Lovable — privacy & data policy

Provider: Lovable. PromptPrivacy score: 77/100. Last verified July 26, 2026.

What happens to your data?

Lovable processes your data to provide services, improve performance, and secure the platform. Your data is not used to train general-purpose AI models for others without your permission, and it is stored using industry-standard encryption. You retain ownership of your Customer Data and can request its deletion at any time.

Does it train on your data?

User artifacts are used only to serve the workspace and, once anonymized or aggregated, to improve models; they are never used to train general-purpose AI models that benefit other customers without permission. Users can opt out of using Customer Data for model training by contacting privacy@lovable.dev or upgrading to a Business plan.

Can you opt out?

Yes, users can opt out of marketing emails, non-essential cookies, and model training by contacting privacy@lovable.dev or using in-product settings.

Data retention

Customer data is retained for up to 90 days after account termination or expiration, unless required by law. Backups may retain data for up to 90 days.

Encryption & security

All traffic is protected with industry-standard end-to-end encryption. Data at rest is protected via database encryption with secure key management. The company maintains SOC 2 Type II audits and uses ISO 27001-certified data centers.

Is it safe for work?

Yes, the policy includes enterprise-grade security measures like SOC 2 Type II compliance, clear data processing agreements, and specific controls for Business/Enterprise plans.

Source policy: https://lovable.dev/privacy