The Free Stack Behind My Apps: Vanilla JS, Supabase, and GitHub Pages

Two real apps, a shared budget and a collaborative road-trip planner, built on a stack that costs nothing to run and that AI tools handle really well. Here’s why it works for non-coders, and the one setting you can’t skip.

By Jared

·

·

3–4 minutes
Isometric illustration of a three-layer app stack: browser app, database, and cloud hosting

When you’re vibecoding, the tools you pick matter more than you’d think. Some stacks make the AI brilliant. Others turn every change into a fight with configuration files you don’t understand.

I’ve landed on a combination that has carried two real apps: Budget Nugget, a shared household budget my partner and I use every week, and Gathering, a collaborative road-trip planner with maps, pins, and a crew page. Both run on the same three pieces, and both cost nothing to host.

The three pieces

Vanilla JavaScript for the app itself. “Vanilla” just means plain JavaScript, HTML, and CSS, with no framework like React. That sounds old-fashioned, but it’s a huge advantage when you can’t read code well: there’s no build step, nothing to install, and when something breaks, the AI is looking at the actual code running in your browser rather than something generated from it.

Supabase for the database and logins. Supabase gives you a real database, user accounts, and live updates, with a free tier that’s plenty for personal apps. This is what lets two people see the same budget, or a whole group edit the same trip.

GitHub Pages for hosting. Push your files to a GitHub repository, flip on Pages, and your app has a public web address. No servers, no bills.

Why AI tools handle this stack so well

All three are extremely common, so AI models have seen enormous amounts of example code for them. Plain JavaScript also has fewer moving parts, which means fewer places for the AI to confidently get something wrong. When I ask for a feature in Gathering, like draggable map pins or color-coded markers by category, the AI can usually go straight to the right file and make the change.

It also means you can make big visual changes without rebuilding anything. Gathering went through a full redesign into a 1920s Art Deco grand-hotel look (emerald, gold, and terracotta, with Cinzel for the headings) in one long iterative session, just by describing the vibe and adjusting from there.

The one setting you cannot skip: Row Level Security

Here’s the part most beginner tutorials rush past. With this stack, your Supabase connection key lives in your JavaScript, which means anyone who opens your site can see it. That’s expected and fine, as long as Row Level Security (RLS) is turned on for your tables, with rules for who can read and write what.

Without RLS, anyone who finds that key can read or wipe your whole database. With it, the database itself enforces “you can only see your own household’s budget.” When you ask an AI to set up Supabase, explicitly ask it to enable RLS and write the policies, then ask it to explain in plain English what each policy allows.

Other things I’d tell a beginner

Lock down any API keys that aren’t meant to be public. Gathering uses Google Maps, and that key also sits in the page. Restrict it in the Google Cloud console so it only works on your own site’s address.

Make it installable. Budget Nugget is a PWA (progressive web app), which means it can be added to a phone’s home screen and behave like a regular app. Ask the AI to “make this an installable PWA” once the basics work.

Know the free-tier limits. Check Supabase’s current free-tier rules, since free projects can be paused after a stretch of inactivity. For an app you use weekly, it’s rarely an issue.

When to reach for something else

This stack is ideal for personal and small-group apps. If you’re building something for lots of paying customers, handling sensitive data, or needing work done on a server (like sending scheduled emails), you’ll eventually outgrow it. For the vast majority of “I wish I had an app that…” ideas, though, it’s all you need.

About the author

Jared works in IT and operations, can’t code from scratch, and builds real software anyway by working with AI. More about me →

Leave a comment