Lovable
Graded against 804 verified platforms, from its own policy text. Automated assessment against a published rubric — not legal advice.
“We do not use raw or identifiable Personal Data for training but may anonymize/aggregate it for any lawful purpose. To opt out of using your Customer Data for model training, contact us at privacy@lovable.dev or upgrade to a Business plan with enhanced controls.”
Watch: Data retention
Start here. These are the highest-risk verified clauses AIRIN found in the platform's own policy text.
Creates an exception to deletion or account closure obligations by permitting continued retention of specific PII after account closure for fraud prevention, legal defense, or compliance with legal obligations.
Establishes an exception to immediate deletion by permitting deleted data to persist in backups for a limited time before permanent removal, qualifying the scope of deletion commitments.
Establishes an exception to immediate deletion by permitting deleted data to persist in backups for a limited time before permanent removal, qualifying the scope of deletion commitments.
How to read this page: Overall risk rates what Lovable's own policy terms mean for your prompts, outputs, and data. The benchmark bands below grade those same verified terms relative to peers — a platform in a risky-by-default category can rate HIGH risk and still grade STRONG against its peer set. Both trace to the cited findings.
Policy benchmark
rubric v1.0 — how this is scoredBased on 344 verified, verbatim-cited findings below — read the citations.
Based on 381 verified, verbatim-cited findings below — read the citations.
Automated assessment against a published rubric — not legal advice.
Fully verified — complete core corpus captured and read in full.
- Terms of ServiceVerified - read in full - 141 citationsstaticLast captured 2026-08-28
- Privacy PolicyVerified - read in full - 123 citationsLast captured 2026-08-07
Only citation-backed plan differences are shown here; absent cells mean AIRIN has not verified a tier-specific claim.
This clause restricts Lovable from using raw or identifiable Personal Data for model training, permits use of anonymized or aggregated data for any lawful purpose, and provides an opt-out mechanism for Customer Data training use via email or a Business plan upgrade, directly governing training data rights and restrictions.
" We do not use raw or identifiable Personal Data for training but may anonymize/aggregate it for any lawful purpose. To opt out of using your Customer Data for model training, contact us at privacy@lovable.dev or upgrade to a Business plan ..."
Grants users the right to opt out of customer data use for model training or other business purposes by contacting the provider or upgrading to a Business plan, and identifies plan tier as a mechanism for obtaining enhanced data-handling controls.
" If you do not want your Customer Data used for model training or other business purposes, you may opt out by contacting us or by upgrading to a Business plan that provides enhanced data-handling controls."
Creates an exception to PII protections by permitting the provider to anonymize and aggregate PII and then use it without restriction for any business purpose, carving out anonymized data from the general PII use limitations.
" We will not use raw or identifiable PII for model training. We do not sell PII and we do not share it with third parties for advertising or marketing. However, we may anonymize and aggregate PII, and once anonymized and aggregated, we may ..."
Grants the user a limited, personal, non-exclusive, non-transferable, revocable license to access and use the Services for personal or internal business purposes as permitted by the subscription plan; reserves all other rights to Lovable and terminates the license upon violation or account termination.
" Subject to these Terms, we grant you a limited, personal, non-exclusive, non-transferable, revocable license to access and use the Services for your personal or internal business purposes, as permitted by your subscription plan. This licen..."
Prohibits affiliates from bidding on the provider's brand or variations in paid search ads, and prescribes specific enforcement consequences including commission forfeiture, permanent exclusion from commissions for affected users, and possible account deactivation.
" Affiliates may not bid on "Lovable" or any misspellings or variations of the brand in paid search ads (e.g., Google Ads). Violations will result in forfeiture of all commissions in the month where a violation occurred, permanent exclusion ..."
The enumerated data categories include 'prompts submitted' and 'code generated' under Internet/network activity, and 'project information you upload' as a separate category. This means user inputs and outputs are explicitly collected as personal data. Inferences drawn to personalise the platform further expand the processing scope. Users in the EEA/UK have GDPR rights but the breadth of collection is still notable.
"Lovable collects the personal information categories below when you use the Services: Identifiers such as name, business-e-mail, phone number, user ID, and IP address (city-level location only). Commercial information such as subscri..."
Creates an exception for Lovable Desktop whereby local device processing that does not transmit data to Lovable's servers is not considered a submission of customer data and is not subject to the policy, limiting the policy's territorial scope to server-side processing.
" Data Handling In Lovable Desktop : If you access Lovable through our desktop app (' Lovable Desktop' ) the data handling of Integrations applies. Certain actions may be taken locally on your device. Where no data is transmitted to Lovable'..."
Defines 'Personal Data' by reference to GDPR, UK GDPR, PIPEDA, Swiss FADP, and US state privacy statutes, and provides examples of covered data types, establishing the scope of data subject to all protective obligations in the policy.
"b. " Personal Data ": For purposes of this Policy, Personal Data (also called personal information under the California Consumer Privacy Act/Privacy Rights Act and similar U.S. state laws) means any information that relates to an identified..."
Clause A states that billing and metering data is anonymized where possible, while Clause B describes usage data collected for credit metering, which inherently requires it to be linked to a specific user and thus not anonymized, creating a conflicting claim about the data's privacy status.
