Law & privacy · 2026
Is Lovable GDPR-compliant? DPA, data location and what your app has to meet itself
The question comes up at the latest when real user data starts flowing into the app. Here is what Lovable commits to contractually, where your data lives, how Base44, Bolt and Supabase compare — and which obligations no tool takes off your hands.
By Janni Hares ·
Short answer: Lovable can be used in a GDPR-compliant way — but not automatically, and the responsibility is yours. According to its own DPA page, Lovable ties the data processing agreement (DPA) to its Business and Enterprise plans. The backend (Lovable Cloud) can run in a European region, but the region is fixed afterwards and does not cover AI requests. And most risks of warning letters and fines don't arise at Lovable at all but in your app: a missing legal notice, an incomplete privacy policy, trackers without consent, open database tables. Exactly these points are what the free decivo Scan checks from the outside.
TL;DR — what matters
- “GDPR-compliant” is not a property of a tool. It depends on three layers: the contract with Lovable, where your backend lives and the obligations of your own app.
- Lovable explicitly names the DPA as part of Business and Enterprise (as of 6 Nov 2025). The DPA page says nothing about Free and Pro — clarify that before launch.
- Lovable Cloud offers a “Europe” region; once enabled it can't be changed. AI requests only stay in the EU with EU inference — available on the Enterprise plan only.
- Supabase concludes the DPA automatically with its terms of service. Base44 stores data in the US by default, Bolt publishes no DPA link of its own.
- Lovable's own security scan checks security, not DACH law. Legal notice, Art. 13 information, consent and AI disclosure are on you — use the checklist below or the free scan.
Three layers instead of one question
“Is Lovable GDPR-compliant?” sounds like a yes-or-no question. It isn't. The GDPR doesn't bind the tool but the controller — that's you, as soon as your app processes personal data. Lovable says so fairly directly in its own privacy policy: whoever builds an app “decides what data it collects and why, so they are responsible for that data”.
Layer 1 — the tool. Your Lovable account, your prompts, your code. Lovable is the contracting party here, and the questions are the DPA, transfers to third countries and whether your content is used to train AI models.
Layer 2 — your app's backend. The database holding your users' data: Lovable Cloud or your own Supabase project. This decides where the data is physically stored and whether the database protects it against access by others.
Layer 3 — your app itself. Legal notice, privacy policy, consent for trackers, AI disclosure, accessibility. You owe these to your visitors regardless of the tool the app was built with. And this is where most warning letters arise in practice — because they are visible from the outside.
Lovable, Supabase, Base44, Bolt compared
What the providers commit to in their own documents. Document version in brackets, retrieved on 8 October 2026 — terms change, so check the current version before signing up.
| Provider | DPA | Where the data lives | US transfer |
|---|---|---|---|
| Lovable (account, prompts, code) | Included in Business and Enterprise (6 Nov 2025). Not mentioned for Free and Pro. | Not specified in the DPA. Processing “in a number of countries, including the United States”. | EU Standard Contractual Clauses |
| Lovable Cloud (your app's backend) | Via the Lovable DPA | Region Americas, Europe or Asia Pacific, cannot be changed after enabling. AI requests only stay in the EU with EU inference (Enterprise). | EU Standard Contractual Clauses |
| Supabase (own project) | Part of the terms of service, applies on acceptance (version 1 Aug 2026) | Region freely selectable, in the EU e.g. Frankfurt. Check backups, logs and edge functions separately. | EU Standard Contractual Clauses, apply on accepting the terms |
| Base44 | Part of the terms of service, published at base44.com/dpa (undated) | Default: US. EU or UK clusters only on higher plans and only for apps created from 16 Apr 2026. Media, account and billing data stay in the US. | Per DPA e.g. Data Privacy Framework or Standard Contractual Clauses |
| Bolt.new (StackBlitz) | No public DPA link found, only “where applicable” | Processing including in the US | Standard Contractual Clauses named as an example |
The table doesn't replace reading the contracts. It shows you where to look.
