Skip to main content

Provider rules

Rules for every add-on service

Effective Date: September 16, 2026

1. Rules for using another company's service through Lovable

Some Lovable features run on another company's service. You turn them on for your workspace and pay for them in Lovable Credits. We call these Add-on Services, and the company behind each one its provider.

Providers have rules for how their services can be used. This page explains when and how those rules apply to you. Part A applies to every Add-on Service. Part B has a section for each provider.

This page is part of our Terms of Service, alongside our Platform Rules. What you see and confirm on the screen when you turn a service on is also part of your agreement with us for that service.

2. How Add-on Services work

Your contract is with Lovable. We hold the account and the API keys with the provider and we pay them. You pay us in Lovable Credits. For support, billing questions and complaints about an Add-on Service, you deal with us, not the provider.

Your requests go through us. Once a service is on, your project can send requests to the provider. That includes requests made by people using your published app if and where you ask Lovable to add that functionality. Each provider's section below says exactly what gets sent.

You use only what you choose. Nothing goes to a provider until its service is turned on for your workspace. A workspace admin can allow, limit or turn off any Add-on Service for everyone in the workspace, and their choice applies before yours.

Your costs. Pricing details of each service are provided in the vendor specific documentation pages. You can set spending limits and turn a service off at any time in your workspace settings. Our Terms of Service govern Lovable Credits, including refunds.

3. What providers do with your data

Each provider's section below says what we send the provider, whether the provider acts on our instructions or under its own terms, how long it keeps the data and what it can use it for, and where it processes it. Those answers come from our signed contract with the provider.

If you are a business customer, our Data Processing Agreement covers how Lovable and Lovable's sub-processors handle your data. It does not automatically cover Add-on Service providers. When your admin turns a service on, that is your instruction to us to send that service's data to its provider and, where the provider acts on our instructions, your authorisation of it as a sub-processor for your workspace. Turning the service off withdraws that authorisation for future requests. The provider's section below tells you how that provider handles the data.

4. Rules that apply with every provider

When you use any Add-on Service, you agree to these rules:

  • If your project sends or collects personal data through the service, you need a legal basis for that, and you must give people any notices the law requires. Where the law requires it, tell your app's users which providers your app uses.
  • Do not send Prohibited Data through a service. That means payment card numbers and card security codes; bank account numbers or government ID numbers together with the passwords, codes or ID images that would let someone use them; biometric identifiers; and health information regulated under the US health privacy law HIPAA. An account number or ID number on its own is not Prohibited Data.
  • If a service generates video, audio, voices or realistic images and you show that content to people in the EU, tell them it is AI-generated where Article 50 of the EU AI Act requires it.
  • Follow our Platform Rules and the extra rules in the provider's section below.

5. If you break these rules

If your use of an Add-on Service breaks these rules, we may turn that service off for your project or workspace. The rest of your Lovable account is not affected unless our Terms say otherwise.

6. Changes to this page

This page has a version date. Each provider section has its own "last updated" date. When you turn a service on, we record which dates you saw.

Provider sections

Firecrawl

Last updated: September 17, 2026

What Firecrawl does. Firecrawl lets your project read and search the public web.

What Firecrawl does with your data.

  1. We send Firecrawl the web addresses and search queries your project asks for, along with the technical details needed to run, meter and bill the request. Firecrawl sends back the public web content it collects.
  2. Firecrawl acts on our instructions and only to provide the service.
  3. Firecrawl's contract with us limits how long it may keep your requests and results and what it may use them for. It does not use them to train its AI models or to build its own products. It keeps its own index of public web content for its service as a whole, separate from you and your app's users.
  4. Firecrawl processes this data in the United States under standard data transfer safeguards for Europe, the UK and Switzerland.

Firecrawl's extra rules. On top of Part A, when you use Firecrawl:

  • Only request pages anyone can open in a browser, not pages behind a login or paywall.
  • Do not collect sensitive personal data in bulk.
  • Do not sell or pass on personal information you obtained through Firecrawl.

Perplexity

Last updated: September 17, 2026

What Perplexity does. Perplexity lets your project run web searches and receive results with their sources.

What Perplexity does with your data.

  1. We send Perplexity the search text your project asks for, along with the technical details needed to run, meter and bill the request. Perplexity sends back the search results.
  2. Perplexity acts on our instructions and only to provide the service.
  3. Perplexity's contract with us treats your search text as confidential and limits how long it may keep it and what it may use it for. It does not use your searches or results to train its AI models or to build its own products, and it does not keep your results in a form linked to you or your app's users. It keeps its own index of public web content for its service as a whole.
  4. Perplexity processes this data in the United States under standard data transfer safeguards for Europe and the UK.

Perplexity's extra rules. On top of Part A, when you use Perplexity:

  • Follow Perplexity's Acceptable Use Policy.
  • Use Perplexity only inside the app you build on Lovable, and do not republish its results as a standalone dataset, API or feed.