Case study · 2024

A private community platform delivered in 6 working days.

SamePlace needed a private community platform. The Facebook Clone base already carried the mechanics, so the engagement went where their product was actually different. We built the product; they launched the brand.

  • Facebook Clone · MXBook
  • 6 working days our build time on the base
  • Source code transferred to SamePlace’s own account
SSamePlaceSame Place Wellness Ltd
SSamePlace
Solution
Facebook Clone
Product
MXBook
Delivered
2024
Stack
PHP · MYSQL · GOOGLE MAPS
Build time
6 working days
Blocks reused
18 of 22
Source code
Transferred
2applications shipped
18blocks reused unchanged
4built for this client
9integrations, each isolated
100%source code transferred

What already existed, and what did not.

The distinction that decides a project like this: the mechanics were proven before the engagement started, so the time went into the part that was theirs.

We build the product; the client launches the brand. That is the arrangement, and it only works if the handover is real: SamePlace owns the source code, had a launch date in writing before work started, and can check every figure on this page against a public ledger.

A privacy-first community app is a long road from scratch. Feed, events and the circle permission model came ready. They built our journal module with end-to-end encryption, the practitioner booking flow and a wellbeing widget. Retention is well above what we modelled.

Anton Barbaro, Founder · Same Place Wellness Ltd

The line between reused and built.

The work sat where it always sits on this base: community rules, circle model, growth surface. Everything else on the list below arrived already built and proven on other engagements running the same base.

2Applications and consoles shipped, each with its own permissions and release pathDelivered
18Platform modules reused unchanged from the Facebook Clone baseDelivered
4Decisions built for SamePlace: community rules, circle model, growth surfaceDelivered
3Environments: development, staging and productionDelivered
100%Source code transferred to SamePlace’s own accountContractual

What SamePlace actually needed.

A private community platform is not one feature. It is 22 distinct pieces that all have to work together before a single customer can be served, and most of them already existed and had been proven elsewhere.

That distinction decides the shape of a project like this. A business does not need a dispatch engine or a settlement ledger to be invented again; it needs one that already works, then it needs the handful of decisions that make the product theirs rather than anyone else’s. The four below are the load-bearing pieces SamePlace would otherwise have spent months building before proving anything to a customer.

Every platform of this kind has the same shape underneath: a set of load-bearing parts that must be correct before a single customer can be served, and a much smaller set of decisions that make it one business rather than another.

Building the first set from zero would have consumed the window before the second was even discussed. That is the decision this engagement turned on, and it was taken before any code was written.

Memberprofile, feed, groups
Adminmoderation, reports,
API gatewayauth, rate limits,
Realtime channelnotifications,

What we settled before building.

Which of the 22 pieces were already solved, and which were genuinely SamePlace’s to decide. Getting that line in the right place before any code is written is what keeps a Facebook Clone engagement short, and it is the conversation we would rather have honestly than optimistically.

Where a scope genuinely does not fit a proven base, we say so during scoping and quote it as a custom build instead, even when that costs us the larger and more comfortable project.

01

Read the requirement back to first principles

What must exist at launch, separated from what a business can add once it has customers. Those are different lists and conflating them is what makes projects run long.

02

Base versus build, capability by capability

Each of the 22 capabilities assessed against the existing base as covered, partial or absent. Partial is treated as absent, because a half-fitting module costs more than a new one.

03

Mark what only SamePlace could decide

4 decisions were commercial or jurisdictional rather than technical. Those were theirs, and the engagement is where they got implemented.

04

Agree the line before writing anything

18 pieces reused unchanged, 4 built. Fixing that line up front is what turns a platform of this size into a six-working-day build.

The parts that are genuinely hard.

Not marketing difficulty, actual difficulty. These are the problems any serious Facebook Clone has to solve properly, and the reason building one from a blank page is a multi-quarter commitment rather than a sprint.

Each was solved once, on the base, and has been under load on other builds since. SamePlace inherited the solutions rather than the problems.

01

The graph decides visibility

Friends, groups and circles determine who sees what. Privacy scoping is the product, not a settings page.

Already solved in the base: Member
02

Feed ranking at scale

What surfaces shapes behaviour, and behaviour shapes the network.

Already solved in the base: Admin
03

Moderation is unavoidable

Any open social product needs reporting, enforcement and appeal from day one.

Already solved in the base: API gateway

What we did not have to build for SamePlace.

Every platform is made of the same mechanics underneath. This is the account of which of them SamePlace paid attention to, and which were already solved.

Built from nothing, SamePlace would have meant paying for the mechanics again: the accounts, the sessions, the payments, the admin, the permissions. That work is real, it is slow, and none of it is what makes this product different from the next one. Starting from the Facebook Clone base moved that cost out of the project entirely, and the platform itself was deployed in 6 working days.