DPA: when you need it, how to get it
As soon as a service provider processes personal data on your behalf, you need a contract under Art. 28 GDPR — the data processing agreement. It ensures the provider only acts on your instructions, protects the data, discloses sub-processors and deletes everything at the end. For a Lovable app that's the case at the latest when users sign up, submit forms or data lands in Lovable Cloud.
At Lovable the DPA page says verbatim: “If you're on a Business or Enterprise plan, your usage includes our Data Processing Agreement.” It says nothing about Free and Pro. If you process real user data on those plans, clarify it with Lovable in writing or switch plans before the app goes live — not afterwards.
At Supabase it's simpler: the DPA is part of the terms of service and applies when you accept them, including the EU Standard Contractual Clauses. There's nothing to sign, but you should download and file the current version — if something goes wrong, you need to be able to show what basis you were working on.
A detail almost everyone misses: for its own purposes (service, log and aggregated data) Lovable acts as an independent controller according to the DPA, not as a processor. That belongs in your privacy policy — and explains why real Lovable apps sometimes list Lovable as a processor and sometimes as a controller. You can also opt out of your content being used for model training in your account settings; according to Lovable that works “on any plan, at no cost”. By its own account, Lovable does not use your users' data in the project database for training.
Data location and US transfers
Lovable Cloud lets you pick a region when enabling it: Americas, Europe or Asia Pacific. The docs contain two pitfalls. First: “After Cloud is enabled, you cannot change the selected region” — pick “Americas” by mistake and the data can't be moved. Second: “The default hosting region covers where project data is stored, not where AI model requests are processed.” AI requests only stay in the EU with EU inference, which is part of the Enterprise plan.
Supabase offers EU regions such as Frankfurt (eu-central-1). Supabase itself warns, though: “Choosing a region is a data-location control and does not make your application GDPR compliant on its own.” Backups, logs, exports, edge functions and sub-processors belong in the assessment too. And note: Supabase's catch-all “Europe” region also includes London and Zurich — neither is in the EU.
US transfers. In their documents, Lovable and Supabase base transfers to third countries on EU Standard Contractual Clauses; they don't name the Data Privacy Framework as the basis there. The framework itself was upheld by the EU General Court on 3 September 2025 (T-553/23, Latombe); an appeal is pending at the Court of Justice. In practice this means: every US service — including AI APIs like OpenAI or Anthropic that your app calls directly — belongs in your privacy policy with recipient and transfer basis (Art. 13(1)(e) and (f) GDPR).
What your app has to meet itself
You have these obligations independently of Lovable. The builder will happily generate a legal notice or privacy page on request — whether it's correct, it doesn't check.
Legal notice (Impressum). In Germany, § 5 DDG (formerly the TMG) requires name, address, legal form, authorised representatives and a fast electronic contact option — “easily recognisable, directly accessible and permanently available”. Austria regulates this in § 5 ECG, Switzerland in Art. 3(1)(s) UWG. A missing or incomplete legal notice is a classic reason for a warning letter, because competitors find it with one click.
Privacy policy. Art. 13 GDPR requires, among other things, the controller, purposes, legal bases, recipients and third-country transfers. The typical mistake in AI-built apps: the policy comes from a generator, but the app talks to services that aren't listed — Lovable Cloud, Supabase, an AI API, an email service. Open your app, check in the browser's network tab which domains are contacted, and compare that with the text.
Consent for trackers and cookies. Under § 25 TDDDG you need consent before storing or reading information on your visitors' devices — unless it's strictly necessary for the service they asked for. A pre-ticked box doesn't count (German Federal Court of Justice, I ZR 7/16). Google Fonts loaded from Google's servers at runtime are attackable too: the Munich Regional Court awarded €100 in damages for it (3 O 17493/20). Prompts like “add Google Analytics” build in the script — often without the consent step in front of it.
Database access control. Art. 32 GDPR requires appropriate technical measures. For Supabase backends this concretely means Row Level Security on every table exposed through the API — as stated in the Supabase docs. Without it, anyone holding the public key from the browser can query all users' data. How that happens is covered in our article on Lovable app security.
