Mobile Apps

App Source Code Ownership: Who Really Owns Your App?

Paying for an app doesn't make you its owner. Here's how IP assignment, accounts in your name and a complete code handover secure source code ownership.

Emrah KaragözEmrah KaragözFounderSeptember 28, 202616 min read

App source code ownership rests on three things, not one: a signed, written assignment of the copyright to your company, a code repository and app store accounts registered in your name, and a handover package that actually builds. A zip file of code on its own doesn't make the app yours.

Most founders only discover a missing piece when the relationship with their developer ends. The contract says "source code will be delivered," but it never says which repository, which version, which keys or which rights. The app sits in the agency's App Store account, the code arrives as an archive, and the new team can't get it to compile.

This guide covers what the law says about source code ownership in the US, the UK and Turkey, what a complete handover package contains, how app store transfers work when you switch agencies, when source code escrow makes sense, and the contract clauses that prevent all of this. It's written from the agency side of the table, by a team that includes code delivery as a standard clause in every project.

Note: This article is general information, not legal advice. For a contract or a dispute, talk to a lawyer who works on software and intellectual property in your jurisdiction.

Table of Contents

What Source Code Ownership Actually Means

Source code is the human-readable text your developers write in Swift, Kotlin, Dart or JavaScript. What you download from the App Store or Google Play is the compiled version of that code. Owning only the compiled app is like owning the keys to a building without its blueprints: you can live in it, but you can't renovate it.

An app is also more than the package on a phone. Behind it sit a backend, a database, store listings, signing keys, third-party service accounts and design files. When you think about source code ownership, think about all of those pieces together.

Ownership matters most at three moments:

  • Maintenance: iOS and Android ship new versions every year and store rules keep changing. Without the code, every update depends on one vendor. Our guide to app maintenance costs breaks down what that ongoing work involves.
  • Switching developers: Agencies close, teams scatter and relationships sour. A new team can only pick up where the old one stopped if the handover is complete.
  • Fundraising and acquisition: Investors and buyers check whether you actually own the code and the rights to it.

What's inside the code matters too. Black Duck's 2026 OSSRA report analyzed 947 commercial codebases across 17 industries. Open source components appeared in 98% of them, and the share of codebases with license conflicts jumped from 56% to 68% in a single year (Black Duck). Saying "we have the code" isn't enough; you also need to know which components it contains and under which licenses.

Holding the Code Is Not the Same as Owning It

The most common misunderstanding about source code ownership is treating file delivery and rights transfer as the same event. In most legal systems they're separate.

United States. Copyright vests in the author, and for a "work made for hire" the employer or commissioning party counts as the author (17 U.S.C. § 201). But the statutory definition covers two cases: work by an employee within the scope of employment, and specially commissioned work in nine listed categories, such as a contribution to a collective work or a compilation, and only when both parties sign a written agreement (17 U.S.C. § 101). Custom software from an outside agency doesn't fit neatly into those categories. That's why careful contracts add a written assignment instead of relying on "work for hire" wording alone. Under § 204(a), a transfer of copyright ownership "is not valid unless" it's in writing and signed by the owner of the rights.

United Kingdom. The author is the first owner of copyright, and an employer owns work an employee creates in the course of employment (CDPA 1988, s.11). A contractor is not an employee, and an assignment "is not effective unless it is in writing signed by or on behalf of the assignor" (s.90(3)).

When the contract is silent. Paying the invoice doesn't, by itself, move the copyright to you. Depending on your jurisdiction and the facts, you may end up with an implied license to use the app but not the right to modify, resell or relicense it. Ambiguity works against the client, so write ownership down.

For the wider picture, including NDAs and trademarks, see our guide on how to protect your app idea.

What a Complete Handover Package Includes

"We sent you the source code" can mean anything from a folder of files to a fully reproducible project. Use this table to define and verify the handover.

ItemWhy you need itHow to verify it
Git repository with full commit historyShows who changed what, when and whyIs the repo in your organization account, with complete history?
Mobile app code (native, Flutter or React Native)The only way to ship updatesDoes it build and run from scratch on a clean machine?
Backend code and API docsThe app doesn't work without its serverAre endpoints documented, and does a test environment start?
Database schema and a current backupUser and business data belong to youCan you restore the backup into a test environment?
Environment variables and secrets inventoryThe code won't run without these valuesIs the list complete, and have values been rotated to keys you control?
Build and CI/CD configurationMakes releases repeatableCan the new team ship a release by following the docs?
Signing keys and certificatesNeeded to publish updates to the storesDo you hold the Android upload key, and do iOS certificates live in your account?
Third-party service accountsMaps, SMS, payments, push notificationsIs your company the owner of every account?
Design source files (Figma, etc.)Keeps new screens consistentHave the files moved into your workspace?
Open source license inventoryCatches license conflicts earlyIs every dependency listed with its license?
README, setup and architecture docsShortens onboarding for the next teamCan one developer set up the project alone from the docs?

