Case study · AI-built app
An AI-built consumer app goes from prototype to production in a week
- 1,000+commits across two separate repositories
- 30findings from a one-day review
- 27closed within 48 hours
- Day 8switched to production
the situation
The web app and the iPhone app lived in separate repositories with no shared checks. Both used one hosted backend, and there was no practice copy of it. Development builds of the phone app used production by default, so testing touched real accounts.
The app handled personal data about its users and paid for an AI call every time it generated content. In both areas a quiet mistake becomes a privacy problem or a surprise bill.
Stack
- Web
- TanStack Start
- Mobile
- Expo and React Native, iPhone
- Backend
- Convex, with Convex Auth
- AI
- LLM-generated content
- Built with
- Claude Code
what we did
Intake
Wrote down what the app does, who uses it, and what worried the founder. Read the project's instructions and scripts before running anything.
One workspace, one set of checks
Combined both repositories into one and kept the full history of each. Pinned tool versions so every machine builds the same way. Ten automated checks run locally and on every pull request.
The review
30 findings across web, mobile, backend and AI, each ranked and filed as an issue. Each one says how it was verified, so the founder knew which were confirmed and which needed another look.
Guardrails for AI-assisted work
Wrote the instructions and checks the founder's AI assistants read on every task: which environment is safe to use, what must not change for apps people already installed, and when a change needs tests.
Fixes, mostly by the founder
With the issues filed and the guardrails in place, the founder worked through the list with their own AI tools. I reviewed changes and brought over unfinished work from their old branches.
Production switch
The combined workspace became the source of the live app.
what the review found
3 High, 14 Medium and 13 Low. A selection, with what changed:
- Mobile app development builds used the production databaseNow they default to a practice backend with sample dataHigh
- The automated test robot changed production dataIt now runs only against the practice backendHigh
- A personal email address was committed in a build scriptRemoved, and secrets moved to encrypted filesHigh
- AI spending was capped per account, with no overall limitPer-user limits plus a daily ceiling for the whole appMedium
- AI output was saved unchecked, and a failure could leave half-saved recordsOutput is validated, and each save completes fully or not at allMedium
- Sign-in links were stored in plaintext and sent in the URLStored as a hash and kept out of the address barMedium
- Removing a device left its server access in placeIt revokes it nowMedium
- One account's failed attempts could lock out other accountsLimits now apply per callerMedium
- Actions taken offline were dropped on any errorQueued taps now survive errors and replayMedium
in place now
- A practice backend, with a fresh copy for each pull request
- Preview websites for changes before they go live
- Encrypted secrets stored alongside the code
- Founder approval required for backend, AI, privacy and app store changes
- Limits that stop files and functions from growing more complex
- In-app problem reports, with optional details attached
still in progress
- Automatic production releases when a change merges
- A full review of who can see each account's data
- Measuring the quality of AI-generated content over time
- Testing on every supported device
The founder fixed most of it with their own AI tools
The review showed what mattered, and the guardrails kept the fixes from breaking anything else.