# Developer Abandoned Your App? Take Over the Project and Ship Again

DreamLabs is an AI-powered app development agency in California — a fractional product team for mobile and web apps, from strategy to launch.

Get your app back under your control and shipping again. If your developer has gone quiet, secure the code, store accounts, backend and domain in the first 72 hours, then audit before anyone writes new code. At DreamLabs, the full code audit runs as our two-week strategy sprint for a flat $4,000 and ends with a verdict: rescue, refactor or rebuild. Most builds take about 6 weeks after it.

By John Krueger and Tomás Quiñonez-Riegos. Updated October 8, 2026.

## Put everything your app runs on in your name

| What to secure | Where it should end up | Watch out for |
| --- | --- | --- |
| Source code | A repository in an organization your company owns, plus a backup clone | A build file isn't source code; transferred repos keep their deploy keys and secrets |
| Rights to the code | A signed assignment of code and designs to your company | US copyright transfers only in a signed writing |
| App Store | Your company's Apple Developer account, with your Account Holder | Only their Account Holder can start a transfer, and the app needs a released version |
| Google Play | Your company's Play Console account, with Play App Signing on | A lost upload key can be reset; an older app's self-managed signing key can't |
| Firebase or Supabase | Owner role on the Firebase project, or the Supabase project in your organization | Firebase Support acts only on Owners' admin requests; only the Supabase org owner can transfer |
| Keys and secrets | New keys for payments, AI, messaging, email and service accounts; old ones deleted | Removing a person doesn't revoke keys they copied |
| Domain | A registrar account in your company's name | Transfer first; changing registrant details first can block a move for 60 days |
| Designs and decisions | Figma files, specs, the backlog, an account list and the contracts | Ask now; the reasons behind the app are hard to recover later |

Platform rules checked October 8, 2026 against Apple, Google Play, Android, Firebase, Google Cloud, Supabase, Stripe, GitHub, ICANN and US Code sources linked in the guide below. General information, not legal advice.

## Frequently asked questions

### My developer disappeared. What should I do first?

Secure access before anything else: the code repository, the Apple and Google developer accounts, the Firebase or Supabase project, the domain and every API key. Move each into an account your company owns, then rotate the secrets the developer could have copied. Only then audit the code and decide whether to rescue, refactor or rebuild.

### Do I own the code my freelancer or agency wrote?

Generally, only if your contract assigns it to you or you get a signed assignment. Under US copyright law, copyright vests initially in the author, and a transfer of ownership is valid only in a signed writing. Ask for an assignment of the code and designs while the relationship still works. This is general information, not legal advice; talk to a lawyer about your contract.

### Can a new developer take over an existing codebase?

Yes, if the code builds from source and someone reads it end to end before changing it. Start with an audit, not a feature request, so the new team knows what works, what's broken and what's risky. If the code can't be built or its security model is wrong at the root, a rebuild that uses the live app as the specification can be the faster path.

### Should we fix the existing app or rebuild it?

Let the audit decide. Rescue when the code builds, the stack fits your roadmap and the problems are concentrated; refactor when one layer, such as the data model or authentication, makes every change slow; rebuild when the code can't be built, the security model is wrong at the root, the signing key is gone or the platform can't grow with you. A rebuild has to cost less over time than maintaining what you have.

### The app is published under my developer's Apple or Google account. Can I move it?

Usually, with their cooperation. Apple's app transfer keeps the app's reviews, ratings and bundle ID, but the current Account Holder has to start it and the app must have at least one version released on the App Store. On Google Play, the developer submits a transfer request to your developer account, and afterward your account can request a new upload key. Without their cooperation, plan to publish under a new listing in your own account.

### What if we don't have the Android signing key?

Apps created since August 2021 use Play App Signing, so Google holds the signing key and you can request an upload key reset. For an older app whose developer managed the signing key alone, a lost key can't be reset, and an update would have to ship under a new package name as a new app.

