Skip to contentFree 30 minute call with Pali

PWA · 2026

StudyBuddy

A tuition centre moved 1,600+ real accounts off WhatsApp and spreadsheets onto one live platform.

StudyBuddy is an online tuition-centre platform I designed and built for a Malaysian tuition centre that ran its classes on WhatsApp groups and spreadsheets. Students, parents, teachers and admins now share one installable app for classes, assessments, timetables and billing. It went live at studybuddy.my on 24 September 2026 with more than 1,600 real accounts migrated.

Live
  • Client
  • PWA
  • Education

Last updated

Visit live site: studybuddy.my (opens in a new tab)

What were the results?

Real accounts migrated
1,600+
Source: Legacy-system import: 841 students, 734 parents and 25 teachers · As of Oct 2026
Classes migrated
304
Source: Legacy-system import count · As of Oct 2026
Enrolments migrated
1,500+
Source: Legacy-system import count (about 1,536) · As of Oct 2026
An open book with blank pages and a pencil resting across them on a light grey studio background

Screens

Real pages from the live product.

What problem did it solve?

A tuition centre ran classes, fees and parent updates through WhatsApp groups and spreadsheets, so every term meant manual enrolment and chasing payments.

What was built?

  • Four roles, one product: students, parents, teachers and admins each get their own view of live classes, assessments, timetable and billing.
  • Logins that match real families: phone and password sign-in with scoped identities, so a parent and child can share one number without sharing an account.
  • Migration as a feature: 841 students, 734 parents, 25 teachers, 304 classes and about 1,536 enrolments moved in from the legacy system.

How is it engineered?

Measured from the source repository, not estimated. As of Oct 2026.

Architecture

React 19 single-page PWA built with Vite and deployed on Vercel, with Vercel serverless functions for payments, PDFs, e-invoicing, AI and notifications, over Supabase Postgres, Auth and Realtime.

Data and isolation

Postgres with 269 migrations, 346 row-level security policies over 123 RLS-enabled tables, four-role access (student, parent, teacher, admin), money stored as integer sen, and a double-entry general ledger with journal entries and lines in integer cents.

Security and privacy

  • Payment webhook rejects any request whose signature does not verify against the gateway public key over the raw body
  • Every scheduled endpoint requires a cron secret; user-facing API routes require a verified bearer token
  • A guard script fails any migration that leaves an API-reachable table without row-level security, added after a real incident
  • E-invoice client secret read only server-side with the service role, never sent to the browser

Regulatory rules in code

Submits monthly consolidated e-invoices to LHDN MyInvois (UBL 2.1, submit and status), stores SSM and SST registration fields, and scopes profile columns so contact details are not exposed to peers under PDPA.

Quality evidence

Billing self-check33 assertions, all passingRegression check on shared money and invoice-status logic
Ledger integrity checks32 named invariantsNamed invariants in the ledger integrity gate (run against the live database)
Cross-user sync test6 end-to-end flows incl. RLS isolationHarness signs in as different roles and checks what each can see (run against the live database)
Commits436 (9 Jun to 18 Sep 2026)Git history of the main branch

Operations

Vercel deploys with five scheduled jobs (daily charging of due invoices, reminders, email and push queues, trial expiry), a post-build guard that makes staging builds non-indexable, and an activity log table for staff actions.

What was my role?

Designer, architect and full-stack builder, including the migration of real data from the legacy system.

What else shaped the build?

  • Payments in Malaysian rails. A parent shop and fee payments built on CHIP.
  • Respect for families. A hard rule that the platform never messages families without an explicit request.

Where does it stand now?

StudyBuddy has been live at www.studybuddy.my since 24 September 2026 as an installable PWA, with more than 1,600 real accounts migrated. CHIP payments are built and awaiting sandbox verification.

Built with
  • Pali UI
  • Asset Library
  • Pattern Library

Next case study

UrusPro and HelloStayUrusPro left a vendor-locked no-code prototype for an owned SaaS that now sells paid plans per listing.

Want something like this built?

Get a price in two minutes, or talk it through on a free call.