All work

Tend

A shared money app for families looking after someone, and a unified interface for the home-care agencies that work with them. Everyone pays into one care fund, and Tend sorts receipts into what you can claim at tax time.

Problem
Families pay for a relative’s care from one person’s account and settle over text like a complicated Venmo transaction. Sometimes, receipts go missing before tax time.
My role
Product design end to end: framing, flows, UI, metrics and the prototype brief.
What I made
A family app and an agency console on one shared ledger, each with a working prototype.
Where it stands
Working prototype. We’ve been using it for my brother’s care.

The Tend agency console. Priya, a care coordinator at Bayview Home Care, sees three purchases that need her and two that Tend approved by itself. The open request is Grace’s $162.40 grocery run for Rose, flagged because it’s over her weekly limit. Close-ups show the policy checks and the audit log, and a phone notification tells Rose’s family the agency is reviewing it.

01Why I made this

Caregiving comes with... a lot of paperwork 😭

I’ve helped care for my brother my whole life and people are surprised to hear that a lot of that care is paperwork. Things like receipts, records and miscellaneous forms. It gets easy to lose track of and annoying to figure out who’s paying for what.

Care is a team effort, and when it all falls on one person it gets stressful fast. I wanted to make it easy for everyone involved.

Banks offer only a joint account (or nothing), which doesn’t work for most families. A lot of care costs also count toward Canada’s Medical Expense Tax Credit, but only if someone keeps track of the receipts.

02How it got here

Three early directions

Who owes who Daniel owes Anna$42 Mei owes Anna$18 Settle up dropped

A · Debt ledger

“owes” on a care app feels awful

The Splitwise model works for college roommates (I can personally vouch for that!), but when it comes to taking care of a loved one, it can become a hassle, with the person doing the most ending up chasing everyone for receipts. Most people don’t want to chase family for money either, so one person often feels like they have to pay for all of it.

Care card $1,284 freeze receipts? dropped

B · Shared card first

good for groceries, not much else

A shared card is great for the support worker’s grocery runs, but most care costs never go on it. Pharmacy runs end up on someone’s own card, and agency invoices show up by email.

Receipts Scan needs you kept

C · Receipt inbox first

every cost leaves a receipt

Almost every care cost comes with a receipt, no matter who paid or how, so this is the one we kept.

The ledger and the card solves individual problems, but the inbox is the umbrella. Through that, we put the fund and the card underneath it.

The receipt screen (shown four times 🧾)

  1. v1 · Wireframe

    Every field looked the same, so nothing told you where to look.

  2. v2 · Lo-fi

    Every field showed how sure the model was, like “62%” next to the date. That helped me while testing, but a caregiver seeing 62% has no idea whether to fix it.

  3. v3 · Mid-fi

    Closer. But Save was always live, and it was easy to tap it right past the questions.

  4. v4 · Hi-fi, current

    Unsure fields turn amber so you know to check them, and each item gets a reason. Save waits until you’ve answered.

03The system

Everything runs through one fund

For instance, Mom’s disability benefits from the government and the family’s top-ups go into one fund, and care gets paid out of it. Because the money goes through one place, Tend can sort spending for tax time and nobody has to spend time keeping track.

The system · money

Where a month of care money goes

Comes in Shared fund Spent on At tax time Mom’s CPP disability $1,450 Canada Disability Benefit $200 Anna $600 Daniel $600 Mei $300 Mom’s care fund $3,150 Support worker hours $1,200 Grace’s card: groceries $740 Pharmacy $420 Physio $380 Care supplies $260 Transport $150 Eligible medical $1,000 Your call: support hours $1,200 Your call: travel $30 Not eligible $920
An example month. Mom’s CPP disability benefit and the federal Canada Disability Benefit come from the government, and the family tops up the rest.
More detail: who can do what

There are four roles, and by default nobody gets more than their job needs. People see each role as a sentence, generated from the table underneath.

The system underneath

Capabilities by role
CapabilityOrganizerContributorViewerCard holder
See balance●Yes●Yes●YesNo
See transactions●Yes●Yes●Yesown
Add money●Yes●YesNoNo
Scan receipts●Yes●YesNo●Yes
Spend with card●YesNoNo$150/wk
Approve over-limit●YesNoNoNo
Manage people●YesNoNoNo
Export tax summary●Yes●YesNoNo

8 capabilities across 4 roles. Engineers and support staff need this view but families shouldn’t need to read this.

What people see

  • A

    Anna can see everything and decides who gets access.

  • D

    Daniel can add money and scan receipts. He sees every transaction.

  • M

    Mei can see the balance and history, but can’t move money.

  • G

    Grace can spend up to $150 a week at pharmacies and grocery stores. She can’t see the balance.

The sentences are generated from the table, so what people read always matches what the system does.

04The AI

Deciding when the AI should ask

Every field the AI reads comes with a score for how sure it is. If Tend auto-accepts low scores, wrong amounts can slip into a tax record that someone has to sign. If it only accepts high scores, people end up answering a question on almost every receipt, which gets old fast.

