WRT.agency
← Back to portfolio

Relokant Hub — an automated media platform for a regulated niche

relokanthub.com · Solo project: architecture, engineering, legal layer · 2026
Relokant Hub — an automated media platform for a regulated niche

The problem

A migrant in Poland needs one thing: to find out in time that the law has changed, and what that means for their paperwork. The information exists, but it is scattered across government portals in legal Polish, published with no announcement, and never translated. The existing "expat community" alternative is rumours in group chats.

There is a second constraint that shapes everything. This audience is politically exposed. For part of the readership, being profiled at all is a risk. That rules out the standard media monetisation toolkit — behavioural tracking, retargeting, data sharing with partners — and makes privacy a condition of the product existing rather than a feature on a list.

The solution

Four connected layers:

1. The content engine. Eight automated workflows ingest public primary sources (the national legislative act registry, agency feeds, immigration authority news), deduplicate by content hash, score relevance, generate a draft with rubric classification and a parametric cover image, then push it to an editor in Telegram behind two buttons. Approve and reject are idempotent; publishing triggers cache revalidation. No material is ever published automatically. main page

2. The law reference. A separate entity with its own draft pipeline: legal categorisation, currency status, effective date, and a link to the official publication. Legal content is always free. That is the core of the mission, not a funnel into something paid.

3. The user account. Deadlines by document type (type and date only, no scans or numbers), a calendar with user-created events, saved items, Telegram notifications with threshold reminders and a digest, procedural checklists, and cascading self-deletion. account

4. Privacy-first recruitment. Job postings come from direct employers only, with mandatory legal verification before anything is published. A candidate profile is split into a public part (skills, years of experience, seniority, region) and a closed part (name, contacts, employer names) that is disclosed only through an explicit consent screen, in both directions of initiative. Matching runs on vector embeddings of skills and is, by construction, a recommendation rather than an access filter: the algorithm cannot screen a candidate out.

The engineering worth looking at

Human-in-the-loop as architecture, not as a disclaimer. The generative pipeline has no publishing rights at the database level. Its service role can see content tables only and can insert drafts in a pending-review state; the publish flag is outside its grants. This is not a policy document, it is an ACL.

Three independent boundaries around personal data. Permissions separated at the database-role level (each contour has its own connection pool and its own grant set), row-level security driven by session parameters, and application-level encryption of sensitive fields. Disclosure of personal data runs through fixed-owner functions where the consent check lives inside the function body, so calling code cannot bypass it — including my own calling code.

Analytics without surveillance. Consent records are anonymous by design: a consent identifier, policy version, and language, with no IP, user agent, email, or link to an account. Third-party session analytics loads only after explicit consent and only on a hard whitelist of public routes. The account area and admin panel are never tracked, default deny.

Single-server infrastructure that survives losing the server. Daily encrypted dumps are shipped to object storage at a different provider using asymmetric encryption, with the private key held offline and retention across three horizons. Separately, there is a restore artifact: documentation and scripts validated by an outsider who brought the system up from zero with no access to me.

Change discipline. A dump before every structural migration, idempotent migrations, rollback as a separate labelled section, patch scripts with anchor-uniqueness assertions and atomic writes, file backups with paired md5 verification, and a smoke check after every deploy. One engineer, zero data loss, zero unplanned downtime caused by a release.

Audits. An infrastructure audit across seven layers and a separate audit of the personal-data module across five layers, both with no critical findings. Accessibility score 100, canonical URLs, sitemap and robots, private routes excluded from indexing, and two-layer HTML sanitisation on both the save and render paths.

The legal layer is part of the product

I am a lawyer by training, and that is built into the implementation rather than attached as a claim:

  • ingestion from public feeds only, never from behind authentication; robots.txt respected;
  • personal data minimised to document type and date, with scans and document numbers never stored at all;
  • trilingual terms of service with versioning and enforced re-acknowledgement on change;
  • a privacy policy, an editorial policy, and explicit labelling of AI-generated and sponsored content;
  • an honest statement about withdrawal of consent: the architecture protects what it can actually protect and makes no false promises about data already exported by a third party.

For regulated subject matter this is where the difficulty actually sits. Anyone can build a news aggregator. Taking one through GDPR, copyright in primary sources, and the accuracy expectations that attach to legal information is a different job.

Stack

Next.js 15 (App Router, standalone), TypeScript, Tailwind with design-token theming (light and dark), Drizzle ORM, PostgreSQL 15 with pgvector, pg_trgm and pgcrypto, n8n, Docker Compose, Cloudflare Zero Trust Tunnel, OpenAI for generation and embeddings, transactional email, Telegram Bot API, and encrypted off-site backups in object storage.

No port is exposed to the public internet except through the tunnel. Internal routes sit behind a bearer token and return 404 on mismatch: fail closed rather than confirming that the endpoint exists.

My role

All of it. Product decisions, architecture, database schema, backend, frontend, automation, infrastructure, security, legal documentation, editorial policy, and the design system.

What is reusable for a client

The project doubles as the reference implementation for a service offering: turnkey automated reference-media platforms for regulated niches. The transferable part is not the migration content, it is the frame — primary source to AI draft to human approval to publication, legally clean ingestion, a GDPR contour with isolated personal data, and a restore procedure that has actually been tested. The niche changes (compliance radars, grant radars, regulator recalls, sector alerts); the frame does not.