  • Metrics declare what they are for. Each metric now carries a purpose: an analytical signal, or something tracked for your benefit that was never a modelling input. This is what separates "no relationship was found" from "this was never tested" — claims of very different strength that used to look identical. See purpose.
  • Unreadable genotypes are reported as unknown, not normal. A gene whose genotype could not be parsed out of an uploaded report is no longer grouped with the genes confirmed to carry no variant. See unparsed genotypes.

Mid 2026 — deeper analysis

  • Unified correlation engine spanning habits, nutrition, WHOOP, bloodwork and genetics in one graph, with partial-correlation controls, autocorrelation-adjusted significance and multiple-testing correction.
  • On-demand relationship analysis for any two metrics, applying the same statistical guards, always labelled a hypothesis.
  • Insights engine — readiness scoring, lead-lag detection, goal ETA with Monte Carlo confidence bands, streak survival curves, training load, HRV baseline, dose-response curves, changepoint detection.
  • User fact index derived from the metric registry, which fixed a real class of error: personal records that only reflected the most recent thirty days.
  • Metric registry as the single source of truth for metric semantics, replacing definitions that had been copy-pasted across five modules and drifted apart.

Early 2026 — health modules

  • Bloodwork. Upload lab PDFs, extract markers, track trends against reference ranges, correlate against daily behaviour over biologically plausible windows.
  • Methylation genetics. One-time genetic profile with pathway view, clusters, genetically predicted watch markers cross-linked to your labs, and priors that get tested rather than asserted.
  • WHOOP webhooks, so recovery scores appear within minutes instead of at the next scheduled pull.
  • Data-quality gating for WHOOP calibration periods and nights with sensor gaps — visible in the ledger, excluded from analysis.
  • Mission Statement — one goal, three commitments, with progress and causality analysis.

Late 2025 — the coach

  • Context Engine 2.0 — temporal awareness, momentum detection, lifecycle stage, profile gap discovery.
  • Smart payload — question classification driving model choice, reasoning effort and context size.
  • Learnings system — bidirectional extraction, semantic deduplication, decay, consolidation, bounded storage.
  • Voice agent over a realtime speech model, with unified, chat, data-entry and onboarding modes.
  • Prompt injection defense on the AI endpoints.
  • Hybrid retrieval — vector search and full-text search fused and reranked.
  • Overview — what the platform does today