About shkriuss
shkriuss is my personal project: a small collection of web apps I build for my own everyday use, and share with anyone who likes them.
Why I build these
Everyday apps (for drinking enough water, keeping track of holidays or remembering what you bought) tend to come with accounts, ads, trackers and far more features than anyone needs. I wanted the opposite: quiet tools that open instantly, keep my data private and get out of the way.
So I build them myself, for myself, with the care I’d expect from any app I trust. They’re public because there’s no reason not to share them. If one is useful to you, it’s yours to use.
Principles
-
Private by default
No ads, analytics or trackers, and nothing loaded from other companies’ servers. Your data is used only to make the app work.
-
Secure by design
Strict security headers, HTTPS everywhere and as little code as possible. Apps that keep personal data on a server sit behind a sign-in.
-
Fast everywhere
Tiny pages served from Cloudflare’s network, close to you, so every app loads quickly even on a slow connection.
-
Accessible
Built to WCAG 2.2 AA and tested with automated accessibility checks, by keyboard, on small screens and in dark mode.
-
Clean and calm
Each app does one job well. No clutter, no dark patterns and no notifications you didn’t ask for.
-
Free to use
I built these for myself, and anyone is welcome to use them. No paid plans, and no sign-up where none is needed.
How they’re built
Every app runs on Cloudflare’s global network. Pages are static files served from the edge, and small Workers run only where a server is really needed, such as push reminders, sign-in or syncing between devices.
- Data lives where it’s safest for each app: only in your browser (Brim), in a separate store for each person (Dayjar’s planner), or in storage only invited people can reach (Magpie).
- The code is TypeScript with as few dependencies as possible, and pages never load scripts, fonts or trackers from other sites.
- Browsers are locked down with strict security headers: a Content Security Policy, Trusted Types, cross-origin isolation and HTTPS with HSTS.
- Every change is checked automatically (types, unit and end-to-end tests, accessibility scans and Lighthouse audits) and goes live only when everything passes.
Reporting a security problem
If you find a vulnerability in this site or any shkriuss app, please email security@shkriuss.dev with what you found and how to reproduce it. Please don’t access other people’s data, disrupt the services or run load tests. I’ll reply as soon as I can.
The same address is listed in each site’s security.txt.
Questions
- Is it really free?
- Yes. There are no paid plans, no ads and no selling of data. The apps are small and cheap to run, and I’d be running them for myself anyway.
- What do the apps know about me?
- Only what each one needs to work, and nothing for analytics or advertising. Every project page lists what is stored and where.
- Why are some apps invite-only?
- Apps that keep your data on a server start out invite-only while I use them myself. Brim and Dayjar’s calendar are open to everyone. Dayjar’s planner and Magpie are invite-only for now.
- Can I suggest a feature or report a bug?
- Please do, at support@shkriuss.dev. I can’t promise to build everything, but I read every message.
Contact
For questions, ideas, bug reports or invites, write to support@shkriuss.dev.