Bobook AppCareinfo@bobook.club

Terms: Health Check & Launch audit

Last updated: 6 October 2026

These terms apply when you book the Bobook AppCare Health Check & Launch audit or ask for a free Vibe Health Check. Please read them before you pay. By paying for the audit, or by asking for the free check, you agree to them.

1. Who we are

Bobook AppCare is a service by Bobook Limited, a company registered in Ireland (CRO 785764), Venture Hub, 136 Capel Street, Dublin 1, D01 T2C9, Ireland ("we", "us"). Contact: info@bobook.club.

2. What these terms cover

  • The one-off Health Check & Launch audit (the "audit").
  • The free Vibe Health Check (the "free check").
  • They do not cover AppCare monthly plans. Monthly plans are covered by separate terms, which we agree with you before any production work starts.

3. Who can buy

  • The audit and the free check are for businesses, not consumers. By booking you confirm you are buying for your business.
  • For now, they are available only to businesses established outside the EU (for example the US, UK, Canada or Australia). EU businesses can join a waitlist until we can invoice them with reverse charge.
  • If a business established in the EU pays for the audit, we refund the payment in full before any work starts and offer the waitlist.

4. The free Vibe Health Check

The free check is automated and non-invasive. It only looks at what is public, and we offer it only to the person who owns or runs the app. It covers:

  • uptime and response time of your app's public URL;
  • security headers on your public pages;
  • Lighthouse scores (performance, accessibility, best practice, SEO) on your public pages;
  • a secret scan of your public code repository, only if you send us the link yourself.

We email you a short written summary. We don't log in, run vulnerability scans, load-test, or probe your APIs, databases or admin areas. The free check is not a security audit and does not certify your app as safe.

5. The audit

  • Price: USD 750, fixed, paid in full up front (see section 8).
  • What we review, with your permission and read-only access: hosting and uptime set-up; error logging; backups and rollback; dependencies and known vulnerabilities; secrets in code; auth and payment flow risks (review only); cost exposure on hosting and APIs; and App Store / Google Play readiness, if your app is in or going to the stores, including upcoming store deadlines.
  • What you get: a written audit report with findings ranked by risk, a fix plan, and which AppCare plan fits your app, plus a 30-minute walk-through call. If you want monthly care, we quote it in writing after the audit.
  • When: within 5 business days of receiving the access we need. Business days are Monday to Friday, Irish business hours, excluding Irish public holidays.
  • No changes: we make no changes to your code, data, settings or production systems during the audit.
  • Who does it: we use AI tools to help analyse issues; our AI provider is OpenAI (the OpenAI API), see section 5 of our Privacy Notice. A person at Bobook reviews the report before we send it to you.

6. Access

  • Read-only, through your own team roles. You grant access yourself, by inviting us into your own accounts (for example hosting, code repository, database, error logging and app-store consoles) with the read-only role each provider offers, or the narrowest role it offers where it has no read-only role. You can see and manage that access in your own accounts.
  • No passwords or secrets. We don't ask for your passwords, shared logins, API keys or other secrets. If you send us one anyway, we won't use it; we delete it and suggest that you rotate it.
  • You stay in control. You can revoke our access at any time. If you revoke it before we finish, the audit pauses until access is back.
  • Our own logins. We keep the logins for the access you give us in a password manager, never in code or chat.
  • End of the audit. When we deliver the report, we remove our own access (leaving your teams wherever the provider lets us) and ask you to remove any roles you gave us. We confirm in writing, within 1 business day of delivery, that we have removed our access.
  • Your users' data. We don't export or download your end users' personal data, and we use it only for the audit. If some is visible to us through read-only access, we look at no more than the audit needs. A short excerpt we analyse (for example a log line) may contain some; section 7 applies. See also section 4 of our Privacy Notice.
  • No security testing without consent. We don't run security tests (beyond reviewing the code and configuration you give us access to) unless you agree in writing to an agreed scope.

7. Your end users' personal data (GDPR Art. 28 processor terms)

We don't need your end users' personal data to do the audit. Wherever possible, please give us access to a staging environment, or redacted or sample logs, instead of live data, so that as little personal data as possible is visible to us.

If your end users' personal data is still visible to us during the audit, or is contained in an excerpt we analyse, you are the controller and we act as your processor under Article 28 of the GDPR. This section is our processing agreement with you; there is no separate data processing agreement.

  • Details of the processing. Subject matter and purpose: carrying out the audit. Duration: the audit, followed by the deletion steps below. Type of data: any end-user personal data contained in the systems, code, configuration or logs you give us access to (for example names, email addresses, IP addresses or account IDs). Data subjects: your app's end users.