" Information Collected Automatically : When you interact with the Services, we automatically collect technical data such as IP address, browser type, operating system, device identifiers, pages visited, timestamps, and error logs. Service Data is processed by Lovable as an independent controller for security, billing, analytics, and product-improvement purposes. Billing and Metering Data: Telemetry on service usage (e.g., compute hours in Lovable Cloud, API requests via AI Gateway) is collected to generate monthly invoices showing consumption by service. This data is anonymized where possible and shared with Stripe for payment processing and revenue recognition. "
" Information You Provide Directly : When you create an account, purchase a subscription, open a support ticket, apply for a role, or otherwise use our Services, you may supply Personal Data such as your name, business-email address, phone number, payment information (processed via Stripe; see Stripe's privacy policy at stripe.com/privacy for details on how they handle your card details and transaction data). For usage-based services like Lovable Cloud and AI Gateway, we collect and process Usage Data (e.g., API calls, storage usage, prompt volumes) to meter consumption against your Credits (prepaid balances). These Credits are tracked in separate balances per service, with metering reliant on Stripe and third-party providers. We do not store full payment card details; Stripe serves as the source of truth for billing records, which may include anonymized usage metrics shared with us for invoicing, and project artefacts (for example, natural-language prompts, code snippets, or deployment configurations). These artifacts are used only to serve your workspace and, once anonymized or aggregated, to improve our models; they are never used to train general-purpose AI models that benefit other customers without your permission. "
Within one documentClause A states that billing and metering data is anonymized where possible, while Clause B describes processing usage data to meter individual consumption against credits, which implies it is linked to a specific user and therefore not anonymized.
" Information Collected Automatically : When you interact with the Services, we automatically collect technical data such as IP address, browser type, operating system, device identifiers, pages visited, timestamps, and error logs. Service Data is processed by Lovable as an independent controller for security, billing, analytics, and product-improvement purposes. Billing and Metering Data: Telemetry on service usage (e.g., compute hours in Lovable Cloud, API requests via AI Gateway) is collected to generate monthly invoices showing consumption by service. This data is anonymized where possible and shared with Stripe for payment processing and revenue recognition. "
" Information You Provide Directly : When you create an account, purchase a subscription, open a support ticket, apply for a role, or otherwise use our Services, you may supply Personal Data such as your name, business-email address, phone number, payment information (processed via Stripe; see Stripe's privacy policy at stripe.com/privacy for details on how they handle your card details and transaction data). For usage-based services like Lovable Cloud and AI Gateway, we collect and process Usage Data (e.g., API calls, storage usage, prompt volumes) to meter consumption against your Credits (prepaid balances). These Credits are tracked in separate balances per service, with metering reliant on Stripe and third-party providers. We do not store full payment card details; Stripe serves as the source of truth for billing records, which may include anonymized usage metrics shared with us for invoicing, and project artefacts (for example, natural-language prompts, code snippets, or deployment configurations). These artifacts are used only to serve your workspace and, once anonymized or aggregated, to improve our models; they are never used to train general-purpose AI models that benefit other customers without your permission. "
Within one documentClause A describes 'Usage Data' for metering without mentioning anonymization, implying it may be identifiable, while Clause B explicitly states that 'Billing and Metering Data' (which is service usage telemetry) is anonymized where possible.
" Information You Provide Directly : When you create an account, purchase a subscription, open a support ticket, apply for a role, or otherwise use our Services, you may supply Personal Data such as your name, business-email address, phone number, payment information (processed via Stripe; see Stripe's privacy policy at stripe.com/privacy for details on how they handle your card details and transaction data). For usage-based services like Lovable Cloud and AI Gateway, we collect and process Usage Data (e.g., API calls, storage usage, prompt volumes) to meter consumption against your Credits (prepaid balances). These Credits are tracked in separate balances per service, with metering reliant on Stripe and third-party providers. We do not store full payment card details; Stripe serves as the source of truth for billing records, which may include anonymized usage metrics shared with us for invoicing, and project artefacts (for example, natural-language prompts, code snippets, or deployment configurations). These artifacts are used only to serve your workspace and, once anonymized or aggregated, to improve our models; they are never used to train general-purpose AI models that benefit other customers without your permission. "
" Information Collected Automatically : When you interact with the Services, we automatically collect technical data such as IP address, browser type, operating system, device identifiers, pages visited, timestamps, and error logs. Service Data is processed by Lovable as an independent controller for security, billing, analytics, and product-improvement purposes. Billing and Metering Data: Telemetry on service usage (e.g., compute hours in Lovable Cloud, API requests via AI Gateway) is collected to generate monthly invoices showing consumption by service. This data is anonymized where possible and shared with Stripe for payment processing and revenue recognition. "
Within one documentClause A describes 'Usage Data' for metering without mentioning anonymization, implying it may be identifiable, while Clause B explicitly states that 'Billing and Metering Data' (which is service usage telemetry) is anonymized where possible.
