Chris, creator of the Amy calorie tracking app, shares how he faced the app’s worst week ever, dealing with major outages from his backend and AI providers as well as a serious security vulnerability. Despite these setbacks, he quickly implemented fixes, improved user communication and security, and ended the week by launching dark mode, ultimately making the app stronger and more resilient.
Chris, the creator of the calorie tracking app Amy, shares a candid update about the app’s most challenging week since launch. Amy is designed to be a frictionless calorie tracker, styled like Apple Notes, where users simply type what they ate and the app calculates calories automatically. Despite recent growth—$1,700 in monthly recurring revenue and improved week-one retention—Chris emphasizes the importance of transparency, especially when things go wrong. He believes it’s more valuable to show the struggles and how he addresses them, rather than just highlighting successes.
The first major issue was a five-hour outage caused by his backend provider, Supabase. The app failed to handle the outage gracefully, displaying a blank white screen and leaving users unable to access support. Chris received numerous messages from frustrated but understanding users, many of whom are developers themselves. In response, he implemented several improvements: the app now displays an informative status indicator during outages, allows users to see which services are affected, and provides a way for Chris to remotely update users with custom messages. He also added a feature to automatically recheck the app’s status every 30 seconds, reducing user frustration.
Shortly after fixing these issues, Chris faced another outage—this time with his AI provider, Perplexity Sonar, which powers Amy’s calorie calculations. Although this outage lasted only 15 minutes, it highlighted the fragility of relying on third-party AI services. To mitigate future disruptions, Chris set up a manual fallback system that switches to Gemini 2.5 Flash Light and Exa as backup providers. While this fallback is more expensive, it ensures users experience minimal disruption. Chris is grateful these problems occurred while the user base is still small, making them easier to manage and learn from.
On top of the outages, Chris discovered a security vulnerability in his app. Due to a misconfiguration in Supabase’s row-level security, users could modify their own subscription status and rate limits, potentially granting themselves premium access or abusing the AI endpoints. While the premium access loophole was relatively harmless, the rate limit issue could have led to significant financial loss. Chris quickly patched the vulnerability by restricting write access and recommends storing sensitive data in separate tables. He also outlines his broader security measures, including account and IP-based rate limiting, a kill switch for AI access, budget caps at the provider level, and best practices for handling environment variables and backend communication.
To end a tough week on a positive note, Chris implemented dark mode in Amy, with help from his fiancée Cecilia, who updated the app’s illustrations. Despite the setbacks, he feels the app is now in a much stronger position, with improved reliability, better user communication during outages, and enhanced security. Chris encourages viewers to follow his journey on social media and thanks them for their support, emphasizing that these challenges have ultimately led to meaningful improvements for Amy and its users.