Inspiration

A recall notice arrives during a busy clinic afternoon. Sixty-four units match the affected lot. Twelve more have no lot recorded. Can the clinic honestly say its response is complete?

Lotline starts with those twelve unknowns. This scenario is illustrative; the demonstration uses fictional clinics and stock.

What it does

Lotline helps small clinic groups respond to recalls of unused medical-device inventory. It connects a human-reviewed source notice to stock records, separates exact matches from unresolved identifiers, records quarantine and permitted disposition, and exports the response evidence. It needs no patient records.

Visitors can explore a separate sample demo. Email accounts provide a private inventory workspace that starts empty, accepts CSV imports, and persists across devices. Sign-in, sign-out and password reset are included. The interface supports desktop and mobile.

In the sample workflow, verifying twelve missing labels changes the affected total from 64 to 76. The operator records quarantine and return of all 76 units, reviews coverage, and completes the response. Thirty units remain outside the reviewed scope. Completed responses preserve their inventory snapshots while later stock can be imported for new responses.

Lotline recall response workspace

How we built it

The public deployment target uses Firebase Hosting, a standalone Next.js application on Cloud Run, Firebase Authentication, and a dedicated Firestore database. The interface uses React and TypeScript; Zod validates inputs. The repository includes a single-command Google Cloud Shell deployment script and reproducible tests.

  • Atomic nine-column CSV import with stable stock IDs and a 500-record workspace limit.
  • Deterministic manufacturer, catalog, individual-unit GTIN and lot assessment. Missing identifiers remain unresolved.
  • Supported GS1 text parsing and GTIN check-digit validation.
  • Optional live FDA reference lookup, followed by mandatory human scope approval.
  • Source-authorized return or destruction, quantity conservation, overlap protection and completion gates.
  • Verified server sessions, separate account/workspace records, transactional revision checks and durable request deduplication.
  • Hash-linked activity, JSON checksums, spreadsheet-safe CSV and printable response records.

The supported notice scope is one product with exact shared lots or an explicitly reviewed all-lots declaration. Complex ranges, serial-number recalls and mixed product/lot combinations require separate handling.

What makes it different

Recall-management products already exist. Lotline's differentiation hypothesis is a lightweight workflow for groups using basic stock exports: missing identifiers remain visible, quantities must reconcile, and completion requires a reviewable record. A successful match count alone cannot close the response.

Challenges and lessons

Clean sample data hide the hard cases: missing lots, packaging identifiers, conflicting writes and repeated submissions. We built uncertainty and server-side quantity checks into the workflow. We also separated the sample demo from imported inventory and froze completed snapshots so later imports cannot rewrite prior assessments.

A second challenge was the meaning of done. Lotline records operator attestations and references; it cannot independently inspect a stockroom. Completing a local response does not terminate an FDA recall or certify product safety.

Verification

The implemented workflow passes 49 core tests, 17 browser/API workflow checks on the Firebase production build with emulators, and 9 account checks. These cover source review, custom CSV data, persistence, two registered accounts, demo separation, password-reset action generation, conflicting updates, input limits, export integrity and mobile widths from 360 to 1440 pixels. Deployment contract tests and GitHub Actions cover the setup path and build.

The public Firebase app also passed live sign-in, persistence, reconciliation, export and forged-identity rejection checks. Two disposable email/password accounts verified isolated inventory and sign-out. Chrome’s 390px layout was checked. Actual password-reset email delivery remains untested.

These are engineering checks, not clinical or customer validation. Shared organizational roles, evidence attachments, ongoing source amendments, formal retention/backups and supervised field evaluation remain next steps. Checksums establish consistency, not independent proof of physical action.

Commercial model and next steps

The initial buyer hypothesis is a clinic group's operations lead. A distributor could sponsor access for its customers. The pricing experiment is US$99 per group per month for up to three sites, plus US$19 per additional site. Pricing, willingness to pay and distribution interest are unvalidated; no customers, revenue or partnerships are claimed.

Next: interview clinic operations and distributor recall staff, then run supervised historical-notice exercises. Compare active response time, unresolved records, reconciliation errors and evidence completeness against the existing process. Prioritize shared access and integrations from those findings.

Team and acknowledgements

Shivam Gupta — creator and product direction lead. Developed with AI-assisted research, implementation, testing and documentation. Third-party libraries and services are acknowledged in the repository. No FDA, GS1, clinic or distributor endorsement is claimed.

References

FDA: What is a medical device recall?

Historical FDA reference Z-2614-2026 informed workflow research. Its original return deadline has passed; the fictional demo does not execute that notice.

Source code, documentation and deployment

Built With

Share this project:

Updates

Submission history