AI disclosure. Since 2 August 2026, Art. 50 of the EU AI Act applies: people must be informed that they are interacting with an AI system, at the latest at the first interaction. The obligation falls on the provider of the AI system — if you build a chatbot into your app under your own name, assume you may be addressed. If your app generates images, audio, video or text, machine-readable marking under para. 2 comes on top; for systems already on the market before 2 August 2026 there is a deadline of 2 December 2026 for that. Fines go up to €15 million or 3% of turnover.
Accessibility. If your app sells to consumers — bookings, subscriptions, a shop — Germany's Accessibility Strengthening Act (BFSG) has applied since 28 June 2025. Micro-enterprises (fewer than ten employees and at most €2 million in turnover or balance sheet total) are exempt, but only if they provide services. Fines reach up to €100,000.
To be honest: this article is a technical and organisational classification, not individual legal advice. For your specific situation, a look from a data protection officer or lawyer belongs in the mix — the article and the scan tell you where to look in the first place.
Security incidents: what they mean for you as controller
For AI-built apps a data leak is not a theoretical risk. Missing Row Level Security in Lovable apps is documented as CVE-2025-48757 (Lovable disputes the classification); its discoverer found 170 of 1,645 checked projects vulnerable. A broader study of 1,072 Supabase apps found at least one flaw in 98%, a critical one in 16%.
In April 2026 Lovable itself acknowledged an incident: between 3 February and 20 April 2026, chat histories and source code of public projects could be accessed by other users with a project link. According to Lovable, private projects and Lovable Cloud were not affected. If you used real customer data, credentials or keys in prompts, check anyway whether the project was public during that period — and rotate keys if in doubt.
If you learn of a data breach, a clock starts: under Art. 33 GDPR you must report it to the supervisory authority without undue delay and where feasible within 72 hours, unless it's unlikely to result in a risk. If the risk is high, Art. 34 also requires you to notify those affected. According to DLA Piper, Europe's supervisory authorities received an average of 443 notifications per day in 2025. So decide before launch who makes the call and reports in an emergency — one sentence in your docs is enough.
What Lovable's scan checks — and what not
Lovable now has a built-in security scan: the Quick Scan runs on every publish and checks database access rules and dependencies among other things; the Deep Scan reviews your app's logic on request. That's good, and you should use it. But Lovable writes itself that the scans “cannot guarantee complete security”.
What the Lovable scan doesn't cover according to its docs: legal notice, privacy policy, consent, AI disclosure, accessibility. No surprise — that's DACH law, not a security topic. This is exactly where the decivo Scan comes in. From the outside, without access, it checks among other things: whether legal notice and privacy policy are linked, whether the legal notice contains address, contact and register or tax ID, whether the privacy policy contains the mandatory Art. 13 information, and whether your app talks to services not named there. On top: Google Fonts at runtime, US trackers without visible consent, AI endpoints without a visible AI notice and signs of BFSG relevance.
On the security side the scan asks the real question: does the public key from the browser actually return rows from your database? It only counts via a header — not a single row is fetched. Plus keys in the shipped code, such as a service_role key. All checks are listed openly in the rule catalogue.
The scan has three tiers, all free: from the outside without access; with an operator proof via DNS record, so we may also show you the exact locations; and with read-only GitHub access for architecture and code. What it can't see is shown in the result as “needs access”, not as “passed” — and nobody can see a DPA from the outside. If you want help with the fixes afterwards, Rescue Scoping is a clear next step; the scan itself commits you to nothing.
Self-check checklist
Twelve points you can work through without a developer. The last column shows whether the decivo Scan checks the point from the outside.
