Skip to content

Frankfurt am Main2026

Software that speaks human.

Hexese is the software studio of Aaron Kuyucu in Frankfurt am Main. It builds apps, servers and websites for businesses and people who spend more time on forms and deadlines than on their actual work.

Hexese starts trading on 1 September 2026. One person, as a side business.

NASA Black Marble 2016 · public domain

Measured — after every build

0third-party requests on loadNo image, no font, no script from a third-party server. scripts/csp-hashes.mjs checks after every build — if it finds one, nothing goes live.
257glyphs in the single font fileOutfit, trimmed to the characters actually used: 257 of 416. Recorded in public/schriften/HERKUNFT.txt.
36,744 Bsize of the single font fileOne file, from this server: public/schriften/outfit-var-latin.woff2. No second font, no font service.
8security headers from the serverHSTS, Content-Security-Policy, X-Content-Type-Options, X-Frame-Options, Referrer-Policy, Permissions-Policy and two Cross-Origin lines. Count them in public/.htaccess.
12rules in the content security policyNothing is allowed to begin with. Every exception is listed and justified — most recently the film above, served from here. This page cannot send anything on its own.
3npm dependencies at build timenext, react and react-dom — count them in package.json. None of it reaches the visitor: the React bundle is stripped after the build.

01Services

What gets built here.

Six kinds of work. Each of them sits finished in at least one of the projects below. Nothing on this list is an intention.

Apps for the phone

One codebase, both platforms (React Native). Camera and file import, accounts, payment handling, states for a poor connection. So far only the iPhone build has been run.

amtsorakel/src/ — about 8,000 lines of TypeScript/TSXNo store account, no installable build.

Server and database

Postgres with access rules per row. Counters that stay correct even under simultaneous requests. Webhooks from other providers may arrive twice and out of order without doing damage.

supabase/migrations/0001–0006, in particular 0003 and 0005No second environment, no Terraform, no Kubernetes.

Connecting language models

Answers in enforced JSON, checked field by field, instead of free text. Cost ceilings, time limits, retries only where they help — and a measuring setup of my own that compares every change against the previous state.

supabase/functions/analyze-letter/index.ts, 786 lines · scripts/eval/, 717 lines

Websites without third-party calls

Static pages that load nothing when opened: their own typeface from their own server, security headers, fully usable without JavaScript. This page is one of them — the figures above prove it.

scripts/schrift-bauen.py · public/.htaccess in every built site

Promises that get measured

For every promise a check script that measures the built result rather than the source. If it finds a breach, nothing goes online. What cannot be measured is not promised — that is the more uncomfortable half of the rule.

scripts/messwerte.mjs · scripts/csp-hashes.mjs · aufmass/…/pruefen.shNo automated test suite. Measurement happens on the built result.

Data protection while building

Deletion that really deletes. Servers located in Germany. As little data as possible, from the first migration on — which column never exists at all is the one question that cannot be reopened later.

supabase/functions/delete-account/index.ts · RLS in migration 0001Implementation, not legal advice. Auditing myself qualifies me for no one else.

02Projects

What is being worked on.

In order of maturity. The tag next to each says where it really stands.

Amtsorakel

Built

An app for the phone. You photograph a letter from a public authority, the app gives it back in plain German, records the deadlines named in the letter and reminds you of them in time.

Product page: amtsorakel.de
Who for
Private individuals who receive German official mail and have to read it twice.
Status
App, server and analysis are built. The analysis runs exclusively on the server in Stockholm, and the account can be deleted completely. Amtsorakel gives no legal advice and decides nothing.

Foto-Aufmaß

Draft

Photos of a building site are meant to become a set of measurements — instead of a notepad, a folding rule and an hour of typing them up in the evening.

Who for
Trade businesses that take measurements by hand and enter them in the office later.
Status
A test page with a calculator exists, built without a single line of JavaScript. The product will be built only once enough businesses confirm that they need it.

What comes next

Hexese builds tools for work in which forms, deadlines and paper hold up the actual work. Which one comes next is decided by whoever has the problem. If you know of one: write to me.

Around the world every ninety minutes. An official letter takes longer to reach you — and you usually take even longer to find your way back.

ISS, 22 June 2025 · NASA · public domain

03Person

Who is behind this.

My name is Aaron Kuyucu. I am a student, and I write the software of Hexese myself — every line, from the database to this page. Hexese is a sole proprietorship in Frankfurt am Main, registered as a side business on 20 August 2026, starting work on 1 September 2026.

I build tools for procedures I know myself: a letter you read four times and still do not know whether anything needs doing. A set of measurements that still has to be typed up in the evening. Neither is an accident or carelessness; both are built in. That cannot be changed from the inside. Building tools for it can.

04Questions

What people ask.

What does Hexese do?

Apps for the phone, servers and websites — for businesses and people who spend more time on forms and deadlines than on their actual work.

Who is behind it?

Aaron Kuyucu. Hexese is a sole proprietorship in Frankfurt am Main, run part-time, in business since 1 September 2026. Every line of software comes from one person.

How does an enquiry work?

An email to info@hexese.com is enough: what you have in mind, in two or three sentences. Follow-up questions come by email, usually within a few working days. No form, no call-back slot, no sales pitch.

What is it built with?

React Native and Expo for apps, Supabase with Postgres for server and database, TypeScript throughout, Next.js for websites like this one. Each project lists the file path where it lives.

Are there references?

No clients yet — Hexese is new. What exists is finished work you can measure me by: Amtsorakel, further up this page.

What happens to my data on this website?

Nothing. No cookies, no analytics, nothing from third-party servers. The figure “0 third-party requests” above is recomputed after every build. The rest is in the privacy policy.

05Contact

Just write.

A plan, an enquiry, a procedure in your business that eats too much time — or a note about this page. An email is enough. I read every one.

Frankfurt am MainUsually an answer within a few working days

info@hexese.com

Built with

  • React Native
  • Expo
  • TypeScript
  • Supabase
  • PostgreSQL
  • Next.js
  • Apple
  • Android
  • Node.js
  • GitHub
  • RevenueCat
  • PostHog
  • Sentry
  • Figma
  • WebGL