<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Devin Smith</title>
    <description>The latest articles on DEV Community by Devin Smith (@devin_smith_deebe697da649).</description>
    <link>https://dev.to/devin_smith_deebe697da649</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4172515%2Fd840a581-dbe1-432a-9ef3-789bcec7f4c0.jpg</url>
      <title>DEV Community: Devin Smith</title>
      <link>https://dev.to/devin_smith_deebe697da649</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/devin_smith_deebe697da649"/>
    <language>en</language>
    <item>
      <title>I vibe-coded a mental health app in 5 weeks. Getting it ready for real users took 3 months</title>
      <dc:creator>Devin Smith</dc:creator>
      <pubDate>Fri, 09 Oct 2026 05:23:33 +0000</pubDate>
      <link>https://dev.to/devin_smith_deebe697da649/i-vibe-coded-a-mental-health-app-in-5-weeks-getting-it-ready-for-real-users-took-3-months-178d</link>
      <guid>https://dev.to/devin_smith_deebe697da649/i-vibe-coded-a-mental-health-app-in-5-weeks-getting-it-ready-for-real-users-took-3-months-178d</guid>
      <description>&lt;p&gt;Quick background: I'm not a developer. I spent 8 years in operations at a healthcare staffing company, and during a rough patch in 2024 I wanted someone to talk to about burnout. Not therapy necessarily, just someone qualified who'd check in. Every app I tried either pushed me into $150 therapy sessions or matched me with whoever was online.&lt;/p&gt;

&lt;p&gt;So I built my own app. You answer a few questions about what's going on, and it matches you with a mental health supervisor who fits. Then you chat privately and book sessions when you need them, this was the initial idea.&lt;/p&gt;

&lt;h2&gt;
  
  
  Phase 1: the fun part
&lt;/h2&gt;

&lt;p&gt;I built the first version with Lovable and Supabase in about 5 weeks, mostly evenings. Sign-up, intake questions, matching, chat, booking, and Stripe payments all worked. I showed it to 6 supervisors I knew from my old job, and 4 said they'd try it.&lt;/p&gt;

&lt;p&gt;I genuinely thought I was 2 weeks from launch.&lt;/p&gt;

&lt;h2&gt;
  
  
  Phase 2: the question that changed the plan
&lt;/h2&gt;

&lt;p&gt;One of those supervisors asked me, &lt;em&gt;"Is this HIPAA compliant?"&lt;/em&gt; I said something vague like "the data's encrypted." She didn't look convinced, and she said she couldn't use it with clients until she knew for sure.&lt;/p&gt;

&lt;p&gt;I didn't know what I didn't know, so I went looking for developers who had worked on health apps. I talked to 3 teams. Two quoted me a full rebuild right away, which felt like they hadn't really looked. The third, Clixlogix, suggested starting with a review of what I already had. I went with that.&lt;/p&gt;

&lt;h2&gt;
  
  
  What the review found
&lt;/h2&gt;

&lt;p&gt;I expected a list of code bugs. Some of the worst problems turned out to be in the UX, things I'd designed on purpose because they felt friendly:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Push notifications showed message previews.&lt;/strong&gt; "Sarah: I had another panic attack at work today..." on someone's lock screen, readable by anyone near their phone.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Booking confirmation emails included the reason for the session&lt;/strong&gt;, pulled straight from the intake answers. Email isn't a safe place for that.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Supervisors could scroll back through a user's entire chat history&lt;/strong&gt;, even after the user switched to a different supervisor.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;No session timeout.&lt;/strong&gt; If you left the app open on a shared laptop, it stayed logged in forever.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;My analytics tool was recording full screen sessions&lt;/strong&gt;, including the intake form. I'd added it to see where people dropped off and never thought about what it captured.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Some of my tools wouldn't sign a BAA&lt;/strong&gt; (the agreement health apps need from vendors that handle patient data). One of them was my email provider.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;And the code issues: chat messages weren't properly locked down at the database level, and an API key was sitting in the frontend.&lt;/p&gt;

&lt;p&gt;Honestly, this was a hard week. Half the app needed to change, and some of it was stuff I was proud of.&lt;/p&gt;

&lt;h2&gt;
  
  
  Phase 3: redesign, then rebuild
&lt;/h2&gt;

&lt;p&gt;Before writing any code, their team walked me through what had to change and why. We spent about 2 weeks on that, and I pushed back on some of it. I wanted to keep message previews because they help people come back to the app. We landed on a middle ground: the notification just says "You have a new message," and the preview shows only after you unlock the app.&lt;/p&gt;

&lt;p&gt;Other changes:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Emails now say only "Your session is confirmed" with a link. No details.&lt;/li&gt;
&lt;li&gt;Supervisors only see conversations from the period they're matched with someone.&lt;/li&gt;
&lt;li&gt;Auto logout after inactivity, and an optional PIN for the app.&lt;/li&gt;
&lt;li&gt;I swapped the analytics tool and switched email providers to ones that sign BAAs.&lt;/li&gt;
&lt;li&gt;An access log, so we can see who viewed what.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Then they rebuilt the backend, the chat, and the parts of the frontend that needed it. They kept most of my screens and the matching logic, so it wasn't a full restart. The &lt;a href="https://www.clixlogix.com/vibe-coding-cleanup-services/" rel="noopener noreferrer"&gt;vibe code cleanup and fix&lt;/a&gt; took about 6 weeks, plus 2 for testing. It did not cost more than I'd budgeted, but the launch slipped from June to September.&lt;/p&gt;

&lt;p&gt;One thing I want to be clear about: &lt;strong&gt;a dev team can't make you "HIPAA compliant" on its own.&lt;/strong&gt; Compliance also covers your policies, your vendors, and how you run things. What they did was make the product built for it. I'm still working through the rest with a compliance consultant.&lt;/p&gt;

&lt;h2&gt;
  
  
  Where we are
&lt;/h2&gt;

&lt;p&gt;Launched September 12. 141 users, 11 supervisors, 312 sessions booked so far. The supervisor who asked the HIPAA question is now our most active one. Honest problem: retention after the first month is about 32%, and I haven't cracked it yet.&lt;/p&gt;

&lt;h2&gt;
  
  
  What I'd tell anyone building a health app with AI tools
&lt;/h2&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;The AI built exactly what I asked for. The problem was I didn't know what to ask for.&lt;/strong&gt; It never told me a lock screen preview could be a privacy issue.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Many compliance problems are design problems, not code problems.&lt;/strong&gt; Have someone review your flows, not just your code.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Ask your first professional users what they need to trust the app.&lt;/strong&gt; One question from a supervisor saved this company.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Get quotes from more than one team&lt;/strong&gt;, and be wary of anyone who suggests a full rebuild before reading your code.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;Happy to answer questions about the matching, the BAA mess, or working with supervisors.&lt;/p&gt;

</description>
      <category>vibecoding</category>
    </item>
  </channel>
</rss>