What that bought is attention. The engagement went into the 4 parts that were actually different, instead of being spread thin across 22 of them.

Shipped ready-made18 of 22
01
Memberprofile, feed, groups
02
Adminmoderation, reports,
03
API gatewayauth, rate limits,
04
Realtime channelnotifications,
05
Event busfan-out on post and
06
Social graphfriends, groups, follows
07
profilesaccounts, presence
08
visibilitywho may see each post
09
Feed assemblyranking, ordering,
10
Posts & mediacomposer, albums,
11
Interactionscomments, reactions,
12
Notificationsmentions, activity
13
Moderation queuereports, enforcement
14
Search & discoverypeople, groups, pages
15
Analyticsengagement, reach
16
storeaccounts, graph
17
realtimefeeds, sessions,
18
Object storagephotos, video,
Made for SamePlace4 of 22
01
Community ruleswhat you allow
02
Circle modelhow privacy is scoped
03
Growth surfaceinvites and discovery
04
Brand & themingweb and app
Build all 22 from nothing, mechanics included 18 already solved, so the effort went to the 4 that were not

What this market demanded.

Private wellness community

A privacy-first community stands or falls on who can see what. The circle permission model is the product, and members judge it immediately.

None of that is optional, and none of it is something a platform can guess on a client’s behalf. It is precisely why the 4 decisions listed further down sat with SamePlace rather than with us: they are commercial and jurisdictional questions, and the base exists so that answering them is the whole job rather than the last ten per cent of it.

Everything that shipped with it.

The full working set SamePlace took delivery of. Each piece was already built and proven on other engagements before this one started, which is the only honest reason a platform of this size stands up in six working days rather than months.

None of it is a demo or a scaffold. These are the same components running under other businesses in other markets, which means the failure modes are already known and already handled rather than waiting to be discovered by SamePlace’s first real customers.

Reused from the Facebook Clone base

Memberprofile, feed, groups
Adminmoderation, reports,
API gatewayauth, rate limits,
Realtime channelnotifications,
Event busfan-out on post and
Social graphfriends, groups, follows
profilesaccounts, presence
visibilitywho may see each post
Feed assemblyranking, ordering,
Posts & mediacomposer, albums,
Interactionscomments, reactions,
Notificationsmentions, activity
Moderation queuereports, enforcement
Search & discoverypeople, groups, pages
Analyticsengagement, reach
storeaccounts, graph
realtimefeeds, sessions,
Object storagephotos, video,

Built for SamePlace

Community ruleswhat you allow
Circle modelhow privacy is scoped
Growth surfaceinvites and discovery
Brand & themingweb and app

The base this was built on.

The same architecture carries every Facebook Clone on this page. The filled blocks are the parts built for SamePlace.

Facebook Clone architecture MXBook / filled = built for this client
Facebook Clone: the architecture, and one post traced through it 2 client surfaces reach an edge of gateway, realtime channel and event bus. The base holds 10 services, of which Social graph is the source of truth, and 4 blocks are built for each client. Partner services sit behind a boundary and are chosen by the client. Underneath, one post is traced across 5 steps. 18 of 22 blocks are reused unchanged. Facebook Clone MXBook One documented build runs on this base. Only the filled blocks are built for you. Ships ready-made Built for this client Surfaces Edge The base - already built Partner boundary Data Member profile, feed, groups Admin moderation, reports, policy API gateway auth, rate limits, idempotency Realtime channel notifications, presence, chat Event bus fan-out on post and follow Social graph friends, groups, follows SOURCE OF TRUTH Identity & profiles accounts, presence Privacy & visibility who may see each post Feed assembly ranking, ordering, dedupe Posts & media composer, albums, attachments Interactions comments, reactions, shares Notifications mentions, activity Moderation queue reports, enforcement Search & discovery people, groups, pages Analytics engagement, reach Built for this client Community rules what you allow Circle model how privacy is scoped Growth surface invites and discovery Brand & theming web and app chosen by the client Media pipeline transcode, CDN Push & email their sender Content scanning their moderation service Maps & places their key Object storage their bucket Transactional store accounts, graph edges, posts Cache & realtime feeds, sessions, counters Object storage photos, video, attachments one post, end to end every step below runs on blocks that already existed 1 Compose text, media, audience 2 Scope the graph decides who may see it 3 Fan out feeds and notifications built 4 Interact reactions, comments, shares 5 Moderate reports reviewed, action taken PHP · MYSQL · GOOGLE MAPS 18 of 22 blocks reused unchanged 4 built for you
This is the Facebook Clone base, drawn as it was actually assembled for SamePlace. The plain blocks are the ready-made platform and shipped as they are. The filled blocks are the ones we built for this client. 18 of 22 blocks were reused, 4 were built.

Why none of this had to be written again.

Each of these was already running on other builds of the same base before SamePlace started. That is the whole reason the platform was standing in days rather than months.

