Skip to content

[About]

A small studio that ships real products.

Grallumae is an independent product studio in Kerala. We build privacy-first software for small groups and the infrastructure to run it, rather than advising other people how to do the same.

Grallumae Technologies is a one-person product studio. There is no team, no investor deck and no roadmap written for a funding round — which turns out to be a useful constraint. It means every product gets built because someone needed it, and every claim on this website can be checked against the code behind it.

The work is deliberately unglamorous in the best way: multi-tenant data models, row-level security, edge runtimes, encrypted storage, and test suites that try hard to break the authorisation boundary. We care about the part of a system that decides who gets to see what, because that is the part that silently fails in most applications.

We run the whole stack — Cloudflare Workers and Pages, Supabase Postgres and Deno Edge Functions, D1, Durable Objects and Queues, R2 — and we build the surrounding product surface as well, because an idea nobody can actually use is not finished.

Grallumae

Technologies

Founded
TODO_FOUNDED_YEAR
Based in
Kerala
Team
Independent, one founder
Products shipped
Three
Ads run
None, ever
Data sold
Never

[Origin]

How we got here.

Not a company history — the five moments that actually shaped what we build.

    1

    Where it started

    One person, one problem

    Grallumae began as a side project to keep a study group in one place — chat, notes, calendar and the deadlines nobody could keep track of. That group is the reason Mangofold exists in the shape it does.

    2

    The hard turn

    A billing dispute became an architecture

    Leaving Firebase meant rewriting the entire authorisation layer as Postgres row-level security and replacing Functions with Deno Edge Functions. It was unplanned, and it turned out to be the single best decision in the project's history.

    3

    Shipping

    Mangofold v1.0

    Thirty routes, twenty-four edge functions, twenty-six migrations, and a test suite that treats the security boundary as the main event. Live at mangofold.pages.dev.

    4

    New territory

    FamilyFolds starts

    The question shifted from groups of friends to households. FamilyFolds began with its hardest decisions written down first — no penalty points, opt-in leaderboards, transparent location — before a line of product code existed.

    5

    Archive

    bottlemail retires

    The service went offline. The repository stayed, because the AES-256-GCM addressing model is the clearest expression of how we think about identity, and throwing that away would waste it.

[Principles]

What we believe, operationally.

Six positions we hold consistently enough that they have cost us work.

Privacy is an architecture, not a setting

A privacy policy is a promise about behaviour; a row-level security policy is a guarantee about the database. We build the second kind and treat the first as documentation.

State the real status

FamilyFolds is labelled in development because it is. bottlemail is labelled retired because it is. Overclaiming is cheap and it destroys the only asset a small studio has.

Build the thing you would use

Every product here started as a problem someone actually had. That constraint is why they are scoped the way they are, and it is why they exist at all.

Write it down

Design docs, architecture notes, an honest changelog and a status label on every product. If a decision cannot be explained in writing, it is not settled.

Optimise for small groups

The interesting communities are the ones of six to fifty people, and they are underserved by platforms built for millions. Mangofold is designed around a server of twelve.

Boring where it does not matter

Cryptography, ledgers and authorisation get real engineering attention. Everything else should be unremarkable, well-tested and out of the way.

[Boundaries]

How we build

These are engineering positions rather than business-model promises. They describe how the code is written, not how a product is eventually funded.

  • No dark patterns — no nagging, no fake urgency, no confirmshaming
  • No engagement mechanics aimed at compulsive use
  • No analytics that fingerprint you across our own properties
  • No growth target that requires weakening a security policy
  • No product that cannot work with its server switched off

[Get in touch]

Have something that needs building?

We take on a small number of contract projects — product builds, privacy-critical backend work, and taking an idea from zero to shipped. Tell us what you're working on.

Taking on select projects for 2026