Product · 2025 · Backend architecture & scale
AfterCollege
A campus-only social platform where every account is verified against a real college, built to hold 10,000 users on a student budget.
- Users designed for
- 10k
- Swipe deck target
- 60fps
- API runtime
- Go
The problem
Campus social apps die from two causes: outsiders flooding in, and a feed that stalls the moment it gets popular. The product needed hard verification at the door and a swipe deck that stays at 60fps while the backend runs on free-tier economics.
Constraints
- Verification must gate signup without becoming a support queue
- TRD scoped to 10k concurrent users before any paid scaling
- iOS-first — the swipe deck is the product, so jank is a P0 bug
Architecture
01 Client
- iOS (Swift)
- Rolling candidate window
- Optimistic swipe writes
02 Edge
- Cloudflare CDN
- Image transforms
- Cached static payloads
03 API
- Go services
- Candidate precompute worker
- Rate limiting
04 Data
- Supabase Postgres
- Row-level security
- Redis hot cache
- Go
- Supabase
- PostgreSQL
- Cloudflare CDN
- Swift
- Redis
Key decision
Prefetched the deck instead of paginating it
The obvious build is a paginated feed: fetch 20, swipe, fetch 20 more. That puts a network round-trip in the middle of a gesture. Instead the client holds a rolling window of candidates and refills in the background at a low-water mark, while the Go service precomputes candidate sets per user rather than ranking on read. Swipes never wait on the network.
What it cost
Precomputed candidate sets go stale — a user who joins now isn't visible to everyone instantly. Acceptable for a social deck, unacceptable for anything transactional, so the same pattern is deliberately not used for messaging.
Outcome
- Wrote the TRD first — capacity model, failure modes and cost ceiling — then built to it, which is what kept the design inside free-tier limits.
- Row-level security enforces campus isolation at the database, not in application code, so a bug in a handler cannot leak across colleges.
- Media served through Cloudflare, so the origin never pays for image bandwidth.