Lovable — privacy & data policy
Provider: Lovable. PromptPrivacy score: 81/100. Last verified August 26, 2026.
What happens to your data?
Lovable processes your prompts, code, and account details to generate, host, and deploy web applications. Infrastructure and AI processing rely on third parties such as Supabase, OpenAI, and Google under pass-through or sub-processor arrangements. Your raw personal data is not used to train public AI models, and data is retained for defined operational periods.
Does it train on your data?
Lovable does not use raw or identifiable personal data to train general AI models that benefit other customers without permission. However, anonymized or aggregated project artifacts and usage data may be used to improve models unless the user opts out by email or uses an Enterprise/Business plan.
Can you opt out?
Yes. You can opt out of having your data used for model improvement by emailing privacy@lovable.dev or by upgrading to a Business plan. Cookie tracking can also be managed via in-product cookie settings or browser signals like the Global Privacy Control.
Data retention
Customer data is retained for up to 90 days, after which it is deleted or isolated. Upon account termination, personal data is deleted within 30 days (except for data required for compliance or legal defense), while backups and log data may persist for up to 90 days.
Encryption & security
Lovable uses industry-standard end-to-end encryption for data in transit and database encryption with key management for data at rest. Infrastructure is hosted in SOC 2- and ISO 27001-certified data centers, supported by annual SOC 2 Type II audits.
Is it safe for work?
Yes, but business users should preferably use Business or Enterprise tiers which are governed by formal Data Processing Agreements and enhanced controls. Free and Pro users should be aware that inputs pass through third-party AI providers (such as OpenAI, Google, and OpenRouter) and backend infrastructure via Supabase.
Source policy: https://lovable.dev/privacy