08Full-Stack Product2025 — nowSolo — product, backend, web and mobile
Cook Galaxy — Recipe & Meal-Planning App
A full-stack cooking product with AI import, meal plans, subscriptions and a companion mobile app.
Private repo

The problem
Recipes live in screenshots, bookmarks and messages to yourself, and none of that survives contact with a kitchen. I wanted one place for the recipes you actually cook, with a weekly plan that turns into a shopping list without retyping anything — and then I kept it running as a product instead of stopping at a demo.
Decisions
01
AI where it removes typing, not where it looks clever
Import a recipe from a photo, a screenshot or a link, and ask what you can cook from what is in your fridge. Both are model calls behind a gate: the trial plan needs a verified email and gets a daily cap on AI actions, because an ungated model endpoint is someone else's free API.
02
One backend for the site and the mobile app
The Expo app is not a second product. Every API route accepts either a session cookie or a mobile bearer token, so a feature shipped on the web is available in the app without a parallel implementation.
03
Subscriptions on two rails
Recurring card billing on the web and in-app purchases on mobile resolve to the same subscription state, with a trial that is granted once and cannot be re-granted by deleting the account.
04
Separate databases for production and previews
Preview deployments and local development share a throwaway database; migrations never run against production from a preview. It sounds obvious until the first time a preview branch tries.
05
The tests run against a real database
The end-to-end suite spins up Postgres and a mail catcher inside the CI runner rather than pointing at a preview deployment, so a run is reproducible and does not depend on someone else's environment being awake.
What I measured
78
API routes
all of them serving both the web session and the mobile token
26
mobile screens
every one with a test, including error and retry states
33 → 0
flaky e2e failures
after the suite moved into a hermetic CI environment
21
security findings closed
from an audit, plus a content security policy now enforced
Built with
- Next.js
- TypeScript
- Prisma
- PostgreSQL
- Tailwind CSS
