Is Your Vibe-Coded App Getting Sued? What Actually Happens, Ranked by Likelihood
Is Your Vibe-Coded App Getting Sued? What Actually Happens, Ranked by Likelihood
Short version: you are probably not going to be sued. What actually reaches small web apps, in order of how often it happens, is a demand letter about the tracking scripts on your site — then, a long way behind, everything else.
There’s a video going around that lists ten ways your app is about to be sued and totals the damage at $135,157. The ten items are all real legal requirements. The number is not a number anyone is going to demand from you: roughly $106,000 of it consists of federal penalties that only the government can collect, and the federal government is not opening a file on an app with 400 users. Meanwhile the thing most likely to actually land in your inbox isn’t on the list at all.
So here is the honest ranking, most probable first. If you stop reading after the next section, you’ll have handled the majority of your real exposure. This is general information rather than legal advice, and it’s written for a business facing California users, which is most of them.
The most likely thing by far: a letter about your tracking scripts
If something legal happens to your small web app in the next year, this is overwhelmingly what it will be.
California has a wiretapping statute from 1967 — the California Invasion of Privacy Act — that plaintiffs’ firms have adapted to modern websites. The argument is that your analytics tool, ad pixel, chat widget, or session-replay script lets a third party intercept a visitor’s communications with your site without their consent. Statutory damages run to $5,000 per violation, and “per violation” is carrying enormous weight in that sentence.
This arrives as a letter, not a lawsuit. It comes from one of a small number of firms sending them at high volume, and the demand is typically sized to sit just below what it would cost you to fight it. That’s the business model, and it’s aimed at your Google Analytics tag, not at anything distinctive about your product.
It has become common enough that courts have started pushing back — in July 2026 a federal court in California declared one especially prolific filer a vexatious litigant, though the order was narrow and doesn’t stop the broader practice.
What this means practically: the single highest-value hour you can spend is auditing what third-party scripts load on your site and getting your consent banner and privacy disclosures to match reality. That one hour addresses your most probable legal event. Almost everything in the viral video addresses something less likely.
The one to fix today if it applies to you: chatbots
If your product includes a companion-style conversational AI, stop and handle this one.
California’s SB 243 took effect on January 1, 2026. It requires an actual protocol for users who express suicidal ideation or self-harm — including referring them to crisis resources — plus clear disclosure that the user is talking to a bot, and additional protections for minors. You can read the text directly; it’s short.
Two features make this different from most of the list. Any person injured by a violation can sue directly, for the greater of their actual damages or $1,000 per violation. And the statute shifts attorney’s fees, which is what makes a small case worth a lawyer’s time. It’s also new enough that a lot of shipped products simply haven’t caught up.
If you have a chatbot, this is the item on the list with the shortest path between “you’re non-compliant” and “someone is suing you personally.” It is also, unlike most compliance work, a genuine safety requirement — a user in crisis is the person the statute is actually about.
The tier below that: things that only become claims if something else goes wrong
A publicly readable storage bucket is not, by itself, a lawsuit. It becomes one when data comes out of it.
California lets consumers sue when unencrypted personal information is exposed because a business failed to maintain reasonable security, with statutory damages of $100 to $750 per consumer, per incident. Note the trigger: an actual breach, not merely a sloppy configuration. There’s also a written-notice-and-cure mechanic that can defeat statutory damages if you fix the problem in time.
So misconfiguration belongs on your list — but as a thing that converts other people’s bad day into your legal problem, not as a standing claim against you today.
The rest of the list: real rules, but a different enforcement path
Here’s the distinction the viral video flattens, and it’s the reason its total is misleading.
Some rules come with somebody who is paid to find you and enforce them. Others only get enforced if a government agency decides to open a file on your company. Both kinds are binding law. Only one kind produces a letter next Tuesday.
Most of what’s on that list is the second kind. Not having a privacy policy, not disclosing the categories of data you collect, not mentioning AI or third-party recipients in your policy, not honoring deletion requests — all real obligations under California privacy law, all enforced by the Attorney General or the California Privacy Protection Agency, and none of them giving an individual user a direct claim against you for the violation itself.
