Send one link. Behind it: everybody's face, a whiteboard you can all draw on, text
channels, breakout rooms, a private thread with anyone there, and questions with
live results when you need them. Not a tab per tool — all of it, at once. Teams
run reviews and standups in it; it runs a class just as well.
1link to sendthe code and the key travel in the hash, so they stay out of Referer headers and server logs
1channel underneathrooms, breakouts and DMs are all inside it, so a person is in the room exactly once
0media serversfaces go peer to peer; the channel carries only who is here and what they switched on
28assertions on the live siteincluding two privacy properties checked by breaking them on purpose
The layout is the argument
Opening the whiteboard should not cost you the room
The first version of this app was a mode switcher. The board replaced the faces, the quiz
replaced the board, and a side conversation had nowhere to go. Every feature was there and
none of them were there at the same time, which is the opposite of what a room
needs. So the faces were moved out of the rotation entirely.
The roomfaces stay; the surface changes
# general 🎥 faces — always on screen chat
# questions ──────────────────────────────── ┃ Amina: is this on?
🔊 Main room [ Board ] [ Quiz ] [ Results ] ┃ Host: loud and clear
🔊 Group A ┃
the working surface ┃ 📎 😀 ✋
● Amina ┃
● Sam people (3)
Faces live in a strip that is always on screen. Board, quiz and results are tabs underneath it.
The strip folds when somebody wants the whole board — a choice you make, not one the app makes for you.
Chat is always in the right panel, whichever surface you are on.
Channels, breakouts and direct threads sit in the left rail, so switching what you are reading never changes what you are watching.
On a phone the rail becomes a row of rooms across the top — a sidebar next to a whiteboard leaves neither of them usable.
What is in it
Three things a working group needs, in one place
Talking to each other, working on something together, and finding out whether any of it
landed. Each of those exists elsewhere on this site as its own demo; here they are one app.
Talking
Camera, microphone and screen share. Click any tile to enlarge it, or go
fullscreen; somebody who starts sharing a screen is put on the stage and shown
whole rather than cropped. Text channels that keep their own history, breakout
rooms the host opens, and a private thread with anyone in the room. Pictures,
eight reactions that float up the screen, and a raised hand on the roster.
VideoEnlarge & fullscreenChannelsDMsReactions
Working
A whiteboard everyone can draw on: pen, line, arrow, rectangle and ellipse, six
colours, a width slider. Shapes travel as geometry, so a circle cannot
arrive as a square, and the room watches a shape form while you drag it. Undo takes
back your own strokes and nobody else's. The host can lock the pen or clear it.
WhiteboardLive shapesPer-author undo
Finding out
The host writes a question and ticks the right answer. The room gets the question
without the key. Answers go to the host alone, one per person, and
the host grades. Three graphs come out of it: how the room answered, whether the
class is getting it question by question, and where everybody stands.
QuizzesGraded by the hostCharts
The rule underneath
The host is an identity, not a flag
One person grades the quizzes and moderates the board, which makes "who is the host?" a
security question rather than a display one. Two rules answer it, and both are load-bearing.
A message counts as the host's when its sender matches the host recorded in the room — never because the payload says {host: true}. A payload field is written by the sender, so any participant's console can assert it.
There is no automatic promotion. Every other app on this platform elects a new host when the old one leaves. Here the host holds the answer key, so promoting whoever is left would hand a participant the ability to grade themselves. If the host goes, the room pauses.
Grading, clearing the board and opening a breakout are all gated on that same check — in the modules, not by hiding a button.
Who receives whatstated, not implied
Text channeleveryone — the UI files it by room
Breakouteveryone — a grouping label
Quiz answerthe host only
Direct messageone person only
A channel is a filing label and this page says so, rather than implying a
privacy it does not have. An answer and a DM are addressed, so they
genuinely reach one person.
Proof
An assertion nobody has watched fail is decoration
Both privacy claims above are tested against the live site, and both were checked by
breaking them on purpose — pointing the send at a broadcast and confirming the test goes
red. A test that cannot fail proves nothing, and it is the easiest kind to ship.
answer() → broadcast ✗ a classmate never receives another student's answer
sendDm() → broadcast ✗ and nobody else in the room receives it
restored ✓ 28 passing, against the deployed copy
What it demonstrates
Every primitive the SDK has, doing a job rather than being shown. Presence and a heartbeat keep
the roster honest about a phone that backgrounded its tab. Broadcast carries strokes and
questions. Addressed messages carry the things that must reach one person —
an answer, a private line — which is the difference between a demo and something a class could
use. Channel storage keeps the room record, each room's history and one version per closed
question, so somebody who joins late can read back.
The one trap worth repeating: a message's type is validated against the service's
own enum and anything else is dropped in silence — the socket stays up, the send reports
success, and nothing arrives. Every logical type here rides inside a valid one. It cost a full
debugging round to find, and the first green test run was hollow because of it.
How many people, and what that costs you
A meeting is a full mesh: every pair negotiates its own stream, so nothing you
say or show touches our servers, and the video is end-to-end encrypted by construction. It is
also why a meeting has a ceiling — each camera is uploaded once per other person — and that
ceiling is around six.
A broadcast room sends the presenter's picture to our relay once and the relay
passes it on, so what the presenter uploads stops growing with the audience. Measured, on two
dedicated processor cores: ten viewers of one 640×480 stream, all receiving the full
twenty frames a second, at about two thirds of that allowance. The cost per extra viewer is
small and steady, which puts the real ceiling somewhere in the low twenties — an extrapolation
from a measured slope, not a number anybody has watched happen, so it is written here as such
rather than rounded up into a promise.
The trade is not free. The relay decrypts and re-encrypts, so in a broadcast
room our server can see the video. Chat, the whiteboard and files stay end-to-end encrypted in
every room. The app says which kind of room you are in, on screen, the whole time — you cannot
tell by looking, so it should not be something you have to remember.
Not a file host either. Pictures go inline and are capped well under a megabyte, because they
ride the same channel as everything else. For real transfer there is
Drop, which streams peer to peer, and
Fieldstamp, which chunks and hashes what it
sends. And the whiteboard is not persisted — a board lives as long as somebody is in the room,
while the quiz history and the channel chat outlive it.
Announced 5 September 2026 — applies to new accounts from 1 October 2026
This is the announcement the beta promised: paid plans are announced before they apply. Joining a room stays free and account-less, for ever — that is not a pricing decision, it is what makes the product work. Minutes bill the host, never the guest.
Free Host · £03 rooms · 3,000 hosted minutes a month (about six eight-person hours) · everything in the room, including add-ons.
Host · £9/mo or £79/yr10 rooms · 15,000 minutes a month · co-host, board and results export, a usage dashboard.
Venue · £39/mo or £349/yr100 rooms · 60,000 minutes a month, then £1 per 1,000 minutes rounded in your favour · presenter broadcast · white-label.
Who this applies to. Accounts created on or after 1 October 2026 start on Free Host. Every account that exists before that date keeps exactly what it has today — its current room cap, no minute cap — until its owner chooses a plan. Nothing moves on the day.
How you pay, for now. By invoice: ask for a plan and an admin moves your account and sends the invoice. Card payment arrives when a provider is wired, and will be announced the same way. The meters on your dashboard show what you have used before anything is ever refused.