FlowDeck · project overview
FlowDeck: a task board for teams, on free plans
FlowDeck keeps a team's work as cards on boards, shown as a gallery, a Trello-style board, a calendar or a timeline. Cards have comments, checklists, files, due dates, time tracking, automations, reports and AI helpers. It runs entirely on free plans that need no card.
- Running cost
- 0free plans only, no card on file
- Database
- 49tables, from 29 migrations
- Automated tests
- 479328 API · 151 web, all run before every push
- Features
- 152in 18 areas, listed below
What it does152 features
Every feature in the live app, one line each, grouped by area.
Signing in and your own account12 features
- Sign inWith a username and password. Five wrong passwords lock sign-in for 15 minutes.
- First-run setupOn a fresh install the sign-in page creates the first admin.
- Forgot passwordEmails a reset link. The form never reveals whether an account exists.
- Registration from an emailed linkChoose a username and password, and optionally add a phone number and a profile photo. The link works once, for 24 hours.
- Welcome pageGreets a newly registered person by name, says which account they joined and what their role allows, and lists the boards they can open.
- Two-step verificationBy an authenticator app (scan a QR code) or by emailed codes. Switching method or turning it off asks for a code from the method that is on.
- Change password
- ThemeLight, Dark or System (follows the device), plus an accent colour. Choices preview at once and are saved on the account.
- Account avatar with a role badgeAt the right end of the header. It opens the account menu.
- Sign out, or sign out every other device
- Session locked to its browserA session cookie copied into another browser stops working there. Both browsers are told why, and the owner gets an email and a push notification.
- Install the appFrom the account menu. On iPhone and iPad it explains Share, then Add to Home Screen.
People, roles and accounts18 features
- Separate accountsAn account never sees another account's people, boards or cards.
- Five rolesOwner, admin, member, guest (only the boards they are added to) and viewer (read only). Every route checks the role.
- Who sees which cardsOwners and admins see every card. Members see the cards they made, the cards assigned to them, and cards that came in with no maker (from a form or email).
- Add a person by name and emailTheir row shows where they are: link not sent, link sent, link expired, active or suspended, with Send or Resend link.
- Revoke a registration linkIt stops working at once.
- Edit, suspend or change the role of a person
- Set a person's password
- Unlock someone's sign-in
- See and sign out a person's devices
- Mirror a personSee FlowDeck as they do, for up to eight hours, with a banner and a Return button.
- Delete a person but keep their workTheir cards and comments stay, shown as "Name (Deleted User)".
- Site admins' extrasMove people between accounts, make site admins, and turn off someone's two-step verification.
- Accounts pageEvery account with its status, owners, counts and AI use. Create one (even empty), rename, suspend, add a person or a board, and delete it once empty.
- AI per accountSwitch the AI helpers off for one account, or cap its AI requests a day.
- Hand an account to someoneIn two steps: an offer they accept or decline, and the giver can withdraw it.
- Account page for owners and adminsThey manage their own account's people and read its audit log.
- Usage per accountChanges saved, files uploaded and AI requests, each day.
- Claim boards with no ownerAn admin gives them, and their cards, to their own account.
Boards10 features
- Board switcherThe board name in the header lists your boards first. Admins see the rest grouped by owner.
- My cardsEvery card you are on, across all boards, as one board.
- New board, rename, archive
- Board backgroundA choice of background colours per board.
- Guests on a boardPeople who see only the boards they are added to.
- Transfer a board to a user, or copy it to a user
- The board is in the addressA link sent to a teammate opens the same board. The last board used is remembered.
- LabelsCreate, rename, recolour and delete. A picker beside the card searches labels and ticks them on or off.
- Platforms and prioritiesThe lists behind those dropdowns: add, remove, and put priorities in order, highest first.
- "No boards yet" screenFor someone with no board yet, with New Board when they may make one.
Lists7 features
- Add, rename and delete lists
- Reorder listsDrag a list's header, or choose Move left or Move right.
- The done listOne list can be marked as the place done cards go.
- Card limitFor example "at most 5". The count turns red when a list holds more, and moving a card into a full list warns first.
- Whole-list actionsAssign every card to a user, or archive, delete or restore them all. Only the cards the search and filters show are affected.
- Load moreEach list loads 25 cards at a time, and the whole board comes in one request.
- Time totalsTracked against estimated hours for the list's open cards.
