BrassWell went live on the web in mid-September 2026. It was built by one person, and most of what that took was not writing software.

This is the part the launch posts leave out — not because it is secret, but because nobody looks impressive filing a form with the Copyright Office. It is also the part that actually stops people: you can have a working product months before you are allowed to charge anyone for it. So here is the real list, and then the honest half about building it with AI, including what the AI got confidently wrong.

Five words I did not know in March

An API is how two pieces of software talk to each other. JSON is the format they talk in; it is not a person named Jason, which took me an embarrassing beat. A repo is the folder where the code and every past version of it lives. To deploy is to push the new version out to real people. A webhook is one service poking another to say something happened.

I learned all of that in a few months. My alma mater has a two-word motto for exactly this: Learn by Doing. Thanks, Cal Poly San Luis Obispo.

It started on a training run

In spring 2026 I was training for the Rock ’n’ Roll marathon in San Diego. Long runs on the bluff trail in Encinitas, ocean on the right, nothing to do for two hours but think. What I kept thinking was that I knew how to build websites, I had a money problem I had already solved for myself in a spreadsheet, and the two had never been introduced. A web app I would use, and that the self-employed people I knew would use. That was the whole scope.

A man in a gray t-shirt, dad hat and tortoiseshell sunglasses walking a small Alaskan Klee Kai on a tree-lined Huntington Beach street in early morning light, glancing at his phone as he walks.
The other half of the thinking happened on the dog walk. Most of what ended up in the product got decided holding a phone.

Then came the unglamorous middle: house-sitting in Orange County to keep the rent down, working at somebody else’s round white table with a borrowed dog at my feet, starting at five in the morning because that is when my usage limits reset.

The paper trail nobody posts about

Here is what sat between “it works” and “it is legal to sell” for a US consumer finance app that touches bank data and bills on a subscription.

  • A registered DMCA agent. Safe-harbor protection only exists if you have designated one with the US Copyright Office: a real filing, a real fee, renewed every three years, with a street address rather than a PO box.
  • A privacy policy and terms that name you. California Civil Code §1789.3 requires the provider’s legal name, business address and a telephone number for complaints. Not an email form. A phone number.
  • Automatic-renewal disclosures, including a renewal reminder inside a defined window before the charge. Get the window wrong and you get refunds and regulatory letters.
  • Two written security policies, because Plaid’s launch process asks you to attest to them, and attesting to a practice you have not written down is how an attestation becomes untrue later.
  • CAN-SPAM in every email, lifecycle mail included: a physical postal address and a working unsubscribe.
  • A breach-notification plan under Civil Code §1798.82, decided before you need it.
  • And then Apple: a developer account, the Paid Apps Agreement, a privacy manifest, a privacy label that matches what the app collects, and a build that survives review.

The terms of service are where you decide, in advance, what happens when something goes wrong. Ours are public. The short version: you have to be 18 or older, and onboarding checks it. Disputes go to individual arbitration, but we pay the fees on claims under $10,000 and you can opt out within 30 days with one email. Liability is capped at what you paid in the last twelve months, because a one-person company cannot carry unlimited exposure. And there is Apple’s required language, which you do not get to negotiate.

One clause I will point at on purpose: the terms say plainly that the photographs of people on our site are AI-generated and are not customers. Including the ones on this page. If you use generated imagery, say so in the document that binds you, not in a caption nobody reads.

A man working on a laptop at a round white table in a dark open-plan living room before dawn, a single pendant light overhead, a dog asleep on the floor behind him.
Most of that list got worked through at this table, before sunrise, in somebody else’s house. The start time was not discipline — it was when the usage limits reset.

The order is the part you cannot see from the outside. The address decision comes first, because it lands in the privacy policy, the terms, every email and the Copyright Office record at once. The security policies have to exist before the attestation that references them. And the legal pages have to be reachable before the marketing site that links to them ships — which nearly went wrong, as you will see.

What it runs on, and what scared me

Nothing exotic, because the point is that one person can run it. Claude Code for most of the writing — not autocomplete, an agent that reads the repository, makes the change and runs the tests. Google Gemini for the images. Greptile for pull-request review with the whole codebase in context, which catches the change that looks fine in the diff and is wrong three files away. Then GitHub, Vercel, Cloudflare and Supabase underneath, with Plaid for banks, Stripe and RevenueCat for payments, Resend for email, Sentry for errors and Expo for the iPhone build.

What actually kept me up was not the App Store. It was getting breached. This connects to people’s bank accounts, so before the paywall went on, the infrastructure got built to a standard I could defend out loud:

  • Row-level security on every user table, so the database itself refuses to return another person’s rows.
  • Bank tokens encrypted at rest with AES-256-GCM, under a key that is not in the codebase.
  • A PIN, passkey or Face ID check before you can connect a bank at all. It adds friction to the most important step, and it stays, because a stolen password should not be enough to reach somebody’s transactions.
  • Signed payment webhooks, so nobody can grant themselves a subscription with a forged payload.

None of that makes anything unbreakable, and anyone who says their setup is bomb-proof is selling something. It makes the easy attacks fail, and it gives me an honest answer when a customer asks what happens to their data.

I sat on a Zoom call with an attorney, hired through UpCounsel, and went through the terms, the privacy policy and the cookie policy line by line. North of $200 an hour. Not because the drafts were bad, but because those documents decide what happens when something goes wrong, and a confident draft of a legal document is exactly the kind of thing this whole article is about distrusting. You are not buying paperwork. You are buying a person who is professionally accountable for being right.

