You Built It in Lovable or Bolt. What Does It Take to Launch for Real?

An AI builder gets you a working app in a weekend. Paying users need more than that. Here is what usually has to be fixed, what you can keep, and what the work costs.

· 5 min read
You Built It in Lovable or Bolt. What Does It Take to Launch for Real?

You described an app to Lovable, Bolt or Base44, and two days later you had one. It has screens, a login page, maybe a Stripe button. Friends tried it and said nice things. Now a real customer wants to sign up, and you've got a bad feeling about it.

That feeling is usually right, and it's fixable. We keep seeing the same request on Upwork: "finish my Lovable app", "connect a backend to my Base44 MVP", one of them with $5,000 attached. This post is what we'd tell those founders before they hire anyone.

What you actually have

You have a prototype that works on the happy path. One user, clean data, nobody trying to break anything. That's worth a lot. You proved the idea can be shown and clicked, and you did it for the price of a subscription.

What you don't have yet is the dull part. Who is allowed to see which data. What happens when a payment fails halfway. Where the backups are. An AI builder won't raise these questions, because you didn't ask and the demo runs fine without them.

Where these apps break

Data that anyone can read. In 2025 a flaw registered as CVE-2025-48757 turned up in apps generated by Lovable. The database rules that decide who sees what were missing, and researchers counted more than 170 live apps where a stranger could pull users' emails, phone numbers and payment details. The founders hadn't done anything unusual. They shipped what the tool gave them. Lovable disputes the report and says each customer is responsible for protecting their own app's data. That's the part to remember: the responsibility is yours.

It isn't one tool's problem either. Veracode ran 80 coding tasks through more than 100 AI models and found a security flaw in 45% of the results.

Logins. Sign-up works. Password reset, email confirmation and "this account already exists" often don't. Roles are the bigger risk. If your app has customers and admins, check whether a customer can open an admin page by typing its address.

Payments. The button charges a card. The app then has to learn that the charge went through, and that message can arrive late, arrive twice or never arrive. Prototypes tend to trust the browser instead, so a refund or a failed renewal leaves the account in the wrong state.

Keys in the wrong place. Secret keys for Stripe, email or an AI service sometimes sit in code that every visitor's browser downloads. Anyone can copy them and spend your money.

No safety net. No backups, no error alerts, no second copy of the app to test changes on. You find out something broke when a customer writes to you.

Code nobody can change. After fifty prompts the app has three versions of the same form and logic copied between screens. Each new prompt fixes one thing and breaks another. This is usually the moment founders start looking for a developer.

What you can keep

What to keep, fix and rebuild in an AI-built prototype

More than you'd think. Nobody should charge you to start again from a blank page without a reason.

  • Keep the screens and the flow. You've already tested them on real people, and they're the cheapest part to carry over.
  • Fix the data rules, logins, payment handling and where the secret keys live. This is most of the work.
  • Rebuild only what can't be repaired. If the data is laid out in a way that can't grow, or the tool won't let you take the code out, that piece gets written again.

One question settles a lot: can you export the code and move the database to an account you own? If yes, a developer can work on what exists. If the app only runs inside the builder, you're renting it.

What it costs

One published breakdown puts a focused "production lift" at $5,000 to $30,000 and an agency rebuild at $25,000 and up. The spread comes from how much has to be rewritten.

Here is how we'd estimate it at our rate of $40 an hour:

  • Audit, 8 to 12 hours, $320 to $480. A developer reads the code, tries to break it, and gives you a list sorted by risk. Do this first whatever you decide afterwards.
  • Hardening, 60 to 120 hours, $2,400 to $4,800. Data rules, logins and roles, payment confirmations, keys moved to the server, backups, error alerts, hosting on accounts you own.
  • Partial rebuild, 150 to 250 hours, $6,000 to $10,000. The screens stay, the back end is written properly. This is the usual outcome for marketplaces and anything with subscriptions.

A full rebuild costs about the same as building the MVP from scratch, and you can price that with the calculator below.

When to do nothing yet

If nobody pays you and you don't store anything personal, leave it alone. Keep showing the prototype, keep changing it, and spend the money on finding users.

The line is simple. The day you take a payment or someone's personal data, the app is a product, and the list above stops being optional.

Three checks you can run today

  1. Open the app in a private window, without logging in, and paste the address of a page that should be private. If it loads, your data rules need work.
  2. Create two accounts. From the first, try to open an order, profile or file that belongs to the second.
  3. Ask the builder where your secret keys are stored and whether you can export the code. Save the answer.

If any of the three worries you, send us the link. We'll tell you whether it needs an audit, a few fixes or a rebuild, and what each would cost.

  • #ai app builders
  • #lovable
  • #bolt
  • #mvp
  • #startups
  • #production
Planning a product?

See what your first version would cost

Pick the features you need and get a price range and timeline in under a minute. No call, no sign-up.

Open the MVP calculator