" Information You Provide Directly : When you create an account, purchase a subscription, open a support ticket, apply for a role, or otherwise use our Services, you may supply Personal Data such as your name, business-email address, phone number, payment information (processed via Stripe; see Stripe's privacy policy at stripe.com/privacy for details on how they handle your card details and transaction data). For usage-based services like Lovable Cloud and AI Gateway, we collect and process Usage Data (e.g., API calls, storage usage, prompt volumes) to meter consumption against your Credits (prepaid balances). These Credits are tracked in separate balances per service, with metering reliant on Stripe and third-party providers. We do not store full payment card details; Stripe serves as the source of truth for billing records, which may include anonymized usage metrics shared with us for invoicing, and project artefacts (for example, natural-language prompts, code snippets, or deployment configurations). These artifacts are used only to serve your workspace and, once anonymized or aggregated, to improve our models; they are never used to train general-purpose AI models that benefit other customers without your permission. "
" Information Collected Automatically : When you interact with the Services, we automatically collect technical data such as IP address, browser type, operating system, device identifiers, pages visited, timestamps, and error logs. Service Data is processed by Lovable as an independent controller for security, billing, analytics, and product-improvement purposes. Billing and Metering Data: Telemetry on service usage (e.g., compute hours in Lovable Cloud, API requests via AI Gateway) is collected to generate monthly invoices showing consumption by service. This data is anonymized where possible and shared with Stripe for payment processing and revenue recognition. "
Within one documentClause A states that billing and metering data is anonymized where possible, while Clause B describes processing usage data to meter individual consumption against credits, which implies it is linked to a specific user and therefore not anonymized.
" Information Collected Automatically : When you interact with the Services, we automatically collect technical data such as IP address, browser type, operating system, device identifiers, pages visited, timestamps, and error logs. Service Data is processed by Lovable as an independent controller for security, billing, analytics, and product-improvement purposes. Billing and Metering Data: Telemetry on service usage (e.g., compute hours in Lovable Cloud, API requests via AI Gateway) is collected to generate monthly invoices showing consumption by service. This data is anonymized where possible and shared with Stripe for payment processing and revenue recognition. "
" Information You Provide Directly : When you create an account, purchase a subscription, open a support ticket, apply for a role, or otherwise use our Services, you may supply Personal Data such as your name, business-email address, phone number, payment information (processed via Stripe; see Stripe's privacy policy at stripe.com/privacy for details on how they handle your card details and transaction data). For usage-based services like Lovable Cloud and AI Gateway, we collect and process Usage Data (e.g., API calls, storage usage, prompt volumes) to meter consumption against your Credits (prepaid balances). These Credits are tracked in separate balances per service, with metering reliant on Stripe and third-party providers. We do not store full payment card details; Stripe serves as the source of truth for billing records, which may include anonymized usage metrics shared with us for invoicing, and project artefacts (for example, natural-language prompts, code snippets, or deployment configurations). These artifacts are used only to serve your workspace and, once anonymized or aggregated, to improve our models; they are never used to train general-purpose AI models that benefit other customers without your permission. "
Within one documentClause A states that billing and metering data is anonymized where possible, while Clause B describes usage data collected for credit metering, which inherently requires it to be linked to a specific user and thus not anonymized, creating a conflicting claim about the data's privacy status.
" Information Collected Automatically : When you interact with the Services, we automatically collect technical data such as IP address, browser type, operating system, device identifiers, pages visited, timestamps, and error logs. Service Data is processed by Lovable as an independent controller for security, billing, analytics, and product-improvement purposes. Billing and Metering Data: Telemetry on service usage (e.g., compute hours in Lovable Cloud, API requests via AI Gateway) is collected to generate monthly invoices showing consumption by service. This data is anonymized where possible and shared with Stripe for payment processing and revenue recognition. "
" Information You Provide Directly : When you create an account, purchase a subscription, open a support ticket, apply for a role, or otherwise use our Services, you may supply Personal Data such as your name, business-email address, phone number, payment information (processed via Stripe; see Stripe's privacy policy at stripe.com/privacy for details on how they handle your card details and transaction data). For usage-based services like Lovable Cloud and AI Gateway, we collect and process Usage Data (e.g., API calls, storage usage, prompt volumes) to meter consumption against your Credits (prepaid balances). These Credits are tracked in separate balances per service, with metering reliant on Stripe and third-party providers. We do not store full payment card details; Stripe serves as the source of truth for billing records, which may include anonymized usage metrics shared with us for invoicing, and project artefacts (for example, natural-language prompts, code snippets, or deployment configurations). These artifacts are used only to serve your workspace and, once anonymized or aggregated, to improve our models; they are never used to train general-purpose AI models that benefit other customers without your permission. "
Within one documentClause A describes 'Usage Data' for metering without mentioning anonymization, implying it may be identifiable, while Clause B explicitly states that 'Billing and Metering Data' (which is service usage telemetry) is anonymized where possible.
