A retro board you can start in ten seconds.
A real-time collaborative sticky-note whiteboard for workshops and retros. Share a link, type a name and you're in: no accounts, no sign-up. Everyone sees notes, frames and pointers move live, and the host gets proper facilitation tools: a timer, board lock, anonymous dot voting and a silent brainstorm.
The idea is simple: the quickest way to get a group onto a shared board. Joining is a link plus a typed name. Starting a session is gated by a passcode so the free relay can't be abused. Sessions clean themselves up after seven days with nobody in them.
Built in small slices, each usable on its own. Here's what's in the app today.
Notes with a title and body, size, colour and text styling, edited in place. Frames mark out named areas and carry their notes when moved. Text labels plus rectangles, ovals and diamonds round it out, and an emoji picker works in note, shape and frame text. All on a 6400 × 4000 board.
React FlowLive syncRetros (Start Stop Continue and others), Planning and facilitation (sprint planning, Lean coffee, 2x2 impact and effort, RAID) and Architecture and analysis (SWOT, TIME, migration strategy, technology radar, architecture decision). Each one lands on the board in a single step.
Frame templatesWhoever starts a session is the host on that device. They can run a countdown timer everyone sees, lock the board, and end the session. Guests see a clear banner and greyed-out controls with the reason, rather than things silently not working.
TimerLock boardThe host starts a round and everyone spreads a few dots across the notes. Nobody sees totals until the host stops the round, then a Top voted highlight and a results list appear. Voters are anonymous, even to the relay, and budgets are enforced on the server.
FacilitationThe host starts a silent round and everyone writes notes only they can see, marked "Only you". A strip shows how many notes each person has written, and the host reveals them all at once. The hidden notes stay sealed on the relay, so other people's pages never receive them early.
Sealed notesAn avatar stack, join and leave messages, a chat, and everyone's pointer with their name as they move over the board. Go to a person's pointer from Participants, or switch cursor sharing off. Pointers are relayed live and never stored.
Real-timeMulti-select across notes, shapes and frames, arrange into a grid, match sizes, bring to front or send to back, duplicate, and per-person undo and redo. Fit to notes, zoom to a selection and a clickable overview map keep big boards manageable.
Multi-selectUndo/redoExport the board as a PNG picture or a Markdown file, made entirely in the browser with nothing uploaded. If the connection drops, the page reconnects with backoff, resyncs the board, and tells you if any change didn't make it.
PNG + MarkdownThe front end is Vite, React and strict TypeScript with Zustand, Tailwind and React Flow, deployed to GitHub Pages. The real-time side is a Cloudflare Worker with one SQLite-backed Durable Object per room, using the WebSocket Hibernation API on the free plan. The whole thing is one repo: web/, worker/ and shared/.
Every message between browser and relay is a Zod schema in shared/, used by both the web app and the Worker. The relay validates every message and is the authority (last write wins, with optimistic updates on the page). The protocol is versioned (now at v18) and an old page gets a friendly "please reload" rather than breaking.
Room codes are long, random and HMAC-signed, and the Worker checks the signature before it touches any Durable Object. Creating a session needs a passcode (compared in constant time, rate-limited, never logged). There are per-IP and daily creation caps, per-room limits on size and message rate, an Origin check, and a kill switch that stops new sessions from a phone in under a minute without a redeploy. No secrets are ever committed.
Signed room codesKill switchThere are no accounts, and names are typed and unverified (the app says so). The relay's own code logs nothing about requests, and a test fails if anyone adds a log line. Votes are anonymous via a per-room key that the relay never stores, cursors are never stored, and empty rooms delete themselves after seven days, leaving only a small marker so old links say "Session expired".
No accountsDevelopment happens on a Raspberry Pi 5 (arm64), including running the Worker locally. Every change must pass typecheck, the test suite (Worker tests run inside the real Workers runtime) and a build, and GitHub Actions deploys Pages and the Worker on each merge. Screenshots at 360, 768 and 1280px in light and dark are generated by a script.
GitHub ActionsCloudflare WorkersEach slice has its own branch, is built tests-first, and stops for review. Every protocol or storage change gets a version bump, compatibility handling and tests.
Repo, CI, Pages and Worker deploys, app shell and design system, gated room creation and signed room codes.
DoneLive sticky notes, styling, multi-select and arrange, inline editing, z-order, frames and the first templates.
DoneAutomatic reconnect and resync, avatars and join/leave messages, live cursors, idle room expiry.
DoneHost timer, board lock and end session, anonymous dot voting, and a three-part silent brainstorm.
DoneText and shapes, PNG and Markdown export, a four-times-larger board, panel layout, navigation and eleven more templates.
DoneFollow a person and the host's Bring to me, a load test and accessibility pass, and reactions on notes.
NextArrows bound to notes and shapes, grouping and stencils, a phone participant view with QR join, and optional AI summaries and sentiment.
PlannedBuilt with Claude Code. Each slice is planned in chat and then built with Claude Code, tests first. The repo's CLAUDE.md is kept under 6 KB (a test checks it), with detail for each area in docs/architecture/, and a docs test fails CI if the changelog, plan and README fall out of step.
Join any session with just its link and a name. Starting a new session needs the create passcode, which keeps the free relay from being abused.