Legal
Terms of Service
These terms govern the fixed-scope diagnosis, review, audit, assessment and any separately ordered execution, migration, hypercare or managed-coverage service provided through App Rescue Desk. The applicable product page, order, invoice and written Statement of Work form part of the agreement.
1. Who we are
App Rescue Desk is a trading name of Alp Bozkurt, a sole proprietor established in Türkiye. In these terms, "we", "us" and "App Rescue Desk" refer to that provider, and "you" refers to the person or organisation that requests or purchases a service.
App Rescue Desk is an independent service. We are not affiliated with, endorsed by, or acting as an agent of Lovable, Supabase, Stripe, GitHub or any other platform we work with. All product names and trademarks belong to their respective owners.
2. Definitions
- Entry product
- One of the fixed-scope paid starting points: Production Incident Diagnosis, Supabase RLS & Data Isolation Review, Production Readiness Audit, or Production Independence & Migration Assessment.
- Engagement
- The specific service you order for a named application, environment, assets and workflows, as recorded in the written scope.
- Written scope / SOW
- The product page, order, invoice and any Statement of Work that name the assets, exclusions, price, delivery window and acceptance criteria for an engagement.
- Execution work
- Production changes, remediation, migration, recovery or a stabilization sprint ordered separately after a diagnosis or assessment.
- Deliverable
- The written output of an engagement — for example a diagnosis, finding register, risk assessment, dependency map or decision plan.
3. Services and product families
App Rescue Desk provides productized production-engineering services for named applications, environments, assets and workflows. The public entry products are:
- Production Incident Diagnosis;
- Supabase RLS & Data Isolation Review;
- Production Readiness Audit;
- Production Independence & Migration Assessment.
Implementation, migration, hypercare and managed coverage are not entry products. They require a separate written scope or coverage schedule, approved before work begins.
The service does not build new applications from scratch, take open-ended feature backlogs, provide visual redesign, or give legal, financial, tax or compliance advice. The service is currently offered as a pilot; hours, pricing and scope are as published on this website at the time you order, and may change for future engagements.
4. Eligibility and authorization
An incident is eligible when the affected workflow previously completed its intended job in production and has now stopped — users could sign in and now cannot, payments completed and now fail, data loaded and now errors. A workflow that has never worked correctly in production is implementation or readiness work, not an incident; where the application is substantially complete, a Production Readiness Audit or a bounded stabilization scope may fit instead, and the direct Incident Diagnosis checkout is not used.
Reviews, audits and assessments are eligible for applications that are sufficiently complete for the agreed assets, boundaries and critical workflows to be examined.
You must be authorised. By requesting a service you confirm that you own the application and its connected accounts, or that you are authorised by the owner to request investigation, review and changes to them. We do not work on systems you do not own or control.
Health, regulated financial, children's, government-critical, surveillance and high-volume payment systems require enhanced contract, data-processing, insurance and specialist review. Where those conditions cannot be met, the engagement is declined. See Access & Security.
5. Diagnosis, reviews, audits and assessments
Subject to the agreed scope and the access made available, an entry product delivers the applicable written diagnosis, finding register, risk assessment, dependency map, decision plan or external blocker. An entry product does not guarantee that your preferred business outcome can be achieved safely or within a fixed time.
The USD 99 Incident Diagnosis buys a human technical investigation of one reported incident on one application and the directly connected systems needed to identify the affected component or blocker. It does not buy a repair, an amount of time, or a fix within a fixed period. The full USD 99 is credited toward any repair you approve — it is not added on top. One diagnosis fee covers one incident; if investigation reveals several unrelated failures, we tell you and agree how to handle them before doing further work.
Reviews, audits and assessments confirm the exact scope and pilot price before payment, and no production change is included in them.
Universal scope boundary. An engagement covers only the application, environment, assets, workflows and directly related finding or root cause identified in the written scope. Unrelated defects, new features, redesign, broad refactoring, additional applications, unplanned data migration and any work outside the agreed assets require a separate scope or a written change request.
6. Execution work and change approval
After a diagnosis or assessment, any execution work is proposed with a fixed or capped price. The indicative bands published on this website are pilot ranges, not quotes; the written scope you approve for your engagement is the price that applies.
