Looph
Customer-feedback software: public boards where customers post and vote on ideas, a roadmap that shows what is being built, and a changelog that tells everyone who asked when it ships. The founder shaped it in Lovable. We rebuilt everything underneath it, and it is live in production.
At a glance
Looph is customer-feedback software for product teams: public boards where customers post and vote on ideas, a roadmap, and a changelog that tells every voter when their request ships. Its founder shaped it in Lovable. From 4 August 2026, Plutonapps engineers rebuilt everything underneath — hosting, row-level security on all 172 database tables, custom domains, notifications and an MCP server for AI agents — and it now runs in production with 10,387 automated tests passing in CI.
- Automated tests passing
- 10,387
- Stack
- TanStack Start · React · Node · PostgreSQL
- Live since
- 2026
- Build time
- 28 working days
The Lovable prototype
What did the founder design in Lovable?
The founder shaped Looph in Lovable, and it was a working product rather than a mockup: public boards where customers post, vote and comment, a roadmap and a changelog, a rewards engine with points, badges and bounties, automations, integrations, a Chrome extension, a Zapier app and an operator area for running the platform. On 4 August 2026 our engineers took over everything underneath it.
The divide
What did Plutonapps engineer?
The prototype risk
Engineered by Plutonapps
The prototype ran on Lovable's own hosting, compiled for Cloudflare Workers, with no container, no health check and no second copy to try a change on before customers saw it.
A platform of its own
Looph now builds into a Node server in Docker, with a health check that proves the database answers, not only that the process is up. Production runs on DigitalOcean App Platform from its own release branch, and staging is a full second copy with its own database and test-mode payments, sign-in and email. Database migrations never ride along with a deploy: they are applied by a separate, deliberate step.
The browser talks to the database directly with the signed-in person's token, so a permission checked only on screen is no permission at all, and one team's feedback must never reach another's.
Every workspace walled off in the database
Looph's database checks every read and write itself, row by row. Row-level security is on for all 172 public tables, and 1,180 policies decide what a browser, an API key, an AI agent or an anonymous visitor may read or write. One database function answers every permission question for every caller, so there is no second copy to drift. 110 pgTAP suites, tests that run inside a real database, cover those rules, and three privileged functions that any signed-in user could call were found and closed, checked on production before and after.
Teams want the board on their own domain. It shares no cookie with Looph, so visitors would sign in again or the sign-in provider would charge per domain, and a hostname typed into a form must never go live before its owner proves it.
Their own domain, still signed in
Every workspace gets its own subdomain, and a customer's domain is served through Looph's own edge, with certificates issued automatically on the first request. Only a domain that has passed its DNS check resolves at all. On it, people stay signed in through Looph's own first-party session: a single-use, sixty-second handoff code, stored only as a hash, and a cookie that never outlives the sign-in behind it. In production since 17 September 2026.
The whole product is one promise: whoever asked hears when it ships. When we measured the email pipeline, 23 notifications pointed at templates that did not exist, and no invitation had ever reached anyone.
Closing the loop, for real
One typed pipeline now carries 63 notification events to five channels (in-app, email, push, Slack and webhook), each behind its own preference check and idempotency key. Email leaves through a leased queue in batches of 100, paced under the provider's limit. On staging, one email now takes a median of 6 seconds end to end, down from about 100, and a burst of 100 was accepted in 3.1 seconds.
Letting Claude, ChatGPT or Cursor act inside a workspace is only safe if an agent can never do more than the person who connected it, whatever the model says.
AI agents that cannot overstep
Looph's MCP server (Model Context Protocol, the open standard AI assistants use to call tools) is a separate app with its own OAuth sign-in and consent screen, where the person chooses what the agent may do. For every request it mints a sixty-second database token for that person, so their own row-level security decides every row, and four more layers in the database can only take permissions away. It offers 28 tools (12 read, 16 write), logs and attributes every action, and the owner can switch agents off at any time. In production since 29 September 2026.