Memberprofile, feed, groups
Adminmoderation, reports,
API gatewayauth, rate limits,
Realtime channelnotifications,
Event busfan-out on post and
Social graphfriends, groups, follows
profilesaccounts, presence
visibilitywho may see each post
Feed assemblyranking, ordering,
Posts & mediacomposer, albums,
Interactionscomments, reactions,
Notificationsmentions, activity
Moderation queuereports, enforcement
Search & discoverypeople, groups, pages
Analyticsengagement, reach
storeaccounts, graph
realtimefeeds, sessions,
Object storagephotos, video,

The decisions that were actually theirs.

A ready-made base does not remove these; it removes everything underneath them. Each one below is a choice SamePlace had to make, and the engagement is where those choices got implemented.

Community rules

Configured for SamePlace during the engagement.

Why it sat with themWhere the line sits is theirs to draw, and it moves with their audience. We built the controls and left the thresholds to them.

Circle model

Configured for SamePlace during the engagement.

Why it sat with themCommercial rather than technical. The base already handles the mechanics underneath, so the engagement is where their own answer gets implemented.

Growth surface

Configured for SamePlace during the engagement.

Why it sat with themCommercial rather than technical. The base already handles the mechanics underneath, so the engagement is where their own answer gets implemented.

Brand & theming

The identity carried across every surface, so it reads as the client’s product rather than a template.

Why it sat with themThe base has to disappear behind their identity, so this is applied across every surface rather than skinned on one.

What the six days actually cover.

Our build time on a ready-made base, and nothing else. The parts that sit with the client are named plainly.

01

White-label

The base is rebranded to the client’s identity across every surface.

02

Deploy

Stood up on the client’s own hosting, not ours.

03

Publish

Apps submitted from the client’s own developer accounts.

04

Handover

Source, schema, deployment configuration and architecture notes transferred.

The client supplies the hosting and domain, a verified developer account we publish from, branding and business details, an onboarded payment gateway with KYC complete, and any third-party API keys. Store review and merchant onboarding are controlled by Apple, Google and the payment provider, so those sit outside our window. Every figure here is defined on the facts page.

Who uses it, and for what.

Rather than screenshots of a product that has moved on since delivery, this is the set of surfaces that shipped and what each one is for. SamePlace received every one of them, with the source behind each.

Every role here is a separate application with its own permissions, its own state and its own release path. Building them to work as one system is most of the engineering in a platform of this kind, and it is the part that was already finished before this engagement began.

Member
profile, feed, groups
Admin
moderation, reports,

What guards the platform.

Built into the base and hardened across every engagement running it, rather than bolted on at the end of this one. Security added late is security that has to be argued for; the controls below were load-bearing from the first deployment.

We claim the process, not a certificate. Miracuves does not hold ISO 27001, and we do not say otherwise: we build to the controls those frameworks require, and the evidence trail is there for an auditor who asks.

Moderation queue

reports, enforcement. Part of the base, so it was proven before this engagement started.

Role separation

Each surface sees only what its role permits, enforced server-side rather than hidden in the interface.

Audit trail

Who changed what and when, retained so a dispute can be answered with a record rather than a recollection.

Transport and storage

TLS end to end, credentials hashed, and anything sensitive at rest encrypted rather than merely obscured.

Secrets handling

Keys live in environment configuration on their own infrastructure, never in the repository we hand over.

Card data stays out

Payment details go to the gateway directly. The platform holds a reference, not a card number.

Backups and restore

Scheduled backups with a restore that was actually run, because an untested backup is a guess.

What it connects to.

The connection points are part of the base and were already written and tested. Which providers sit behind each one was SamePlace’s decision, because those choices are commercial and jurisdictional rather than technical.

This is also where the client-side dependencies live. Gateway onboarding, KYC approval and merchant review are controlled by the provider, not by us, which is why they sit outside the build window rather than inside it.

Every one of these was already wired and tested in the base. What changed for SamePlace was which account sat on the far side of it.

Messaging and voicein-product communication
Object storage and CDNtheir bucket, their region
Product analyticsevents, funnels, retention
Media pipelinetranscode and delivery
Search and indexingcatalogue, filters, ranking
Market data feedsrates and reference prices
Push and transactional emailsent under their sender identity
App store developer accountspublished from their own accounts
Error and uptime monitoringhanded over with the source

What it runs on.

The platform stack for MXBook. This describes the base as it stands today; SamePlace took delivery of the source and has owned it since.

Platform
PHPMYSQLGOOGLE MAPS
The stack the MXBook base runs on, already in production elsewhere
Surfaces
MemberAdmin
Each a separate application with its own permissions and release path
Client decisions
Community rulesCircle modelGrowth surfaceBrand & theming
Configured for SamePlace during the engagement
Handover
SourceSchemaDeployment configArchitecture notes
Transferred at the end of the build

Where the six days went.