Cards24 features
- Quick addType a heading and press Enter. Pasting several lines makes one card per line.
- Card dialogHeading, description, start and due date, people, priority, platform, labels and done.
- Rich description editorThree modes: a rich editor, Markdown with a formatting toolbar and shortcuts, and Preview. Code blocks get a language, highlighting, line numbers and Copy. Links to known services show as named chips.
- People on a cardUsers, or plain names for people who never sign in. Typing, with or without @, suggests both.
- Labels, priority and platform
- Start and due datesThe start date places the card on the timeline.
- CoverThe card's first image attachment, or none.
- ChecklistsSeveral per card, each with items to tick. The card shows how many are done.
- Files and photosDrop them anywhere on the dialog, or paste them. Up to 20 MB each, allowed file types only.
- File viewerFull screen, with download and open in a new tab. Images (zoom and pan), video, audio, PDF, and code or text with highlighting. Markdown files are rendered, with a Source toggle.
- Card facesLabels, the fields marked "On cards", checklist and comment counts, avatars, the board, the cover, "Blocked", and time tracked against the estimate.
- A link for every cardEach card has a short address. Back and Forward reopen or close it, and Copy link copies it.
- Move or copy a cardTo another list or another board.
- Assign to a user from the card's menu
- Card templatesSave a card as a template. A new card on that board can start from one.
- Repeating cardsDaily, on weekdays, weekly or monthly. The next copy is made when the due date comes.
- Mark done, archive, deleteDeleted cards go to a trash an admin can restore from. Restoring asks first.
- Archive all doneOne button on the gallery's Done tab.
- Many cards at onceAssign, archive, delete or restore a selection. Either every card changes or none do.
- UndoFor 8 seconds after a move, archive or delete, of one card or many.
- Custom fieldsUp to 20 per board: text, a number, a choice, a date or a tick.
- SprintPlan a card into one of its board's sprints.
- Waits on other cardsAdd blockers by short id (#abc12345), even from other boards. The card shows "Blocked" while any is open, completing it asks first, and loops are refused.
- Estimate and timerAn estimate in hours and a start/stop timer. One timer runs per person, ticking in the header, and people delete their own entries.
The board view4 features
- Trello-style columnsGrouped by list, or by priority or platform. The app opens here.
- Drag and dropBetween columns to change a card's list (or priority, or platform), within a column to reorder. A dashed placeholder shows where it lands.
- Done, Archived and Deleted switchesShow those cards too, with Restore. Deleted is for admins.
- Swiping on phonesOne column per swipe, with a dot per column to jump.
Gallery, calendar and timeline5 features
- Card gridTabs for To Do, Done, Archive and (for admins) Deleted, with Load more.
- SortBoard order, newest first, name A–Z, due date or priority.
- Compact mode
- CalendarA month of due dates. Drag a card to another day to change its due date.
- TimelineSix weeks of cards as bars from start to due date, a row each, grouped by list.
Filters, search and saved views9 features
- Filters on the gallery and the boardPerson (or Unassigned), priority, platform, label, sprint and due date (overdue, due this week, due this month).
- Clear allAppears when a search or any filter is on, and resets them all at once.
- Filters fold away on phonesBehind a "Filters" button showing how many are set.
- Filters in the addressA reload or a shared link shows the same cards.
- SearchRuns on the server 300 ms after typing stops, and not again for the same words.
- Close spellingsWhen nothing matches exactly, near matches are shown.
- Saved viewsThe gallery's filters saved under a name, per person and board, reopened in a click. A "due this week" view keeps meaning this week.
- Rename saved viewsFilter values a view can no longer hold are dropped.
- Share filters as a linkCopy a link that opens the same filters.
Comments and following cards7 features
- CommentsWrite, edit and delete. Ctrl+Enter sends.
- @mentionsTyping @ lists the people who can see the card. Whoever is named gets an email.
- Reply by emailReplying to a comment email within 30 days adds the answer as a comment, files included.
- Reactions👍 ✅ 👀 🎉 ❤️ on any comment.
- Card historyEvery change, who made it and when, including what automations and GitHub did.
- Watch a cardBell and push when it moves, is done, archived or deleted, or gets a comment.
- Remind meA reminder for you alone: in an hour, this evening, tomorrow morning, next Monday, or any date and time. It comes by bell, push and email.