The single most important check is the build test. Ask an independent developer to compile the delivered code on a clean machine and compare the result with the version live in the stores. Code that doesn't build hasn't really been handed over.

Close the handover with a signed delivery note. List the repository URL, the final commit hash, the store version number, the accounts transferred and any open issues. That one page ends future arguments about "which version did you receive" and ties your IP assignment to a specific codebase.

Whose Name Is on the Accounts?

Account ownership is as important as source code ownership. Even with the code in hand, if the app lives in the agency's store account, its users, ratings and reviews are attached to that account.

  • Apple Developer Program: Organizations need a D-U-N-S Number to enroll, and Apple displays your organization's name as the seller on the App Store. Membership costs 99 USD per year (Apple Developer). If the agency publishes from its own account, its name shows as the seller.
  • Google Play Console: Organization accounts must provide a D-U-N-S number at signup (Play Console Help). Open the account in your company's name and grant the agency only the permissions it needs.
  • Code repository: Create the organization on GitHub, GitLab or Bitbucket yourself and add the agency as members. The code then accumulates in your account from day one.
  • Cloud and Firebase: Servers, databases and Firebase projects should sit under your billing account, with the agency invited as members. We compare the trade-offs in Firebase vs a custom backend.
  • Domain and email: Your API address, privacy policy page and support email usually depend on a domain. Register it in your company's name so an expired agency-held domain can't take your backend offline.

If the app isn't live yet, setting up accounts correctly costs almost nothing. Our free app launch checklist walks through the pre-launch steps, and how to publish an app covers the store process in detail.

How to Switch Agencies Without Losing Your App

Done well, a developer switch is invisible to your users. This sequence keeps the code and account transfers in step.

  1. Review the contract and payments. Check which event triggers the IP assignment, such as delivery or final payment. An open payment dispute is the most common blocker.
  2. Build an inventory. List every item from the table above and write down its current owner.
  3. Transfer the repository. When you transfer a GitHub repository, its issues, pull requests, wiki and commit history move with it. Webhooks, secrets and deploy keys also stay associated after the transfer (GitHub Docs), so rotate them right away.
  4. Run the build test. Have the new team compile from scratch and compare with the live version.
  5. Start the App Store transfer. The sending account's Account Holder initiates it and the receiving Account Holder accepts. The app stays on the store during the transfer, keeps its ratings, reviews and Bundle ID, and users keep receiving updates (Apple Developer).
  6. Start the Google Play transfer. Users, statistics, ratings, reviews and the store listing move to the new account; some financial reports don't, so download them first. A new developer account costs a US$25 registration fee, and if you're worried about the old upload key, the target account can request a new one (Play Console Help).
  7. Revoke access and rotate credentials. Remove the previous team from cloud, store and service accounts, then change API keys and passwords.
  8. Hold a knowledge-transfer session. Architecture decisions, known bugs and technical debt rarely make it into the docs. A few hours between the old and new teams can save weeks.

Apple's criteria require at least one version released on the App Store, no pre-order or in-review status, and current agreements accepted on both sides (Apple Developer). Apps that use keychain sharing force users to sign in once more after the first update, and apps with Sign in with Apple need extra preparation to migrate users. Put these details in the plan from the start.

Three Ways Businesses End Up Without Their Code

These composite scenarios show what typically happens when source code ownership is left vague. They're illustrative and don't describe any specific company.

Scenario 1: The agency is gone and the app is in its account. A restaurant group commissions a loyalty app, and the agency publishes it from its own App Store and Google Play accounts. When the agency shuts down, nobody can reach the Account Holder who would have to start the transfer. Because both stores require the sending account to act, the usual fallback is to publish a new listing from your own account. Ratings and reviews reset, and every user has to download the new app.

Scenario 2: The code arrived but won't build. The folder contains the app code, but dependencies from a private package registry, environment variables or signing keys are missing. The new team spends its first weeks just getting the project to run, and rewrites parts of it along the way. A simple update turns into a project.

Scenario 3: The code depends on the agency's proprietary platform. Some agencies build every project on their own framework or admin panel. Without a perpetual, transferable license to that platform, you can't run the app independently, even if you hold the rest of the code.

The common exit in all three is a partial or full rewrite. Code reverse-engineered from a compiled app is no substitute for maintainable source. To get a rough budget range for a rebuild, try our app cost calculator.

Is Source Code Escrow Worth It?

Source code escrow means a neutral third party holds the code and releases it to you when a defined event occurs, such as the vendor going out of business. Pricing is published by some providers: one escrow provider lists 139 USD per month per application (billed annually) plus a 249 USD setup fee for a single agreement (Codekeeper).

In Turkey, the national standards institute TSE offers a source code escrow service. According to its description, the vendor uploads the latest version encrypted with AES-256, and release starts when the customer submits a court decision confirming the contract conditions have been met (TSE, in Turkish).