Our build time only. Store review and merchant onboarding are controlled by Apple, Google and the payment provider, so they sit outside this window and we do not count them as ours. Stating that plainly is the difference between a build time and a promise we cannot keep. Every figure here is defined on the facts page.

The six working days are guaranteed. If a ready-made platform is not live in six, we keep working free until it is. A deadline nobody is accountable for is not a deadline, and a guarantee nobody pays for is not a guarantee.

Throughout, a named team worked the build and sent SamePlace progress on WhatsApp every working day. There was never a week where nobody knew where it stood, which is the part clients tell us they notice more than the date itself.

6 working days our side of the window

The bar below is that window, day by day. Nothing outside it is counted as ours, and nothing inside it waits on someone else.

Day 1
Base stood up and white-labelled
Base stood up and white-labelled
Days 2-4
4 client decisions implemented
4 client decisions implemented
Day 5
Deployed, apps submitted
Deployed, apps submitted
Day 6
Source, schema and config handed over
Source, schema and config handed over

This base has done this before.

SamePlace was not the experiment. The base underneath this build had already carried other businesses in other markets before it carried theirs, which is the whole argument for reuse: the risk was retired by somebody else’s project, not by this one.

Across everything delivered since 2010 that is more than 9,000 products for over 6,000 businesses across 35+ industries. The eighty-four documented on this site are the ones with a named client and permission to show the work; most of the rest sits under NDA or white-label and is deliberately not here at all.

Every number on this page is defined and sourced on a public facts ledger. That is the whole instinct behind how this company is run: most vendors ask you to trust them, and we would rather you checked us. If we cannot back a claim, we do not make it, which is why you will not find a satisfaction percentage or an unnamed award anywhere on this site.

18 of 22

Blocks reused unchanged on this build, each already under load on other engagements.

Architecture
1

Documented builds running on the Facebook Clone base, in different markets.

Portfolio
9,000+

Products delivered for more than 6,000 businesses across 35+ industries since 2010.

Company record
3,900+

Apps published under clients’ own brands, counted per store release.

Company record

What the client reported.

Figures supplied by the client and published with their name against them.

90-day retention at 41% reported by the client

The base carried the load-bearing parts, so the engagement went into what made this build theirs rather than anyone else’s.

Anton Pascella Barbaro, Founder, Same Place Wellness Ltd
6 working daysOur build window on this engagement.Miracuves delivery record
100%Source code transferred to SamePlace’s own account.Contractual
18 of 22Blocks reused unchanged from the base.Facebook Clone architecture

A privacy-first community app is a long road from scratch. Feed, events and the circle permission model came ready. They built our journal module with end-to-end encryption, the practitioner booking flow and a wellbeing widget. Retention is well above what we modelled.

Anton BarbaroFounder, Same Place Wellness Ltd

What SamePlace holds now.

The same on every engagement. What happened to the platform after handover was theirs to decide.

GITApplication sourceFull repository history, transferred to their accountDelivered
APPMobile projectsSources with signing documentedDelivered
SQLSchema and migrationsReproducible from empty, not a dumpDelivered
ENVDeployment configurationAnother team can run it unaidedDelivered
MDArchitecture notesWhat was chosen, what was rejected, whyDelivered
60dSupport windowSixty days included, six and twelve month optionsDelivered

The questions that decide this.

Answered for this build. The same answers hold for every Facebook Clone in the portfolio.

Do we own the code?

Yes. The full repository history transferred to SamePlace’s own account at handover, with deployment configuration and architecture notes. It is not a licence and it is not held against a support contract.

How is six working days realistic?

Because 18 of the 22 pieces were built and proven before the engagement started. The six days are our build time on that base, not a calendar promise.

What sat with SamePlace?

Hosting and domain, a verified developer account we publish from, branding and business details, an onboarded payment gateway with KYC complete, and any third-party API keys.

Will it look like everyone else’s?

No. The base supplies mechanics, not identity. Branding, flows and every customer-facing screen were built for this product.

Is this what the platform looks like today?

This describes what was delivered in 2024. What happened afterwards was SamePlace’s to decide; the source transferred at handover. Clients move on, rebuild, or sell up, and none of that changes what was delivered or how it went.

Would you have said no to this project?

We are a good fit for a founder who wants a proven model launched fast, a deadline they can hold us to, and code they own outright. We are a poor fit for anyone who needs a team embedded in their office full-time, or who wants a blank page and a six-month roadmap. Being straight about that up front saves everyone a call.

Who actually worked on it?

A named team, not a rotating pool. Our leadership is public with real profiles rather than a stock-photo team page, and progress went to SamePlace on WhatsApp every working day of the build.

Building something like this?

Tell us what you are building and we will say plainly whether a ready-made base fits it, including when the answer costs us the larger project.