# Launch checklist for US founders of AI apps

Source: https://www.plutonapps.com/resources/launch-checklist-us-founders

Published 2026-10-10, sources checked 2026-10-10. By Irfan Habib (https://www.plutonapps.com/authors/irfan-habib).

Your app works. Before real customers pay, a handful of business tasks decide whether launch day goes quietly. This is the non-engineering list, with where to click for each.

As of October 10, 2026, a US founder taking a Lovable app live has a short list of business tasks that no prompt finishes for you. Verify your business in Stripe and switch to live keys, live prices and live webhook endpoints. Decide how you will handle sales tax. Publish your Google sign-in screen if you use your own Google credentials. Send email from your own domain. Post a privacy policy, terms and a refund policy. Check basic accessibility. Set up a support address, a status page, backups and monitoring. Get your entity and EIN in order. Most items take an afternoon. Skipping them is how a working app turns into failed sign-ins, disputed charges and support emails nobody answers.

This checklist is for a founder whose app already works and is about to take real customers and payments. It covers the business side only. The engineering side, from database rules to tests, is in our guide to [taking a Lovable app to production](https://www.plutonapps.com/guides/lovable-app-to-production) and our [Lovable security checklist](https://www.plutonapps.com/guides/lovable-security-checklist). Platform facts come from Stripe, Google, Lovable, the FTC, California's Attorney General and the IRS, listed under Sources. This is general information, not legal or tax advice.

## What is on a US launch checklist?

| Task | Where you do it | What goes wrong if you skip it |
| --- | --- | --- |
| Verify your business in Stripe | Stripe Dashboard, account onboarding | You cannot take live payments |
| Switch keys, prices and webhooks to live | Stripe Dashboard and the Lovable chat | Checkout fails, or customers pay and get nothing |
| Decide on sales tax | Stripe Tax and your state tax agency | Tax owed that you never collected |
| Publish Google sign-in | Google Cloud console, OAuth consent screen | Only listed test users can sign in, or your brand is missing |
| Send email from your domain | Your email provider and DNS | Sign-up and receipt emails land in spam or nowhere |
| Privacy policy, terms, refund policy | Pages on your own domain | Payment and sign-in reviews fail, and privacy law exposure |
| Accessibility basics | Your app, with a keyboard and free tools | Customers locked out, and lawsuit risk |
| Support address and status page | Your domain and a status service | Unanswered customers file disputes |
| Backups and monitoring | Supabase or Lovable Cloud, plus an uptime monitor | You find out about outages from customers |
| Entity and EIN | Your state, the IRS and an accountant | Business and personal money mixed up |

## How do you switch Stripe from test mode to live mode?

Stripe says switching between its sandbox and live mode is mostly a matter of swapping API keys. In practice there are six steps, and the order matters:

1. **Verify your business** In the Stripe Dashboard, open account onboarding and give Stripe the details it asks for about your business, your product and your role. Stripe must collect this under its know-your-customer obligations. Choose the country carefully: once a service is live, you cannot change the business's origin country.
2. **Set your public business details** Stripe shows customers your business name, website, support email, phone, address and statement descriptor on card statements or receipts. Make them clearly yours. Stripe warns that a customer who does not recognize a payment may dispute it.
3. **Recreate products and prices in live mode** Sandbox objects cannot be used in live mode. Lovable's docs note that price IDs differ between test and live mode, so ask Lovable to switch the app to the live price IDs once they exist.
4. **Swap the keys** Live keys start with pk_live_, rk_live_ or sk_live_. Lovable's docs say to ask Lovable to update your Stripe key and submit the live key in the Update Stripe secret key form. Stripe recommends restricted keys over unrestricted secret keys.
5. **Register live webhook endpoints** Test and live webhook endpoints are separate in Stripe, and each endpoint has its own signing secret. Add the live endpoint, then copy its new signing secret into the app's server settings.
6. **Make one real purchase** Lovable's docs suggest a real purchase on your published app. Note that with a live key, payments made from the preview are real too. Refund it from the Stripe Dashboard and check that access changes both ways.

