232 APPS TRACKED · 227 CLAUSES ON FILE · 38 WITH NO CLAUSE TO QUOTE

Lovable's privacy changed

Notable
CHANGED 14 SEPT 2026FIRST SEEN 14 SEPT 2026 · 12:40 UTC
SCORE
79
PARAGRAPHS CHANGED
123 (3 added, 3 removed)
SNAPSHOTS COMPARED
172 hours apart
FAMILIES TOUCHED
human_review ×1 · jurisdiction ×46 · optout ×68 · retention ×37 · scope ×67 · subprocessor ×52 · tier ×7 · training ×32

Hedging language on file: De-identified, aggregated, as described, de-identified, may include, may use, such as. See what these phrases permit.

What actually changed

REMOVEDPrivacy Policy Last Updated: April 14th, 2026 Lovable Labs Incorporated (" Lovable ," " we ," " us ," or " our ") provides tools to empower developers and non-technical users to build, share, and deploy web applications using natural language prompts. Our mission is to simplify software development through innovative tools, seamless integrations, and collaborative features, while prioritizing the privacy and security of your data. We are committed to fostering a vibrant builder community and ensuring compliance with applicable privacy laws in the United States (including all applicable state privacy statutes), European Economic Area, United Kingdom, Switzerland, and Canada. This Privacy Policy (" Policy ") outlines how Lovable collects, uses, shares, and otherwise processes Personal Data from users, including developers, entrepreneurs, and visitors (" User ," " you ," or " your ") of our website, any software, platform (collectively, our " Services "). By using our Services, you acknowledge and agree to this Policy. This Policy incorporates our Terms of Service. If you do not agree with the terms of this Policy, please discontinue your use of our Services. Existing users with contractual obligations should contact us to discuss applicable terms. Please note: This Privacy Policy applies to Free and Pro plans. This does not include Business and Enterprise plans which are governed by our terms and Data Processing Agreement found here .

ADDEDLovable Privacy Policy Effective Date: September 9th, 2026 Last Updated: August 5th, 2026 Introduction and Scope Lovable provides tools that let you build, share, and deploy apps and websites using natural-language prompts (each, an "App" - see Section 2). This Privacy Policy ("Policy") explains how we collect, use, disclose, and otherwise process Personal Data when you use our websites, applications, and platform (together, the "Services"). This Policy covers your use of the Services - visiting our websites, creating and using an account or App, billing, and visiting Apps. If you use the Services through a workspace covered by an organization's agreement with us, that agreement governs the content in that workspace. This Policy does not cover data that people submit to Apps built by our users: the person or organization that built an App is responsible for the data it collects and how it is used, as described in Section 15. This Policy is designed to meet the requirements of the data protection laws that apply to our Services, including the EU and UK GDPR, Switzerland's Federal Act on Data Protection, Canada's PIPEDA, Brazil's Lei Geral de Proteção de Dados ("LGPD"), and applicable U.S. federal and state privacy laws.

Definitions

REMOVEDa. " Data Protection Laws ": Collectively, (i) Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of Personal Data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (the " GDPR "), UK GDPR and any implementing or supplementary legislation, and (ii) all U.S. federal or state privacy statutes in force during the Term together with other national laws governing the Processing of Personal Data. If the Customer is a UK entity, any reference to the "GDPR" shall be interpreted to include a reference to the UK GDPR. b. " Personal Data ": For purposes of this Policy, Personal Data (also called personal information under the California Consumer Privacy Act/Privacy Rights Act and similar U.S. state laws) means any information that relates to an identified or identifiable natural person or is reasonably capable of being linked to a particular consumer or household, as set out in the EU GDPR, UK GDPR, Canada's PIPEDA, the revised Swiss Federal Act on Data Protection, and all applicable U.S. federal or state privacy statutes. Personal Data may include, for example, your name, business email address, postal address, telephone number, username, unique device or browser identifiers, Internet-protocol (" IP ") address, authentication tokens, usage and telemetry logs, or other information generated through your use of our Services. c. " Service Data ": Any data relating to the use, support and/or operation of the Services, which is collected directly by Lovable from the Customer's use of the Service. Service Data is used for Lovable's security, billing, analytics, or product-improvement purposes. Service Data is not Personal Data. Collection and Use of Information Information You Provide Directly : When you create an account, purchase a subscription, open a support ticket, apply for a role, or otherwise use our Services, you may supply Personal Data such as your name, business-email address, phone number, payment information (processed via Stripe; see Stripe's privacy policy at stripe.com/privacy for details on how they handle your card details and transaction data). For usage-based services like Lovable Cloud and AI Gateway, we collect and process Usage Data (e.g., API calls, storage usage, prompt volumes) to meter consumption against your Credits (prepaid balances). These Credits are tracked in separate balances per service, with metering reliant on Stripe and third-party providers. We do not store full payment card details; Stripe serves as the source of truth for billing records, which may include anonymized usage metrics shared with us for invoicing, and project artefacts (for example, natural-language prompts, code snippets, or deployment configurations). These artifacts are used only to serve your workspace and, once anonymized or aggregated, to improve our models; they are never used to train general-purpose AI models that benefit other customers without your permission. Information Collected Automatically : When you interact with the Services, we automatically collect technical data such as IP address, browser type, operating system, device identifiers, pages visited, timestamps, and error logs. Service Data is processed by Lovable as an independent controller for security, billing, analytics, and product-improvement purposes. Billing and Metering Data: Telemetry on service usage (e.g., compute hours in Lovable Cloud, API requests via AI Gateway) is collected to generate monthly invoices showing consumption by service. This data is anonymized where possible and shared with Stripe for payment processing and revenue recognition. Usage And Analytics Data : We record how you engage with key features (e.g., prompts submitted, code generated, build and deployment events, clicks on the GitHub or Supabase integrations). If you authorize a third-party integration, Lovable accesses only the minimum data required to provide that integration and processes it under the same terms as other Customer Personal Data. Data Handling In Lovable Cloud and AI Gateway : Lovable Cloud provides cloud hosting and back-end services (e.g., database, authentication, storage), where your Customer Data (as defined in our Terms of Service), including hosted applications, files, and generated outputs, is stored and processed on Supabase infrastructure. By using Lovable Cloud, you consent to the transfer, storage, and processing of your Customer Data by Supabase under their privacy policy (available at supabase.com/privacy ). The AI Gateway acts as a proxy to connect