How to Avoid App Development Scams in Nigeria

App projects involve the largest sums most Nigerian SMEs will spend on a single technology purchase, and the work stays invisible longer than on a website project. That combination attracts both fraud and overselling, and it makes the difference between the two hard to spot until several million naira have moved.
The checks that matter are specific to apps. A portfolio is easy to borrow, a clickable prototype is easy to mistake for a working product, and an app published under someone else's developer account can be taken away from you. Each has a simple countermeasure.
Why app projects carry extra risk
- The sums are large. Indicative 2026 ranges run from ₦1,500,000–₦5,000,000 for a simple MVP, ₦5,000,000–₦15,000,000 for a medium app with accounts, payments, notifications and an admin dashboard, and ₦15,000,000 upwards for marketplaces, fintech and multi-role platforms. Indicative only; quotes vary with scope, team and exchange rate.
- You are buying three things. The app, the backend that serves it, and the admin dashboard. A demonstration of the app alone can hide the fact that the other two do not exist.
- Demos can be illusions. A design prototype can be made to look like a functioning app, with taps moving between screens and nothing behind them.
- Store accounts create leverage. An app published under a developer's account is not straightforwardly yours, and the signing key controls who can issue updates.
Common app development scams and bad-faith practices
| Pattern | How it presents | What exposes it |
|---|---|---|
| Borrowed portfolio | Screenshots of well-known apps they did not build | Check the publisher name on the store listing |
| Prototype passed off as a build | A "working app" that only moves between screens | Ask it to save data and reopen it later |
| Missing backend | App looks complete, data does not persist or sync | Ask to see the admin dashboard and a live database |
| Reskinned template | A generic template app rebranded and sold as custom | Ask what was built from scratch and what was licensed |
| Store account in their name | "We will publish it under our account" | Insist on your own Google Play and Apple accounts |
| Keystore withheld | You cannot publish updates without them | Require the signing key at handover, with backup |
| Deposit and delay | Large upfront, then months of "final testing" | Milestone payments against installable builds |
| Undisclosed subcontracting | Work resold to a cheaper team without your knowledge | Require disclosure in the contract |
| Feature bait | Very low quote omits payments, notifications, admin | Compare quotes on one identical written scope |
| Fake traction claims | Invented download or user numbers for past apps | Store listings show ratings and review dates |
| Equity-for-build offers | "We build free for 30% of the company" | Treat as an investment decision, not a discount |
| Perpetual maintenance charge | Monthly fees with no defined service | Require a written support scope and response times |
How to verify a portfolio app is genuinely theirs
This is the highest-value hour you will spend, and it requires no technical skill.
- Ask for the exact app names, not screenshots. A vendor unwilling to name the apps has told you something.
- Find each app on Google Play or the App Store. Look at the publisher or developer name on the listing. It will usually be the client's business or the agency's registered name.
- Tap the developer name to see the other apps published under that account. A development agency's own account typically shows several apps; a business's account shows only theirs.
- Download and use the app. Register, complete the core action, and see whether it is a finished product or a shell.
- Check the update history. The listing shows the last update date and recent release notes. Apps that have been maintained show regular updates.
- Read the reviews, including the one-star ones, and any developer responses. They reveal how the product actually performs and whether anyone supports it.
- Ask what they built. Many agencies join a project midway or handle only the app layer. "Which parts did your team write, and who else worked on it?" is a fair question with an informative answer.
- Contact one of the client businesses yourself. Find the business independently and ask whether the vendor delivered, whether the code and accounts were handed over, and whether support continued after launch.
If the apps cannot be found in either store, ask why. There are legitimate reasons — internal enterprise apps, apps withdrawn after a contract ended, or work under a non-disclosure agreement — and a genuine vendor will explain and offer an alternative demonstration, such as a test build you can install.
