[Takeover guide]
Get your app back under your control and shipping again. If your developer has gone quiet, secure the code, store accounts, backend and domain in the first 72 hours, then audit before anyone writes new code. At DreamLabs, the full code audit runs as our two-week strategy sprint for a flat $4,000 and ends with a verdict: rescue, refactor or rebuild. Most builds take about 6 weeks after it.
Start with a code audit[First 72 hours]
| What to secure | Where it should end up | Watch out for |
|---|---|---|
| Source code | A repository in an organization your company owns, plus a backup clone | A build file isn't source code; transferred repos keep their deploy keys and secrets |
| Rights to the code | A signed assignment of code and designs to your company | US copyright transfers only in a signed writing |
| App Store | Your company's Apple Developer account, with your Account Holder | Only their Account Holder can start a transfer, and the app needs a released version |
| Google Play | Your company's Play Console account, with Play App Signing on | A lost upload key can be reset; an older app's self-managed signing key can't |
| Firebase or Supabase | Owner role on the Firebase project, or the Supabase project in your organization | Firebase Support acts only on Owners' admin requests; only the Supabase org owner can transfer |
| Keys and secrets | New keys for payments, AI, messaging, email and service accounts; old ones deleted | Removing a person doesn't revoke keys they copied |
| Domain | A registrar account in your company's name | Transfer first; changing registrant details first can block a move for 60 days |
| Designs and decisions | Figma files, specs, the backlog, an account list and the contracts | Ask now; the reasons behind the app are hard to recover later |
[Take back control]
This guide is for founders whose app is stuck: a freelancer who stopped answering, an agency that missed one deadline too many, a half-finished build nobody can explain. You can get it moving again. First, put everything the app runs on into accounts your company owns, within about three days if the developer cooperates. Then have the code audited before anyone writes more of it, and decide from the evidence whether to rescue, refactor or rebuild. At DreamLabs, the full code audit runs as our two-week strategy sprint for a flat $4,000, and most builds take about 6 weeks after it. Platform rules below were checked on October 8, 2026, and link to their sources. This is general information, not legal advice.
We've been on your side of this. In 2020, when Tomás and John needed a web app, a team of traditional developers told them the prototype would be ready within one month. Several months later it still wasn't complete, and it was well over budget. They built it themselves instead, and that's how DreamLabs started (our story).
Get the repository into an organization your company owns, with admin rights. GitHub lets a repository admin transfer it to a new owner. Check two things afterward: a repository moved between personal accounts brings its original owner and collaborators along as collaborators, and its webhooks, secrets and deploy keys stay attached. Remove anything you don't recognize, then keep a clone somewhere the previous developer can't reach. A build file or a TestFlight install is not the source code.
Then the paperwork. Under US copyright law, copyright vests initially in the author, and a transfer of ownership is not valid unless it's in writing and signed. If your contract doesn't assign the code and designs to your company, ask for a signed assignment now, while the relationship still works, and get legal advice before you build on code you don't clearly own.
On Apple's side, the Account Holder renews the membership, accepts legal agreements, adds the first Admins and approves banking changes, so that role belongs to someone at your company. An organization's account also shows the organization's name as the seller on the App Store. If the app lives in the developer's account, an app transfer keeps its reviews, ratings and bundle ID and keeps updates flowing to users, but their Account Holder has to start it, and the app must have at least one version released on the App Store. Keys for push notifications, Sign in with Apple and similar services can be downloaded only once, and revoking one breaks whatever uses it, so create the replacement, deploy it, then revoke the old key.
On Google Play, the developer submits a transfer request to your developer account, and the app's users, ratings, reviews and store listing move with it. Android signing is where takeovers break. Apps created since August 2021 must use Play App Signing, so Google holds the app signing key and a lost or compromised upload key can be reset; after a transfer, your account can request a new one. An older app whose developer managed the signing key alone is different: that key can't be reset, and an update signed with a different key has to ship under a new package name, as a new app.
For Firebase, someone at your company needs the Owner role: Owners manage access and billing, and Firebase Support can only fulfill administrative requests from demonstrated project Owners. Service accounts don't appear in the Firebase console's member list, so check the IAM page in the Google Cloud console as well. For Supabase, only an owner of the current organization can transfer a project to an organization you belong to.
Removing someone's access doesn't revoke the keys they copied. Google Cloud says service account keys downloaded from IAM stay valid until you delete them. Supabase's procedure for a compromised key is to create a new secret key, replace it everywhere, confirm, then delete the old one or deactivate the legacy keys. Stripe lists a team member leaving as a reason to rotate API keys, and keeps the old and new keys working for up to 7 days so nothing breaks mid-switch. Do the same for AI providers, text messaging, email and anything else that holds a secret.