If you used Lovable's built-in payments instead, claim the Stripe account Lovable created from the Payments tab and finish Stripe's onboarding. Lovable then reviews your live site for a privacy policy, terms of service, a refund policy and genuine content. If you chose Paddle, Paddle verifies your business and reviews your domain, and Lovable's docs describe it as a merchant of record that handles payments, tax and compliance. Our [Lovable Stripe guide](https://www.plutonapps.com/resources/lovable-stripe-integration) covers webhooks, and [paid but not upgraded](https://www.plutonapps.com/resources/lovable-stripe-paid-not-upgraded) covers the most common launch-week bug.

## Do you need to charge sales tax on a SaaS app?

Possibly, and it depends on where your customers are. Stripe's guide to US sales tax explains that since the Supreme Court's 2018 decision in South Dakota v. Wayfair, a state can require an out-of-state seller to collect sales tax once its sales there pass a threshold, called economic nexus. Stripe counts 46 states with economic nexus laws. Most use $100,000 in sales or 200 transactions in 12 months; Texas and California use $500,000.

Software is taxed differently in each state. Stripe's examples: SaaS is fully taxable in Connecticut, not taxable in California, and taxed on 80% of the price in Texas. Stripe Tax tracks your sales against each state's threshold and alerts you when you may need to register. It does not register for you by default. You register with the state first, then add the registration in Stripe, or ask Stripe to register on your behalf in US states outside your home state. Some jurisdictions expect returns even when you collected nothing. Turn on monitoring from day one, and bring in an accountant when Stripe flags a state.

## Does Google sign-in need verification before launch?

Only if you use your own Google credentials. On Lovable Cloud, Lovable's docs say it manages the Google sign-in client for you by default. If you switched to your own client ID, or run your own Supabase project, the Google Cloud project is yours to finish:

- Publishing status: a project left in Testing is limited to up to 100 listed test users, whose access expires after seven days. Apps that ask only for name, email and profile, which covers plain Sign in with Google, are exempt. For anything more, publish the app as In production.
- Brand verification: to show your app's name and logo on the consent screen, Google requires a lighter check. Your homepage must sit on a verified domain you own, describe the app and be more than a login page. Your privacy policy must be on the same domain, linked from the homepage and the consent screen. Your authorized domains must be verified in Google Search Console.
- Full verification: an app that asks for any scope Google classes as sensitive or restricted must pass Google's full app verification before it gets access.

If sign-in already fails on the live site, start with our guide to [Google login not working in Lovable](https://www.plutonapps.com/resources/lovable-google-login-not-working).

## Is your email ready for real customers?

Check that sign-up confirmations, password resets and receipts come from your own domain, with the domain records email providers check, and that they reach a real inbox outside your team. Our [Lovable email guide](https://www.plutonapps.com/resources/lovable-resend-email) walks through the domain setup, sign-in emails and retries.

## What privacy policy and terms does a US app need?

Most early apps do not face one big federal privacy law, but several rules still reach them:

- California's Online Privacy Protection Act (CalOPPA). California's Attorney General says any operator in the world that collects personal information such as a name or email address from California consumers must comply. The policy must list the categories of information collected, the kinds of third parties it is shared with, how users can review and request changes, and its effective date. It must also say how you respond to Do Not Track signals and whether third parties collect personal information on your site.
- California's Consumer Privacy Act (CCPA). It applies to for-profit businesses that do business in California and meet one test: gross annual revenue over $25 million (adjusted for inflation to $26,625,000 from January 1, 2025), buying, selling or sharing the personal information of 100,000 or more California residents or households, or earning half or more of revenue from selling it. Most early startups fall below these, but plan for them.
- Other states. Several other states have passed comprehensive privacy laws of their own, each with its own thresholds. The IAPP keeps a tracker.
- The FTC Act. The FTC enforces Section 5, which bars misleading or unfair practices, so a privacy policy that says one thing while the app does another is a risk.
- COPPA, if children may use the app. It covers services directed to children under 13, and general-audience services that know they collect personal information from a child under 13. It requires a privacy policy, direct notice to parents and verifiable parental consent before collecting, among other duties. The FTC amended the rule on April 22, 2025.