We will:

  • Follow your instructions. Process that data only on your documented instructions (these terms and any written instructions you give us), and only to carry out the audit. We tell you if we think an instruction breaks data protection law.
  • Keep it confidential. Make sure everyone at Bobook who can see it is bound by confidentiality.
  • Keep it secure. Use appropriate technical and organisational security measures to protect it.
  • Use only listed sub-processors. You give us general authorisation to use the sub-processors listed in section 5 of our Privacy Notice, including OpenAI for AI-assisted analysis. We use each of them under data processing terms. We tell you before we add or replace a sub-processor, so that you can object.
  • International transfers. If a sub-processor processes the data outside the European Economic Area, the safeguards described in section 6 of our Privacy Notice apply.
  • Help you. Help you respond to requests from your end users who use their data protection rights, help you deal with any personal data breach and, where relevant, help with data protection impact assessments. If we become aware of a breach affecting that data, we tell you without undue delay.
  • Delete it at the end. Delete any of it that ended up in our notes at the end of the audit, and remove our access as set out in section 6. Excerpts sent to OpenAI are deleted under OpenAI's retention policy, described in section 5 of our Privacy Notice.
  • Show compliance. Give you, on request, the information you reasonably need to show that we meet this section, and allow for and contribute to audits, including inspections, by you or an auditor you appoint, on reasonable notice.

8. Payment, invoices and tax

  • The audit is paid in full up front through Stripe's secure checkout, before the audit starts (unless you buy it through a freelance marketplace, see section 9).
  • Card details are handled by Stripe. We don't see or store your full card number.
  • Invoices are issued by Bobook Limited, in USD. Irish VAT is not charged because you are a business established outside the EU. You are responsible for any taxes due in your own country (for example under reverse charge).

9. Buying through a freelance marketplace

If you buy the audit through a freelance marketplace (Upwork, Freelancer or Contra), that platform's contract and payment terms govern the purchase, and you pay through the platform. Wherever the platform allows it, these terms serve as the scope document for the audit.

10. Refunds

  • Before you give us access. If you change your mind after paying but before you give us access, tell us and we refund the audit fee in full.
  • No refund once you've given us access. Once you have given us read-only access, the audit fee is not refundable.
  • Full refund if we cancel or can't deliver. We refund the audit fee in full if we cancel the audit, or if we can't deliver the report within 10 business days of receiving the access we need. Days when the audit is paused because access was revoked don't count towards the 10.
  • EU businesses. If your business is established in the EU, we refund the fee in full before any work starts (see section 3).
  • Refunds required by law. Nothing in these terms takes away any refund the law requires.

11. Audit credit towards a monthly plan

If you commit in writing to an AppCare monthly plan within 30 days of receiving your audit report, the full USD 750 is credited against your first monthly charge. The credit applies to your first monthly charge whenever that charge happens, even if production work begins more than 30 days after the report. Monthly plans are quoted after the audit and are covered by separate terms, agreed before any production work starts.

12. Your responsibilities

  • You own and keep control of your accounts (hosting, database, code repository, app-store developer accounts, payment provider).
  • You remain responsible for keeping your own backups of your app's code, data and configuration.
  • You are responsible for your app, its content, your users, your own privacy policy and terms, your compliance with laws and app-store rules, and decisions about your product, including what to do with the findings in the report.

13. What we don't promise

  • We carry out the audit with reasonable skill and care.
  • The audit is a point-in-time review of what you gave us access to. It doesn't guarantee that every issue is found.
  • We don't promise uptime, security, app-store approval or any business result, and we don't certify your app as secure. Hosting providers, AI builders, third-party APIs and app stores are outside our control.
  • Except as stated in this section, all warranties are excluded to the extent the law allows.

14. Limitation of liability

  • Nothing in these terms limits or excludes liability that cannot be limited or excluded by law, including liability for death or personal injury caused by negligence, or for fraud.
  • We are not liable for indirect or consequential loss, or for loss of profits, sales, revenue, business, goodwill or data.
  • We are not liable for actions or decisions of hosting providers, app stores or other third parties, or for changes you or others make to your app.
  • Subject to the first point, our total liability to you in connection with the audit and the free check, together, is limited to USD 750 (the price of the audit).

15. Confidentiality

We keep your confidential information confidential and use it only for the audit. We won't name you as a client or use your app as an example without your written permission.

16. Privacy

How we handle personal data is explained in our Privacy Notice.

17. Not affiliated

Lovable, Bolt, Replit, Cursor, Base44, App Store and Google Play are trademarks of their owners. Bobook AppCare is an independent service and is not affiliated with or endorsed by them.

18. Changes to these terms

We may update these terms. The "Last updated" date above shows the current version. The version in place on the day you pay applies to your audit.

19. Law and courts

These terms are governed by the laws of Ireland. The courts of Ireland have jurisdiction, without limiting any mandatory protections that apply to you where you are based.

20. Contact

Bobook Limited, Venture Hub, 136 Capel Street, Dublin 1, D01 T2C9, Ireland · CRO 785764 · info@bobook.club