Lovable Privacy Policy
Effective Date: September 9th, 2026
Last Updated: August 5th, 2026
- Introduction and Scope
Lovable provides tools that let you build, share, and deploy apps and websites using natural-language prompts (each, an "App" — see Section 2). This Privacy Policy ("Policy") explains how we collect, use, disclose, and otherwise process Personal Data when you use our websites, applications, and platform (together, the "Services").
This Policy covers your use of the Services — visiting our websites, creating and using an account or App, billing, and visiting Apps. If you use the Services through a workspace covered by an organization's agreement with us, that agreement governs the content in that workspace. This Policy does not cover data that people submit to Apps built by our users: the person or organization that built an App is responsible for the data it collects and how it is used, as described in Section 15.
This Policy is designed to meet the requirements of the data protection laws that apply to our Services, including the EU and UK GDPR, Switzerland's Federal Act on Data Protection, Canada's PIPEDA, Brazil's Lei Geral de Proteção de Dados ("LGPD"), and applicable U.S. federal and state privacy laws.
- Definitions
"Personal Data" means any information relating to an identified or identifiable natural person, or that is reasonably capable of being linked to a particular person or household. It includes, for example, your name, email address, phone number, payment details, IP address, device and browser identifiers, authentication tokens, and usage and telemetry logs that relate to you. Where a law that applies to you uses a different term — such as "personal information" under U.S. state privacy laws or "dados pessoais" under the LGPD — we mean whatever that law covers.
"App" means anything you build or publish with Lovable — a website, web app, online store, internal tool, mobile app, or other software project. When this Policy says "app" or "apps and websites," it means Apps in this sense.
"Customer Content" means the content you submit to or create with the Services: prompts, code, project files, hosted applications, configurations, and generated outputs. Customer Content may contain Personal Data. Customer Content does not include Your Users' Data.
"Your Users' Data" means Personal Data that people who use your Apps — including your websites — provide to those Apps or that your Apps collect about them — for example your App's user accounts, form submissions, orders, and the records in your project's database and storage. It does not include data about people you invite to collaborate in your Lovable workspace, who are covered by the rest of this Policy.
"App Usage Data" means a category of Your Users' Data: usage event data generated by people using your Apps and collected through Lovable-provided analytics instrumentation, as described in Section 7A.
"Usage Data" means data about how the Services are accessed and used: feature events, API calls, build and deployment events, metering and billing telemetry, log data, and diagnostic information. Where Usage Data relates to an identifiable person (for example, because it is tied to your account or device), it is Personal Data and is protected as such.
"De-identified Data" means data that no longer identifies and cannot reasonably be linked to any person or household, whether aggregated or individually de-identified. We maintain De-identified Data in de-identified form, do not attempt to re-identify it (except to test the effectiveness of our de-identification), publicly commit to processing it only in de-identified form, and contractually require recipients to do the same, as U.S. privacy laws require. We may use and disclose De-identified Data for any lawful purpose.
- Personal Data We Collect
Information you provide or generate. Account details (name, email address, and how you sign in — a password, or single sign-on through a provider such as Google or GitHub), profile information, payment information (processed by Stripe; we do not store full card numbers — see stripe.com/privacy), Customer Content you submit or generate using the Services, communications with us, and information you provide when registering domains (see Section 9).
Information collected automatically. Metadata about your use of the Services: IP address and approximate (city-level) location, browser and OS type, device identifiers, session identifiers, pages and features used, build/deploy and API events, metering and billing telemetry, error and diagnostic logs, and cookie data as described in Section 7.
Information from integrations you enable. If you connect a third-party integration (for example GitHub, Supabase, or an MCP connector), we receive the data that integration makes available under the permissions you grant, plus authentication status and integration-usage events. We access only what the integration you enabled requires. Connections your App makes for its own users are different: what your App's users send through them is Your Users' Data (Section 2), which we process only on your behalf. Where an integration operates under terms you accept directly with its provider, that provider's agreement and privacy policy govern its side of the exchange. Connections made locally through a desktop application are described below. Data made available to us by a messaging or collaboration platform you connect is used only to operate the integration and generate responses; we do not use it to train AI models.
Device features and local processing. Some of our applications — for example, Lovable Desktop — can use your device's files, microphone, camera, or screen, only where you enable the feature. What you transmit to us or to an AI model provider this way is Customer Content, handled under this Policy. Where a feature processes data entirely on your device and nothing is transmitted to us, we do not receive it, and this Policy does not apply to it. You are responsible for any consents needed before recording or sharing information about others. Feature-specific controls are described in the applicable terms, such as our Desktop App Terms.