I set it at 0.80, just before automation drops off sharply. Drag the slider to try other settings.

Model confidence per extracted field

auto-accepted →← ask a personcorrect fieldswrong fields (scaled ×33)0.30.50.70.91.0

The trade-off

01503000%50%100%receipts saved with no check →errors reaching ledger / 1k
67%receipts save with no questions
59taps per 100 receipts
5errors per 1,000 receipts reach the ledger
99%of model errors caught by asking

At 0.80, about 7 in 10 receipts save without a question. On average that’s 0.6 taps per receipt (you may notice that this is where the curve bends!). Errors are rare enough for a tax record and most receipts still save in one go.

Sample data: 800 receipts with 5 fields each, from a seeded random model. About 15% of the receipts are hard to read.

More detail: the receipt pipeline

The system · AI

How a receipt becomes a tax-ready record

Step 1 Receipt photo camera or email Edge guides help withcrumpled paper Step 2 Vision + OCR text and layout Every field keepsits own confidence Step 3 Line-item parser items and totals Items must add up tothe total, or it asks Step 4 Eligibility rules → classifier Rules first; themodel only forambiguous items What the UI does at each step Confidence ≥ threshold? yes Auto-accept quiet % shown on field no Ask the caregiver amber field · “Your call” Ledger audit trail on every edit Feedback loop corrections become labeled examples
Rules go first because you can check them. The model only handles what the rules can’t decide, and anything under the threshold goes to a person.

05The family app

Getting a receipt in

1234
5678
  1. 1The balance is the only large figure on the screen (I dimmed the cents).
  2. 2Spending is shown against the budget the family agreed on, and there’s no red “over budget” state.
  3. 3Anything the model wasn’t sure about waits here, so nothing gets saved without someone seeing it.
  4. 4Scanning is what people come back to do. It gets the only filled button.
  5. 5When the model’s sure, the field shows a small green percentage you can glance at.
  6. 6Below the threshold, the field goes amber so you know to double-check it.
  7. 7Each eligibility tag comes with a sentence based on CRA rules, so you can explain the claim later.
  8. 8You can’t save until the questions are answered. The button says what’s left.
Try the working prototype

Scan the grocery receipt and it separates the care supplies from the groceries, then asks about the one item it can’t decide on. In People, changing Grace’s access rewrites the sentence underneath.

9:41

Mom’s care fund

$1,284.50

Available · 4 contributors

$1,960.00 of $3,150.00 October care budget

Recent

  • ↗Wheel-TransTransport · Grace−$7.50
  • +Daniel’s monthly top-upContribution · Daniel+$300.00
  • ✚Physio PlusMedical · eligible · Anna−$95.00
  • GrNo FrillsGroceries · Grace−$38.40
More detail: sharing, tax time and edge cases
123
456
  1. 1Family and paid help share one list, and everyone’s relationship to Mom is always showing.
  2. 2Grace’s limits are written the way you’d say them out loud. The permission table sits underneath.
  3. 3Roles change in one tap. Someone covers for a week, then hands it back.
  4. 4The tax screen leads with the one number you need in April. It’s been adding up all year.
  5. 5Each open item says what’s missing, like a prescription photo.
  6. 6Tend keeps your records organized but doesn’t give tax advice, and it says so next to the export button.

Confidence chip · 4 states

Total$89.7996%

High · ≥ 0.90 · quiet green %

MerchantBeck Taxi84%

Medium · 0.80–0.89 · neutral %

DateSep 29Check

Low · < 0.80 · field turns amber

DateSep 29✓ confirmed

Confirmed · checked by a person · logged

Eligibility tag · 4 states

Eligible

Matched a rule. The reason always shows.

Not eligible

Muted grey-pink, so it doesn’t look like an error.

Your call

Blocks saving until you pick an answer.

You decided

Your answer, remembered for next time.

Your call padding 1 × 7 radius 999 Inter 700 · 0.85em

Rules

  • Colour is never the only signal, since each state also has a word.
  • Amber means “needs you”. There’s no red anywhere in the money UI.
  • All tap targets are ≥ 44px, and ≥ 52px in large-text mode.
  • Every tag passes WCAG AA for text. The lowest pair is Eligible at 5.2:1.

A misread receipt, found in March

Every saved field keeps the original photo crop and who confirmed it. Fixing it updates the tax summary and adds a note to the history.

A support worker leaves

Removing Grace freezes her card right away. Her past purchases stay in the history, and the organizer gets a heads-up.

Mom wants control

The person getting care can be the organizer, with family as contributors.

No signal at the hospital

Photos wait on the phone and get read once you’re back online.

06Tend for agencies

The same system, run by a home-care agency

A lot of families also pay an agency, and the agency’s personal support workers end up buying groceries and picking up prescriptions. Today they use mostly cash and paper receipts, which is inefficient. Tend gives each worker a card and gives the coordinator a console.