Last, the domain. ICANN Lookup shows which registrar holds it. If the developer registered it, they request the transfer code, which, according to ICANN's registrant FAQ, the registrar must provide within five calendar days. The same FAQ notes that changing the registrant's name, organization or email can lock a domain against moving registrars for 60 days, so if you're moving registrars, transfer first and update the details after.
A new team that starts coding on day one is guessing. An audit reads the repository, the infrastructure and the running product side by side, because stalled projects hide their problems in the gaps: a build that only runs on one person's machine, a database rule loosened to make a screen load, a feature that's half there. We work read-only against a commit, every security finding comes with a reproduction, and the written report is one you could hand to any team, your own included. Our code audit page lists everything we check, and our free Firestore and Supabase checklists let you test the database rules yourself today.
The audit's job is to make this call with evidence. Here's how it usually breaks down.
A rebuild has to earn itself: we weigh what maintaining the current code costs per quarter against what replacing it costs once. We've made that call on our own work. We used to build apps in FlutterFlow, switched to AI-accelerated development in Flutter, and have exported most of the apps we started in FlutterFlow. And when Community Gearbox's founder asked us to rebuild an early prototype so more people could use and test it, we narrowed the feature set to the key hypothesis he was testing and built a two-sided Flutter app in six weeks.
[How it works]
[01]
In the first 72 hours, move the repository, store listings, backend projects and domain into accounts your company owns, get a signed assignment of the code, and rotate every secret the previous team could have copied.
[02]
The full code audit runs as our two-week strategy sprint: $4,000 flat, refunded in full if we don't move forward together. We read the repository, the infrastructure and the running product read-only against a commit, and prove every security finding with a reproduction.
[03]
You get a written report: what to fix this week, what belongs in this quarter, what is fine to leave alone, and whether to rescue, refactor or rebuild. The build price is set and approved at the end of the sprint, and that's what you pay.
[04]
Close the critical issues first: security holes, crashes, broken builds. Then add the tests and CI checks that keep them closed, so the next change doesn't quietly undo the last fix.
[05]
Ship the next release on solid ground; most builds take about 6 weeks. Then stay with us monthly, priced from your roadmap, or hand the product to your own team with documentation a new engineer can start from.
[Where we fit]
DreamLabs is an AI-powered app development agency in California that works as a fractional product team, from strategy to launch. Tomás Quiñonez-Riegos leads product and John Krueger leads development (meet the founders). We build production apps with AI-accelerated development ourselves and test on real devices, which is how we know where an inherited codebase tends to break.
Zach Muñoz, co-founder of UNALTERED: “Often times, dealing with developers can feel shady, as a result of confusion and a lack of understanding of the development process. However, DreamLabs is always straightforward and honest about the work they do and the associated cost to do it.”
[Decision guides]
Already built a prototype with Lovable, Bolt, or Replit? See AI prototype to production →
[FAQs]
Secure access before anything else: the code repository, the Apple and Google developer accounts, the Firebase or Supabase project, the domain and every API key. Move each into an account your company owns, then rotate the secrets the developer could have copied. Only then audit the code and decide whether to rescue, refactor or rebuild.
Generally, only if your contract assigns it to you or you get a signed assignment. Under US copyright law, copyright vests initially in the author, and a transfer of ownership is valid only in a signed writing. Ask for an assignment of the code and designs while the relationship still works. This is general information, not legal advice; talk to a lawyer about your contract.
Yes, if the code builds from source and someone reads it end to end before changing it. Start with an audit, not a feature request, so the new team knows what works, what's broken and what's risky. If the code can't be built or its security model is wrong at the root, a rebuild that uses the live app as the specification can be the faster path.
Let the audit decide. Rescue when the code builds, the stack fits your roadmap and the problems are concentrated; refactor when one layer, such as the data model or authentication, makes every change slow; rebuild when the code can't be built, the security model is wrong at the root, the signing key is gone or the platform can't grow with you. A rebuild has to cost less over time than maintaining what you have.
Usually, with their cooperation. Apple's app transfer keeps the app's reviews, ratings and bundle ID, but the current Account Holder has to start it and the app must have at least one version released on the App Store. On Google Play, the developer submits a transfer request to your developer account, and afterward your account can request a new upload key. Without their cooperation, plan to publish under a new listing in your own account.
Apps created since August 2021 use Play App Signing, so Google holds the signing key and you can request an upload key reset. For an older app whose developer managed the signing key alone, a lost key can't be reset, and an update would have to ship under a new package name as a new app.
The full code audit runs as our two-week strategy sprint for a flat $4,000, refunded in full if we don't move forward together. It ends with a written report, a verdict on rescue, refactor or rebuild, and the scope of the work. The build price is set and approved at the end of the sprint, and that's what you pay.
Securing ownership can take about three days when the developer cooperates, though a domain registrar has up to five calendar days to issue a transfer code. The audit takes two weeks. After that, most builds take about 6 weeks.
[Interested?]