The operator area, which can see and change every customer's workspace, lived inside the same app customers use.
The operator console, out of the customer's app
Looph's operator console was rebuilt as a separate app on a host of its own, importing nothing from the product. Who you are is proved on your own token before the key that reaches every workspace is touched, operators hold one of three roles, and nobody can remove their own access or the last super-admin's.
At handover no change could be verified: type checking had never run, lint reported 19,849 problems so a real one was invisible, and two tests failed on untouched code.
Gates that tell the truth
Every gate now runs in CI against a recorded baseline, and a count that goes up fails the build: old debt is tolerated, new debt is refused. An architecture check fails the build when one layer reaches into another. Passing tests went from 1,152 at handover to 10,387 across five suites, with every test file green in CI on 29 September 2026.
172
Database tables. Row-level security on every one.
Every public table in Looph's database enforces row-level security. Whoever is asking, the database decides what they may see, so no screen, server route or AI agent can skip the check.
“We prompt a version on Monday and their engineers have the same thing on staging for our test users by Thursday. Lovable removed the arguing, their team removed the waiting.”
Looph
Guarantees
What we hold ourselves to while it runs.
Isolation
Row-level security on every table, enforced by the database
Releases
Staging first, and migrations never ride along with a deploy
Quality
A gate count that goes up fails the build
AI agents
Never more than the person who connected them
Results
What were the results?
- Automated tests passing in CI on 29 September 2026, up from 1,152 at handover
- 10,387
- Database tables under row-level security, with 1,180 policies
- 172 of 172
- Median email delivery on staging, down from about 100 seconds
- 6 s
- Notification events, sent in-app, by email, by push, to Slack and to webhooks
- 63
- Tools for AI agents (12 read, 16 write), through an MCP server live since 29 September 2026
- 28
- pgTAP suites that test the access rules inside a real database, beside 253 migrations
- 110
Stack and timeline
- Product
- Feedback boards, feature voting, a public roadmap and a changelog
- Built with
- TanStack Start, React 19 and Vite on Node; PostgreSQL on Supabase; Clerk, Stripe and Resend
- Apps
- Three apps (the product, the operator console, the MCP server) and four shared packages, plus a Chrome extension and a Zapier integration
- Hosting
- DigitalOcean App Platform in production, a full staging copy, and Looph's own edge for customer domains
- Engineering began
- 4 August 2026, from the founder's Lovable prototype
- Moved to DigitalOcean App Platform
- 16 September 2026
- Custom domains live
- 17 September 2026
- AI agents live
- 29 September 2026
- Build time
- 28 working days with engineering commits, between 4 August and 29 September 2026
- Plan
- Starter
Questions
What else do people ask about Looph?
What is Looph?
Looph is customer-feedback software. Customers post ideas on a public board and vote on each other's, a roadmap shows what is being built, and when something ships the changelog goes out and everyone who asked, voted or commented is told. It lives at looph.ing.
Who built Looph?
Its founder designed the product in Lovable. Plutonapps engineers rebuilt everything underneath it from 4 August 2026: the hosting, the database security, custom domains, notifications, an MCP server for AI agents and a separate operator console.
What is Looph built with?
TanStack Start and React on Node, PostgreSQL on Supabase with row-level security, Clerk for sign-in, Stripe for billing and Resend for email. Production runs on DigitalOcean App Platform.
Is Looph live?
Yes. Looph is in production at looph.ing. Custom domains went live on 17 September 2026 and AI agents on 29 September 2026.
How does Looph keep one team's feedback away from another's?
With row-level security in the database. Every public table has it switched on, and one database function decides every permission for every caller, whether a browser, an API key or an AI agent, so no screen or server route can skip the check.
Everything you have just read runs on our Starter plan. It is the plan we start everyone on.
Bring us what you made. We will build it like this.
Billed yearly. Month to month is $3,999 per month.