ISB Hangout
A campus social app that answers one question: what's happening right now?
A campus social Progressive Web App (PWA): post real activities, or gauge interest with no-commitment polls that convert into a plan in one tap. Self-hosted push, hand-implemented RFC 8291 encryption, three-layer domain-gated auth, feature-flagged rollouts, an admin analytics dashboard, AI-generated company briefings for placement talks, plus a from-scratch festival minigame. Solo build, no funding, no team, alongside the PGP program.
Frameworks in practice
Step through how each one actually played out, not just the name-drop.
Wizard of Oz MVP
"Would anyone come?" tests real demand with zero setup behind it. Only proven interest converts into a real Activity, in one tap. No venue booked, no logistics built, until someone has already said yes. That interest carries over as "interested," not "going": agreeing in principle isn't the same as confirming once a real time and place exist.
Build-Measure-Learn
Features ship behind a flag (Peer CV Reviews, Wall banners, the ILS category, the Ganpati theme), get measured through 17 admin metric functions, then get iterated on or switched off. No redeploy needed to turn something off that isn't working.
Click a stage. The loop runs continuously: nothing ships without a way to measure it, nothing gets learned without shipping it first.
What "measure" actually looks like
4 of the event types the client quietly logs in the background, feeding straight into the metric functions above.
Jobs-to-be-Done
Not a feature backlog, a single question users actually have: what's happening right now? That's why Activities and Polls are the only two primitives in the entire app. Categories later grew tags for cross-filing, something can sit under Food and still be tagged Games, but strictly as an addition; the two primitives never moved. Everything else got cut until it earned its place.
The two primitives, in practice
Polls stay deliberately lightweight rather than a parallel feature to maintain: 3 posted pulled 24 "I'd come" taps, 8 per poll, before converting into a real Activity.
Reach & Impact Prioritization
13 categories got sequenced by reach and impact, not build effort. The minigame, high effort and lower reach, stayed a flag-gated seasonal extra instead of a launch blocker.
Activation funnel
Weekly active users grew 14 → 20 (+43%) across the tracked window.
Reach by category
Live product metrics, pulled from the admin Metrics dashboard: reach holds up even for a niche category like Peer CV Reviews, not just the campus-wide favorites.
Kano Model
Not every feature earns the same investment. Sorting the build list into basic expectations, performance features, and delighters kept effort pointed at what would move reach and impact, not just what felt fun to build next.
Basic
Performance
Delighter
The clearest delighter payoff: a seasonal, flag-gated minigame nobody had to build pulled 67 students into 2,389 finished runs, about 36 each, more repeat plays than any single core feature gets.
The problem
Campus plans lived scattered across WhatsApp groups, each visible only to whoever was already in that chat. No single place to see what was happening today.
What I built
Two primitives: Activities ("I'm In", a real time and place) and Polls ("would anyone come?", no commitment). A poll that gathers enough interest converts into a real activity in one tap. Activities support capacity limits, recurring series, multi-category tagging, and posting before the venue is locked in.
An AI feature that only speaks when spoken to
Placement Talk posts with a company name set can generate a five-section AI briefing: overview, scale and financials, markets, known ISB placement history, and the roles that company typically hires ISB MBAs for, explicitly told to say it doesn't know rather than invent a number. Nothing calls the model on its own: a host taps Generate (or later, Regenerate), and only that tap spends a call. It's powered by Google Gemini's free tier, falling through several free-tier models on a rate-limited response so one busy model doesn't fail the whole request, with a short cooldown so a double-tap doesn't spend two calls where one would do.
Notifications, without a vendor
Self-hosted push, no OneSignal or Firebase: talks directly to Apple, Google, and Mozilla's push services via a VAPID key pair, with RFC 8291 encryption hand-implemented against Web Crypto. A caller only ever names the event; the notification text is rebuilt server-side, so a compromised client can't push arbitrary text campus-wide.
Security is structural, not cosmetic
Sign-up is gated to the school's email domain by three independent layers: a client-side check, a Postgres trigger, and row-level security on every table. Even a leaked anon key reads nothing useful. Admin actions run through security-definer functions checked server-side, never trusted from the client.
Iterating safely in production
Features ship behind a database-backed flag table, toggleable from an admin dashboard, so a half-finished feature can go live dark. Peer CV Reviews, Wall banners, the ILS category, and the Ganpati theme all shipped this way, flippable campus-wide with no code change or redeploy. A "Metrics" tab reads from 17 Postgres functions covering activation, retention, and engagement, each addable without touching the dashboard's rendering code, and every one is gated at the database level so a non-admin calling one gets back nothing, never an error.
A themed minigame
For Ganesh Chaturthi, I built "Mooshak's Modak Dash": a from-scratch endless-runner with its own physics engine, an anti-cheat leaderboard (server-issued single-use run tokens), and its own analytics funnel, gated entirely behind a feature flag.
Built for the long tail, not just the demo
Admins can post horizontally-scrollable Wall banners with a live countdown to a set date, each with its position and size dragged into place against a preview of that banner's own artwork rather than a fixed template. A separate, member-driven Tools & Apps directory lets anyone list a tool the batch has found useful (a CGPA calculator, a club's own app), the same way Places is admin-curated but open for members to contribute to instead. Both sit behind their own admin controls, alongside a sign-up approval queue, a password-reset queue, and an attributable admin action log for every moderation call.
Engineering discipline
Every schema change ships as a sequential, idempotent migration with a plain-English header. One production bug (an admin override that silently changed nothing) was root-caused to Postgres's quiet behavior on a zero-row UPDATE, then fixed by asserting row counts on every admin override write.
Tech stack
Vite, React 18, TypeScript (strict), Supabase (Postgres + Row-Level Security + Auth + Storage + Realtime + Edge Functions), self-hosted Web Push (VAPID, RFC 8291), Google Gemini API for AI-generated content, installable PWA with a custom service worker, deployed on Vercel.