DEV Community

Cover image for I vibe-coded a mental health app in 5 weeks. Getting it ready for real users took 3 months
Devin Smith
Devin Smith

Posted on

I vibe-coded a mental health app in 5 weeks. Getting it ready for real users took 3 months

Quick background: I'm not a developer. I spent 8 years in operations at a healthcare staffing company, and during a rough patch in 2024 I wanted someone to talk to about burnout. Not therapy necessarily, just someone qualified who'd check in. Every app I tried either pushed me into $150 therapy sessions or matched me with whoever was online.

So I built my own app. You answer a few questions about what's going on, and it matches you with a mental health supervisor who fits. Then you chat privately and book sessions when you need them, this was the initial idea.

Phase 1: the fun part

I built the first version with Lovable and Supabase in about 5 weeks, mostly evenings. Sign-up, intake questions, matching, chat, booking, and Stripe payments all worked. I showed it to 6 supervisors I knew from my old job, and 4 said they'd try it.

I genuinely thought I was 2 weeks from launch.

Phase 2: the question that changed the plan

One of those supervisors asked me, "Is this HIPAA compliant?" I said something vague like "the data's encrypted." She didn't look convinced, and she said she couldn't use it with clients until she knew for sure.

I didn't know what I didn't know, so I went looking for developers who had worked on health apps. I talked to 3 teams. Two quoted me a full rebuild right away, which felt like they hadn't really looked. The third, Clixlogix, suggested starting with a review of what I already had. I went with that.

What the review found

I expected a list of code bugs. Some of the worst problems turned out to be in the UX, things I'd designed on purpose because they felt friendly:

  • Push notifications showed message previews. "Sarah: I had another panic attack at work today..." on someone's lock screen, readable by anyone near their phone.
  • Booking confirmation emails included the reason for the session, pulled straight from the intake answers. Email isn't a safe place for that.
  • Supervisors could scroll back through a user's entire chat history, even after the user switched to a different supervisor.
  • No session timeout. If you left the app open on a shared laptop, it stayed logged in forever.
  • My analytics tool was recording full screen sessions, including the intake form. I'd added it to see where people dropped off and never thought about what it captured.
  • Some of my tools wouldn't sign a BAA (the agreement health apps need from vendors that handle patient data). One of them was my email provider.

And the code issues: chat messages weren't properly locked down at the database level, and an API key was sitting in the frontend.

Honestly, this was a hard week. Half the app needed to change, and some of it was stuff I was proud of.

Phase 3: redesign, then rebuild

Before writing any code, their team walked me through what had to change and why. We spent about 2 weeks on that, and I pushed back on some of it. I wanted to keep message previews because they help people come back to the app. We landed on a middle ground: the notification just says "You have a new message," and the preview shows only after you unlock the app.

Other changes:

  • Emails now say only "Your session is confirmed" with a link. No details.
  • Supervisors only see conversations from the period they're matched with someone.
  • Auto logout after inactivity, and an optional PIN for the app.
  • I swapped the analytics tool and switched email providers to ones that sign BAAs.
  • An access log, so we can see who viewed what.

Then they rebuilt the backend, the chat, and the parts of the frontend that needed it. They kept most of my screens and the matching logic, so it wasn't a full restart. The vibe code cleanup and fix took about 6 weeks, plus 2 for testing. It did not cost more than I'd budgeted, but the launch slipped from June to September.

One thing I want to be clear about: a dev team can't make you "HIPAA compliant" on its own. Compliance also covers your policies, your vendors, and how you run things. What they did was make the product built for it. I'm still working through the rest with a compliance consultant.

Where we are

Launched September 12. 141 users, 11 supervisors, 312 sessions booked so far. The supervisor who asked the HIPAA question is now our most active one. Honest problem: retention after the first month is about 32%, and I haven't cracked it yet.

What I'd tell anyone building a health app with AI tools

  1. The AI built exactly what I asked for. The problem was I didn't know what to ask for. It never told me a lock screen preview could be a privacy issue.
  2. Many compliance problems are design problems, not code problems. Have someone review your flows, not just your code.
  3. Ask your first professional users what they need to trust the app. One question from a supervisor saved this company.
  4. Get quotes from more than one team, and be wary of anyone who suggests a full rebuild before reading your code.

Happy to answer questions about the matching, the BAA mess, or working with supervisors.

Top comments (0)