SituationBest fit
Custom app built for you, with IP assigned to youRepository in your account from day one; escrow is unnecessary
Licensed off-the-shelf software (ERP, industry package)Escrow makes sense; the vendor keeps the code but deposits it
Project built on the agency's proprietary platformLicense for the platform plus escrow
Business-critical SaaSEscrow for code and data, plus regular data exports

In short, escrow protects you in licensing relationships where you'll never own the code. When the code and the IP are supposed to be yours, the simplest and cheapest safeguard is a repository that lives in your account from the first commit.

Outsourcing to Turkey: What Changes

Turkey is a popular nearshore destination, and its copyright law is strict about form. Under Article 52 of the Law on Intellectual and Artistic Works (FSEK), contracts on economic rights must be in writing and must list each right separately (FSEK, in Turkish). A vague "all rights belong to the client" sentence is weaker than a clause that names adaptation, reproduction, distribution, performance and communication to the public (FSEK Articles 21-25).

Three more points matter for source code ownership:

  • Who is the author: Turkey's copyright directorate states that the author of a computer program is the person or people who wrote its source code, and that someone who commissioned and paid for a program can't register it in their own name (Telif Hakları Genel Müdürlüğü, in Turkish).
  • Modification rights: FSEK treats adapting or modifying a computer program as an adaptation (Article 6), and Article 55 says a transfer of economic rights doesn't cover adaptations unless agreed otherwise. Make sure the adaptation right is listed explicitly.
  • Employees and freelancers: Under Article 18, rights in work that employees create on the job are exercised by the employer unless agreed otherwise. Freelancers are different, and Article 49 says a party that acquired a right can pass it on only with the author's written consent. Ask your agency to confirm it holds the rights from every subcontractor.

For rates, time zones and vendor selection, read our guide to outsourcing software development to Turkey.

8 Clauses to Put in Your Development Contract

Almost every source code ownership problem can be solved before you sign. Ask for these clauses at the proposal stage:

  1. IP assignment: All copyright and economic rights, listed individually and including the right to modify, assigned without time or territorial limits. State when the assignment takes effect, for example on delivery or final payment.
  2. Definition of deliverables: Define "source code" using the handover table above. The format is a repository with commit history, not a zip file.
  3. Continuous access: Development happens in a repository under your organization from day one; don't leave delivery until the end.
  4. Pre-existing components: If the agency reuses its own libraries or platform, you get a perpetual, transferable license that includes the right to modify.
  5. Open source inventory: The agency lists every dependency and its license at delivery and flags anything that could restrict commercial use.
  6. Subcontractors: The agency warrants it has written assignments from every freelancer or subcontractor who touched the code.
  7. Account ownership: Store, cloud, domain and third-party accounts are opened in your company's name.
  8. Exit assistance: When the contract ends, the agency supports the transition to a new team for a defined period and rate.

A maintenance agreement doesn't mean the agency should keep the code. A healthy setup is one where you own the code and the agency provides a service on top of it. For the rest of your vendor checklist, see how to choose a software development company and our guide to hiring a mobile app developer.

Frequently Asked Questions

Who owns the source code of an app I paid for?

By default, the author owns the copyright, which usually means the agency or the developers who wrote it. You own the source code only once a written, signed agreement assigns the rights to your company.

Is custom software a "work made for hire" in the US?

Only in limited cases. Under 17 U.S.C. § 101, commissioned work qualifies only in nine listed categories and with a signed written agreement, so software contracts usually add a written copyright assignment as well.

Does the developer have to give me the source code?

Only if the contract says so. If it's silent, the outcome depends on the jurisdiction and the facts, and you may end up with a right to use the app but not to modify it. Put code delivery and IP assignment in writing.

What should a source code handover include?

A repository with full history, backend code, database schema and backup, a secrets inventory, build configuration, signing keys, third-party accounts, design files, an open source license list and setup documentation. The package should build on a clean machine.

Will my app disappear from the stores if I switch agencies?

No, not with a proper transfer. On Apple, the app stays available and keeps its ratings and reviews; on Google Play, users, ratings and reviews move to the new account. The sending account has to start the transfer.

Do I need source code escrow?

Escrow makes sense for licensed software where the vendor never hands over the code. For a custom app whose IP is assigned to you, a repository in your own account from day one is simpler and cheaper.

Is source code delivery an extra cost?

It varies. Some proposals price code delivery as a separate line item, so ask in writing whether source code delivery and IP assignment are included in the quote.

Source code ownership is settled at the contract stage, not after launch. A written IP assignment, accounts in your company's name and a handover package that builds give you quiet insurance when the relationship goes well and a way out when it doesn't.

At Master Web, source code delivery is a standard clause in our mobile app development and web software development projects, and the app is yours. If you're planning a handover or want to start a new project on the right contract, get in touch.

#source code ownership#software ip assignment#source code escrow#switching developers#app handover

Need professional help with this?

Talk to our team about your project — same-day response, free quote.

Share this post

Related Articles