Warning signs before you pay
- Portfolio consists of design images rather than installable apps or store links
- Publisher names on the store listings do not match the vendor or their stated clients
- Demand for more than half the project value before any installable build exists
- Payment requested to a personal account with no invoice or registered company
- Reluctance to let you open store accounts in your own business name
- No mention of the backend, the admin dashboard or hosting in the quote
- Refusal to give you access to the code repository during development
- A quote far below every other quote for the same feature list
- Promises of App Store features, guaranteed downloads or guaranteed investor interest
What a cheap app quote usually leaves out
A quote that looks dramatically cheaper is usually pricing a smaller object. Ask specifically whether each of these is included:
- Backend development: APIs, database, business logic, hosting configuration
- Admin dashboard: the web panel your staff use to manage orders, users or content
- Both platforms: Android and iOS, or one only
- Payment integration: card, transfer, USSD and the failure and refund paths
- Push notifications: setup on both platforms and the sending mechanism
- Testing: QA across multiple real devices, not one phone
- Store submission: listing assets, privacy policy, data-safety declarations, resubmissions after rejection
- Source code delivery and documentation
- Warranty period for defect fixes after launch
- Recurring costs: hosting, notification services, SMS, maps, store fees, all usually billed in US dollars
A quote with half of these missing is not cheaper; it is incomplete. Put the full list into your request for proposals so every vendor prices the same thing, and compare two or three written quotations on that identical scope.
Proof of progress that cannot be faked
Four forms of evidence are difficult to manufacture. Build them into your milestones.
1. An installable build on your own phone. From week three or four, ask for an APK or an internal testing track on Google Play, and TestFlight for iOS. Install it yourself. Then test persistence: create a record, close the app fully, reopen it. If the data is gone, you are looking at a prototype rather than a working product.
2. Repository access from day one. Create the code repository under a company account and add the vendor as a collaborator. You do not need to read the code. You need to see commits arriving steadily, by named people, throughout the project.
3. The admin dashboard. Ask for a login to the web admin panel. Create an item there and confirm it appears in the app. This single test proves that a real backend exists and that the app is connected to it.
4. A staging environment you control. Hosting under your own cloud account means the server, database and logs are yours. It also means a vendor cannot switch off your system during a dispute.
Ask for these as milestone deliverables in the contract rather than as favours during the project.
Store accounts, signing keys and cloud access
Set these up in your business's name before development starts.
| Asset | Why it matters | Who should hold it |
|---|---|---|
| Google Play developer account | Owns the listing, reviews and release history | Your business |
| Apple Developer Program account | Same, plus certificates for iOS builds | Your business |
| Android signing key or keystore | Without it you cannot publish updates to your own app | Your business, backed up securely |
| Cloud hosting and database | Runs the backend; holds your customer data | Your business, with billing under your account |
| Payment gateway account | Receives your customers' money | Your business only |
| Push notification and messaging services | Sends notifications to your users | Your business |
| Code repository | Holds the work you are paying for | Your business, vendor as collaborator |
Google Play developer registration has historically been a one-time US$25 fee, and the Apple Developer Program an annual fee, historically US$99. Verify current fees, identity requirements and organisation verification rules directly with Google and Apple, as these change. Allow time: business verification can take days, and it is better done in week two than the week before launch.
Two consequences worth understanding. If the app is published under a vendor's account, transferring it later depends on that vendor cooperating with a store transfer process. And if the vendor holds the Android signing key and will not release it, updating your published app becomes difficult, which is exactly the leverage you do not want to hand over.
Payments and contract terms for app projects
A defensible structure for a multi-million naira app build:
| Milestone | Deliverable you verify | Indicative share |
|---|---|---|
| Kick-off | Signed contract, written MVP scope, project plan | 20–25% |
| Design approval | Screen designs and a clickable prototype | 15% |
| Backend milestone | Admin dashboard login that works | 20% |
| App build milestone | Installable build with the core flow working | 20% |
| Acceptance | Defects closed to the agreed severity level | 10–15% |
| Launch and handover | App live, accounts, keys and code transferred | 10% |
| Retention | Released after the warranty period | 5–10% |
Indicative structure; terms vary by vendor and project size.