Write the policy from what your app actually does. List every service that receives user data, such as your database, Stripe, email, analytics and AI providers, and say what each gets. Terms of service and a refund policy are expected too: Lovable's built-in payments review looks for both, and Stripe shows your support details on receipts. A template is a fine start; a lawyer's review is worth paying for once money moves. Our overview of [which rules your product must meet](https://www.plutonapps.com/resources/which-rules-your-product-must-meet) covers GDPR and the rest, and health products should read [is Lovable HIPAA compliant](https://www.plutonapps.com/resources/is-lovable-hipaa-compliant).

## What else should be in place on launch day?

- Accessibility basics. Can someone use sign-up and checkout with only a keyboard, and read every label? Our guide to [ADA accessibility for AI-built apps](https://www.plutonapps.com/resources/ada-accessibility-ai-built-apps) shows how to check in an hour.
- App store listing, if you are shipping to phones. Store review and testing take extra time; see [taking a Lovable app to the App Store](https://www.plutonapps.com/resources/lovable-app-to-app-store).
- Backups. Supabase's docs list daily backups from the Pro plan up, kept for 7 days on Pro, and tell Free plan projects to export their data regularly. Our guide to [Supabase backups and disaster recovery](https://www.plutonapps.com/resources/supabase-backups-disaster-recovery) covers Lovable Cloud too, and how to rehearse a restore.
- Monitoring. An uptime check on your live address, with alerts that reach a named person's phone, not a shared inbox.
- A support address. Use support@ on your own domain, put it in Stripe's public details and your app's footer, and decide who answers it and how fast.
- A status page. Host it on a separate service, so it stays up when your app is down, and link it from your support replies.
- Entity and EIN. Whether to form an LLC or a corporation is a question for an accountant or lawyer. The IRS says you never have to pay a fee for an EIN, warns against websites that charge for one, and issues it immediately online once approved.

## When should you stop prompting and get help?

Prompting can write a privacy page or swap a key. It cannot tell you which states you owe tax in, or prove that a renewal, refund and dispute each change access correctly with live money. Get help when:

- Real customers are about to pay, and nobody has tested a renewal, a refund and a cancellation end to end.
- Customer data is involved and you are not sure your database rules keep each customer's data private.
- The same payment or sign-in bug has come back three times.
- A customer, a buyer's security team or an investor asks for evidence you cannot produce.

Our [vibe-coding rescue service](https://www.plutonapps.com/services/vibe-coding-rescue) is for apps in exactly this spot. The free [production-readiness check](https://www.plutonapps.com/tools/production-readiness-check) scores yours in a few minutes and names the biggest risks.

> **The engineering half** This list is the business side. Plutonapps engineers handle the other half on a monthly subscription: reviewing, fixing, testing and securing a Lovable app, then launching and running it, with named engineers you can talk to.

See [pricing](https://www.plutonapps.com/pricing) for what each plan includes.

## Sources

All checked on October 10, 2026.

