Founders · October 8, 2026 · 4 min read

Who owns your app? The accounts and code founders must control

Many founders believe they own their app because they paid for it. In practice, ownership is decided by something much more mundane: whose name is on each account. If a developer, agency or former co-founder holds the logins, they control your product, whatever the invoice says.

This is easy to fix while everyone is friendly and painful to fix after a falling-out. Here's what to check and how to set it up properly.

The accounts that matter

Every app depends on a chain of services. You need owner-level access to each one, ideally created with a company email address rather than a personal one.

  1. Domain registrar: whoever controls the domain controls your website, your email and your login links.
  2. DNS provider, if it's separate from the registrar, such as Cloudflare.
  3. Code repository: GitHub, GitLab or similar. This is the product itself.
  4. Hosting: Vercel, Netlify, Render, a cloud provider, or the app builder's own hosting.
  5. Database and backend: Supabase, Firebase, or a managed database.
  6. Payments: Stripe or your payment provider, where the money and customer records live.
  7. Email sending, analytics, error tracking and any AI or API providers with billing attached.
  8. App store accounts, if you have a mobile app. Apple and Google developer accounts should be in the company's name.
  9. The app builder itself, if you use Lovable, Bolt, Replit or similar.

What "owning" actually means

Having a login isn't enough. For each service, check three things:

  • You are the owner or top-level admin, not an invited member who can be removed.
  • The billing is on a payment method you control, so it can't lapse when someone else's card expires.
  • Recovery goes to you: the account email and two-factor authentication are tied to your company, not to a contractor's phone.

For code, there's one more layer. Your contract should state that the intellectual property in the work transfers to your company. Ask a lawyer to check the wording in your agreements, because accounts give you practical control while contracts give you legal ownership. You want both.

A one-hour ownership audit

Make a simple spreadsheet with one row per service and these columns: service, what it's used for, account owner, login email, who else has access, billing method, and whether two-factor is on.

  1. List every service. Check your bank and card statements for software subscriptions, and ask your developer for a full list.
  2. Log in to each one yourself. If you can't, that's your first finding.
  3. Look at the members or team page and note every person with access.
  4. Check the billing page and the account owner field.
  5. Store every credential in a password manager owned by the company.

Setting it up right from the start

  • Create accounts yourself, under a company email such as admin@ or tech@ your domain, and invite developers as members.
  • Use organizations or teams, not personal accounts. GitHub organizations, Vercel teams and Supabase organizations all support this.
  • Give each person their own login. Shared passwords can't be revoked from one person without breaking everyone.
  • Grant the least access that lets someone do their job. Not everyone needs billing or owner rights.
  • Keep at least two owners on critical accounts, so losing one person never locks you out.

Fixing it when someone else holds the keys

If you find accounts in a developer's name, raise it calmly and early. Most transfers are routine. Ask them to either transfer ownership or add you as an owner, depending on what the service supports.

  • GitHub repositories can be transferred to your organization, keeping the full history.
  • Domains can be moved to a registrar account you own, or pushed to your account within the same registrar.
  • Hosting and database projects can usually be transferred between organizations from the project settings.
  • Stripe accounts are harder to move, so make sure you are the account owner rather than migrating.

After each transfer, remove access you don't need any more and rotate any API keys or secrets that the previous owner could have copied. Do this in a planned order so the app keeps running throughout.

Deeraf can run this audit as part of On Call: we map every account, confirm the company holds the keys, and set up access so people can join and leave without risk.

Keep reading

Want a second pair of eyes on your app?

Book a Tech Check