AI apps that survive real users
Lovable, v0, Cursor and Replit will get you a working demo in an afternoon. Getting from there to something you can safely charge people for is a different job — and it's the one I do.
Free, no sign-up. Only looks at pages your visitors can already see.
And here's one of the tools I built, running. No account, nothing to install.
The reply appears here — written live, not a canned example.
This site is the portfolio
Not a case study about work done somewhere else. The thing you are reading is the thing I built, and you have already used part of it.
- tools shipped
- 10tools shipped
- automated tests passing
- 284automated tests passing
- database tables
- 11database tables
- secrets in the browser
- 0secrets in the browser
Authentication, done on the server
Sessions with NextAuth, passwords hashed, email verification before first login, and separate user and admin roles. Every permission decision is made server-side from the database — never from anything the browser sends.
Usage metered so it cannot overspend
Each account's monthly allowance is claimed with a single conditional database update, which Postgres applies atomically. Requests arriving at the same instant serialise on that row, so the limit holds under concurrency instead of being overshot.
An AI layer that fails properly
Provider-agnostic, called over plain HTTP with a hard timeout, one retry on unusable output, and errors sorted into credential, transient and permanent. A failed generation refunds the allowance it claimed, and the provider's own message goes to the log, never to the visitor.
A schema meant to be changed
Postgres via Prisma: 11 tables, 8 foreign keys, 27 indexes and a unique constraint that makes the usage counter safe. Every change ships as a migration, so nothing is lost when the shape of the data moves.
Deployed, not demonstrated
Running on a real host under its own domain over HTTPS, with environment variables held server-side, social preview images, a sitemap, and privacy and terms pages that describe what the system actually does with data.
The other 9 tools
Each one is a complete feature — its own form, validation, prompt, output checking and export. Open any of them to see what it does.
Content
Product Description Generator
Turn a product name and a few features into sales-ready copy.
Customer Support
WhatsApp Reply Generator
Answer customer messages quickly, in the right tone.
Finance
Invoice Maker
Build professional invoices and download them as PDF.
Marketing
Social Media Content Generator
Write posts, captions and hashtags tailored to each platform.
Business
QR Menu Maker
Build a scannable digital menu for your restaurant.
Design
Image Background Remover
Remove plain backgrounds from product photos in your browser.
Ecommerce
Product Title Generator
Create clear, attractive and SEO-friendly product titles for your online store.
Marketing / SEO
SEO Meta Generator
Write meta titles and descriptions that fit and rank.
Branding
Business Name Generator
Brainstorm brandable business names in seconds.
Finance
PDF/Document Generator
Turn structured content into polished PDF documents.
Your AI-built app works in the demo
That is the easy part, and the tools are good at it. What they leave out is everything that stands between a demo and a product people pay for.
Authentication that only looks real
Sessions that can be forged, routes that check permissions in the browser instead of on the server, admin pages one URL guess away.
No limit on what a user can spend
Every AI call costs you money. Without a per-user cap enforced in the database, one visitor with a script can run up a bill overnight.
API keys shipped to the browser
If the key reaches the client bundle it is public, whatever the variable is called. Anyone who opens developer tools has it.
Works on your laptop, nowhere else
No build pipeline, no environment configuration, no domain, no HTTPS. A demo is not a deployment.
You hear about failures from customers
No error tracking, no logs worth reading, no timeout on calls that can hang forever and quietly hold a connection open.
A schema that loses data when it changes
No migrations, no indexes, no constraints. It holds until the first real change, then it doesn't.
Three ways to work together
Fixed prices, agreed before anything starts. No hourly billing, no surprises.
Audit
Find out what's actually wrong before spending anything on fixing it.
Turnaround · 2 working days
- Full review of your codebase and deployment
- Written report: what breaks, what's exposed, what it risks
- Every issue ranked by what it costs you if ignored
- A fixed quote for the repair — no obligation to take it
Production Fix
Most asked forTake a working prototype and make it safe to put customers on.
Turnaround · about 1 week
- Server-side authentication and access control
- Per-user usage limits enforced in the database
- Database schema, migrations and indexes
- Deployed to a real host, on your domain, over HTTPS
- Error tracking, timeouts and sane failure messages
- Secrets moved out of anywhere the browser can reach
Full Build
An idea to a live product, built the way this site was built.
Turnaround · 3–4 weeks
- Everything in Production Fix, from the first commit
- AI features wired to a real provider, with retries and fallbacks
- Admin dashboard so you can see what users are doing
- Legal pages, SEO and social previews
- Handed over with the code, the accounts and the documentation
Starting out, and honest about it. The first three clients pay half, in exchange for a review I can publish — good or bad. You get the work at cost; I get the one thing I can't build for myself.