30 Days Gen AI Risk Trial -Start Now
Skip to main content
Code AssistantsFree; Pro $25/mo; Business $50/mo; Enterprise customlovable.dev

Lovable

Lovable is an AI app builder that turns natural-language prompts into full-stack web apps with Supabase backend, custom domains, and one-click deployment for non-developers and prototypers.

Risk score

5/10Medium

Assessment across data handling, compliance, security and transparency.

Overview

Lovable (lovable.dev) is a prompt-to-app platform that generates React/Supabase codebases from chat, lets users publish to custom domains, and collaborates via shared workspaces. It pipes prompts to OpenAI, Google Gemini, and OpenRouter on a pass-through basis, storing code and generated assets on Supabase infrastructure with annual SOC 2 Type II audits and ISO 27001 data centers. For enterprises, the core risk is that AI-generated code and agent output may be deployed to production without security review, exposing misconfigured Supabase policies, leaked keys, or auth bypasses. Training opt-out requires Business plan or a privacy@lovable.dev request, and HIPAA is explicitly unsupported. Ideal for rapid prototyping; unsuitable for regulated workloads without rigorous code review.

Risk factors

3
  • Cloud SaaS with third-party data storage
  • Data may be used for model training without explicit opt-out
  • Requires user input of potentially sensitive information

Recommendations

7
  • Restrict to non-production prototypes; require security review before any public deploy
  • Upgrade to Business plan to disable training on customer data
  • Ban uploads of PHI, PCI, or regulated personal data per vendor policy
  • Require secrets management review of generated Supabase configs and API key handling
  • Enable SSO and role-based access on Business/Enterprise tiers
  • Block custom-domain publishing from free accounts via egress or DNS controls
  • Audit generated auth flows and database RLS before production launch

Data handling

Storage
Customer data, hosted apps, and generated outputs stored on Supabase infrastructure with database encryption; prompts transit OpenAI, Gemini, and OpenRouter on a pass-through basis.
Retention
Customer data deleted within 90 days post-termination; logs up to 90 days; analytics cookies anonymized after 13 months.
Training on inputs
Does not use raw personal data for training; Business plan or email opt-out required to exclude customer data from model improvement.

See the AI tools in use across your organisation.

Connect your tool research to the employee AI activity and data security questions that matter to your team.