A1. Svelte 5 runes ($props, $state, $derived, $effect) power the client-side reactivity layer, keeping component state predictable and the template syntax minimal.
A2. SvelteKit form actions handle every web mutation through +page.server.ts loaders and actions, with use:enhance providing progressive enhancement so the app degrades gracefully without JavaScript.
A3. Drizzle ORM provides type-safe query building against a Neon serverless PostgreSQL database, with schema definitions that double as the migration source via drizzle-kit.
A4. Lucia v3 manages database-backed sessions validated in hooks.server.ts on every request, with Arctic handling OAuth flows for Google and GitHub providers.
A5. Resend delivers transactional email for verification codes, password resets, and a daily Vercel Cron job at /api/cron/reminders that sends overdue medication alerts.
A6. CSP headers, per-route rate limiting, Zod validation on every form action, and user_id scoping on every database query form the security boundary.
A7. A versioned /api/v1 JSON surface sits beside the form actions, because a native client cannot post SvelteKit form actions. Both surfaces funnel through the same service layer into the same schema, so a dose logged on either is the same row.
A8. A native macOS client (Swift 6, SwiftUI, GRDB/SQLite) consumes that API offline-first: writes land in a local outbox and drain to the server when connectivity allows, with server IDs reconciled back into local rows.