How a Non-Developer Vibe-Coded IvaBot: 9 Months, 3 Rewrites
October 7, 2026 · 1404 words
| Fact | IvaBot |
|---|---|
| What it is | SEO and AI-visibility tool: site audits, rank tracking, AI citation checks, SEO article builder |
| Builder | Non-developer (Galyna Arikh, 15 years in SEO) |
| AI tool | ChatGPT as a teacher for ~6 months, then Claude for development (which Claude product: not disclosed) |
| Stack | Supabase (auth + database), DataForSEO API, Stripe, GitHub; landing page first built in Webflow |
| Time to launch | ~9 months, at least 3 stack rewrites; launched April 29, 2026 |
| Revenue | First paying transaction in early May 2026; amount not disclosed (self-reported) |
| Pricing | Pay-as-you-go credits, no subscription; from $5 per the founder's post (the live pricing widget was unclear when checked) (pricing page) |
| Source | Indie Hackers post |

IvaBot launched on April 29, 2026 with live Stripe payments. Its first paying transaction came in early May. The founder, Galyna Arikh, is not a developer. Arikh has spent 15 years ranking sites on Google.
Getting there took about nine months and at least three stack rewrites. The monthly bill before the first sale was about $200. After moving the build to Claude, it dropped to about $40.
This post is about that path. The one point: for a non-developer, the expensive part is not the AI tool, it's the no-code glue you bolt around it.
The founder's background: deep domain, zero code
Arikh came to this as an SEO specialist. The Indie Hackers post describes 15 years of SEO work. It also lists project management and illustration. Arikh drew IvaBot's logo and homepage illustrations by hand.
That domain depth shows in the product. IvaBot has three modules that share one credit balance:
- Core Audit: technical SEO checks, Google positions, backlinks and a prioritised fix list.
- AI Readiness: tracks how ChatGPT, Perplexity, Gemini and Google AI mention your brand.
- Content Builder: drafts SEO articles from live Google search data.
The Google data comes from DataForSEO, a paid API (a service you call from code) that returns search results and keyword metrics.
At the start, Arikh did not know how to build any of this. A designer friend drafted a rough homepage for free. After that, by the founder's account, it was a solo build.
Tool choice: no-code first, then Claude

The first idea was a Telegram chatbot. Arikh dropped it. Plan B was a no-code stack, meaning tools you wire together without writing code:
- Webflow for the landing page
- Typebot for the chat-style decision flow
- Memberstack for logins
- Supabase for the database
- Make for webhooks (automatic messages one service sends another when something happens)
- SerpDev for SEO data
- Stripe for payments
Seven services, seven bills. That is how the cost reached roughly $200 a month before a single sale. Arikh called it unsustainable.
For about six months, ChatGPT was the teacher. Arikh used it to learn prompts, HTTP requests, JSON parsing, webhooks and working with a real database. None of that shipped a product on its own, but it gave the vocabulary to direct an AI coder.
Then development moved to Claude. In Arikh's words, "Build sped up significantly." The backend was rebuilt and the code went on GitHub. Typebot and Memberstack were removed, and logins switched to Supabase Auth. SerpDev was swapped for DataForSEO, which is pay-as-you-go.
The post does not say which Claude product was used (the chat app, the API or Claude Code). I'd treat it as "Claude" and nothing more specific.
Where the build got stuck
Three sticking points come through in the post.
Stripe webhooks. Arikh jokes that their partner is tired of hearing about them. Webhooks are where the payment tells your app "this person paid, give them credits". They are easy to get subtly wrong.
The AI editing stale code. The most costly Claude habit was editing from a version of a file it remembered. It should have fetched the current file from GitHub first. If you paste code into a chat window, this bites you fast.
Security, late. Arikh's list of regrets includes bolting security on later instead of thinking about it from day one. That one is worth pinning above your desk.
What the founder paid for help
The spending went to three places:
- No-code subscriptions: about $200 a month at the peak, before any revenue.
- AI: Arikh says next time they would skip Memberstack and spend that money on Claude credits instead.
- A security consultation. Arikh went through the app with a consultant, fixed the remaining issues with him, and reshaped parts so they can be maintained solo.
That last one is the most useful detail in the whole post. A non-developer shipped a paid SaaS with an AI coder. Then paid a human to check it.
What a non-developer should copy
Arikh's own "do differently" list, lightly condensed:
- Start a GitHub repo on the first day. Keep real code in version control instead of a no-code stack.
- Skip the paid auth add-on. Supabase Auth replaced Memberstack.
- Think about security from the start.
- Use the stronger AI coder earlier.
I'd add one from the post's distribution notes. Arikh says building gives an instant hit and distribution gives silence, so your brain always picks building. The fix was cold email, until it felt like a routine task before lunch. Nine months of building is a long time without that habit.
If you vibe-code this
IvaBot is the example here, not the subject of an audit. These are the checks I'd run on any credit-based SaaS built on Supabase, Stripe and a paid data API:
- Lock the credits table with RLS. Row Level Security (database rules on who can read or change each row) must stop users from updating their own balance. See Supabase RLS for vibe coders.
- Grant credits only from a verified Stripe webhook. Check the signature and store the event ID so a retry can't add credits twice. See Next.js Stripe webhook security.
- Deduct credits on the server, before calling the paid API. Add rate limits so one account can't drain your DataForSEO budget. See API rate limiting.
- Keep API keys server-side. Stripe secret keys, the Supabase service role key and data-API keys never go in browser code. See environment variables.
- Validate URLs users submit for audits. A tool that fetches user-supplied URLs needs guardrails. See SSRF in Next.js.
A minimal webhook that verifies the signature before granting credits:
// app/api/stripe/webhook/route.ts
import Stripe from "stripe";
import { createClient } from "@supabase/supabase-js";
const stripe = new Stripe(process.env.STRIPE_SECRET_KEY!);
const admin = createClient(process.env.SUPABASE_URL!, process.env.SUPABASE_SERVICE_ROLE_KEY!);
export async function POST(req: Request) {
const body = await req.text(); // raw body, needed for the signature check
const sig = req.headers.get("stripe-signature") ?? "";
let event: Stripe.Event;
try {
event = stripe.webhooks.constructEvent(body, sig, process.env.STRIPE_WEBHOOK_SECRET!);
} catch {
return new Response("Invalid signature", { status: 400 });
}
if (event.type === "checkout.session.completed") {
const s = event.data.object as Stripe.Checkout.Session;
// grant_credits inserts event.id into a UNIQUE column first, so retries can't double-credit
await admin.rpc("grant_credits", {
p_event_id: event.id,
p_user_id: s.client_reference_id,
p_credits: Number(s.metadata?.credits ?? 0),
});
}
return new Response("ok");
}
Want a second pair of eyes before you charge real money? I review vibe-coded Supabase and Stripe apps. Email [email protected] with your stack and what worries you.
Key takeaway
A non-developer with deep domain knowledge can ship a paid SaaS with an AI coder. Arikh's lesson is to skip the no-code glue, put real code in GitHub early, and budget for a security review before launch, not after.
More case studies: Vibe-coded apps making money · The security checklist: Vibe coding security
Sources
- Indie Hackers, "I'm a solo founder. It took me 9 months and at least 3 stack rewrites to ship my SaaS" (May 19, 2026): https://www.indiehackers.com/post/im-a-solo-founder-it-took-me-9-months-and-at-least-3-stack-rewrites-to-ship-my-saas-a66b5fbe33
- IvaBot homepage and pricing: https://ivabot.xyz/