your applications to third-party AI providers, including OpenAI, Google Gemini, and models via OpenRouter. When using the AI Gateway, your inputs (e.g., prompts, queries) and related Customer Data are transmitted to these providers for processing and response generation. These transmissions occur on a pass-through basis; we do not store the raw prompts or responses unless you explicitly save them in your workspace. By using the AI Gateway, you consent to such transfers under the privacy policies of OpenRouter ( openrouter.ai/privacy ), OpenAI (openai.com/policies/privacy-policy), and Google (policies.google.com/privacy). We do not control these providers' data practices, and you are responsible for reviewing their policies If an Integration is connected via MCP Server to permit data to be accessed, Lovable may receive information that the Integration makes available through the API to facilitate the integration. When an Integration is enabled via API, Lovable is authorised to connect and access data made available to it in accordance with our agreement with the provider of the Third-Party Service and any permission(s) granted by the Customer. Lovable may receive whether you successfully authenticated with an Integration and your usage of the functionality. Data Handling In Integrations and App Connectors : Our Services allow users to send and receive Personal Data from third-party services (which we refer to as ' Integrations '). Integrations are applications or platforms that integrate with Lovable via API Connectors or using a Model Context Protocol for chat connectors (' MCP Server '). Once an API connection is enabled, the provider of an Integration may share certain information with Lovable. For example: If an Integration is connected via MCP Server to permit data to be accessed, Lovable may receive information that the Integration makes available through the API to facilitate the integration. When an Integration is enabled via API, Lovable is authorised to connect and access data made available to it in accordance with our agreement with the provider of the Third-Party Service and any permission(s) granted by the Customer. Lovable may receive whether you successfully authenticated with an Integration and your usage of the functionality. Data Handling In Lovable Desktop : If you access Lovable through our desktop app (' Lovable Desktop' ) the data handling of Integrations applies. Certain actions may be taken locally on your device. Where no data is transmitted to Lovable's servers or the Lovable API, such processing does not constitute a submission of Customer Data to Lovable and is not subject to this Policy. More information can be found in our Desktop App Terms . Process and maintain your domain name registration; Comply with applicable ICANN requirements, including the publication of certain data elements in the Registration Data Directory Service (RDDS); Enable the sponsoring registrar and applicable registry operator to fulfil their obligations under the Registrar Accreditation Agreement and applicable registry agreements; Communicate with you regarding your domain name registration, including verification and renewal, and any other ICANN-required communications. The applicable registry operator; ICANN; Any ICANN-authorised escrow service provider; and Other third parties as required or permitted by applicable ICANN policies or law. You consent to the collection, use, and processing of your Personal Data for the purposes described above; You consent to certain data being transferred to ICANN (as described in the ICANN Privacy Policy ) and to other third parties as described; and, Where you have supplied Personal Data relating to a third party (someone that is not you) for a domain registration, you have obtained that individual's equivalent consent. Data Handling For Domain Name Registrars : Lovable provides domain registrations through cooperation with domain name registrars subject to the Domain Name Registration Terms. To provide domain registrations Lovable may process your Personal Data to: Process and maintain your domain name registration; Comply with applicable ICANN requirements, including the publication of certain data elements in the Registration Data Directory Service (RDDS); Enable the sponsoring registrar and applicable registry operator to fulfil their obligations under the Registrar Accreditation Agreement and applicable registry agreements; Communicate with you regarding your domain name registration, including verification and renewal, and any other ICANN-required communications. The Personal Data required to fulfil the domain purchase will be clearly indicated to you during the purchase flow. Any additional data fields not marked as required are voluntary. Your Personal Data may be shared with: The applicable registry operator; ICANN; Any ICANN-authorised escrow service provider; and Other third parties as required or permitted by applicable ICANN policies or law. By completing a domain purchase, you confirm that: You consent to the collection, use, and processing of your Personal Data for the purposes described above; You consent to certain data being transferred to ICANN (as described in the ICANN Privacy Policy ) and to other third parties as described; and, Where you have supplied Personal Data relating to a third party (someone that is not you) for a domain registration, you have obtained that individual's equivalent consent. You may access, correct, or request deletion of your Personal Data at any time by contacting us at privacy@lovable.dev , as described in this Policy. Lovable and its registrar partners take reasonable technical and organisational precautions to protect your Personal Data against loss, misuse, unauthorised access or disclosure, alteration, or destruction, as outlined in this Policy. In the event that Lovable changes its registrar partner or ceases operations, your domain name and associated registration data (including DNS records, nameserver configuration, authorisation codes, and expiry dates) will be made available to you or transferred to a new registrar on your behalf in accordance with the ICANN Bulk Transfer process. Lovable will not impose any lock or restriction on your domain that prevents transfer, except as required by ICANN policy or applicable law. Children's Data : Lovable's Services are not intended for individuals under the age of eighteen (18), and we do not knowingly collect or solicit Personal Data from anyone under this age, unless as part of a program with a partner, the child has obtained consent or authorisation from a parent or guardian before they can use the Services. By using our Services, you represent that you are at least 18 years old or the age of majority in your jurisdiction. If we discover that we have collected Personal Data from a minor without verifiable parental consent, we will promptly delete that information. If you believe we may have collected such data, please contact us at privacy@lovable.dev . Sensitive Data : Lovable does not intentionally collect special-category or sensitive Personal Data, such as biometric identifiers, health information, or precise geolocation, and instructs customers not to upload such information. This definition will be interpreted to include any equivalent term under other privacy laws that come into force during the life of this Policy. We process Personal Data for the following purposes: to provide, operate, and maintain the Services, including storing code, generating suggestions, and deploying applications; To personalize your experience and tune AI-driven features for your workspace, unless you withdraw consent by emailing us at privacy@lovable.dev ; to analyze usage patterns and improve performance, functionality, and