### How much does it cost to take over an app project?

The full code audit runs as our two-week strategy sprint for a flat $4,000, refunded in full if we don't move forward together. It ends with a written report, a verdict on rescue, refactor or rebuild, and the scope of the work. The build price is set and approved at the end of the sprint, and that's what you pay.

### How long does a takeover take?

Securing ownership can take about three days when the developer cooperates, though a domain registrar has up to five calendar days to issue a transfer code. The audit takes two weeks. After that, most builds take about 6 weeks.

## Own every key to your product again

This guide is for founders whose app is stuck: a freelancer who stopped answering, an agency that missed one deadline too many, a half-finished build nobody can explain. You can get it moving again. First, put everything the app runs on into accounts your company owns, within about three days if the developer cooperates. Then have the code audited before anyone writes more of it, and decide from the evidence whether to rescue, refactor or rebuild. At DreamLabs, the full code audit runs as our two-week strategy sprint for a flat $4,000, and most builds take about 6 weeks after it. Platform rules below were checked on October 8, 2026, and link to their sources. This is general information, not legal advice.

We've been on your side of this. In 2020, when Tomás and John needed a web app, a team of traditional developers told them the prototype would be ready within one month. Several months later it still wasn't complete, and it was well over budget. They built it themselves instead, and that's how DreamLabs started ([our story](https://www.dreamlabs.pro/about)).

### Hours 0 to 24: the code, and your right to use it

Get the repository into an organization your company owns, with admin rights. GitHub lets a repository admin [transfer it to a new owner](https://docs.github.com/en/repositories/creating-and-managing-repositories/transferring-a-repository). Check two things afterward: a repository moved between personal accounts brings its original owner and collaborators along as collaborators, and its webhooks, secrets and deploy keys stay attached. Remove anything you don't recognize, then keep a clone somewhere the previous developer can't reach. A build file or a TestFlight install is not the source code.

Then the paperwork. Under US copyright law, copyright [vests initially in the author](https://www.law.cornell.edu/uscode/text/17/201), and a transfer of ownership is [not valid unless it's in writing and signed](https://www.law.cornell.edu/uscode/text/17/204). If your contract doesn't assign the code and designs to your company, ask for a signed assignment now, while the relationship still works, and get legal advice before you build on code you don't clearly own.

### Hours 24 to 48: the store listings and signing keys

On Apple's side, the [Account Holder](https://developer.apple.com/help/account/access/roles/) renews the membership, accepts legal agreements, adds the first Admins and approves banking changes, so that role belongs to someone at your company. An organization's account also shows [the organization's name as the seller](https://developer.apple.com/programs/enroll/) on the App Store. If the app lives in the developer's account, an [app transfer](https://developer.apple.com/help/app-store-connect/transfer-an-app/overview-of-app-transfer) keeps its reviews, ratings and bundle ID and keeps updates flowing to users, but their Account Holder has to start it, and [the app must have at least one version released](https://developer.apple.com/help/app-store-connect/transfer-an-app/app-transfer-criteria) on the App Store. Keys for push notifications, Sign in with Apple and similar services can be [downloaded only once](https://developer.apple.com/help/account/keys/revoke-edit-and-download-keys), and revoking one breaks whatever uses it, so create the replacement, deploy it, then revoke the old key.

On Google Play, the developer submits a [transfer request](https://support.google.com/googleplay/android-developer/answer/6230247) to your developer account, and the app's users, ratings, reviews and store listing move with it. Android signing is where takeovers break. Apps created since August 2021 must use [Play App Signing](https://developer.android.com/studio/publish/app-signing), so Google holds the app signing key and a lost or compromised [upload key can be reset](https://support.google.com/googleplay/android-developer/answer/9842756); after a transfer, your account can request a new one. An older app whose developer managed the signing key alone is different: that key can't be reset, and an update signed with a different key has to ship under a new package name, as a new app.