| Check | Basis | How to check yourself | In the scan |
|---|---|---|---|
| DPA with Lovable or Supabase in place | Art. 28 GDPR | Lovable: check your plan (DPA per Lovable on Business/Enterprise). Supabase: download and file the current DPA version. | No — contracts aren't visible from outside |
| Backend in an EU region | Art. 44 ff. GDPR | Lovable Cloud: check the selected region in the project settings. Supabase: a specific EU region instead of the catch-all “Europe”. | No |
| Training opt-out set at Lovable | Lovable privacy policy | Opt out of your content being used for model training in the account settings. | No |
| Row Level Security on every table | Art. 32 GDPR | Look for tables without RLS in the Supabase dashboard; bind every policy to the user ID. | Yes: anonymously readable tables, keys in the code |
| Legal notice complete and reachable from every page | § 5 DDG · § 5 ECG · Art. 3(s) UWG (CH) | Check the footer of every page: name, address, email, register or VAT ID. No placeholders from the template. | Yes |
| Privacy policy with all mandatory information | Art. 13 GDPR | Controller, purposes, legal bases, recipients, retention period, data subject rights, right to complain. | Yes |
| All contacted services are named | Art. 13(1)(e), (f) GDPR | Open the network tab, note the domains (Supabase, AI API, email, analytics) and compare with the policy. | Yes |
| No trackers or third-party fonts before consent | § 25 TDDDG | Private window, network tab, don't click anything: are analytics, pixel or Google Fonts domains loaded? | Yes: Google Fonts, US trackers, trackers without a consent UI |
| Forms with a privacy notice | Art. 13 GDPR | Next to every form, one sentence plus a link to the privacy policy. | Yes |
| AI chat recognisable as AI | Art. 50(1) AI Act | Notice right at the chat, not only in the privacy policy. | Yes |
| Accessibility if you sell to consumers | BFSG | Labels on form fields, alt texts, language attribute, keyboard operation; prepare an accessibility statement. | Partly: relevance and basic signals |
| Plan for data breaches | Art. 33, 34 GDPR | Decide who decides and reports within 72 hours; note the competent supervisory authority. | No |
“Yes” means the scan checks the signal from the outside. A clean result is a technical classification, not proof of legal compliance.
Sources
All figures and provider statements in this article come from the following primary sources. Retrieved on 8 October 2026.
- Lovable — Data Processing Agreement (Last updated: 6. November 2025)
- Lovable — Privacy Policy (Stand 15. September 2026)
- Lovable Docs — Lovable Cloud: Hosting-Regionen und EU inference
- Lovable Docs — Security Scan (Quick Scan und Deep Scan)
- Lovable — Our response to the April 2026 incident (22. April 2026)
- Supabase — Data Processing Addendum (Version 1, 1. August 2026)
- Supabase Docs — GDPR compliance
- Supabase Docs — Hardening the Data API (RLS auf jeder Tabelle)
- Base44 Docs — Privacy and security (Serverstandort, Data Residency)
- Base44 — Data Processing Agreement
- StackBlitz (Bolt.new) — Privacy Policy
- NVD — CVE-2025-48757: unzureichende Row Level Security in Lovable-Apps
- Matt Palmer — Statement on CVE-2025-48757 (170 von 1.645 Projekten)
- Symbiotic Security — 1.072 Vibe-Coding-Apps gescannt, 98 % mit Lücken
- DSGVO Art. 13, 28, 32, 33, 83 (Wortlaut)
- EuG, Urteil vom 3. September 2025, T-553/23 (Latombe) — Pressemitteilung 106/25
- § 25 TDDDG — Schutz der Privatsphäre bei Endeinrichtungen
- § 5 DDG — Allgemeine Informationspflichten (Impressum)
- § 5 ECG (Österreich) — Allgemeine Informationspflichten
- SECO — Onlinehandel: Impressumspflicht nach Art. 3 Abs. 1 lit. s UWG (Schweiz)
- BGH, Urteil vom 28. Mai 2020, I ZR 7/16 — Cookie-Einwilligung II
- LG München I, Urteil vom 20. Januar 2022, 3 O 17493/20 — Google Fonts
- KI-Verordnung (EU) 2024/1689, Art. 50 — Transparenzpflichten (AI Act Service Desk)
- KI-Verordnung, Art. 111 — Übergangsfrist für Art. 50 Abs. 2 bis 2. Dezember 2026
- Barrierefreiheitsstärkungsgesetz (BFSG) — §§ 1, 2, 3, 37
- DLA Piper — GDPR Fines and Data Breach Survey, Januar 2026
Lovable takes a lot of work off your hands — the responsibility for your users' data, it doesn't. The good news: most of it can be checked in an afternoon. Scan for free now →
Frequently asked
Lovable and GDPR: the key questions
Is Lovable GDPR-compliant?