reliability; to detect, prevent, and investigate fraud, abuse, or security incidents; to deliver product updates and measure the effectiveness of our own marketing; to communicate with you and provide customer support, as permitted by your account settings; to process payments and other transactions you authorize; to comply with legal, regulatory, export-control, and sanctions obligations in the jurisdictions where we operate; and to meet record-keeping, accounting, and audit requirements. Lovable does not engage in automated decision-making that produces legal or similarly significant effects on individuals (GDPR Art 22). We collect only the Personal Data necessary for these purposes and retain it in line with the schedule in the Policy. You can exercise your opt-out or objection rights to certain processing activities as described in this Policy. How we use your Personal Data Lovable processes Personal Data only where a valid legal ground applies under each privacy regime that governs our Services. Legal bases we rely on: Performance of a Contract: We process your Personal Data to provide, maintain, and support the Services you have requested under our Terms of Service or other agreement with you. Legitimate Interests: We use Personal Data to secure the platform, detect fraud, generate aggregate analytics, and improve AI features where these interests are not outweighed by your privacy rights. Consent: We rely on your opt-in consent for non-essential cookies, marketing e-mails, and any other processing that requires consent under Data Protection Laws. You may withdraw consent at any time without affecting the lawfulness of prior processing. Legal Obligations: We retain and disclose information as necessary to comply with bookkeeping rules, export-control and sanctions regulations, court orders, or other legal duties. Protection of Vital Interests: In rare cases, we may process Personal Data to protect an individual's vital interests, such as preventing serious harm or responding to an emergency. Data Processing and Sub-Processors As a data processor, Lovable processes Personal Data on behalf of our customers in accordance with their instructions and applicable DPAs. We engage third-party sub-processors to support our Services, such as: Hosting and maintaining our platform, website, and databases. Processing payments through secure third-party payment processors. Providing technical support, customer service, and analytics. Storing and securing data, including integrations with Supabase and GitHub. All sub-processors are bound by contractual obligations equivalent to those in our DPAs, ensuring compliance with Data Protection Laws. We provide notice of sub-processor changes, allowing customers to object within ten (10) business days. The current list of authorized sub-processors is available at https://trust.lovable.dev and includes the sub-processor's name, location, and processing purpose. We do not sell your Personal Data. Data Usage We do not use raw or identifiable Personal Data for training but may anonymize/aggregate it for any lawful purpose. To opt out of using your Customer Data for model training, contact us at privacy@lovable.dev or upgrade to a Business plan with enhanced controls.

ADDED"Personal Data" means any information relating to an identified or identifiable natural person, or that is reasonably capable of being linked to a particular person or household. It includes, for example, your name, email address, phone number, payment details, IP address, device and browser identifiers, authentication tokens, and usage and telemetry logs that relate to you. Where a law that applies to you uses a different term - such as "personal information" under U.S. state privacy laws or "dados pessoais" under the LGPD - we mean whatever that law covers. "App" means anything you build or publish with Lovable - a website, web app, online store, internal tool, mobile app, or other software project. When this Policy says "app" or "apps and websites," it means Apps in this sense. "Customer Content" means the content you submit to or create with the Services: prompts, code, project files, hosted applications, configurations, and generated outputs. Customer Content may contain Personal Data. Customer Content does not include Your Users' Data. "Your Users' Data" means Personal Data that people who use your Apps - including your websites - provide to those Apps or that your Apps collect about them - for example your App's user accounts, form submissions, orders, and the records in your project's database and storage. It does not include data about people you invite to collaborate in your Lovable workspace, who are covered by the rest of this Policy. "App Usage Data" means a category of Your Users' Data: usage event data generated by people using your Apps and collected through Lovable-provided analytics instrumentation, as described in Section 7A. "Usage Data" means data about how the Services are accessed and used: feature events, API calls, build and deployment events, metering and billing telemetry, log data, and diagnostic information. Where Usage Data relates to an identifiable person (for example, because it is tied to your account or device), it is Personal Data and is protected as such. "De-identified Data" means data that no longer identifies and cannot reasonably be linked to any person or household, whether aggregated or individually de-identified. We maintain De-identified Data in de-identified form, do not attempt to re-identify it (except to test the effectiveness of our de-identification), publicly commit to processing it only in de-identified form, and contractually require recipients to do the same, as U.S. privacy laws require. We may use and disclose De-identified Data for any lawful purpose. Personal Data We Collect Information you provide or generate. Account details (name, email address, and how you sign in - a password, or single sign-on through a provider such as Google or GitHub), profile information, payment information (processed by Stripe; we do not store full card numbers - see stripe.com/privacy ), Customer Content you submit or generate using the Services, communications with us, and information you provide when registering domains (see Section 9). Information collected automatically. Metadata about your use of the Services: IP address and approximate (city-level) location, browser and OS type, device identifiers, session identifiers, pages and features used, build/deploy and API events, metering and billing telemetry, error and diagnostic logs, and cookie data as described in Section 7. Information from integrations you enable. If you connect a third-party integration (for example GitHub, Supabase, or an MCP connector), we receive the data that integration makes available under the permissions you grant, plus authentication status and integration-usage events. We access only what the integration you enabled requires. Connections your App makes for its own users are different: what your App's users send through them is Your Users' Data (Section 2), which we process only on your behalf. Where an integration operates under terms you accept directly with its provider, that provider's agreement and privacy policy govern its side of the exchange. Connections made locally through a desktop application are described below. Data made available to us by a messaging or collaboration platform you connect is used only to operate the integration and generate responses; we do not use it to train AI models. Device features and local processing. Some of our applications - for example, Lovable Desktop - can use your device's files, microphone, camera, or screen, only where you enable the feature. What you transmit to us or to an AI model