Notifications and emails7 features
- Notifications bellAssignments, mentions, comments, watched cards, reminders, due dates, ownership offers and security alerts. It shows an unread count, opens the card a notification is about, and keeps 60 days.
- Push notificationsTo each device where a person turns them on, with a test push. On iPhone this works once FlowDeck is on the Home Screen.
- Emails for signing inRegistration, password set, reset link, sign-in and setup codes, and "sign-in used elsewhere".
- Emails about cardsCard assigned, comments, mentions and personal reminders.
- Due-date remindersOnce an admin turns them on: one email and push a day listing what is due tomorrow, due today or overdue.
- Weekly summary emailEach person's week, on the day and hour an admin picks, optionally with a paragraph written by AI.
- Emails that look like FlowDeckEach is laid out as a FlowDeck card. An admin can edit every template, reset it, or send themselves a test.
Sharing outside the team4 features
- Read-only share linkAnyone with the link sees the board's lists and open cards without signing in, but never people, comments or files. It lasts 7, 30 or 90 days, or until turned off.
- Calendar feedA private link per person for Google Calendar, Outlook or Apple Calendar, listing their open cards that have due dates.
- ExportThe cards the gallery shows, in its order, as CSV or Excel.
- ImportCards from CSV, Excel or a Trello board's export. An exported file reads back in.
Bringing work in, and telling other tools4 features
- Email a card into a boardEveryone who may add cards gets a personal address for the board. An email sent to it from their own address becomes a card, with its files.
- Request formA public link where people outside the team file requests without signing in. They land in a list the managers chose, and the owner is told. It filters out bots and has hourly and daily limits.
- Slack, Teams and Discord alertsUp to 5 channels per board, each picking which events to post: cards added, moved, done or commented on. Each has a test message.
- GitHub linkA pull request naming a card by its short id shows in the card's history, and merging it marks the card done.
Automations5 features
- WhenA card is made in a list, moves into one, has every checklist item ticked, or passes its due date.
- ThenMove it, add a label, assign someone, set its due date some days ahead, tick its checklists, mark it done, or archive it (at once or after some days).
- Rules in plain wordsFor example "When a card moves into Done, archive it after 7 days". Each can be switched on or off, or deleted.
- Broken rules flaggedA rule that uses a list, label or person that is gone says so.
- Safe by designRules never set each other off, and every action is written to the card's history.
AI helpers9 features
- Write descriptionWrites one from the heading, or tidies the one there.
- Suggest fieldsProposes priority, platform, due date and labels.
- Suggest stepsA checklist of the steps to finish the card.
- Summarise cardA short summary of the description and comments.
- Similar cardsA likely-duplicate warning when making a card, and related cards in the dialog.
- Cards from notesPaste notes, get one card per action item, pick and edit them, then add.
- AI searchA plain-English search turned into filters, or cards found by meaning.
- Week summaryWhat happened on a board in the last 7 days.
- Admin controlOn or off for everyone and helper by helper, a daily limit per person, and every prompt editable (with reset). They run on Cloudflare Workers AI's free daily allowance.
Reports and time5 features
- Board reportThe last 12 weeks: cards done and made each week, cards overdue at each week's end, and median days from made to done.
- People tableEach person's open, overdue, estimated and tracked hours.
- SprintsPlan sprints (two weeks from next Monday to start with, up to 8 weeks). See how many of each sprint's cards are done, rename them, move their dates or remove them.
- Sprint burndownA sprint's open cards each day, against the ideal line.
- Running timer in the headerShows the card and its time, ticking each second. Click it to open the card, or Stop it.
Site administration7 features
- Admin menuManage users (people and accounts) and Settings (every admin page).
- Live boardsOpen boards show other people's changes by themselves, at an interval the admin picks. A board checks only while its tab is in front and was used in the last 15 minutes.
- AI pageThe helpers, the daily limit, and every prompt.
- Emails pageWeekly email (on or off, day, hour, time zone, AI paragraph, a preview to yourself). Due reminders (on or off, hour, time zone). Every template.
- Jobs pageWhen the timer last checked in. Pause or resume every job, run one now, and read recent runs.
- Audit logWho added, changed, suspended or deleted whom, and changes to roles, accounts, AI and settings. Site admins can pick an account.
