Frequently Asked Questions
Choose the right starting point .
Answers about incident diagnosis, RLS reviews, production-readiness audits and independence assessments — plus how pricing, access and follow-on work actually run, and the things we deliberately don’t promise.
- Incident desk
- Mon–Fri, 9 AM–6 PM ET
- Incident diagnosis
- $99, credited toward any repair
- Assessments
- Scope and price confirmed before payment
- Questions
- hello@apprescuedesk.com
Choosing a service
four ways inWhich service should I start with?
Start with an Incident Diagnosis when a previously working production workflow is broken now.
Start with the RLS & Data Isolation Review when role or tenant isolation is uncertain, the Readiness Audit when launch or real-user production risk needs assessing, and the Independence Assessment when Lovable dependency, external deployment or a migration needs planning.
What if the app has never worked correctly?
Don’t use the direct Incident Diagnosis checkout — it’s for restoring something that used to work.
If the application is substantially complete and the real question is production risk or launch readiness, the Readiness Audit may fit. A full build or open-ended implementation backlog stays outside scope.
Timing & process
How quickly do you respond?
Paid incidents are reviewed by a human within 15 minutes during published incident-desk hours.
Assessment delivery is measured in business days and confirmed after scope and access are agreed. It isn’t covered by the 15-minute incident response objective.
Will you change production immediately?
No. Diagnosis and assessment don’t authorise production changes.
Any implementation begins only after you approve the exact scope, price, risks, test plan and rollback or forward-fix path.
Pricing & deliverables
you pay for a resultWhy pay for a diagnosis or assessment before implementation?
The paid entry product is a usable deliverable in its own right: evidence, risk, a bounded decision and an implementation scope.
It prevents open-ended debugging, premature rewrites and blind production changes.
Can you guarantee a fix?
We guarantee the agreed paid deliverable within a qualified scope, subject to the access and dependency limitations in the Terms.
We don’t guarantee that every provider outage, lost-data event, security incident or migration can be repaired safely.
Access, security & data
Will you need my passwords?
No. Don’t send passwords, API keys or access tokens by form, email or chat.
We prefer customer-controlled screen sharing, collaborator invites or minimum-privilege temporary roles. The access & security page sets this out in full.
Can you recover deleted or corrupted data?
We can investigate available backups, database history and recovery options, but we don’t guarantee recovery of deleted or corrupted data. Anyone who guarantees that without seeing your system is guessing.
A potential data-loss incident may need a separate, agreed scope before anything is changed.
Execution & follow-on work
What happens after an assessment?
You can use the report independently.
Where implementation is justified, we provide a fixed or capped scope tied directly to selected findings, milestones, acceptance criteria and rollback.
Do you offer ongoing maintenance?
We don’t offer unlimited maintenance, a generic developer-hours retainer or an open-ended feature backlog.
Where an application has a suitable baseline and named critical workflows, Managed Reliability may be offered under a separate coverage schedule with defined checks, a response tier, credits and exclusions.
Platforms & limitations
honestly boundedDo you only support Lovable?
The current public focus is Lovable applications and the services commonly connected to them — Supabase, Stripe, GitHub, authentication, email, APIs, deployment and domains.
Closely related React, Supabase or Stripe applications may be accepted through manual review, but this site doesn’t claim support for every builder or stack.
Do you support current and older Lovable projects?
Yes, after verifying the actual repository and runtime.
We don’t assume every Lovable project uses the same framework, deployment model or payment path.
Is the RLS Review a penetration test?
No. It’s a scoped configuration and data-isolation review.
It isn’t a penetration test, compliance certification or active-breach investigation.
Can you guarantee zero downtime or zero data loss during migration?
No. We define the assumptions, rehearsals, acceptance criteria, cutover controls and rollback so those risks can be managed honestly.
What if the cause is a third-party outage?
We can identify and document the external blocker and recommend a safe next step or workaround where one exists.
We can’t repair infrastructure controlled by a third party — but confirming the fault isn’t in your app is itself a useful answer.
Are you affiliated with Lovable, Supabase or Stripe?
No. App Rescue Desk is an independent service and is not affiliated with or endorsed by Lovable, Supabase, Stripe or any other third-party platform.