" Information You Provide Directly : When you create an account, purchase a subscription, open a support ticket, apply for a role, or otherwise use our Services, you may supply Personal Data such as your name, business-email address, phone number, payment information (processed via Stripe; see Stripe's privacy policy at stripe.com/privacy for details on how they handle your card details and transaction data). For usage-based services like Lovable Cloud and AI Gateway, we collect and process Usage Data (e.g., API calls, storage usage, prompt volumes) to meter consumption against your Credits (prepaid balances). These Credits are tracked in separate balances per service, with metering reliant on Stripe and third-party providers. We do not store full payment card details; Stripe serves as the source of truth for billing records, which may include anonymized usage metrics shared with us for invoicing, and project artefacts (for example, natural-language prompts, code snippets, or deployment configurations). These artifacts are used only to serve your workspace and, once anonymized or aggregated, to improve our models; they are never used to train general-purpose AI models that benefit other customers without your permission. "
" Information Collected Automatically : When you interact with the Services, we automatically collect technical data such as IP address, browser type, operating system, device identifiers, pages visited, timestamps, and error logs. Service Data is processed by Lovable as an independent controller for security, billing, analytics, and product-improvement purposes. Billing and Metering Data: Telemetry on service usage (e.g., compute hours in Lovable Cloud, API requests via AI Gateway) is collected to generate monthly invoices showing consumption by service. This data is anonymized where possible and shared with Stripe for payment processing and revenue recognition. "
Within one document
Evidence appendix
Showing priority citations first. The full appendix is available for audit trails; not every citation is a severe risk.
" may be limited to specific Services (for example, only the AI Gateway);"
Restricts the use of promotional credits and offers to specific designated Services, limiting their applicability to only those services identified in the promotion.
AI-generated interpretation, not legal advice.
"Please note: This Privacy Policy applies to Free and Pro plans. This does not include Business and Enterprise plans which are governed by our terms and Data Processing Agreement found here ."
This clause explicitly scopes the Privacy Policy to Free and Pro tiers, excluding Business and Enterprise. Enterprise customers typically negotiate DPAs with stronger deletion, audit, and sub-processor obligations. Free/Pro users lack those contractual mechanisms.
AI-generated interpretation, not legal advice.
" We do not use raw or identifiable Personal Data for training but may anonymize/aggregate it for any lawful purpose. To opt out of using your Customer Data for model training, contact us at privacy@lovable.dev or upgrade to a Business plan with enhanced controls."
This clause restricts Lovable from using raw or identifiable Personal Data for model training, permits use of anonymized or aggregated data for any lawful purpose, and provides an opt-out mechanism for Customer Data training use via email or a Business plan upgrade, directly governing training data rights and restrictions.
AI-generated interpretation, not legal advice.
" We will not use raw or identifiable PII for model training. We do not sell PII and we do not share it with third parties for advertising or marketing. However, we may anonymize and aggregate PII, and once anonymized and aggregated, we may use it for any business purpose without restriction."
Creates an exception to PII protections by permitting the provider to anonymize and aggregate PII and then use it without restriction for any business purpose, carving out anonymized data from the general PII use limitations.
AI-generated interpretation, not legal advice.
"Lovable collects the personal information categories below when you use the Services: Identifiers such as name, business-e-mail, phone number, user ID, and IP address (city-level location only). Commercial information such as subscription tier and purchase history; full payment-card numbers are processed solely by our PCI-compliant provider and are never stored by Lovable. Internet / network activity such as log-in events, feature usage, prompts submitted, code generated, and telemetry. Inferences drawn to personalize the platform. Project information you upload (e.g., repositories and configuration files)."
The enumerated data categories include 'prompts submitted' and 'code generated' under Internet/network activity, and 'project information you upload' as a separate category. This means user inputs and outputs are explicitly collected as personal data. Inferences drawn to personalise the platform further expand the processing scope. Users in the EEA/UK have GDPR rights but the breadth of collection is still notable.
AI-generated interpretation, not legal advice.
" Sensitive Personal Information is not intentionally collected, and customers are instructed not to upload sensitive data (for example, Social-Security numbers or precise geolocation). No sensitive data (e.g., HIPAA-protected health info, financial accounts) should be uploaded; our Services are not designed for it, and we disclaim responsibility if submitted."
Restricts collection of sensitive personal information, instructs customers not to upload sensitive data such as SSNs or health information, and disclaims responsibility if such data is submitted, combining a behavioral restriction on users with a liability disclaimer for the platform.
AI-generated interpretation, not legal advice.
"we reserve the right to reclaim subdomains immediately without notice when necessary to address urgent issues, including but not limited to violations of our Platform Rules , legal requirements, security threats, or abuse."
The emergency reclamation right is triggered by Lovable's unilateral determination of urgency across broad categories. Users have no procedural protections and no recourse for sudden loss of a deployed application's domain.
AI-generated interpretation, not legal advice.
"We may terminate your account or access to the Services for convenience by providing you with advance notice, or as otherwise provided in the " Suspension and Termination for Breach" section. We may also discontinue or modify the Services in whole or in part at any time by providing you with advance notice."
The platform can terminate any account for any reason (convenience) or no reason, and can alter or shut down the service entirely. The lack of a defined notice period weakens user protections.
AI-generated interpretation, not legal advice.
" Credits are prepaid, non-refundable, and non-redeemable for cash or any other value. Credits represent only a limited license to access the Services and are not deposits, stored value, or financial instruments. For rollover and expiration rules, see the " Credit Rollover and Expiration" section above. For forfeiture rules, see the " Refunds and Termination" section."
Restricts credits to non-refundable, non-redeemable prepaid access rights, defines them as a limited license rather than a financial instrument, and cross-incorporates rollover and forfeiture rules from other sections.
AI-generated interpretation, not legal advice.
" We can retain PII as long as reasonably necessary to provide the Services."
Creates an exception to deletion or account closure obligations by permitting continued retention of specific PII after account closure for fraud prevention, legal defense, or compliance with legal obligations.