Approvals

3 need you · 2 approved by policy today

Groceries · Rose L.

No Frills $162.40

Policy checks by Tend

  • ✓Merchant categoryGroceries is allowed for Rose L.
  • !Weekly limit$162.40 this week. Grace’s limit is $150.
  • ✓Receipt attachedItemized, 14 lines, read at 97% confidence
  • ✓Items match categoryNo alcohol or gift cards found

Context from Tend

Two shops were combined into one this week, and the total is about double her usual.

  1. Tend checks every request against the policy and shows each check. Coordinators see why something was flagged instead of a risk score.
  2. Policy changes go to the family organizer before they apply. The agency runs the card, but the family still decides where the money goes.
  3. The audit log can’t be edited. Agencies get audited too, and a log anyone can change wouldn’t help them.
  4. There’s one ledger and two exports. The family statement and the billing CSV come from the same records, making them consistent.

One system, two front ends

Families and agencies share the same core

Family app Rose, Anna, Daniel, Mei scan receipts · top up the fund set access · tax summary Agency console Bayview coordinators policies · approvals audit log · billing Grace’s card (PSW) Shared core Funds & members who pays in, who has access Policy engine limits, categories,receipt rules Receipt pipeline read, check, ask a person Approvals auto or human, with reasons Ledger append-only, every edit and decision kept Family statement tax summary, receipts Billing export CSV or QuickBooks
Both apps write to the same ledger. A purchase on Grace’s card shows up for Rose’s family and for Bayview’s billing as the same record.

07Design system

Building trust into the components

The family app and the agency console use the same components. I spent the most time on the policy check, since that’s where people decide whether to trust what Tend did. Every state it can be in is drawn out below, along with the design tokens.

Policy check row · 2x

! Weekly limit$162.40 this week. Grace’s limit is $150.
324 10 20 10 10 56 r 10

every check is a sentence, never just a red dot

Check states

  • ✓PassedPharmacy is allowed for Dev P.
  • !FailedOver the weekly limit by $12.40
  • …WaitingReceipt requested from Marcus
  • POverriddenApproved once by Priya, 9:14 AM

Request status pill

Auto-approvedOver weekly limitApprovedDeclined

Colour tokens

  • --a-ink#1d1820Text, primary buttons
  • --a-ink-2#57505cSecondary text
  • --a-plum#5d3e66Selection, focus, the brand
  • --a-amber#74500fNeeds a person
  • --a-ok#2f6a45Passed, approved
  • --a-line#ebe7eeDividers, card edges

Type

  • Display26 / 1.1 · Instrument SerifAmounts, record titles
  • Heading17 / 600 · InterView titles
  • Body13 / 1.45 · InterEverything else
  • Meta11.5 / 400 · InterTimestamps, who did what

Spacing

  • 4
  • 6
  • 8
  • 10
  • 12
  • 14
  • 18
  • 22

Two scales on purpose. The console runs tight at 4–22px. The family app runs bigger, with 44px tap targets and 52px in large-text mode.

08Launch and metrics

A small beta first: 5 families and 1 agency

In v1

  • Receipt scanning with review questions
  • The shared fund and four roles
  • Agency approvals and the audit log
  • Family statements and a CSV export

Cut for now

  • Bank linking. Top-ups are manual at first.
  • RDSP and ODSP planning
  • QuickBooks sync
  • Receipts in languages other than English and French

09Engineering handoff

What engineers get with the designs

For engineering

Receipt states

captured photo, email or card data extracted fields + confidence needs review below threshold or policy accepted in the ledger exported statement or billing all fields ≥ 0.80 and policy passes unreadable → retake rejected declined or not eligible correction → amended entry
Every move between states is written to the ledger with who or what made it. An exported receipt can still be corrected, but the fix becomes a new entry instead of an edit.
More detail: data model and analytics events

For engineering

Data model

1 : nn : 11 : n1 : n1 : n1 : n1 : n1 : 1 Fund idnamebalancebudget_month Member idfund_idpersonrelationshiprole_id Role idnamecapabilities[] Policy idfund_idagency_id?categories[]weekly_limitreceipt_over Receipt idfund_idmember_idstateimagetotal LineItem idreceipt_iddescriptionamounteligibilityconfidence Approval idreceipt_idpolicy_iddecided_bychecks[]decision LedgerEntry idfund_idrefactorkindat
Policy has an optional agency_id. Without one it’s a family rule, and with one it’s an agency rule the family has agreed to. Same table either way.
EventFires whenFeeds
receipt_capturedA photo, email or card transaction comes inTime to log
fields_extractedThe model returns fields with confidence scoresSaved with no questions
review_answeredA person confirms a field or answers “your call”Time to log
receipt_acceptedA receipt reaches the ledger, auto or by a personSaved with no questions
field_correctedSomeone edits a field after it was acceptedField corrections
approval_decidedAn agency request is approved or declined, with failed checksRequests needing a person
export_sentA family statement or billing export goes outAdoption (agency)