Skip to main content
Back to Portfolio
Habit Parity Engine & Wearable Telemetry

doit

Multi-tenant two-player habit accountability & competition platform featuring Supabase Row-Level Security, AES-256-GCM encrypted wearable sync adapters (Apple Health, Google Health, Strava, Hevy), and 12-week consistency heatmaps.

Strict Isolation & Cryptographic Wearable Ingestion

Engineered with a zero-compromise security posture: Supabase PostgreSQL Row-Level Security (RLS) ensures absolute duel boundary isolation across multi-tenant matchups, OAuth 2.0 refresh tokens for health providers are stored with AES-256-GCM symmetric envelope encryption, and telemetry verification pipelines calculate deterministic daily par across heterogeneous workouts.

System Architecture Highlights

  • Duel-Level Supabase RLS Isolation

    Granular database policies enforcing strict multi-tenant boundaries. Participants can only query and mutate duels where auth.uid() matches player_a or player_b.

  • AES-256-GCM Encrypted Token Vault

    Wearable OAuth tokens (refresh & access tokens) are symmetrically encrypted before persistence using AES-256-GCM with unique cryptographic initialization vectors (IVs).

  • Equivalent Habit Parity (240 Daily Par)

    Deterministic algorithmic normalization converting diverse workout intensities, running splits, and gym volume into standardized habit points with an unbending 240 Daily Par threshold.

  • Multi-Source Wearable Adapters

    Extensible connector ecosystem aggregating raw telemetry from Apple HealthKit, Google Health Connect, Strava API, and Hevy workout logs into unified JSON schema payloads.

  • Hybrid Offline-First Sync Engine

    Optimistic UI mutations backed by client-side local caching and exponential backoff retry queues to guarantee habit completion during spotty gym connectivity.

  • Event-Driven Streak Verification

    Atomic database triggers tracking 12-week consistency heatmaps, sudden-death tiebreakers, and rolling accountability streaks without distributed race conditions.

Technology Stack & Operational Specs

Frontend CoreNext.js 16 (App Router), React 19, TypeScript
Styling & UITailwind CSS v4, Radix UI Primitives, Lucide Icons
Database & AuthSupabase (PostgreSQL), Row-Level Security (RLS)
CryptographyNode.js Crypto, AES-256-GCM Envelope Encryption
Wearable OAuthStrava API, Apple HealthKit, Health Connect, Hevy
State & CacheZustand, React Query, IndexedDB Offline Buffer
DeploymentVercel Edge Network, Supabase Managed Cloud

1v1 Habit Parity Calibration

Traditional habit trackers rely on subjective checkboxes, easily exploited by dishonesty. Do It enforces objective parity: running 5km, logging a 60-minute barbell session, or completing 45 minutes of cardiovascular conditioning all map to calibrated fractional par points. Neither competitor can gain an unfair advantage through volume spoofing.

The Mission & Competitive Psychology

Habit adherence collapses when accountability is solitary or subjective. Peer pressure and head-to-head competition remain the most effective behavioral incentives in sports science. Do It transforms daily habit execution into a high-stakes, real-time two-player duel. By bridging physical health telemetry directly with cryptographic accountability, players compete with absolute confidence that every rep, split, and milestone is validated.

1. Multi-Tenant Isolation via Supabase Row-Level Security

Rather than relying exclusively on application-layer permission middleware, Do It delegates data boundary enforcement directly to the PostgreSQL kernel using Supabase Row-Level Security:

  • Duel Matchup Guard: Matches, logs, and scoreboards are inaccessible to external tenants. SELECT and UPDATE statements are filtered by auth.uid() = player_a OR auth.uid() = player_b.
  • Audit Immutability: Historical completion records are cryptographically tagged with submission timestamps, preventing retro-active date modifications or artificial streak preservation.

2. AES-256-GCM Wearable Sync & OAuth Token Vault

Handling third-party health integrations (Strava, Apple HealthKit, Google Health Connect, Hevy) requires handling long-lived sensitive OAuth refresh credentials. Do It isolates token storage using an envelope encryption schema:

  • Tokens are never stored in plaintext within database rows.
  • Each payload is encrypted using AES-256-GCM with a server-side master key and a dynamically generated initialization vector (IV), verifying both confidentiality and authentication tag integrity upon decryption.
  • Rate-limited asynchronous sync workers poll external APIs on configured cadences, normalizing disparate health units (kJ, kcal, meters, RPE) into standard metric representations.

3. 12-Week Consistency Matrix & Micro-Interactions

The user interface pairs low-latency Next.js 16 App Router streaming with Tailwind CSS v4 styling. Interactive 12-week GitHub-style activity heatmaps visualize mutual progress, while real-time parity meters calculate who is leading the current week's 240 Par threshold, fueling healthy accountability and relentless consistency.