- No execution work begins, and no production change is made, without your explicit written approval of the scope, price, risk, test plan and rollback path.
- Where a price is capped rather than fixed, you are not charged above the cap without agreeing a new one in writing first.
- If the work turns out to be materially different from what was scoped, we stop and re-quote rather than continue and invoice.
- You may decline execution. In that case the entry-product deliverable stands on its own and nothing further is charged.
Before a material change we define the current state, the proposed change, the business and technical risk, the backup or last-known-good state, the test plan, the rollback or forward-fix decision, the approval authority and the acceptance criteria.
7. Migration, cutover and recovery work
Migration, independence and recovery work may involve downtime, re-authentication, data reconciliation, provider constraints, subscription limitations and rollback risk.
No zero-downtime, zero-data-loss, zero-regression or seamless-provider-migration guarantee is made unless an expressly written, narrowly defined acceptance term states otherwise. We define the assumptions, rehearsal, cutover controls, acceptance criteria and rollback path needed to manage those risks; we do not promise a one-click migration.
8. Managed or recurring coverage
The current public entry products are one-time purchases. Implementation work may be billed upfront or through written milestones.
Any managed or recurring coverage is offered only under a separate written coverage schedule, with defined checks, response tier, credits and exclusions, and is billed in advance as stated in that schedule. No recurring charge is created merely by purchasing an entry product.
9. Deliverables and acceptance
Entry-product deliverables are written. "Deployed" is not the same as "working": where execution work is ordered, acceptance means the agreed business workflow and the relevant negative paths pass the tests stated in the written scope.
Findings distinguish confirmed evidence from strongly supported or probable conclusions, and name the limitations of what was reviewed. We do not present a guess as a verified root cause.
10. Fees, payment and taxes
Prices are in US dollars. The bands published on this website are pilot ranges, not automatic quotes; you approve the written scope and price before any execution work begins.
When a payment is taken it is processed by İyzico, our payment provider. We never see or store your full card details. You are responsible for any taxes, duties or bank charges applicable in your own jurisdiction; where we are required to charge tax, it is shown at the point of payment.
Third-party costs are never included in a price: platform fees, hosting charges, paid API usage and software subscriptions remain yours.
11. Refund and cancellation
For a qualified engagement, once the necessary access and information are available, you receive at least one of the outcomes appropriate to the entry product — for example:
- a verified or strongly supported root cause;
- a working limited repair where it fits the diagnosis scope;
- a finding register, dependency map or decision plan; or
- a concrete external blocker and next-step plan.
If we deliver none of these, we review a refund of the entry-product fee under these terms. This is not an open-ended "no fix, no fee" guarantee — the deliverable is what is being paid for.
When a refund review does not apply
- The access required to do the work was not made available to us.
- The issue cannot be reproduced or observed.
- Material information was withheld or misrepresented at intake.
- For an incident, the request was not, in fact, a previously working workflow.
- The work is blocked by a third-party provider or an outage outside our control.
When we do not refund
- A deliverable was provided and you chose not to proceed with execution.
- The cause is a third-party outage or a provider limitation we identified for you.
- Execution was completed and verified, and you later change your mind.
- You did not provide the access or information needed, after being asked.
If you believe a charge is wrong, email us before opening a chargeback. We would rather resolve it directly.
12. Your responsibilities
- Accurate information. Describe honestly what you need, what changed and what the current state is. A misleading intake usually means a wasted engagement.
- Authorisation. Only request work on systems you own or are authorised to change.
- Timely access. Provide the access we identify as necessary, in the form described in our access and security process.
- No secrets in writing. Never send passwords, API keys, access tokens or private customer records through the form, by email or over chat.
- Backups. Maintaining appropriate business backups and recovery capability is your responsibility.
- Avoid parallel changes. While an engagement is open, do not make unrelated changes to the affected system without telling us. It can invalidate the work.
13. Access and security
We use the minimum access required to answer the agreed question, we do not use shared passwords, and we make no production change without your approval. Access granted for an engagement is revoked at closure. Our full process — how access is requested, what we do with it, and how it is revoked afterwards — is set out on the Access & Security page, which forms part of these terms.