Contract clauses that matter most on app projects: written MVP scope with an out-of-scope list; intellectual property assignment of the custom code on payment; source code delivered to a company-owned repository throughout, not at the end; store accounts and signing keys in your name; a list of third-party libraries and their licences; a warranty period of 30–90 days; a defined support scope with response times; subcontracting disclosure; and termination terms stating exactly what you receive if the project ends early. Have a Nigerian lawyer review the agreement; this article describes commercial risk rather than legal advice.
Equity, revenue-share and "we will build it for a stake" offers
These are not automatically bad, but they are investment decisions, not discounts. Before agreeing:
- Value the work in naira first, so you know what the equity is actually buying.
- Establish what happens if the developer loses interest after launch, and whether the stake returns.
- Confirm in writing who owns the code and accounts under that arrangement.
- Take legal advice before signing anything that transfers shares in a CAC-registered company.
A common outcome is a business that owns a half-finished app and a shareholder who no longer participates. Structure it properly or pay cash.
Example (hypothetical): the ₦2.5 million marketplace app
Example (hypothetical). A Lagos entrepreneur wants a two-sided marketplace app connecting artisans to customers, with in-app payments, ratings and an admin panel. Quotes come in at ₦14,000,000, ₦11,000,000 and ₦2,500,000. She accepts the lowest, paying 70% upfront.
Month two brings a polished demo: screens move smoothly, profiles look complete. She approves the next payment. Month four brings "final testing". Month six brings silence.
An independent developer reviews what exists: a design prototype with no backend, no database, no admin panel and no payment integration. Nothing was ever committed to a repository, because there was no repository.
The checks that would have exposed this within three weeks, at no cost:
- Looking up the vendor's claimed apps on Google Play and finding that the publisher names belonged to unrelated companies
- Requesting an installable build in week three, creating a profile, closing the app and reopening it to see whether the data persisted
- Asking for an admin dashboard login and trying to create a test artisan account
- Creating the repository under her own account and watching for commits
- Paying 25% at kick-off rather than 70%
The instructive point is the price gap. A ₦2,500,000 quote against ₦11,000,000 and ₦14,000,000 for a marketplace with payments was not a bargain; it was a different product, or no product. When one quote sits far outside the range, ask what has been excluded before assuming you have found efficiency.
If it has already gone wrong: what you can salvage
- Stop payments, including any recurring charge or standing order.
- Secure access. Change passwords on accounts you control, remove vendor access, and download any code, designs, database exports or assets you can reach.
- Establish what exists. Pay an independent developer for a short technical review: is there a repository, a backend, a database with real records, a usable codebase? A few hundred thousand naira here prevents a larger decision made blind.
- Collect evidence — proposal, invoices, transfers, contract and messages, exported with dates — then send a formal written demand to the registered address and email, stating what was paid, what is outstanding and a deadline for delivery of the code, accounts and keys.
- Take legal advice on recovery, particularly where a contract with an IP assignment clause exists, and report suspected fraud to the Nigeria Police Force, or the EFCC for online financial fraud.
- Decide rebuild versus repair honestly. Where a codebase is genuinely incomplete or poor quality, a clean rebuild on a properly structured contract is often faster and cheaper than paying a second team to untangle the first team's work. Get that assessment in writing before committing.
What changes for Nigerian businesses
- Large sums move by bank transfer. There is no chargeback, so payment staging carries the weight that consumer protections carry elsewhere.
- Store verification requires documents. Registering as a business on Google Play or Apple may require identity and organisation details; have your CAC documents ready and allow processing time.
- Payment integrations must be tested for real. Card, transfer, USSD and wallet flows through Paystack, Flutterwave, Interswitch, Moniepoint or OPay behave differently in an app. Run a live low-value transaction, a deliberate failure and a refund before accepting the milestone.
- Dollar-denominated running costs. Cloud hosting, notification services, SMS, maps and AI APIs are billed in US dollars. Require these to be itemised at quotation and billed to accounts you own, so no one can inflate "server costs" later.
