Inspiration

I'm from LA. Fire season is a really big problem for many families. Red Flag Warnings, dry wind, everyone half-checking the forecast without really noticing they're doing it. I remember the sky going red and smoke in the distance. Friends near the hills evacuating more than once.

What bugged me was the gap. The official alerts cover a whole county, not your street. The group chat "does anyone know if that's smoke by the 118" is fast but nobody can verify it. Nothing in between. And nobody's opening a safety app for fun, so it just doesn't get checked until it's too late. That's the whole reason for building this, plus a game on top, since that's the part people actually want to open.

How We Built It

One day, split three ways: the map, the security underneath it, Phaser for the game. React, Leaflet, Supabase, and NWS's public API for real alerts.

Two things needed actual math. Sorting reports by distance uses haversine.

And the game's fire count scales exponentially after an easy opening stretch. That's why it feels chill for a minute, then isn't, just like it happens in real life.

Challenges

Deleting your own report with no login was the real problem. No account means no user_id to check against. We generate a one-time token on submit, hand it back to just that browser, and check it inside a database function instead of trusting the app. Verifying that against the live database, not just reading the code and assuming it worked, took a while.

Tuning the growth rate above also took longer than it should have, first pass either stayed flat for ten waves or spiked so hard wave 6 felt like wave 20.

Mostly though, it was just the clock. One day for an abuse-resistant reporting system and a full game meant some stuff didn't make it in, spam protection, connecting the game to real reports made off platform.

What We Learned

When trust is involved in public safety, it isn't one decision, it's a bunch of small ones, what an API returns, what's excluded from a read grant, whether a check happens client-side or in the database. Easy to build something that looks secure but is really just relying on the client behaving, making something that prevented bad actors from affecting people looking for safety was something we had to work around.

And building even a rough version of the thing I wished existed growing up made the problem feel less like background noise.

Built With

Share this project:

Updates

Submission history