14. Third-party platforms
Your application depends on services we do not control. We can investigate how a third-party service is affecting your application, confirm whether an outage or a provider change is the cause, and recommend a safe workaround where one exists.
We cannot repair infrastructure owned by a third party, and we are not responsible for their outages, pricing, policy changes, deprecations or data handling. Your use of those platforms remains governed by your agreements with them. Where the work identifies a third-party cause, the fee still applies — the work was performed.
15. Specialists and subcontractors
App Rescue Desk may use appropriately qualified specialists where the scope requires it, subject to confidentiality, minimum access, named accounts, contractual permission and App Rescue Desk QA. Material specialist involvement is disclosed where required by the applicable agreement or data-processing obligations. We do not subcontract where the customer agreement does not allow it, and we remain accountable for engagement scope and quality assurance.
16. Security-review and certification limitations
A configuration or data-isolation review — including the Supabase RLS & Data Isolation Review — is a scoped review of agreed assets and application boundaries. It is not a formal penetration test, a compliance certification, a forensic or active-breach investigation, or a warranty that every vulnerability has been identified. We report what was reviewed, the evidence available, the limitations and the tests performed; we do not make an unbounded "secure" or "compliant" guarantee.
17. Backup, data-loss and migration limitations
You remain responsible for maintaining appropriate business backups and recovery capability. Where approved work requires a snapshot, export, duplicate or recovery artifact, we state what it creates and what it does not protect. An engagement-specific snapshot is not a substitute for your ongoing backup responsibility.
We do not guarantee recovery of deleted or corrupted data. We can investigate available backups, database history and recovery options, but a potential data-loss event may require a separate scope and carries no assurance of recovery.
Response and review times published on this website apply to paid incidents during published desk hours and are targets, not contractual service levels. The 15-minute review objective does not apply to reviews, audits or assessments, whose delivery is measured in business days and confirmed after scope and access are agreed. We do not offer 24/7 coverage during the pilot.
18. Intellectual property
Your application, your source code, your accounts and your data remain yours. Any code or configuration we write specifically to deliver your engagement belongs to you once the engagement is paid for.
We retain the right to reuse general knowledge, techniques, templates, taxonomies and non-identifying patterns learned during our work — for example, that a particular provider configuration commonly causes a particular failure.
19. Confidentiality and case studies
We keep your business information, code and data confidential. We do not sell it, publish it, or use it to train models.
No customer name, logo, application, result or identifying detail is used publicly without your written permission. Any reference-lab or illustrative material we publish is labelled as such and does not represent a customer engagement.
20. Prohibited use
You may not use the service to:
- access or change systems you do not own or are not authorised to control;
- bypass a platform policy, abuse suspension or account restriction;
- obtain active-breach or forensic response through the standard intake, or send exploit details or customer-data exports through the form;
- carry out any unlawful purpose.
Where high-risk or regulated data is involved without the required contract, data-processing and insurance basis, the engagement is declined.
21. Warranties and liability
The service is provided on a reasonable-effort basis, without warranties of any kind beyond those expressly stated in these terms.
To the maximum extent permitted by law, our total liability arising out of or relating to an engagement is limited to the amount you paid us for that engagement. We are not liable for indirect or consequential losses, including lost revenue, lost profits, lost or corrupted data, business interruption, or third-party claims.
Nothing in these terms excludes liability that cannot be excluded under applicable law, including liability for fraud, wilful misconduct or gross negligence.
22. Suspension or termination
We may decline or stop work — refunding any unearned fee — if:
- the request is outside the scope of the service;
- required access cannot be provided or is withdrawn;
- we have reason to believe you are not authorised to request the work;
- the work would require us to act unlawfully, or against a platform's terms;
- communication becomes abusive.
You may close an engagement at any time. If execution is already in progress under an approved scope, the work completed up to that point remains payable.
23. Governing law and disputes
These terms are governed by the laws of the Republic of Türkiye. The courts and enforcement offices of Ankara have exclusive jurisdiction over any dispute arising from them, without prejudice to any mandatory consumer protections available to you under the law of your own country of residence.
Questions about these terms: hello@apprescuedesk.com.
24. Changes
We may update these terms as the pilot evolves. The version published on this page at the time you order a service is the version that applies to that engagement. Material changes are reflected in the "last updated" date above.