- Errors pageServer errors grouped by cause, with how often, where, the latest occurrences and the stack. Mark resolved. New ones are emailed at once, repeats in an hourly digest.
App, phones and keyboard8 features
- Installable appOn desktop, Android and iPhone. It opens offline from a saved copy.
- Fits every screenFrom 360 px phones to 1920 px monitors.
- Phone dialogsEach fills the visible screen with its header always in view. The card dialog does not open the keyboard until a field is tapped.
- Keyboard shortcuts
nnew card,/search,j/kor arrows between cards,eor Enter to open,ggallery,bboard,ccalendar,?the list. - Keyboard-friendly menusEvery dropdown and menu works with the arrow keys, Enter, Escape and Tab.
- New-version noticeA tab left open across a release offers to reload.
- Never stuck loadingIf the first load fails or takes too long, the loader turns into a message with Try again and Sign in.
- Link previewsThe sign-in page carries search and link-preview tags. Every page behind sign-in stays out of search engines.
Behind the scenes7 features
- Instant savingChanges show at once. If the server refuses one, the card goes back and a message says why.
- No double changesA bulk change is all or nothing, and a bulk request sent twice is applied once.
- Daily backupEvery table to private storage, kept 30 days.
- Backup before every database changeProduction is copied in full first. Any backup can be put back in one step.
- Scheduled jobsEvery hour, and every five minutes for email, reminders and chat alerts. A run never overlaps the previous one.
- Rate limitsOn sign-in, password resets, registration, invitations and the request form.
- Free plans onlyHosting, database, files, AI, email and the timer all run on free allowances with no card on file.
Technologies
Current versions throughout. Every service is on a free plan.
Front end
- Angular 22: standalone components, signals, zoneless change detection, pages and dialogs loaded on first use
- TypeScript 6, RxJS
- Angular SSR in hybrid mode: the sign-in page is built ahead of time
- Quill 2, Marked, DOMPurify and highlight.js for the editor and Markdown
- fflate for Excel files, qrcode-generator for authenticator QR codes
- Charts drawn as plain SVG, with no chart library
- A typed API client generated from the API's OpenAPI document, so calling a route the API does not have fails the build
- Service worker and web app manifest (installable app)
API
- NestJS 12 on Express 5, one folder per feature: accounts, admin, AI, auth, boards, calendar, comments, fields, files, forms, GitHub, health, hooks, jobs, notifications, push, replies, sprints, tasks, users, views
- Node.js 24 on Vercel Functions (Mumbai)
- An OpenAPI document generated from the code's own types. Every API test checks each answer against it.
- Zod for settings; Web Crypto for passwords, tokens, two-step codes, device keys and Web Push
- Nodemailer for sending email; ImapFlow and postal-mime for reading replies
Data and services
- PostgreSQL on Supabase (Mumbai), through Prisma 7
- pg_trgm for close spellings, pgvector for similar cards
- Backblaze B2 for files and backups: a private bucket, with short-lived signed links
- Cloudflare Workers AI: a Llama 3.1 chat model and the bge-base embedding model
- Upstash Redis for rate limits, locks and a small cache, with PostgreSQL as the fallback
Hosting
- Cloudflare Pages: the front end, plus a small Function that forwards
/apicalls to the API - Vercel: the API
- Supabase: the database
- A Cloudflare Worker on a timer: hourly jobs, plus a run every five minutes for email, reminders and chat alerts
Quality
- Vitest:
- 60 API test files (328 tests), run against a real PostgreSQL;
- 20 web test files (151 tests).
- ESLint 10 (typescript-eslint, angular-eslint) and Qlty, which runs secret scanners and ShellCheck
- Git hooks: before each push, branch and commit-message rules, lint, the type check, then every API and web test
- GitHub Actions runs the tests on a PostgreSQL with pgvector
How it fits together
Browser (Angular app, service worker)
│ https://flow-deck.pages.dev
▼
Cloudflare Pages ── the app's static files (the sign-in page pre-rendered)
│ /api/* → a Pages Function forwards each call to the API
▼
NestJS API on Vercel (Mumbai)
├── PostgreSQL on Supabase (Prisma; pg_trgm, pgvector)
├── Backblaze B2 (files, backups; the browser uses signed links)
├── Workers AI (helpers, similar cards) ├── Upstash Redis (limits, locks, cache)
└── Email out and replies in └── Web Push (devices)
Cloudflare Worker (timer): every hour the jobs, every five minutes email, reminders and chat alerts
Every request is checked in the same order: that it came through the site, who is signed in, what their role allows, and finally which cards they may see, which is applied inside the database query itself.