AI-generated interpretation, not legal advice.
" We may also retain specific PII, after account closure or deletion requests, for fraud prevention, legal defense, or to comply with our legal obligations."
Establishes an exception to immediate deletion by permitting deleted data to persist in backups for a limited time before permanent removal, qualifying the scope of deletion commitments.
AI-generated interpretation, not legal advice.
" Deleted data may persist in backups for a limited time before being permanently removed."
Establishes an exception to immediate deletion by permitting deleted data to persist in backups for a limited time before permanent removal, qualifying the scope of deletion commitments.
AI-generated interpretation, not legal advice.
" TO THE FULLEST EXTENT PERMITTED BY LAW, WE AND OUR LICENSORS, PROVIDERS, AFFILIATES, AND OFFICERS WILL NOT BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, EXEMPLARY, OR PUNITIVE DAMAGES, INCLUDING LOST PROFITS, LOST DATA, BUSINESS INTERRUPTION, OR LOSS OF GOODWILL, ARISING OUT OF OR RELATING TO THE SERVICES OR THESE TERMS, EVEN IF WE WERE ADVISED OF THE POSSIBILITY OF SUCH DAMAGES, EXCEPT TO THE EXTENT SUCH LIABILITY CANNOT BE LIMITED UNDER APPLICABLE LAW. WITHOUT LIMITING THE FOREGOING, WE WILL NOT BE LIABLE FOR ANY DOWNTIME, FAILURES, DELAYS, OR OTHER ISSUES CAUSED BY INFRASTRUCTURE PROVIDERS, THIRD-PARTY AI PROVIDERS, OR OTHER THIRD PARTIES; FOR ERRORS OR INACCURACIES IN AI OUTPUT; FOR ANY ACT OR OMISSION BY YOU, YOUR USERS, OR ANYONE USING YOUR ACCOUNT; OR FOR LOSS OF CUSTOMER DATA, EXCEPT TO THE EXTENT CAUSED BY OUR GROSS NEGLIGENCE OR WILLFUL MISCONDUCT. IN NO EVENT WILL OUR TOTAL LIABILITY FOR ALL CLAIMS ARISING OUT OF OR RELATING TO THE SERVICES OR THESE TERMS, WHETHER IN CONTRACT, TORT (INCLUDING NEGLIGENCE), STRICT LIABILITY, OR ANY OTHER LEGAL THEORY, EXCEED THE AMOUNT YOU PAID US FOR THE SERVICES IN THE TWELVE (12) MONTHS IMMEDIATELY PRECEDING THE CLAIM, EXCEPT TO THE EXTENT SUCH LIABILITY CANNOT BE LIMITED UNDER APPLICABLE LAW. "
Excludes the platform and its affiliates from liability for indirect, incidental, special, consequential, exemplary, or punitive damages including lost profits, lost data, and business interruption, and specifically disclaims liability for downtime or infrastructure failures, to the fullest extent permitted by law.
AI-generated interpretation, not legal advice.
"NCLUDING NEGLIGENCE), STRICT LIABILITY, OR ANY OTHER LEGAL THEORY, EXCEED THE AMOUNT YOU PAID US FOR THE SERVICES IN THE TWELVE (12) MONTHS IMMEDIATELY PRECEDING THE CLAIM, EXCEPT TO THE EXTENT SUCH LIABILITY CANNOT BE LIMITED UNDER APPLICABLE LAW."
This is a standard but aggressive liability cap. For free-tier users who have paid nothing, the cap would be $0, leaving them with no practical remedy for platform-caused harm. Even paid users are limited to a relatively modest 12-month fee amount regardless of actual damages.
AI-generated interpretation, not legal advice.
" Except where required by law, all fees are non-refundable."
Restricts customers from obtaining refunds on fees paid, establishing that all fees are non-refundable except where required by applicable law, limiting the provider's financial liability for reversals.
AI-generated interpretation, not legal advice.
"By using Lovable Cloud, you consent to the transfer, storage, and processing of your Customer Data by Supabase under their privacy policy (available at supabase.com/privacy )."
Implied consent through service usage is a legally contestable basis for international data transfers under GDPR. Lovable should rely on SCCs or adequacy decisions for transfers to Supabase, not user consent, since consent as a transfer mechanism is disfavored by regulators (EDPB Guidelines 05/2021).
AI-generated interpretation, not legal advice.
"Your Personal Data may be shared with: The applicable registry operator; ICANN; Any ICANN-authorised escrow service provider; and Other third parties as required or permitted by applicable ICANN policies or law"
Sharing personal data with 'other third parties as required or permitted by applicable ICANN policies or law' is an open-ended disclosure that may not satisfy GDPR Art. 13/14 requirements for specific identification of recipients or categories of recipients at the time of collection.
AI-generated interpretation, not legal advice.
" You may not assign, delegate, or transfer these Terms, by operation of law or otherwise, without our prior written consent. We may assign, delegate, or transfer these Terms, in whole or in part, without restriction. Any attempt to assign in violation of this section is void."
Restricts users from assigning or transferring the Terms without prior written consent, while granting the platform an unrestricted right to assign, delegate, or transfer the Terms; declares any unauthorized assignment void, establishing both a user restriction and a platform right.
AI-generated interpretation, not legal advice.
