How is it engineered?
Measured from the source repository, not estimated. As of Oct 2026.
Architecture
Expo and React Native app for iOS and Android built with EAS, on Supabase Postgres with 4 Deno edge functions, plus a static marketing site on Cloudflare Pages that ships no JavaScript.
Data and isolation
Postgres with 119 migrations, 297 row-level security policies over 130 RLS-enabled tables, every record scoped to a household (household_id referenced 2,594 times in migrations), and allowance money stored as integer sen.
Security and privacy
- Profile PINs stored as bcrypt hashes in a table no client can read, with attempt counting and lockout
- Subscription webhook authenticated by shared secret and idempotent on event id
- Append-only tables reject deletes unless a security-definer function opts in for that transaction
- Background purge functions fail closed when their secret is not configured
Regulatory rules in code
PDPA consent is collected before any family data is stored, parents can export the household's data as JSON and delete the account in-app, and a daily retention job purges expired data.
Quality evidence
| Automated tests | 1,384 passing, 0 failing | Full app and back-office test suites run on the main branch |
|---|---|---|
| Database smoke scripts | 20 | SQL smoke tests for payments, roles, push and data sync |
| Schema migrations | 119 | Count of versioned migration files |
| Commits | 581 (16 Sep to 5 Oct 2026) | Git history of the main branch |
Operations
Six scheduled Postgres jobs (push sending every minute, image purge every 15 minutes, daily retention purge, yearly hashing-pepper rotation), EAS production build profile, and a marketing site with a strict content security policy.
The problem
UrusFamily is for Malaysian families with parents aged 30 to 45 and two to four children, in BM and English. The aim is simple: everyone in the house contributes, and children can see what their effort is worth in RM, with the parent still paying the allowance.
My role
Founder, product designer and solo builder of my own product: PRD, kickoff, design system, app, backend and release.
Approach
- A family team, not a to-do list. Everyone in the house contributes: chores earn points, points feed one shared family goal, and each child sees an RM allowance add up, paid by the parent.
- Kids without email. Children use PIN profiles. They never approve their own chores; only a parent approval writes points, enforced on the server.
- A virtual wallet, no real money. Points convert to RM in a per-child ledger with payday, a savings goal and a weekly cap. No money moves inside the app in v1.
- Safe defaults parents can change. Leaderboard off, allowance cap on, at most three notifications a day.
- Privacy rules from day one. Chore proof photos are not kept, personal notes and diary sit behind each member’s PIN, and PDPA consent and export are part of onboarding.
- A minimal lovable product, not an MVP. Ten milestones, each with a polish gate of ten exit criteria, and an Apple-style design pass on device that moved type to the iOS scale and dropped colours that failed contrast.
- Built for Malaysian families. BM and English, clay avatars for every Malaysian family, and an Android home widget, from one Expo codebase.
Outcome
UrusFamily went from first commit on 16 September 2026 to version 1.0.0 submitted for App Store and Play review on 25 September 2026. As of 28 September 2026, 1,182 automated tests pass, and the live backend passed all 70 smoke checks on 18 September 2026.