- Informal arrangements are common. Many capable Nigerian developers work in small teams without elaborate corporate structures. That is not a warning sign in itself. The warning sign is resistance to a written contract, staged payments or company-owned accounts.
- Referrals are not due diligence. A recommendation from a trusted contact tells you the vendor delivered for someone once. It does not replace checking the store listings and the contract terms.
- Data protection is your obligation. Apps collecting personal data engage the Nigeria Data Protection Act 2023, and both stores require accurate data declarations. Check the Nigeria Data Protection Commission's current guidance and confirm your obligations with a qualified professional.
Mistakes to avoid
- Accepting screenshots or screen recordings as evidence of a working app. Install it yourself.
- Letting the vendor publish under their developer account. Your listing, reviews and update rights should be yours.
- Paying most of the money before an installable build exists.
- Ignoring the backend in the quote. The invisible part is usually the larger part of the work.
- Assuming a portfolio is theirs. Check the publisher name on every store listing.
- Agreeing equity without valuing the work first.
- Treating the build price as the total cost. Maintenance runs at an indicative 15–25% of build cost per year, plus hosting and store fees.
Conclusion
App fraud in Nigeria relies on the work being invisible. Remove the invisibility and most of the risk disappears: check every portfolio app on the store listing, insist on an installable build you can test in the first month, require a company-owned repository with steady commits, log into the admin dashboard yourself, keep store accounts and signing keys in your business's name, and release payments only against deliverables you have personally verified. These steps cost nothing and are the difference between a difficult project and a total loss.
If you are evaluating app proposals and want help checking the scope, the technical claims and the ownership terms before you commit, Linestech can review what you have been quoted and explain what a properly structured app engagement should include.
Frequently asked questions
How can I tell whether a demo is a real app or just a design prototype?
Ask to install it and then test persistence and connectivity. Create an account or a record, close the app completely, reopen it and see whether your data is still there. Turn off mobile data and see how it behaves. A prototype cannot save information or respond to a real server; a working build can.
Should the developer publish the app under their account to save time?
No. Open your own Google Play and Apple developer accounts, even though it takes a few days and a fee. The listing, the reviews, the update rights and the user relationship should belong to your business. Transferring an app between accounts later is possible but depends on the other party cooperating.
Is a Nigerian developer riskier than an overseas agency?
Location is not the risk factor; verification is. A Nigerian vendor you can check through CAC, meet in person and whose clients you can call is often easier to hold accountable than a remote overseas firm. The same protections apply either way: written contract, staged payments, company-owned accounts and repository access.
What is a realistic price for an app in Nigeria?
Indicative 2026 ranges are ₦1,500,000–₦5,000,000 for a simple MVP, ₦5,000,000–₦15,000,000 for a medium app with accounts, payments, notifications and an admin dashboard, and ₦15,000,000 upwards for marketplace, fintech or real-time platforms. These are indicative only. Judge a quote by the scope it covers, not by the headline figure.
What if my developer will not release the source code?
Check your contract for an intellectual property assignment clause and a source code delivery clause, then make a written demand referencing them. The situation is largely avoided by having the repository under your company account from the start, with the vendor as a collaborator, so the code accumulates in your possession as it is written.
Can I recover an app if the developer holds the signing key?
It is difficult. Without the original Android signing key you generally cannot publish an update to the existing listing, and the practical route may involve publishing as a new app and asking users to install it again. That is why the key belongs in your custody, with a secure backup, from the first release.
How much should I pay upfront for an app project?
A kick-off payment of roughly 20–25% is a defensible norm for a custom app build, with further payments released against verified deliverables — an admin dashboard you can log into, an installable build you have used — and a 5–10% retention after the warranty period. Requests for 50% or more before any deliverable exists warrant hard questions.
Sources and further reading
Figures, platform rules and regulations change. These are the primary references behind this article and the places to check before you act on it.