provider this way is Customer Content, handled under this Policy. Where a feature processes data entirely on your device and nothing is transmitted to us, we do not receive it, and this Policy does not apply to it. You are responsible for any consents needed before recording or sharing information about others. Feature-specific controls are described in the applicable terms, such as our Desktop App Terms . Information from other sources. Payment and fraud signals from our payment processor; technical signals from security vendors protecting the Services; measurement data flowing back from the advertising platforms described in Section 6; and publicly available information where the law permits. How We Use Personal Data We use Personal Data for the following purposes: Provide the Services - provide, operate, secure, and maintain the Services, including storing and running your projects and generating outputs; Personalize - personalize your experience and tune AI-driven features for your workspace; Train and develop our AI models - train, develop, and improve our AI models, as described in Section 5 (with an opt-out); Improve and research - analyze usage to improve performance, functionality, and reliability; test and compare features, interfaces, and model configurations; and conduct surveys and user research (with your participation); Protect and secure - detect, prevent, and investigate fraud, abuse, security incidents, and violations of our terms, and protect the safety of users and the public (including as described in Section 8); Payments and billing - process payments and meter usage-based services against your credits; Communicate - communicate with you, provide support, and send service notices; Market and advertise - market our own services, measure our marketing, and - where you have the choices described in Section 6 - for advertising; Create De-identified Data - create aggregated or De-identified Data (Section 2), which we maintain and use as described there; and Comply with law - comply with legal, regulatory, tax, export-control, and sanctions obligations, and establish, exercise, or defend legal claims. We use automated systems to detect fraud, abuse, and security risks. If an automated decision significantly affects you - for example, an account suspension - you can request human review and appeal the decision by contacting privacy@lovable.dev . AI Model Training and Your Opt-Out What we use. We use Customer Content and Usage Data - which may include Personal Data - to train, develop, fine-tune, and improve our AI models and AI-powered features, including models we operate within the Services and models we may make available to customers through Lovable products such as the AI Gateway. Trained members of our team may review this content to check model quality and diagnose failures, under the confidentiality and access safeguards described in Section 14. What we do not train on. Your account and billing details. We use them to run your account, not to train our models. Business and Enterprise Customer Content or Usage Data. We set out this prohibition in our Data Processing Agreement. Your Users' Data (Section 2), including App Usage Data. It is held in your project's own database and storage, and we do not use it to train our models. Your opt-out. You can opt out of model training at any time in your account settings, on any plan, at no cost, and it does not affect your use of AI features. Opting out takes effect going forward: your content is excluded from all training data assembled after your opt-out takes effect. It does not retract content from training datasets assembled, or models trained, before you opted out. What about the AI companies whose models we use? When your content is sent to a third-party model provider (or providers), our agreements with that provider restrict its use of your content, including for training - see Section 8. Advertising and Sharing With Ad Platforms What we do. With the choices described below, we share limited Personal Data - pseudonymized identifiers, not the contents of your projects - with advertising platforms such as Meta and Google for the following purposes: Suppression: excluding existing customers from paid advertising, so we do not pay to advertise to people who already use Lovable; Audience targeting: showing Lovable ads to our contacts on those platforms; and Lookalike audiences: asking those platforms to reach new people that resemble our customers. The only information a platform receives from us is the identifier used for matching. Your choices. In the EEA, UK, Switzerland, and Brazil, we do this only with your consent, which you can withdraw at any time in your privacy settings. In the United States, this sharing may constitute a "sale" or "sharing" of personal information under state privacy laws; you can opt out at any time via the "Do Not Sell or Share My Personal Information" link in our website footer where required, via your privacy settings, or by broadcasting a Global Privacy Control (GPC) signal, which we honor as an opt-out for the browser or device sending it. We also use cookies for advertising measurement as described in Section 7. We do not share Customer Content or Your Users' Data with advertising platforms, unless you instruct us to do so, and we do not use the contents of your projects for advertising. Cookies, Analytics, and Session Recording Lovable and selected partners use cookies, pixels, SDKs, and similar technologies to operate, secure, analyze, and market the Services. We group them as follows: Strictly necessary - sign-in, session routing, fraud prevention, consent storage. No consent required. Analytics & performance - feature adoption, error diagnosis, and service performance, using first-party and third-party analytics providers. Session recording - with your consent where required, we record a sample of sessions, with a session-replay provider acting on our behalf, to understand how the product is used and to fix usability problems. Recordings capture interactions such as clicks, scrolling, and navigation. We configure the tool to mask the input of project chat, so that what was typed there is not captured; recordings are not used to train AI models. Where required, you can withdraw consent in the Cookie Preferences panel, which stops future recording. Functional - preferences such as language, theme, and layout. Marketing - conversion tracking and campaign measurement for the advertising platforms described in Section 6. The specific cookies we and our providers set, including names, providers, and durations, are listed in the Cookie Preferences panel ( lovable.dev/cookie-policy ). In the EEA, UK, and Switzerland we obtain consent before setting non-essential cookies. In the United States we honor opt-out preference signals such as GPC. You can manage preferences any time via the Cookie Preferences panel or your browser. Analytics in Apps and Websites You Publish (App Usage Data) If enabled by you, your Apps and websites built on Lovable can include analytics instrumentation - we call the data it produces App Usage Data - so that you, and Lovable's agent acting for you, can understand how your App performs. When you enable it for an App, we collect measurement data about visits and events: for example, how many times pages and features are used, approximate location, device type, and where traffic came from. The instrumentation is designed for aggregate measurement rather than to identify or track individual people, and it collects the minimum needed for that purpose. What is collected, and the controls available to you, are described in our product documentation. App Usage Data is Your Users' Data (Section 2): you control it, and we process it on