Common questions about Lovable's policies
- Does Lovable train its AI models on your data?
- Training possible — conditions or opt-outs apply — based on 3 verified findings from Lovable's published policy. Informational only, not legal advice.
- Who owns the content you create with Lovable?
- You own your outputs — based on 3 verified findings from Lovable's published policy. Informational only, not legal advice.
- Can you use Lovable's output commercially?
- Commercial use allowed — with conditions — based on 4 verified findings from Lovable's published policy. Informational only, not legal advice.
Clause detail — protections, your obligations, and coverage
Every clause below is a verbatim quote from Lovable's own published policy, read in full and linked to its exact location. Protections and user obligations are reported separately from risk because they are different kinds of clause — an obligation on you is not a risk to your data. Informational only, not legal advice.
✅ Protections found
47 verified clausesClauses in Lovable's policies that work in your favour — commitments the platform made to you.
- Governing law & disputesarbitration & class-action waiver
“This Policy is governed by and governed in accordance with the laws of the State of Delaware, United States, without regard to its conflict-of-law principles. However, if you are located in a jurisdiction that grants you mandatory consumer protection or data p…”
Designates Delaware law as the governing law for the Policy, preserves mandatory local consumer and data protection rights for users in other jurisdictions, and specifies Irish law and Dublin courts as the governing fram…
📍 Privacy Policy › “Governing Law & Venue”Jump to exact text → - Governing law & disputes
“This Policy is governed by and governed in accordance with the laws of the State of Delaware, United States, without regard to its conflict-of-law principles. However, if you are located in a jurisdiction that grants you mandatory consumer protection or data p…”
Delaware law and Wilmington courts are designated as the default exclusive forum. While mandatory consumer/data protection laws in the user's jurisdiction are preserved, this requires users to identify and assert those r…
📍 Privacy Policy › “Governing Law & Venue”Jump to exact text → - Privacy & data usebreach notification promises
“You may access, correct, or request deletion of your Personal Data at any time by contacting us at privacy@lovable.dev , as described in this Policy. Lovable and its registrar partners take reasonable technical and organisational precautions to protect your Pe…”
Grants users the right to access, correct, or request deletion of personal data, establishes security obligations for Lovable and its registrar partners, and creates a procedure for data portability/continuity obligation…
- Designated security contact: privacy@lovable.dev
📍 Privacy Policy › “Any ICANN-authorised escrow service provider; and”Jump to exact text → - Data retentiondeletion rights & post-termination survival
“Resolving disputes or enforcing agreements. Customer data is retained for up to ninety (90) days, unless required by law, after which it is deleted or isolated. To cancel your account or request data deletion, contact us as outlined in the Policy. Upon account…”
Specifies a 90-day customer data retention limit, a 30-day post-termination deletion obligation, exceptions for fraud prevention and legal compliance, a 90-day backup retention allowance, and a procedure for requesting d…
- Designated security contact: privacy@lovable.dev
📍 Privacy Policy › “Retention of Your Information”Jump to exact text → - Subprocessors & data sharing
“We engage third-party sub-processors to support our Services, such as: Hosting and maintaining our platform, website, and databases. Processing payments through secure third-party payment processors. Providing technical support, customer service, and…”
The platform shares data with a broad category of sub-processors. The 10 business day objection window is relatively short and standard practice does not guarantee users can exit the service if they object. The non-selli…
📍 Privacy Policy › “Data Processing and Sub-Processors”Jump to exact text → - Privacy & data usechildren's data
“Children's Data : Lovable's Services are not intended for individuals under the age of eighteen (18), and we do not knowingly collect or solicit Personal Data from anyone under this age, unless as part of a program with a partner, the child has obtained consen…”
Restricts collection of personal data from individuals under 18, establishes a representation warranty by users regarding their age, and imposes an obligation to promptly delete personal data collected from minors withou…
- Designated security contact: privacy@lovable.dev
📍 Privacy Policy › “Any ICANN-authorised escrow service provider; and”Jump to exact text →
+ 41 more verified clauses of this kind on this platform, cited in full in the report.
📋 Rules you must follow
29 verified clausesWhat Lovable requires of YOU. These are your obligations, not risks to your data or IP, so they are cited here and excluded from this platform's risk rating.
- Moderation & enforcement
“You may not use the Services if you are located in, or acting on behalf of a person or entity located in, a country or territory that is subject to U.S. government embargoes or sanctions (including Cuba, Iran, North Korea, Russia, Syria, and the Crimea, Donets…”
Restricts use of the Services by persons or entities located in U.S.-sanctioned countries or territories, or those on U.S. restricted-party lists, and requires users to represent and warrant compliance with export contro…
📍 Terms of Service › “Export Controls and Sanctions”Jump to exact text → - Commercial useconduct restrictions
“Affiliates may not bid on "Lovable" or any misspellings or variations of the brand in paid search ads (e.g., Google Ads). Violations will result in forfeiture of all commissions in the month where a violation occurred, permanent exclusion from affiliate commis…”
Prohibits affiliates from bidding on the provider's brand or variations in paid search ads, and prescribes specific enforcement consequences including commission forfeiture, permanent exclusion from commissions for affec…
📍 Terms of Service › “No Brand Bidding”Jump to exact text → - Moderation & enforcement
“You agree not to upload, input, or otherwise provide any protected health information under HIPAA, or any other sensitive categories of data (such as financial account numbers, government identifiers, or biometric data). Our Services are not designed to handle…”
Prohibits users from uploading HIPAA-protected health information or other sensitive data categories such as financial account numbers, government identifiers, or biometric data, and disclaims all provider responsibility…
📍 Terms of Service › “No Sensitive Data”Jump to exact text → - Moderation & enforcement
“You are responsible for ensuring that your use of the Services, including transfers of Customer Data through the Platform, Lovable Cloud, the AI Gateway, or any model or service you connect, complies with applicable data protection and privacy laws.”
