# Lovable

## Kurzbeschreibung
**“Build something Lovable”**


**Lovable **is an AI-powered app and website builder that enables users to create, iterate on, and publish apps, websites, prototypes, and digital products via chat. The platform combines prompting, visual editing, code mode, GitHub sync, hosting/deployment, as well as backend options via Lovable Cloud or Supabase.

## Claim
Create apps and websites by chatting with AI

## Geeignet für
- API Integration
- Design / Graphics
- Customer Service & Chatbots
- Marketing & Advertising
- no Code App
- Programming / Software Development
- SEO / GEO Optimization
- Websites / Landing Pages

## Kernfunktionen
- App Development
- Programming
- Website Development

## Preismodell
- **free:** Free entry-level version with daily credits, a monthly credit cap, subdomains, and collaboration capability; suitable for trying out and for simple projects.
- **subscription:** **Pro** Paid individual/creator plan with more monthly credits and more room for serious app projects. Credits are consumed for AI prompts in Plan Mode and Agent Mode.


**Business** Team-oriented plan with team features, advanced controls, and DPA usage; suitable for professional use in organizations.
- **other:** **Enterprise** Custom Enterprise offering with advanced security, governance, support, and data control requirements.


**Credits / Cloud Credits **Lovable uses Credits for AI agent prompts; cloud infrastructure such as database, functions, and storage uses separate Cloud Credits.

## DSGVO und Datenschutz
**Gesamteinschätzung:** Conditional

**On-prem / local hosting: partially**


The website does not specify a true on-premise option for the entire Lovable platform. However, there is a documented path for running the backend and data outside of Lovable Cloud or on your own infrastructure, specifically via self-hosted Supabase; the website also states that the production frontend can run on Lovable Cloud or elsewhere.


**Private Cloud / Data Center: Partially**


The website mentions regional data storage and enterprise security documentation, but does not mention a dedicated private cloud, a customer-specific, isolated EU data center model, or an explicit single-tenant/private cloud description. Therefore, only partially covered.


**EU SaaS / Managed: Covered**


Lovable operates a managed SaaS service called Lovable Cloud and lists EU regions for data storage on its security page. It states that customer data remains in the selected region and is not moved across regions by default.


**Hybrid: covered**


The documentation explicitly describes hosting outside of Lovable Cloud for teams with compliance or data residency requirements. In this setup, the backend and data can be self-hosted, while development or the frontend can continue to run via Lovable, GitHub, or other deployment platforms. This is a clear hybrid path.


**AVV / DPA: Covered**


A DPA/AVV is available on the website. According to the DPA, it is included in Business or Enterprise plans; Lovable processes customer data “solely on behalf of and under the instructions of the Customer.”


**No training: partially**


There is a documented opt-out process. The security page strongly states that customer data is not used for training; however, other pages specify that customer data may be used by default for model training/model improvement until an opt-out is set or requested. For Business/Enterprise, there is a workspace setting; for Free/Pro, only a support request is available. Therefore, this is not fully implemented, but only partially.


**Open Source / Transparency Path: Partial**


The website offers a transparency/sovereignty path via GitHub Sync, code export, alternative deployments, and self-hosted Supabase. In addition, Supabase is mentioned as the open-source foundation. However, the pages found do not specify open-source components of the entire Lovable platform or a fully self-hostable version of Lovable itself.


**Data Processing**


The website documentation found describes Lovable as a managed platform with Lovable Cloud and regional data storage, including an EU region. For stricter EU/EEA requirements, there is a documented workaround: code can be synced to or exported from GitHub, and the backend can be operated via self-hosted Supabase or other infrastructure. The AVV/DPA as well as SCC provisions for transfers outside the EEA are documented. Subprocessors are managed through a subprocessor/Trust Center structure. Regarding the use of data for training purposes, the information provided on the website is not entirely clear: An opt-out option is clearly documented, but not every pricing tier offers the same level of convenience.


**Conclusion**


From an EU/EEA perspective, based on the website’s current state, Lovable *cannot* be *automatically* classified as a completely uncomplicated, standard GDPR-compliant SaaS solution *across the board*; however, there is a robust compliance path: EU region for Lovable Cloud, Data Processing Agreement (DPA), Standard Contractual Clauses (SCCs), documented subprocessors, and a training-related opt-out. For more stringent requirements, a hybrid/self-hosting path via exported code and self-hosted Supabase is documented. Therefore, overall, “conditional.”


