I changed my GitHub account name. I did it thinking it was the right move.

The result: the privacy policy and terms of service for all 3 of my released apps went 404, and I could no longer submit to Google Play review.

And I didn’t notice until several days after I broke it. The whole time, every user in closed testing was hitting a 404.

Why I renamed the account

Because my real email address was still sitting in my commit history.

When you’re doing indie development, it’s easy to fire off your first commit with git config left at whatever it was, and your real name and personal email get carved into the log. The moment you make the repository public, anyone can read it.

I renamed the account to get rid of that. I still think that decision itself was correct. Leaving personal information in a commit log forever is by far the bigger risk.

The problem wasn’t making the change. It was never once checking what the change would break.

What broke

GitHub Pages domains are tied to your account name.

https://<username>.github.io/<repository>/privacy.html

The instant you change your account name, every page you published under that account changes URL. The old URLs 404. No redirect is set up. The repository name hasn’t changed, but the whole domain side moves house.

And I had my privacy policies and terms of service on those GitHub Pages. For all 3 apps.

The damage spread across 3 layers.

Layer 1: the app itself broke

The “Privacy Policy” and “Terms of Service” links on the settings screen had the old URLs hardcoded into the Dart source.

// lib/constants/legal.dart
const kPrivacyPolicyUrl = 'https://<old-username>.github.io/kiroku/privacy.html';
const kTermsUrl         = 'https://<old-username>.github.io/kiroku/terms.html';

This builds fine. The tests pass. Static analysis says nothing. Of course it does — they’re just strings. There was no mechanism anywhere that would tell me they were broken.

Every user in closed testing, and every reviewer who would later touch the app, would hit a 404 the moment they tapped.

Layer 2: Play Console broke

The privacy policy URL registered in the store listing was still the old URL too. That one isn’t code, it’s a setting in a console, so searching the entire repository turns up nothing.

Layer 3: the Data safety declaration broke

Google Play has a field where you declare the URL of the page that accepts data deletion requests. I had that on the same domain.

Google checks during review that this declared URL is actually reachable. The result: I couldn’t submit for review at all. Pressing the submit button just got rejected.

Why it took me days to notice

Because the renaming work and the app operations work were running completely separately.

I develop by assigning roles to AI agents. The one that carried out the GitHub rename was “a session working on one specific app’s needs.” That session didn’t know that the other 2 apps referenced the same GitHub Pages.

Not knowing, it had no way to check the blast radius. And I, the one giving the instruction, hadn’t considered that the other apps would get dragged down with it.

What actually surfaced it was fixing the same symptom in a different app. I thought “wait, are my other apps set up the same way?”, ran a search across all of them, and found out they were all dead.

Honestly, I don’t think this was an accident caused by delegating to AI. If you own multiple apps as one person and keep your legal pages on a single domain, anyone would step on the same mine. If anything, if I’d been managing all of it in one human head, I might have found it even later.

What I changed after fixing it

I changed 3 things so this doesn’t happen again.

Before changing an account name, a domain, or a hosting provider, search every project that references that domain. It’s one grep across all the repositories. It takes under a minute. This time I just didn’t do it.

Keep legal URLs consolidated in one file. If your constants live in one place, like legal.dart, swapping them out is a one-file job. Write them inline on each screen and you will miss one.

Add “actually open the legal pages” to the pre-release checklist. Automated tests can’t detect this area, so you eyeball it — but you always click through. That’s the last line of defense.

The lesson: external URLs are a dependency that never tells you it’s broken

Code dependencies have package.json, and if they break the build fails. If types don’t line up, the compiler stops. A machine tells you it’s broken.

External URLs hardcoded into an app have none of that. The build passes. The tests pass. Until you submit to store review, or until a user taps, nobody can notice.

And the nastiest part this time was that the person who made the change had no sense of having broken anything. All I did was change an account name on a GitHub settings screen. I didn’t touch a single line of app code. The idea that this breaks the app is counterintuitive.

I still think renaming an account for privacy is the right call going forward. But before you do it, count what it will break. That’s all this was.


This accident happened in a setup where I run multiple AI agents as “employees.” I wrote up what worked and what was a waste in that setup in this post.

On the Google Play front there’s one more requirement that reliably beats up indie developers: closed testing with 12 people for 14 days. I’m planning to write about that in a separate post.