Lovable can be used in a GDPR-compliant way, but not automatically. Three layers decide: a data processing agreement with Lovable (according to Lovable part of the Business and Enterprise plans), a backend in an EU region, and your own app's obligations such as legal notice, privacy policy and consent for trackers. Under the GDPR, you are the controller, not Lovable.
Do I need a DPA with Lovable?
Yes, as soon as Lovable processes personal data on your behalf — for example when users sign up or data lives in Lovable Cloud. Lovable states on its DPA page that the agreement is part of the Business and Enterprise plans (as of 6 November 2025). The page names no DPA for Free and Pro; clarify that with Lovable before launch.
Where are Lovable's servers?
For the backend (Lovable Cloud) you pick a region when enabling it: Americas, Europe or Asia Pacific. It can't be changed afterwards. The region covers project data, not AI requests — those only stay in the EU with EU inference, available on the Enterprise plan. For the platform itself, Lovable states processing in several countries, including the US.
Is Supabase in Frankfurt automatically GDPR-compliant?
No. Supabase itself writes that choosing a region only controls the storage location and does not make an app GDPR-compliant on its own. Backups, logs, exports, edge functions and sub-processors belong in the assessment. At Supabase, the data processing agreement is part of the terms of service and applies on acceptance.
Does my Lovable app need a cookie banner?
Only if it stores or reads information on visitors' devices that isn't strictly necessary for the service they asked for — typically analytics, ad pixels or embedded third-party services. Then § 25 TDDDG requires consent beforehand, with a real option to decline and no pre-ticked boxes. A banner that loads the scripts anyway doesn't help.
Do I have to label the AI chatbot in my app?
Yes. Since 2 August 2026, Art. 50 of the EU AI Act requires that people learn at the latest at the first interaction that they are talking to an AI system. The notice belongs right at the chat. If your app generates images, audio, video or text, machine-readable marking comes on top; for systems on the market before 2 August 2026 there is a deadline of 2 December 2026 for that.
Is Base44 GDPR-compliant?
Same here: not automatically. According to its docs, Base44 stores data in the US by default. EU or UK clusters are only available on higher plans and only for apps created from 16 April 2026; media, account and billing data stay in the US. Base44 publishes a DPA at base44.com/dpa. Your app's obligations — legal notice, privacy policy, consent — are the same as with Lovable.
Does Lovable's security scan check GDPR too?
No. Lovable's Quick Scan and Deep Scan cover security topics such as database access rules, dependencies, open endpoints and keys. Legal notice, privacy policy, consent, AI disclosure or accessibility don't appear in the docs. The free decivo Scan checks these points from the outside.
What does the decivo Scan cost?
Nothing. The outside scan, operator proof and repository scan are free and need no sign-up. You only pay if you want a human to classify or fix the findings.
Related articles
9 min read
Lovable app not working anymore? The honest emergency guide
Your Lovable app breaks on every click and the AI agent makes it worse? Why it happens, what you can check yourself in 5 minutes, and when a rescue beats a rebuild — with the numbers from 1,072 scanned apps and a free scan.
Read article9 min read
Is your Lovable app secure? The 5 most common security gaps 2026
98% of AI-built apps have security flaws. The 5 most dangerous — open database (RLS), service_role key in the browser, exposed .env, API keys, missing auth — explained in plain terms, plus the GDPR factor and a free security scan.
Read article22 min read
Vibe Coding: From Prototype to Product 2026 — What Comes After the First Prompt
Vibe-code MVP works but the code is chaos? 4-stage maturity scale, Stack of Truth, Clarity Retrofit workflow with prompts, before/after code, and 3 paths to production-grade software.
Read articleCheck what your app reveals to the outside.
The free decivo Scan checks legal notice, privacy policy, trackers, AI notice and open database tables right at your URL — with evidence and without access.
Free · no sign-up · result in a few minutes.