Case study · Web app · Messaging
Wisp
An anonymous, ephemeral messaging app with no accounts, from idea to a production MVP in 10 days.
Visit the site ↗
- 10 days
- from first commit to a production MVP
- 0
- personal data: no account, email or phone
- 5 min
- lifetime of a message, by default
- 95
- automated tests (65 on the server, 30 in the app)
- Client
- Juan Farre
- Product
- Private messaging web app · Mobile first
- Start
- September 2026
- Services
- Custom web development · Real time · Automated testing · Cloud deployment
- Technologies
- React 19
- TypeScript
- Vite
- Tailwind CSS 4
- TanStack Query
- React Router
- NestJS
- Socket.IO
- Node.js
- Vitest
- Railway
The client
Juan Farre had a clear idea: a way to chat without leaving a trace. No account to create, no email or phone number to give, and conversations that disappear on their own. He wanted to turn it into a product people can use and show, not a mockup.
The project
Wisp is a web app designed for the phone first. When you open it, a temporary ID is generated, and you share it by hand with the other person. There is no search and no contacts: only someone who knows the ID can start a chat. When the session ends, the ID stops being valid.
We worked from an end-to-end product document: what goes into the first version, what stays out and how each stage is tested. That got us to a complete MVP in 10 days, with no shortcuts where it matters: security, real time and automatic deletion.
The challenge
- Privacy without asking for anything
- An app with no accounts has to identify each person another way, and do it securely. The ID had to be easy to read and to say out loud, yet impossible to guess.
- Truly ephemeral
- Messages, files and sessions must disappear automatically, not just be hidden on screen. An expired message can't be reachable even if someone still holds the ID.
- Reliable real time
- The chat has to feel instant, with presence and delivery indicators, and no page reloads to see new messages.
- Promising only what is true
- In a privacy product, the interface text is part of the trust. It can't claim anything the product doesn't deliver.
Our solution
- Anonymous session with a temporary ID
- The server generates an ID of two groups of four characters, easy to read aloud because it avoids look-alikes (like 0 and O), using a cryptographically secure random generator, never sequential. Each session also has its own token: knowing the ID isn't enough to impersonate someone.
- Real-time chat
- Messages over WebSocket, with online or offline status and delivery receipts. The conversation list shows unread messages and a preview of the last one.
- Messages and files that delete themselves
- Every message and every file expires after 5 minutes by default, and a server process removes them. Idle sessions expire too. An expired message is no longer available through the API.
- Photos, video, audio and documents
- They can be sent with a preview before sending. The server validates type and size (up to 15 MB) and doesn't trust what the client declares. The recipient can view once, download or delete.
- Privacy controls
- A settings screen with auto-delete, the option to clear all data and to log out erasing the identity. When a session ends, the app explains what happened to the ID and the conversation.
- Abuse protection
- Per-IP request limits when creating sessions and chats, server-side recipient validation and a maximum message length. Message content is never written to the logs.
How we work
We split the project into phases, each with an acceptance criterion, for example: two sessions in two tabs that connect a chat using only the ID, or an expired message that can no longer be requested through the API. Every change came with its tests. The result is a server and an app with 95 automated tests, plus end-to-end tests of the chat flow on the server, and deployment on Railway.
The results
- An MVP running in production
- Wisp is live and can be tried today: start a private session and chat anonymously.
- From first commit to deploy in 10 days
- From September 2 to 11, 2026, with an organized, tested codebase ready to keep growing.
- Honest copy
- The MVP doesn't include end-to-end encryption, and the interface doesn't claim it. It says what it is: private and ephemeral. Encryption remains a possible evolution.
Conclusion
Wisp shows how we take an idea to a real product: narrowing the first version, building security and deletion into the design and testing every stage. The MVP is already online and ready to keep growing with its users.
Have an idea you want to see working? Tell us and we'll scope it together. Let's talk →