your behalf to provide your analytics and recommendations. We also produce De-identified Data from it (Section 2), which we use to improve the Services and to give you comparative insights. You are responsible for your App's privacy notice and any consents your App requires. Who Receives Your Personal Data Service providers and sub-processors - hosting, payment, support, analytics, and AI infrastructure providers acting on our instructions under contracts consistent with this Policy. Our current sub-processor list, including each provider's location and purpose, is at trust.lovable.dev . Integrations you enable - when you connect a third-party service, we send that service the data it needs to perform the integration, limited to what you authorize. What that service does with the data is governed by its own privacy policy. AI model providers - when you use features that generate content or code with AI, your prompts and related Customer Content are transmitted to one or more of the model providers we use. Our agreements with these providers restrict their use of your content. Our current model providers are listed at trust.lovable.dev . Advertising platforms - as described in Section 6, subject to your choices. Domain partners and registries - when you register a website address through us, as described in Section 9. An organization that claims your account (for example, your employer) - as described in Section 10. Law enforcement, courts, and safety organizations - where we believe disclosure is required by law or legal process, or is necessary to protect the rights, property, or safety of Lovable, our users, or the public. This includes reporting apparent child sexual abuse material to the U.S. National Center for Missing & Exploited Children (NCMEC), as U.S. law requires, and cooperating with the resulting processes. Acquirers, investors, and their advisers - if we enter into or negotiate a merger, acquisition, financing, or sale of assets, Personal Data may be disclosed to the other parties and their professional advisers, and may transfer as part of the transaction. This Policy continues to apply to that Personal Data unless and until you are given notice of a different policy. We share limited Personal Data - pseudonymized identifiers, not the contents of your projects - with the advertising platforms described in Section 6. Some U.S. state privacy laws treat this as a "sale" or "sharing" of personal information, and you can opt out at any time via the "Do Not Sell or Share My Personal Information" link in our website footer, your account settings, or a Global Privacy Control signal. In the EEA, UK, Switzerland, and Brazil, this sharing happens only with your consent. We do not share Customer Content or Your Users' Data with advertising platforms, unless you instruct us to do so. Domains You Register Through Lovable If you buy a domain through Lovable, the contact details you provide are shared with the registrar and registry that operate it, and - where ICANN's rules require - with ICANN and a data escrow provider. For most domain endings your personal details are hidden from public lookups by default. You can view and correct these details in your account settings; full terms are in the domain registration agreement you accept at checkout. If You Signed Up With an Organization's Email Address (Domain Claims) If you created your account with an organization's email address - an address at a domain owned by your employer, university, or another organization, rather than a personal one - that organization can verify it owns the domain and "claim" accounts registered under it. Here is how it works: What the organization can see. The organization's administrators can see limited information about accounts registered with email addresses on that domain: email address, display name, number of workspaces and projects, and last-active date. They cannot see the contents or names of your projects unless and until your account transfers. Notice and your choice. You will be notified by email or in the product. You will then have an opportunity to either join the organization or keep your account personal by changing your account email to an address outside the claimed domain. If you do not choose. Your account transfers to the organization on the date stated in the notice. After transfer. The organization controls the account (including sign-in and billing) and its agreement with us governs it. The organization becomes responsible for deciding how the data in the account is used, and Lovable handles that data on the organization's behalf. Our Legal Bases for Processing Where the law requires us to have a legal basis for using your Personal Data, these are the bases we rely on: To provide the Services - processing necessary to give you the Services you signed up for, including support and billing. Our legitimate interests - securing the platform, preventing fraud and abuse, aggregate analytics, service improvement, AI model training subject to Section 5's opt-out, and establishing, exercising, or defending legal claims - in each case where our interests are not outweighed by your rights. Your consent - non-essential cookies, marketing emails, the advertising uses described in Section 6, and taking part in surveys or research. You can withdraw consent at any time, which does not affect processing that already took place. Complying with legal obligations - bookkeeping, tax, sanctions and export controls, mandatory safety reporting, and responses to lawful process. Protecting life - rare emergencies where processing is needed to protect someone's life or physical safety. In Brazil, we rely on the equivalent bases under the LGPD. Swiss law does not require a legal basis in the same way; there we apply the principles of Switzerland's Federal Act on Data Protection together with the protections described in this Policy.

International Data Transfers

REMOVEDFor customers in the EEA, UK, or Switzerland, we may transfer Personal Data to the United States or other jurisdictions whose privacy laws have not been deemed "adequate" by European or Swiss authorities. Lovable safeguards these transfers through the following legally recognized mechanisms: EU Standard Contractual Clauses (SCCs): Module 2 (Controller-to-Processor) per Commission Decision 2021/914. UK International Data Transfer Addendum: Version B1.0, issued by the UK ICO under s119A DPA 2018. Swiss Addendum: Adapts the SCCs to the revised Swiss FADP, naming the Swiss Federal Data Protection and Information Commissioner (FDPIC) as the competent authority. Investigations Lovable may investigate and disclose information, as permitted by law, if we believe in good faith that such action is: Necessary to comply with a valid legal process or governmental request (e.g., subpoena, court order, or law-enforcement demand) and, unless legally prohibited, Lovable will notify the affected customer before producing data. Helpful to prevent, investigate, or identify fraud, security incidents, or other wrongdoing in connection with our Services. Necessary to protect our rights, reputation, property, or those of our users, affiliates, or the public. Disclosures will comply with Data Protection Laws and be limited to what is necessary. Log Data When you use our Services, Lovable automatically collects operational telemetry (" Log Data ") that helps us secure and improve the platform. Log Data may include: Your device's IP address and approximate location Browser type and version. Pages, APIs, or features you access within the Services. Timestamps and time spent on specific screens or functions. Unique session or device identifiers and error/debugging codes. Other usage statistics. Log data is retained for up to ninety (90) days, unless required by law, to monitor performance, troubleshoot issues, and improve user experience. Cookies and Other Tracking Lovable and selected third-party partners use cookies, pixels, and similar technologies (" Cookies ") to operate, secure, and analyze our Services. We deploy four types of Cookies: Strictly Necessary Cookies support core functions such as sign-in, session routing, fraud prevention, and consent storage. These are set on the basis of legitimate interests / contract performance and do not require consent. Analytics & Performance Cookies measure feature adoption, diagnose errors, track user interactions, and improve service performance. We use first-party analytics (PostHog) and third-party services (Google Analytics, TikTok) for these purposes. We obtain prior consent for these Cookies in the EEA/UK/CH and honor CPRA "opt-out" signals (e.g., Global Privacy Control) in the United States. Functional Cookies remember your preferences (language, theme, layout) and are configurable in the in-product Cookie Settings panel. Marketing Cookies enable conversion tracking and campaign measurement through third-party services including Tiktok, Facebook/Meta, and Google Ads. While we use these cookies to measure the effectiveness of our marketing efforts, we do not "sell" or "share" Customer Personal Data for cross-context behavioral advertising as defined under Data Protection Laws. These cookies require consent in the EEA/UK/CH and respect opt-out preferences in other jurisdictions. You can manage or withdraw your Cookie preferences at any time by (i) clicking the Cookie Preferences button in our Cookie Policy , (ii) changing your browser controls, or (iii) enabling an authorized browser signal such as the Global Privacy Control. Disabling non-essential Cookies will not affect core functionality but may limit analytics-based improvements. Cookie-derived identifiers are retained only for the period necessary to fulfil the purposes above and never longer than thirteen (13) months for analytics cookies after which they are deleted or irreversibly anonymized. Information Security and Accuracy Lovable is committed to protecting your Personal Data and maintaining its accuracy. We implement reasonable industry standard safeguards, including: Data in Transit: All traffic between your browser or API client and our servers is protected with industry standard end-to-end encryption. Data Storage: Database encryption with secure key management and pseudonymize or anonymize data, where feasible. Access Controls: Role-based access, multi-factor authentication, and regular reviews to ensure only authorized staff can view your data. System Resilience: Continuous backups with industry-standard recovery objectives designed to minimize downtime and data loss. Security Monitoring: Real-time monitoring, centralized logging with one-year retention, and annual SOC 2 Type II audits. Physical Security: Data is hosted in SOC 2- and ISO 27001-certified data centers with 24/7 guards, biometric access, CCTV, and environmental safeguards. Staff & Vendor Oversight : All employees pass background checks, sign confidentiality agreements, and receive yearly security training; sub-processors are vetted and contractually bound to equivalent protections. Incident Response: We maintain a 24/7 incident-response team and will notify affected customers within 72 hours of confirming any notifiable breach. Your Role: Please keep your account credentials confidential, enable multi-factor authentication, and let us know if any of your information is incorrect so we can update it. Lovable keeps a record of processing activities in line with GDPR Article 30(2) and performs regular risk assessments to adapt these measures as threats evolve. If you believe your account information is inaccurate, contact us as set out in this Policy and we will correct it promptly. We implement reasonable security measures (e.g., encryption in transit/rest, access controls) to protect your Personal Data, but our Services rely on third-party providers like Supabase (for Lovable Cloud), OpenAI, Google, and OpenRouter (for AI Gateway). We cannot guarantee uninterrupted availability, security, or performance of these providers, and data interruptions, delays, or losses may occur due to their actions or events beyond our control (including force majeure). For Lovable Cloud, certain provisioned resources may not be immediately terminable via API; you remain responsible for any data hosted there until fully decommissioned. In cases of misuse or abuse (e.g., excessive data uploads causing cost spikes), you agree to indemnify us for related privacy or security claims arising from third-party provider interactions, as detailed in our Terms of Service. We use commercially reasonable efforts to notify you of material security incidents involving your data but disclaim liability for third-party failures. Retention of Your Information We retain Personal Data only as long as necessary to fulfill the purposes outlined in this Policy or as required by applicable law, including: Providing and improving our Services. Complying with legal and regulatory obligations. Resolving disputes or enforcing agreements. Customer data is retained for up to ninety (90) days, unless required by law, after which it is deleted or isolated. To cancel your account or request data deletion, contact us as outlined in the Policy. Upon account termination or expiration (including forfeiture of unused Credits as per the Terms), we will delete your Personal Data within 30 days, except for data required for fraud prevention, legal compliance, or legal defense purposes. Backups may retain data for up to 90 days. To request deletion, contact us at privacy@lovable.dev ; we comply with Data Protection Laws (e.g., GDPR erasure rights). We retain Customer Data only as needed to provide the Services, with deletion available upon request (subject to backups and legal holds). Links to Other Sites and Integrations Our Services may include links or integrations (for example, GitHub, Supabase, CI/CD tools, or payment providers) that are not controlled by Lovable. Your interactions with Third-Party Services are governed by their own privacy policies and terms. We encourage you to review those policies before providing Personal Data, as Lovable is not responsible for the privacy or security practices of external sites or integrations. Notice and Communications By using the Services, you consent to receive transactional or administrative electronic communications from Lovable - such as account alerts, security notifications, and billing messages. You may opt out of non-essential marketing e-mails at any time via the "unsubscribe" link or your account settings; this will not affect core service communications. To send formal privacy notices to Lovable, e-mail privacy@lovable.dev or post to the address in this Policy. Lovable may provide legal or privacy notices to you via e-mail, in-product banners, or any other method allowed by law. Governing Law & Venue This Policy is governed by and governed in accordance with the laws of the State of Delaware, United States, without regard to its conflict-of-law principles. However, if you are located in a jurisdiction that grants you mandatory consumer protection or data protection rights under local law, those provisions will take precedence to the extent they conflict with this Policy. For residents of the European Economic Area (EEA), United Kingdom (UK), or Switzerland, international data transfers are subject to the EU Standard Contractual Clauses governed by Irish law with the courts of Dublin as the chosen forum, the UK International Data Transfer Addendum governed by the laws of England and Wales with the courts of