Money
The money module is the largest single feature in Dawnlet and the only one gated as a whole. It's also where a few decisions get noticeably stricter — because being vaguely wrong about money is worse than being vaguely wrong about a todo.
§The shape
One month at a time, driven by a shared month stepper, with two views behind a segmented control:
There's no separate budgets segment — budgets live inside Overview, because a budget is only meaningful next to what you've actually spent. Splitting them would mean two screens that each tell half the story.
A transaction is income or expense, with an amount, a date, an optional category, an optional note and any number of tags — the same categories and tags every other module uses.
1Budgets
One budget per category per calendar month, enforced by a uniqueness constraint. Setting a grocery budget for March creates a March row; April is a separate row.
Underspending in March doesn't raise April's ceiling. Two reasons: rollover makes "am I over budget?" depend on history you can't see on the screen, and — more importantly — editing a limit would have to decide whether it rewrites the future. Here it can't: editing March's limit touches exactly March. Every month is independently true.
Budget status drives two notification kinds: crossing 80% of a limit, and going over it. Each fires at most once per budget per month, so a month spent over budget doesn't generate a daily scolding.
2Recurring transactions
A recurring transaction is income or expense on a schedule — reusing the same recurrence model todos use, including its editor screen.
Loading a month runs a generation pass: for each active recurring transaction, walk the days of the month and create a transaction for every date the schedule matches — unless that pairing already has one, skipped or not.
Three consequences fall out of that single rule:
- A skip is never regenerated. The skipped row still exists, so the generator sees the pairing is handled.
- A weekly schedule generates several rows in one month, without any special-casing of monthly-ness.
- Deactivating stops future generation but keeps history. A bill you've cancelled doesn't erase the year you paid it.
Editing a generated occurrence is intentionally restricted: instead of a full editor you get a read-only summary of the series, an amount override for that month alone, and a non-destructive skip in place of delete. The override exists because a real bill's amount varies; the restriction exists because editing an occurrence into something unrecognisable makes the series meaningless.
3The category breakdown
Two stacked bars — income by category, spending by category — each with a legend showing amount and percentage, sorted largest first.
A stacked bar rather than a pie chart, because comparing a 9% slice to an 11% slice by angle is a task nobody performs accurately. A single bar keeps the parts in a shared line and makes "rent is most of it" legible at a glance, which is the only question this chart is actually asked.
Uncategorised amounts appear as their own neutral-coloured band rather than being hidden, so the parts always sum to the total. A breakdown that doesn't add up to the number above it is worse than no breakdown.
4The Face ID lock
An optional setting requiring biometric authentication before the money module's contents are shown. Off by default, because a lock the user didn't ask for on a tab they open ten times a day is friction, not security.
Its state is mirrored on-device rather than read from the database on demand, for a specific reason covered next: the notification planner has to know about it while running in the background with no network.
5Redaction
Notifications are the hole in any in-app privacy lock. A locked money tab is pointless if the lock screen displays "Rent — $1,850 due today" to whoever picks up your phone.
So when the lock is on, amounts are removed from notification copy. "Rent — $1,850 due today" becomes "A recurring transaction is due today".
The redaction happens when the notification is composed — before it's written to the notification log and before that log syncs. Redacting at display time would mean the full amount was already sitting in the log, and the in-app lock has no meaning in a database row. The difference is invisible until it matters, and then it matters completely.
It's implemented as one shared helper every money-related notification passes through, rather than a conditional at each call site — because "we forgot one" is the only way this feature fails, and thirteen separate conditionals is thirteen chances to forget.
6Where the line is drawn
Logging money is free. What Plus buys is the layer on top. Add income and expenses, categorise and tag them, step through any month, see the month's list and its income / expenses / net totals — all free, uncapped, and visible on the dashboard and in the day view like every other module. Plus adds the two category-breakdown charts, budgets, and recurring transactions.
This page used to argue the opposite, and it's worth keeping the argument. Money was the one module gated as a whole feature, on the grounds that a cap needs a unit to count and money doesn't have a sensible one: ten transactions is useless after a week, ten budgets is nearly unlimited, and capping by months of history means deleting the past, which is the one thing financial records are for.
All of that is still true. The conclusion drawn from it was still wrong. "No sensible cap" argued for not capping; it didn't argue for locking the door. The result was that the most-built module in the app was invisible to everyone who hadn't paid — and nobody subscribes to a money tracker they have never seen the inside of. Someone who has been logging expenses here for three months is the most convertible person Dawnlet has, and the old gate guaranteed that person never existed. The split that replaced it needs no unit to count: what you spent is a record you typed in yourself, and where it went is analysis.
Face ID is not part of the paywall, and charging for it would be indefensible. Locking the tab behind biometrics, and redacting amounts out of notification copy before they reach a lock screen, are free — and now that free members can log transactions, they need that more than subscribers do, not less.
One thing survives from the old design: no teasing locked previews. Where a free member can't have something here, they get one small card naming what it is, not a greyed-out chart. A permanent advert the size of the thing you declined is a bad way to treat someone.