**Sources**


- [https://lovable.dev/data-processing-agreement](https://lovable.dev/data-processing-agreement)
- [https://lovable.dev/security](https://lovable.dev/security)
- [https://lovable.dev/faq/account/privacy](https://lovable.dev/faq/account/privacy)
- [https://docs.lovable.dev/features/business/data-opt-out](https://docs.lovable.dev/features/business/data-opt-out)
- [https://docs.lovable.dev/tips-tricks/external-deployment-hosting](https://docs.lovable.dev/tips-tricks/external-deployment-hosting)
- [https://docs.lovable.dev/integrations/supabase](https://docs.lovable.dev/integrations/supabase)
- [https://docs.lovable.dev/integrations/git-integration](https://docs.lovable.dev/integrations/git-integration)
- [https://docs.lovable.dev/features/cloud](https://docs.lovable.dev/features/cloud)
- [https://docs.lovable.dev/introduction/faq](https://docs.lovable.dev/introduction/faq)
- [https://lovable.dev/es/subprocessors](https://lovable.dev/es/subprocessors)

For the EU/EEA region, there are several clearly positive indicators on the website: Lovable provides a Terms of Service (TOS) and Privacy Policy (DPA), explicitly references the EU GDPR and UK GDPR, lists Standard Contractual Clauses (SCCs) for transfers to third countries, offers regional data storage within the EU according to its Security page, and documents an opt-out process for AI training. At the same time, GDPR-compliant use is not automatically clear in every standard configuration: The website states that customer data may be used for model improvement by default, as long as no opt-out has been set or requested; furthermore, international transfers and the use of subprocessors remain relevant. Therefore, based on the information on the website, GDPR-compliant use within the EU/EEA is possible, but only under certain conditions and with proper configuration.


**Positive**


The following have been confirmed: Data Processing Agreements (DPAs) for Business and Enterprise customers; explicit reference to the EU GDPR, UK GDPR, and Standard Contractual Clauses (SCCs); EU data residency in Lovable Cloud with regional data storage in the EU, the U.S., and Australia; documented subprocessor management; certifications or evidence of compliance with **ISO 27001:2022** and **SOC 2 Type II**; and a documented opt-out for training-related data use.


**Negative**


A limitation is that the website also states that customer data may be used for model training or model improvement unless an opt-out is in effect. The simple, contractually clear process is documented primarily for Business/Enterprise plans; for Free/Pro plans, the documentation states that an opt-out is only available via a support request. Additionally, international data transfers are not excluded but are safeguarded through SCCs and other mechanisms. Fully local operation of the entire Lovable platform on the customer’s own infrastructure is not described on the website as a native product model.


**Server Location**


The website states that Lovable Cloud offers “regional data hosting in the EU, US, and Australia”; customer data is intended to remain in the selected region. Specific EU country or data center locations are not specified on the pages found.

## Hosting und Daten
- **On-Prem / lokales Hosting:** teilweise / indirekt
- **Private Cloud / Rechenzentrum:** teilweise / indirekt
- **EU SaaS / Managed:** abgedeckt
- **Hybrid:** abgedeckt
- **AVV / DPA:** abgedeckt
- **Kein Training auf Kundendaten:** teilweise / indirekt
- **Open-Source / Transparenz-Pfad:** teilweise / indirekt

## Standort
**Land:** Sweden

**Taxonomie:** Sweden

Sweden / USA, depending on the perspective. Lovable officially describes itself as a Stockholm-based company; the contractual partner in the DPA is Lovable Labs Incorporated, registered in Dover, Delaware, USA.
Lovable Labs Incorporated, 1111b South Governors Avenue, Dover, DE 19904, USA according to the DPA. In addition, LOVABLE LABS UK LTD exists, Registered office: Lovable, Second Home, 68 Hanbury Street, London, England, E1 5JL

## Vorteile
- Very fast path from idea to clickable prototype or production-ready app.
- Usable for non-developers, but with Code Mode/GitHub also compatible for developers.
- Full-stack features via Lovable Cloud or Supabase, including auth, database, storage, and edge functions.
- App, chat, and API connectors, including Stripe, Shopify, GitLab, Firecrawl, Linear, Notion, Jira/Atlassian, and Miro.
- Custom domains, publishing, visual edits, versioning, and security scanning.

## Nachteile
- AI-generated code/output must be reviewed and tested; Lovable itself points out that AI output may contain errors.
- Pricing logic is complex: workspace credits, cloud costs, and AI runtime costs are separate.
- Cloud/AI usage may incur additional charges on top of the subscription; if cloud credit runs out, the app may stop.
- According to the FAQ, existing external codebases cannot be directly imported as a starting point.
- Sensitive data, especially PHI/HIPAA and other sensitive categories, should not be uploaded.
- Privacy/compliance depends heavily on configuration, third-party providers, model usage, and data types.

## Quellen
- Offizielle Website: https://lovable.dev/dashboard

## Letzter Datenstand
2026-04-24

## Originalseite
https://kifox.ai/en/ki-tools/lovable-en/