- Stripe documentation: Go-live checklist, Set up your account, and API keys, on verification, public business details, live objects, keys and webhook signing secrets ([docs.stripe.com/get-started/checklist/go-live](https://docs.stripe.com/get-started/checklist/go-live); [docs.stripe.com/get-started/account/activate](https://docs.stripe.com/get-started/account/activate); [docs.stripe.com/keys](https://docs.stripe.com/keys)).
- Stripe: Introduction to US sales tax and economic nexus, on Wayfair, thresholds and SaaS taxability ([stripe.com/guides/introduction-to-us-sales-tax-and-economic-nexus](https://stripe.com/guides/introduction-to-us-sales-tax-and-economic-nexus)).
- Stripe documentation: Stripe Tax, and Register for sales tax, on threshold monitoring and registration ([docs.stripe.com/tax](https://docs.stripe.com/tax); [docs.stripe.com/tax/registering](https://docs.stripe.com/tax/registering)).
- Lovable documentation: Connect your own Stripe account, and Add payments to your app, on going live ([docs.lovable.dev/integrations/stripe](https://docs.lovable.dev/integrations/stripe); [docs.lovable.dev/features/payments](https://docs.lovable.dev/features/payments)).
- Lovable documentation: Google sign-in on Lovable Cloud ([docs.lovable.dev/features/google-auth](https://docs.lovable.dev/features/google-auth)).
- Google Cloud Help: OAuth app verification, Manage app audience, and Verification requirements, on publishing status, test users and brand verification ([support.google.com/cloud/answer/13463073](https://support.google.com/cloud/answer/13463073); [support.google.com/cloud/answer/15549945](https://support.google.com/cloud/answer/15549945); [support.google.com/cloud/answer/13464321](https://support.google.com/cloud/answer/13464321)).
- State of California, Department of Justice: press release of October 14, 2016, on CalOPPA, and the CCPA page, on who each applies to ([oag.ca.gov/news/press-releases](https://oag.ca.gov/news/press-releases); [oag.ca.gov/privacy/ccpa](https://oag.ca.gov/privacy/ccpa)).
- California Privacy Protection Agency: CCPA monetary thresholds, effective January 1, 2025 ([cppa.ca.gov/regulations/cpi_adjustment.html](https://cppa.ca.gov/regulations/cpi_adjustment.html)).
- IAPP: US State Privacy Legislation Tracker ([iapp.org/resources/article/us-state-privacy-legislation-tracker](https://iapp.org/resources/article/us-state-privacy-legislation-tracker)).
- Federal Trade Commission: Children's Online Privacy Protection Rule, and Complying with COPPA: Frequently Asked Questions ([ftc.gov/legal-library/browse/rules/childrens-online-privacy-protection-rule-coppa](https://ftc.gov/legal-library/browse/rules/childrens-online-privacy-protection-rule-coppa); [ftc.gov/business-guidance/resources/complying-coppa-frequently-asked-questions](https://ftc.gov/business-guidance/resources/complying-coppa-frequently-asked-questions)).
- Supabase documentation: Database backups, on backups by plan ([supabase.com/docs/guides/platform/backups](https://supabase.com/docs/guides/platform/backups)).
- Internal Revenue Service: Get an employer identification number ([irs.gov/businesses/small-businesses-self-employed/get-an-employer-identification-number](https://irs.gov/businesses/small-businesses-self-employed/get-an-employer-identification-number)).

## Frequently asked questions

### How do I switch my Lovable app's Stripe from test to live?

Verify your business in Stripe, recreate your products and prices in live mode, then ask Lovable to update your Stripe key and switch to the live price IDs. Add live webhook endpoints, which have their own signing secrets. Finish with one real purchase on the published app and refund it.

### Do I have to collect sales tax on my SaaS subscription?

It depends on the states your customers are in and how each taxes software. Most states require collection once your sales there pass an economic nexus threshold, often $100,000 or 200 transactions a year, and some do not tax SaaS at all. Stripe Tax can monitor thresholds, but you register with each state yourself or through Stripe. An accountant should confirm your obligations.

### Does a small app need a privacy policy?

Usually, yes. California's Attorney General says CalOPPA applies to any operator that collects personal information such as names or email addresses from California consumers, with no size threshold. Google's brand verification and Lovable's payments review also expect a privacy policy on your own domain.

### Why can only some people sign in with Google on my app?

If your Google Cloud project is in Testing status and asks for more than basic profile scopes, only up to 100 listed test users can sign in. Publish the app to In production in the Google Cloud console. Apps that ask only for name, email and profile are exempt from that limit.

### Do I need to pay for an EIN?

No. The IRS says you never have to pay a fee for an EIN and warns against websites that charge for one. You can apply online, and the number is issued immediately once approved. Whether you need one depends on how your business is set up, so check with an accountant.