Information from other sources. Payment and fraud signals from our payment processor; technical signals from security vendors protecting the Services; measurement data flowing back from the advertising platforms described in Section 6; and publicly available information where the law permits.
- How We Use Personal Data
We use Personal Data for the following purposes:
- Provide the Services — provide, operate, secure, and maintain the Services, including storing and running your projects and generating outputs;
- Personalize — personalize your experience and tune AI-driven features for your workspace;
- Train and develop our AI models — train, develop, and improve our AI models, as described in Section 5 (with an opt-out);
- Improve and research — analyze usage to improve performance, functionality, and reliability; test and compare features, interfaces, and model configurations; and conduct surveys and user research (with your participation);
- Protect and secure — detect, prevent, and investigate fraud, abuse, security incidents, and violations of our terms, and protect the safety of users and the public (including as described in Section 8);
- Payments and billing — process payments and meter usage-based services against your credits;
- Communicate — communicate with you, provide support, and send service notices;
- Market and advertise — market our own services, measure our marketing, and — where you have the choices described in Section 6 — for advertising;
- Create De-identified Data — create aggregated or De-identified Data (Section 2), which we maintain and use as described there; and
- Comply with law — comply with legal, regulatory, tax, export-control, and sanctions obligations, and establish, exercise, or defend legal claims.
We use automated systems to detect fraud, abuse, and security risks. If an automated decision significantly affects you — for example, an account suspension — you can request human review and appeal the decision by contacting privacy@lovable.dev.
- AI Model Training and Your Opt-Out
What we use. We use Customer Content and Usage Data — which may include Personal Data — to train, develop, fine-tune, and improve our AI models and AI-powered features, including models we operate within the Services and models we may make available to customers through Lovable products such as the AI Gateway. Trained members of our team may review this content to check model quality and diagnose failures, under the confidentiality and access safeguards described in Section 14.
What we do not train on.
- Your account and billing details. We use them to run your account, not to train our models.
- Business and Enterprise Customer Content or Usage Data. We set out this prohibition in our Data Processing Agreement.
- Your Users' Data (Section 2), including App Usage Data. It is held in your project's own database and storage, and we do not use it to train our models.
Your opt-out. You can opt out of model training at any time in your account settings, on any plan, at no cost, and it does not affect your use of AI features. Opting out takes effect going forward: your content is excluded from all training data assembled after your opt-out takes effect. It does not retract content from training datasets assembled, or models trained, before you opted out.
What about the AI companies whose models we use? When your content is sent to a third-party model provider (or providers), our agreements with that provider restrict its use of your content, including for training — see Section 8.
- Advertising and Sharing With Ad Platforms
What we do. With the choices described below, we share limited Personal Data — pseudonymized identifiers, not the contents of your projects — with advertising platforms such as Meta and Google for the following purposes:
- Suppression: excluding existing customers from paid advertising, so we do not pay to advertise to people who already use Lovable;
- Audience targeting: showing Lovable ads to our contacts on those platforms; and
- Lookalike audiences: asking those platforms to reach new people that resemble our customers. The only information a platform receives from us is the identifier used for matching.
Your choices. In the EEA, UK, Switzerland, and Brazil, we do this only with your consent, which you can withdraw at any time in your privacy settings. In the United States, this sharing may constitute a "sale" or "sharing" of personal information under state privacy laws; you can opt out at any time via the "Do Not Sell or Share My Personal Information" link in our website footer where required, via your privacy settings, or by broadcasting a Global Privacy Control (GPC) signal, which we honor as an opt-out for the browser or device sending it.
We also use cookies for advertising measurement as described in Section 7. We do not share Customer Content or Your Users' Data with advertising platforms, unless you instruct us to do so, and we do not use the contents of your projects for advertising.
- Cookies, Analytics, and Session Recording
Lovable and selected partners use cookies, pixels, SDKs, and similar technologies to operate, secure, analyze, and market the Services. We group them as follows:
- Strictly necessary — sign-in, session routing, fraud prevention, consent storage. No consent required.
- Analytics & performance — feature adoption, error diagnosis, and service performance, using first-party and third-party analytics providers.
- Session recording — with your consent where required, we record a sample of sessions, with a session-replay provider acting on our behalf, to understand how the product is used and to fix usability problems. Recordings capture interactions such as clicks, scrolling, and navigation. We configure the tool to mask the input of project chat, so that what was typed there is not captured; recordings are not used to train AI models. Where required, you can withdraw consent in the Cookie Preferences panel, which stops future recording.
- Functional — preferences such as language, theme, and layout.
- Marketing — conversion tracking and campaign measurement for the advertising platforms described in Section 6.