When you are in the red, every line item feels impossible to justify. There are no investors here. The lawyer, the developer account, the Copyright Office, the subscriptions, the domains — all of it came out of pocket before a single customer existed. That is not a complaint. It is just the actual shape of bootstrapping, and I would rather say so than pretend it arrived fully formed.

Building it with AI: five things it got wrong

I am not going to pretend AI did not matter. One person produced a web app, an iOS build, a support portal, a marketing site and a library of these guides. That would not have happened in 2019. It is genuinely good at work that is large, structured and tedious, and it is a tireless researcher.

What it is not is reliable. Its failure mode is specific and dangerous: work that is confident, fluent and wrong, in a voice identical to work that is right. Five real examples from this project, four of which would have reached production:

A man standing at a desk late at night working across a laptop and a monitor, lit by the screens and a warm corner lamp, a tan dog lying on the rug beside him.
The last week of September. A web app, a new site and an App Store submission, all due at once.
  1. A routing bug that passes every test. A config comment said unknown paths fall through to the Worker. With this Cloudflare setup they do not, for any request a browser makes when you click a link. So curl would have shown the privacy policy while every real visitor got a 404 — on the two pages carrying the required California notice.
  2. A security claim that was 25 days stale. I was told bank tokens were stored in plaintext. They had been encrypted for over three weeks. The source was a document that had been accurate for one day, and the confident summary inherited its error without inheriting the doubt.
  3. A homepage that advertised zero. The animated numbers shipped their starting values, so with JavaScript off the page promised “0 days of full Core access”. A zero-day free trial.
  4. A sitemap that lied to Google. Twenty-three guide URLs were submitted as live while every one of them redirected to the homepage, for two weeks, without anything failing loudly.
  5. A button that does not work. I was walked through deleting a duplicate billing app twice before anyone checked that the platform refuses — and that its suggested workaround would have wiped every subscription record in the account.

The bottleneck moved

That is the finding worth taking away. Not “AI is good now” or “AI is overhyped”, but that the expensive step changed places. Producing plausible work is close to free. Establishing whether it is true now costs more than producing it did, so the job is mostly verification — a skill that does not feel like progress while you are doing it. It is why this site carries scripts that refuse to let it publish when a number drifts from its source or the sitemap drifts from the build.

The rule that has served me best: anything that would be embarrassing or expensive if wrong gets checked against the primary source, by hand, before it ships. Not the summary of the source. The source.

Where it actually is

Live on the web since mid-September 2026. The iPhone app has been submitted to the App Store and is waiting for App Review, which runs on Apple’s timetable, not mine, so there is no launch date to promise here. Android is the intention before the end of the year, with the same caveat and less certainty behind it. An article arguing that confident claims should be checked does not get to make an unverifiable promise at the end, so if you are reading this later, go and look at the stores.

There are no user numbers in this post because there are not yet user numbers worth posting. That felt like the right way to tell a launch story about a product whose whole pitch is that it tells you the truth about your money.

Questions, answered

What do you legally need before charging for a finance app in the US?

At minimum: a legal entity, a privacy policy and terms of service, and, in California, the notice required by Civil Code section 1789.3 giving the provider’s legal name, business address and a telephone number for complaints. A subscription product must also meet automatic-renewal requirements, every commercial email must carry a physical postal address and working unsubscribe under CAN-SPAM, and you should have a breach-notification plan under Civil Code section 1798.82. If you host user-posted content, designating a DMCA agent with the US Copyright Office is what gives you safe-harbor protection. This is a description of what one company had to do, not legal advice.

Can one person actually ship a product like this with AI?

Yes, and this one did — a web app, an iOS build, a support portal, a marketing site and a library of guides. The honest caveat is that the work arrives confident, fluent and sometimes wrong in a register identical to work that is correct. Four of the five errors documented in this guide would have reached production, including one that would have returned the correct page to curl while serving a 404 to every browser.

How do you secure a finance app as a one-person company?

The measures that mattered most here were structural rather than clever. Row-level security on every user table, so the database refuses to return another person’s rows regardless of what the application does. Bank access tokens encrypted at rest with AES-256-GCM under a key held outside the codebase. A second check, a PIN, a passkey or Face ID, required before a bank account can be connected at all. HMAC-signed payment webhooks, so no one can grant themselves a subscription with a forged payload. Sessions in the device keychain behind a Face ID lock. And written security policies, because an undocumented practice is one that quietly stops happening. None of that is unbreakable — it makes the easy attacks fail.

How long did it take?

The idea took shape in spring 2026 during marathon training, and the web app went live in mid-September 2026. The iPhone app has been submitted and is waiting for App Review, which runs on Apple’s timetable rather than ours. An Android release is intended before the end of 2026.

Sources

  1. DMCA Designated Agent Directory — US Copyright Office. The register itself, the fee, the three-year renewal, and the requirement that the service provider give a street address.
  2. California Civil Code § 1789.3 — California Legislative Information. The provider name, address and complaint telephone number a consumer service must publish.
  3. California Civil Code § 1798.82 — California Legislative Information. The data-breach notification duty and its timing.
  4. CAN-SPAM Act: a compliance guide for business — Federal Trade Commission. The physical postal address and unsubscribe requirements that apply to lifecycle email, not just campaigns.
  5. Launch checklist — Plaid. What a production integration is asked to attest to, including the security policies referenced above.
  6. Static assets: advanced routing control — Cloudflare. Why navigation requests bypass the Worker when assets and a not-found handler are both configured — the first error in this guide.