Imposes a legal obligation on the customer to ensure that their use of the Services, including all data transfers through the platform and connected services, complies with applicable data protection and privacy laws.
📍 Terms of Service › “Customer Responsibility”Jump to exact text → - Moderation & enforcementconduct restrictions
“Affiliates may not use spammy tactics, misleading claims, or false endorsements in promoting Lovable. This includes fake discounts, deceptive landing pages, or unauthorized use of brand assets.”
Prohibits affiliates from using spam, misleading claims, false endorsements, fake discounts, deceptive landing pages, or unauthorized brand assets in promoting the provider, establishing conduct standards enforceable aga…
📍 Terms of Service › “No Spam or Misleading Promotions”Jump to exact text →
+ 24 more verified clauses of this kind on this platform, cited in full in the report.
What the policies actually cover
17 topics- Product telemetry & usage tracking24 clauses
- Advertising & tracking3 protective8 clauses
- Sale or sharing of personal data2 protective2 clauses
- Sensitive data (biometric, location, health)1 protective2 clauses
- Children's data2 protective3 clauses
- Government & law-enforcement disclosure2 protective6 clauses
- Data shared with other AI providers7 clauses
- Does not train on your content1 clause
- Trains by default, opt-out available2 clauses
- Arbitration & class-action waiver1 protective1 clause
- Damages & liability cap5 clauses
- Indemnity direction6 clauses
- Terms can change at any time3 protective6 clauses
- Deletion rights & post-termination survival4 protective10 clauses
- Auto-renewal & cancel window4 clauses
- Breach-notification promises4 protective5 clauses
- Conduct restrictions12 obligations12 clauses
160 further verified clauses are cited on this page but not yet assigned a topic.
Cross-clause notes
Two verified clauses intersect on the same subject matter: the Terms of Service, Terms of Service › “Retention and Deletion” addresses how long content is retained, and the Privacy Policy, Privacy Policy › “Data Usage” addresses use of content in connection with model training or service improvement. Both clauses are in force at the same time — read them together.
The Privacy Policy, Privacy Policy › “Data Usage” describes a way to decline model training, and the Terms of Service, Terms of Service › “Restrictions” states that terms differ by plan or tier. Whether the opt-out applies on every tier is determined by those clauses together — read both before relying on the opt-out.
Verified retention clauses point in different directions: the Terms of Service, Terms of Service › “Retention and Deletion” describes broad or open-ended retention, while the Terms of Service, Terms of Service › “Retention and Deletion” describes deletion or erasure. Which clause controls in a given situation is not resolved by the documents' text alone — this is surfaced as an ambiguity, treated as Caution.
Automated cross-reference against the published rubric — not legal advice.
Clause intelligence
Canonical clauses and stance patterns extracted from the same gate-verified citations shown on this page.
The clause allows indefinite, perpetual, or necessity-based retention.
“We retain Personal Data only as long as necessary to fulfill the purposes outlined in this Policy or as required by applicable law, including:”Open source citation
The clause allows indefinite, perpetual, or necessity-based retention.
“We may also create de-identified, anonymized, or aggregated data from your Customer Data, and we may retain and use that data on a perpetual basis for any lawful business purpose; such data does not identify you and is no longer your Customer Data. This license is granted notwithstanding any confidentiality obligations in these Terms and survives to the extent needed to give effect to the purposes above. Our handl...”Open source citation
The clause allows indefinite, perpetual, or necessity-based retention.
“We retain Personal Data only as long as necessary to fulfill the purposes outlined in this Policy or as required by applicable law, including:”Open source citation
The clause allows indefinite, perpetual, or necessity-based retention.
“We retain Personal Data only as long as necessary to fulfill the purposes outlined in this Policy or as required by applicable law, including:”Open source citation
The clause allows indefinite, perpetual, or necessity-based retention.
“We may also create de-identified, anonymized, or aggregated data from your Customer Data, and we may retain and use that data on a perpetual basis for any lawful business purpose; such data does not identify you and is no longer your Customer Data. This license is granted notwithstanding any confidentiality obligations in these Terms and survives to the extent needed to give effect to the purposes above. Our handl...”Open source citation
Tier matrix
Plan-level conditions detected from citation-backed clauses. Empty tiers mean AIRIN has not captured decisive tier language yet.
| Tier | Surface | Verdict | Risk | Citations |
|---|---|---|---|---|
| All applicable tiers | commercial use | worsens | HIGH | 1 |
| All applicable tiers | data retention | conditional | MEDIUM | 9 |
| All applicable tiers | moderation enforcement | worsens | HIGH | 10 |
| All applicable tiers | output ownership | improves | LOW | 1 |
| All applicable tiers | prompt ownership | worsens | HIGH | 1 |
| All applicable tiers | tier differences | worsens | HIGH | 1 |
| Free | privacy data use | conditional | MEDIUM | 3 |
| Free | training use | conditional | MEDIUM | 1 |
| Standard | governing law disputes | improves | LOW | 1 |
| Standard | output ownership | improves | LOW | 3 |
| Team / Business | commercial use | worsens | HIGH | 5 |
| Team / Business | data retention | conditional | MEDIUM | 3 |
Policy evolution
Open full timelineBefore/after stance changes across captured policy versions. When no material delta exists yet, AIRIN shows the latest citation-backed stance events instead.
model training worsened from medium/training with opt out to high/training permitted.