The specific cookies we and our providers set, including names, providers, and durations, are listed in the Cookie Preferences panel (lovable.dev/cookie-policy). In the EEA, UK, and Switzerland we obtain consent before setting non-essential cookies. In the United States we honor opt-out preference signals such as GPC. You can manage preferences any time via the Cookie Preferences panel or your browser.
- Analytics in Apps and Websites You Publish (App Usage Data)
If enabled by you, your Apps and websites built on Lovable can include analytics instrumentation — we call the data it produces App Usage Data — so that you, and Lovable's agent acting for you, can understand how your App performs. When you enable it for an App, we collect measurement data about visits and events: for example, how many times pages and features are used, approximate location, device type, and where traffic came from. The instrumentation is designed for aggregate measurement rather than to identify or track individual people, and it collects the minimum needed for that purpose. What is collected, and the controls available to you, are described in our product documentation.
App Usage Data is Your Users' Data (Section 2): you control it, and we process it on your behalf to provide your analytics and recommendations. We also produce De-identified Data from it (Section 2), which we use to improve the Services and to give you comparative insights.
You are responsible for your App's privacy notice and any consents your App requires.
- Who Receives Your Personal Data
- Service providers and sub-processors — hosting, payment, support, analytics, and AI infrastructure providers acting on our instructions under contracts consistent with this Policy. Our current sub-processor list, including each provider's location and purpose, is at trust.lovable.dev.
- Integrations you enable — when you connect a third-party service, we send that service the data it needs to perform the integration, limited to what you authorize. What that service does with the data is governed by its own privacy policy.
- AI model providers — when you use features that generate content or code with AI, your prompts and related Customer Content are transmitted to one or more of the model providers we use. Our agreements with these providers restrict their use of your content. Our current model providers are listed at trust.lovable.dev.
- Advertising platforms — as described in Section 6, subject to your choices.
- Domain partners and registries — when you register a website address through us, as described in Section 9.
- An organization that claims your account (for example, your employer) — as described in Section 10.
- Law enforcement, courts, and safety organizations — where we believe disclosure is required by law or legal process, or is necessary to protect the rights, property, or safety of Lovable, our users, or the public. This includes reporting apparent child sexual abuse material to the U.S. National Center for Missing & Exploited Children (NCMEC), as U.S. law requires, and cooperating with the resulting processes.
- Acquirers, investors, and their advisers — if we enter into or negotiate a merger, acquisition, financing, or sale of assets, Personal Data may be disclosed to the other parties and their professional advisers, and may transfer as part of the transaction. This Policy continues to apply to that Personal Data unless and until you are given notice of a different policy.
We share limited Personal Data — pseudonymized identifiers, not the contents of your projects — with the advertising platforms described in Section 6. Some U.S. state privacy laws treat this as a "sale" or "sharing" of personal information, and you can opt out at any time via the "Do Not Sell or Share My Personal Information" link in our website footer, your account settings, or a Global Privacy Control signal. In the EEA, UK, Switzerland, and Brazil, this sharing happens only with your consent. We do not share Customer Content or Your Users' Data with advertising platforms, unless you instruct us to do so.
- Domains You Register Through Lovable
If you buy a domain through Lovable, the contact details you provide are shared with the registrar and registry that operate it, and — where ICANN's rules require — with ICANN and a data escrow provider. For most domain endings your personal details are hidden from public lookups by default. You can view and correct these details in your account settings; full terms are in the domain registration agreement you accept at checkout.
- If You Signed Up With an Organization's Email Address (Domain Claims)
If you created your account with an organization's email address — an address at a domain owned by your employer, university, or another organization, rather than a personal one — that organization can verify it owns the domain and "claim" accounts registered under it. Here is how it works:
- What the organization can see. The organization's administrators can see limited information about accounts registered with email addresses on that domain: email address, display name, number of workspaces and projects, and last-active date. They cannot see the contents or names of your projects unless and until your account transfers.
- Notice and your choice. You will be notified by email or in the product. You will then have an opportunity to either join the organization or keep your account personal by changing your account email to an address outside the claimed domain.
- If you do not choose. Your account transfers to the organization on the date stated in the notice.
- After transfer. The organization controls the account (including sign-in and billing) and its agreement with us governs it. The organization becomes responsible for deciding how the data in the account is used, and Lovable handles that data on the organization's behalf.
- Our Legal Bases for Processing
Where the law requires us to have a legal basis for using your Personal Data, these are the bases we rely on:
- To provide the Services — processing necessary to give you the Services you signed up for, including support and billing.
