Mangofold
Discord-grade real-time infrastructure rebuilt as one calm, invite-only space per small group. Mangofold pairs channel chat with a shared wiki, a shared calendar, personal task lists and a configurable home dashboard — so a study group, club or long-distance family gets the infrastructure of a platform without the noise of one.
Shipping at v1.0.2 across iOS, Android and web, with signed-URL gated storage and a scheduled push pipeline.
- Platforms4 surfaces
- Features10 documented
- Architecture4 decisions
- Stack12 technologies
[In the box]
What it actually does
- Real-time channel chat with replies, edits, polls and attachments
- Shared Markdown wiki and a shared calendar for the whole group
- My Day — personal tasks with due dates, notes and defer
- Thoughts feed with hot/new/following ranking, likes, reposts and threads
- Six configurable widgets: calendar, weather, timer, timetable, My Day, recommendations
- Row-level security enforced in Postgres across 26 migrations
By the numbers
- Routes
- 30
- Edge Functions
- 24
- DB migrations
- 26
- RLS boundary assertions
- 188
- E2E test suite
- 21 tests
- Unit tests
- ~55
- Storage / server (free → plus)
- 1 GB → 100 GB
- Max upload (free → plus)
- 25 MB → 500 MB
- Invite code lifetime
- 24 hours
[Features]
Inside Mangofold
Every item below is implemented in the codebase, not planned for a future release.
Real-time channel chat
Supabase Realtime channels with replies, edits, unsends, image and file attachments via signed URLs, and in-chat polls.
Shared Markdown wiki
A real wiki with a custom renderer and in-app search, so decisions and notes outlive the scrollback.
Shared calendar
Important dates for the whole group, surfaced on the home strip and scheduled for automatic reminders.
My Day
Personal tasks with due date and time, notes, complete, defer and edit — grouped by day.
Thoughts feed
A server-scoped social feed with hot/new/following filters, polls, quote posts, threads, likes and reposts. Cross-server engagement is rejected by composite foreign keys.
Six configurable widgets
Server-shared calendar and recommendation widgets, plus personal weather, timer, timetable and My Day widgets — each placed and themed by the member.
Moderation built in
An admin-only report queue with captured content excerpts and one-tap removal, plus member blocking enforced by the message read policy.
Scheduled push
An outbox table with a pg_cron retry sweep dispatches calendar reminders the night before, the morning of, and at task due times.
Six themes, both modes first-class
Dark, Midnight, Light, Mango, Lagoon and Orchid — every colour published as a runtime custom property so re-theming needs no rebuild.
Installable PWA
Installable with an offline-capable service worker, per-platform install guidance and OTA updates over the air.
[Architecture]
How it is built.
The decisions that shaped the codebase, and what each one buys.
Permissions live in Postgres
Role checks, membership and blocking are expressed as row-level security policies rather than client conditionals, so a modified client cannot widen its own access. Entitlements are owner-readable and service-role-only writable.
One edge function per capability
Twenty-four Deno Edge Functions each own a single callable, all behind a shared actor-verification layer. This keeps the trust boundary narrow and the failure modes local.
Theming without rebuilds
Every colour is emitted as a `--mf-*` custom property at runtime. Re-theming ~250 class sites is a variable swap, not a compile step — which is what makes six palettes and two modes affordable.
Retries that survive failure
Push delivery goes through an outbox table drained by pg_cron via pg_net, so a flaky APNs or FCM response retries instead of silently dropping the notification.
[Who it is for]
Built for
- Study groups and school cohorts
- Clubs and small teams
- Long-distance families
- Friend groups that have outgrown a group chat
[Non-negotiables]
The rules we held
- Invite-only by construction — a 24-hour rotating code is the only way in
- Privacy by default — invite-only, no public profiles, no data resale
- Server-authoritative — permissions live in the database, not the client
- Members can block, report and moderate without leaving the app
[Stack]
Built with
Delivered
- Invite codes with rotation and revocation
- Owner / admin / member roles with ownership transfer
- Chat, wiki, calendar, My Day, Thoughts, widgets, profiles
- Reading shelves with cover art, ratings and progress tracking
- Report queue and member blocking
- Activity feed with per-category push toggles
- Account deletion, display-name change, legal docs
Not done yet
Listed rather than hidden.
- Poll result display and vote-result UI in Threads
- Post edit and delete UI for Thoughts
- Complete search UI for the Thoughts feed
- Thought-specific notification presentation
- Server-side ranking for the Hot feed
[Timeline]
How it got here.
Where this came from, in order.
Foundation
Left Firebase for Supabase
A billing dispute triggered a full migration in one change: Firestore to Postgres, security rules to RLS, Functions to Edge Functions, hosting to Cloudflare Pages.
v1.0
Invite-only servers ship
Membership, rotating invite codes, role management and the chat surface land as a single coherent unit.
v1.0.x
From chat to community
Wiki, calendar, My Day, the Thoughts feed, widgets and scheduled push extend the server beyond a message log.
Now
Hardening for release
Closing the documented product gaps listed above, with the test suites — 188 RLS assertions plus E2E — as the gate.
[FAQ]
Common questions.
The questions we would expect to be asked.
Why build another chat app?
Because the interesting groups are small. Mangofold optimises for a study group of twelve rather than a network of millions — which is why it can afford a wiki, a calendar and real moderation without any of them feeling bolted on.
How does privacy actually work?
Every read and write passes through a row-level security policy in Postgres. Profiles are only visible to co-members of a live server, thoughts are bound to a server id, and blocking is enforced by the message read policy — so it holds even if a client is modified.
Can anyone join, or is it gated?
It's gated. A server is invite-only, invite codes expire after 24 hours, and rotating the code revokes the previous one.
What are the storage limits?
Free servers get 1 GB with 25 MB max upload; Plus raises that to 100 GB and 500 MB. Joining a server is never capped — only creation is.
The rest of the catalogue
[Get in touch]
Questions about Mangofold?
Want to know more about Mangofold — timelines, availability or how it works under the hood? Send us a note.
Taking on select projects for 2026