Doug Borg

Case study · AI-built app

An AI-built consumer app goes from prototype to production in a week

A solo founder built a consumer app almost entirely with Claude Code: a web app, an iPhone app, and AI features that generate content for each user. It worked and looked great, and real users were about to start signing up.

  • 1,000+commits across two separate repositories
  • 30findings from a one-day review
  • 27closed within 48 hours
  • Day 8switched to production

the situation

The web app and the iPhone app lived in separate repositories with no shared checks. Both used one hosted backend, and there was no practice copy of it. Development builds of the phone app used production by default, so testing touched real accounts.

The app handled personal data about its users and paid for an AI call every time it generated content. In both areas a quiet mistake becomes a privacy problem or a surprise bill.

Stack

Web
TanStack Start
Mobile
Expo and React Native, iPhone
Backend
Convex, with Convex Auth
AI
LLM-generated content
Built with
Claude Code

what we did

  1. Intake

    Day 1

    Wrote down what the app does, who uses it, and what worried the founder. Read the project's instructions and scripts before running anything.

  2. One workspace, one set of checks

    Day 7

    Combined both repositories into one and kept the full history of each. Pinned tool versions so every machine builds the same way. Ten automated checks run locally and on every pull request.

  3. The review

    Day 7

    30 findings across web, mobile, backend and AI, each ranked and filed as an issue. Each one says how it was verified, so the founder knew which were confirmed and which needed another look.

  4. Guardrails for AI-assisted work

    Day 7

    Wrote the instructions and checks the founder's AI assistants read on every task: which environment is safe to use, what must not change for apps people already installed, and when a change needs tests.

  5. Fixes, mostly by the founder

    Days 7–9

    With the issues filed and the guardrails in place, the founder worked through the list with their own AI tools. I reviewed changes and brought over unfinished work from their old branches.

  6. Production switch

    Day 8

    The combined workspace became the source of the live app.

what the review found

3 High, 14 Medium and 13 Low. A selection, with what changed:

  • Mobile app development builds used the production databaseNow they default to a practice backend with sample data
    High
  • The automated test robot changed production dataIt now runs only against the practice backend
    High
  • A personal email address was committed in a build scriptRemoved, and secrets moved to encrypted files
    High
  • AI spending was capped per account, with no overall limitPer-user limits plus a daily ceiling for the whole app
    Medium
  • AI output was saved unchecked, and a failure could leave half-saved recordsOutput is validated, and each save completes fully or not at all
    Medium
  • Sign-in links were stored in plaintext and sent in the URLStored as a hash and kept out of the address bar
    Medium
  • Removing a device left its server access in placeIt revokes it now
    Medium
  • One account's failed attempts could lock out other accountsLimits now apply per caller
    Medium
  • Actions taken offline were dropped on any errorQueued taps now survive errors and replay
    Medium

in place now

  • A practice backend, with a fresh copy for each pull request
  • Preview websites for changes before they go live
  • Encrypted secrets stored alongside the code
  • Founder approval required for backend, AI, privacy and app store changes
  • Limits that stop files and functions from growing more complex
  • In-app problem reports, with optional details attached

still in progress

  • Automatic production releases when a change merges
  • A full review of who can see each account's data
  • Measuring the quality of AI-generated content over time
  • Testing on every supported device

The founder fixed most of it with their own AI tools

The review showed what mattered, and the guardrails kept the fixes from breaking anything else.