### Hours 48 to 72: the backend, every key and the domain

For Firebase, someone at your company needs the [Owner role](https://firebase.google.com/docs/projects/iam/roles-basic): Owners manage access and billing, and Firebase Support can only fulfill administrative requests from demonstrated project Owners. Service accounts don't appear in the Firebase console's member list, so check the [IAM page in the Google Cloud console](https://firebase.google.com/docs/projects/iam/overview) as well. For Supabase, only an owner of the current organization can [transfer a project](https://supabase.com/docs/guides/platform/project-transfer) to an organization you belong to.

Removing someone's access doesn't revoke the keys they copied. Google Cloud says service account keys downloaded from IAM [stay valid until you delete them](https://cloud.google.com/iam/docs/best-practices-for-managing-service-account-keys). Supabase's procedure for a compromised key is to create a new secret key, replace it everywhere, confirm, then [delete the old one or deactivate the legacy keys](https://supabase.com/docs/guides/api/api-keys). Stripe lists a team member leaving as a reason to [rotate API keys](https://docs.stripe.com/keys), and keeps the old and new keys working for up to 7 days so nothing breaks mid-switch. Do the same for AI providers, text messaging, email and anything else that holds a secret.

Last, the domain. [ICANN Lookup](https://lookup.icann.org/) shows which registrar holds it. If the developer registered it, they request the transfer code, which, according to [ICANN's registrant FAQ](https://www.icann.org/resources/pages/name-holder-faqs-2017-10-10-en), the registrar must provide within five calendar days. The same FAQ notes that changing the registrant's name, organization or email can lock a domain against moving registrars for 60 days, so if you're moving registrars, transfer first and update the details after.

### Then audit, before anyone writes code

A new team that starts coding on day one is guessing. An audit reads the repository, the infrastructure and the running product side by side, because stalled projects hide their problems in the gaps: a build that only runs on one person's machine, a database rule loosened to make a screen load, a feature that's half there. We work read-only against a commit, every security finding comes with a reproduction, and the written report is one you could hand to any team, your own included. Our [code audit page](https://www.dreamlabs.pro/services/ai-generated-code-audit) lists everything we check, and our free [Firestore](https://www.dreamlabs.pro/services/firestore-security-rules-checklist) and [Supabase](https://www.dreamlabs.pro/services/supabase-rls-checklist) checklists let you test the database rules yourself today.

### Rescue, refactor or rebuild

The audit's job is to make this call with evidence. Here's how it usually breaks down.

- **Rescue: stabilize it and keep going.** The code builds from source, the stack fits your roadmap and the problems are concentrated: a few broken flows, missing tests, rules left open. Fix the critical issues, add the tests and checks that keep them fixed, and keep shipping on the same codebase.

- **Refactor: keep the product, replace the weak layer.** The app works, but one layer, such as the data model, authentication or state management, makes every change slow or risky. Rework that layer in place, behind tests, while releases continue.

- **Rebuild: keep the product, not the code.** The code can't be built from source, the security model is wrong at the root, the signing key is gone, or the platform can't take you where your roadmap goes. The live app becomes the specification, and your data, designs and store listings carry over wherever the platforms allow.

A rebuild has to earn itself: we weigh what maintaining the current code costs per quarter against what replacing it costs once. We've made that call on our own work. We used to build apps in FlutterFlow, switched to AI-accelerated development in Flutter, and have exported most of the apps we started in FlutterFlow. And when [Community Gearbox](https://www.dreamlabs.pro/project/community-gearbox)'s founder asked us to rebuild an early prototype so more people could use and test it, we narrowed the feature set to the key hypothesis he was testing and built a two-sided Flutter app in six weeks.

## When you don't need a takeover team

A takeover team is the right call when a project is truly stuck. Here's when you can save the money.

- **Your developer is slow, not gone.** Ask for repository access, account access and a written plan with dates first. Switching teams has its own ramp-up, and a cooperative developer makes every transfer above easier.

- **Your own engineers can read the code.** Hand them the checklist above and the outline on our [code audit page](https://www.dreamlabs.pro/services/ai-generated-code-audit). You may only need a second opinion on the hardest calls.

- **You need one well-defined fix.** A single bug, or a store rejection with a clear cause, is freelancer-sized work.