- Our legitimate interests — securing the platform, preventing fraud and abuse, aggregate analytics, service improvement, AI model training subject to Section 5's opt-out, and establishing, exercising, or defending legal claims — in each case where our interests are not outweighed by your rights.
- Your consent — non-essential cookies, marketing emails, the advertising uses described in Section 6, and taking part in surveys or research. You can withdraw consent at any time, which does not affect processing that already took place.
- Complying with legal obligations — bookkeeping, tax, sanctions and export controls, mandatory safety reporting, and responses to lawful process.
- Protecting life — rare emergencies where processing is needed to protect someone's life or physical safety.
In Brazil, we rely on the equivalent bases under the LGPD. Swiss law does not require a legal basis in the same way; there we apply the principles of Switzerland's Federal Act on Data Protection together with the protections described in this Policy.
- International Data Transfers
Our main establishment is in Stockholm, Sweden and Integritetsskyddsmyndigheten (IMY), the Swedish Authority for Privacy Protection, is our lead supervisory authority. We and our service providers process Personal Data in a number of countries, including the United States. This means your Personal Data may be transferred outside the country or region where you live.
Where Personal Data is transferred from a jurisdiction that restricts international transfers, we use legally recognized mechanisms:
- EEA: the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), with transfer impact assessments where required.
- UK: the UK International Data Transfer Addendum issued under section 119A of the Data Protection Act 2018.
- Switzerland: the EU Standard Contractual Clauses with the Swiss addendum recognized by the Federal Data Protection and Information Commissioner, applying Switzerland's Federal Act on Data Protection.
- Brazil: the Brazilian Standard Contractual Clauses approved by the ANPD (Resolution CD/ANPD No. 19/2024), or another transfer mechanism recognized under Brazilian law.
You can request a copy of the relevant transfer safeguards, with commercially sensitive terms redacted, at privacy@lovable.dev.
- Data Retention
We keep Personal Data only as long as needed for the purposes described in this Policy or as the law requires, then delete or de-identify it. How long that is depends on the data:
- Your account and Customer Content — kept while your account is open, then deleted or de-identified after it closes or after a verified deletion request, unless the law requires us to keep it longer. Deletion does not retract content from training datasets assembled, or models trained, before your request took effect (see Section 5).
- Operational and security logs — kept for as long as needed to run and secure the Services, and longer where we are investigating an incident.
- Analytics identifiers — see lovable.dev/cookie-policy.
- Billing and tax records — for the periods accounting and tax law require.
- Records of notices, consents, opt-outs, and account transfers — kept as evidence that we met our obligations, for as long as a claim or regulatory question about them could still arise.
- Information Security
We protect Personal Data with technical and organizational measures appropriate to the risk, and we review them as our Services and the threats to them change. No system is perfectly secure, so we also rely on you to help protect your account.
- Protecting data — encryption in transit and at rest, with managed keys, and regular backups.
- Controlling access — access limited by role to staff who need it, multi-factor authentication, and periodic access reviews.
- Detecting and responding — security monitoring, centralized logging, and an incident response process. Where a breach is notifiable, we inform affected users and regulators within the timeframes the law requires.
- Our people and vendors — staff are bound by confidentiality obligations and receive security training; vendors are assessed before we use them and bound by contract.
Current information about our security certifications and audit status is published at trust.lovable.dev.
- Your Privacy Rights and How to Exercise Them
You can ask us to provide a copy of your personal data, including in a portable, machine-readable format, to correct it, or to delete it along with your account. You can also object to or restrict certain processing, withdraw any consent you have given, opt out of model training (Section 5), and opt out of advertising-related sharing (Section 6). Use your account settings or email privacy@lovable.dev. We respond within the period your local law requires, and we will tell you if we need longer and why. If you are in the EEA, UK, or Switzerland you may complain to your supervisory authority (for us: Integritetsskyddsmyndigheten in Sweden, the UK ICO, or the FDPIC); in Brazil, to the ANPD; in Canada, to the OPC; in the US, see Section 17.
If you used an app or website someone built with Lovable. The person or organization that built it decides what data it collects and why, so they are responsible for that data. Send your privacy requests to them; their own privacy notice should say how to reach them.
- Children
Our Services are intended for adults. You must be 18 or older to create your own Lovable account.
Organizations — including schools and education partners — can also use Lovable under a written agreement with us to give people under 18 supervised access as part of a program. Where that happens, the organization decides what is collected and why, and is responsible for obtaining any consent the law requires from a parent or guardian. We process that data only on the organization's instructions, and the organization is the point of contact for privacy requests about it.
If we learn that someone under 18 has created an account outside such a program, we will close it and delete the Personal Data associated with it. Parents, guardians and organizations can reach us at privacy@lovable.dev.
