Skip to content
Live in production

Mangofold

Discord-grade real-time infrastructure rebuilt as one calm, invite-only space per small group. Mangofold pairs channel chat with a shared wiki, a shared calendar, personal task lists and a configurable home dashboard — so a study group, club or long-distance family gets the infrastructure of a platform without the noise of one.

Shipping at v1.0.2 across iOS, Android and web, with signed-URL gated storage and a scheduled push pipeline.

Mangofold
iOSAndroidWeb (PWA)Installable

[In the box]

What it actually does

  • Real-time channel chat with replies, edits, polls and attachments
  • Shared Markdown wiki and a shared calendar for the whole group
  • My Day — personal tasks with due dates, notes and defer
  • Thoughts feed with hot/new/following ranking, likes, reposts and threads
  • Six configurable widgets: calendar, weather, timer, timetable, My Day, recommendations
  • Row-level security enforced in Postgres across 26 migrations
iOSAndroidWeb (PWA)Installable

By the numbers

Routes
30
Edge Functions
24
DB migrations
26
RLS boundary assertions
188
E2E test suite
21 tests
Unit tests
~55
Storage / server (free → plus)
1 GB → 100 GB
Max upload (free → plus)
25 MB → 500 MB
Invite code lifetime
24 hours

[Features]

Inside Mangofold

Every item below is implemented in the codebase, not planned for a future release.

Real-time channel chat

Supabase Realtime channels with replies, edits, unsends, image and file attachments via signed URLs, and in-chat polls.

Shared Markdown wiki

A real wiki with a custom renderer and in-app search, so decisions and notes outlive the scrollback.

Shared calendar

Important dates for the whole group, surfaced on the home strip and scheduled for automatic reminders.

My Day

Personal tasks with due date and time, notes, complete, defer and edit — grouped by day.

Thoughts feed

A server-scoped social feed with hot/new/following filters, polls, quote posts, threads, likes and reposts. Cross-server engagement is rejected by composite foreign keys.

Six configurable widgets

Server-shared calendar and recommendation widgets, plus personal weather, timer, timetable and My Day widgets — each placed and themed by the member.

Moderation built in

An admin-only report queue with captured content excerpts and one-tap removal, plus member blocking enforced by the message read policy.

Scheduled push

An outbox table with a pg_cron retry sweep dispatches calendar reminders the night before, the morning of, and at task due times.

Six themes, both modes first-class

Dark, Midnight, Light, Mango, Lagoon and Orchid — every colour published as a runtime custom property so re-theming needs no rebuild.

Installable PWA

Installable with an offline-capable service worker, per-platform install guidance and OTA updates over the air.

[Architecture]

How it is built.

The decisions that shaped the codebase, and what each one buys.

01

Permissions live in Postgres

Role checks, membership and blocking are expressed as row-level security policies rather than client conditionals, so a modified client cannot widen its own access. Entitlements are owner-readable and service-role-only writable.

02

One edge function per capability

Twenty-four Deno Edge Functions each own a single callable, all behind a shared actor-verification layer. This keeps the trust boundary narrow and the failure modes local.

03

Theming without rebuilds

Every colour is emitted as a `--mf-*` custom property at runtime. Re-theming ~250 class sites is a variable swap, not a compile step — which is what makes six palettes and two modes affordable.

04

Retries that survive failure

Push delivery goes through an outbox table drained by pg_cron via pg_net, so a flaky APNs or FCM response retries instead of silently dropping the notification.

[Who it is for]

Built for

  • Study groups and school cohorts
  • Clubs and small teams
  • Long-distance families
  • Friend groups that have outgrown a group chat

[Non-negotiables]

The rules we held

  • Invite-only by construction — a 24-hour rotating code is the only way in
  • Privacy by default — invite-only, no public profiles, no data resale
  • Server-authoritative — permissions live in the database, not the client
  • Members can block, report and moderate without leaving the app

[Stack]

Built with

Expo SDK 57React Native 0.86TypeScriptNativeWind / TailwindSupabase PostgresSupabase RealtimeDeno Edge FunctionsSupabase StorageCloudflare PagesEASVitestzod

Delivered

  • Invite codes with rotation and revocation
  • Owner / admin / member roles with ownership transfer
  • Chat, wiki, calendar, My Day, Thoughts, widgets, profiles
  • Reading shelves with cover art, ratings and progress tracking
  • Report queue and member blocking
  • Activity feed with per-category push toggles
  • Account deletion, display-name change, legal docs

Not done yet

Listed rather than hidden.

  • Poll result display and vote-result UI in Threads
  • Post edit and delete UI for Thoughts
  • Complete search UI for the Thoughts feed
  • Thought-specific notification presentation
  • Server-side ranking for the Hot feed

[Timeline]

How it got here.

Where this came from, in order.

    1

    Foundation

    Left Firebase for Supabase

    A billing dispute triggered a full migration in one change: Firestore to Postgres, security rules to RLS, Functions to Edge Functions, hosting to Cloudflare Pages.

    2

    v1.0

    Invite-only servers ship

    Membership, rotating invite codes, role management and the chat surface land as a single coherent unit.

    3

    v1.0.x

    From chat to community

    Wiki, calendar, My Day, the Thoughts feed, widgets and scheduled push extend the server beyond a message log.

    4

    Now

    Hardening for release

    Closing the documented product gaps listed above, with the test suites — 188 RLS assertions plus E2E — as the gate.

[FAQ]

Common questions.

The questions we would expect to be asked.

Why build another chat app?

Because the interesting groups are small. Mangofold optimises for a study group of twelve rather than a network of millions — which is why it can afford a wiki, a calendar and real moderation without any of them feeling bolted on.

How does privacy actually work?

Every read and write passes through a row-level security policy in Postgres. Profiles are only visible to co-members of a live server, thoughts are bound to a server id, and blocking is enforced by the message read policy — so it holds even if a client is modified.

Can anyone join, or is it gated?

It's gated. A server is invite-only, invite codes expire after 24 hours, and rotating the code revokes the previous one.

What are the storage limits?

Free servers get 1 GB with 25 MB max upload; Plus raises that to 100 GB and 500 MB. Joining a server is never capped — only creation is.

The rest of the catalogue

[Get in touch]

Questions about Mangofold?

Want to know more about Mangofold — timelines, availability or how it works under the hood? Send us a note.

Taking on select projects for 2026