The two biggest dollar figures in the video are in this category:
Fake testimonials. The FTC’s rule on consumer reviews and testimonials has been in force since October 2024. It reaches invented reviews, buying positive or negative reviews, undisclosed insider reviews, and fake indicators of social-media influence. The per-violation penalty exceeds $50,000 and adjusts annually — and it is collected by the FTC, not by your users. The FTC’s plain-language Q&A is genuinely readable. Fix this anyway; the fix is free and takes ten minutes.
Making cancellation harder than signup. Same category, and currently in flux — see below.
None of this is permission to ignore them. Regulatory risk is real, it compounds as you grow, and “we were small” stops working as a defense at some point. But if you’re triaging with limited hours, put these after the tracking audit.
What’s actively changing right now
Three moving pieces, because a lot of published advice on these is already out of date.
Click-to-cancel is gone, but California’s version isn’t. The FTC’s federal rule requiring cancellation to be as easy as signup was vacated by the Eighth Circuit in July 2025, days before it took effect, on procedural grounds. The FTC restarted the rulemaking in March 2026, so something will likely return. But California’s Automatic Renewal Law still applies and was strengthened effective July 1, 2025 — expanding coverage to free trials that convert to paid and tightening the rules on obstructing cancellation. If you sell subscriptions to Californians, the federal rule’s disappearance changed almost nothing for you.
CIPA reform just cleared the Legislature — but it isn’t law yet, and it isn’t a full fix. On August 28, 2026, both chambers passed SB 690, which now sits on the Governor’s desk (sign or veto by September 9). The final version is far narrower than early drafts: it would end private suits under one specific provision — the pen-register theory behind much of the recent letter wave — leaving enforcement of that provision to the Attorney General, and if signed it would reach pending pen-register claims retroactively. The wiretapping section, the other workhorse of these letters, is untouched, and you should expect demand letters to lean on it harder. So if you’ve heard California is about to end the demand-letter problem: not quite. If signed, one popular lane closes January 1, 2027; the letters keep coming through the other one.
AI-specific privacy obligations are still settling. Disclosure of automated decision-making and AI use in privacy policies is an area with active rulemaking. Write your policy to describe what you actually do, and expect to revisit it.
So what do you actually do?
Ranked the same way — by how likely it is to reach you, not by how large the number sounds:
- Audit what loads on your site. Every analytics tag, ad pixel, chat widget, session-replay tool. Then make your consent flow and privacy policy describe it accurately. This is your most probable legal event and it’s mostly configuration work.
- If you have a companion chatbot, address SB 243 now. Direct claims, fee-shifting, and a compliance gap across a lot of shipped products.
- Check your storage and access configuration — because a breach converts it into a claim.
- Fix your cancellation flow if you sell subscriptions to Californians.
- Make your privacy policy accurate. What you collect, who receives it, whether AI touches user data, how deletion works. The bar is accuracy, not eloquence.
- Delete any testimonial you can’t substantiate. Fastest item here.
Notice what’s mostly not on this list: lawyers, litigation, and large sums of money. This is configuration and disclosure work. Which is the real headline — it is dramatically cheaper to be roughly right before launch than precisely wrong afterward.
What do you do next?
If you’re pre-launch or recently launched, this is a bounded piece of work: a handful of documents and a review of what your site actually does. Worth handling before traffic arrives rather than after a letter does. If it’s useful to have someone walk your specific stack, that’s work I do on a flat fee.
One thing to be straight about: if you’ve already received a demand letter, that isn’t work I take on right now. You need someone who handles active disputes, and you need them promptly rather than after a consultation with me. This piece is written for the founder who hasn’t gotten one yet.
If you’re earlier than all of this and working out what a young company needs and when, I’ve mapped that sequence in the founder’s legal stack, and the contracts side of it separately.
This article is general information, not legal advice, and reading it does not create an attorney-client relationship. The law here is moving quickly — several items above were amended, vacated, or introduced within the last eighteen months. Your specific facts matter; confirm current requirements with the relevant authorities or your own advisor. Law Office of Ian Daily.