- United States State Privacy Disclosures
This section supplements the rest of the Policy for residents of U.S. states with comprehensive privacy laws, including California. In the preceding 12 months we have collected the categories of personal information below and disclosed them as indicated. The sources we collect from are described in Section 3, the purposes we use them for in Section 4, and how long we keep each category in Section 13.
| Category | Examples | Disclosed for business purposes to | Sold or shared? |
|---|---|---|---|
| Identifiers | Name, email, IP address, user ID, device identifiers | Service providers; integrations you enable | Shared: pseudonymized identifiers to ad platforms (opt-out available) |
| Commercial information | Subscription tier, purchase history | Payment processor; service providers | No |
| Internet or network activity | Feature usage, log-in events, session recordings, telemetry | Service providers, including analytics and session-replay providers | Shared: cookie-based ad measurement (opt-out available) |
| Geolocation (coarse) | City- or region-level location from IP address | Service providers | No |
| User content | Projects, prompts, code, and configurations you upload or create | Service providers; AI model providers; integrations you enable | No |
| Inferences | Preferences used to personalize the Services | Service providers | No |
| Sensitive personal information | Account log-in credentials | Service providers, to authenticate you | No |
Your rights. Depending on your state, you may have the right to know and access your personal information, to have it corrected or deleted, and to receive a portable copy — including, where you ask for it, information collected more than 12 months ago. You may also have the right to opt out of the sale or sharing of personal information, of targeted advertising, and of profiling used to make decisions that have legal or similarly significant effects; and to limit our use of sensitive personal information. We collect account log-in credentials as sensitive personal information and use them only to authenticate you, which is not a use that requires that limit. Your state may give you additional rights, and we will honor them.
How to exercise them. To opt out of advertising-related sharing, use the "Do Not Sell or Share My Personal Information" link in our website footer, your privacy settings, or send a Global Privacy Control signal. For any other right, email privacy@lovable.dev or use the in-product privacy controls. For requests to know, delete, or correct, we verify your identity using the email address on your account, and we may ask for information needed to match your request to our records. We do not require you to verify your identity to opt out of sale or sharing, or to limit the use of sensitive personal information. We respond within the time your state's law requires. An authorized agent may submit a request on your behalf with proof of authorization. We will not discriminate against you for exercising your rights.
If we say no. You may appeal by replying to our decision. We will respond to your appeal within the time your state's law requires, and if we deny it you may contact your state Attorney General.
- Canada
For Canadian users, we process Personal Data in accordance with PIPEDA and applicable provincial laws. You may access or correct your Personal Data and withdraw consent as described in Section 15, and you may complain to the Office of the Privacy Commissioner of Canada.
- Brazil — LGPD Disclosures
This section supplements the Policy for users in Brazil. Lovable Labs Sweden AB is the controller (controladora) of Personal Data processed under this Policy; after a domain-claim transfer (Section 10), the claiming organization is the controller and Lovable is the operator (operadora).
Your rights. You may obtain, at any time and free of charge: confirmation that we process your data; access to it; correction of incomplete, inaccurate, or outdated data; anonymization, blocking, or deletion of unnecessary, excessive, or unlawfully processed data; portability to another provider; deletion of data processed with your consent; information about the public and private entities with which we have shared your data; information about the consequences of refusing consent; and revocation of consent. Where we rely on legitimate interest, you may object. You may also ask us to review a decision taken solely by automated processing that affects your interests, and to explain the criteria we used to make it. We respond via privacy@lovable.dev.
Encarregado (DPO). Our Encarregado for Brazil is reachable at dpo@lovable.dev. You may also lodge complaints with the Autoridade Nacional de Proteção de Dados (ANPD) at gov.br/anpd.
International transfers from Brazil are made under the mechanisms described in Section 12.
- Changes to This Policy
If we make material changes — changes that reduce your rights or significantly expand how we use your Personal Data — we will give you at least thirty (30) days' notice before they take effect, using a method reasonably likely to reach you, such as an in-product notice, a prominent notice on our website, or an email. Where the law requires your consent for a specific change, we will ask for it.
Policy history. Earlier versions of this Policy are available upon request to privacy@lovable.dev.
- Contact Us
Questions, concerns, or rights requests: privacy@lovable.dev. Data Protection Officer: dpo@lovable.dev. Our address: Lovable Labs Sweden AB, Regeringsgatan 25, 111 53 Stockholm, Sweden. Brazil encarregado: see Section 19. If we cannot resolve your concern, you may contact your supervisory authority as described in Section 15. Lovable Labs Sweden AB is the entity responsible for the Personal Data processed under this Policy (the "data controller" where that term applies).