“We do not use raw or identifiable Personal Data for training but may anonymize/aggregate it for any lawful purpose. To opt out of using your Customer Data for model training, contact us at privacy@lovable.dev or upgrade to a Business plan with enhanced controls.”Before citation
“developing and training artificial intelligence and machine learning models;”After citation
model training improved from high/training permitted to medium/training with opt out.
“use the Services, AI Output, or prompts to train, develop, or improve competing AI models.”Before citation
“We do not use raw or identifiable Personal Data for training but may anonymize/aggregate it for any lawful purpose. To opt out of using your Customer Data for model training, contact us at privacy@lovable.dev or upgrade to a Business plan with enhanced controls.”After citation
model training worsened from medium/training with opt out to high/training permitted.
“We do not use raw or identifiable Personal Data for training but may anonymize/aggregate it for any lawful purpose. To opt out of using your Customer Data for model training, contact us at privacy@lovable.dev or upgrade to a Business plan with enhanced controls.”Before citation
“use the Services, AI Output, or prompts to train, develop, or improve competing AI models.”After citation
model training improved from high/training permitted to medium/training with opt out.
“developing and training artificial intelligence and machine learning models;”Before citation
“We do not use raw or identifiable Personal Data for training but may anonymize/aggregate it for any lawful purpose. To opt out of using your Customer Data for model training, contact us at privacy@lovable.dev or upgrade to a Business plan with enhanced controls.”After citation
model training worsened from medium/training with opt out to high/training permitted.
“We do not use raw or identifiable Personal Data for training but may anonymize/aggregate it for any lawful purpose. To opt out of using your Customer Data for model training, contact us at privacy@lovable.dev or upgrade to a Business plan with enhanced controls.”Before citation
“developing and training artificial intelligence and machine learning models;”After citation
model training improved from high/training permitted to medium/training with opt out.
“use the Services, AI Output, or prompts to train, develop, or improve competing AI models.”Before citation
“We do not use raw or identifiable Personal Data for training but may anonymize/aggregate it for any lawful purpose. To opt out of using your Customer Data for model training, contact us at privacy@lovable.dev or upgrade to a Business plan with enhanced controls.”After citation
Latest stance: training permitted on training use
“We may use your Customer Data to develop and train artificial intelligence and machine learning models. You may tell us at any time that you do not want your Customer Data used for model training or the other business purposes described above, and we will honor that request for prospective use, free of charge and regardless of your plan.”Open timeline citation
Latest stance: broad license on privacy data use
“You grant us a worldwide, perpetual, royalty-free license to use, copy, modify, process, analyze, and otherwise exploit your Customer Data for our business purposes, including without limitation:”Open timeline citation
Latest stance: platform claims or reserves rights on moderation enforcement
“If you create a username on the Platform, you acknowledge and agree that we reserve the right, at our sole discretion, to reclaim, reassign, or terminate any username at any time and for any reason, including but not limited to: (a) usernames that are inappropriate, offensive, or violate our Platform Rules ; (b) usernames that impersonate or could be confused with official Lovable pages, features, or routes (such as "home," "projects," "settings," or similar); or (c) usernames that impersonate another company, brand, or individual. You have no proprietary or ongoing rights to any specific username, and reclamation of a username does not entitle you to a refund or any other compensation.”Open timeline citation
Latest stance: platform claims or reserves rights on moderation enforcement
“We reserve the right, at our sole discretion, to reclaim, reassign, redirect, suspend, or terminate any subdomain at any time and for any reason, including but not limited to: enabling the subdomain to be used by another user or for another purpose that better serves the Lovable community;”Open timeline citation
Capture recency
- Terms of Service:Last captured 2026-08-28· verified 2026-08-28
- Privacy Policy:Last captured 2026-08-07· verified 2026-08-07
Dates state when our pipeline captured and verified each document — not when the vendor last changed it. Documents are re-scanned on a recurring cadence; a document verified once says so until a re-scan confirms it again.
↑ 34 more findings this quarter vs last (363 vs 329). First scan: June 2026.
Compare and stack are saved in your browser. Open compare · View your stack. A correction triggers an automated re-read of Lovable's policies — no human edits the data.
Need this for procurement or legal diligence?
Free shows today's risk. A Stack Audit gives you a citable, verbatim-sourced PDF across your whole AI stack — and flags the moment a vendor's terms change.
Every finding above is a verbatim quote from Lovable's own published policy, captured to an immutable snapshot and read in full through a two-gate verification pipeline. Confidence labels and any analysis are AI-generated and informational only — not legal advice.
AIRIN Brief
Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.