London as forum, and the Swiss Addendum governed by Swiss law with the FDPIC as the competent authority. Any other disputes arising under this Policy shall be exclusively resolved in the state or federal courts located in Wilmington, Delaware, unless otherwise required by applicable mandatory law. We disclaim warranties on data accuracy/security in AI outputs or third-party services. See Terms for IP ownership (you own Customer Data/AI Output; we own Usage Data). Residents of the United States, Canada, EEA, United Kingdom, and Switzerland This section supplements the rest of the Policy and applies to individuals located in the United States-including California, Colorado, Connecticut, Virginia, Utah, Florida, Nebraska, and any other state with an active consumer-privacy statute, as well as Canada, the EEA, the United Kingdom, and Switzerland. Lovable collects the personal information categories below when you use the Services: Identifiers such as name, business-e-mail, phone number, user ID, and IP address (city-level location only). Commercial information such as subscription tier and purchase history; full payment-card numbers are processed solely by our PCI-compliant provider and are never stored by Lovable. Internet / network activity such as log-in events, feature usage, prompts submitted, code generated, and telemetry. Inferences drawn to personalize the platform. Project information you upload (e.g., repositories and configuration files). Sensitive Personal Information is not intentionally collected, and customers are instructed not to upload sensitive data (for example, Social-Security numbers or precise geolocation). No sensitive data (e.g., HIPAA-protected health info, financial accounts) should be uploaded; our Services are not designed for it, and we disclaim responsibility if submitted. Depending on where you live, you may have some or all of the rights listed below (subject to legal limits). You can exercise them by e-mailing privacy@lovable.dev ; Lovable will verify your identity and respond within 30 days or the period required by your local law. Right of Access/Portability: Request disclosure of personal information collected, used, or disclosed. Right of Deletion: Request deletion of personal information, subject to exceptions. Right to Correct: Request correction of inaccurate personal information. Right to Withdraw Consent: Withdraw consent for certain processing activities. Opt-out of sales, sharing, or targeted advertising: Opt out of the sale or sharing of personal information. Lovable does not sell or share personal information as defined under U.S. privacy laws. Lovable will not discriminate against you for exercising your privacy rights. If you believe a request has been wrongly denied, U.S. residents may file an appeal by replying to our decision within sixty days; EEA, UK, or Swiss residents may contact their supervisory authority (the Irish DPC, the UK ICO, or the FDPIC). Changes to This Policy Lovable reserves the right to update or revise this Privacy Policy to reflect changes in our practices, legal requirements, or the Services themselves. We will post any revised Policy at https://lovable.dev/privacy and indicate the "Effective" date at the top of the document. For material changes that reduce your rights or expand our processing purposes, we will provide at least thirty (30) days' advance notice by e-mail or in-product banner. Your continued use of the Services after the new Policy takes effect constitutes acceptance of the revised terms. Severability If any provision of this Policy is found to be unlawful, void, or unenforceable under applicable law, that provision will be interpreted to achieve its intent as closely as possible, or, if impossible, deemed severed, and the remaining provisions will remain in full force and effect. Contact Details If you have questions, concerns, or wish to exercise your privacy rights, please contact us. We have appointed a Data Protection Officer (DPO) that you can contact at: a. Email: dpo@lovable.dev b. Representative name: Assenteo Ltd c. EU Address: Lovable Labs AB, Regeringsgatan 25, 111 53 Stockholm, Sweden We aim to respond to verified data-subject requests within thirty (30) days, or longer where permitted under applicable law, in which case we will notify you of the delay and reason. If you believe your inquiry has not been satisfactorily resolved, you may lodge a complaint with your local supervisory authority, the Irish Data Protection Commission, the UK Information Commissioner's Office, or the Swiss FDPIC, as appropriate. Entire Agreement This Policy, together with the Terms of Service constitutes the entire agreement between you and Lovable regarding privacy and data protection in connection with the Services.

ADDEDOur main establishment is in Stockholm, Sweden and Integritetsskyddsmyndigheten (IMY), the Swedish Authority for Privacy Protection, is our lead supervisory authority. We and our service providers process Personal Data in a number of countries, including the United States. This means your Personal Data may be transferred outside the country or region where you live. Where Personal Data is transferred from a jurisdiction that restricts international transfers, we use legally recognized mechanisms: EEA: the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), with transfer impact assessments where required. UK: the UK International Data Transfer Addendum issued under section 119A of the Data Protection Act 2018. Switzerland: the EU Standard Contractual Clauses with the Swiss addendum recognized by the Federal Data Protection and Information Commissioner, applying Switzerland's Federal Act on Data Protection. Brazil: the Brazilian Standard Contractual Clauses approved by the ANPD (Resolution CD/ANPD No. 19/2024), or another transfer mechanism recognized under Brazilian law. You can request a copy of the relevant transfer safeguards, with commercially sensitive terms redacted, at privacy@lovable.dev . Data Retention We keep Personal Data only as long as needed for the purposes described in this Policy or as the law requires, then delete or de-identify it. How long that is depends on the data: Your account and Customer Content - kept while your account is open, then deleted or de-identified after it closes or after a verified deletion request, unless the law requires us to keep it longer. Deletion does not retract content from training datasets assembled, or models trained, before your request took effect (see Section 5). Operational and security logs - kept for as long as needed to run and secure the Services, and longer where we are investigating an incident. Analytics identifiers - see lovable.dev/cookie-policy . Billing and tax records - for the periods accounting and tax law require. Records of notices, consents, opt-outs, and account transfers - kept as evidence that we met our obligations, for as long as a claim or regulatory question about them could still arise. Information Security We protect Personal Data with technical and organizational measures appropriate to the risk, and we review them as our Services and the threats to them change. No system is perfectly secure, so we also rely on you to help protect your account. Protecting data - encryption in transit and at rest, with managed keys, and regular backups. Controlling access - access limited by role to staff who need it, multi-factor authentication, and periodic access reviews. Detecting and responding - security monitoring, centralized logging, and an incident response process. Where a breach is notifiable, we inform affected users and regulators within the timeframes the law requires. Our people and vendors - staff are bound by confidentiality obligations and receive security training; vendors