- **The app lives in a no-code or AI builder you can still edit.** You may be able to keep going yourself. When it hits the platform's ceiling, our [no-code migration](https://www.dreamlabs.pro/services/no-code-migration) and [AI prototype to production](https://www.dreamlabs.pro/services/ai-prototype-to-production) guides cover the move.

- **You're in a dispute over who owns the code.** Talk to a lawyer before anyone builds on it. An audit can't settle ownership.

- **The app is built on a stack we don't work in.** We build most apps in Flutter, work in Swift when native iOS is the right call, and build React, React Native and Next.js apps on Firebase or Supabase. For anything else, hire specialists in that stack.

## A second team that starts with the truth

DreamLabs is an AI-powered app development agency in California that works as a fractional product team, from strategy to launch. Tomás Quiñonez-Riegos leads product and John Krueger leads development ([meet the founders](https://www.dreamlabs.pro/about)). We build production apps with AI-accelerated development ourselves and test on real devices, which is how we know where an inherited codebase tends to break.

- **The truth first.** The audit's verdict comes with evidence: a reproduction for every security finding, and a rebuild recommendation only when the numbers support one.

- **One price, approved before the work.** The audit runs as the $4,000 two-week strategy sprint, refunded in full if we don't move forward together. The build price is set and approved at the end of it, and that's what you pay.

- **Everything in your name.** You own every line of code, every signing credential and every store account, on infrastructure under your own accounts.

- **Built to last past launch.** [Nurture](https://www.dreamlabs.pro/project/nurture)'s engagement began in late 2022; by August 2024 its app had reached 19 releases, and it still receives updates. [UNALTERED](https://www.dreamlabs.pro/project/unaltered) grew over three releases in 13 months. We maintain [Grove](https://www.dreamlabs.pro/project/grove), our own product, ourselves.

Zach Muñoz, co-founder of UNALTERED: “Often times, dealing with developers can feel shady, as a result of confusion and a lack of understanding of the development process. However, DreamLabs is always straightforward and honest about the work they do and the associated cost to do it.”

## Secure, audit, stabilize, then ship

### Secure ownership

In the first 72 hours, move the repository, store listings, backend projects and domain into accounts your company owns, get a signed assignment of the code, and rotate every secret the previous team could have copied.

### Audit as a strategy sprint

The full code audit runs as our two-week strategy sprint: $4,000 flat, refunded in full if we don't move forward together. We read the repository, the infrastructure and the running product read-only against a commit, and prove every security finding with a reproduction.

### Get a verdict and a price

You get a written report: what to fix this week, what belongs in this quarter, what is fine to leave alone, and whether to rescue, refactor or rebuild. The build price is set and approved at the end of the sprint, and that's what you pay.

### Stabilize

Close the critical issues first: security holes, crashes, broken builds. Then add the tests and CI checks that keep them closed, so the next change doesn't quietly undo the last fix.

### Improve, or rebuild

Ship the next release on solid ground; most builds take about 6 weeks. Then stay with us monthly, priced from your roadmap, or hand the product to your own team with documentation a new engineer can start from.

## Case studies

- [Community Gearbox](https://www.dreamlabs.pro/project/community-gearbox.md): Native mobile app
- [Nurture](https://www.dreamlabs.pro/project/nurture.md): Native Mobile App
- [UNALTERED](https://www.dreamlabs.pro/project/unaltered.md): AI-powered fitness app

## Free checklists

- [Firestore and Cloud Storage Security Rules Checklist](https://www.dreamlabs.pro/services/firestore-security-rules-checklist.md): 24 checks, each with a test and its source.
- [Supabase Row Level Security (RLS) Checklist](https://www.dreamlabs.pro/services/supabase-rls-checklist.md): 23 checks, each with a test and its source.

## Links

- Full page: https://www.dreamlabs.pro/services/take-over-an-app-project
- Offerings & pricing: https://www.dreamlabs.pro/offerings
- Contact: https://www.dreamlabs.pro/contact
