work / 01 of 06 / desktop research tool

NXTStopHealth

Measuring transportation access to Jackson Free Clinic, with an offline desktop workflow that keeps entered addresses out of saved research records.

Year2026
StackElectron, JavaScript, Census address data, JTRAN GTFS
FocusTransportation access, local computation, research privacy
FormatDesktop app for Windows, macOS, and Linux

The problem

Researching access to a clinic means turning a location into useful transportation measures. The design challenge was to support that analysis without building an address history or requiring a network connection for each lookup.

NXTStopHealth brings address matching and transit calculations onto the researcher’s computer. It is built around a fixed destination, Jackson Free Clinic, and a repeatable review-and-confirm workflow.

The workflow

The researcher enters an address, calculates the connection, and reviews distance to the nearest bus stop alongside estimated walking and bus travel measures. Only an explicit confirmation saves a measurement. Discarding a result leaves the research dataset unchanged.

The app then clears the form for the next entry. Local records make the results available for analysis without an account or automatic cloud sync.

How the measures work

Local Census street-address ranges provide approximate locations. The transit engine uses JTRAN’s public GTFS timetable to find the nearest stop with scheduled pickup service and evaluate a connection to the clinic from that stop, allowing up to two transfers.

Walking distance is estimated from straight-line distance using a 1.35 multiplier and a 2.5 mph walking speed. Bus riding time comes from published timetable durations. Waiting, delays, and coordinated departures are excluded, so the output describes estimated access rather than a live trip plan.

Missing connections stay missing in the saved measurements; they are not recorded as zero travel time. Public data and method versions travel with the detailed records so an analyst can identify which assumptions produced each result. Read the measurement method →

Privacy in the design

Address matching runs locally. After a match, the app clears the entered address before computing the route. Only an explicitly allowed set of rounded measurements crosses the desktop storage boundary after confirmation; saved records omit addresses, coordinates, patient identities, and stop or route identifiers.

The Electron renderer is sandboxed and isolated from Node.js. Network requests from the research interface are blocked, and unconfirmed results clear after inactivity or exit. A separate, optional timetable update downloads public transit data without sending research input.

Those choices reduce what the application retains. They do not make the measurements anonymous: combinations of distances and times can still be distinctive, and device security remains a separate responsibility. Read the privacy design →

Engineering and validation

The code separates the address and routing engine, the public timetable importer, the restricted measurement schema, and desktop record storage. That keeps calculation logic testable independently of the interface.

The repository includes checks for address matching, routing, confirmation and clearing, privacy boundaries, persistence, failed saves, retry deduplication, and migration. Release automation tests and packages the application, while platform-specific launch checks remain necessary. Development and validation notes →

The result

A downloadable desktop tool that connects public geographic and transit data to a focused research workflow. Researchers can review an estimate, choose whether it belongs in the dataset, and keep the resulting measurements on their own computer.

The core lesson: deciding what not to retain belongs in the data model and storage boundary, alongside the calculations themselves.