are assessed before we use them and bound by contract. Current information about our security certifications and audit status is published at trust.lovable.dev . Your Privacy Rights and How to Exercise Them You can ask us to provide a copy of your personal data, including in a portable, machine-readable format, to correct it, or to delete it along with your account. You can also object to or restrict certain processing, withdraw any consent you have given, opt out of model training (Section 5), and opt out of advertising-related sharing (Section 6). Use your account settings or email privacy@lovable.dev . We respond within the period your local law requires, and we will tell you if we need longer and why. If you are in the EEA, UK, or Switzerland you may complain to your supervisory authority (for us: Integritetsskyddsmyndigheten in Sweden, the UK ICO, or the FDPIC); in Brazil, to the ANPD; in Canada, to the OPC; in the US, see Section 17. If you used an app or website someone built with Lovable. The person or organization that built it decides what data it collects and why, so they are responsible for that data. Send your privacy requests to them; their own privacy notice should say how to reach them. Children Our Services are intended for adults. You must be 18 or older to create your own Lovable account. Organizations - including schools and education partners - can also use Lovable under a written agreement with us to give people under 18 supervised access as part of a program. Where that happens, the organization decides what is collected and why, and is responsible for obtaining any consent the law requires from a parent or guardian. We process that data only on the organization's instructions, and the organization is the point of contact for privacy requests about it. If we learn that someone under 18 has created an account outside such a program, we will close it and delete the Personal Data associated with it. Parents, guardians and organizations can reach us at privacy@lovable.dev . United States State Privacy Disclosures This section supplements the rest of the Policy for residents of U.S. states with comprehensive privacy laws, including California. In the preceding 12 months we have collected the categories of personal information below and disclosed them as indicated. The sources we collect from are described in Section 3, the purposes we use them for in Section 4, and how long we keep each category in Section 13. Category Examples Disclosed for business purposes to Sold or shared? Identifiers Name, email, IP address, user ID, device identifiers Service providers; integrations you enable Shared: pseudonymized identifiers to ad platforms (opt-out available) Commercial information Subscription tier, purchase history Payment processor; service providers Internet or network activity Feature usage, log-in events, session recordings, telemetry Service providers, including analytics and session-replay providers Shared: cookie-based ad measurement (opt-out available) Geolocation (coarse) City- or region-level location from IP address Service providers User content Projects, prompts, code, and configurations you upload or create Service providers; AI model providers; integrations you enable Inferences Preferences used to personalize the Services Sensitive personal information Account log-in credentials Service providers, to authenticate you Your rights. Depending on your state, you may have the right to know and access your personal information, to have it corrected or deleted, and to receive a portable copy - including, where you ask for it, information collected more than 12 months ago. You may also have the right to opt out of the sale or sharing of personal information, of targeted advertising, and of profiling used to make decisions that have legal or similarly significant effects; and to limit our use of sensitive personal information. We collect account log-in credentials as sensitive personal information and use them only to authenticate you, which is not a use that requires that limit. Your state may give you additional rights, and we will honor them. How to exercise them. To opt out of advertising-related sharing, use the "Do Not Sell or Share My Personal Information" link in our website footer, your privacy settings, or send a Global Privacy Control signal. For any other right, email privacy@lovable.dev or use the in-product privacy controls. For requests to know, delete, or correct, we verify your identity using the email address on your account, and we may ask for information needed to match your request to our records. We do not require you to verify your identity to opt out of sale or sharing, or to limit the use of sensitive personal information. We respond within the time your state's law requires. An authorized agent may submit a request on your behalf with proof of authorization. We will not discriminate against you for exercising your rights. If we say no. You may appeal by replying to our decision. We will respond to your appeal within the time your state's law requires, and if we deny it you may contact your state Attorney General. Canada For Canadian users, we process Personal Data in accordance with PIPEDA and applicable provincial laws. You may access or correct your Personal Data and withdraw consent as described in Section 15, and you may complain to the Office of the Privacy Commissioner of Canada. Brazil - LGPD Disclosures This section supplements the Policy for users in Brazil. Lovable Labs Sweden AB is the controller (controladora) of Personal Data processed under this Policy; after a domain-claim transfer (Section 10), the claiming organization is the controller and Lovable is the operator (operadora). Your rights. You may obtain, at any time and free of charge: confirmation that we process your data; access to it; correction of incomplete, inaccurate, or outdated data; anonymization, blocking, or deletion of unnecessary, excessive, or unlawfully processed data; portability to another provider; deletion of data processed with your consent; information about the public and private entities with which we have shared your data; information about the consequences of refusing consent; and revocation of consent. Where we rely on legitimate interest, you may object. You may also ask us to review a decision taken solely by automated processing that affects your interests, and to explain the criteria we used to make it. We respond via privacy@lovable.dev . Encarregado (DPO). Our Encarregado for Brazil is reachable at dpo@lovable.dev . You may also lodge complaints with the Autoridade Nacional de Proteção de Dados (ANPD) at gov.br/anpd . International transfers from Brazil are made under the mechanisms described in Section 12. Changes to This Policy If we make material changes - changes that reduce your rights or significantly expand how we use your Personal Data - we will give you at least thirty (30) days' notice before they take effect, using a method reasonably likely to reach you, such as an in-product notice, a prominent notice on our website, or an email. Where the law requires your consent for a specific change, we will ask for it. Policy history. Earlier versions of this Policy are available upon request to privacy@lovable.dev . Contact Us Questions, concerns, or rights requests: privacy@lovable.dev . Data Protection Officer: dpo@lovable.dev . Our address: Lovable Labs Sweden AB, Regeringsgatan 25, 111 53 Stockholm, Sweden. Brazil encarregado: see Section 19. If we cannot resolve your concern, you may contact your supervisory authority as described in Section 15. Lovable Labs Sweden AB is the entity responsible for the Personal Data processed under this Policy (the "data controller" where that term applies).