BlogOur First Paid User Signed Up Despite Google's Scary 'Unverified App' Warning
Behind the Build5 min read·August 7, 2026

Our First Paid User Signed Up Despite Google's Scary 'Unverified App' Warning

How we got our indie hacker first paid user when Google warned them our app might be unsafe. The trust signals that made the difference.

On March 12th, someone I'd never met clicked through Google's scariest warning screen—the one with the red shield that essentially screams "this app will steal your data"—and handed us $5 for a monthly subscription. That moment taught me more about earning trust as an indie hacker first paid user than any marketing guide ever had.

The Google OAuth "unverified app" warning exists for good reason. It protects users from malicious apps. But for legitimate indie hackers building Gmail tools, it creates a brutal chicken-and-egg problem: you need users to get verified, but the warning scares away users. Here's exactly how we navigated that challenge and what convinced our first paying customer to take the leap.

Why Google Shows the Unverified App Warning

When your app requests access to Gmail, Google checks if you've completed their OAuth verification process. This involves a security assessment, privacy policy review, and sometimes a third-party audit costing $15,000-$75,000.

For bootstrapped indie projects, that audit cost can exceed your entire development budget. So you launch unverified, and users see this: a red warning page with "Google hasn't verified this app" in bold text, plus a tiny "Advanced" link they must click to proceed. Then another confirmation. Google's data shows most users bail at this screen.

Our first week, 47 people started the signup flow. 3 completed it. That's a 93.6% drop-off rate at a single screen.

The Trust Signals That Converted Our Indie Hacker First Paid User

I emailed everyone who completed signup (yes, all 3 of them) asking why they pushed through the warning. Two responded. Their answers reshaped our entire approach:

  • Transparency about what data we access: We listed exactly which Gmail scopes we request and why. "Read-only access to email headers" meant something to technical users.
  • A real human behind the product: Our landing page showed my name, my photo, and linked to my Twitter. One user said, "I could see you were a real person building something, not some anonymous data harvester."
  • Privacy-first architecture explained: We documented that InboxClean never reads email body content—only headers (From, Subject, Date, List-Unsubscribe). This specific detail mattered.

The third person who signed up? They became our first paid user three days later.

What We Changed After Getting Our First Subscriber

That $5/month subscription validated more than the product. It validated that trust could be built despite Google's warning. We immediately invested in making that trust-building faster:

  1. Added a pre-OAuth explainer page: Before users hit Google's warning, we show them exactly what they'll see and why it appears. Conversion from this page improved 34%.
  2. Recorded a 90-second Loom video: I walked through the entire flow, showing the warning and explaining what happens after. Users who watched had 2.8x higher completion rates.
  3. Published our privacy architecture: A technical breakdown of exactly how we handle Gmail data. This became our most-shared page among developer communities.
  4. Made our security contact prominent: A direct email for security questions. Three people used it before signing up. All three converted.

The Revenue Reality of Early Indie Hacker Subscribers

Let's be honest about the numbers. One $5/month subscriber means $60/year in revenue. Our infrastructure costs were $23/month at launch. We were deeply unprofitable, and would be for months.

But that first subscriber provided something more valuable than revenue: proof that someone would pay for what we built. When I posted about it in an indie hackers community, the response surprised me. People wanted to know the exact conversion rate, the pricing psychology, the onboarding flow. That one subscriber generated more useful feedback than our previous 50 free signups combined.

The subscriber also became our most engaged user. They reported bugs. They requested features. When we launched Inbox Shield—the feature that creates permanent Gmail filters to block senders forever—they tested it first and confirmed it worked.

Getting Google Verified Changed Everything (Eventually)

Four months and 89 paying subscribers later, we completed Google's OAuth verification. The warning disappeared. Our conversion rate at the OAuth screen jumped from 6.4% to 71.2%.

Those four months of operating unverified taught us to communicate trust in ways that still matter post-verification:

  • Every landing page element now addresses a specific user concern
  • We explain what happens with their data before asking for access
  • Technical users can inspect exactly which API scopes we request
  • Our comparison with alternatives like Unroll.me honestly addresses privacy differences between services

The unverified period forced us to be radically transparent. That transparency became a competitive advantage even after we no longer needed it to overcome a warning screen.

Lessons for Indie Hackers Chasing Their First Paid User

If you're building a Gmail tool—or any app requiring sensitive permissions—and facing the unverified app challenge, here's what actually worked for us:

Show your face. Anonymous products asking for email access feel sketchy. Put your name on it. Link your social profiles. Let users Google you and confirm you're a real person with a reputation to protect.

Be specific about data. "We respect your privacy" means nothing. "We read only email headers: sender address, subject line, date, and unsubscribe link. We never access email body content." That specificity builds trust.

Prepare users for the warning. Don't let Google's scary screen surprise them. Explain it first. Show them what they'll see. Tell them exactly where to click. This single change made the biggest difference for us.

Make security questions easy to ask. A prominent email address for privacy concerns. A detailed FAQ about data handling. People with concerns who can't easily get answers will leave. People who can ask and get reassurance often become your most loyal users.

That First $5 Still Hits Different

We've grown past those early days. InboxClean now processes thousands of inbox cleanups weekly. Our comparison with other Gmail cleaners shows how far the product has come. But I still remember the notification on March 12th: someone believed in what we built enough to push through a warning designed to scare them away.

For any indie hacker working toward that first paid user milestone: the warning screen, the doubt, the 93% drop-off rates—they're all survivable. Build something genuinely useful, be radically transparent about how it works, and show up as a real human. Someone will take a chance on you. Then your job is to prove they were right to do so.

Try InboxClean free

Scan 1,000 emails. Clean all of it. 60 seconds.

Scan my inbox →