Data
49 tables in PostgreSQL. Deleted cards are kept as deleted rather than erased, so they can be restored.
| Area | Tables |
|---|---|
| People | accounts, users, sessions, two-step challenges, password resets, push subscriptions, notifications |
| Boards | boards, board members (guests), lists, labels, options (platforms, priorities), saved views, automation rules and their history, custom fields, sprints, chat alert channels and their queue |
| Cards | cards, their people and plain names, labels, checklists and items, comments and reactions, attachments, card templates, blockers, time entries, similar-card vectors, custom field values, watchers, reminders |
| History | events (each card's history and the audit log), job runs, grouped server errors |
| Site | settings, email templates, AI prompts, usage counts, rate limits, locks, sent reminders and weekly emails, reply tokens |
Security
How accounts, sessions and files are protected.
Signing in
- Passwords are hashed with PBKDF2-SHA256 and a salt per person. Five wrong passwords lock sign-in for 15 minutes, and there are rate limits too.
- Two-step verification by an authenticator app or by emailed codes.
- Everyone can sign out their other devices. Admins and account managers can do it for others.
Sessions locked to one browser
- A secure, script-proof cookie. The server keeps only a hash of it.
- At sign-in the browser makes a key it cannot export, and every request is signed with it.
- A cookie copied into another browser ends the session. Both browsers are told why, the person gets an email and a push notification, and the audit log records it.
Links, files and public entry points
- Links that work as keys (calendar feeds, share links, registration and reset links) are stored only as hashes and shown once.
- Files sit in a private bucket and are reached through short-lived signed links, given after an access check. Only allowed file types can be uploaded.
- The request form filters out bots and has hourly and daily limits.
- GitHub deliveries must carry the board's own signature, and chat alerts go only to Slack's, Teams' and Discord's own addresses.
Secrets, audit and backups
- No secret is kept in the code repository. Settings are stored as encrypted values on each host.
- An audit log records every administrative change and security event. Server errors are grouped and emailed as a digest.
- A daily backup goes to the private bucket and is kept 30 days. Tokens appear in it only as hashes.
- Every database change is preceded by a full backup, and backups taken before a change are kept longer.
Scheduled jobs
A small Cloudflare Worker runs them on a timer. Admins see its last run, pause every job, run one now and read the history.
| Job | When | What it does |
|---|---|---|
| Weekly summary email | hourly check | On the chosen day and hour, each person's week, optionally with a paragraph by AI |
| Repeating cards | hourly | The next copy of each repeating card whose due date came |
| Board automations | hourly | Overdue-card rules (once per card) and archives an automation scheduled |
| Due-date reminders | once a day | What is due tomorrow, due today or overdue, after the chosen hour |
| Similar cards | hourly | Meaning vectors for cards whose text changed |
| Database backup | daily | Every table to the private bucket, kept 30 days |
| Email in | every 5 min | Replies to comment emails become comments; emails sent to a board's address become cards |
| Reminders and chat alerts | every 5 min | Personal reminders whose time came, and each board's waiting chat alerts |
Speed
- A board loads all its lists in one request.
- Only the board page is in the first download (760 kB). Every other page, the timeline, import and export, and every dialog opened from a menu download the first time they are opened.
- Live-board checks are off by default. When on, they pause while a tab is in the background or has been idle for 15 minutes.
- Measured through the site, most API answers come back in 0.2–0.5 s. Once in a while the API starts from cold, which takes about 2 s.
How changes are made
- Each change is its own numbered branch and commit (
CAP-<n>), so every step can be found and reviewed. - Before anything is pushed, the code is linted, scanned for secrets and type-checked, and every API and web test runs.
- A database change is a versioned migration. Production is backed up in full before any migration runs, and a backup can be put back in one step.
- Releases are batched into a few deploys, and each one is checked against the live site afterwards.
Not built yet
- Custom fields are not yet in exports or filters.
- The timeline shows at most 100 cards.
- Watching a card never sends email, to stay within the free email allowance.
- Reminder emails and email into a board need the reply mailbox to be set up.
- GitHub sends pull request events only.
- The request form takes text only, no files.